Back to all updates
30 September 2026v2.0.0Available now

Koora v2: the record that travels, the audit before you pay, and one price

WorkersProviders

Ten weeks ago we opened V1 and said we were onboarding our first customers. The first customers said the same three things. A worker's passport should not wait on a review to exist. A provider should see the audit before paying for it. And the price needed to be one number. Here is what changed.

A Career Passport exists as soon as the credentials add up

At launch a passport waited in a review queue. Now the compliance engine tests every credential you supply against what your roles require, and your verdict updates the moment a credential is date-complete. That verdict is engine-checked. Each credential still carries its own status, and it stays "Not yet checked" until someone has looked: a person reviews your own uploads once you share your passport or a provider requests access, and a workplace's own records are reviewed where the workplace does it or where Crew, the paid review add-on, is attached. Three words describe the result on every screen: Reviewed, Verified, and Verified and monitored. Verified is reserved for checks against an authoritative register: identity and work rights, AHPRA, state Working with Children Check portals, teacher registration, and the ban registers, which are the only credentials monitored today.

Claim the record a workplace already holds about you

Providers import their workforce, so a record about you may exist before you do. You now sign up with any email, verify your identity once, and the record joins your Career Passport on its own; Koora matches the verified legal name and date of birth, the code in the workplace's email completes it, and a mismatch goes to a person at Koora rather than silently binding. The join is the passport: a claimed record builds your sectors, roles and states, the documents the workplace holds count as evidence, and the passport page lists exactly what would show you as Compliant to that workplace. Nothing the workplace holds moves onto your own passport until you choose to adopt it, and an organisation with several services asks once, on one sheet.

The audit runs before you pay

The workforce import was rebuilt end to end: your file, match your data, your records, audit, cost and send. The audit runs worker by worker before anything is sent, with ticks for what you hold and crosses for what is missing, judged on the records your organisation supplies. Typed records count where the number is the checkable evidence, AHPRA, WWCC, teacher registration and NDIS clearance; where the document is the evidence, the row says so until the file is attached. Records that arrive from another system are treated as already reviewed, and they stay your organisation's whoever the worker is. Existing workers whose records are complete at import get 50% off their seat for year one. No gaps, no gap rates.

One decision per credential, and a queue that says whose turn it is

A worker's page shows two things about a person and never blends them: the engine's verdict, and, only while your organisation still owes a decision, Review needed. The Compliance queue is the first tab on Workforce: review, sighting, missing details and ready, in one place, on every plan, because it is your organisation's own evidence work. Review evidence with Approve, Approve with edits or Decline. A register check you make reads "Verified by your organisation" with the date; a document sighting reads "Reviewed by" the person who did it. Koora pre-clears the credentials. The legal responsibility for who you engage stays with you.

One price

V2 replaced the launch bundles with a seat: passport access is priced per worker per year, collected on a monthly invoice on the Australian 1st, and the first five workers are free across the whole organisation for the life of the account. On 30 September the card came down and lost its steps. Flex and Pro share one seat at $22 per worker per year, flat at any book size. Pro adds $50 a month for the integrations: workers synced in from your HR system, compliance updates pushed out, the workforce API and webhooks, and a bigger Kooka AI pool. Enterprise commits a book of 250 or more for 12 months at a lower flat rate, quoted on a call. An organisation pays once per worker, however many of its services track them. Crew is $24 for the first review plus $18 per worker per year, an add-on on every plan. Register Upload, the childcare register workflow (who to sight, what's due, and the upload file for the National Early Childhood Worker Register), is included on every plan. Every price includes GST. Current numbers are always on the pricing page.

Integrations, on Pro

The workforce API and webhooks moved from Enterprise to Pro in August. Since then: credentials by API as a file or a typed record, a completeness read, a sync-file channel that lets any HR system drop a roster export for an admin to review, and events for claims, seats, adoption and disputes. The API reference lives in the app under Integrations, and the breaking changes are listed below with their dates.

Kooka AI, from day one

Kooka AI opens on your first sign-in. It now says plainly what leaves Australia: chat and voice go to overseas providers with your first name and a summary of your Career Passport; identity, police, health and screening data stay in Australia and are never sent. Credit packs cost the same on the web, the App Store and Google Play.

Where we are

Koora's SOC 2 Type I report was issued in September 2026, as at 20 July 2026, examined by Advantage Partners against the Security trust services criteria, with an unqualified opinion and no exceptions noted. It is available to customers and prospective customers through the trust centre; the Type II observation window is under way. Sensitive compliance and identity data stays in Australia and is never transferred overseas.

The worker marketplace is gone; we wrote up why. If something here is wrong or confusing, support@koora.care reaches a human. We're here to uplift care.

Improvements (38)

For workers

  • Your Career Passport is ready as soon as your credentials add up: an uploaded credential counts towards your verdict once its dates are complete, and there is no submit-for-review stage
  • Tap any role on your passport or Home to see which credentials make it compliant and what is outstanding, named per state where the rule is state-specific
  • One Credentials card holds everything: each row carries its history, who checked it and when, and Replace, Update details and Delete on the row
  • Three badge words on every screen, Reviewed, Verified, and Verified and monitored, grey until someone has looked; every badge opens an explanation
  • Onboarding is folded into the passport wizard: one guided flow from your details to your credentials, with a workplace's sector, role and state pre-ticked when they invited you
  • Claim a record a workplace holds about you: sign up with any email, verify your identity, and the record joins your passport on its own
  • The join is the passport: a claimed record builds your sectors, roles and states, and the passport page lists exactly what would show you as Compliant to that workplace
  • Records a workplace holds about you stay off your own passport until you adopt them, and an organisation's several services ask once, on one sheet
  • Kooka AI is open from your first sign-in, and it says plainly what leaves Australia; identity, police, health and screening data never do
  • Kooka AI credit packs cost the same on the web, the App Store and Google Play, GST included
  • Face ID or fingerprint is offered once after sign-in; the iPhone app has a frosted tab bar that shrinks as you scroll
  • Forms explain themselves: errors appear at the top and scroll into view, and buttons stay enabled and say what is missing
  • Find a workplace with one search-first pattern everywhere, with logos, group membership and a sort by your current location
  • A first aid certificate covers CPR for 12 months from issue in every sector; a certificate issued or expiring today is accepted
  • Your Koora ID sits on your passport: it never changes and is what you quote to support
  • Block a whole service, covering every current and future staff member of it
  • You are emailed 30, 7 and 0 days before a workplace-held record of yours expires
  • Delete your account from any sign-in method; it names each organisation with access and what is kept, and restoring inside 30 days brings your connections back

For providers

  • The workforce import, rebuilt: Your file, Match your data, Your records, Audit, Cost and send, with the audit run before you send
  • Typed records count where the number is the checkable evidence (AHPRA, WWCC, teacher registration, NDIS clearance); where the document is the evidence, attach it, and the row says so until you do
  • Records you import from another system are treated as already reviewed, and they stay your organisation's even for a worker who already holds a Career Passport
  • Cost and send is itemised: the free five, existing workers with complete records at half price for year one, the standard rate, GST and the exact charge date
  • Every worker you track carries a verdict on the records you hold, claimed or not, with a small badge naming the connection state
  • One credentials list per worker: each record says what was done, by whom and when; your own sighting is your organisation's verdict, never Koora's review
  • Review evidence with Approve, Approve with edits or Decline, one decision per credential, with corrections carried through the worker's record
  • The Compliance queue is the first tab on Workforce and takes a slot on Home: review, sighting, missing details and ready, in one place
  • A workplace register check reads Verified by your organisation with the date; a document sighting reads Reviewed by the person who did it
  • Police check requirement is one setting at both organisation and service level: who it applies to and how recent it must be
  • Tracked roles belong to the organisation, so a change applies at every service; tracked states stay per service
  • Requesting passport access shows one complete organisation quote before you pick services, and a plain invitation needs no legal name or date of birth
  • When a worker stops sharing, tracking continues; stop or resume tracking from Workforce or Billing with an exact quote
  • Organisation mode: org-first onboarding, claim several services with one evidence bundle, one Pro plan across every service, Crew as one organisation-wide control
  • Billing has one Cost card: expected cost each month, the next Australian 1st and what it collects, the next three sweeps, and the card on file
  • HR sync file channel: a scheduled roster export from any HR system lands in Koora for an admin to review in the import wizard; nothing imports on its own
  • Expiry warnings reach records your organisation supplied at 90, 60, 30, 7 and 0 days
  • Feedback about a worker asks one sector-worded safety question under Would you recommend
  • Kooka AI compliance partner answers across every service of an organisation
  • Workforce and organisation Home load for large books instead of timing out
Fixes (18)

For workers

  • File uploads work again on iPhone and Android
  • Foreign passport holders no longer see a failed work rights check; affected workers were repaired
  • A suburb saves as a suburb, never as the state and country alone
  • Remember me no longer signs you out minutes later, and a brief network drop on open no longer signs you out
  • Share links stop at the expiry you were shown
  • A Teacher Registration is no longer labelled as a Working with Children Check; AHPRA and NDIS badges no longer claim monitoring
  • A nurse's own role sheet no longer asks for first aid
  • Adopting a current NDIS document from a workplace counts on your passport
  • Each message sends one push instead of two, and every notification opens the right screen

For providers

  • Accepting a share bills and connects the service it was sent to
  • Import completeness no longer grants the half-price year to every record, and the quote never says $0 inside the free five
  • View-only team members cannot change settings, endpoints or keys, or end a worker's access
  • One organisation cannot read another organisation's private records about the same worker
  • Search no longer shows Compliant for workers you have no connection to
  • Revoking a worker takes effect, and the ended list shows the date
  • An adopted or renewed file never wears an older review, and no second review is asked after a worker adopts
  • Abandoned checkouts no longer appear as sent requests, and a worker's police check counts once per organisation
  • Exports no longer include another service's private records or a replaced credential twice
API and webhook changes (10)
  • Changed from 25 August 2026The workforce API and webhooks are on Pro and Enterprise (formerly Enterprise only); keys can be provider-scoped, and creating a webhook endpoint needs an admin
  • Added from 25 August 2026GET /v1/roles, POST /v1/workers/credentials (file or typed record with checked_on, checked_by, check_method), GET /v1/workers/completeness, POST /v1/workers/submit
  • Added from 25 August 2026Webhook events record.claimed, record.relinquished, seat.minted, seat.ended, document.adopted, document.disputed, document.dispute_resolved, passport.worker_deleted, credential.expiring_soon, and document.review_completed (fires only with Crew)
  • Added from 31 August 2026POST /v1/workforce/sync-file (a CSV of up to 4MB that lands for wizard review); rto_name and rto_number on credentials; preferred_name on add and transfer
  • Changed from 15 September 2026Every 201 carries a warnings array (typed_record_not_sufficient, deprecated_document_type_code, declaration codes); rate limiting answers 429 with error.code rate_limited and Retry-After; a rotated key keeps working inside its grace window
  • Changed from 18 September 2026/v1/workers/add, /v1/workers/bulk and the worker.added envelope require the legal first and last name and date_of_birth (400 missing_legal_name or missing_date_of_birth)
  • Added from 21 September 2026A file record missing a required date is read for it server-side; the 201 carries details_read_from_document, details_missing or details_reading, and the events credential.details_read and credential.details_missing follow
  • Changed from 22 September 2026reviewed_by_organisation defaults to true; check_method document means a reviewed record; re-sending a typed credential needs update: true or answers 409 credential_exists; add, remove and transfer are atomic with X-Idempotency-Key
  • Removed from 22 September 2026409 worker_claimed on credential writes: your records stay yours whoever the worker is, and a claimed worker resolves by the record's email key
  • Changed from 12 September 2026passport.compliant and passport.non_compliant carry the engine's verdict for what each provider tracks; private, loopback and metadata webhook destinations are refused