On 8 July 2026, users were unable to sign in to Iris. The sign-in page looped without completing, affecting all users attempting to log in. Sign-in was restored at 00:42 UTC, within 40 minutes of the first report reaching us at 00:04 UTC.
We deployed an upgrade to a core authentication library to remediate a security vulnerability. The upgrade carried a documented breaking change for a specific legacy authentication setting. Our test environment used the modern setting and passed all checks, but our production environment was still on the legacy setting, a configuration difference dating back to when Iris was originally built that had gone unnoticed. When the upgrade reached production, sign-in broke.
The first report reached us at 00:04 UTC. An incident was declared at 00:25 UTC, the root cause was identified within a minute, and a rollback was deployed, restoring sign-in at 00:42 UTC.
Sign-in to Iris was restored within 40 minutes of the first report.
The underlying cause was configuration drift between our test and production environments. That has been corrected: both environments now use the same modern authentication setting, and the security upgrade was safely redeployed the following day with no regressions. Two further follow-up actions have come out of the review: verifying production configuration directly against documented breaking changes before upgrades of this kind are released, rather than relying on the test environment as a proxy, and adding a manual review step immediately after high-impact production deployments that land during peak usage hours.