This is our first published snapshot - we're not backfilling a version history we can't verify. From here, entries get added as real changes ship.
Version 1.8.98
Native hash href navigation for settings links
Business Module and CRM settings Open links use hash href anchors only; no routerLink or click interceptors.
Application Settings
Linked settings and module settings are plain hash anchors with returnTo preserved.
Fix actions still use Router.navigate with segmented commands.
CRM
Settings destination cards and Settings menu use hash hrefs.
Version 1.8.97
Hash-routing link navigation repair
Business Module and CRM settings links use routerLink plus Router.navigate with queryParams instead of navigateByUrl on combined URLs.
Application Settings
Linked settings and Open module settings match Run setup wizard routerLink bindings.
Fix actions use Router.navigate with queryParams, not navigateByUrl on serialized query strings.
CRM
Settings destination cards and overflow menu entries navigate with Router.navigate([path], { queryParams }).
Version 1.8.96
Business Module settings link navigation
Linked settings and module settings Open links route reliably under hash routing via navigateByUrl.
Application Settings
Linked settings and Open module settings use hash hrefs with navigateByUrl; fixes 1.8.94 routerLink no-ops.
Module detail Fix actions use the same route-target navigation helper.
Version 1.8.95
CRM module Linked settings hash navigation
Linked settings Open links navigate via hash hrefs; route targets use single-path router commands.
Application Settings
Business Module Linked settings use hash hrefs without a broken click handler; returnTo is preserved.
parseRouteTarget emits one absolute path command for hash routing parity with setup wizard and Fix actions.
Version 1.8.94
CRM module Linked Settings router links
Module detail Linked Settings Open links use Angular router links with query params for reliable tab deep links.
CRM
Linked Settings on Business Module detail pages navigate with routerLink and queryParams instead of hash href workarounds.
Version 1.8.93
Quote Engine P1 integrity and export audit
Lifecycle uniqueness, issue and party/GST guards, decision ledger, export artifact audit trail, and pilot library qualification on the Quote Engine API.
Quote Engine
One draft and one issued revision per quote with compare-and-swap lifecycle writes.
Unified artifact export audit for proposal, proforma, cut-list and drawing outputs.
Pilot qualification metadata on catalogue rows with buildable planning anchors.
Version 1.8.92
CRM settings navigation
CRM Settings cards and sidebar links open the right tab; child settings routes match; Back respects returnTo.
CRM
Settings destination cards and menu links split query params so tab deep links work.
Picklist section tabs are router links; the settings menu navigates without losing the click to a closing details menu.
Lead assignment and other child settings routes no longer collide with the parent settings path.
Platform chrome
Back button uses shared returnTo handling and defers to the layout return bar when returnTo is present.
Version 1.8.91
CRM module settings enforcement
CRM business-module policy fields are editable on Application Settings and enforced on staff lead create and lead conversion.
Application Settings
More CRM settings controls territory scoping, lead-source defaults, manual entry and conversion rules on the module configuration page.
Manage territories links preserve returnTo when opened from module setup.
CRM
Staff lead create applies default source, required source, manual-entry block and territory scoping from module configuration.
Lead conversion honours allow-direct and require-opportunity rules before creating an opportunity.
Version 1.8.90
CRM configuration audit follow-up
Setup wizard and linked settings preserve return navigation; keyboard users can open linked settings with Enter; wizard fix actions match module detail resolution targets.
Application Settings
Run setup wizard from a module passes returnTo through the wizard and essentials territory links.
Linked Settings Open responds to Enter as well as primary click.
Wizard Fix uses the same resolution targets as the module configuration page, including Setup Center with returnTo.
Version 1.8.89
Estimate workspace and CRM configuration readiness
New estimates are built in a dedicated workspace with prospect-scoped CRM data, rich terms and templates; CRM module configuration separates required setup from optional enhancements and names every fix action.
Sales
New Estimate opens a tabbed workspace (customer and dates, line items, terms and document) instead of an inline list form.
Contacts and opportunities load for the selected prospect only; issue date and validity default on create and are snapshotted on the estimate.
Line items use grouped catalog pickers with add-below, duplicate and delete; terms use the rich-text editor, content snippets and published document templates.
Application Settings
CRM module configuration scores required Setup Center steps separately from optional service and portal work.
Blocking issues use named actions and Linked Settings carry return links; destinations show Back to CRM settings.
More CRM settings that are not enforced yet are read-only with stored-value summaries.
Version 1.8.88
Personal email verification works
The link in the personal-email verification email now opens a page that confirms the address.
HR
The Verify your personal email link opens a branded page that confirms the address at once, or explains if the link has expired or was already used. Links sent before this update need to be sent again.
Version 1.8.87
Document previews, redesigned command centers and simpler opportunities
Every report and document can be previewed before downloading, sales documents follow the new professional layouts, command centers and maps match the approved designs, and opportunities move forward from one simple stage bar.
Documents and reports
Preview any sales document, report or HR letter in the app before you download it; downloaded PDFs now always open.
Estimates, proformas, sales orders, delivery challans, receipts, tax invoices and credit notes use the new professional layouts, with customer cards, a clear tax split, totals band and signature block.
Report Format Studio previews no longer fail on long documents, and a failed preview explains why.
Command centers and maps
CRM Leads by Territory is a regional heat map on a world map, ready for markets outside India.
Prospect Companies shows company density across India with territory callouts and expansion markets, and is now in the CRM menu.
Command centers across modules follow the approved layouts.
CRM and sales
Opportunities have one clickable stage bar and a Next step card that says what to do now; mark won or lost from any stage.
Duplicate companies show in Master Data Deduplication, and the quick lead phone field is full width.
New leads load states and cities for India straight away, and a new Lead Assignment page explains who receives website leads.
Settings and integrations
Every integration has a step-by-step setup guide, and IndiaMART, TradeIndia, Justdial, Meta, WhatsApp, Google Maps, LinkedIn, Facebook, Instagram, YouTube and AWS show their own logos.
A module setup wizard walks through the business modules one at a time, and each module's default page is honoured.
Organisation settings use a step-by-step form; the Location Database lists every country; the settings tab is now Communications & File Storage.
HR
Employee addresses use a full address box with tidy country, state, city and postal code fields.
Goals & KPIs line up the performance cycle and employee filters and show governed scorecards.
Version 1.8.86
Application Settings workspace and command-center charts
Application Settings is now a guided settings workspace, command centers show real monthly trends and a shared India map, and Purchase and CRM gain new home views.
Application Settings
A guided workspace for business modules, integrations, access, branding, documents, notifications and audit, with progress read from your live configuration.
Administrators can choose, preview and publish one of six application-navigation layouts; nothing changes for users until it is published.
Command centers
CRM, Purchase, SaaS, Site Survey, Training, Knowledge Base, Library, Marketing, Accounts and Fulfilment homes plot real monthly trends; panels without a trusted source say so instead of showing zeros.
CRM, Prospect Intelligence and Site Survey show activity on a shared India region map.
CRM Command Center offers Daily Operations, Pipeline & Territory and Relationship 360 views; Prospect Intelligence is under CRM More → Insights.
Purchase home is a Purchase Command Center; its Quick Actions open the create form directly.
Everyday fixes
Quick Lead, Quick Contact, Quick Prospect Company, Verify Prospect Details and Link Existing Customer open as centred forms.
Tools → Email reads your mailbox settings correctly, letters and report previews stay white in dark mode, and search boxes no longer overlap their icon.
Version 1.8.85
Email fill, remaining shell icons, Purchase Command Center and print paper
Tools → Email and other tool workspaces fill the routed column, remaining shell chrome uses mapped Material icons with wrapping labels, and Pilot also ships the Purchase Command Center and print-paper tokens already on main.
Shell and tools
Tools → Email fills page-content; an unconfigured mailbox uses the existing RBAC settings getters and a 44px control to Profile → Email.
Community, Support Conversations and To-Do stretch with the shell instead of 100vh caps.
Remaining shell chrome uses mapped Material Design tokens on app-platform-icon, and Tools and rail labels wrap instead of truncating.
Command centers and paper
Purchase home is a Sales-pattern Command Center from ordinary documents, without enabling inventory procurement v1.
Quick Actions menus portal onto document.body. Print-paper tokens stay white in both themes while chrome follows the theme.
Verification
Passes 3,118 frontend specifications plus Support 45/45 and shared UI audits, npx ng build platform, and API syntax lint across 4,497 files. Isolated Puppeteer PDF validation passed with the provisioned Chrome.
Version 1.8.84
HR evidence, search-field alignment and menus that close
Pilot HR onboarding and performance collectors now fail closed on missing evidence, search dropdowns line up with the text boxes beside them, and module More menus close when you click away.
HR and performance measurement
Hardens onboarding sign-off so required uploads and live prerequisites cannot be completed from stale flags.
Activates canonical KPI collectors at calculator v2, including pinned deliverable evidence, configured furniture stages, employee-compliance dates, manufacturing manifest timing, purchase SLA holidays and vendor-bill match snapshots.
Leaves onboarding/probation timing planned and seven composite keys blocked pending definition; existing Pilot sources remain classified and score-ineligible.
Forms and navigation
Search dropdowns keep the typed text, placeholder and loading hourglass on one line, and floating labels no longer collide with the search box.
Dropdowns and text boxes in form and list toolbars share the same 44px height and inner spacing; location pickers open above surrounding panels.
The module More and Settings menus, including the CRM workspace, close on a click outside the menu, on Escape and on navigation.
Verification
Passes focused HR 102/102, API platform 11,163/11,165 (one local pdftotext font-extraction check that needs the provisioned extractor), API syntax lint across 4,491 files, 3,092 frontend specifications with the sizing, drawer, tab and view-switcher audits, and ng build platform. Quote Engine is unchanged.
Version 1.8.83
Match approved command-center icon language
Pilot module homes now use the approved contextual icon treatment across KPI cards, section views and analytics panels instead of generic or text-only card chrome.
Visual fidelity
Adds contextual semantic icon wells to the twenty module homes and their command-center section cards while preserving each approved hierarchy and authoritative data source.
Assigns an explicit relevant icon to every shared KPI card, including Inventory, HR governance, performance and branding-preview cards; generic fallback-only cards are rejected by the regression gate.
Passes 3,091 frontend specifications, Support 45/45, sizing, overlay, tab and view-switcher audits, icon coverage and the production Angular build.
Version 1.8.82
Restore complete overview command centers
Pilot module homes now expose their approved operational hierarchy, certified queues and honest unavailable states instead of sparse, fragmented or duplicate navigation views.
Command-center composition
Restores Finance, Purchase, SaaS, Training, Digital Experience, Work, Manufacturing, Assets, Fulfilment, Projects and Application Settings overview composition.
Uses existing certified queues, site health, search, publication, portfolio, capacity, asset, project and manufacturing aggregates while labeling unsupported series explicitly unavailable.
Removes duplicate local module navigation and obsolete role-tier fragmentation so the shared icon-led module tabs remain the single navigation authority.
Verification
Passes 3,089 frontend specifications, Support 45/45, sizing, overlay, tab and view-switcher audits, the production Angular build and 11 focused backend aggregate tests.
Version 1.8.81
Close authenticated UAT fidelity gaps
Pilot navigation, command centers, governed CRM capture and API request handling now match the approved app-wide UAT contract under sustained authenticated use.
Command centers and navigation
Restores the approved Marketing, HR and Sales panel hierarchy while labeling unsupported trends and activity sources explicitly unavailable.
Removes duplicate Library, Site Survey and Training module tabs, preserves workflow tabs, and assigns Project and Site Survey record routes to their correct shell destinations.
Adds permission-aware launcher fallbacks and exact Marketing, Training and Knowledge Base destination gates so scoped users land on a route they can use.
CRM, accessibility and reliability
Uses the scoped governed territory catalogue in full and Quick Contact capture without requiring Territory administration access.
Makes the Calendar follow-up workspace modal to assistive technology, traps keyboard focus while modal and keeps the desktop read-only popover non-modal.
Removes duplicate global rate-limiter counting for versioned API requests, preventing valid data-heavy ERP sessions from reaching the configured limit at half its intended allowance.
Version 1.8.80
Complete app-wide UAT fidelity
The remaining approved module, CRM, territory, location, return-navigation, report and onboarding requirements are reconciled for Pilot validation.
Module and CRM fidelity
Reconciles all twenty approved launcher homes and their shared inner-page contracts with full-width command centers, icon-led tabs, 44 pixel controls and no module side navigation.
Keeps Karam assigned across all seven active India territories, preserves Nepal and Middle East as planned territories, and stabilizes governed territory selection in Prospect Pool.
Adds authoritative City and State columns to the remaining applicable CRM, Party, vendor, warehouse, plant and business-unit tables.
Connected work and evidence
Restores search, filter, pagination, scroll and local view state when users return from connected Party, Contact and onboarding workspaces.
Extends the approved report contract across Estimate, Proforma, Sales Order, Delivery Challan, Receipt, Credit Note and Tax Invoice, including live side-pane branding preview refresh.
Records email-provider submission, acceptance or rejection evidence for onboarding invitations without persisting provider payloads or message bodies.
Version 1.8.79
Complete module overview command centers
Inventory, Knowledge Base, Library and Site Survey now open dedicated, full-width command centers with authoritative module-wide data and the approved analytical composition.
Overview and analytics
Promotes Inventory Intelligence to the Inventory home while preserving its KPI strip, charts, ABC by FSN matrix, priority actions, working-capital analytics and specialist operational dashboards.
Adds dedicated Knowledge Base and Library command centers with repository-wide lifecycle totals, publication workflow, search or adoption evidence, governed queues and explicit unavailable states for unsupported measures.
Adds a business-unit and permission-scoped Site Survey aggregate with real readiness, exception, portfolio, trend and recent-survey panels while keeping the survey register as a separate workspace.
Navigation and controls
Makes each command center the canonical launcher destination and keeps Articles, Seed Pack Repository, Survey Cases and Item Master as separate icon-led tabs.
Keeps Library and Inventory bounded actions in centered modals with 44 pixel controls and no rendered side drawers.
Preserves semantic tokens, full-width routed canvases, keyboard navigation and light/dark responsive behavior from the approved resource designs.
Version 1.8.78
Complete Week calendar item list
Week view now exposes the same complete, actionable calendar-item treatment as Month and Day, grouped by date without capping or hiding records.
Calendar
Groups the visible week into seven named day lists with item counts, time, title, source, amount and status.
Keeps every item connected to the shared event and follow-up dialog, while each day heading opens its detailed Day ledger.
Stacks the seven groups on mobile and keeps the desktop calendar inside the full-width module canvas without document overflow.
Version 1.8.77
Calendar follow-up completion
CRM day-calendar entries now open the approved communication-notes and next-follow-up form for both lead and deal commitments, closing the final live Pilot mismatch found during the app-wide acceptance replay.
CRM calendar
Makes direct Lead and Deal next-action entries expose the same compact follow-up editor as scheduled CRM activities.
Records the completed communication in the activity timeline and replaces the canonical next action with the selected future date, so the calendar advances instead of retaining the old commitment.
Keeps Edit Lead or Open Source as a separate action and preserves the approved Day ledger, full-width module canvas and shared navigation contract.
Version 1.8.76
Complete approved module UI fidelity
The approved app-wide tabbed interface now reaches the operational pages, calendars, shared quick actions, location-aware CRM records and full-width command centers required for Pilot acceptance.
Navigation and workspaces
Removes the obsolete desktop hamburger and keeps module navigation in icon-led horizontal tabs with authorized Settings actions and no module side drawers.
Makes command centers, overview pages, launcher destinations and Application Settings inner pages use the available routed canvas across the approved modules.
Adds the approved CRM Calendar placement and day-detail controls while retaining the compact notes and next-follow-up action with a separate Edit Lead route.
CRM and connected records
Completes Quick Lead and Quick Contact modal patterns, contextual Back navigation, and shared Party Directory entry points across CRM, Sales, Purchase, Accounts, Inventory and SaaS.
Shows City and State as separate Lead list values and repairs all nine territory definitions using governed country, state and city references.
Adds employee-owned Email with private mailbox settings, sanitized message rendering, owner-scoped drafts and outbox delivery records.
Version 1.8.75
Approved command-center visual fidelity
Operational overviews now match the approved resource hierarchy with centered workspaces, prominent semantic KPI icons, denser ledgers and reliable module-tab ownership.
Command centers
Applies the approved large-icon KPI composition and readable desktop canvas to CRM, Sales, Purchase, Finance, Inventory, Marketing, SaaS, Assets, Fulfilment, Support, Training and Digital Experience.
Matches the approved V2 Projects, Work Management and Manufacturing hierarchy with four execution-status cards, dense task ledgers, icon-led gate readiness and blocking-issue panels.
Keeps unsupported metrics explicitly unavailable and preserves existing routes, permissions, actions and real-data boundaries.
Navigation and settings
Prevents a previous module's tab strip from remaining visible after navigation and assigns control-panel pages to Application Settings consistently.
Updates Application Settings launchers with the approved constrained layout, larger semantic icons, compact card density and responsive summary counters.
Adds icon-led, keyboard-sized Inventory Intelligence tabs while retaining the application-wide no-side-navigation rule.
Version 1.8.74
Simpler module workspaces and resilient CRM reads
Module workspaces now use the approved tabbed navigation and consistent controls, while legacy imported CRM references no longer break sales command-center views.
Navigation and workspaces
Keeps the Sales More menu outside the scrolling tab strip so every destination remains visible and keyboard accessible.
Removes standalone Process Flow launchers and record links while retaining useful progress context inside operational records.
Adds the approved command-center ledgers, settings launchers, icons, contextual Back actions and full-page record patterns across the in-scope modules.
CRM and form reliability
Allows CRM overview, forecast, salesperson-performance and follow-up reads to display imported records with legacy owner or account tokens without an invalid-ID failure.
Continues to resolve valid employee and account references normally and leaves create and update validation unchanged.
Applies the shared 44-pixel control contract to list toolbars and primary forms and narrows the phone country selector to the approved compact width.
Version 1.8.73
Restore Support Chat inboxes on Pilot
Support Chat inbox aggregation now uses the MongoDB stage supported by the deployed Pilot server while preserving the same unread and activity projections.
Support operations
Restores both staff and public chat inbox list endpoints, including full-name search, on the Pilot MongoDB version.
Preserves requester scope, latest-message projection, unread totals, recent-activity ordering and the existing bounded inbox window.
Adds an explicit compatibility regression for both inbox pipelines without changing stored conversations.
Version 1.8.72
Private Vault access for founders and proprietors
Founders and sole proprietors can now use the same isolated, email-verified private Vault as eligible directors without being treated as employee-directors for payroll.
Governed access
Adds a legal governance capacity, effective date, approval reference and server-recorded change history to the employee Account & Access record.
Recognizes a governed Founder / Proprietor capacity while continuing to require a verified corporate work email and a completed email-migration review.
Keeps Vault eligibility separate from job titles, payroll classification and application roles; only the dedicated governance authority can change it, and superadmin or a founder-named role alone still grants no private access.
Pilot data protection
Uses the separate Vault database and encryption-key contract already built into the module; each eligible principal receives an independent private Vault.
Makes guarded cross-module UAT cleanup compatible with the Pilot MongoDB version while retaining exact document and concurrent-change protection.
Version 1.8.71
Correct cross-module Pilot stock balances
The Pilot UAT graph now keeps its opening stock in one warehouse and presents the issue-adjusted ledger balance as the current quantity.
Inventory evidence
Prevents the startup opening-stock migrator from duplicating the synthetic five-unit opening balance into the default warehouse.
Preserves the immutable ledger's append order so opening five, receipt twenty and issue ten resolve to fifteen units in the Gurugram Pilot warehouse.
Exercises the real startup seed and stock-balance service after graph insertion to verify one warehouse, fifteen units and the issue as the latest movement.
Version 1.8.70
Memory-safe cross-module Pilot data protection
Pilot UAT seed snapshots now protect the complete database against drift without loading every business record into memory.
Pilot data safety
Keeps complete before images for every collection the guarded cross-module pack can change, including its ownership manifest.
Fingerprints every Pilot collection so unrelated writes, collection additions, missing scope and tampered snapshot content stop the operation before insertion.
Retains verification support for existing version-one snapshots while issuing bounded-memory version-two snapshots for the CRM-to-accounting UAT graph.
Version 1.8.69
Billing-backed performance and managerial notice correction
Revenue KPIs now rely on posted billing evidence, and managerial employment drafts can be corrected through a crash-safe, Pilot-only policy repair.
Performance evidence
Calculates owned won revenue from posted invoice taxable value less posted credit notes instead of editable CRM opportunity value.
Requires accepted Estimate or Quotation lineage through the Sales Order to an employee-owned won Deal, with governed currency, account and business-unit validation.
Classifies retained Pilot invoices and credit notes as pre-go-live, score-ineligible evidence before operational KPI scoring is enabled.
Employment policy correction
Uses the grade-aware notice-period authority for reconstructed offers and employment documents, giving L4 and higher grades a 60-day default while preserving explicit negotiated terms.
Adds a Pilot-only correction for Rajni Sehgal's untouched draft offer, appointment and confirmation snapshots with journalled before images, compare-and-set writes, resumable recovery and safe rollback.
Pins the operator to the exact Pilot database, environment, host directory and stopped Pilot process, and requires a verified backup before any write.
Version 1.8.68
Auditable HR decisions and governed promotion review
Salary-advance and Fleet decisions now require immutable evidence, and Pilot-to-Production HR conflicts can be resolved only through an exact reviewed, rollback-capable merge plan.
Decision evidence
Records salary-advance approval and rejection with the canonical checker, request identity, status transition and decision reason.
Gives Fleet approval and rejection one stable audit receipt so retries and concurrent requests cannot duplicate the evidence.
Restores a salary advance to pending if its required audit cannot be written; Fleet and TA decisions retain hidden repair authority only inside the configured security-audit retention window, honor legal hold, and leave a PII-free tombstone so expired evidence cannot be recreated by retry.
Production promotion controls
Binds each reviewed merge choice to the exact encrypted artifact, Pilot source, Production target, source row, target row and their full-document digests.
Supports explicit Production reuse, safe rekeyed insert and complete field-by-field HR Settings resolution. Generic Pilot-authoritative replacement requires a future domain-aware workflow.
Rejects stale, partial, ambiguous or conflicting reviews. The composed HR Settings singleton must pass its Mongoose schema and is protected with a before image, compare-and-set apply, resumable journal and compare-and-set rollback. No HR data is promoted until the owner supplies the evidence-backed decisions and separately authorizes the Production operation.
Version 1.8.67
Production launch safety and governed KPI actuals
Managed performance actuals now stay evidence-backed, HR promotion previews verify typed dependencies and role authority, and the Production deploy path has stronger isolation and identity checks.
Performance governance
Blocks direct actual edits for every KPI carrying a managed measurement key across both legacy write endpoints.
Keeps operational reconciliation, independent approval and unmanaged legacy KPI history behavior intact.
Records explicit implementation modes for the Propulsive performance measures so unsupported indicators remain visible without fabricated scores.
HR promotion safety
Adds a checksum-backed schema-v2 reference catalogue for Pilot Role and Tenant dependencies and maps them by reviewed immutable identities.
Compares role permissions and governance flags, models HR Settings as a singleton and prevents an ObjectId in the wrong collection from satisfying a dependency.
Keeps Production import blocked while missing roles, authority drift, employee collisions, keyless KPIs and dependency-aware merge decisions remain unresolved.
Adds a dry-run-first Production promotion operator that binds the encrypted artifact, reviewed plan, target database and protected snapshot, with authenticated journals, exact confirmations, crash recovery and rollback.
Release assurance
Preserves exact Quote Engine Phase 2 ancestry and the approved global UI-kit tab behavior without changing Quote Engine calculations or feature flags.
Protects nested Pilot and Staging web roots during Production backup and extract, restores explicit ownership and verifies the exact full commit in health checks.
Uses local gates and the sanctioned deployment script; Production migration, data promotion and deployment remain separately approval-gated.
Points the employee-retention settings hint to the governed `/legal/privacy` publication route while leaving publication and approval with the authorized policy owner.
Version 1.8.66
Guarded Perfex reminder reconciliation
Pilot can now retire only the exact duplicate reminders left by the legacy Perfex manifest while preserving every business record and retaining complete disposition evidence.
Exact data reconciliation
Verifies the completed checksum-matched Perfex batch, all 5,338 source identities, linked targets, Party activations and proforma payment totals; 1,225 lifecycle links resolve to 1,151 canonical histories through 74 exact Lead and Client shared records.
Retires only 347 legacy reminder rows that have exact authoritative semantic replacements and preserves the remaining 3,686 historical activities.
Preserves and verifies 694 import-lineage and KPI-exclusion references, records a disposition for all 12,950 legacy-owned records and marks the old manifest superseded by the authoritative import.
Pilot safety
Defaults to a read-only preview and requires the exact Pilot database and host identity for every operation.
Apply requires the Pilot process to be stopped, a fresh protected BSON snapshot outside the checkout, its SHA-256 checksum and a maintenance coordination reference.
Uses full-document compare-and-delete checks, blocks external references or drift, supports exact rollback and is idempotent after completion.
Simpler tabbed ERP workspaces and governed CRM data
Commercial modules now use the approved icon-led tab shell, CRM follows the prospect-first lifecycle, locations share one governed authority, and customer reports retain their approved print geometry.
Module navigation and forms
Replaces module-level side navigation with the shared horizontal tab row, grouped More menu and permission-filtered Settings action.
Adds consistent icons, semantic controls, contextual Back navigation, City and State columns, and shared Party Directory access across applicable modules.
Keeps primary records as full pages and quick lead/contact capture as centered modal actions.
CRM, territories and imported records
Preserves Contact to Lead to Opportunity to Prospect to Party boundaries, including direct/reference, upsell and cross-sell flows with Party activation only after payment.
Adds a governed Location Database beside Territories for countries, states, cities, aliases, audit history and dependency-safe duplicate merges.
Corrects the guarded Perfex plan to preserve all 96 estimates, 354 proformas, 282 linked payments and GST registrations with exact totals.
Commercial documents
Aligns estimate, proforma, order and delivery layouts with the approved color and monochrome print skeletons, margins, repeated continuation headers and branding controls.
Places proforma transactions below Amount Payable, hides unused discounts, labels applied coupon discounts and omits the rejected status ribbons.
Validation covers the complete frontend and backend gates, governed UI audits, CRM lifecycle UAT, location authority, report fidelity, data integrity and secret scanning.
Version 1.8.64
Launch-safe HR governance and performance boundaries
Onboarding, employee payments and Propulsive KPI evidence now use one governed launch boundary, with permanent Pilot scoring exclusions and an encrypted HR promotion manifest.
Onboarding and employee payments
Onboarding list, detail and completion now share one live readiness result; stale sign-off cannot conceal missing evidence or incomplete mandatory tasks.
Configured login, shift and asset tasks govern new-hire completion, while historical employee-file onboarding identifies operational steps that do not apply.
A guarded setup can create a credential-free INR employee-payments cash authority and canonical TA expense mapping while preserving valid administrator choices.
Performance and promotion safety
All 60 Propulsive KPI assignments have immutable measurement keys; the managed 2026 authority begins on 1 September and pristine pack-owned targets are prorated to four months.
Existing Pilot attendance, CRM and support source identities can be classified permanently outside KPI scoring before migration, and every current automated collector is covered by a regression guard.
The HR promotion exporter preserves BSON identities in an encrypted, checksum-backed allow-list, excludes known UAT data and reports unresolved Production dependencies before any import is considered.
Shared UI contract
Universal module tabs again use the shared keyboard directive while preserving route activation, responsive overflow and the phone More sheet.
Onboarding refreshes its derived readiness after checklist mutations and labels non-applicable steps and tasks explicitly in both list and detail views.
Version 1.8.63
Guarded standalone pay-band repair
Propulsive's approved L1-L7 pay-band corrections can now be applied safely to Pilot's standalone MongoDB with protected recovery evidence.
Pay-band authority
The Pilot repair requires a stopped application, a fresh protected snapshot, exact database identity, checksum and a matching maintenance reference before it can write.
Standalone changes use full-record compare-and-set checks, verify the complete L1-L7 authority and restore owned writes exactly after handled failures without overwriting an unexpected concurrent change.
The repair preserves every existing absolute salary limit while closing the superseded 2025 L1-L4 rows and aligning the approved 2026 monthly midpoints.
Version 1.8.62
Connected Pilot operations with governed evidence
Employee performance, fleet logging, privacy controls, the Pilot order-to-cash rehearsal and Quote Engine Phase 2 now use clearer workspaces and stronger audit evidence.
Employee and fleet workspaces
Profile now shows each employee's governed KRA and KPI plan separately from monthly operational targets, so a missing collector no longer hides the approved performance framework.
Fleet logging now opens in the full page workspace with responsive filters, unclipped dropdowns, field-level validation, fuel-proof requirements and touch-safe actions.
Attendance actions meet mobile touch-target guidance and shared list import controls align with their neighbouring filters and actions.
Audit and Pilot rehearsal
Employee privacy-retention changes record the linked employee as the canonical actor and roll back when the required immutable audit receipt cannot be stored.
A guarded synthetic Pilot pack links one canonical item and unit across CRM quotation, purchasing, warehouse stock, sales order, delivery, invoice, part payments and balanced accounting entries.
The new Pilot pack defaults to preview, refuses Production, requires a protected snapshot and maintenance window for writes, preserves existing records and blocks cleanup after external references or operator changes.
Quote Engine Phase 2
Projects, Quotes and product workspaces now share responsive lists with KPI summaries, City/State and stage filters, scoped views, quote values and phone record cards.
Universal module tabs support the tab keyboard contract and move overflow destinations into a phone More sheet, while headers wrap their actions at laptop widths.
Quote and revision responses hide cost and margin unless the reader has quotes.view_cost; quote summaries use a dedicated route and proforma tax tails print separate CGST and SGST rows.
Version 1.8.61
Completed connected employee lifecycle safeguards
Onboarding audit rows, attendance provenance, movement locks, privacy retention and final-settlement dues now remain reliable across the complete employee lifecycle.
Onboarding and lifecycle integrity
Onboarding retains and identifies archived employee audit rows, renders a truthful unavailable state for broken references, removes stale expanded actions when a relation changes and keeps archived-list reads from rewriting historical tasks.
A connected synthetic UAT journey now verifies offer approval, candidate consent, onboarding completion, Digital ID issue, resignation, clearance, final settlement, experience-letter issue and post-exit access rejection.
Final settlement includes approved unpaid INR travel and expense reimbursements plus outstanding disbursed advances, rejects claims without governed INR authority or TA bills already owned by reimbursement posting, and atomically consumes every frozen source obligation when payment is recorded.
Attendance, movement and privacy controls
Temporary move-out locks every active device until the employee completes the password-protected return flow; break and move-out starts are serialized, and recovery is restricted to the employee's exact open record.
Manual and CSV-imported attendance provenance is server-owned and cannot be forged or rewritten by an API client, while biometric imports retain their integration source and corrected punch evidence.
Privacy retention now covers security audit, AI audit, employee activity, access-event and ended-session evidence while preserving active sessions and records subject to legal hold.
Version 1.8.60
Restored the live onboarding register
The Onboarding page keeps its shared enterprise table mounted during asynchronous loading so returned employee rows render without waiting for content projection to be recreated.
Onboarding list rendering
The shared data table now uses its built-in keep-while-loading mode, so Angular mounts the employee table projection on the first render and dims it during loading.
The table retains its employee, designation, profile-submission, progress and expandable checklist content when the asynchronous request completes.
The regression check prevents a second data-table projection target from consuming the live row content, and HR Report Format Studio now labels and scopes warning, show-cause and achievement-certificate formats.
Version 1.8.59
Enforced employee access and governed HR records
Attendance breaks, inactivity locks, onboarding, Digital IDs, resignation terms and employee documents now enforce their authority at the API boundary and retain reviewable audit evidence.
Session, break and attendance enforcement
An open tea or lunch break locks every active device at the API boundary; only session inspection, logout, reauthentication, today's attendance and the guarded break-end recovery path remain available.
Ending a break requires a recent password step-up, inactivity uses persisted per-session human-action evidence across tab closure and reopening, and access-policy changes roll back when their required audit record cannot be written.
Staff Attendance expanded rows now show every recorded break punch with its start, end, planned duration and actual duration, while Employee Operations exposes the readable access-event register.
Employee lifecycle integrity
Onboarding cannot accept a missing required upload, approve an incomplete required-document checklist or complete until every required file is present and accepted.
Digital ID issue, reissue, display and QR verification fail closed for departed, deleted or unresolved employment states, even if an earlier revocation side effect was missed.
Resignation freezes the negotiated or grade-based notice-period authority already used by Employment Terms, preserving an explicit zero-day agreement and the managerial default.
Governed documents and performance evidence
Warning, show-cause and achievement-certificate issue now pins the published report definition, version, checksum, immutable compiled HTML and content hash; preview and Chromium PDF replay the same verified output.
Operational performance collection detects Pilot UAT markers in Attendance, CRM, activities and Support, and rejects synthetic facts before they can create an eligible KPI-actual proposal.
Persisted published Estimate and Proforma formats are regression-tested end to end: zero item-discount money hides the Discount column and Itemised Discount row, while positive special-discount money shows only its own summary row.
Version 1.8.58
Governed HR operations and operational KPI actuals
Offer letters, payroll payments, TA reimbursements, RACI, session controls, attendance and operational KPI actuals now share stronger authority, audit and retry guarantees.
Employment and payment authority
Offer preview, candidate preview and PDF now replay one approved Chromium report snapshot with controlled numbering, verified personal email, compensation breakup and employment-policy terms.
Payroll generation, review, approval, accrual posting, salary payout and advance funding use canonical Employee identities while retaining the authenticated login as separate provenance.
Salary payouts and TA reimbursements are idempotent, use governed account mappings and fail closed when legacy authority or required accounting dimensions do not reconcile; salary payout requires dedicated disbursement authority.
Employee operations governance
RACI activation permits one active version, records required audit evidence and displays each employee's active assignments in Profile and Employee 360.
Configurable device limits serialize simultaneous logins and support replace-oldest or block-new behavior, including employee-specific field-work exceptions.
Fleet decisions resume safely after interrupted writes, while strict attendance prevents overlapping breaks and excludes personal movement from working time.
Operational performance and Estimate accuracy
A maker/checker workspace proposes KPI actuals from attendance, CRM, service and support records, revalidates the aggregate source before approval and refreshes Home cards; attendance follows the payroll workday calendar and historical lead qualification respects the stated as-of cutoff.
Synthetic evidence remains visibly score-ineligible and cannot update KPI actuals, appraisals or incentives.
Estimate item and special discounts stay hidden unless positive persisted money exists; stale percentages and coupon codes are cleared when zero-discount records reopen.
Version 1.8.57
Focused CRM primary navigation
CRM now matches the approved compact hierarchy with six direct daily-work tabs and grouped access to every other destination.
Approved primary tabs
The sole primary row now contains Overview, Prospect Pool, Qualification, Assignments, Reports and Party Directory in that order.
Selected pages retain the shared icon, semantic color and underline treatment without a second navigation row or module sidebar.
The row stays horizontally scrollable on smaller screens while More and administrator Settings remain anchored at the right.
Complete route access
All remaining sales, activity, communication, insight, automation, data-quality, service and administration pages are grouped under More.
CRM Settings remains visible only to module administrators and each settings destination keeps its own narrower permission check.
No CRM route, follow-up workflow, contact, lead, opportunity, report or party function was removed.
Version 1.8.56
CRM tabbed workspace navigation
CRM now uses a single icon-led tab workspace across every route, with module administration kept in a permission-gated Settings area at the upper right.
One consistent CRM workspace
Overview, sales work, activities, communications, insights, service, data quality and administration are available through the same two-level tab navigation.
CRM routes no longer render the module side navigation or duplicate page-level CRM tab strips.
The active work area and page stay visibly selected while nested routes retain their existing permissions and route contracts.
Responsive and governed access
CRM Settings appears at the upper right only for users with CRM settings permission, while each settings destination keeps its narrower resource permission.
Tabs retain labels and relevant icons, meet the 44-pixel target rule, scroll safely on smaller screens and use shared light and dark theme tokens.
Mobile CRM navigation uses the app switcher and tab workspace instead of reopening a module side menu.
Version 1.8.55
CRM lifecycle and territory workspace
CRM now supports clean contact-to-customer progression, territory-scoped work, historical prospect qualification, compact capture, and the imported Perfex pilot dataset.
Simpler CRM workspace
Overview, Pipeline, Follow-ups, Leads, Contacts, Prospect Pool, Party Directory, Reports, Calendar and Territories use the shared icon-led tab navigation in desktop, mobile, light and dark themes.
Quick Lead and Quick Contact open as compact centered modals, while full create and edit forms stay in the page workspace.
Lead and contact names are normalized to readable title case, and the shared phone control keeps its country prefix compact.
Governed customer lifecycle
Contacts qualify into Leads, Leads convert into Opportunities, quoted Opportunities become Prospects, and a Party Account activates only after a recorded payment.
Direct-reference, upsell and cross-sell opportunities retain their sales motion without requiring a new lead.
Prospect organizations preserve multiple people, phone numbers, emails, websites and showroom, warehouse or factory locations with duplicate-review evidence.
Territory ownership and continuity
Nine domestic and planned international territories support city coverage and one-to-many telesales assignment.
Employee exit transfer moves owned Leads, Opportunities, Contacts and Party Accounts through an auditable handoff.
Existing-business onboarding
The guarded Perfex importer preserves customer GST registrations, contacts, Leads, items, Estimates, Proforma Invoices, payments and follow-ups with source lineage and replay safety.
Historical company data can enter the Prospect Pool without polluting active Leads or Party Accounts.
Party 360 can start or resend counterparty onboarding for both new and existing accounts.
Version 1.8.54
Auditable salary advance recovery
Salary advances now post from an approved funding account, recover only from available pay, carry unpaid balances forward, and remain traceable through payroll and employee self-service.
Funded and controlled disbursement
Advance disbursement requires a purpose-scoped active INR bank or cash account and creates an idempotent Employee Advances journal before the request becomes disbursed.
The approver cannot record the disbursement, and platform-owned advance and payroll journals cannot be reversed through the generic accounting action.
Legacy advances without posted funding evidence remain visible but cannot enter payroll until accounting reconciliation is complete.
Safe payroll recovery
Payroll allocates the oldest due advance balances only up to available net pay; zero-pay months recover nothing and unpaid balances remain due for a later month.
Each payslip freezes its exact advance, schedule entry, recovered amount and disbursement reference, while the calculation manifest detects later disbursement or schedule changes.
Approval claims are concurrency-safe, interrupted locks reuse the verified posted journal, and retry refuses payroll values that no longer match its posting snapshot.
Payroll visibility
Payroll administrators see salary-advance recovery in run totals, expanded payslip detail, reports and compensation-protected CSV exports.
Employees can expand their own salary slips to review earnings, deductions, net pay and the advance recovery references included in that month.
The advance register shows scheduled, partial and completed instalments with recovered and remaining amounts plus payroll history.
Accounting journal boundary
Manual journal endpoints accept only user-owned accounting fields and reject attempts to supply platform posting identity, control-account authority or internal idempotency values.
Quick post saves one draft and then invokes the separately permissioned posting action with the returned journal identifier.
If posting fails after the draft is saved, the journal remains visible for a safe retry instead of creating a duplicate entry.
Version 1.8.53
Clearer sales and purchase reports
Commercial terms, addresses and payment details are easier to read across sales and purchase documents.
Report formatting
Commercial terms and notes use full-width rows to reduce unnecessary pages.
Customer, Bill To, Ship To, delivery and similar details use aligned rows with hidden table borders.
Proforma invoices have a wider receiving-bank section, payment status below the signature and a payment QR code when valid UPI details are configured.
Continuation pages retain their top margin.
Version 1.8.52
Explicit Estimate discount authoring
Estimate authors now add itemised and special discounts explicitly, while zero-discount records keep those controls and report fields hidden.
Estimate discount controls
New Estimates start without an item-discount column or special-discount fields; each area appears only after its named Add action.
Removing an item or special discount clears the related percentages, amounts and coupon code so hidden values cannot alter the saved total.
Editing a discounted Estimate automatically restores the relevant controls from positive persisted discount values.
Governed PDF configuration
The Estimates toolbar now opens the Report Format Studio used by the live Estimate and Proforma PDF renderer.
The former legacy customizer and block-editor links no longer imply control over generated Estimate PDFs.
Version 1.8.51
Employee salary advances and live access controls
Employees can open a focused salary-advance workspace from their profile, while HR device and inactivity policies now reach already-open sessions safely.
Employee salary advances
The Employee Profile salary-advance card now opens a focused self-service request and tracking workspace.
Employees see only their own advance history, with validated amount, reason, instalment and recovery-period fields.
HR retains the permission-controlled full register, approval and disbursement workflow, and unsupported register scopes are rejected.
Live session governance
Changes to an employee's inactivity and lock policy reach an already-open ERP session within the policy refresh window.
Policy and attendance refreshes do not overlap on slow networks, and a temporary network failure cannot silently clear a known lock.
Signing out resets the local inactivity clock before another employee uses the same browser.
Version 1.8.50
Accurate sales-estimate discounts after navigation
The Sales estimate detail now reloads the selected record on every route change, so itemised and special discounts from a prior estimate cannot remain visible on a zero-discount estimate.
Estimate discount integrity
Changing directly between Sales estimate records clears the previous record while the new estimate loads.
Discount, Itemised Discount and Special Discount visibility is recalculated only from the newly selected estimate.
A slower response from a previously selected Sales estimate cannot overwrite the current record or restore its discount fields.
Version 1.8.49
Reliable estimate-to-estimate navigation
Estimate details now reload the selected record whenever its route changes, preventing commercial columns and totals from a prior estimate from remaining on screen.
Estimate detail integrity
Changing directly between estimate records reloads the new estimate instead of retaining the prior record under the new URL.
Itemised Discount and Special Discount visibility is recalculated from the selected estimate after every route change.
Slower responses from a previously selected estimate cannot overwrite the current estimate detail screen.
Version 1.8.48
Accurate commercial-report discounts and payment history
Estimate and Proforma outputs hide unapplied discounts, render authored terms cleanly, and present part payments as a complete final audit table.
Sales document integrity
Estimate, Proforma, Tax Invoice and Sales Order discount columns follow positive persisted item-discount amounts, so zero discounts and stale percentage-only values remain hidden.
Special Discount rows remain conditional on a positive finite persisted amount, including coupon-only, cleared-discount and invalid imported records.
Customer-authored terms, notes, instructions and proposal conditions render as sanitized rich text instead of visible HTML tags.
Legacy HTML in plain addresses and item descriptions becomes readable text across sales reports.
A partial or split Proforma payment renders a final Payment History table with receipt/reference, mode, date, amount, cumulative paid and balance.
Version 1.8.47
Reliable HR travel-proof links
Pilot TA receipts now resolve against one valid public origin even when the configured browser allowlist contains several comma-separated URLs.
HR reimbursement evidence
New TA evidence uploads use the first configured client origin instead of treating the complete CORS allowlist as a hostname.
Reapplying the reversible HR UAT pack repairs only manifest-owned TA proof links from their governed upload records, preserving bills, approvals and files.
Version 1.8.46
Responsive employment-document register
Employment Documents keeps its heading and guidance readable at phone widths while actions wrap into their own row.
Mobile HR
The Back and New Document actions no longer compress the page title and description into a narrow column on mobile screens.
The document table remains contained in its horizontal scroll region without creating page-level overflow.
Version 1.8.45
Truthful legacy confirmation reconstruction
Historical probation metadata can prepare a confirmation draft while a missing canonical Employment History event remains visibly blocked for independent resolution.
Employment record integrity
Rajni Sehgal's existing probation metadata now prepares a pending-review confirmation draft without treating the legacy self-recorded action as independent approval.
The pilot pack reports confirmation-authority gaps separately from employees whose probation decision is entirely missing.
A blocked confirmation draft cannot be submitted until HR records the authoritative Employment History decision through a valid independent process.
Version 1.8.44
Governed employment documents and employee-file history
HR can reconstruct, approve, issue and acknowledge appointment letters, probation confirmations and professional-service agreements with controlled numbers and immutable issued records.
Employment document governance
Added a maker/checker register for appointment letters, probation confirmation letters and fixed-monthly professional-service agreements.
Historical reconstructions require verified evidence and source references; confirmation letters also require an authoritative confirmation event in employment history.
Approval freezes the employee, role and salary snapshot. Issuance uses a published report format, assigns a controlled document number and stores the rendered PDF for audit.
Employee 360 shows controlled employment documents separately from supporting attachments and opens issued PDFs through authenticated access.
Pilot preparation
Added published enterprise formats for appointment, probation-confirmation and professional-service documents, including compensation breakup, increment policy and information-security duties.
Added a reversible pilot pack that prepares seven appointment drafts, Rajni Sehgal's evidence-backed confirmation draft and two professional-service agreement drafts without approving, issuing, emailing or inferring consent.
Version 1.8.43
Reports without ribbons and corrected branding previews
All report ribbons are removed. Status appears as plain document metadata, and branding previews open at the top with accurate page sizing.
Report branding
Removed ribbons from all generated reports and previews, including older published formats. Headers use their full available width.
One-page previews no longer allocate a second blank page when the report includes a footer.
Changing the report or branding resets the preview pane to the document header.
Commercial samples reconcile item discounts, special discount, GST, amount in words and recorded sample transactions.
Version 1.8.42
Approved commercial reports and usable branding previews
Commercial documents follow the approved report skeletons with printable corner ribbons, consistent branding, safe continuation pages, and a responsive preview. Party Directory and Customer 360 now expose onboarding email actions.
Commercial reports
Estimate, Proforma Invoice, Sales Order, Delivery Challan, Receipt, Credit Note and Tax Invoice follow their approved document-specific layouts in colour and monochrome.
Corner status ribbons remain clear of the company and title. Measured pagination preserves margins, repeats table headings and keeps footer space on every page.
Proforma transactions use gray headings below Amount Payable and before terms. Item and special discounts preserve persisted-money and coupon-provenance rules.
Estimate downloads now use the selected governed report definition instead of a separate legacy layout.
Branding and Party 360
Theme branding previews the published report with unsaved header, footer, font and watermark choices, fitted to the side pane width.
Report Format editor controls stay within their panels at narrow widths.
Party Directory and Customer 360 offer onboarding for new and existing parties, with prefilled recipients, confirmation and keyboard-accessible dialogs.
Integrated HR release
Retains the governed disciplinary and recognition workflows, KPI proposal evidence, canonical actor permissions and discount integrity corrections delivered in 1.8.41.
Version 1.8.41
Governed employee records and commercial discount integrity
HR can issue controlled disciplinary and recognition documents, employees can see proposal-only KPI evidence on Home, and customer reports show discount columns only when positive persisted discount money exists.
Employee discipline and recognition
Warning and show-cause cases now follow evidence, maker-checker approval, controlled document numbering, immutable issue snapshots, acknowledgement, response, closure and audit controls.
Issued warning and show-cause letters use the governed report engine and preserve the employee identity approved at issue time.
Top Employee, Star Performer and custom achievement certificates support evidence, citations, approval, controlled numbering, immutable issued content, acknowledgement, revocation and Employee 360 visibility.
Performance and employee-file evidence
Home KRA and KPI cards surface the newest current-cycle synthetic pilot proposal evidence without presenting it as an approved score, appraisal result or incentive input.
The pilot employee-file baseline links current internal staff to structured designations while retaining the approved job descriptions, grades and employment history.
The July and August pilot evidence pack supplies 120 immutable, visibly synthetic and permanently score-ineligible KPI measurements for end-to-end review.
Estimate, proforma and invoice discounts
Accepted-estimate Proforma Invoices decide item discount-column visibility from positive persisted discount money, matching the Itemised Discount total.
Sales Invoices use the same persisted-money rule, so stale imported percentages cannot expose empty discount columns and real stored discounts cannot be hidden.
Special Discount remains hidden for zero, blank, invalid, negative or coupon-only values and appears with the normalized coupon label only for positive finite persisted money.
Version 1.8.40
Full-width commercial report preview
Branding now renders the selected commercial report skeleton in the dedicated right preview pane, at a usable scale and with the same header, discount, transaction, payment and footer structure as generated PDFs.
Report preview fidelity
Opening Report Branding replaces the generic application canvas with a full commercial document preview in the right pane instead of squeezing it into the narrow settings accordion.
The preview includes the governed Proforma header, Bill To and Ship To blocks, conditional item and coupon discounts, Amount Payable, transactions, commercial terms, payment status, receiving bank, signatory and footer.
Color and monochrome selection, the active header preset, universal font, logo controls, watermark and footer values update the same full document preview.
Version 1.8.39
Governed HR and KPI pilot foundations
New-hire probation, confidential offer delivery, structured employee designations and performance evidence now share enforceable source and approval controls without inventing production scores.
Employee-file and onboarding integrity
Normal boots no longer recreate retired demo HR catalogs when SEED_DEMO is disabled, and a guarded employee-file pack links the eight current staff records to structured designations.
Confidential offers require a verified personal address with verification time evidence, while direct employee creation, job postings and ATS conversion default new joinees to six months probation unless HR records a negotiated value.
CL request and accrual eligibility now resolve the same explicit or joining-date-derived probation window.
Performance evidence and scoring
CRM employee achievements use the current employee identity plus legitimate legacy ownership, and support evidence merges canonical CRM and legacy ticket queues once.
Lower-is-better quantitative KPIs score in the declared direction with deterministic zero handling.
Immutable measurement snapshots preserve source facts, digests, periods and maker-checker decisions; the guarded July/August UAT pack creates 120 synthetic readings that are permanently excluded from appraisal and incentive scoring.
Version 1.8.38
Preview-faithful commercial reports and print controls
Commercial PDFs now follow the approved estimate, proforma, sales-order and delivery-challan structures, with governed branding, color or monochrome output, conditional discount evidence and safe multipage pagination.
Report fidelity and payment evidence
The Professional GST Proforma keeps transactions directly below Amount Payable and before Commercial Terms and Notes, then closes with receiving-bank, payment-status and signatory details.
Item discount percentages appear only on discounted lines; special discounts remain hidden unless applied and show the stored coupon code when present.
Paid, unpaid, partially paid and cancelled states render as header ribbons, with print-safe color and monochrome palettes.
Universal branding and printing
Installation Branding controls the shared report font, header, footer, watermark, confidential marking and color mode, with a live side-pane preview.
All 16 governed report formats receive the selected branding without replacing their document-specific body structures.
A4 page boxes preserve margins and footer clearance; long sales orders and delivery challans repeat table headings and retain every line across page breaks.
Version 1.8.37
HR identity controls and estimate discount integrity
Estimate discounts now appear only when backed by positive persisted money, while HR identity, Digital ID, RACI, multi-establishment policy and employee-lifecycle controls are hardened for the pilot rollout.
Estimate and customer reports
Estimate detail and Executive Estimate output hide item discount evidence for zero, string-zero or stale percentage values, and keep totals aligned when the column is absent.
Itemised and Special Discount totals require positive persisted amounts; coupon evidence remains visible when a real special discount exists.
Commercial terms, notes and banking instructions retain safe formatting, universal branding preserves document-specific controls, and part-payment history closes the Professional GST Proforma.
HR identity and responsibility
PAN and Aadhaar capture is normalized and validated across employee, onboarding, API and model boundaries, including Aadhaar Verhoeff checksum validation.
Digital ID uses short-lived screen QR verification without printable cards or durable badge tokens, and employee profiles show their active RACI assignments within existing access boundaries.
Policy and lifecycle integrity
India State and Union Territory policy coverage resolves through the employee effective establishment and branch without treating unverified policy data as law.
Employee and Employment History writes remain transactional on replica sets and use compensating restoration on standalone pilot or local MongoDB installations.
The independently owned Quote Engine tree is unchanged from the deployed CRM and Sales base.
Version 1.8.36
Balanced proforma margins and payment placement
The Professional GST Proforma now uses even A4 page margins and keeps the receiving-bank, payment-status and signatory details as the final report block after commercial terms and notes.
Proforma page layout
All four Proforma Invoice page margins are set to 10 mm for consistent print alignment and footer clearance.
Commercial Terms and Notes appear before the payment section.
Receiving Bank, Payment Status and Authorised Signatory form the final report block immediately above the shared footer.
The approved fixture remains a single A4 page and its discount, coupon, GST and amount-in-words evidence remains unchanged.
Version 1.8.35
Compact proforma header and discounts
The proforma uses a more compact header with source evidence in the document body, and estimate/proforma detail tables show item discount percentages only when at least one line has an applied discount.
Commercial document clarity
The Proforma Invoice header keeps the shared commercial typography while moving source quotation and acceptance evidence into a compact body strip.
Estimate and proforma line-item tables hide the Discount column when every line has zero itemised discount.
When an itemised discount exists, the percentage column and itemised-discount total remain visible for reconciliation.
Special discounts use the coupon-aware label Special Discount (Coupon Applied : CODE) when coupon evidence is stored.
Version 1.8.34
CRM follow-ups, quick capture and governed reports
Leads can be captured quickly in a centered modal, calendar follow-ups can be completed and rescheduled in place, parties are searchable across connected modules, and commercial reports now follow the approved structures with installation-wide branding and conditional discount evidence.
Lead capture and follow-up
Quick Lead opens as a compact centered modal with name, phone, email, company, next action and follow-up date, while the complete lead record remains available through the full workspace.
Calendar activities and issued commercial documents now open a focused notes and next-follow-up editor, and person names are normalized consistently when leads are captured or edited.
The shared phone input uses a compact country-code control while keeping the readable country list, keyboard access and touch-safe sizing.
Connected records and navigation
CRM, Purchase and SaaS Commercial now expose a shared Party Directory for customers, suspended subscription accounts, contacts, partners, architects, B2B accounts, vendors and service vendors.
Page and form navigation uses the shared icon-led tab pattern throughout the application with roving keyboard focus, selected-state semantics, mobile overflow cues and no side-drawer form presentation.
Reports and branding
Executive Estimate, Professional GST Proforma, Compact Sales Order and Professional GST Invoice follow the approved report structures while retaining the universal installation font and text settings.
Installation Branding now controls report font, footer and legal text, standard watermarks and automatic confidential markings through versioned settings.
Item discount percentages and Special Discount rows appear only when applied; coupon provenance is retained and printed as Special Discount (Coupon Applied : CODE).
Version 1.8.33
Consistent forms, dialogs and icon-led navigation
Large CRM forms now show a clear selected section boundary, controls follow one size and focus contract, record actions open in centered dialogs or full workspaces, and tab and view choices carry relevant icons with accessible selected states.
Form clarity
Lead, Opportunity and Employee forms now give every collapsible section its own boundary, with the current section marked by the semantic primary outline and subtle elevation.
Lead dropdowns, phone fields and shared quick-create controls now match the common 40-pixel desktop control height and retain 44-pixel touch targets where required.
Navigation and overlays
Remaining tab, view, viewport, editor and density choices now use registered shared icons, visible selected states, keyboard focus and accessible pressed semantics.
Shared record overlays default to centered modal presentation, while primary create and edit work continues to replace the route workspace.
Prevention
App-wide audits now reject missing tab or view icons, undersized view controls, unregistered mapped icons, side-drawer presentation, mismatched form-control heights and missing collapsible-section boundaries.
The guarded pilot import now preserves lead and follow-up ownership for staff who have one verified active employee match by email, phone or exact name, while leaving unresolved identities unassigned for review.
Corrected
Deduplicated identical work and personal employee email fields so one active employee is never reported as an ambiguous pair.
Added ordered exact matching by email, normalized phone and unique active employee name, with inactive, deleted and genuinely ambiguous identities excluded.
Controlled import
Recorded the match rule in aggregate-only preview output and retained employee-linked active platform users where available.
Added a disposable-database regression test covering duplicate email fields, phone and name fallbacks, linked users, duplicate names and inactive employees.
Version 1.8.31
Universal icon-led workspace tabs
Tab navigation now follows one shared Analytics-style pattern throughout the app, with relevant icons, clearer selected state, keyboard movement and mobile overflow guidance.
Improved
Standardized 58 page and form navigation groups with 112 contextual icons while preserving each screen's labels, counts, permissions and actions.
Added consistent light and dark styling, 44-pixel touch targets, horizontal mobile scrolling and a visible continuation fade for longer tab sets.
Accessibility
Added shared Arrow Left, Arrow Right, Home and End navigation with roving focus for tab groups.
Added an app-wide audit that rejects new bespoke or iconless navigation tabs while retaining reviewed exemptions for compact editor controls and image thumbnails.
Version 1.8.30
Pilot fleet approval evidence
The registered Propulsive vehicle now has a guarded, reversible pilot data pack for Parvesh-to-Rajni trip, fuel and maintenance approval testing, including genuine synthetic refill-slip files without changing the vehicle master or odometer.
Added
Added four clearly marked historical fleet UAT rows covering an approved trip, approved fuel, pending fuel and rejected maintenance decision.
Added two genuine synthetic PNG refill slips owned by Parvesh Gera and linked through the upload ledger to the corresponding fuel logs.
Governance
Every log routes from Parvesh Gera to reporting manager Rajni Sehgal, while preview, exact database matching, backup acknowledgement and manifest-backed cleanup protect the pilot.
Cleanup refuses to erase a row after a live approval decision or edit, and the pack never creates or edits the registered vehicle, driver assignment, odometer or maintenance authority.
Fresh Propulsive deployments now create the Haryana salary-policy establishment after verified organization facts are available, allowing the State/UT policy interface to open without inventing registrations, contribution coverage or Aadhaar data.
Added
Added an insert-only Propulsive salary-establishment bootstrap keyed to the active tenant and verified proprietorship PAN/Haryana address.
Seeded no statutory registration, TAN, Aadhaar, EPF or ESI coverage; all applicability overrides remain AUTO for later evidence-based resolution.
Improved
Made masked Aadhaar optional in salary-establishment setup and retained strict format validation when HR has a documented reason to record it.
Preserved existing and soft-deleted establishment authority records without automatic edit or restoration.
Version 1.8.28
India-wide establishment-aware HR policy controls
Organization setup now records legal constitution and planned legal-employer transitions, while governed payroll policy packs can target every Indian State and Union Territory, legal-entity type and establishment context without treating unverified rules as certified. Offer negotiation also supports managerial notice defaults and complete probation-assessment terms.
Added
Added legal constitution, constitution effective date and evidence-aware planned legal-employer transition fields to Organization Settings, preserving the current employer identity until a successor entity and actual transfer are verified.
Extended payroll policy-pack selectors with legal-entity types and retained the complete 36-jurisdiction India catalogue for effective-dated State and Union Territory policy configuration.
Added a white-label compliance-engine design covering tenant, legal employer, establishment, workplace and employment assignment boundaries, plus a Haryana manufacturing compliance rollout and an exceptional employee service-agreement plan.
Improved
Managerial L4-and-above offers now default to a 60-day notice period, with a reasoned pre-joining negotiation flow that creates a superseding offer version, resets approval and document control, and invalidates the earlier consent link.
Offer terms now state the probation assessment factors for performance, learning, conduct, problem solving, communication and interpersonal capability, including reasoned extension, confirmation and lawful separation procedure.
Policy applicability continues to fail closed when a jurisdiction source, establishment fact or certification is incomplete, preventing invented State rules from reaching payroll calculations.
Version 1.8.27
Universal report branding and IT employment safeguards
Application Settings now controls eight approved report-header layouts across compatible reports, with Banner layout C selected by default for Propulsive. Offer terms include a governed information-security and data-breach schedule, and employee attendance history uses a compact month view with monthly insights.
Added
Added configurable A–H report-header presets, including four true three-column formats, logo fit and alignment, identity/control visibility, page numbering and repeat-header controls.
Applied the shared header policy to browser Offer Letters and compatible enterprise report formats, with one atomic branding version and Banner preset C as the Propulsive default.
Added versioned IT and data-protection terms covering confidential information, credentials, source code, personal data, incident and breach escalation, evidence preservation, devices, monitoring and disciplinary procedure.
Reduced the employee attendance calendar to compact fixed-height rows and added a monthly insights panel for present days, late arrivals, recorded leave and absences.
Version 1.8.26
Controlled offer letters show complete employment terms
HR can review a branded A4 offer with governed company identity, personal-email status, salary components, notice and increment policy before applying the approved format to other employee documents.
New
Offer approvals allocate a controlled PT/HR/OFFER document number from the shared atomic number-series engine before candidate delivery.
Employee 360 shows each employee's active RACI assignments with role badges, effective dates and a link to the complete responsibility matrix.
Improved
The A4 offer preview uses the configured light-surface logo, governed organization and business-unit identity, complete Gurugram address, GSTIN, PAN and website, while omitting unconfigured phone and email values.
Offer terms now freeze the approved salary revision breakup, probation and notice periods, attendance and leave policy, and the recorded annual-increment policy without promising an automatic raise.
Historical offer corrections are pilot-only, manifest-backed, reversible and preserve any draft that HR has edited or progressed through approval or candidate consent.
Corrected
Offer creation and delivery use the verified personal email; corporate login addresses remain a post-onboarding provisioning step.
CRM pilot snapshots can be written to the protected external backup directory while paths inside the deployed API checkout remain rejected.
Version 1.8.25
CRM and sales UAT controls are ready for the pilot
A guarded pilot pack can validate a complete CRM-to-cash flow with linked commercial and finance records while protecting background jobs and enforcing published enterprise receipt formats.
New
A manifest-backed UAT pack supplies 89 deterministic CRM, sales, billing, accounting and finance records with exact dependencies, scoped cleanup and HR-preservation checks.
Pilot isolation mode pauses all background jobs during the coordinated UAT window and reports that state through health and reminder endpoints.
Improved
Open leads require a next action and due date, surface inline validation, follow the configured status catalogue and retain usable keyboard focus.
Rupee inputs use Indian lakh and crore grouping, one accessible currency symbol and correct programmatic value and disabled-state handling.
Corrected
Payment receipts require a published canonical Report Format Engine definition and return an actionable service-unavailable response when no approved format exists.
Lead exports and ownership errors use explicit employee-account wording when an owner record is unavailable.
Version 1.8.24
Proprietor lifecycle and performance roll-up safeguards
HR can seed truthful employee lifecycle records without treating proprietor drawings as salary, while performance setup repairs only provably stale baseline roll-ups.
Corrected
Bhushan Gera remains in platform onboarding and Digital ID coverage, while salary-based employee offers, appointment letters and probation confirmation are recorded as not applicable to the sole proprietor.
ACTIVE salary authority remains mandatory for every employee contract record from EMP-00002 through EMP-00008.
Organization performance targets created before later baseline employee targets can be repaired when their original value and all supporting rows are reconstructable and unchanged.
Any credible administrator edit to an organization or employee target continues to block automated replacement.
Version 1.8.23
Employee lifecycle and performance setup are ready for governed pilot use
HR can rehearse employee entry-to-exit workflows, manage role-specific KRA and KPI plans, and use consistently sized, validated forms without exposing internal server failures.
New
A pilot-only employee lifecycle pack creates reviewable historical offer drafts and onboarding checklists for the eight existing employees without inventing acceptance, email, KYC or bank evidence.
A clearly labelled synthetic employee exercises onboarding, confirmation history, resignation, final settlement, experience-letter draft and Digital ID revocation with exact cleanup support.
Role-specific 2026 performance plans provide one goal, three KRAs and six balanced KPIs for each current Propulsive employee, with monthly, quarterly and annual operational targets where the source systems can measure them.
Improved
Table page-size selectors and form controls now share the UI kit height and spacing across platform modules, preventing overlap at desktop and mobile widths.
TA bills use a full-page workflow with associated labels, inline validation and touch-sized actions.
Performance seed replay preserves recorded actuals, administrator changes, achievement snapshots and governed incentive evidence.
Corrected
Unexpected server failures now return a safe actionable message to UI toasts while intentional validation and conflict messages remain visible.
Performance API validation now uses the model's complete metric catalogue, including collected revenue and realized margin.
Entity Code Settings now identifies TA bill numbering as an active automatic sequence.
Lifecycle document drafts identify their evidence provenance and require the published enterprise report format before issue; the legacy PDF engine is not used.
Version 1.8.22
Pilot HR workflows have a reversible two-month test baseline
HR can populate July and August pilot attendance and exercise leave, travel, advance and movement workflows with clearly marked synthetic evidence and a governed cleanup path.
New
A pilot-only UAT pack creates July and August attendance for all eight internal employees while preserving approved-timesheet, punch and fixed-monthly-service policies.
Attendance examples cover self, admin and biometric sources, GPS evidence, tea and lunch breaks, late decisions, shortfall, half-day, absence, leave, holiday, weekly-off work, missing checkout and regularization.
The same pack creates approved and pending CL/CO requests, every TA and salary-advance workflow state, expense claims, early-departure requests and temporary move-out outcomes.
Vijay Gera and CA Sandeep Yadav receive September service-visit evidence only because their fixed monthly engagements start on 1 September; attendance never prorates their fees.
Preview blocks non-UAT attendance collisions, apply and cleanup require a verified-backup acknowledgement, and a manifest reverses leave impacts and uploaded proof files.
Version 1.8.21
RACI ownership is visible as a matrix and on employee profiles
Employees can review their approved role duties and active process ownership, while HR sees a conventional process-by-person RACI matrix.
Improved
Employee Operations now presents active processes as rows and participating employees as columns, with clear Responsible, Accountable, Consulted and Informed cells and an accessible legend.
The RACI matrix supports keyboard and horizontal review at narrow widths while keeping process names visible in a sticky first column.
Each employee Profile now displays the responsibility list from the assigned approved Job Description and the employee's own active RACI process assignments.
The self-service Profile API returns only the signed-in employee's RACI roles and never exposes other process participants or grants permissions.
RACI creation now opens as a focused workspace and uses the shared searchable employee selector instead of native dropdown controls.
Version 1.8.20
Propulsive leave policy uses CL and Comp-off only
Paid Leave and Earned Leave have been retired from Propulsive's operating policy, and prior pilot availability is reversed through auditable ledger entries.
Corrected
A fresh Propulsive environment seeds only Casual Leave and Comp-off; PL and EL are never created as active policy types.
Existing PL and EL catalog rows are retained for audit but deactivated with zero accrual and no encashment, so an API restart cannot bring them back.
The guarded reconciliation refuses to erase any PL/EL record tied to a leave request and reports such cases for HR reclassification.
Remaining pilot PL availability is reversed with linked ledger adjustments instead of editing or deleting historical ledger entries.
The standard appointment template no longer promises Paid Leave and instead refers to the currently approved company leave policy.
Version 1.8.19
Existing employee files have an evidence-safe ERP baseline
Current employee roles can be recorded from the ERP start date without falsely treating the latest designation or manager as the employee's original joining record.
Improved
Employment History now includes an explicit ERP migration baseline event for people employed before the platform go-live.
The baseline records the approved department, designation, reporting manager, shift and employment type effective 1 September 2026 while keeping the original joining date on the employee master.
Subhash Malik's confirmed promotion effective 1 January 2026 is retained as a separate historical event; his original pre-promotion designation remains pending source evidence.
Bhushan Gera's single Founder & Sole Proprietor employee record is assigned L7 Director, matching its approved JD without creating a salary revision.
The guarded seed refuses missing employees, unapproved JDs or grade/JD mismatches and does not invent onboarding invitations before personal email addresses are supplied.
Version 1.8.18
HR records begin from the approved ERP go-live date
Attendance, leave and shift records now follow the 1 September 2026 operating baseline, with policy corrections retained as auditable ledger adjustments.
Improved
Monthly leave accrual excludes fixed monthly service and board-remuneration records, future joinees, and Casual Leave for interns, trainees or employees still on probation.
A guarded reconciliation removes disposable pre-go-live and orphan attendance records while retaining original leave entries and posting linked compensating adjustments.
September Paid Leave is corrected to one day, and Vijay Gera and CA Sandeep Yadav no longer carry employee leave balances.
General Shift is fixed at 10:00 AM to 7:00 PM with Tea 10, Lunch 40 and Tea 10 in sequence, an eight-hour net-work rule, and a 30-minute move-out grace period.
Parvesh Gera receives General Shift and Kramajeet's existing-employee probation is corrected to three months ending 1 July 2026, with employee audit entries retained.
Version 1.8.17
Business ownership is governed through RACI
Thirteen effective-dated RACI processes now document responsibility and accountability across Propulsive's current HR, customer, finance, purchasing, fleet, IT and operating workflows.
New
The RACI baseline covers ERP governance, HR onboarding, attendance and leave, salary advances, support and onboarding, sales and collections, invoicing and payment recording, manufacturing and dispatch, sourcing and purchase, financial audit, statutory compliance, fleet logs, and IT support/deployment/onboarding.
Every active process has exactly one Accountable owner and at least one Responsible employee, effective from 1 September 2026.
IT support and SaaS deployment use Rajni as the documented interim Responsible owner until the approved IT manager and executive roles are hired.
RACI remains separate from RBAC and approval matrices, so documenting ownership cannot grant access or bypass maker-checker controls.
The guarded seed is insert-only, preserves administrator-owned active versions, fails if a required employee is missing, and requires an exact database name plus verified-backup acknowledgement.
Version 1.8.16
KRA and KPI baselines cover every operating department
The production-safe performance seed now gives every governed department a measurable, editable plan without inventing achievements or ratings.
Improved
Executive Office now receives strategic execution, financial stewardship and go-live readiness KRAs, so the proprietor home page has a real performance plan.
Information Technology includes support reliability, SaaS deployment and onboarding, access review and IT asset-control measures.
Project, production, procurement, inventory, PPC, furniture quality, dispatch, showroom, installation and facilities teams now have department-specific governed KPI definitions, directions, targets and reconciliation sources.
The seed remains insert-only and leaves KPI actuals, reviews, ratings, appraisal scores and incentives empty for managers to update from real evidence.
Version 1.8.15
Trainees are distinct from interns
HR can classify a training-stipend engagement as Trainee across employee records, JDs, requisitions, postings and employment history.
Improved
Trainee is now an explicit employment type throughout the Platform HR hiring and employee lifecycle.
Intern remains available as a separate category for internship engagements.
The IT Deployment & Onboarding Trainee can now carry L1 and the Trainee employment type without using the Intern category.
Version 1.8.14
Job descriptions carry the current salary grade
HR can classify each employee and hiring role against the live L1-L7 Salary Structure ladder while payroll continues to use the employee's effective Salary Revision.
Improved
The Job Description form now loads L1-L7 from Salary Structure instead of calling the retired legacy pay-grade endpoint.
The JD catalogue shows the grade code and name for workforce planning, recruitment, and role comparisons.
The pilot role catalogue now includes a dedicated Information Technology department plus plant-head, uPVC, millwork, metal, PVD, packaging, dispatch, installation, facility, and machine-operation job families.
A JD grade remains optional for fixed-fee professionals and service providers who are outside employee salary bands.
Actual pay remains governed by the employee's approved, effective Salary Revision so a JD change cannot alter payroll.
Version 1.8.13
Job descriptions follow roles instead of salary bands
HR can maintain one reusable job description for a role without forcing it into a legacy pay grade. Employee compensation continues to come from each employee's effective salary revision, including professional-service engagements that have no employee grade.
Improved
The Job Description form labels the pay-grade link as an optional legacy reference and explains the effective Salary Revision path.
A JD can be shared across employees in different salary bands without changing their compensation.
Contract and professional-service roles can now receive accurate JDs without being assigned a fictional employee pay grade.
Version 1.8.12
Receipt-backed TA bills with separated approvals
Eligible employees can submit travel allowance bills with owned receipt evidence. Each bill follows reporting-manager review, independent HR approval, and a separate Finance reimbursement record with a payment reference.
Added
A dedicated TA Bills workspace shows employee eligibility, personal claims, approval queues, settlement targets, receipt evidence, and the full reimbursement status.
Every submission requires one to three active receipts or tickets uploaded by the employee who owns the bill.
Manager approval routes from the employee reporting line, then authorized HR gives final approval, and a different authorized user records payment with its bank, cash, or voucher reference.
Approval and reimbursement decisions write append-only audit events, while rejected claims retain their evidence and reason.
Approved attendance punch corrections now recalculate gross time, actual break deductions, personal move-out deductions, net working hours and the configured shortfall status before the corrected record reaches monthly reporting or payroll.
Fixed
Approving a corrected check-in or checkout rebuilds the attendance row's stored gross and net hours instead of leaving the previous value behind.
Completed and automatically closed breaks are deducted from corrected attendance, while non-official temporary move-outs remain excluded from net working time.
The eight-hour requirement and configured tolerance are reevaluated after correction so payroll receives the corrected shortfall state.
The Attendance Regularization description now states the actual single-stage approval rule: the employee's reporting manager or authorized HR can decide the request.
Version 1.8.10
Breaks and move-outs show live progress
Attendance actions now use full-width cards. Active tea and lunch breaks show live progress against the scheduled allowance, while temporary move-outs show progress from departure to the employee's expected return time on both the attendance card and the locked return screen.
Added
The break lock screen shows a live, accessible progress bar, elapsed time, remaining time and the scheduled allowance.
Temporary move-out screens show progress from the recorded departure time to the expected return time, including minutes remaining or overdue.
The attendance card repeats the active break and move-out progress indicators so status remains visible in degraded or manager-assisted flows.
Break actions use stacked, full-width cards with the whole unused card as the click target and a full-width resume action inside the active card.
Improved
Progress bars use the shared UI-kit component, semantic status colours and screen-reader labels in light and dark themes.
Break progress changes to the danger treatment after the scheduled allowance, while move-out progress changes when the promised return time is exceeded.
Break actions remain disabled while another break or a temporary move-out is active, and the card explains when they become available.
Version 1.8.9
HR controls employee devices and activity retention
HR can now decide whether an employee may use one, two, or three active devices, choose whether a new login replaces the oldest device or is blocked, and end one or all sessions. Employee activity uses the existing business and security audit trails, with configurable retention, deletion previews and legal holds. The attendance card also reliably applies the 10/40/10 break policy to legacy shifts and locks every permitted device during an active tea or lunch break.
Added
HR can configure one, two, or three active devices per employee. The default is one device with the newest login signing out the previous device; selected field roles can keep more than one active session.
The Access Control workspace lists active device sessions with start and last-active times and lets authorized HR end one device session or all sessions with a required audit reason.
The Activity & Privacy workspace configures separate retention windows for daily activity markers, employee access events and ended sessions, security/business audit events, and AI audit events.
HR can preview records due for deletion without changing data, publish a privacy-policy version and notice URL, and pause the scheduled deletion job under a reasoned legal hold.
Improved
Every browser installation now carries a stable device identifier so separate computers on the same network are governed independently.
A tea or lunch break started on one permitted device reaches other open devices within the attendance policy polling interval and activates the same break lock.
The legacy General Shift break backfill now recognizes both stored array orders, so the former 15/15/30 policy upgrades to two 10-minute tea breaks and one 40-minute lunch break.
The activity policy uses the existing audit and daily-use ledgers and does not capture keystrokes, screen contents, or private message text.
Version 1.8.8
Employee operations now have controlled approvals
Salary advances now move through request, independent approval, disbursement and payroll recovery. Fleet evidence follows the reporting line, HR can publish versioned RACI ownership, selected employees can use audited inactivity controls, and attendance now locks the ERP during governed tea and lunch breaks while enforcing an eight-hour review policy.
Added
Eligible employees can request salary advances with a business reason and recovery plan. Approval and disbursement require different authorized users, and disbursed instalments flow into the matching payroll period with an audit trail.
HR can create versioned RACI process records with one accountable owner, at least one responsible employee, optional consulted and informed participants, effective dates, coverage metrics and controlled activation.
Authorized HR administrators can enable a configurable inactivity lock for selected employees, review their unlock reason, restore access with a recorded decision, or terminate an active session. Employee accounts permit one active system session at a time.
Starting a scheduled tea or lunch break immediately opens a reload-surviving account lock with the employee image, live clock, break allowance and elapsed time. The ERP resumes only after the server records the break end.
Attendance checkout measures net working time after tea, lunch and personal move-out periods. Shortfalls against the configurable eight-hour standard enter an HR review queue before payroll can run.
Fuel entries require a refill slip and every new fleet log follows the submitter’s recorded reporting manager for approval.
Improved
The General Shift break standard is ten minutes for each tea break and forty minutes for lunch. Existing untouched 15/30/15 defaults are upgraded without overwriting custom shift policies.
Vehicle odometer and service facts update only after the related fleet log is approved; rejected logs retain their proof and reason without changing vehicle facts.
The app lock verifies the current password without opening a second login session. Server-side lock state survives refreshes and records policy changes, requests, decisions, session starts and session endings. Tabs in the same browser reuse one session identity while a different browser or device is refused.
Version 1.8.7
GST split by where the work is, and a quote that says what it cannot price
A quotation's tax now splits the way the law expects: CGST and SGST when the site is in your own state, IGST when it is not, decided from the site on the quote and printed as separate lines on the proforma. The total is unchanged either way — only its composition. Elsewhere this release is about a quote telling you what it could not work out: a sliding wardrobe with no track chosen, a panel with no collection, a mechanism your library does not stock now say so on the results screen and on the hardware schedule, instead of quietly leaving the item out of the price.
Added
Tax splits by place of supply: a quotation's GST becomes CGST plus SGST when the site is in the same state you supply from, and IGST when it is not. Set the state you supply from once in Production Configuration; the proforma then prints each component on its own line.
A quote now reports every line it could not price, with the reason, on the results screen — a sliding bay with no track system, a panel with no collection, a shelf with no rate. The reason used to exist only inside the calculation.
The hardware and accessory schedule lists what a job needs but your quotation does not supply, such as a sliding track nobody has chosen yet, instead of leaving the row out altogether.
Two placeholder sliding-track systems ship with the library so a sliding wardrobe can be planned and drawn straight away. They carry no price on purpose: a quote using one is reported unresolved rather than costed as though the track were free.
Gola runs can state which face of the profile their level was measured to, and a house convention for it can be set once in Production Configuration.
Changed
The proforma prints the tax component by component rather than as a single combined line.
A quotation now says which construction standards it was calculated against — and says plainly when those are the built-in defaults that nobody at your business has reviewed or saved.
The proposal's appendix list no longer describes the hardware schedule as empty when it has items to print that your quotation does not supply.
The setup checklist gained rows for the state you supply from and for the Gola convention, and shows the sliding-track systems it finds.
Fixed
A discount above the limit set for a quotation's channel level is now refused when it is entered, naming the limit — and the refusal names the correct level for quotes holding a B2B enquiry, which it previously did not.
Version 1.8.6
A help desk for your team, wardrobes in the Quote Engine, and tidier proposals
Your staff can now raise and track support requests from their own profile, and your support team has a full desk to answer them with private notes, replies and resolution history. The Quote Engine gains wardrobes end to end: a unit library, all four door types including sliding, named internal layouts, lofts and their hardware on the schedule. Areas can carry their own charge and discount, optional supply lines come from the catalogue instead of being typed, and printed proposals no longer break a page straight after a heading.
Added
Helpdesk under My Profile: any employee can raise a request, follow its status and exchange replies with the support team, without needing support permissions.
A Support desk for staff: one command centre with queues for pending, urgent and unassigned work, private internal notes kept separate from replies the requester sees, assignment, resolution history and CSV export.
Wardrobes in the Quote Engine: a unit library, hinged, sliding, bi-fold and open door types, named internal layouts you can fill a bay from and keep editing, lofts, and a sliding bay's track charged and listed on the hardware schedule.
Wardrobes are drawn as their real doors in 3D and included in the quote documents and bill of quantities.
An area can carry its own charge and its own discount, within the discount range its channel level allows.
Optional supply lines are picked from the catalogue instead of typed by hand, and a line that could not be priced is reported on the result rather than only during planning.
A setup checklist shows what an installation still needs entered before quotes can price.
Fixed
Printed proposals and proformas broke a page immediately after a heading, because two page-layout settings were silently dropped whenever a report format was saved. Stored formats now keep them.
A proposal appendix that had drawings to print could be described as empty.
Attendance punch-in reminders: the tests covering them failed around midnight, which masked whether the reminder rule itself was right. They now run against a fixed clock.
Version 1.8.5
Quote a project area by area, and send it as a proposal with drawings and a hardware schedule
A project is now one quote divided into areas — a kitchen, a study, a bedroom — each included or left out. It prints as a premium proposal the customer can sign, with your standard terms, a bill of quantities cabinet by cabinet, and optional appendices: drawings to scale, a complete hardware schedule and 3D views. Website content for the three sites is now edited, reviewed and released through the CMS.
Added
Divide a project into areas from 42 templates or your own, include or leave out each one, and see what each holds. Cabinet lines, kitchens and typed lines each belong to an area, the planner opens on one area at a time, and the proforma prints area by area.
The Projects screen lists the quotes that have areas and opens each on its Areas step.
Print a project as a premium proposal: who it is prepared for, work packages by area, a bill of quantities cabinet by cabinet, specifications, delivery, exclusions, payment milestones and a page for the customer to sign. A cabinet without a rate says so rather than printing a zero.
Keep your standard proposal terms in Production Configuration. Each quote starts from them and can change its own copy; issuing a revision keeps the terms it printed.
Choose what a proposal PDF holds: the areas its detail covers, drawings printed to a stated scale, the complete hardware and accessory schedule — every hinge, runner, fitting and handle with what is included in a price, billed or free — and schematic 3D views. A contents list gives the page of each section.
Every proposal PDF is kept with the options and revision it was made from, and can be reprinted from the Proposal step.
Clear pictures of hardware for customer documents in Production Configuration, with where each came from. Only cleared pictures print; every other line says the image is unavailable.
Website pages for the three sites are edited as drafts in the CMS, previewed privately, reviewed and released as versions that can be restored, with navigation, redirects and search settings managed alongside them.
The media library records usage rights and review for every image and prepares responsive sizes. Newsletter issues are approved before they are sent, job applications arrive from the websites with their CVs kept private, and website chat opens a support case. Each needs its provider set up before it sends or receives.
Changed
Excluded areas stay on the quote with their value but leave the total, the cut list and the proforma, which says which areas it covers.
Version 1.8.4
B2B cabinetry quotes from a kitchen box library, priced from your panel definitions
A B2B cabinetry enquiry is now built from its carcass and shutter definitions and a grouped library of kitchen boxes, priced at the quote's channel level and printed as a proforma invoice. Each box can be divided into drawers and doors, given a handle, fitted from the hardware library, and seen in 3D.
Added
Define carcass and shutter panels once in the Panel Library, and build a B2B enquiry from them in one step. Its proforma invoice can supply cabinets only, shutters only, or both, with optional discounted hardware and accessories.
Add boxes from a grouped kitchen library: drawer and door units, sink and hob units, corners, lift-ups, pull-outs and accessory units, appliance niches and openings, panels and fillers, internal drawers and open bays, glass cabinets, islands and angled ends.
Divide a box's front into drawers, doors, false fronts and flaps, choose its handle (bar, Gola, inlay profile, full grip or CNC), and leave out a panel it does not need. Gola profiles are cut into the carcass and appear on the cut list.
Pick each enquiry's drawer systems, lift fittings, handles and accessories from the hardware library; accessories are suggested by the box's width. A standard hardware and materials library is added to the Item master.
See the selected box in 3D, open its doors and drawers, and show its minifix and dowels.
Keep the factory's construction standards, drawer profiles and lift fittings in Production Configuration, and set panel markups, discount limits and glass shelf costs by channel level in Pricing.
Changed
Panels are priced from the quote's channel level. Edge banding is included in the panel price, and handle routing and hinge boring are charged on each front from the shutter's own rates.
A B2B line is priced for one cabinet and then multiplied by its quantity, so the unit price and the line total always agree.
Fixed
Saving a quote no longer erases its cabinet plan.
The Quote Engine's dropdowns now match the rest of the application.
Version 1.8.3
Email-only joinee invitations and safer customer and supplier onboarding
HR can now invite a new joinee with just their personal email address; the joinee enters their own name and details through the secure link, and HR completes employment setup after approving them. Customer and supplier onboarding keeps approved records stable, stores uploaded evidence privately, applies stricter review controls, and supports refunds to the original payment method and recorded bank exceptions.
Added
Invite a new joinee to onboarding with only their personal email address. They confirm the email with a one-time code and enter their name, personal, bank and emergency-contact details themselves.
Nothing a new joinee enters reaches the employee record until HR approves it. The joinee then stays in pre-boarding until HR completes their employment details and activates them. Onboarding an existing employee still starts by selecting that employee.
Fixed
Expired invitation links can no longer change a submitted or approved onboarding case, and verification or resend actions cannot reopen a locked submission.
Gateway refunds return to the original payment method without requiring bank evidence. Bank-transfer payouts can use an explicitly recorded and audited approval exception.
Shared SaaS subscriptions remain blocked by the tenant-isolation gate even when the customer has not yet been enrolled or linked to CRM.
Customer, supplier and employee onboarding documents are stored privately and accepted only when their file name, type and contents identify a genuine PDF, JPG or PNG.
Approval checks provider GST evidence before updating any customer or supplier record: an inactive registration, or a name that matches neither the legal nor the trade name, blocks approval. A GSTIN not yet verified by a provider can still be approved with a recorded reason, and no exception can approve an unsubmitted form.
Staff contact verification, selected-record email auto-fill and valid action visibility now reflect the saved case correctly.
The portal and invitation email describe the GST certificate as required only for GST-registered organizations.
Approving an employee onboarding submission made before this release keeps the employee’s name.
Version 1.8.2
Secure onboarding for customers, suppliers and new joiners
Customers, suppliers and software subscribers can now be invited to a secure onboarding page to confirm their company details, contacts, bank account and documents, and one organization can be a supplier, a customer and a subscriber under a single verified record. HR gets the same kind of secure page for new joiners and for existing employees whose records need completing. In both cases the person confirms their email with a one-time code, and nothing they enter reaches your records until someone on your team approves it.
Added
Invite a customer, supplier, software subscriber or legacy white-label customer to a secure onboarding page. One organization can hold several of these roles at once, with one set of verified details.
The invitation email lists the documents to prepare. The authorized signatory's name is enough, with no proof of authority requested. The establishment registration and the Udyam/MSME certificate are needed only if they apply, and the GST certificate only when the business is GST registered.
The organization confirms its email with a one-time code, then enters its legal details, owner, accounts and IT contacts, who should receive which messages, and its bank account for payments or refunds.
Your team reviews each document, checks the GSTIN and the bank account, and approves the case. Approval updates the customer or supplier record.
Once an organization is enrolled, sales order confirmation, purchase order issue, payments, refunds and subscription activation wait for its approval. Existing customers and suppliers who have not been enrolled keep working as before and show a reminder to enrol them.
Onboarding invitations for new joiners and for existing employees, sent to the person's personal email address. The email lists each document to upload and says whether it is required, optional or needed only if applicable.
The employee onboarding page opens only after the person enters a one-time code sent to that personal email. The code expires after 10 minutes.
HR can accept each document or send it back with a correction note, open uploads through a secure link that expires after five minutes, and approve the submission once every required document is accepted.
Changed
Approving an existing employee's onboarding updates their personal details and documents only. Their login, roles and access stay exactly as they were.
Fixed
Links in onboarding, offer-letter and experience-letter emails could open a broken address. They now open the right page.
Version 1.8.1
Quote Engine cabinets planned on the drawing are priced from their technical definition
A cabinet placed on a Quote Engine room plan can now use a technical definition, so its panels are calculated at the size it is actually built and the same panels reach the price, the cut list, the drawings and the SVG, DXF and PDF exports. This release also carries the owner's construction decisions for corner, drawer and top panels, and fixes a set of planning problems found while working through complete kitchen and wardrobe quotes.
New
Choose a technical definition for a cabinet on the room plan and fill in the values it asks for. Its parts are calculated from that definition at the cabinet's planned size.
Kitchen cabinets can have drawers added, edited and removed after the cabinet is placed, including the drawer system's make, family, article and side clearance.
A board stock can carry its sheet price, and a part is only cut from a board of its own thickness.
Corner tops and bottoms are listed at full size, with a note that the L or diagonal shape is cut on the panel or beam saw, or by the nesting program.
Fixed
Undo and Redo on the room plan failed every time. They now work.
A cabinet created without doors could never be given doors afterwards.
A thicker replacement side narrowed the top and bottom but left the back too wide to fit.
A beam adjustment for a beam that was not in the room still cut the cabinet down.
A width, depth or height of zero or less was quietly changed to 600 mm. It is now refused with a message.
Editing the bays of a second wardrobe changed the first wardrobe instead.
Drawer backs and bases were labelled as drawer sides in the parts list.
A CNC premium could not read the size of the shutter it was on.
A technical definition that could not be calculated was quietly replaced by a standard cabinet. It is now shown as needing attention.
Some planning and quote screens ran off the edge of narrow windows.
Version 1.8.0
Edits in multi-row forms stay with the row you changed
Forms that hold a list of rows, such as document lines, addresses, discount tiers, salary slabs and workflow transitions, now keep every edit with the row it was made in. Before this release, an edit could be dropped without any message when you saved: after switching to another record while the form was still open, after removing a row from the middle of a list, or after moving a row up or down.
Fixed
After opening a different record while a form was still on screen, changes to that record's rows were not saved; the rows could even show the previous record's values. The rows now show the record you opened, and your changes to them are saved.
Saving a document with line items and then editing its lines again without closing it could lose the second change. Every save now includes the lines as you last edited them.
Removing a row from the middle of a list made the last row disappear instead, while the removed row stayed on screen. The row you remove is now the one that goes.
Moving a row up or down changed the saved order without moving the row on screen. The screen now shows the order that will be saved.
Version 1.7.1
Process flows that look like the design, and say what they know
The process band on every module now follows the approved design: completed stages are a pale tint of the brand colour with a check, the current stage is filled, and upcoming stages are plain tiles with an empty circle. Module Process Flow pages show bold, clearly separated stages instead of a thin strip. On an opportunity, stages carry their real names, the band ends in a single Won / Lost stage, stages ahead are shown as upcoming, and a stage the opportunity actually moved on from shows as completed with the date it did.
Changed
Process bands use one colour family, taken from your brand colour: completed stages are a pale tint with a check mark, the current stage is filled, and upcoming stages are neutral tiles. Completed stages were previously green, which did not match the design or the rest of the band. Choosing the Operational Teal palette under Appearance gives the exact colours of the design previews.
Module Process Flow pages show taller tiles with larger stage names and a solid arrow between stages, instead of a thin strip of small text.
The status legend beside a record uses the same marks as the band.
Fixed
An opportunity's pipeline stages showed their internal keys, such as demo_scheduled and proposal_sent. They now show their names.
Won and Lost appeared as two separate stages at the end of an opportunity's pipeline. They are one final Won / Lost stage again, and a lost opportunity is marked as lost there.
Every stage after an opportunity's current stage read Not determined. Stages not reached yet now read Upcoming.
A stage an opportunity has been moved on from now shows as completed, with the date of that move, taken from its recorded stage changes. A stage it was never moved through, such as one skipped by creating the opportunity at a later stage, still says Not determined rather than claiming it was done.
Version 1.7.0
See where the work stands, and plan projects from reviewed templates
Every module now has a Process Flow page that explains how its work moves from stage to stage, and an opportunity shows how far its own work has actually progressed, built from the quotations, orders, projects, surveys, deliveries and invoices saved against it rather than from its pipeline stage alone. Projects can start from ten reviewed milestone templates, with a preview of the plan against working days and holidays before anything is created. Customers now carry an explicit GST registration declaration and an individual or business identity, instead of both being guessed from whether a GSTIN happens to be recorded.
Added
A Process Flow page for each module, listed below its command center. It explains what each stage is for, what it needs first and who usually does it, and opens the screen where that work happens. It is a guide: it does not claim any record's progress.
An opportunity's record page shows how its work is progressing, read from the records saved against it: quotations, orders, projects, site surveys, production and purchasing, deliveries, acceptance, invoices and collections. Where something has not been recorded, or you do not have access to it, the page says so instead of marking the stage complete.
Opportunities can be classified as IT services, SaaS, B2B furniture, retail interiors or mixed. The classification is kept separately from the sales pipeline and the customer record, and changing one never rewrites the others.
Ten reviewed milestone-template families, from custom software and SaaS implementation to B2B cabinetry, retail kitchens and wardrobes, turnkey interiors, commercial fit-out and supply-only delivery. Templates can be edited, reviewed, published, copied and retired. Installing them creates drafts for review; nothing is published automatically.
Applying a template previews the resulting plan first: the work, its dependencies, owner and reviewer roles, the evidence each acceptance milestone needs, and dates calculated around your working calendar and holidays. Applying it to an existing project requires a reviewed baseline and an approved change, and keeps the work and financial links already there. Applying the same template twice returns the same project rather than creating a second one.
Where Estimation & Quotation is enabled, an ERP Sales quotation can be written, revised, reviewed, issued and accepted on one screen and handed to a sales order. The customer's tax classification is fixed at the moment the quotation is issued, so later changes to the customer do not rewrite an issued document.
Where Site Survey is enabled, a survey can be planned from the opportunity it belongs to and answered with typed values, each recording how it was measured and how confident the surveyor is. Verification and approval need a different person from the one who captured it.
Changed
A customer's GST registration status and whether they are an individual or a business are now declared on the customer record. A missing GSTIN no longer implies the customer is unregistered, and an existing customer with no declaration reads as not yet classified rather than being assigned one.
Fixed
Quotation codes generated into a CRM activity timeline are now hidden from people without permission to read quotations, on the opportunity, the customer timeline and the AI assistant's context. Notes people wrote themselves are unaffected, and no historical record was changed.
The quotation document-discount fields and the customer's GST declaration reason now show their error beside the field, rather than only in a message at the top of the form.
Version 1.6.0
An ID card with an ID on it, and somewhere to issue one
The Digital Employee ID has had a card design, a printable PDF, a scannable code and a public verification page for some time — and no way to issue one, so every employee's Workspace read "No Digital ID has been issued for you yet — ask HR to issue one" and HR had nowhere to do it. HR can now issue, reissue, suspend, reinstate and revoke a Digital ID from an employee's record, which makes the rest of it reachable for the first time. Alongside that: three of the four attendance card formats on Home carried no identity at all, and choosing a format did nothing until the page was reloaded; the calendar and the organization chart stopped short of the space they were given; and the Lead and Opportunity forms now follow the same sectioned pattern as the Employee form.
Added
HR can issue a Digital Employee ID from the employee's record, under a new Digital ID tab, and can reissue, suspend, reinstate or revoke it. Suspending is reversible and revoking is not, and the screen says so before you choose. Each action needs the permission it has always declared, so an installation can grant suspend without granting revoke.
Once a card is issued, the employee's own Workspace shows it with Download ID, Print ID and a verification code a reception or security desk can scan. None of that was reachable before, because no card could exist.
Fixed
Choosing a different attendance card format under Customize dashboard now changes the card straight away. It used to report success and leave the card exactly as it was until the next full page load.
Three of the four attendance card formats showed no photo, name, designation, employee code or work location — despite being named after an ID card. All four now carry the same identity line.
The attendance card's Check In, Move Out and Check Out buttons no longer run out of the card and over the panel beside them in the narrow Home column.
The calendar fills the space on screen instead of stopping short and leaving a band of empty page below it. Month, week, day and agenda each scroll inside themselves, and the calendars panel scrolls itself rather than stretching the page.
The organization chart uses the full width of the page rather than a capped reading column, and its frame takes the height left to it. A chart shorter than its frame now sits in the middle of it instead of at the top with the rest blank.
Changed
The Lead and Opportunity forms now follow the Employee form's sections: numbered steps that say which one you are on and how many there are, Back and Next buttons that name where they go, and a section marked "Needs attention" when it holds the field that is blocking the save. A blocked Opportunity save opens the section that is genuinely at fault rather than always the first one.
Both forms now behave correctly for keyboard and screen-reader users: opening a section moves focus to it, and each section header is properly tied to the panel it controls. No field moved and no grouping changed.
Version 1.5.10
Opening an opportunity now opens the opportunity
Opportunities opens on the board view, and a card on that board offered only an edit pencil — so clicking an opportunity opened the edit form, and the opportunity’s own page was reachable only from the table view, and only if you knew to switch first. The card title is now a link, so the record opens from the view that actually opens. Alongside that, three things on the record page that were visibly wrong have been corrected: the progress stages had a grey groove between them instead of meeting cleanly, the pipeline drew a dangling branch for “Lost” that the approved design does not have, and the GST panel was overlapping its own text inside the narrow side column.
Fixed
An opportunity card on the board now opens the opportunity. It previously opened the edit form, which is why the record page appeared not to have changed — most people were never seeing it.
The progress stages meet cleanly instead of showing a grey gap between each pair.
The pipeline ends in a single “Won / Lost” stage, as the approved design does, instead of a separate “Lost” hanging below the row on a dashed line. A lost opportunity is still shown as closed without a sale and still does not count as progress.
The GST panel no longer overlaps its own labels in the side column. It now shows the diagram where there is room for it and the plain statement where there is not.
The opportunity’s details are laid out in readable columns rather than stretching a date across half the screen.
Changed
The record page no longer displays a “Process” control. There is only one opportunity process, so it offered no choice and told a reader nothing.
Version 1.5.9
The opportunity page, matched to the approved design
The opportunity screen has been taken through the approved design one element at a time rather than in outline. It now opens with a single heading naming the record, its customer and its reference — “OPP-0142 · Asha Mehta — Kitchen renovation” — over the line of context the design shows, instead of two competing titles. Its fields sit in two labelled columns, each value in its own box, as drawn. Activity is a dated table with the person who logged each entry. The GST check sits inside the readiness card where the design puts it, rather than beside it, and the next agreed action carries the page’s one filled button.
Changed
One heading, not two. The page named the record twice, the second time with a value and a stage already shown by the progress band and the details below it.
The details card is two columns of labelled boxes, matching the design. It was three columns of loose text.
Activity is a table of date, time, what happened and who — with “Add note” as an action on the card rather than a form permanently open.
The GST compliance check is now inside the readiness card, and linked records say what kind of document each one is and when it was raised.
The page states which process it is showing and that you are looking at a record’s progress rather than the process guide.
Note
Some things the design shows are deliberately not on the page: a site location, a priority and tags, none of which this system records against an opportunity; and “attach file” and “view all” on the activity card, which have nothing behind them here. An empty box reads as information somebody failed to enter, and a button that opens nothing is worse than no button.
The breadcrumb follows the record’s real location rather than the one in the design image, which the design’s own written instructions ask implementers to replace.
Version 1.5.8
The opportunity page reads like the design
The opportunity record page kept three of its four sections behind tabs, so opening an opportunity showed you a quarter of it — and the part it hid worst was the activity history, which sat out of sight of the readiness check a few inches away that grades whether the record has any activity at all. The page is now a single column of cards you scroll, in the order the approved design shows: the opportunity’s own details, the site surveys raised against it, then its activity. The Process Flow page has been brought to the same chrome, with the process picker where the design puts it.
Added
Site requirement. A site survey has always been able to record which opportunity it belongs to, and nothing could ask the question — so the surveys existed and the opportunity had no way to list its own. It can now, and the card is honest about the difference between “no surveys” and “the surveys could not be loaded”, which matter differently to somebody deciding whether to send a surveyor.
A note can be added to an opportunity from the opportunity itself, rather than from a separate screen. The timeline is re-read from the server afterwards, so what appears is what was actually saved.
Changed
The opportunity page is a stack of cards rather than a set of tabs. Details, site requirement and activity are all on the page at once, followed by commercial documents, campaign attribution, competitors and stakeholders.
Every card now says in one line what it is, which the approved design does throughout and the page previously did not.
The Process Flow page carries a description under its title and puts its process picker in the page header as a dropdown, matching the design. Its footer now states plainly why every stage on that page is shown as not-started: a guide describes the process, it does not report on a record.
Note
The design also shows an “attach file” action beside “add note”. It is not built, because there is no file store behind an opportunity’s activity to attach anything to. A button that opens nothing would be worse than its absence.
Version 1.5.7
One name for an opportunity, and a cleaner main page
Two things the owner asked for after looking at the running system. The application had been calling the same record a “deal” in some places and an “opportunity” in others, sometimes on the same screen — the record page was headed “Opportunity details” under a breadcrumb reading “Deals”. It is now called an opportunity everywhere a person can read it. Separately, thirty screens — every module overview, dashboard and command centre — carried a strip of process stages above their figures. That strip describes a process rather than reporting on any particular record, so it was grey on every one of them, and it has been taken off. It remains where it means something: on a record, showing that record’s progress, and on the module’s own Process Flow page.
Changed
An opportunity is called an opportunity — in the menu, in search, in the command palette, and on every page title, breadcrumb, button, column heading, form label and empty state. Web addresses are unchanged, so existing links and bookmarks still work.
Module overviews, dashboards and command centres no longer carry the process strip. It described the module’s process in general and could not report progress, because those screens are not about one record. Each module’s Process Flow page still explains the process in full, and the menu still links to it.
The strip still appears on the twenty-one record screens where it shows real progress through that record’s own stages.
Note
Roles and permissions are untouched by the rename. Only what is written on the screen changed.
Version 1.5.6
Quote Engine stops looking like a different application
Quote Engine was drawing its icons from a different icon set than the rest of the product — different shapes and weights on every button, list row and panel, on every screen. Beside it in the same menu sat the older commercial quotation screens, which were on the correct set, so the newer workspace was the one that looked out of place. Every Quote Engine icon now comes from the same set as the rest of the application. The menu has also been reduced to the Quote Engine itself: the older commercial quotation and commercial masters screens no longer appear in it.
Changed
Every icon in the Quote Engine — buttons, list rows, panels, the drawing view list, the product workspace tiles — now comes from the same icon set the rest of the application uses.
The Quote Engine menu now contains only Quote Engine: Command Center, Process Flow, Quotes and Calculation Coverage. The commercial quotation lifecycle, commercial insights and the commercial masters under Setup & Administration no longer appear there.
Unchanged, deliberately
The commercial quotation screens still exist and still open. Only their menu entries were removed — nothing was retired, no permission changed, and an existing link or bookmark still works.
Converting a commercial quotation into a sales order is unaffected. That screen never had a menu entry of its own; it is opened from a quotation row or from a CRM deal, and the CRM route is untouched.
Version 1.5.5
The opportunity page can name its customer
Opening an opportunity from the deals list showed a progress band, a readiness checklist and a set of tabs, and nowhere on the screen did it say who the opportunity was for. The list row beside it showed the company and the contact; the record page showed neither. The cause was in the API: the list query asked for those names and the single-record query did not, so the page was sent two identifiers and had nothing to display. With the names arriving, the page now leads with an Opportunity details card carrying the record’s own facts, and the next agreed action moves to the side panel where it sits beside the check that grades it.
Fixed
An opportunity now shows its customer, its primary contact and how to reach them, the customer type and GSTIN held against the account, the owner, when it was created, its expected value and close date, its probability, its lead source and pipeline, and the requirement recorded against it. None of this was previously on the page.
The readiness checklist no longer contradicts itself. “Contact identified” counted a contact it could not name, so a green check sat above the words “No primary contact recorded”. Both halves now read from the same resolved contact.
The GST panel could not reach a classified state on this screen, because it reads the account and was only ever given the account’s identifier. It now reads the real account. Where an account has not declared its registration status the panel still says so — a missing GSTIN is not a declaration, and tax still applies either way.
The next agreed action, and whether it is overdue, is now visible without opening a tab. It sat inside the Overview tab, out of sight of the readiness check that grades it.
Changed
The record header no longer repeats six facts the details card below it now carries, and the side panel’s “Key facts” box is gone into the same card. The same fact shown twice on one screen invites a reader to wonder which is current.
Fields the design shows but the system does not hold — site location, priority and tags — are absent rather than shown empty. An empty labelled row reads as something somebody forgot to fill in.
Version 1.5.4
The Quote Engine landing screens join the rest of the application
The Quote Engine’s own screens — its Command Center, quote list, calculation coverage and quote progress board — were missing the process band that every other module carries at the top of its landing and list screens, and their summary figures were plain unclickable panels. Opening Quote Engine therefore looked like arriving in an older, separate product, whatever the screens further in looked like. The band is now there, and each figure on the Command Center is a real card: it says what the number means and where it came from, and clicking it opens the records behind it.
Changed
Quote Engine’s Command Center, quote list, calculation coverage and quote progress screens now carry the same process band as every other module, in guide form — it explains the stages a quote goes through rather than reporting any one quote’s progress.
The four figures on the Command Center — quotes, drafts, issued and declared rule gaps — are now cards you can open. Each carries the definition of what it counts, and the rule-gap card also says how it was counted: from the engine’s own registry of what it does not implement, never inferred from missing output.
From the Command Center you can now reach the quote list and calculation coverage by clicking a figure, rather than only through the navigation menu.
Known
The quote list still draws its own table rather than using the shared one, so it does not yet offer the column, density and sorting controls other lists in the application have. The table is correct and readable; it is the controls around it that are missing.
Version 1.5.3
Open a record from its list
Twelve modules had a record screen — the page showing one support case, one work order, one purchase order, one asset — and nothing in the application linked to any of them. They were built and they worked; there was simply no way to open one. The only process flow anyone could reach was the module guide page, which explains a process rather than tracking a record, so every stage there reads as not yet started and the whole band is deliberately grey. That is why the flow looked colourless: not a broken palette, but the correct rendering of the only page that could be opened. Each list now opens its record from the identifier in the row.
Fixed
The identifier in each list row now opens that record, across support, manufacturing, purchase, accounts, inventory, assets, projects, fulfilment, training and leave.
Work management opens its records from the work breakdown tree, which is where work items actually appear — there is no separate work-items list to click through.
Onboarding opens by employee, because that is how an onboarding record is identified.
The process flow on a record screen now shows that record’s real progress. It was only ever grey because the module guide was the sole reachable page, and a guide asserts no progress by design.
Changed
Lists keep managing records in side drawers, which is unchanged and deliberate. The row identifier is now additionally a way into the full record screen.
Version 1.5.2
The kitchen and wardrobe screens look like the workspace they are
The CAD planning and drawing screens that arrived in 1.5.0 worked, but they were laid out like a standard record page — a heading, a row of summary tiles, then stacked notices — rather than like the drawing workspace they were designed as. This rebuilds them on the layout the design review approved: the quote’s name and status at the top with its key facts on one line, the process band beneath it, a row of sections, and then a single framed workspace holding the list of views, the drawing itself with its own toolbar, and a properties panel beside it. Nothing about the drawings, the calculation or the exports changed — only where things sit and how the screen reads.
Changed
CAD planning and Drawing review now open as a single bordered workspace: the list of drawing views on the left, the drawing in the middle with its own zoom and fit controls, and the properties panel — layers, plot settings, exports and the resolved specification codes — on the right.
The revision, formula version, view count and output status used to sit in four tiles across the top. They are facts about which quote you are looking at, so they now sit on one line under the title, with the revision status shown as a chip beside the name.
The drawing sits on a framed sheet with its own header and footer, so the caption that says the on-screen rendering is not to the sheet scale reads as a property of the drawing rather than a note about the page.
The quote configuration screen carries the same identity header, so moving between configuring a quote, planning it and reviewing its drawings no longer feels like moving between three products.
Zoom and fit on the drawing are screen-only. They change nothing about the geometry, the sheet scale, or a single byte of any export.
Fixed
The process band on these screens was a second, thinner copy of the one every other module uses. It now uses the shared band, which means each step shows the sentence explaining its state, and steps that cannot be reached say so rather than looking merely incomplete.
Sections that have no screen in this release are no longer shown as tabs. A tab that does nothing when clicked reads as a broken workspace rather than an unfinished one.
Version 1.5.1
The corporate homepage is edited in the CMS, not in the code
The corporate site’s homepage lived in the website source, so changing a headline meant a developer and a rebuild. This release moves that page into the CMS: the homepage is imported as a governed draft, edited and published through the normal page workflow, and the website reads it from the published feed. Publishing a page still does not make a hidden site readable — the public feed checks that the site itself is published, not just the page.
Added
The corporate homepage is a CMS page. An import brings the existing hero, expertise, outcome and closing-call-to-action blocks in as a draft, so the live wording is preserved rather than retyped, and replaying the import on untouched content changes nothing.
The public website reads the homepage from the published CMS feed instead of from its own source, so an editor’s published change reaches the site on its next build with no code change.
A time-limited preview grant renders an unpublished homepage draft at a chosen viewport, so wording and layout can be checked before publishing without exposing the draft publicly.
Changed
The public content feed sends no-store cache headers and asks search engines not to index it, so unpublishing a page takes effect immediately rather than after a cache expires.
Fixed
Two dead Bootstrap classes in CRM and elsewhere that styled nothing after the design-system migration.
Not included
Editing the homepage does not publish the website. The corporate site is still governed separately, and its publication state is what decides whether the page is served.
Version 1.5.0
Plan a kitchen on screen, and quote from the same drawing
The Quote Engine could price a kitchen but never place one. It calculated parts — a width, a height, a thickness and a quantity — with nothing to record which drawer sat in which cabinet or how high a shelf landed, so no drawing could be derived from a quote and the two were kept in step by hand. This release adds a planning workspace where cabinets and wardrobe bays are placed against measured walls, and produces the plans, elevations and sections from the same saved calculation the quote is issued from — so a drawing cannot describe a different kitchen from the one being priced. Alongside it: the HR onboarding flow, process-flow status on 22 of 23 modules, and several dropdowns that were being clipped by the panels they sat in.
Added
Kitchen and wardrobe CAD planning in the Quote Engine. Rooms, walls, openings and obstructions are measured; cabinets are placed along a wall and wardrobe bays across an opening, with internals — levels, shelves, rails and drawers — placed inside them. Dimensions are edited against the base you actually measured (site opening, external carcass, clear interior, additional cover or overall installed), and the screen says which one it is using.
Placements are checked in three dimensions, not on the plan alone. A wall unit sitting directly above a base unit overlaps when seen from above and is correct; a plan-only check would reject it, and every real kitchen with it. An edit that would put two cabinets in the same space is refused and the previous layout is left exactly as it was.
Coordinated drawings from the saved revision: a plan, an elevation for every measured wall — including walls that carry only a window or a door — and sections. A wardrobe gets closed-front, internal, plan, rear, both ends and a section for each bay.
Export as SVG, as a vector PDF sheet, or as DXF for CAD. All three are drawn from one set of entities, so they cannot disagree with each other, and a reprint of an issued revision is identical to the first print.
Planned cabinets now reach the cut list, the board plan and the costing, not just the drawings. A planned kitchen produces panels to saw in the same place every other module does.
Sloping tops, columns and beams. Panels, backs, shelves, fronts and fittings each recompute against the shape; anything the engine cannot resolve stays an editable draft carrying the reason, rather than being quietly approximated.
A Quote Engine Command Center, and a Quote progress board showing where every quote stands across Site & measurements, CAD planning, Collections, Internals & fittings, Drawing review and Quote. A step counts as complete only when the saved record supports it — opening a tab does not complete a step.
The HR onboarding flow, built from the models its own preview shows.
Process Flow is now recorded on 22 of 23 modules, so the status band reports what a module actually has rather than reporting nothing.
Changed
The status band no longer tells readers the system lacks things it has. It was describing absent records for modules that had them.
The Quote Engine uses the platform-wide Process Flow row rather than one of its own, so the entry behaves the same here as in every other module.
Fixed
Dropdowns clipped to a sliver by the panel they sat in — the calendar view selector, the CMS site switcher and the Quote Engine planning inspector. Each showed only its current value and could not be opened. A page header scrolls sideways, and a menu drawn inside it was cut off at the edge; the menus are now drawn above the page instead.
robots.txt reported the wrong cause when it was serving a restrictive rule, so the diagnostic sent readers to the wrong setting.
Not included
Exact manufacturer cutting rules. Naming a brand does not select a deduction, so without a resolved manufacturer, article and technical revision a drawer or slider is reported unresolved rather than guessed.
Hinge, lock and closer counts — no rule derives one from a leaf size or weight.
Native DWG, associative dimensions and CNC output. The DXF is validated on its own terms; exporting a drawing does not drive any machine.
Shaped-part nesting. The saw planner still prepares rectangular blanks, so a notched part is not finished merely because the rectangle around it fits.
The other eight product workspaces. They are named in the Command Center and marked not yet operational rather than left to look available.
Version 1.4.0
A calendar you can read a week in
The calendar that arrived in 1.3.0 showed the right work in the wrong shape: everything sat at the top of its hour, a fifteen-minute call and a three-hour installation drew the same block, two meetings in one hour covered each other up, and the panel beside the grid was usually empty. This rebuilds the workspace around a continuous time grid where an event sits at the minute it starts and is as tall as it actually lasts. There is a Day view, a small month navigator for jumping around, a list of your calendars you can switch on and off, and event details that open where you clicked instead of in a permanent side panel. Times are now shown in your organisation's timezone throughout — the toolbar said one thing and the grid did another.
Added
A Day view, alongside Month, Week and Agenda. Picking a date and switching to Day opens on the day you picked, not on whatever the previous view was centred on.
A month navigator beside the calendar for moving around quickly. It shades the range the main view is actually showing, and the arrow keys move a day, a week or a month at a time.
A list of your calendars, grouped by the module each belongs to, with reminders kept in their own group. Each one carries the colour its events use in the grid, so the list reads as a key rather than a set of filters. Collapsing a group hides its rows and changes nothing about what is shown.
Event details now open in a small panel next to the event you clicked, with the date and time, the timezone, which calendar it came from, its status, any amount you are allowed to see, and Open source record. Escape or the close button dismisses it and puts you back on the event.
A line above the grid when something falls outside working hours — "1 item outside 09:00-18:00, earliest Thu 02:40" — with a Show link that scrolls to it.
The whole day is always there to scroll through, so evening visits, night shifts and overnight jobs have somewhere to appear.
Changed
Events are placed by the minute they start and drawn as tall as they last. A 09:30 meeting no longer sits on the 09:00 line, and a three-hour installation no longer looks like a forty-five minute call.
Overlapping events sit side by side in their own columns instead of on top of one another. Two events that merely run back to back still each get the full width.
Times are shown in your organisation's timezone everywhere — which day an event falls on, where it sits in the grid, which day is marked today, and the current-time line. The toolbar named that timezone before but the grid quietly used your computer's. If the two differ, the calendar now says so.
The always-present panel beside the grid is gone. It was empty unless you had selected something, and the space belongs to the calendar.
Unticking every calendar now shows nothing, and says so. It used to show everything, which is the opposite of what unticking them asks for.
Your view, your calendar selection, the panel being open or closed, and where the grid was scrolled to are remembered between visits. A saved selection is re-checked against what you can currently see, and the calendar still opens on today.
Opening a record from the calendar and coming back returns you to the date and view you left.
On a phone the agenda gives each entry its own line for the record name instead of squeezing it into a narrow column, and the calendars panel starts closed so the schedule is the first thing on screen.
Each calendar has its own colour, used consistently in the week grid, the month cells, the agenda and the list. Colour is never the only signal — every entry also carries its calendar's name and an icon for its kind.
Fixed
A reminder, or anything with no recorded end time, no longer appears to occupy an hour. It is shown as a marker at its moment, and its details show one time rather than a range.
Work spanning several days now appears on every day it covers. It previously showed on the first and last day only, so a three-day installation was missing from the middle of the week.
Something running until exactly midnight no longer also appears on the following morning.
The current-time line is drawn only in today's column. It previously ran across unrelated days, and it is a clock marker rather than a warning — red is kept for work that is genuinely overdue.
An overdue deadline is now marked as overdue in the month view too.
Long record names no longer push the time out of an event and get cut mid-line. Short events show what fits and the full text is always in the details panel and the agenda.
A day with a single early reminder no longer opens the week on an empty pre-dawn screen. The grid starts on the working day and points at the early item.
Note on the version number
1.3.0 is live on both servers, so this is a new version rather than another build of that one. Nothing about 1.3.0 is withdrawn — this changes how its calendar looks and behaves, and the underlying data, permissions and sources are the same.
Version 1.3.0
A quoting engine, a calendar everywhere, and drawings the shop can build from
The largest release so far, and the first to reach these servers since 1.1.56. Estimation & Quotation becomes Quote Engine: a standalone workspace that prices a kitchen, wardrobe or doorset and returns a cut list, a board plan and an issued revision that still adds up months later. A shared calendar shows everything dated you are meant to see, and the same calendar appears inside ten modules. The shop floor gets part labels it can print and a terminal it can scan at, and the drawings, BOMs and cut plans it works from now agree with each other about thickness. Account & Access is rebuilt around roles, so an HR Admin can grant a new starter their access without going to a Superadmin.
Added
Quote Engine, at Quote Engine → Quotes. Enter wall runs for a preliminary budget, or configure carcasses, shutters, drawers and doorsets for a detailed one. It returns parts with both finished and cut sizes, a nested board plan with a sheet count, costing, and issued revisions. The module also stops being hidden: the flag that concealed the whole section is gone, so it appears in the launcher on installations where that flag was never switched on.
A Calculation Coverage screen listing every geometry, costing and board-planning rule the engine applies and where each came from — and the five things it refuses to guess: hinge, lock and closer quantities, wardrobe-specific construction, and glass and aluminium profiles. A gap you can price by hand is worth more than a number nobody can trace.
Part labels that print. Every part-label screen previously returned data only, so the shop had a scanning system and nothing to scan. There are now two printable outputs: a single 100×70mm label carrying QR, cabinet, size, material and next station, or a whole work order’s labels as one print job — a page each, sorted by cabinet and part.
An operator terminal under Manufacturing, built for standing at a machine. The scan box keeps and re-takes focus after every scan, because a barcode scanner is a keyboard and lost focus looks like a broken station. The verdict is the largest thing on screen and is carried by shape and text as well as by colour.
A design workspace that can place openings: pick a window or door from a template picker showing each type’s plan symbol, watch a ghost preview report problems as sentences you can act on — “Runs off the end of the wall” — and sketch several obstructions in one pass.
A People calendar under Time & Attendance: approved leave as one entry per day of a multi-day absence, joining, probation-end and notice-period milestones, holidays and interviews.
A shared calendar at Calendar, with Month, Week and Agenda views. Week opens by default on a desktop; on a phone it opens on Agenda, where a seven-column grid cannot be read.
The same calendar inside People, Financial, Sales, Purchase, Delivery, Production, Statutory, Despatch, Developer and Assets, each showing only that area’s own work.
Thirty-eight kinds of dated record now appear, including meetings and follow-ups, service response deadlines and site visits, holidays, interviews, approved leave, joining and probation dates, invoices and vendor bills due, estimate and quotation expiry, purchase deliveries, RFQ deadlines, scheduled work and deliverables, work orders and planned maintenance, despatch lines, e-way bill validity, TDS deposits, vehicle document expiry and your own to-dos.
Reminder entries appear separately from the work they remind you about, so acting on a reminder never marks the underlying task done.
Changed
Account & Access on an employee is now just roles. The old “1. Module Access / 2. Roles for Selected Modules / 3. Access Review” wizard has been removed — its module checklist never granted anything, because permissions have only ever come from roles. In its place: a searchable role picker, and a read-only Effective access panel showing what the person can actually open, worked out by the server from the same rules it enforces.
An HR Admin can now grant staff their access without a Superadmin, for anything whose permissions sit inside what HR Admin itself holds. In exchange HR Admin becomes a privileged role: only a Superadmin or Platform Admin can grant it.
Roles you are not allowed to hand out are locked in the picker with the reason on the row — “Grants permissions you do not hold yourself, so you cannot delegate it”, “Privileged role — needs global role-assignment authority” — rather than failing silently on save.
Assigning roles is its own action with its own reason. “Save roles” will not run without one, every change is written to the audit trail with who and when, and a save refuses to overwrite someone else’s edit made since you opened the form. Editing employment facts can no longer change access at all.
You cannot change your own access, and resetting someone’s password now requires that you would be allowed to assign every role they hold — closing the route where a password reset stood in for a promotion.
Seeing costs and margin on a quote is a separate permission from opening one. A coordinator gets the full specification, cut list and board plan; the Costing tab says “Costing is hidden for your role” instead of showing zeros that read as free.
An issued quote still adds up months later. Picking a material copies its code, description, unit, dimensions and rate onto the quote along with the catalog version and the time it was taken, and every calculation reads that copy. A draft offers “Check for catalog changes”; an issued revision never moves under you.
You only ever see calendar entries you already have permission to read, decided for each kind of record before it is fetched. The list of calendars you can switch on shows only what is available to you.
If one kind of record cannot be loaded, the calendar says which and keeps showing the rest, instead of appearing empty as though nothing were scheduled.
People data stays out of the organisation-wide view. A probation ending shows as an unnamed entry there and names the person only on the People calendar.
Your to-do list is visible only to you, on your own calendar, whatever anyone else’s permissions are.
Fixed
The BOM is issued per board, not per material name, and at the size you actually cut. A larder used to issue one line reading “MDF, 89.48 sqft” covering 18mm carcass panels, a 6mm back and 6mm drawer bottoms — nothing anyone can order from, since the same rate card prices 6mm and 18mm 87.5% apart. Lines now split by material and thickness, and the BOM stops requisitioning more board than the quote ever priced.
Cut plans put each piece on a sheet of its own board, and name that board’s thickness. Every nesting layout used the first sheet in the list regardless of the piece’s material, so a 6mm back, an 18mm side and a 20mm stone slab were laid out together and the second sheet definition was inert.
Cabinet drawings now agree with each other and with the cut list. Doors and drawer fronts in the section view were drawn from the cavity rather than the cabinet top, putting a 694mm door 12mm below the wall unit it hangs on; corner units had no drawings at all.
A quote could show six sheets of ply and a priced doorset and still total zero, because neither reached the total. Both are counted now, with the board plan’s waste marked as already included so a wastage percentage cannot be applied on top of it twice.
The room check stops inventing conflicts with beams and doorways, and starts catching the case that matters: two cabinets in the same place.
A production batch that scraps a panel at cutting can be closed, instead of staying open forever.
The CRM calendar no longer shows one salesperson the whole team’s diary. The owner was a filter the caller chose rather than a scope, so anyone holding one of four CRM read grants could read every user’s scheduled activities by changing an id in the address bar.
Terminating or deleting an employee can no longer lock the business out of its own access administration. The last active account able to administer access cannot be stripped of that role, disabled, terminated or deleted — and that refusal now covers the ordinary HR paths too, which previously went around it.
People data stays inside HR on the company-wide calendar. Outside HRMS, an absence, a probation ending or an interview shows without naming anyone; names appear only on the People calendar, and only to someone holding the HR read permission for that kind of record.
Organization chart: “Fit to screen” now actually fits. It measured width only — correct while the chart frame was always taller than the chart, but since the frame started filling the page a tall organisation overflowed downward and the button did nothing at all. It now takes whichever of width or height needs the bigger reduction, and rounds the zoom down rather than up, so the result no longer overshoots the frame by a few pixels.
Module Control announces what happened to a screen reader when you reorder or save. Moving a row swapped it and renumbered every position, all of it invisible without sight.
Self-service checkout stops telling a customer mid-purchase that it lost their session when it had not.
Each of the three websites gets its own link preview card. All three emitted the same neutral image, so a Woodworking ERP link and a Propulsive link previewed identically wherever they were shared.
The CRM calendar could show one person the whole team’s scheduled activity. It now shows an individual contributor only their own, matching the follow-up and appointment lists beside it.
Due dates, holidays and expiry dates can no longer shift by a day. An invoice due on the 9th reads as the 9th regardless of timezone.
Needs a database update before it takes effect
Codes on 86 record types — Product Engine materials and the Design Library first, then AMC, service ticket, warranty, expense claim and payment receipt numbers among others — were declared unique in the code, but the constraint had never actually existed in the database, so duplicates could be created. The repair ships here as database updates 054–058. Deploying does not run them: they are applied by hand, per server, and until that is done duplicates remain possible on those records. Everything else in this release works without them.
Note on the version number
This release has been numbered three times, and both earlier numbers were already taken. It was first 1.1.49, which a parallel line of work had already used and has since carried to 1.1.54. It then became 1.2.0 — but 1.2.0 was already published on woodworkingerp.com and propulsive.in as "August platform update", dated 2026-08-25, so that number already names a different release in front of customers. It is now 1.3.0, which nothing has published. Nothing was ever published from here as 1.1.49 or as 1.2.0.
Version 1.1.48
Two release lines merged, plus Reports-to and document details
This number named two releases. On one line it merged the Design Engine and report-format work with the role-only access change and fixed a checkout lease and a test port race. On the other it made Reports-to save and gave documents their own recorded details. Both shipped as 1.1.48 before the lines were joined, so both are recorded here rather than one being renumbered after the fact.
Changed (merged-lines release)
Two release lines were merged into one. The only overlaps were version identity files and the changelog; no source conflicts arose.
The merged tree is 1.1.48 because 1.1.30 names two different releases — each line numbered independently from 1.1.29 — and neither was renumbered after publication.
Fixed (merged-lines release)
Self-service checkout could report "processing ownership was lost" to the worker that still held the lease, when two heartbeats landed in the same millisecond. Ownership is now proved by matching the lease, not by the write changing a value.
The parallel-test port-race retry recognised only one of the two messages that race produces, so whole test files failed together while the retry never fired.
Fixed (HR and documents release)
Choosing a reporting manager saved nothing. The picker showed the person you clicked, and the record kept none — confirmed against the database, where every employee on both environments had no reporting manager at all, including records saved that morning. The picker emits the selected employee rather than a plain id, and the code read a field that employee does not have, so a real choice became empty on the way to the form. Reopening an employee also now shows the manager already on file.
Added (HR and documents release)
Employee documents now record the document number and issue date beside the expiry date and the attachment, so a licence, passport or certificate is filed as a document rather than only as a scan. Aadhaar Card and PAN Card are unchanged — they remain plain upload slots.
Verified (HR and documents release)
New reporting-manager and document contract suites 8/8 between them, HR 677/677, platform 8456/8458 (the two failures are an unrelated timing-sensitive test that passes on its own).
Note on the version number
1.1.48 was issued independently on two lines of work that were numbering separately. Both had already shipped under it, so neither was renumbered; this entry carries what each contained. The lines were merged on 2026-09-08 so it cannot happen again.
Version 1.1.35
Money and tax corrections in Sales
Four defects in how credit notes, GST place of supply, mixed-category tax rates and draft invoices handle money. None has reached a customer — there are no invoices or credit notes on production yet.
Fixed
A credit note credited the price before discount. A line billed at ₹8,000 after a 20% discount was credited at ₹10,000 — refunding money the customer never paid and reversing GST that was never charged. A full credit of a discounted invoice was then rejected for exceeding the invoice total, so only partial, over-refunding credits went through. Credit notes now use the price actually billed.
An undetermined place of supply was charged as IGST. When the customer’s state could not be resolved, the whole tax was assumed to be inter-state — so a local customer was charged IGST instead of CGST+SGST and filed in the wrong GSTR bucket. It no longer guesses; a taxed document whose place of supply cannot be determined is refused at posting, naming the record to fix.
A mixed-category estimate was taxed at whichever line happened to sit first, so reordering the lines could change the tax on the quotation. Every category is now resolved: if they agree that is the rate, and if they genuinely differ the platform default applies — the documented behaviour all along. Same fix on quotations.
A draft tax invoice printed a grand total that included tax above three tax lines each reading zero, because the CGST/SGST/IGST split ran only at posting. Drafts now carry their own split, so the figures agree.
Verified
New money and tax contract suite: 12 tests covering the intra/inter/undetermined split, credit-note discount arithmetic, a full credit reproducing the invoice total, and order-independence of the mixed-category rate.
Sales, tax, invoice, credit-note, estimate, quotation and commercial suites 806/806; accounting money 21/21 and ledger 9/9.
Setup note
A GST invoice cannot state CGST/SGST or IGST without the seller’s own registration. The Head Office business unit has no GSTIN or state set, so a taxed invoice will not post until one is entered.
Version 1.1.36
Destroyed vendor details, a compensation leak, and two wrong prices
Four confirmed defects from the pre-production audit: an edit that silently wiped vendor bank and tax details, salary changes visible to a role denied compensation access, quotation revisions that raised the price, and ESI charged to employees who are not covered.
Fixed
Editing a vendor silently erased its GSTIN, PAN and bank details. Those fields are hidden from anyone without the admin-only bank/tax grant, so the edit form loaded them empty and saved them back as empty — destroying values that role can never see to retype. The damage carried onward: vendor bills read the place of supply from that GSTIN, so the next bill lost its CGST/SGST vs IGST determination and the GSTR purchase rows went out with a blank counterparty. A field you may not read is no longer a field you may write; the stored value is left untouched.
The employee audit log returned salary and bank changes to roles denied compensation access. Salary is stripped from the employee list, the detail screen, the CSV export and the employment summary for those roles — and was then handed back in the change log, with the previous value attached. The values are now redacted while the row still records that a change happened, who made it and when.
Revising a quotation silently raised the price. The revision copied every line field except the negotiated per-line discount, and the total is recomputed from that percentage — so a quote of ₹1,06,200 came back as a v2 draft at ₹1,18,000 with the discount gone from every line and nothing on screen saying so.
ESI was charged to employees who are not covered by it. Eligibility was tested against the month’s prorated pay rather than the contracted salary, so anyone above the wage ceiling dropped below it in any month with unpaid leave and gained an ESI deduction they have never had and hold no ESI number for — contradicting their own approved salary structure. Coverage now follows the contracted salary; the contribution still follows the wages actually paid.
Verified
New wave-1 contract suite 8/8; vendor sensitive-data masking 9/9 including a case that posts blank bank fields and asserts the stored values survive.
HR 672/672, CRM 729/729, platform 8405/8406 — the one failure is a timing-sensitive lease test that passes in isolation and is unrelated.
Version 1.1.37
Dashboard figures that were quietly wrong
Receivables that omitted money still owed, a CRM open-AR figure that collapsed to zero, and won deals credited to the wrong month.
Fixed
The Sales Command Center dropped every partially credited invoice from receivables, overdue and ageing. A partial credit note reduces an invoice; it does not settle it, and the remainder is still owed. The same invoice counted against the customer’s credit limit and appeared in the AR ageing report while being missing from the dashboard. The definition of an open receivable now lives in one place instead of five.
CRM open receivables collapsed to ₹0 for the rest of the day as soon as any lead or deal was created before the nightly figures ran. The dashboard took its balances from whichever snapshot row came last, and an event creates a row with no financial figures in it — so a real balance read as zero, indistinguishable from being paid up. Rows now record whether the financial pass actually ran.
“Won this month” credited each win to the day the deal was created rather than the day it closed, so it only ever counted deals created and closed inside the same calendar month — the longer the sales cycle, the more of the month’s revenue disappeared from the figure. The same applied to deals lost. A deal with no recorded close date still counts on its creation day, exactly as before, so nothing moves without evidence.
Verified
CRM 733/733 including four new cases: a July-created deal won in September counted in September and not July, the creation counter staying on the creation day, and open AR surviving a later event-only row.
Platform 8410/8410 — a fully green run.
Version 1.1.38
Permissions that hid the wrong things from the wrong people
Approvals invisible to the managers authorised to give them, settings screens hidden behind a key none of them use, and write buttons offered to viewers who cannot use them.
Fixed
Reporting managers could see their team’s attendance regularization and move-out requests but had no Approve or Reject button. The decision endpoint deliberately allows either the employee’s reporting manager or the HR approval permission; the screen checked only the permission, so the queue built for line managers was unusable by them. Each row now carries the server’s own answer.
CRM Module Settings was hidden behind the CRM settings-write permission — the key for one of its eleven screens. Anyone holding, say, Portal Users access but not CRM settings-write lost the entire group. Each destination is now gated on the permission it actually requires.
HR Module Settings had the same fault: an HR Manager who may edit shifts, departments, holidays and leave types saw none of them, because the group demanded a settings-write key none of those screens use.
CRM Deals, CRM Leads and Sales Estimates offered Add, Edit, Delete and Create revision to every viewer and refused the action only after it was attempted. Those buttons now appear only for people who can actually complete them.
Changed
A settings group whose destinations are all hidden by permission no longer renders as an empty heading.
Verified
New permission-gate contract suite 6/6, including a check that both approval queues fail closed outside the approval scope.
Customer receivables summed from the 50 newest invoices, a bank reconciliation that never looked at the ledger, marketing rates counting inbound replies, and three more totals counting the wrong rows.
Fixed
Bank Reconciliation’s Difference never consulted the ledger. It was arithmetically just the unmatched statement total — the number already shown beside it — so matching every imported line displayed a green 0.00 “reconciled” while the books still held entries no statement accounted for. The book side now comes from posted, unreconciled ledger movements, and a new tile shows them.
Customer 360’s Open AR and Payments were summed from the 50 most recent invoices and payments. Both lists are sorted newest first, so the figures excluded precisely the oldest — the ones most likely to be overdue. Both are now aggregated over the whole customer, and a partially credited invoice counts toward what is still owed.
Marketing delivery, read and failure rates counted inbound customer replies, which are stored as delivered because they did arrive. A busy inbound week pushed the delivery rate up and the failure rate down while outbound performance was unchanged. The statistics now describe only what was sent.
The Customer 360 service card called every high-priority ticket ever raised “urgent”, so a customer whose urgent issues were all resolved kept the same red count forever — and disagreed with the Command Center and CRM Dashboard, which both scope urgency to open tickets.
AP ageing ignored the “As of” date while AR honoured it, so the combined screen aged supplier bills that had not been raised yet on the chosen date and moved Net exposure when only the receivables half should have changed.
People Command Center’s “Active Workforce” counted soft-deleted employees and the dev onboarding account, contradicting the Payroll Readiness figure beside it.
Verified
New figures contract suite 7/7, including a case proving the reconciliation difference can now be non-zero when every statement line is matched — the state the old formula made arithmetically impossible.
CRM 733/733, HR 672/672, platform 8415/8416 (the one failure is an unrelated timing-sensitive test), TypeScript clean.
Version 1.1.40
Reports, exports and payroll that disagreed with themselves
A report that ignored its own filters, a cost-to-company lower than net pay, PF capped against the salary structure’s own setting, two CSV exports shipping database ids, and a sales funnel counting the wrong documents.
Fixed
HR Department Analysis ignored the Department, Business Unit, Status, Designation and Employee filters while the page stated every number was filtered by them — selecting one department showed the whole organisation, and nothing said so.
The Payroll report’s “Cost to Company” omitted holiday and week-off bonuses and employer labour welfare fund, all of which were actually paid. On a payroll including any of them, the cost to company printed lower than the net pay beside it.
PF was capped at the statutory wage ceiling even when the salary structure switched that cap off. The structure honours the toggle; the payslip dropped it, so the two disagreed for every employee earning above the ceiling under an uncapped policy. A missing toggle is now rejected as a misconfigured policy rather than guessed.
The Employees CSV export wrote the Business Unit’s database id instead of the branch name, and the Contacts CSV export did the same for the linked company — 24-character identifiers in files people open in a spreadsheet.
The Benefits list never loaded employee names, so its Employee column showed a database id.
Team Workspace “Present Today” counted half-day, holiday and week-off rows as fully present — on a public holiday a manager saw full attendance. Those are now counted separately, and an unrecognised status is counted nowhere rather than as present.
The Quote-to-Cash funnel’s “Dispatched” stage looked for two delivery-challan statuses that do not exist, so it always fell back to counting every challan including drafts and cancellations. Its “Paid” stage counted proforma advance receipts rather than tax-invoice collections — a different document on a different path, which could exceed the stages above it.
Verified
HR 673/673 including a new case proving the PF ceiling toggle reaches the payslip, CRM 733/733, platform 8423/8423 — fully green.
Version 1.1.41
Deal figures and company names that stopped at 200 records
The Deals cards contradicted the Total beside them, and Deals and Contacts showed a dash for any company outside the first 200.
Fixed
The Deals screen’s Open, Won and Open Pipeline Value cards were computed from the 300 rows already fetched for the pipeline board, while Total Deals used the real count — so the four cards contradicted each other as soon as the pipeline outgrew that page, and the money figure was the one that quietly went missing. All four now come from one server aggregate over the whole pipeline, scoped to the viewer the same way their list is.
Deals and Contacts resolved each row’s company and contact name against a separate 200-record fetch, so anything outside it rendered a dash — indistinguishable from a record with no company at all. The list now returns the linked names with the rows.
Both edit forms still submit a plain reference, so opening a record for editing keeps its company selected rather than blanking the picker.
Verified
New CRM list contract suite 4/4, CRM 733/733, platform 8427/8427 — fully green. TypeScript and build clean.
Version 1.1.42
HR screens that mistook a page of records for the records
A leave tab that told you an employee had no leave, an attendance register with no names past employee 200, a monthly card that under-counted, and a register showing 100 of 340 employees with no way to see the rest.
Fixed
Employee 360’s Leave tab read “No leave requests yet” for anyone whose requests fell outside the newest 200 in the company. It fetched the company’s recent leave and filtered it on screen, so a statement about company volume was presented as a fact about the person. It now asks for that employee’s leave.
The attendance register showed a dash instead of a name from employee 201 onward, because names were matched against a separate 200-employee fetch. Each row now carries its own employee.
“Approved This Month” counted approvals within the 200 most recent approved requests, so past that point it could only under-count — silently, while reading like a fact about the month. It is now counted by the database over the month itself.
The HR Employee Register rendered 100 rows, printed the true total underneath and offered no way to reach row 101 — which reads as “here are all 340 employees” while showing 100. It now says how many of how many, and pages.
Verified
New HR list contract suite 5/5, HR 673/673, platform 8431/8432 (the one failure is an unrelated timing-sensitive test). TypeScript and build clean.
Version 1.1.43
Compliance tiles stuck at zero, and other figures that misread themselves
Every e-invoice tile read a field that does not exist, expired e-way bills were counted in the wrong 100 rows, the leakage KPI counted resolved cases, appointment lists showed the oldest entries ever, and a failed audit-log fetch read as “nothing happened”.
Fixed
Every e-invoice tile on the Compliance dashboard sat permanently at zero. It read a top-level field that does not exist — the real status is nested — and fell through to the invoice’s own status instead. Counts now come from the server, over every candidate rather than the first hundred rows.
“Expired E-Way Bills” was counted within the 100 most recent bills. Sorted newest first, those are the least likely to have expired, so the tile under-reported almost by construction. It is now counted over every bill.
“Open leakage” counted cases of every status, including resolved and dismissed ones, and stopped rising at 500 however many there were. It now counts open cases, uncapped.
Appointments and Scheduled Demos listed the oldest scheduled activities ever recorded, so with any real history no upcoming appointment appeared — a schedule that was in effect an archive. With no date filter they now start from today.
A failed audit-log fetch on Closing & Audit Log rendered “No audit entries found” — a statement that nothing happened, on the one screen whose purpose is to evidence that something did. It now says the load failed.
CRM Quotation detail rounded every amount to whole rupees, printing a real balance due of ₹0.40 as ₹0 — paid in full, on a screen customers are shown.
The Leads CSV export wrote the owner’s database id in the Owner column instead of their name.
Verified
New contract suite 5/5, CRM 733/733, platform 8437/8437 — fully green. TypeScript and build clean.
Version 1.1.44
A reconciliation that said no match existed, and controls that failed in silence
Bank reconciliation reported that no journal line matched an amount whenever the entry was an old one, and four controls sat empty and unusable without saying why.
Fixed
Bank reconciliation searched the 200 most recent unreconciled journals and only then compared amounts, so if the matching entry was older it reported “No unreconciled journal lines match this amount” — a statement that the entry does not exist, about one that does. The amount is now part of the query, so the limit applies to entries that actually match. The line conditions also bind to the same journal line, which they previously did not.
The Approval Inbox printed 24-character database ids for “Requested by” and “Current step” whenever the viewer could not read the employee directory — and for anyone past the 200th employee, because the directory was only ever fetched one page deep. It now pages, and an unresolved reference reads as text saying which situation it is.
The tax-invoice “New invoice from SO” picker discarded every load failure, leaving Create draft disabled behind an empty list with no reason shown. A permission failure now says so.
“Record receipt” could offer no bank account and no explanation, leaving a form that could never be submitted. It now says whether no receipt account is configured or the lookup failed.
The estimate form’s Customer field is required by the save but its label never said so, and an empty picker gave no hint whether the lookup had failed or no company exists. Both are now stated.
Verified
New contract suite 4/4; platform 8441/8441 — fully green. TypeScript and build clean.
Version 1.1.45
An unpostable invoice says so while you are still drafting it
A tax invoice whose place of supply cannot be determined is refused at posting. It now warns on the draft instead, naming the two records to fix.
Changed
A draft tax invoice carrying tax whose CGST/SGST vs IGST split cannot be decided now shows a warning on the draft itself, naming the business unit and the customer account as the records to fix. The refusal at posting is unchanged and correct — charging a guessed tax is worse than refusing — but discovering it only when Post is pressed meant building the whole invoice first. The draft has carried this information since the split began running on every draft write; it simply was not shown.
Note
Setting a GSTIN or state on the Head Office business unit is a one-field configuration step, and is required before any taxed invoice can be posted.
Version 1.1.46
A tax cliff, two permissions nobody could hold, and a tile with no source
Earning ₹600 more could cost ₹62,493 in tax; two agreement features were unreachable because their permissions were never declared; and a dispatch tile reported zero when it had nothing to measure.
Fixed
Income tax had a cliff at the Section 87A rebate threshold: crossing it by ₹600 attracted the full slab tax of ₹62,493, leaving the employee materially worse off for earning more and putting ₹5,208 a month on their payslip. Statutory marginal relief now caps the tax at the income earned above the threshold. It applies on both the governed slab path and the built-in fallback, and can only ever reduce tax.
The usage-evidence table and “Attest usage” action on a Commercial Agreement were unreachable for everyone except a full module administrator, because the two permissions their routes require were never declared in the permission catalogue and so were never created. Both now exist and are assignable; the commercial-ops manager role that owns period attestations picks them up.
“Ready to Dispatch” reported 0 on any installation not running the fulfilment-planning engine — the only thing that ever sets the field it counts — so it stated a fact it had no source for. It now reads “Not tracked” in that case, and explains why. A genuine zero under a running engine still shows 0.
Note
Marginal relief is applied to income tax before cess, which is the standard computation. Net pay therefore still dips by the cess on the marginal income — about 4% of it — rather than by the whole slab tax. Capping the tax inclusive of cess would remove even that, but would withhold less than the usual treatment, so it is not done without a ruling.
Verified
New statutory contract suite 9/9 including the exact case from the audit, HR 673/673, platform 8451/8451 — fully green.
Version 1.1.47
Three caps a cross-check caught
A reconciliation table that stopped at 200 lines, an account picker that lost everything past the first 200, and a vendor form still showing blank boxes for fields it cannot read.
Fixed
The bank reconciliation table rendered the first 200 statement lines and stopped, while the summary tiles above it counted every one — so on a larger statement the totals described a set the table could not show, and those lines could not be reconciled at all. It now pages and states how many of how many.
The journal entry’s account picker loaded only the first 200 accounts, which is also the server’s maximum page, so a larger chart of accounts silently lost its tail: those accounts could not be posted to, and an existing line referencing one showed a database id instead of a name. Every page is loaded now.
The vendor form showed empty Tax and Bank boxes to roles that cannot read those fields, which reads as “this vendor has no GSTIN” when it has one. Those roles now see a short note instead, confirming that values already on file are preserved when they save.
Verified
New contract suite 3/3; platform 8454/8454 — fully green. TypeScript and build clean.
Version 1.1.49
Proforma invoice rebuilt, employee documents become a list, three modules move
The Proforma Invoice now prints like the Tax Invoice instead of a basic layout, and a discount bug in its figures is fixed. Employee documents are a list you add to, with a type, number, issue and expiry date and attachments per document. Compliance now sits under Accounts, Developer Tasks under SaaS Commercial, and Role Dashboards under HRMS.
Fixed
Proforma Invoice: the printed taxable value ignored line-item discounts. It read the gross line total minus the header discount, so on any quotation with a line discount the subtotal was overstated by exactly the line-discount total and disagreed with the grand total printed beside it.
Proforma Invoice: the tax split was assumed rather than resolved. Where either GSTIN was missing the document printed no tax at all while still charging it; the place of supply is now resolved from the customer GSTIN or, failing that, their address state, and a genuinely undeterminable one prints a single GST column and says so rather than asserting a split nobody established.
Proforma Invoice: no logo, no CIN or registration line, and no authorised signatory, because the document read company details from a settings field that no longer exists. It now uses the same business-unit and legal-entity letterhead every other document does.
Changed
Proforma Invoice: rebuilt to match the Professional GST Tax Invoice — letterhead, Bill To and Ship To with place of supply, an item table whose tax columns follow the supply type, a GST summary by HSN or SAC, an ordered totals panel, amount in words, receiving-bank details, payment status against the amount received, commercial terms and an authorised signatory, with a footer that repeats the non-tax-invoice statement and the document number on every page.
Employee documents: a list you add to. Each row records the type of document, its number, issue date, expiry date where the type expires, and its attachments — so two education certificates or three other documents can be filed separately. Aadhaar Card and PAN Card are unchanged, keeping their fixed front and back upload slots with no detail capture.
Navigation: Compliance moved under Accounts, Developer Tasks under SaaS Commercial, and Role Dashboards under HRMS. Every destination stays reachable and keeps the exact permission it had; a compliance-only, approvals-only or dashboards-only user still opens the section their work is in and sees nothing more.
Version 1.1.50
Organization chart rebuilt as a real hierarchy
The organization chart is a top-down tree instead of an indented list, with a focus view for one person and their reporting line. Search, zoom and Fit to screen actually work, the chart is navigable by keyboard, and the same chart reads as an outline on a phone.
Changed
Organization chart: rebuilt to the approved Classic hierarchy concept — a top-down tree with connectors drawn to each card, replacing the indented list. Cards match the employee directory: photo, name, designation, employee code, status and direct-report count, with initials where a photo is missing or unreadable.
Organization chart: selecting a person opens the Focus view — their manager, themselves and their direct reports, beside a panel with their code, department, resolved manager and report count, and a link to their full profile. The manager section is omitted for someone at the top rather than shown empty. Returning to the full chart restores the position and zoom it was left at.
Organization chart: the toolbar controls all do something. Search reveals a match and opens its reporting line rather than filtering people out of the chart, and says plainly when nobody matches. Zoom is bounded and shows its level, and Fit to screen measures the chart against the window.
Organization chart: the chart and the phone-friendly outline are the same content, restyled — so an employee is never listed twice for a screen reader, and the two cannot drift apart.
Fixed
Organization chart: the chart claimed to be a navigable tree but had no keyboard handling at all, so every node was reachable only by tabbing through the whole organization. Arrow keys now move between people, expand and collapse, and Enter opens someone.
Organization chart: the spoken description of each person replaced their own card contents, which silently hid their employment status and any reporting-line problem from screen readers.
Organization chart: an employee recorded as their own reporting manager was reported as a generic reporting cycle. It now says exactly that, because it is a single-record correction rather than a puzzle.
Organization chart: the keyboard focus outline was drawn around a manager entire team instead of the person focused.
Organization chart: connector lines were drawn a few pixels to the left of the cards they pointed at, and the clear-search button was below the minimum touch size.
Verified
The reporting-line logic moved into its own module so it could be tested for real rather than by reading the source: multiple tops, managers recorded as text or as a linked record, missing managers, self-references, reporting cycles, a sixty-deep chain, and direct-report counts.
Frontend suites 1,432 checks; production build, type checking and interface governance clean; no sideways scrolling and no undersized controls at desktop, tablet and phone widths in both light and dark.
Version 1.1.51
Employee cards show the real role, and stop wasting a third of themselves
Every employee card in the directory was labelled "Support" regardless of the roles actually assigned. Cards also carried a large empty gap, could shear a long name with no way to read it, and could show a deputation that had already ended.
Fixed
Employee directory: the Role on every card read "Support", whatever roles the employee actually held — including people with no login at all, whose own Login row on the same card said "None". The directory was not loading the assigned role names, so the card fell back to a coarse account setting that is "support" for everyone by default. Real role names are loaded now, and where a role genuinely cannot be resolved the card says so instead of inventing one.
Employee directory: a long name or job title could be cut off on the front of a card with no way to read the rest. Both now wrap, and the identity area gives way rather than pushing View profile and Details off the card.
Employee directory: a card could keep showing "Deputed to …" after the deputation had ended, while the table row for the same person showed nothing. Both now agree.
Employee directory: every card carried about 90px of empty space between the status badge and its buttons. The card is shorter by that much, with nothing lost.
Verified
A new backend check drives the real directory endpoint to prove role names arrive resolved, and pins the account setting as a last resort rather than a stand-in for a role.
The check protecting the rule that flipping a card is not a permission boundary was rewritten: it could previously pass with contact details sitting outside the permission gate. It now fails on exactly that.
Card geometry measured at desktop, tablet and phone widths against the real application chrome: four columns, two, then one; the card cannot change size when flipped; the loading placeholder matches it exactly; no sideways scrolling and no undersized controls.
Version 1.1.52
Experience totals that are true, bank details that can pay someone, addresses that agree
An employee with a blank end date on an old job was credited with every year since — one 2015 row alone read as eleven years and eight months, under a heading that called it verified. The employee record also accepted anything at all as an IFSC code, held too few bank fields to produce a bank transfer, and recorded country, state and city as free text. The organization chart used about a sixth of the screen it was given.
Fixed
Employee record: total experience was wrong in six of eight cases checked. A previous job left without an end date was counted as still running to today — a row starting in 2015 added eleven years and eight months that nobody worked. A job recorded as ending in 2032 was counted in full. Working from 31 January to 1 February counted as a whole month, and a single leap day counted as a month. A job whose end date was before its start was dropped from the total with no trace. All of these are corrected.
Employee record: the figure labelled "Verified total including current tenure" counted every dated job whatever its verification status. Verified experience is now its own separate figure, computed only from jobs actually marked verified, and the combined total is called what it is.
Employee record: jobs that cannot be counted are now listed with the reason — no end date, end before start, start in the future — instead of quietly lowering the total. A blank end date is treated as unknown, not as ongoing; where someone genuinely still works there, a new "Still working here" tick states it.
Employee record: saving the form discarded the internal identifiers on each previous-employment row, so documents attached to a particular employer lost track of which employer that was. The identifiers now survive a save.
Employee record: the Bank IFSC code field accepted any eleven characters — "abcdefghijk" and "1" both saved onto the account a salary is paid into. It is now checked against the real IFSC format, the same rule the company’s own bank accounts have always been held to. The candidate self-service onboarding form, which was the loosest of all at fifteen characters, is held to the same rule.
Organization chart: the chart sat in a short box with the rest of the window empty below it, and could not grow past about two thirds of the screen however much room there was. It now fills the space available — measured at 184px before and 813px after on a 1176px-tall window. On a short window it keeps a usable minimum and the page scrolls instead.
Employee record: country, state and city on both the permanent and communication addresses were free-text boxes, so "Punjab", "punjab", "PB" and "Panjab" were four different states and nothing could group or report on where people are. All three now come from the same governed location list the CRM Lead form uses.
Added
Employee record: a Look up button beside the IFSC code fills the bank, branch, branch address and MICR code from the public bank directory, so they no longer have to be typed. The screen states plainly that this confirms the branch only — it does not check the account number.
Employee record: the disbursement account gained the fields a bank transfer actually needs — account holder name exactly as the bank has it, account type (savings or current), branch, branch address, MICR code and UPI ID. The account holder name is asked for separately and never guessed from the employee’s own name, because a bank matches on the name it holds.
Every one of the new bank fields is recorded in the employee’s change history and carries the same restriction as the account number, so none of them can be read by someone not entitled to see bank details.
Employee record: the experience figures shown while editing now follow exactly the same rules as the ones stored on the record, so the preview and the saved value cannot disagree. Contradictory rows — marked ongoing and given an end date, or an end date before the start — are refused by the server as well as the form.
Verified
The experience calculation was measured against the shipped version first, case by case, so every claim above is a number rather than an assertion. Twenty-three new checks cover month boundaries, leap days, overlapping jobs, gaps between jobs, unknown and future dates, and the verified subset.
The IFSC rule now exists once and is shared. A check proves the copy the browser uses and the copy the server enforces are character-for-character identical, so they cannot drift into disagreeing about what an IFSC is.
Chart height measured against a reproduction of the real application chrome at three window sizes, including a short window where the page is expected to scroll rather than the chart to be crushed.
Thirteen new backend checks and twenty new frontend checks. Every new safeguard was deliberately broken to confirm it fails — including one that caught a new check quietly registering nothing while still reporting success.
Version 1.1.53
Bank details are restricted to the people entitled to see them
Anyone who could open the employee directory received every employee’s bank account number and IFSC in full. Worse, a reporting manager approving a subordinate’s leave request, expense claim or resignation received that subordinate’s account number in the approval response — without holding any employee permission at all, and without being able to open the directory. Bank details now require a dedicated permission.
Fixed
Employee bank details — account number, IFSC, bank, branch, branch address, MICR, account type, account holder name and UPI ID — are no longer returned to everyone who can read an employee. They now need the dedicated "View bank and tax details" permission, the same restriction a supplier’s bank details have always had.
The more serious case: eleven approval and decision screens returned the employee’s whole record alongside the decision, bank details included. Seven of them require no employee permission at all — a reporting manager reaches them through the reporting line. So approving a subordinate’s leave, expense claim, regularization, move-out or resignation handed over their bank account number. All eleven are now restricted.
The onboarding checklist keeps its own copy of what a candidate submitted, including their bank details, and it is read under a different permission. Completing a single onboarding task on a subordinate returned that copy. It is now restricted the same way.
Changed
The Salary A/C Details section of the employee form is hidden from anyone without the permission, and says so plainly instead of appearing empty. Showing empty boxes that accept typing and then quietly discard it would be worse than saying no.
An edit made by someone without the permission can no longer clear bank details. The form sends every field on every save, so without this a manager changing a phone number would have wiped the account number — silently, and discovered on payday. Those fields are now left exactly as they were.
The IFSC Look up button needs the same permission as the fields it fills.
Verified
Twenty-two new checks cover all nine fields, list rows, records nested inside an approval response, the onboarding copy, and the rule that an edit without permission cannot clear anything.
Nine deliberate breakages confirmed each safeguard actually fails when removed — including dropping the restriction from a single one of the thirty protected routes, and moving one input outside the hidden section.
Version 1.1.54
Approval screens stop handing over the whole employee record
Approving a subordinate’s leave, expense claim or resignation returned that person’s entire employee record in the response — salary, PAN, Aadhaar, personal email and home address included. The previous release restricted the bank details on these screens; this removes everything else that was never needed there.
Fixed
Fourteen approval and decision actions returned the employee’s complete record alongside the decision. Seven of them need no employee permission at all — a reporting manager reaches them through the reporting line — so approving a subordinate’s leave request, expense claim, attendance regularization, late check-in, move-out or resignation disclosed their salary, PAN, Aadhaar, personal email address and home address. Each now returns only the identifying details the screen actually shows: employee code, name, and where relevant department, designation and status.
Release 1.1.53 restricted the bank details on these same screens. That closed the field that had been reported; this closes the rest of what was riding along with it.
Verified
Established before changing anything that nothing depends on the removed fields: internally these actions read only the employee’s id, code, name and reporting manager, and where real work needs the full record it already loads it separately. On screen, every one of these actions either ignores the response and reloads the list or reads a field that is not part of the employee.
Each action now returns exactly what the matching view screen already returns for the same record, so nothing on screen can be reading a field it no longer receives.
Six new checks, and five deliberate breakages to confirm they fail — including one that caught a check which would have missed a genuine regression, and which was rewritten before this shipped.
Version 1.1.55
The onboarding link is treated as the credential it is
The link emailed to a new joiner is a password in all but name — anyone holding it can submit that person’s PAN, Aadhaar and bank details, with no sign-in. It was stored in readable form and travelled back inside ordinary onboarding responses, including one screen action that needs no permission at all. It is now stored scrambled and never sent anywhere.
Fixed
The onboarding self-fill link was stored in readable form and included in onboarding responses — among them completing a single checklist task, which any reporting manager can do for their own team member without holding an onboarding permission. Anyone who saw one of those responses held a working link to submit that candidate’s KYC and bank details. The link is now stored scrambled, cannot be read back by anyone, and is never included in a response.
The link is now shown exactly once, in the email it is sent in — the same place it always went. Nothing else can retrieve it, including the system itself.
Changed
Links already emailed to candidates keep working. Nobody needs to be chased for a resend.
Sending a fresh link now properly cancels the previous one. It did not before, which was found while testing this change rather than assumed.
Verified
Fifteen new checks, including that a link already in a candidate’s inbox still opens, that re-sending genuinely invalidates the old link, and that the stored value can never be turned back into a working link.
Seven deliberate breakages confirmed each safeguard fails when removed — including one that caught a gap in this change while it was being written, and another that caught a check which was not testing what its name claimed.
Version 1.1.56
Housekeeping: a database update was numbered the same as another team’s
No change to how anything behaves. The pending database update shipped in the previous release carried the same sequence number as one another workstream had already prepared, which would have stopped both from running. Renumbered before either was applied.
Changed
The database update that accompanies the onboarding-link change was renumbered so it no longer clashes with an update prepared elsewhere. Nothing had run yet, so there is nothing to undo and no effect on any record.
Version 1.1.30
Letterhead, logo and fonts on every generated document
Generated documents could never show the company logo, never applied their fonts and carried no letterhead at all. All three are fixed, and the GST Tax Invoice, Sales Order and Payment Receipt were rebuilt against their reference designs.
Fixed
The logo could never appear on any generated document. Branding stores it as an asset path the renderer has no base URL to resolve, and the obvious fix — inlining it — was silently rejected by the renderer’s URL guard. Both halves are fixed, and the API now carries its own copy of the brand wordmarks so the default resolves wherever the web root is deployed.
The fonts never applied, for two independent reasons: the stack led with typefaces the Linux render host does not have, and design-token values were HTML-escaped into a style block, where character references are literal text — so the declaration was discarded outright.
Documents were printing with no company letterhead at all. Eight controllers built their company information from a settings field that was removed some time ago, so the lookup returned an empty object every time. The letterhead now comes from the document’s Business Unit and Legal Entity, which also supply the CIN and the authorised signatory.
Changed
Professional GST Tax Invoice and Compact Sales Order rebuilt against their reference designs — logo and full letterhead, per-column alignment and widths, a TOTAL row summed from exactly the lines above it, the HSN-wise GST summary, Bill To / Ship To panels, bank and declaration blocks and the signatory panel.
Nothing was invented to fill those references. There is no website field anywhere in the schema, so that line is absent; a sales order has no currency field, so the reference’s Currency line is not printed rather than filled with a constant.
The Payment Receipt has an adapter at last — the format shipped with a complete data contract and no code to build its data. Only a genuinely posted journal entry reads as Settled. The instrument reference and bank account number are masked, and anything under eight characters is withheld entirely rather than “masked” into disclosing most of itself.
A governed way to get a format change onto an environment that has already booted. The catalog seed is insert-only by design, so editing a format had no effect anywhere that had started once; republishing now runs the same fork, preflight and publish flow the Studio uses, and a definition that fails preflight is refused rather than shipped.
Verified
Report Format Engine suite green: 408 tests, including new coverage for the logo fix and for the inline URLs that must still be refused.
Existing formats render byte-identically — the new ruled totals and header-band styling are opt-in per format.
Version 1.1.31
Uploads survive a deploy
Every deploy had been silently deleting every uploaded file. Uploads now live outside the application tree, the restored files are back in place, and documents render with real fonts, real icons and the dark-ink logo.
Fixed
Every deploy was destroying every uploaded file. The API served /uploads from a directory inside its own tree, and each release swaps a freshly staged tree into place. Uploads now live outside the app tree and are symlinked back in on every swap; the restored files are back (7,995 on production, 5 on pilot).
An uploaded logo is read from disk, not fetched over HTTP. For an uploaded logo that URL is served by the very API doing the rendering, so the document depended on a network round trip that could 404 — and did. A genuine external URL is still left to the browser.
Reports always use the dark-ink logo. The branding variant names describe the surface, not the ink, so on white paper only the orange chevron survived.
Documents render in a proportional typeface. The render host carried two font families, one of them monospace, so every PDF printed like a typewriter whatever the format asked for.
Icons are inline SVG. The glyphs used before have no coverage in the fonts that host carries, so they printed as empty boxes sized by font metrics rather than by the document.
Changed
Names are cased for print — a contact saved as “subhash malik” reached a customer exactly like that. Applied to names only: a word already containing a capital is left alone, so product codes and initialisms survive untouched.
The estimate’s itemised discount is a column, showing the percent entered with the amount beneath, rather than a note tucked under the item name.
The build stamp reads in 12-hour IST with AM/PM, and the product version increments per publish.
Version 1.1.32
Settings for five modules, and Email Templates where you would look for them
Sales, Purchase, Assets, Compliance and Order Fulfilment had no settings group at all, so their email templates and document formats were reachable only by someone who already knew the URL. Each has one now, and the 196-template email catalogue is in Application Settings.
Added
Sales, Purchase, Assets, Compliance and Order Fulfilment each have a footer-pinned Module Settings group carrying that module’s own Email Templates and, where the format catalogue actually holds one, Report Templates — 33 Sales templates and 10 formats, 19 Purchase and 4, 5 Fulfilment and 1, 5 Assets & Fleet, 2 Compliance. Each link is gated on the permission its destination requires, so a shortcut is never a dead link.
Email Templates is in Application Settings. The 196-template catalogue had no entry there at all — “Transactional Email” is the SMTP relay, not the messages. It spans 26 modules, so it now has a platform route to match; the old accounts route still works.
Sales, Purchase and Order Fulfilment appear in the Business Module Settings directory, which previously could not answer “where do I configure Sales?” for the three modules whose documents customers and suppliers actually receive.
Fixed
Seven of the thirteen live report document types were invisible in the Studio. Its picker named one key wrongly and omitted six others outright, so the entire Purchase document set could not be filtered for and rendered with its raw key as a label. A contract test now pins the picker and the catalogue to each other in both directions.
Nine email templates had no module, and the API filed them under a bucket no template actually declared. They now declare Sales, Payments and Marketing, and the fallback says “Unclassified” rather than inventing a home for a template whose key has left the catalogue.
Changed
Approvals and IT & Infrastructure now live inside Developer Tasks — two fewer top-level sidebar apps, with every item keeping the exact gate it carried as its own app. The group-level developer permission moved onto the individual items, so the infrastructure team’s own settings are not hidden behind a developer key.
Version 1.1.33
One document engine, and the pendency it was hiding
Estimates and quotations could resolve three different renderers, which is why format changes kept appearing to be skipped. There is exactly one now, and the HR, CRM and ledger defects that had been sitting behind it are fixed.
Changed
A document now has exactly one renderer. Which of the three won depended on what happened to be published, with nothing on screen saying — so a change could land in an engine the document never reached. Every other document type had already been cut over; estimates and quotations had not. When no governed format is published the download now refuses and says so, rather than silently printing a different layout.
Fixed
The Executive Estimate splits tax the way its reference does — CGST/SGST, or IGST — determined from the seller’s and the customer’s GSTIN state codes. A missing or malformed GSTIN keeps the single Tax line rather than guessing, and the rate is named only when every taxed line shares one. The footer also numbers pages properly instead of printing “Page 1” on every page.
Issued documents recorded an undefined template version, so a PDF could not name the revision that produced it.
Collapsing a manager on the organization chart accused their whole team of broken data — one traversal both marked nodes visited and stopped at a collapsed manager, so the “find cycles and disconnected records” pass swept up every hidden report and re-listed them at the top as hierarchy errors. Reachability is computed over the whole graph now; only rendering knows about collapse.
Two screens silently truncated the organisation at 500 employees — the employee directory’s Reporting Manager picker and the org chart. Anyone reporting to employee 501 or beyond read “Not available”, indistinguishable from a broken reference. Both page to the end, and an incomplete fetch says so instead of blaming the data.
The employee card printed a raw database id as the role. An unpopulated reference serialises to a string, so the “it is already a slug” branch took it.
Employee salary is labelled “Legacy monthly salary” and states that an approved Salary Revision is what payroll pays — which the backend has enforced for some time, while the screen still presented the old number as authoritative.
Employee 360’s Expenses tab said there was no Expense entity. There is; the tab lists that employee’s claims, behind a per-employee filter so the screen does not fetch every claim in the organisation.
Digital Employee ID download and print work. The badge code is derived rather than stored, so a card re-renders identically without keeping a recoverable token at rest, and a five-minute on-screen QR was added for gate and reception verification.
“My Day” led only to “My Day is unavailable” — its projection is pre-seeded disabled and checked fail-closed. The link is gated on that flag and appears when it is enabled.
Thirteen sidebar entries had icons that do not exist, including Experience Letters and every Command Center, so they rendered as blank space.
Overlapping controls in the document template editor: the style-swap button and the structure-locked badge both positioned themselves at the same corner, so the badge covered the button.
The ledger’s base-currency conversion assumed a scale of 2 — right for INR and USD, wrong by a factor of a hundred for a zero-decimal currency. It reads the currency’s own scale now.
The AI-summary thumbs-up and thumbs-down on Customer 360 and Lead detail wrote to the browser console, or nothing at all. There is no feedback store, so the control is off rather than pretending to record an opinion.
Version 1.1.34
The release note catches up with the version number
Six releases shipped with the version number updating and nothing written down behind it. The missing entries are here, 26 test fixtures that had been shipping as release notes are gone, and a version with no release note can no longer be built.
Fixed
Six releases shipped with no release note. The build copies the product version into the footer, the account menu and this screen, so all three always named the running version — and nothing checked whether anyone had written down what that version changed. 1.1.28 through 1.1.33 shipped while this history still ended at 1.1.27. Those six entries are written below.
26 test fixtures were shipping as release notes. This history is a tracked file the release tooling writes to, and before the test suite was isolated from it, it published fixtures straight into it — rows titled “RM-8 test release” and “RM-3 gate test release” at versions 7.x through 10.x, each with an empty body. They are gone.
Changed
A version with no release note now fails the build. A reminder would have been forgotten the same way the last six were, so the check sits on the script that stamps the version itself and names the changelog headings to source the content from. Running the app locally only warns — a developer working on their own machine has not shipped anything. The same check rejects a duplicate version, a malformed date, an empty entry and the test-fixture shape.
Version 1.1.28
Recovered settings screens and the Delivery Challan download
Seven configuration screens that could only be opened by typing their URL are back in the sidebar, the Delivery Challan can be downloaded at last, and line endings are decided by the repository rather than by each developer’s machine.
Added
Seven settings screens recovered from URL-only access — Report Customizer, Report Formats, Document Block Templates, the Block Palette, Email Block Templates, CRM Integration Governance and platform Operations. Each had a working route, a component and a permission, and no sidebar entry at all.
CRM message templates moved into Module Settings, alongside the rest of that module’s configuration rather than under Communications. A move, not a copy — a second entry to one screen is the duplicate-destination pattern that was removed earlier.
Delivery Challan PDF download — the only Sales document with no download path at all. The document states quantities and no pricing, and every field the model cannot supply stays absent rather than blank.
Fixed
Line endings were decided per developer rather than by the repository, so any test comparing file content passed on CI and failed on Windows for a reason that had nothing to do with the code under test.
Verified
Frontend suite green: 145 spec bundles, 1,060 specs.
Delivery Challan report-format adapter: 13 focused tests, with adjacent document suites green (35 tests).
Navigation gates within limits — reachable destinations 348 → 354, visible menu depth still 2, dead-route audit clean.
Version 1.1.29
Superseded document editors kept out of navigation
Four replaced document editors that the previous release listed in the sidebar are retired again — they stay reachable by URL, as their retirement plan requires — and Report Formats moved beside the Studio it belongs with.
Fixed
Four superseded document editors removed from navigation again — Report Customizer, Document Block Templates, the Block Palette and Email Block Templates. Their absence was deliberate, not an oversight: they are the two legacy families the Report Format Studio replaces, and listing them again steered users toward the engine being phased out.
No route, component, permission or endpoint changed. All four stay reachable by URL and by deep link, which their retirement plan requires.
Changed
Report Formats — the one screen of the five that is genuinely current — now sits in the existing Documents & developer group beside Document Template Studio, rather than alone in a group of one.
Verified
A guard test pins the four retired destinations out of navigation and Report Formats in. The mistake is recurrent by construction: any sweep that reads “routed but unlisted” as a defect will rediscover these four, so the reason they are absent is now recorded where that sweep will find it.
Version 1.1.27
Field-level validation messages and restored regression gates
Every validated field now names its own problem instead of relying on a form-level banner, two Save buttons that blocked silently are fixed, and the automated test suites that had been skipped rather than passing are running again.
Fixed
Regional Defaults: Default country and Default phone country code blocked Save while showing no message at all.
Added the missing error text to 64 validated fields across HR Salary Structure (authority, engine, policy packs, statutory masters), CMS Media Library, CMS Navigation, Location Management, Sales Invoices and Regional Defaults. Each field now states its own problem instead of a banner listing field names in prose.
Assets: Fleet menu items shared hide-keys with Asset menu items, so hiding Asset Register also hid Fleet Tracker, and hiding Asset Maintenance also hid Vehicles.
Industry Packs, in both Product Engine and Work Management: the page heading rendered twice while creating a pack.
Estimation & Quotation commercial dashboard: the tab read "Approval Requests" while the page it opens calls itself "Approval Inbox".
Marketing website: a duplicate export stopped all three sites building, and every CMS media block would have failed to render.
Quality and verification
The four backend test suites had been reported as skipped rather than passing: they depend on a static-analysis job that was failing on both this branch and main, so CI never ran them. Repairing that job ran them for the first time and surfaced 90 failures, all now fixed.
Roughly half were real defects rather than out-of-date tests, including sales-order pages that would fail to load whenever their controller was the first thing loaded, and a lead-routing lease that was validated against a different clock than the one that granted it.
The website build gate now checks the page count the build itself reports, so it no longer demands a shape that publication gating is designed not to produce.
Version 1.1.26
Guided access setup and professional report review
Simplifies RBAC role authoring, brands password recovery and exposes the next six professional accounting formats for governed Studio review.
Added
Added guided module, access-breadth and role-template controls with an effective-access preview and advanced matrix fallback.
Made custom non-CRUD actions such as approve, publish, post and issue visible in the canonical permission matrix.
Added realistic draft previews for Payment Receipt, Purchase Order, Goods Receipt Note, Delivery Challan, GST Debit Note and Internal Vendor Bill Approval Sheet.
Added Payment Receipt PDF download to the Sales Receipts list.
Security and communication
Moved password-reset email onto the enterprise branded shell with a Reset password button and single-use expiry notice.
Reset destinations now come only from the installation-configured frontend origin, never a caller-supplied redirect base.
Guided access presets do not bypass ownership, reporting-hierarchy, business-unit, record-state or feature-flag checks.
Version 1.1.25
Professional report rendering and designer typography
Makes URE previews and PDFs render as print-ready documents and exposes safe typography and image-size controls in Report Format Studio.
Fixed
Applied one shared print stylesheet to preview and PDF output for headers, footers, tables, totals, signatures, images and pagination.
Added direct document font, body-size, table-size and maximum-image-height controls to Report Format Studio.
Certified invoice and credit-note mappings against the live URE adapters instead of the removed legacy adapter utility.
Added professional typography and density defaults to the six bootstrapped URE catalogue formats.
Quality gates
All 368 report-format kernel, format, safeguard, adapter and PDF-pipeline tests pass.
Visual references remain composition and design-intent baselines; record data continues to come only from certified adapters and Pilot fixtures.
Version 1.1.24
Phase 1 UI and backend route reconciliation
Restores completed non-reserved Phase 1 applications to Pilot, aligns the GST feature flag and clears the remaining dead-route and mechanical UI-governance findings.
Recovered
Exposed Assets/Fleet, Library, Projects, Work Management, Fulfilment, Training, Estimation & Quotation, Inventory and Infrastructure in Pilot.
Kept Product Engine, Design Engine and Manufacturing outside this release under their separate ownership and rollout gates.
Aligned GST Verification navigation with the canonical backend feature-flag key.
Repointed Commercial and Work Management dashboard actions to declared, usable application routes.
Quality gates
Dead-route audit now reports zero unresolved links and has no grandfathered baseline exceptions.
UI-governance audit now reports zero blockers and zero warnings.
Page-header audit now passes all enforceable checks.
Version 1.1.23
Live Work Inbox unread count
Keeps the shared desktop and mobile Work Inbox badges synchronized with the employee notification source for every role.
Fixed
Refreshes the employee-scoped Work Inbox count every 15 seconds instead of only once at shell startup for non-approval roles.
Uses the same inbox response for desktop and mobile badges, avoiding conflicting approval-only rendering paths.
Stops the polling subscription when the Platform shell is destroyed.
Version 1.1.22
International phone capture completion
Completes country-aware phone capture in every discovered in-scope flow and makes the default-country configuration visible in Platform Settings.
Fixed
Replaced raw Lead, mobile CRM and Partner Portal phone fields with the shared country-prefix control.
Phone values are normalized to E.164 using the selected country while preserving existing legacy values for editing.
Added a complete libphonenumber country fallback so public Careers, Onboarding and Partner forms remain usable when the protected Location Authority API is unavailable.
Added Regional Defaults to Platform Settings navigation for default country and default phone-country management.
Boundary and verification
Manufacturing-owned phone fields were not changed because that module remains in its separately owned lane.
A frontend contract pins E.164 handling, fallback-country availability and adoption in Lead, mobile CRM and Partner capture.
Version 1.1.21
Recovered navigation, employee cards and branding verification
Restores visible Phase 1 UI integrations that were present in completed branches but lost or masked in the combined Pilot candidate, with explicit residual ownership boundaries.
Recovered
Restored bottom-pinned Module Settings groups and their original routes for CRM, Marketing, HRMS, Accounts, Support, Projects and Work Management.
Restored Platform Settings and Integrations as peer navigation applications while keeping Application Settings focused on Setup Center readiness.
Added the requested employee directory flip-card interaction: identity, organization and reporting summary remain on the front; email, phone and login are on the reverse face.
Retained the previously completed employee accordion form, Quick Capture first step and structured prior-employment table in the integrated source.
Verified
Claude's shared-topbar brand placement remains present across navigation modes; Pilot's configured light/dark full and compact SVG URLs respond successfully.
Theme and Branding still expose Installation Branding, Console Appearance and Brand Preview Studio through Platform Settings.
Frontend regression coverage now pins the employee flip-card reverse-face field contract.
Residual ownership and test status
Manufacturing Module Settings remains excluded from this recovery because Manufacturing is reserved to the Claude-owned lane.
The full frontend gate still reports pre-existing Manufacturing, Asset/Fleet and retired document-adapter expectations; all in-scope CRM, HRMS, Accounts, Support, Projects, Work Management and Settings ownership failures were cleared.
Pilot deployment requires a successful Angular build and human authenticated browser acceptance before production promotion.
Version 1.1.20
Resource-certified CMS and Asset recovery
Recovered completed Phase 1 Asset/Fleet and Websites/CMS work that was omitted or masked during branch reconciliation, with exact Pilot comparison evidence.
New
Restored the completed Asset and Fleet dashboards, registers, maintenance controls and governed navigation.
Restored the Resource-defined three-site CMS migration pack with 39 site-scoped noindex drafts and immutable version lineage.
CMS media permissions now use the certified least-privilege submit, review, approve and archive lifecycle.
Active lead forms enforce the required intake-field contract, and expired or revoked media rights fail closed.
Bugs resolved
Fixed branch reconciliation that dropped CMS migration lineage and unresolved internet-media publication safeguards.
Fixed the Pilot local-preview origin rejection that appeared as a Gateway Timeout during sign-in.
Verification
CMS backend contracts: 246/246 passing.
Asset and Fleet backend contracts: 49/49 passing.
Combined frontend production build succeeds; production promotion remains subject to Pilot human acceptance.
Version 1.1.19
Phase 1 reconciliation and Pilot recovery
Completed Phase 1 work from the handed-off branches is reconciled into one tested Pilot candidate, including restored HR/CRM forms, governed reports, command centers and settings.
New
Restored the completed accordion-based Lead and Employee capture experiences, previous-employment records and attendance bypass mapping.
Included the completed CRM, CMS, Compliance, Support, SaaS commercial and HR salary-authority candidates in the integrated Pilot release.
Restored CRM navigation for My Day, territories, adaptive sequences, governed agents, revenue intelligence and metadata studio, plus CMS media and navigation tools.
Improved
Unified Estimate, Sales Order and Invoice PDF actions now call the governed document download endpoints through the Sales service boundary.
Report generation includes the complete governed format catalogue and legacy-renderer retirement work.
Pilot settings, top navigation and cache/deployment safeguards are retained while completed module work is reconciled.
Bugs resolved
Fixed merge gaps that removed CMS declarations, HR Labour Welfare Fund service routes and sales-document download methods from the combined build.
Fixed the stale Pilot artifact gap that made completed CRM and HR features appear absent or disabled.
Known issues
Production promotion remains subject to Pilot acceptance; this release is for integrated human testing.
Version 1.1.18
Complete Phase 1 Pilot candidate
The committed Phase 1 application candidate is available in Pilot for integrated acceptance testing.
New
The completed CRM candidate and the remaining committed Phase 1 module work are included for integrated Pilot testing.
Improved
Pilot now runs from one committed candidate revision with a reproducible frontend build and API route graph.
Bugs resolved
Closed the deployment gap that left completed workspace changes out of the previous Pilot artifact.
Known issues
Production promotion remains subject to Pilot acceptance and deployment evidence; this release does not itself claim production certification.
Version 1.1.17
Pilot routing and browser cache recovery
Pilot now targets its isolated API consistently and safely refreshes browser application assets after deployment.
Improved
Pilot builds now use the dedicated Pilot API origin and publish a valid Angular service-worker manifest.
Bugs resolved
Corrected a deployment that directed the Pilot frontend to the production API.
Corrected browser cache rules that could retain an older application worker and stale release identity after a Pilot update.
Restored the visible application version to a monotonic release after the working branch regressed it to 1.0.1.
Version 1.0.1
Uploads, honest confirmations, and a readable build stamp
Employee photos now appear, several screens stopped claiming saves nobody made, and the build stamp says when it was built.
New
The build identifier shown on the dashboard, in the account menu and on this page is now the date and time the build was made (UTC), instead of a counter that told you nothing about which build you were looking at.
Improved
Release history is reliably newest-first, including several releases published on the same day — previously the order was arbitrary whenever dates matched.
Test entries published while the release-management tools were being built have been removed from this changelog. They were never real releases and should not have been visible here.
Bugs resolved
Employee photos uploaded successfully but never appeared. They were being written to a storage bucket that is not publicly readable; uploads now go to the correct bucket and photos display.
Seven screens showed a green “Saved successfully” or “Updated successfully” for something nobody did. The worst appeared at the exact moment the application crashed, which could tell you a save had worked when it had in fact failed. Two others reported a save while previewing a design change whose Apply button had not been pressed.
Opening this Version & changelog page announced a save.
The Document Template Studio warned that Experience Letters “will fail” without a published template. They generate correctly using the fixed legal layout; publishing a template there replaces that layout rather than enabling it.
A deployment no longer deletes the server's uploaded-files directory.
Known issues
Deleting a previously uploaded file fails. The storage account is missing delete permission; the file remains in place and nothing else is affected.
Version 1.0.0
Version visibility and release history baseline
This is the first governed changelog entry. Earlier work has not been reconstructed or assigned artificial release dates.
New
The running application version and exact build number are now visible from the application shell.
Users can open release notes inside the application without leaving their current workspace.
The product website and application use the same approved release-history record.
Improved
Version access is available from both the global footer and the account menu, without adding clutter to the main navigation.
Bugs resolved
Resolved the lack of a discoverable running-version indicator and an in-application changelog destination.
Known issues
Release history begins with this baseline; earlier changes are intentionally not reconstructed without verified release records.
Module availability snapshot
Platform status snapshot
A module-by-module summary of what's genuinely available today versus what's in beta or planned. Every line links to the module's full product page, where the same status is broken down capability by capability.