Delivery record
What's shipped
Everything that reached customers, with the date it reached them — including the fixes. A roadmap only shows intent; this is the record.
What we're building next2026 · Q3
- HR
Review assignments
Three review systems had grown up separately — whole-organisation review cycles, schedule-generated review instances, and duty-based scoring — with no way to say who a given review was actually for. Assignments give each of the three a target without forcing them into one model, so a review cycle can now be aimed at a department, a branch or a named list rather than fanning out to everybody.
- Payroll
Payroll approval, corrected
Managers no longer appear in the payroll approval chain. They had a permission they could never meaningfully use, which made the approval queue misleading about who was actually holding a pay run up.
- Platform
Email delivery through Resend
Transactional email — payslip notifications, leave decisions, document requests, onboarding reminders — now sends through a dedicated delivery provider with retries, a suppression list and per-message logging. Auth email (confirmation, password reset, magic links) was moved onto configured SMTP at the same time. Before this, signup confirmation links pointed at a development address.
- Platform
Production and UAT environments
Two environments with separate databases: production, and a preview environment running on demo data where every change is checked before it reaches customers. Changes only ever move forward — from preview to production, never the other way.
- Platform
v1.0.0 — first production deployment
The first production release, on its own database. Milestone entry: everything below this line was built before the product was live.
- Platform
Gate parity — every page works for the roles it offers
Eleven pages offered themselves to roles that then could not use them, and a further set gated a whole page where only one panel needed restricting. Both are closed: if a role is shown a destination, that role can use it.
Alongside it, work-from-home approvals were tightened so that switching the policy off stops pending approvals rather than only new requests, and branch-scoped endpoints now narrow by branch rather than widening the guard around them.
- Platform
Acting-tenant coverage
When our support and platform team work inside a customer's organisation — with the customer's permission — every part of the product now shows them that organisation consistently. Before this, one screen could show the right organisation while the next reported that no organisation was selected. An automated check now keeps every new screen in line.
- Platform
Empty states that tell the truth
Pages across employees, payslips and payroll used to display "no results" while they were still loading, and again when a query had failed. Both now say what is actually happening. A list that cannot load says so rather than looking empty.
This is the defining lesson of this codebase: three separate outages — every quiz in the learning module, the leave half of both request inboxes, and the company directory — all presented as an empty screen rather than an error, and none was noticed.
2026 · Q3 — earlier
- HR
Documents module — the learning module's twin defect
The same class of defect found in the learning module was present in documents, and is closed.
- HR
Guided onboarding and the policy library
A seven-segment guided setup for a new organisation, where completion is computed from your actual data rather than stored when somebody clicks "done". Delete every leave type and the payroll segment reopens and says so. A required segment cannot be skipped, and readiness is re-checked server-side at the end.
With it: a policy library where an acknowledgement is of a specific version, only the person themselves can sign, and a signed policy is retired rather than deleted so the signatures survive.
- HR
Learning — courses, lessons and quizzes
Courses can carry ordered lessons — rich text, video, documents, external links — in private storage, with per-learner progress, a course builder, a learner player and roster progress for administrators. Existing courses were untouched: every course that already existed kept behaving exactly as it did.
- Trust & privacy
Security and performance audit
A full review of access control and performance. Public forms — sign-up, careers applications, contact — are now rate limited to protect them from abuse, and every automated integration endpoint answers errors with a reference number rather than internal detail.
Confirmed in the same review: every table of customer data is protected by database-level access rules, every employee listing is confined to its own organisation, and no credential is ever sent to the browser.
- Platform
Reachability — every destination leads somewhere
A page's permission could be written in four places that were free to disagree, and three of them had no test. 36 dead navigation links, 11 pages whose inline check contradicted their own menu row, and 23 destinations that rendered for anyone with the URL. All converged onto a single permission key per page, and 48 unreachable server functions were either connected to a surface or removed.
Before v1.0.0
Waves 1 through 4 — tenant isolation and data correctness, platform hygiene and the QA harness, module completion, and the information-architecture rework that produced the current navigation. Attendance was rebuilt in this period: punches now take their time from the moment the button is pressed rather than after the server finishes its checks, geofencing reads GPS accuracy instead of discarding it, and refusals leave an audit trail that the person refused cannot suppress.