What's New
Recent changes, hardening rounds, and the new capabilities they unlock
Overview
A running log of the substantive changes that have landed in the last few weeks. Each entry links to the relevant docs page and the source ADR when there is one. Older entries live in CHANGELOG.md at the repository root.
2026-10-07 — Coupon reliability, recovery, and Contact history
PR #4131 merged the Coupon
reliability work, and the protected 0632_goofy_doctor_doom migration/rollout
completed on 2026-10-07 UTC. The
dated production receipt
records the exact source, migration, and serving evidence.
- Authoring — Recoverable operator drafts and saved revision checks protect against reloads and stale edits/publication.
- Private distribution — One-time private link reveal, durable creation fences, and original-attempt recovery prevent duplicate issuance after a lost reply.
- Guest sessions and reports — Server-owned expiry, mutation/read coordination, restaurant-timezone presentation, and labeled fulfillment evidence keep status and capacity truthful. Guest confirmation still does not verify Toast.
- Customer identity and delivery — Canonical Contact locks, merge/consent preservation, authoritative notification workers, and expiry health diagnostics preserve accepted records independently of delivery failures.
See Coupons, Contacts, and Coupons and Guest NPS. Team flags, QR availability, manual real-device/privacy checks, and POS pilot acceptance remain separate from release completion; contactable NPS remains gated.
2026-09-02 — Data sync ownership, release evidence, and app hardening
- Single-writer ingestion — Dagster now owns Toast ingestion, repairs, analytics, and backfills; legacy Toast writers fail closed, and the admin employee refresh is an idempotent, ledger-backed Dagster request. See Data Sync Pipeline Architecture and Live Sync Data Freshness. PR #2672.
- Protected production evidence — Migration release preparation now requires pre-staged evidence, exact-SHA binding, and the matching deployment/rehearsal contract before production execution. See Database Migrations and Deployment Guide. PRs #2664, #2497, and #2558.
- Server-owned app scope and shell — Dashboard reads honor the canonical location scope, while the authenticated shell and responsive layout contracts received the final QA and accessibility hardening pass. See Architecture Overview. PRs #2673, #2674, #2635, and #2644.
- Dagster admission compatibility — Build admission validates runner labels and uses the portable GitHub API path. PRs #2670 and #2671.
2026-09-01 — Auth, reports, time zones, and release contracts
- Local authorization is canonical — Clerk remains the identity provider, while local PostgreSQL owns team membership, role, location scope, lifecycle, and employee mapping. Provider role mirrors and trusted-origin edge cases were removed or rejected. See Auth & RBAC, Security & Compliance, and Local Authorization Boundary. PRs #2550, #2622, #2623, #2626, #2634, and #2641.
- Service Day reporting — Staff reports and manager closeouts now use Service Day grain, deliberate Staff Reviews, server-authoritative publish preflight, and the documented 10–500 character override reason when incomplete tasks need an exception. See Staff Service Day Reports and Manager Closeouts. PRs #2477 and #2495.
- Calendar exports use strict local time zones, and Slack delivery received P0/P1 path stabilization. PRs #2563 and #2578.
2026-08-31 — Coupons, inbox, analytics, and developer tooling
- Coupon lifecycle and reporting — Location-scoped authoring, opaque assignment URLs, staff confirmation, guest recovery, redemption reporting, privacy-safe contact handling, and rollout evidence are now documented in the coupon feature contract, manager guide, and rollout runbook. PRs #2440, #2441, #2442, #2443, #2445, #2478, and #2489.
- Operations Inbox — Purpose-first message intake and the canonical Inbox lifecycle now govern the unified triage flow. See Unified Operations Inbox and the message-management contract. PRs #2476 and #2490.
- Trusted analytics and contact history — The governed analytics dashboard and minimal contact-card foundation now have repository contracts and route inventory coverage. PRs #2447 and #2481.
- Online-authoritative PWA behavior — Live reads and mutations remain network-only, while the shell and identity-scoped drafts support safe offline recovery. See PWA & Offline Shell and ADR-0103. PRs #2408 and #2438.
2026-08-30 — Analytics MCP, notifications, and production readiness
- Analytics MCP now publishes an executable tool catalog with explicit access modes, canonical liveness probes, request-lifecycle certification, and cross-app parity coverage. See the Analytics MCP user guide. PRs #2412, #2415, #2420, #2423, and #2430.
- Notification ownership moved to the owning package, and the published data-flow page was updated to match. See Data Flow and the notifications package README. PR #2372.
- Production readiness now uses the same-origin status proxy, explicit environment contracts, and evidence-bound Vercel/Dagster release checks. See Deployment Guide and the production readiness research. PR #2401.
2026-08-29 — Documentation tree and workstation bootstrap
- Documentation ownership was consolidated across the repository and Fumadocs pages, with navigation, ADR lifecycle, package READMEs, and canonical source links reconciled. PR #2358.
- Developer onboarding now documents the pinned Bun/Node toolchain, guarded worktree setup, current package ownership, and protected migration path. See Development and the development onboarding guide. PR #2317.
2026-08-07 — Mainline analytics and release hardening
- Analytics source finality now binds D-1 facts to exact per-location source windows and deployment identity, with fail-closed handling for gaps, failed attempts, and mixed releases (#1785).
- DQ selection now preserves exact scope/version rows, and discount DQ reference access is explicitly granted (#1786, #1790).
- Sync correctness now persists Toast employee watermarks, mirrors open-punch writer scope, and aligns snapshot reconciliation cutoffs (#1787–#1789).
- Operational workflows received boundary and shift/manager-report hardening; duplicate health coverage was removed (#1769, #1781, #1793).
- Discount and labor contracts continue the deterministic rollout with discount subcategories and 7shifts schedule/labor-variance hardening (#1772, #1773).
2026-08-07 — Sync classification and release confidence
- Toast discount classification now covers GUID-less reward and percent-off discounts with narrow name rules while preserving review for unknown definitions.
- Identity resolution is deterministic for Toast employees, 7shifts jobs, and current menu-item canonicalization paths.
- Release validation includes the exact Playwright smoke marker, Vercel production-build parity, and the simplified fail-fast test pipeline.
- Tip certification conserves observed denominators across allocation and completed-week certification paths.
2026-08-04 — Task integrity and architecture boundaries
- Task integrity checks are registered in the DQ framework and run through the daily
shift_task_integrity_dqDagster asset, with the migration-rehearsal runbook documenting operator gates. - Architecture enforcement now uses the native Turbo/package boundary policy and
bun run architecture:check; the retired package-layering script is no longer a current command. - Analytics contracts continue the evidence-first rollout for labor, tips, identity, and canonical health serving.
2026-06-30 — Messaging Simplification, Service Day Consolidation & Incidents Triage
- Communication Simplified — Slack + Web Push now cover team chat, notifications, and alerts. See Messages & Announcements, Incident Reporting, and AI Assistant.
- Service Day Setup Consolidated — Roster now shows FOH staff only with prefill reason chips (Scheduled / Through close / Manual). Closer dropdown with ⚠ Closer recommended warning when daypart has staff but no closer. See Service Day Setup.
- Incidents Triage Panel — Dashboard (
/incidents) now shows summary chips (open · critical/high · aging · unassigned), filter chips with URL persistence, and incident cards with severity rail, owner, age, and status. Aging thresholds: 72h amber, 168h red. See Incident Reporting. - Navigation Overhaul — Sidebar reorganized into Today / Service Day / Review / Team / Insights / Administration sections with role-based visibility. See Admin → Navigation.
- Manager Staff Reviews — Migrated to employee-centric model (employee key instead of user ID). Can review unlinked employees; picker pre-selects from published Daily Lineup. See Manager Reports.
2026-06-18 — Architecture Extraction, Roster UX and Column Controls
- Architecture Decoupling — Extracted
@repo/optimizationand@repo/daypart-readinessfrom@repo/operations. Decoupled@repo/lineupand@repo/restaurant-analyticsfrom@repo/operationsto establish clean package layering boundaries. - Roster & Dashboard UX — Added mobile visibility and column controls in the unified roster table. Added late minutes display formats and clock status indicators. Optimized dashboard goals/metrics for smaller viewport screens.
→ See Architecture Overview and the Architecture Migration Tracker.
2026-06-15 — 7shifts Override UI, Daypart Shift Boundaries, and Shift Task Timing
- Role Mapping Overrides — Added
/admin/role-mappingsUI for custom team overrides of 7shifts/Toast job roles mapped to internal canonical jobs, with audit logs forcanonical_override_updatedandcanonical_override_reset. - Daypart Shift Boundaries — Aligned shift boundaries in
packages/utils/src/date.tsto Lunch (04:00–16:59), Dinner (17:00–21:59), and Late Night (22:00–03:59). - Task Timing Fields — Added
dueSegment,dueAnchor,blocksReport, andmanagerSignoffRequiredcolumns toshiftTaskDefinitionsandshiftTaskInstancestables. Updated checkout blocker queries to respect theblocksReportflag instead of relying on definition scope.
→ See Admin Tools, Shift Workspace & Tasks, and the Daily Shift Plan Segment Tasks Spec.
2026-06-17 — Analytics tip marts and documentation
Tip mart pipeline and docs refresh for Intelligence → Analytics.
rebuild-comp— writesanalytics.tip_metrics_dailywith ADR-0076 calculation model (Bar Bot redistribution, declared/estimated cash, settlement merge).- Hourly / weekly rollups —
tip_metrics_hourlyfromneon_fct_employee_hourly;tip_metrics_weeklyfrom daily; 1-year backfill completed forhartalliance. - Backfill workflow — bounded, partition-native Dagster backfills for approved date ranges.
- Docs — Analytics user guide and Analytics & Tips Integration rewritten for Neon-native architecture.
→ See ADR-0076.
2026-06-16 — Service Day Command Console
PR #513 ships the Service Day Command Console and Setup (P0 + P1).
- Daypart Readiness on
/lineup— per-daypart cards for briefing acks, checklist progress, staff report filing, and Shift Task Sign-Off; Close Service Day persists closure per location/date. - Service Day Setup in the
/lineupworkspace — the former/lineup/setuproute is retained only as a redirect with date/location context. - Draft / publish lineups — cards default to draft; staff compliance seeds on publish only (service-day grain per ADR-0070).
- Closer from lineup — shift-wide checklist owner set via
isCloseron publish (ADR-0073). - HAR-42 navigation — sidebar sections Daily, Manager Tools, Admin Console; home is Today (staff) or Shift Console (managers).
→ See Service Day Setup and Compliance.
2026-06-08 — Cross-Cutting PII Redaction
PR #180 ships a single redaction primitive in @repo/security/pii and wires it into every output surface that could carry customer contact details.
redactPII/scrubPII— one source of truth for redacting emails and phone numbers, including from nested objects.- Sentry —
scrubSentryEventis registered as thebeforeSendhook for the client, server, and edge runtimes. Messages, exception values, breadcrumbs, andextraare all scrubbed before the event leaves the process. - PostHog —
captureSecureEventin@repo/telemetry/serverscrubs event properties throughscrubPIIbefore transmitting. Use this helper instead of callinganalytics.capturedirectly. - AI chat — The
/api/chatroute callsredactPIIon user-supplied text before it is forwarded to the model or persisted.
→ See Security & Compliance → PII Redaction at the Edge.
2026-06-08 — RBAC Nav Aligned With Server Guards
PR #179 removes the "click a link, get a 403" footgun. The sidebar now mirrors the page-level server guards so no link is shown to a role that can't open it.
getActionContext()is the source of truth — every page guard and every nav entry consults the same role + location data. TheminRolefield onSidebarSectionmakes the rule explicit and unit-testable.- Manager Tools vs. Admin Console split — managers see location-scoped tools under Manager Tools; admins additionally see Admin Console. Superseded by HAR-42 nav (2026-06-16); see Service Day entry above.
- Tightened server guards — coupons, surveys, submissions, and schedule templates moved to admin-only. The "Review & Publish" builder link now hides from managers (matching the underlying
canManageSchedulecheck).
→ See Admin → Navigation: Management vs. System.
2026-06-08 — Webhook Idempotency (@repo/idempotency)
PR #178 closes the W-11.1 finding: every webhook handler now dedupes through a single shared primitive backed by a race-safe INSERT ... ON CONFLICT DO NOTHING.
claimIdempotencyKey/releaseIdempotencyKey/hashBody— exported from@repo/idempotency. Use the provider message id (e.g.svix-id) as the key, orhashBody(rawBody)when no stable id is supplied.processed_webhookstable — extended withsourceandhashcolumns (migration0070). The Clerk webhook and the QStash coupon-automation route both use the shared primitive; no inline insert/delete.- Concurrent deliveries race safely — exactly one of two simultaneous deliveries of the same key wins, the rest get
falseand short-circuit.
→ See Webhooks API → Idempotency and the Architecture Overview for the new package.
2026-06-08 — Schedule Read Model
PR #170 lands a dedicated read model for published shifts, replacing ad-hoc queries on raw shift rows.
- Active-location scoping — the schedule view and the builder scope to the currently selected active location; the page header reflects the location name.
- Roster union — assigned employees and scheduled floaters are unioned so a floater shift never renders as an anonymous "Staff" cell.
- Job-based color coding — shift blocks are color-coded by role (FOH Support, Bartender, Server, BOH/Kitchen, Security, Barback, Manager, Other). Draft shifts are translucent with a dashed border. The signed-in user's own shifts get a focus ring.
→ See Technical: Scheduling Domain → Read Model and Staff Scheduling → Direct Imports and Roster Sync.
2026-06-08 — User Creation & Synchronization
PR #171 reworks the user creation pipeline with audit logging and case-insensitive deduplication.
- Clerk + local
userstable stay in sync — every provisioning path writes a localusersrow alongside the Clerk identity, with an audit entry for the lifecycle event. - Case-insensitive email matching —
findEmployeeByEmailand the user lookup paths compare lowercased addresses against the unique index, so the same person can be created from Clerk, a CSV import, or a roster sync without producing duplicates. - Bootstrap audit trail — provisioning events land in the same
audit_logtable as every other administrative action, so a new user is fully traceable from the moment they appear in the system.
→ See Admin → User Management.
2026-06-05 — Schedule Builder Lock & Roster Sync
PR #168 lets the schedule builder consume shifts that arrive through other paths (CSV import, Toast/7shifts sync) instead of forcing them through the drag-and-drop UI.
- Schedule builder can be locked — when locked, the grid is read-only and shifts are sourced directly from
management_shifts. New rows arrive from the database, the UI reflects the database. - Toast POS and 7shifts sync —
EmployeeSyncDialogandbulkSyncEmployeesmatch case-insensitively on lowercased email inside a locked transaction so concurrent syncs can't double-insert. - Row locks on publish —
select().for('update')row locks onmanagement_schedulesandmanagement_shiftsprevent the compliance + task generation drift that two managers publishing the same week used to cause.
→ See Technical: Scheduling Domain → Row Locking on Publish.
2026-06-05 — Domain Hardening
PR #173 reconciles a wide set of audit, security, and notification hardening work onto main. Headline changes:
getActionContextis the canonical auth helper — every server action uses it; rawrequireUserAuth/requireAdminare on the way out.- Centralized audit logging —
logAudit()runs inside the same transaction as the mutation. The audit trail can never silently drop a record because of a crash between the write and the audit call. - Saturday-Friday service week — compliance and reporting are anchored to a consistent Saturday-Friday boundary across all locations and reports.
- Hardened Slack ingestion — rate limiting and signature verification are both required on every webhook handler.
- CSP and encryption hardening for the guest app, the dashboard, and the chat surface.
→ See Security & Compliance, Auth & RBAC, and Audit Log & Optimization for the new behaviors.