Danvas
Danvas
DashboardSupportWelcome

👤 USER DOCS

User Guides

Getting Started

Getting StartedDashboard & OnboardingApp Settings

Tutorials

Tutorial: Setting Up Shift Tasks & ClosersTutorial: Managing Incidents in the InboxTutorial: Tracking Compliance & Sync StatusTutorial: Operational Workflows with the AI AssistantTutorial: Building & Deploying Custom Checklists

Daily Operations (Staff)

Shift Workspace & TasksService Day SetupDaily Line-UpStaff Service Day ReportsForms

Communication & Chat

Messages & AnnouncementsUnified Operations InboxAI Assistant

Manager & Admin Guides

Daily Line-Up SetupStaff SchedulingManaging LocationsNPS and Guest FeedbackCouponsContacts and Guest HistoryManager CloseoutsDaily Line-Up & ComplianceAnalyticsIncident ReportingWhistleblower Concerns & FeedbackAdmin Tools

⚙️ DEVELOPER DOCS

Getting Started

Getting StartedDevelopmentDeployment Guide

Architecture

Architecture OverviewExplanation: AI Integration & Tenant SecurityExplanation: Dynamic Forms Engine DesignExplanation: Compliance Ledger DesignExplanation: Live Sync & Data FreshnessData FlowArchitecture Decision Records

Core Domain

Core DomainDatabase ReferenceLocations DomainAuth & RBACScheduling DomainReports DomainIncidents DomainUnified Operations InboxLive Sync Data FreshnessToast Sync PipelineNotifications DomainCoupons and Guest NPSAudit Log & Compliance ArchitectureDesign Audit FindingsAI Chat IntegrationAnalytics & Tips Integration

Frontend

Frontend ArchitectureFormsLoading SkeletonsComponentsPWA & Offline ShellScreenshots

API Reference

API Reference

Endpoints

POS Sales APIOptimization Data APISchedule Shifts APIEmployee Export APIReports APIIncidents APIAI Chat APIPush Notifications APIWebhooks APICron API

Contributing

ContributingCode Examples

Security

Security & Compliance

Release Notes

What's New

What's New

Recent changes, hardening rounds, and the new capabilities they unlock

Overview

A running log of the substantive changes that have landed in the last few weeks. Each entry links to the relevant docs page and the source ADR when there is one. Older entries live in CHANGELOG.md at the repository root.

2026-10-07 — Coupon reliability, recovery, and Contact history

PR #4131 merged the Coupon reliability work, and the protected 0632_goofy_doctor_doom migration/rollout completed on 2026-10-07 UTC. The dated production receipt records the exact source, migration, and serving evidence.

  • Authoring — Recoverable operator drafts and saved revision checks protect against reloads and stale edits/publication.
  • Private distribution — One-time private link reveal, durable creation fences, and original-attempt recovery prevent duplicate issuance after a lost reply.
  • Guest sessions and reports — Server-owned expiry, mutation/read coordination, restaurant-timezone presentation, and labeled fulfillment evidence keep status and capacity truthful. Guest confirmation still does not verify Toast.
  • Customer identity and delivery — Canonical Contact locks, merge/consent preservation, authoritative notification workers, and expiry health diagnostics preserve accepted records independently of delivery failures.

See Coupons, Contacts, and Coupons and Guest NPS. Team flags, QR availability, manual real-device/privacy checks, and POS pilot acceptance remain separate from release completion; contactable NPS remains gated.

2026-09-02 — Data sync ownership, release evidence, and app hardening

  • Single-writer ingestion — Dagster now owns Toast ingestion, repairs, analytics, and backfills; legacy Toast writers fail closed, and the admin employee refresh is an idempotent, ledger-backed Dagster request. See Data Sync Pipeline Architecture and Live Sync Data Freshness. PR #2672.
  • Protected production evidence — Migration release preparation now requires pre-staged evidence, exact-SHA binding, and the matching deployment/rehearsal contract before production execution. See Database Migrations and Deployment Guide. PRs #2664, #2497, and #2558.
  • Server-owned app scope and shell — Dashboard reads honor the canonical location scope, while the authenticated shell and responsive layout contracts received the final QA and accessibility hardening pass. See Architecture Overview. PRs #2673, #2674, #2635, and #2644.
  • Dagster admission compatibility — Build admission validates runner labels and uses the portable GitHub API path. PRs #2670 and #2671.

2026-09-01 — Auth, reports, time zones, and release contracts

  • Local authorization is canonical — Clerk remains the identity provider, while local PostgreSQL owns team membership, role, location scope, lifecycle, and employee mapping. Provider role mirrors and trusted-origin edge cases were removed or rejected. See Auth & RBAC, Security & Compliance, and Local Authorization Boundary. PRs #2550, #2622, #2623, #2626, #2634, and #2641.
  • Service Day reporting — Staff reports and manager closeouts now use Service Day grain, deliberate Staff Reviews, server-authoritative publish preflight, and the documented 10–500 character override reason when incomplete tasks need an exception. See Staff Service Day Reports and Manager Closeouts. PRs #2477 and #2495.
  • Calendar exports use strict local time zones, and Slack delivery received P0/P1 path stabilization. PRs #2563 and #2578.

2026-08-31 — Coupons, inbox, analytics, and developer tooling

  • Coupon lifecycle and reporting — Location-scoped authoring, opaque assignment URLs, staff confirmation, guest recovery, redemption reporting, privacy-safe contact handling, and rollout evidence are now documented in the coupon feature contract, manager guide, and rollout runbook. PRs #2440, #2441, #2442, #2443, #2445, #2478, and #2489.
  • Operations Inbox — Purpose-first message intake and the canonical Inbox lifecycle now govern the unified triage flow. See Unified Operations Inbox and the message-management contract. PRs #2476 and #2490.
  • Trusted analytics and contact history — The governed analytics dashboard and minimal contact-card foundation now have repository contracts and route inventory coverage. PRs #2447 and #2481.
  • Online-authoritative PWA behavior — Live reads and mutations remain network-only, while the shell and identity-scoped drafts support safe offline recovery. See PWA & Offline Shell and ADR-0103. PRs #2408 and #2438.

2026-08-30 — Analytics MCP, notifications, and production readiness

  • Analytics MCP now publishes an executable tool catalog with explicit access modes, canonical liveness probes, request-lifecycle certification, and cross-app parity coverage. See the Analytics MCP user guide. PRs #2412, #2415, #2420, #2423, and #2430.
  • Notification ownership moved to the owning package, and the published data-flow page was updated to match. See Data Flow and the notifications package README. PR #2372.
  • Production readiness now uses the same-origin status proxy, explicit environment contracts, and evidence-bound Vercel/Dagster release checks. See Deployment Guide and the production readiness research. PR #2401.

2026-08-29 — Documentation tree and workstation bootstrap

  • Documentation ownership was consolidated across the repository and Fumadocs pages, with navigation, ADR lifecycle, package READMEs, and canonical source links reconciled. PR #2358.
  • Developer onboarding now documents the pinned Bun/Node toolchain, guarded worktree setup, current package ownership, and protected migration path. See Development and the development onboarding guide. PR #2317.

2026-08-07 — Mainline analytics and release hardening

  • Analytics source finality now binds D-1 facts to exact per-location source windows and deployment identity, with fail-closed handling for gaps, failed attempts, and mixed releases (#1785).
  • DQ selection now preserves exact scope/version rows, and discount DQ reference access is explicitly granted (#1786, #1790).
  • Sync correctness now persists Toast employee watermarks, mirrors open-punch writer scope, and aligns snapshot reconciliation cutoffs (#1787–#1789).
  • Operational workflows received boundary and shift/manager-report hardening; duplicate health coverage was removed (#1769, #1781, #1793).
  • Discount and labor contracts continue the deterministic rollout with discount subcategories and 7shifts schedule/labor-variance hardening (#1772, #1773).

2026-08-07 — Sync classification and release confidence

  • Toast discount classification now covers GUID-less reward and percent-off discounts with narrow name rules while preserving review for unknown definitions.
  • Identity resolution is deterministic for Toast employees, 7shifts jobs, and current menu-item canonicalization paths.
  • Release validation includes the exact Playwright smoke marker, Vercel production-build parity, and the simplified fail-fast test pipeline.
  • Tip certification conserves observed denominators across allocation and completed-week certification paths.

2026-08-04 — Task integrity and architecture boundaries

  • Task integrity checks are registered in the DQ framework and run through the daily shift_task_integrity_dq Dagster asset, with the migration-rehearsal runbook documenting operator gates.
  • Architecture enforcement now uses the native Turbo/package boundary policy and bun run architecture:check; the retired package-layering script is no longer a current command.
  • Analytics contracts continue the evidence-first rollout for labor, tips, identity, and canonical health serving.

2026-06-30 — Messaging Simplification, Service Day Consolidation & Incidents Triage

  • Communication Simplified — Slack + Web Push now cover team chat, notifications, and alerts. See Messages & Announcements, Incident Reporting, and AI Assistant.
  • Service Day Setup Consolidated — Roster now shows FOH staff only with prefill reason chips (Scheduled / Through close / Manual). Closer dropdown with ⚠ Closer recommended warning when daypart has staff but no closer. See Service Day Setup.
  • Incidents Triage Panel — Dashboard (/incidents) now shows summary chips (open · critical/high · aging · unassigned), filter chips with URL persistence, and incident cards with severity rail, owner, age, and status. Aging thresholds: 72h amber, 168h red. See Incident Reporting.
  • Navigation Overhaul — Sidebar reorganized into Today / Service Day / Review / Team / Insights / Administration sections with role-based visibility. See Admin → Navigation.
  • Manager Staff Reviews — Migrated to employee-centric model (employee key instead of user ID). Can review unlinked employees; picker pre-selects from published Daily Lineup. See Manager Reports.

2026-06-18 — Architecture Extraction, Roster UX and Column Controls

  • Architecture Decoupling — Extracted @repo/optimization and @repo/daypart-readiness from @repo/operations. Decoupled @repo/lineup and @repo/restaurant-analytics from @repo/operations to establish clean package layering boundaries.
  • Roster & Dashboard UX — Added mobile visibility and column controls in the unified roster table. Added late minutes display formats and clock status indicators. Optimized dashboard goals/metrics for smaller viewport screens.

→ See Architecture Overview and the Architecture Migration Tracker.

2026-06-15 — 7shifts Override UI, Daypart Shift Boundaries, and Shift Task Timing

  • Role Mapping Overrides — Added /admin/role-mappings UI for custom team overrides of 7shifts/Toast job roles mapped to internal canonical jobs, with audit logs for canonical_override_updated and canonical_override_reset.
  • Daypart Shift Boundaries — Aligned shift boundaries in packages/utils/src/date.ts to Lunch (04:00–16:59), Dinner (17:00–21:59), and Late Night (22:00–03:59).
  • Task Timing Fields — Added dueSegment, dueAnchor, blocksReport, and managerSignoffRequired columns to shiftTaskDefinitions and shiftTaskInstances tables. Updated checkout blocker queries to respect the blocksReport flag instead of relying on definition scope.

→ See Admin Tools, Shift Workspace & Tasks, and the Daily Shift Plan Segment Tasks Spec.

2026-06-17 — Analytics tip marts and documentation

Tip mart pipeline and docs refresh for Intelligence → Analytics.

  • rebuild-comp — writes analytics.tip_metrics_daily with ADR-0076 calculation model (Bar Bot redistribution, declared/estimated cash, settlement merge).
  • Hourly / weekly rollups — tip_metrics_hourly from neon_fct_employee_hourly; tip_metrics_weekly from daily; 1-year backfill completed for hartalliance.
  • Backfill workflow — bounded, partition-native Dagster backfills for approved date ranges.
  • Docs — Analytics user guide and Analytics & Tips Integration rewritten for Neon-native architecture.

→ See ADR-0076.

2026-06-16 — Service Day Command Console

PR #513 ships the Service Day Command Console and Setup (P0 + P1).

  • Daypart Readiness on /lineup — per-daypart cards for briefing acks, checklist progress, staff report filing, and Shift Task Sign-Off; Close Service Day persists closure per location/date.
  • Service Day Setup in the /lineup workspace — the former /lineup/setup route is retained only as a redirect with date/location context.
  • Draft / publish lineups — cards default to draft; staff compliance seeds on publish only (service-day grain per ADR-0070).
  • Closer from lineup — shift-wide checklist owner set via isCloser on publish (ADR-0073).
  • HAR-42 navigation — sidebar sections Daily, Manager Tools, Admin Console; home is Today (staff) or Shift Console (managers).

→ See Service Day Setup and Compliance.

2026-06-08 — Cross-Cutting PII Redaction

PR #180 ships a single redaction primitive in @repo/security/pii and wires it into every output surface that could carry customer contact details.

  • redactPII / scrubPII — one source of truth for redacting emails and phone numbers, including from nested objects.
  • Sentry — scrubSentryEvent is registered as the beforeSend hook for the client, server, and edge runtimes. Messages, exception values, breadcrumbs, and extra are all scrubbed before the event leaves the process.
  • PostHog — captureSecureEvent in @repo/telemetry/server scrubs event properties through scrubPII before transmitting. Use this helper instead of calling analytics.capture directly.
  • AI chat — The /api/chat route calls redactPII on user-supplied text before it is forwarded to the model or persisted.

→ See Security & Compliance → PII Redaction at the Edge.

2026-06-08 — RBAC Nav Aligned With Server Guards

PR #179 removes the "click a link, get a 403" footgun. The sidebar now mirrors the page-level server guards so no link is shown to a role that can't open it.

  • getActionContext() is the source of truth — every page guard and every nav entry consults the same role + location data. The minRole field on SidebarSection makes the rule explicit and unit-testable.
  • Manager Tools vs. Admin Console split — managers see location-scoped tools under Manager Tools; admins additionally see Admin Console. Superseded by HAR-42 nav (2026-06-16); see Service Day entry above.
  • Tightened server guards — coupons, surveys, submissions, and schedule templates moved to admin-only. The "Review & Publish" builder link now hides from managers (matching the underlying canManageSchedule check).

→ See Admin → Navigation: Management vs. System.

2026-06-08 — Webhook Idempotency (@repo/idempotency)

PR #178 closes the W-11.1 finding: every webhook handler now dedupes through a single shared primitive backed by a race-safe INSERT ... ON CONFLICT DO NOTHING.

  • claimIdempotencyKey / releaseIdempotencyKey / hashBody — exported from @repo/idempotency. Use the provider message id (e.g. svix-id) as the key, or hashBody(rawBody) when no stable id is supplied.
  • processed_webhooks table — extended with source and hash columns (migration 0070). The Clerk webhook and the QStash coupon-automation route both use the shared primitive; no inline insert/delete.
  • Concurrent deliveries race safely — exactly one of two simultaneous deliveries of the same key wins, the rest get false and short-circuit.

→ See Webhooks API → Idempotency and the Architecture Overview for the new package.

2026-06-08 — Schedule Read Model

PR #170 lands a dedicated read model for published shifts, replacing ad-hoc queries on raw shift rows.

  • Active-location scoping — the schedule view and the builder scope to the currently selected active location; the page header reflects the location name.
  • Roster union — assigned employees and scheduled floaters are unioned so a floater shift never renders as an anonymous "Staff" cell.
  • Job-based color coding — shift blocks are color-coded by role (FOH Support, Bartender, Server, BOH/Kitchen, Security, Barback, Manager, Other). Draft shifts are translucent with a dashed border. The signed-in user's own shifts get a focus ring.

→ See Technical: Scheduling Domain → Read Model and Staff Scheduling → Direct Imports and Roster Sync.

2026-06-08 — User Creation & Synchronization

PR #171 reworks the user creation pipeline with audit logging and case-insensitive deduplication.

  • Clerk + local users table stay in sync — every provisioning path writes a local users row alongside the Clerk identity, with an audit entry for the lifecycle event.
  • Case-insensitive email matching — findEmployeeByEmail and the user lookup paths compare lowercased addresses against the unique index, so the same person can be created from Clerk, a CSV import, or a roster sync without producing duplicates.
  • Bootstrap audit trail — provisioning events land in the same audit_log table as every other administrative action, so a new user is fully traceable from the moment they appear in the system.

→ See Admin → User Management.

2026-06-05 — Schedule Builder Lock & Roster Sync

PR #168 lets the schedule builder consume shifts that arrive through other paths (CSV import, Toast/7shifts sync) instead of forcing them through the drag-and-drop UI.

  • Schedule builder can be locked — when locked, the grid is read-only and shifts are sourced directly from management_shifts. New rows arrive from the database, the UI reflects the database.
  • Toast POS and 7shifts sync — EmployeeSyncDialog and bulkSyncEmployees match case-insensitively on lowercased email inside a locked transaction so concurrent syncs can't double-insert.
  • Row locks on publish — select().for('update') row locks on management_schedules and management_shifts prevent the compliance + task generation drift that two managers publishing the same week used to cause.

→ See Technical: Scheduling Domain → Row Locking on Publish.

2026-06-05 — Domain Hardening

PR #173 reconciles a wide set of audit, security, and notification hardening work onto main. Headline changes:

  • getActionContext is the canonical auth helper — every server action uses it; raw requireUserAuth / requireAdmin are on the way out.
  • Centralized audit logging — logAudit() runs inside the same transaction as the mutation. The audit trail can never silently drop a record because of a crash between the write and the audit call.
  • Saturday-Friday service week — compliance and reporting are anchored to a consistent Saturday-Friday boundary across all locations and reports.
  • Hardened Slack ingestion — rate limiting and signature verification are both required on every webhook handler.
  • CSP and encryption hardening for the guest app, the dashboard, and the chat surface.

→ See Security & Compliance, Auth & RBAC, and Audit Log & Optimization for the new behaviors.

Related

Architecture Overview

Architecture Decision Records

Security & Compliance

API Reference

Security & Compliance

Technical design of authentication, authorization, and data protection

On this page

Overview2026-10-07 — Coupon reliability, recovery, and Contact history2026-09-02 — Data sync ownership, release evidence, and app hardening2026-09-01 — Auth, reports, time zones, and release contracts2026-08-31 — Coupons, inbox, analytics, and developer tooling2026-08-30 — Analytics MCP, notifications, and production readiness2026-08-29 — Documentation tree and workstation bootstrap2026-08-07 — Mainline analytics and release hardening2026-08-07 — Sync classification and release confidence2026-08-04 — Task integrity and architecture boundaries2026-06-30 — Messaging Simplification, Service Day Consolidation & Incidents Triage2026-06-18 — Architecture Extraction, Roster UX and Column Controls2026-06-15 — 7shifts Override UI, Daypart Shift Boundaries, and Shift Task Timing2026-06-17 — Analytics tip marts and documentation2026-06-16 — Service Day Command Console2026-06-08 — Cross-Cutting PII Redaction2026-06-08 — RBAC Nav Aligned With Server Guards2026-06-08 — Webhook Idempotency (@repo/idempotency)2026-06-08 — Schedule Read Model2026-06-08 — User Creation & Synchronization2026-06-05 — Schedule Builder Lock & Roster Sync2026-06-05 — Domain HardeningRelated