April 26, 2026: Workflow layer hits 100% across all 10 surfaces
Workflow Layer Hits 100% Across All 10 Surfaces
Section titled “Workflow Layer Hits 100% Across All 10 Surfaces”This release closes every remaining gap on the workflow-layer audit checklist:
- Invoicing
- Bills / Accounts Payable (with payment runs)
- Expenses
- Payments
- Bank sync
- Transaction categorization (with 24-hour undo)
- Document attachments (now unified on a single table)
- Approvals (with delegation, SLA escalation)
- Recurring entries (invoices, bills, expenses, and now journal entries)
- Customer / Vendor management (with public portals)
- Recurring Journal Entries — a new surface at
/finance/journal-entries/recurringfor scheduling JEs that post automatically on a regular cadence. Supports all five entry categories (standard, adjusting, closing, reversing, opening) and an auto-reverse-next-period toggle that’s standard for accruals. - Vendor Portal — a token-authenticated public surface where vendors can submit a W-9 (last-4 TIN only), view their AP payment history, and submit bills for your review.
- Payment Runs — bundle multiple vendor bills into a single payment workflow with a draft → approved → posted lifecycle.
Changed
Section titled “Changed”- Document attachments are now unified on a single
attachmentstable. The legacyentity_documentspath was migrated and removed, simplifying every vendor- and contact-document route to one canonical store. - Brand orange is now consistent across the app. The
--primarydesign token, default Button background, Progress bar fill, and ~227 component files were all aligned to the brandaccent-50(#FF6600). Tailwind’sorange-*palette (which is a different hue) is now restricted to marketing pages where it’s intentional. - API envelope standardized. Every workflow route uses the documented
{ success: true, data, ...meta }shape. The previous ESLint warning that pushed toward an unfinished alternative migration was retired.
- 149 Supabase performance advisor WARNs cleared —
multiple_permissive_policiesresolved by splittingFOR ALLpolicies into per-command policies on 35 tables;auth_rls_initplanresolved by rewriting 8 user-scoped policies to the canonical(SELECT auth.fn())wrap form; service-role policies on 29 tables scoped toTO service_roleto remove role overlap. - A11y sweep on icon-only buttons — every workflow surface (invoices, customers, banking, expenses, vendors, approvals, journal entries, recurring) now passes the missing-
aria-labelaudit.
Why It Matters
Section titled “Why It Matters”This is the work that separates “the platform technically works” from “the platform is audit-grade complete.” Every workflow surface has:
- Backend service + API routes shipped to production
- Nav-reachable UI built with shadcn primitives
- Polished UI consistent with the brand design system
- End-to-end UX (empty states, loading skeletons, success/failure toasts)
- No N+1 queries, paginated lists, sensible TanStack Query keys
- Keyboard-reachable interactive elements with visible focus
- Unit tests + at least one Playwright spec
- Documentation (runbooks for ops, customer guides for users)
If you ran into a recurring-entry pattern that didn’t fit the invoice / bill / expense engines (rent accruals, depreciation provisions, intercompany transfers), it now has a real home. If you’ve been pasting payment links into emails for vendors instead of giving them a portal, you can stop. If you noticed orange shades that didn’t quite match across the app, they do now.