More Reliable Account Containment and Review
Account containment now tracks Clerk synchronization separately, supports safe retries after a partial service failure, and keeps access blocked until a restore is fully confirmed. Platform users can see accurate containment status on web and mobile, while directory views, API-key access, exports, and unusual access denials produce more complete audit records.
Stronger Access Review and Signup Controls
Platform admins can review who accessed high-risk directories and exports (without storing full response data), get alerts when an account hits an unusual number of access denials, and must provide a reason when opening or closing new school signups. Signup attempts while closed are rate limited and recorded.
Faster Account Lockdown for Platform Admins
Platform admins can now contain a user account from the admin users page in one step. Contained accounts lose sign-in and app access immediately, and the action is recorded for review. Access can be restored later if the account was locked by mistake.
Dark Mode Fix on Feature Pages
Fixed the call-to-action sections on the Enrollment, Attendance, Staff Management, and Billing feature pages, where the Start Free Trial button and supporting text could become unreadable in dark mode. All marketing pages were reviewed and now render correctly in both themes.
Smoother Real-Time Startup on Mobile
Fixed an intermittent “Connection interrupted” screen that could briefly appear in the mobile app while it finished connecting after launch. Live conversations and unread badges now wait for the connection to be ready and recover on their own, with no retry needed.
A Refreshed Icon System Across Web and Mobile
Every icon across the platform has been redrawn with a new icon family chosen for warmth and clarity. Navigation, dashboards, forms, messaging, and the mobile app all share the refreshed look, with icons picked deliberately for each feature so meals, classrooms, families, and daily reports read at a glance.
Notifications Reactivate Reliably on Every Device
Mobile sessions now provide one consistent account identity for notification delivery. Devices safely reactivate their push connection when the app returns to the foreground, while notification content remains restricted to the intended signed-in account.
Notifications Stay with the Correct Account
Live support and platform message notifications now follow the currently authorized account and active role on each device. The iPad Support Inbox tab also centers its two-line label and keeps the unread indicator fully visible inside the floating navigation bar.
Live Support Activity Is Easier to See and Answer
New website chats are now described as live support conversations, and unread visitor messages appear immediately on the mobile Support Inbox tab. On tablets, support reply controls and Mail actions now remain comfortably above the floating navigation bar.
A Dedicated Home for Platform Analytics
Authorized platform administrators now have one analytics workspace for school and user totals, active users, web and mobile adoption, login trends, message volume, role distribution, and school-level activity. The same live analytics are available on web and mobile.
Faster Detection of Web and Mobile Problems
Production error monitoring now connects web and mobile failures to the application version that caused them, helping the team diagnose crashes faster while filtering personal and childcare data from diagnostic reports.
Accurate Unread Messages on School Dashboards
School dashboard insights now use live unread-message state for the connected school. Read conversations and messages from other school contexts no longer leave a misleading unread count.
Parent Incident Reports Open Reliably
Families can open incident reports even when an older report records staff names or legacy staff references. Existing privacy rules remain in place, so parents see only deliberately shared reports for children linked to their account.
Stronger School, Location, Classroom, and Family Data Boundaries
Data access now binds each role to its real school membership and narrows location administrators, classroom staff, and families to the records they are responsible for. School-wide finance, credentials, configuration, admissions, and other unscoped operations require a school-wide administrator, while contact directories and related records return safer, minimal details.
Help Where You Need It
Dashboard work areas now include a quiet, page-specific help link for school administrators, staff, and families. Each link opens the most relevant customer article, often at the exact section for the task, in a new tab so in-progress work stays in place. Platform operators receive the same contextual experience through the separate internal operations manual.
Clearer Customer Help and Internal Operations Guidance
The public Help Center has been rebuilt in plain language around the workflows and role access available today, while platform operators now have a separate internal manual for support, security, permissions, communications, data, API, and payment operations. Billing pages now distinguish invoices, processing fees, refunds, reconciliation, and bank payouts, and no longer describe recorded late-fee settings as automatic invoice changes.
More Reliable Payment Confirmations and Statuses
A temporary email-delivery problem can no longer hold up an otherwise completed Stripe payment. Replayed payment notifications also preserve later refund and dispute statuses, keeping school receipts, exception queues, and reconciled financial reporting aligned with the actual payment lifecycle.
One Safer Stripe Payment Architecture
Every Stripe parent payment now runs directly on the school's connected account; obsolete destination-charge paths and rollout switches have been removed. Payments fail closed on missing account or fee configuration, verify the settled invoice amount, isolate saved methods per school, and reconcile refunds, disputes, fees, and payouts from signed Stripe events. Paystack remains a separate supported path.
Clear Payment Fees, Receipts, and Bank Payouts
Schools now see the fee policy that actually applies to them, connected-account capabilities, payment receipts with real reconciled costs, and Stripe bank payouts as separate events. Families can choose card or eligible ACH payments with clearer processing-time guidance, never have school fees added to the invoice total, and receive a prompt when a direct-charge migration requires saving a payment method again.
Payment Operations and Safer Direct-Charge Rollout Controls
Super Admin payment operations now show real payment volume, application fees, reconciliation exceptions, connected-account health, transaction ledgers, and CSV exports. Fee changes use immutable draft, activate, and retire versions with audit reasons, while a rollout kill switch and per-school readiness checks prevent unsafe direct-charge enrollment without disrupting schools already processing payments.
Stronger Role Boundaries, Reports, and Notification Routing
School settings stay admin-only, protected pages avoid stale browser cache after sign-out, and form builder saves refuse to overwrite a newer tab. Incident dates keep the calendar day you recorded, activity reports surface unassigned rooms and truncation, and exports include source IDs. Daily summary taps open parent activity with the right child/report, notification preferences use the active school with honest error recovery, and mobile sign-out stops push delivery for the previous account.
Cleaner Check-Out, Payments, and Admissions Follow-Through
Payment confirmations no longer resend on webhook retries, and financial reports keep invoices and payments in the same period. Check-out preserves earlier notes, refuses to rewrite a finished day, and parent Home shows Checked out clearly. Public form submit stays success-only, waitlist Contacted records when outreach happened, completed tours keep a completion time, and attendance reports filter by room correctly.
Clearer Form Responses and Safer Parent Invoices
Form response reviews show uploaded files correctly, restrict PDF export to school admins, and prevent concurrent Accept/Reject races. Manual invoices keep line totals honest, preserve the due calendar day you pick, and avoid duplicate creates on retry. Multi-school parents see the active school's invoices, mobile labels match Sent status, cancelled checkouts free Pay Now immediately, and non-production environments refuse live payment keys.
Trustworthy Incident Follow-ups and Safer Paperwork Publishing
Completing an incident follow-up now requires a real outcome note and keeps the original plan on record. Parents only see incidents after staff deliberately notify them, and multi-school parent views stay on the active school. Paperwork forms validate question definitions and answers on the server, create parent assignments when you publish to specific families, and no longer open private forms via a raw form ID.
Clearer Messaging and Trustworthy Incident Notifications
Message replies are easy to find, stay inside the right conversation, and avoid accidental duplicates on retry. Edited messages update the inbox preview, and mute clearly applies to web notifications only. Incident reports require complete core details, show staff and witnesses on the detail view, and email parents only when you choose Notify Parent, so the notification status matches what families received.
Cleaner Parent Sharing for Reports, Photos, and Milestones
Sending a daily report notifies parents once, with a clear first-send record, and saving a draft no longer unshares it. Parent activity views show full meal and nap details, milestones stay scoped to a teacher's rooms, photo uploads report real success or failure, and parent sharing is clearly admin-only. Teachers message families linked to their classrooms, not the whole school directory.
Reliable Schedules, Lesson Plans, and Daily Reports
Teachers can open Schedules on mobile with correct weekdays and times, and only see their own rota instead of every colleague. Lesson plans validate content, avoid duplicate drafts, limit edits to authors or room staff, and show author and status on cards. Daily reports use the local calendar day, store structured care entries cleanly, and no longer notify parents when a private draft is saved.
Smoother Check-In, Clearer Room Labels, and Fairer Staff Tools
Tablet check-in resolves shared last names and PINs safely, requires a real health screening and signature when enabled, and no longer rewrites or re-notifies an already-open check-in. Attendance boards show each child's classroom correctly. Quick-scan QR codes are single-active and expire on kiosk exit; mobile parent scan completes the right check-in or check-out action. Staff time clock can require notes, and teachers only see schedule controls they are allowed to use.
Clearer Parent Setup and Safer Tablet Check-In
Adding a parent is more reliable, with honest invite-email status and location safeguards for multi-site schools. Parent home shows the correct classroom, attendance history stays complete for each child, and emergency contacts can be edited with email and pickup authorization. Tablet Mode is limited to staff and supports a parent PIN-first drop-off and pickup flow.
Reliable Staff Rosters, Schedules, and Student Records
Staff room assignments show correctly again in Staff Management. Weekly schedules are saved as a single multi-day create with better conflict and operating-hours checks. Adding a child with a classroom is atomic, medical edits persist (including insurance), and the mobile staff home shows today's schedule. Mobile sign-in is also more tolerant of school Wi-Fi NATs without weakening abuse protection.
Safer Menus and More Reliable Staff Invitations
Food items and weekly menus enforce cleaner names, categories, and meal types, with safer CSV exports and a working meal-type search. Staff invitations for teachers and admins show up in Staff Management again, invite creation is more reliable, cancelled invites cannot be reused, and accepting an invite with the wrong signed-in account offers a clear sign-out path.
Clearer Account Context and Stronger School Setup
The dashboard sidebar now shows your email and active role next to your school so it is easier to confirm you are acting as the right person. Every school can create a primary campus without an Enterprise plan; multi-location still unlocks additional sites. Classroom create and edit are stricter about names and capacity, profile photo replacements clean up the previous image, and calendar events validate rooms and times more carefully so invalid or cross-school data cannot slip in.
Reliable Profile Photos in Mobile Messages
School administrators can see staff and teacher profile photos in mobile conversation lists. If a saved image cannot load, the app now shows the person's initials instead of an empty avatar.
Mobile Payment Method Controls
Parents can add, replace, or remove their saved card in the mobile app and turn autopay on or off. Removing a card automatically disables autopay.
Accurate Mobile Invoice Amounts
Admin invoice totals and line items now display in dollars consistently. Parent payments also report incomplete school payment setup clearly before opening the payment form.
Reliable Mobile Admin Workflows
Mobile administrators can create invoices for students with linked parents, and waitlist and menu details now save consistently. Billing access continues to enforce school, role, and student-parent relationship checks.
Child Profile Photos for Parents
Parents on the mobile app can again see profile photos for their linked children. Staff and parent avatars used in messaging also load correctly for school members.
More Accurate Service Status
Status monitoring now handles normal site redirects and confirms brief connection failures before reporting an outage. Incorrect outage bars caused by the monitor itself have been corrected.
Swipe Actions on Mobile Mail
On mobile Mail, swipe a conversation left or right for quick actions in Inbox, Archived, Sent, and Unassigned, including archive, restore, mark read or unread, claim, reply, and open.
- Swipe right for primary actions like Archive, Move to Inbox, Claim, or Open
- Swipe left for Read/Unread and Reply where those apply
Status History Bars Updating Again
The public and admin status pages again show daily history for each service. A gap in recording left recent days as “Not tracked”; uptime samples are being collected on schedule again.
- Today’s bar fills in as new checks complete throughout the day
- More resilient monitoring so brief outages in the checker don’t stop history
Real-Time Platform Mail on Mobile
New inbound mail and replies show up on the mobile Mail list and in threads automatically. No pull-to-refresh is required.
- Faster list updates while keeping message previews lightweight
Compose Outbound Platform Mail
Platform admins can start a new email from the mobile Mail screen, not just reply. The send API also accepts multiple To recipients and optional Cc.
- Mobile compose: From identity, To/Cc, subject, body, attachments, signature preview
- Send path validates recipient lists and returns clearer client errors
Cleaner Marketing Callouts
Resource guides and the developer docs no longer use the generic mustard “important note” boxes. Notices now use a brand-accented editorial callout that reads cleanly in light and dark mode.
- State ratio guides, Ireland, late-payments, and API docs updated to the shared callout
More Reliable Status Monitoring
Scheduled health checks for the public status page run reliably again, so uptime history keeps up with how systems are actually doing.
- Status checks resume on their regular interval after a routing fix
Security & Reliability Improvements
Stronger school context for admins, safer role changes, password reset signs out other sessions right away, old soft-deleted uploads are cleaned up automatically, and public chat is harder to abuse with rapid requests.
- Staff, invitations, and calendar actions require a clear school context
- Changing your password ends other signed-in sessions on mobile and web
Payments, Exports & Notifications Reliability
Payment confirmations retry safely when something fails, expired trials stay read-only, and student exports and device notifications are safer against abuse.
- Card and bank payment settlement and retries are more reliable
- Schools past trial stay read-only until a plan is chosen
- Student CSV exports are safer to open in spreadsheets and harder to over-request
Safer Public Forms & Email
Contact, careers, and other public forms are harder to spam, and platform outbound email only sends from verified CentreCareOS addresses.
- Public contact, careers, and school directory requests are throttled against abuse
- Marketing and platform mail only mark a send complete after real delivery
- Announcement links only allow safe web addresses
Smoother Invites & Multi-School Access
Accepting an invite to a second school links you correctly, invite links stay private, and the accept flow no longer gets stuck after sign-in.
- Staff and parents can belong to more than one school without losing access
- Location-scoped admins can only invite for locations they manage
Safer Platform Admin Tools
Platform admin announcements, invites, app-review setup, and billing tools are safer against misuse, with clearer permission checks and input limits.
- Partial platform fee edits no longer reset unrelated fee settings
- Payout account cleanup always targets the correct school
- Trial length and school billing changes stay within sensible bounds
More Reliable Parent & School Payments
Parent card payments route correctly to the school, subscription confirmations cannot be reused to extend access, and plan changes no longer risk double billing.
- Payout country follows the school profile; bank transfer only where supported
- Checkout and plan changes are throttled against accidental spam
- Subscription status is available to school admins for the school they are viewing
Clearer Invoices & Billing Privacy
Billing settings stay admin-only, parents are charged the real invoice total, and multi-school parents always pay for the school they are signed into.
- Checkout always uses the full invoice amount on the bill
- New invoices get unique numbers and required fields are validated
- Bank account numbers are masked in billing overviews
All-or-Nothing Multi-Child Enrollment
Enrolling from a form or waitlist creates the parent, all children, room assignments, and status updates together, so a mid-enroll failure no longer leaves half-created families.
- Form and waitlist enrollment complete fully or not at all
- Parent invite emails still send after a successful enroll
Safer Waitlist & Enrollment
Waitlist management is admin-only, the same family cannot be enrolled twice by accident, and platform admins always work in the school they are viewing.
- Children are only placed in rooms that belong to that school
- Matching a parent email never grants parent access on the wrong account
- Admission status stays in sync with the student's enrollment status
Safer Shared Forms & Paperwork
Public form submissions follow the same rules as the rest of the product, share links are hard to guess, and only school admins review responses.
- Public forms resist spam with sensible submit limits
- Collaborators and audiences must belong to the same school as the form
- Closed forms stay closed when assigning; deleting a response works reliably
Private Photos, Reports & Lesson Plans
Parents only see shared photos of their own children, parent activity notes cannot overwrite staff daily reports, and lesson plans stay staff-only.
- Only admins can share photos with parents; parents only see shared photos of their children
- Parent daily-report notes add activities without changing staff report content
- Lesson plans, menus, and food items stay on staff and admin paths
Tighter Incidents & Ratio Settings
Staff only manage incidents for rooms they work in, parent acknowledgement shows correctly, and ratio compliance settings are limited to school admins.
- Parents no longer see school-wide incident lists; staff stay within assigned rooms
- Parent notify is throttled; how they were notified is recorded
- Ratio compliance settings require school admin access
Clearer Attendance & Pickup
Parents can check out their linked children again, emergency rosters stay within a staff member's rooms, and attendance records keep a trustworthy audit trail.
- Parents can check out their own children from the app
- Emergency roster and pickup options match assigned rooms; reports limited to recent ranges
- Kiosk and signature check-in stay on signed-in staff sessions
Fairer Staff Time-Off & HR Privacy
Staff can no longer edit each other's leave or payroll hours, dual-role people keep parent access when a staff role changes, and approved time off shows on the calendar again.
- Staff manage their own time-off and clock-in; past hours cannot be rewritten casually
- Removing a staff role no longer deactivates people who still have parent or other-school access
- Approved time off appears on the calendar; pay and medical HR fields stay private from peers
Safer Parent Accounts & Privacy
Payment methods stay private from staff directories, removing a parent from one school no longer deactivates multi-role accounts, and parent name/email edits save correctly.
- Staff no longer see parent payment credentials; only the parent can change them
- Leaving one school no longer removes access where the person still has a role
- Email changes cannot take over another account; admin parent edits save name and email
Room Rosters & Child Privacy
Staff only see children and parent contacts for rooms they work in, room lists share less sensitive detail, and school operating hours load and save correctly.
- Room rosters and parent contacts match assigned rooms (and location-scoped admins)
- Room lists no longer include medical notes, dates of birth, or staff emails by default
- Parents with children at more than one school see all of their linked children
- School operating hours load from saved settings and persist on save
Dashboard Access Matches Your Role
Parents and staff can no longer open admin-only modules by typing a URL. Screens you should not see fail closed with a calm empty state instead of an error crash.
- Dashboard pages respect the same role rules as the sidebar
- Stronger browser security headers on every page
Lighter Public Status Page
The public status page shows the latest scheduled health snapshot instead of re-checking every provider on each visitor refresh.
- Status refreshes on a gentler schedule for visitors
- Adding a role no longer reveals whether an email exists at another school
Polished Reports & Room Chat Privacy
Incident reports respect date filters and student names, room chat previews stay private until you join, and several report and upload edge cases are fixed.
- Incident reports honor the selected date range and show full student names
- Room chat lists hide message previews until you have joined the room
Schedules, Signatures & Status Safety
Public status visitors no longer trigger heavy health checks, schedules and document signatures require staff or admin, and peer staff cannot see private HR fields.
- Browsing the public status page is lighter on the platform
- Only staff and admins can change schedules or capture signatures
Plan Changes & Billing Reliability
Changing plans no longer risks two active subscriptions, enterprise room-staff lookups work with API keys, and the public account-deletion page is available without sign-in.
- If the old plan cannot be cancelled, the new plan is not left half-applied
- Invoice reminders process schools in safe batches
Safer Tours, Directories & Emails
Tour bookings use the real published slot times, school directories hide sensitive account fields, and transactional emails render names safely.
- Tour bookings always use the school's published slot time and length
- School user lists no longer show payment or login internals
Safer Support File Uploads
Support chat attachments are throttled against abuse and only attach to a real conversation the agent can access.
- Visitor and agent uploads share the same fair usage limits
- Signed-in agents can only attach files to threads they can reply in
Honest Plan Changes & Signup Notices
Schools can only switch to active self-serve plans, and platform signup notices use the real school and admin details from the system.
- Inactive or retired plans cannot be selected during a plan change
- Staff only see their own room assignments unless they are an admin
Clearer Form Publish & Assign Rights
Only school admins or the form owner can publish or assign forms; collaborators can still edit content. Public form uploads have fair usage caps.
- Collaborators can edit form content, but cannot publish or assign to students
- Large assignment batches are capped so one school cannot overwhelm the system
App Review Setup & Bank Privacy
App Review school setup requires a password the operator chooses, bank account lists show only the last four digits, and public tour slots only appear on shared forms.
- App Review setup no longer ships a default password in the app
- Billing account lists mask full bank numbers to the last four digits
Safer Message Attachments
Messages only accept files you uploaded (or that already belong to the chat), and parents can only request deletion of their own account unless an admin acts.
- You cannot attach someone else's private file to a conversation
- Parent account-deletion requests always apply to the signed-in parent
Parent Dashboard Privacy & Safer Files
The parent dashboard only shows each parent's own children and data, message links stay on CentreCareOS, and private Office files download instead of opening in third-party viewers.
- Parents only see their own dashboard data
- Message attachments only use safe file links on CentreCareOS
- Office documents download in-app instead of opening in external viewers
- Temporary super-admin signup tooling was removed from production
Who Can See Billing, Support Files & Schedules
Only school admins see platform subscription invoices, only support agents attach files in support chat, and only staff or admins manage schedules and time-off.
- Platform subscription invoices are admin-only, like checkout and the billing portal
- Support agents upload files only on threads they can reply in; visitors stay on their own chat
- Approving time-off requires a school admin
Form Exports & Assignment Privacy
Only people who can edit a form can export response PDFs, assigning a form updates due dates correctly, and subscription activation only accepts real plan checkouts.
- Submission PDF export requires form edit access for the school you are viewing
- Assigning a form updates status and due dates for the people who can edit it
- Subscription activation only accepts a real subscription checkout for that school and plan
Stronger Account Linking Across Schools
Sign-in accounts cannot be reassigned to a different person, invites and enrollments only link the verified primary email, and attendance stays within the correct school.
- An existing login cannot be silently rebound to another person's account
- Invites and enrollment only connect when the invited email is the verified primary address
- Attendance actions always stay inside the school they belong to
- Message attachments must belong to the sender and the school before they are sent
Message Notification Sounds on Mobile
Message notification sounds now actually play on iOS and Android, matching the tones on the web app, and the picker lets you hear each one before choosing.
- Real sounds: The Soft, Chime, and Double tones are now delivered as the actual push sound on your device, not just a saved preference
- Tap to preview: A redesigned in-app sound picker plays each tone as you browse, replacing the old list with no preview
- Reliable saving: Your choice now shows immediately after you pick it, fixing the case where it still read "Default" right after saving
Mobile Operations and Notifications
Improved the mobile school-day tools and made notification controls reflect what users actually receive.
- Emergency roster: Safe checkmarks now persist while staff account for students and teachers, with a Mark All Safe action and clear unaccounted-person prompts
- Notification inbox: The mobile Notices tab now shows each user's personal received notifications, with read state and delete controls
- Notification preferences: Message push delivery now honors the Messages push toggle, and parent checkout access was restored after a scope-gate regression
iPad Experience Redesign and Tablet Mode
A ground-up rework of how the mobile app looks and works on iPad, plus a new full-screen Tablet Mode kiosk for shared school devices.
- Floating navigation: The iPad tab bar is now a compact translucent bar that floats over full-width content instead of a wide sidebar
- Full-bleed layouts: Dashboards, lists, and grids use the whole iPad screen with multi-column layouts instead of a stretched phone column
- Tablet Mode kiosk: School admins and staff can launch a full-screen check-in/check-out kiosk with PIN authorization, health screening, and a PIN-protected exit. It is ideal for a room or front-desk iPad.
iPad Support for the Mobile App
The CentreCareOS mobile app (v1.0.5) now runs natively on iPad, designed for shared room tablets and front-desk use in schools.
- Native iPad app: Full-resolution iPad support with all orientations, Split View multitasking, and layouts that adapt to the window size
- Sidebar navigation: On iPad, the bottom tab bar becomes an iPad-style sidebar for faster movement between sections
- Adaptive screens: Dashboards, student and room lists, attendance, messaging, and settings use multi-column grids and readable content widths on larger screens
Public API and Waitlist Hardening
Hardened public and admin API paths while preserving normal school, applicant, and developer workflows.
- Public APIs: Career applications, public school lookup, Paystack account resolution, and eligible-user lookup now have tighter abuse controls and safer error responses
- Waitlist: Opening generation now runs only from an explicit POST action, so read-only checks cannot mutate waitlist opportunities
- Programs and Photos: Program creation now preserves an explicit zero capacity, and API-key photo sharing uses the server-authenticated path
Profile Activity Pagination Hardening
Tightened profile activity pagination handling so invalid page controls cannot produce malformed activity windows.
- Profile Activity: Activity history now normalizes page and limit inputs and caps page size for stable, predictable results
Enterprise Multi-Location Support
Added Enterprise-gated location management for schools with multiple centers, including location-based room organization and scoped administrator access.
- Locations: Enterprise schools can create and manage center locations, assign classrooms to sites, and filter classrooms and students by location
- Admin Access: School admins can be scoped to specific locations, with server-side checks limiting room, student, and admin-invite actions to their assigned sites
- Plan Controls: Super admins can grant, block, or clear multi-location access overrides from the platform schools dashboard
Security and Reliability Hardening
Hardened billing reports, room assignment, messaging indicators, room lookup, and support inbox APIs.
- Billing Reports: Reports now validate date filters, limit abusive refreshes, and avoid global payment-table scans
- Messaging and Rooms: Typing indicators, read receipts, room lookup, and bulk room assignment now enforce tighter server-side authorization checks
- Support Tools: Support inbox routes now match platform permission rules and return generic failure messages
Mail Timezone Fix
Fixed Platform Mail timestamps so sent and received messages keep the correct Eastern Time date across web, mobile, and external inboxes.
- Email Delivery: Outbound mail now includes an explicit send-date header tied to the exact send instant
- Platform Mail: Web and mobile inboxes now display mail dates in CentreCareOS's Eastern Time business timezone instead of the viewer device timezone
Security Hardening
Closed a set of account, billing, and abuse-prevention gaps found in a security review. These changes are transparent to normal use of the web and mobile apps.
- Account Linking: Signing in now only links an account when the email is verified and is never rebound to a different identity, preventing invited-account takeover
- Attendance Privacy: Staff and teachers can only open attendance records for children in the rooms they are assigned to
- Billing Privacy: Parents can only look up the payment status of their own invoices
- Abuse Prevention: Durable brute-force protection on PIN check-in, plus rate limits on file and support uploads
Message Editing & Announcement Access
Added sender-only message editing across school, platform, support, and public chat conversations, with edited timestamps visible on web and mobile.
- Mobile Messaging: Long-press message actions now include Edit for supported message types, including platform and support conversations
- Platform Announcements: Announcement management is now hidden from school roles and gated by active platform role on mobile, web, API, and boundaries
Platform Message Clarity
Fixed admin-to-admin platform conversations so each participant's messages render on the correct side of the thread with the sender name visible for received messages.
API Boundary Hardening
Tightened tenant-scoped API writes, form response access, admissions, photos, and Paystack verification flows.
- Tenant Safety: Billing settings now only save allowlisted fields against the authenticated school, and form submission reads require authorized server or admin access
- Mobile/API Reliability: Admissions and photo-sharing helper endpoints now use the correct authenticated or server-scoped paths
- Payments: Paystack payment confirmations re-check amounts before marking invoices or subscriptions paid
Security Hardening & Export Fixes
Hardened paperwork review, form sharing, imports, reporting, and billing-adjacent routes while improving CSV exports for admins.
- Paperwork Review: Submission approval and rejection now require admin access, prevent repeat reviews, and only send review emails to known submitter or linked parent addresses
- Forms & Invites: Form share and parent invite email flows now cap batches, rate-limit sends, and avoid duplicate invitation bursts
- Reports & Exports: Daily-report summaries now respect older date ranges, and billing/paperwork CSV exports escape spreadsheet formulas and quotes correctly
Loud Alarm Test Delivery Fix
Restored super-admin loud on-call test delivery by keeping critical push payloads within Expo's remote push contract.
- On-Call Tests: Loud alarm tests now use the supported high-priority sound/channel payload again, while Android vibration and selected sounds are handled by the native notification channels
- Diagnostics: Expo push ticket failures for platform alerts are now logged with redacted token details for faster troubleshooting
Selectable On-Call Alarm Sounds
Added mobile controls for choosing the loud alarm used by critical super-admin on-call alerts.
- Alarm Choices: Super admins can choose Classic Alarm, Volunteer Fire Whistle, Siren Alarm, or Emergency Sound Alarm from the mobile On-Call notification settings
- Critical Pushes: The selected alarm sound now drives the bundled notification sound, Android alarm channel, and in-app looping alert screen for critical on-call events
On-Call Alarm Delivery Tuning
Tuned critical super-admin on-call alert delivery so alarm tests behave more urgently before the mobile app is opened.
- Android Alarms: Critical on-call pushes now request a sticky notification with a longer vibration pattern on the high-priority alarm channel
- iOS Alarms: Critical on-call pushes now request time-sensitive delivery where the device and notification settings allow it
Billing Digest & Alert Testing
Added a weekly preview of upcoming auto-generated billing invoices and direct super-admin controls for testing platform security alert delivery.
- Weekly Billing Digest: School admins now receive a Monday digest showing the upcoming Monday-Sunday invoice window, expected invoice count, student/payer details, generation dates, due dates, and totals
- Billing Schedule: Invoice preview, cron generation, and digest calculations now share the same due-date, billing-period, discount, and plan interval helpers
- On-Call Testing: Super admins can trigger synthetic platform security alerts and loud on-call alarm tests from Platform Settings
Paperwork Waitlist Pipeline Fix
Fixed waitlist forms so reviewed submissions reliably create the matching waitlist entries in the configured room without duplicate rows.
- Waitlist Forms: Public waitlist submissions now use the secure server path when auto-adding families to the waitlist
- Review Flow: Marking a waitlist response reviewed now ensures the waitlist entry exists before sending the review email
- Room Targeting: Add-from-submission now respects the form's configured target room and priority, and repeat clicks return the existing linked entry instead of creating duplicates
- Waitlist Enrollment: Enrolling from the waitlist now respects the active dashboard school, validates the selected room before creating records, and surfaces room-capacity blockers clearly
Platform Mail Polish
Improved the new admin mail experience with better mobile composing behavior and smarter sender identity handling for inbound email conversations.
- Android Mail: The reply composer now resizes above the keyboard instead of being covered while typing
- Sender Names: When a later inbound email includes a display name, recent earlier messages from that sender are updated so threads stop showing only the email address
- Send-As Aliases: Mailbox aliases can now each use their own sender name, so support, billing, and personal addresses no longer have to share one display name
- Marketing Replies: Marketing sender addresses now receive replies directly, attach replies to the matching outreach step, and support Gmail-style follow-up replies inside the marketing timeline
- Notification Startup: Mobile notification taps now restore the saved session immediately and refresh auth in the background, avoiding long splash-screen stalls from older notifications
Enrollment, Signatures & Room Staffing Hardening
Closed cross-tenant access gaps in enrollment, restricted signature and support access to the correct roles, and fixed room staffing for enterprise API and mobile admins along with a couple of billing setup glitches.
- Enrollment: Enrolling from a form submission or the waitlist is now restricted to school admins and verifies the form, submission, and waitlist entry belong to the caller's school
- Signatures: Reading a document's signatures (which include personal data) now requires a staff/admin role, and signature uploads are size-limited and scoped to the caller's school
- Room Staffing: Assigning and removing room staff now works for enterprise API keys and mobile admins, with server-side checks that the room belongs to the caller's school
- Support Access: Support-thread tooling is now gated purely on platform support permissions, matching the backend, and API errors no longer echo internal details
- Billing Setup: The Paystack payment-profile button now enables only after the account name is verified, and account verification is debounced so it no longer shows a name from a previous entry
Admissions & Waitlist Hardening
Closed tenant-isolation gaps and restored several mobile and enterprise API workflows for admissions, tours, waitlists, student detail, and parent account deletion.
- Tours & Waitlist: Update and delete actions now verify the record belongs to the caller's school before making changes
- Mobile Workflows: Waitlist, admissions status updates, student detail, and parent account-deletion requests now work through the REST API with server-side tenant checks
- Staff Compliance: Staff training and certification records are restricted to staff/admin viewers, with edits limited to administrators
Security & Reliability Hardening
Closed a set of authorization and account-safety gaps and fixed several reporting and integration defects surfaced by an automated security scan.
- Incident Reports: Staff and teachers now only see, edit, and delete incident reports for their assigned rooms, matching the rest of the platform's room scoping
- Account Security: Changing your password now always requires your current password (verified server-side, rate-limited, and signing out other sessions); forgotten passwords go through the dedicated reset flow
- Roles: Adding a parent or staff role to an existing account now verifies that account already belongs to your school, preventing cross-school role changes
- Teacher & Parent Accounts: Staff, teacher, and parent roles can now share one login, with role switching available in the web dashboard and mobile app
- Developer API: The published JavaScript SDK now signs write requests, so create/update/delete calls work as documented
- Calendar & Photos: Mobile and API-key clients can use calendar events and photo endpoints again, with safer role-switch redirects and generic unexpected-error responses
- Enterprise API: Tightened attendance tenant scoping, restored API-key access for rooms, menus, and schedules, and strengthened public form spam limits
- Security Hardening: Staff role changes, daily reports, schedule time off, support chat, invitation reminders, and canned responses now enforce tighter server-side authorization and safer error handling
- Asset & Paperwork Safety: Audio assets, daily-report creation, form submission review, conversation rooms, food items, and student exports now have tighter tenant checks and safer server-side handling
- Reporting: Attendance reports render data again, and admin/mobile support tickets show the correct requester name
Account & Billing Hardening
Strengthened sensitive account, invitation, and payment flows while improving billing reliability.
- Account Security: Password changes now throttle repeated verification attempts and sign out other active sessions
- Invitations: Invite acceptance requires a verified primary email, avoids sensitive token logging, and preserves existing primary roles for multi-role users
- Billing: Payment intent creation now derives invoice amounts server-side, blocks duplicate Paystack checkout attempts, and limits inactive plan checkout
- Admissions: Failed waitlist status updates now restore the card to its actual prior status
Security Hardening
Closed a set of authorization, account-linking, and content-safety gaps across invitations, billing, uploads, and exports.
- Account Linking: Invitations only link an existing account when the invited address is the verified primary email, and expired invitations no longer apply their role
- Access Control: Payment intents require invoice ownership or billing-admin access, staff invites are limited to staff/admin roles, and the public-API staff read path is properly server-authorized
- Content Safety: Uploaded document, photo, and media URLs are validated to safe schemes before they are stored or rendered, and roster CSV exports neutralize spreadsheet formula injection
- Reliability: Parents can view shared photos again, admin message attachments are validated before upload, new schools get their trial subscription in one step, and sign-in sync verifies requests carefully
Platform Support Inbox & Security
Refined platform messaging and the support inbox, expanded announcements, and hardened backend authorization.
- Platform Messaging: Fixed sender identity, user lists, unread routing, and conversation start; added message deletion and restricted platform-admin direct messages
- Support Inbox: Surfaced school-role support threads, preserved role context, and fixed list layout
- Announcements: Added mobile announcement targets and fixed the announcement picker scrolling
- Notifications & Media: Expanded platform alert emails with actor details and improved web voice note playback
- Security: Hardened server-to-server auth and authorization
Attendance, Staff Time & Billing
Completed attendance check-out workflows, staff time tracking, and billing improvements.
- Attendance: Added audited check-out and parent child check-out flows, and fixed same-day re-check-in status
- Staff: Completed the staff time tracking workflow and tightened staff school scoping and route auth
- Billing: Added school-admin invoice deletion and billing due notifications, and fixed billing route authorization
- Parents: Notified parents when photos are shared and fixed daily report parent display fields
Messaging Upgrades & Account Privacy
Reworked messaging notifications and delivery, redesigned the new-chat experience, and added account and privacy pages.
- Messaging: Added room/group notification titles, per-platform mute, soft-hide delete, and a redesigned new-chat dialog
- Delivery: Used sender names for push titles, healed room-chat membership, and hid removed users from lists
- Voice Notes: Redesigned the web voice recorder and improved typing indicators
- Privacy: Added a public account deletion page and updated the mobile privacy policy
Status Page, Reliability & Data Import
Redesigned the public status page, added reliability probes, and shipped a school data import system.
- Status Page: Redesigned with richer live indicators, daily rollups, and refined group summaries
- Reliability: Added external health monitoring for outages, and reduced database load on the busiest features
- Data Import: Added a Brightwheel import system with bulk parent invites and a super-admin import entry point
Platform Access, Auth & Support Push
Expanded platform admin access controls, moved API routes onto authenticated clients, and added support chat push alerts.
- Platform Admin: Expanded access controls, routed admins to the right landing pages, and handled accepted invites and support redirects
- Auth Hardening: Used authenticated server clients across API routes and preferred session role and school IDs over stored user data
- Support Push: Added support chat push alerts and broadened push recipient matching
- Homepage: Redesigned the hero with a brand explainer panel
Marketing Outreach
Added a marketing outreach system for admins.
- Outreach: Added a marketing outreach schema and admin permissions with alternate-email support for contacts
- Delivery: Improved send retries, failure handling, dark-mode error states, and failed-send removal
Emergency Roster & Support Routing
Added an emergency attendance roster and hardened contact and support routing.
- Attendance: Added an emergency attendance roster with export actions
- Support: Hardened contact form routing with a support fallback
Admin Cleanup, Support Presence & Attendance Controls
Cleaned up the super admin experience, expanded school attendance and notification settings, improved live support handoffs, and refreshed the homepage showcase and messaging.
- Support Inbox: Added assignment activity messages, in-thread reassignment controls, per-agent typing indicators, first-name agent labels, and reduced duplicate typing writes
- Admin Navigation: Added support unread badges to the super admin sidebar so messages and support inbox activity remain visible when sections are collapsed
- Admin Settings: Moved one-time review school setup and status alert email utilities into the settings area to reduce dashboard clutter
- Attendance Settings: Wired PIN-backed attendance, QR scan, digital signature, activity log, and school notification controls into their related dashboard and API flows
- Homepage: Replaced the dashboard showcase with the latest local screenshot asset and refined the hero and final call-to-action copy
Security, API Keys & Platform Alerts
Strengthened tenant isolation, API authentication, platform security monitoring, school deletion safety, and enterprise API access across high-risk admin and data paths.
- Tenant Security: Added broader tenant access checks across school, parent, staff, billing, forms, photos, schedules, and other shared data functions
- Server Auth: Tightened how internal services call the backend and how sensitive routes check access
- API Credentials: Added key-pair API credentials, form scopes, improved reveal/copy actions, updated SDKs, and expanded enterprise student data access
- Platform Alerts: Added platform security alerts for sensitive admin actions and configurable super admin on-call alert settings
- Admin Maintenance: Hardened school deletion, cleaned up Clerk identities, removed the legacy asset migration flow, and fixed admin analytics exclusions for removed users
Parent Calendar, Voice Notes & Marketing Polish
Improved parent-facing calendar access, messaging media reliability, public page theming, SEO metadata, and branded loading/auth screens.
- Parent Calendar: Added a parent calendar view, filtered events by child rooms, exposed calendar events through the parent API, and surfaced upcoming activity on the parent dashboard
- Voice Notes: Transcoded uploaded voice notes to M4A for more reliable playback and added explicit conversion failure handling
- Messaging Assets: Linked platform message assets to conversations and added a one-time repair for older platform message attachments
- Public Pages: Centralized marketing SEO metadata and schema helpers while updating parent communication and resource pages to use theme tokens
- Auth Polish: Refreshed the loading screen with a branded spinner and normalized sign-in, signup, invite, and callback screens to a cleaner light theme
Storage, Support Uploads & Status Monitoring
Completed the move to secure file storage, hardened support chat attachments, aligned support conversation controls, and updated platform status monitoring so file health reflects the new storage path.
- Secure File Storage: File uploads now use secure platform storage with safer access links and attachment metadata
- Support Attachments: Split live support uploads into direct storage upload and commit steps so image attachments avoid server body limits and preserve asset IDs
- Support Conversation UI: Matched public live-support message bubbles to the internal messaging layout and fixed delete conversation from the support detail menu
- Notification Sounds: Preserved asset IDs for custom notification sounds so migrated sounds and newly uploaded sounds share the same validated shape
- Status Monitoring: Updated file upload health checks to probe Storage upload URL generation instead of relying on legacy blob token configuration
Autopay, ACH & Parent Billing by Child
Expanded billing with ACH payment support, autopay enrollment, normalized invoice amount handling, child-level parent billing summaries, and refreshed public screenshots for the billing and parent communication experience.
- ACH Payments: Added bank-account payment methods across setup, checkout, parent billing, and dashboard billing
- Autopay: Added autopay enrollment, automatic invoice payment, and parent notification emails
- Invoice Accuracy: Normalized invoice amount calculations across generation, scheduled billing, payments, and student plan handling
- Parent Billing View: Parent billing now groups invoices, balances, plans, and payment context by child for clearer family account review
- Billing Help & Marketing: Updated billing help content, payment method summaries, dashboard school fallback handling, and homepage product screenshots
Attendance, QR Check-In & Tablet Mode
Reworked attendance and tablet check-in around faster QR sessions, stronger PIN verification, clearer attendance views, and more reliable scan handling for school front-desk workflows.
- QR Sessions: Added QR session APIs, QR session state, scan validation, session refresh handling, and deployment routing for scan endpoints
- Tablet Mode: Improved the tablet check-in screen with stronger scan states, better PIN flow handling, and clearer check-in/check-out feedback
- PIN Verification: Optimized check-in PIN lookup and verification so authorized pickup and staff flows respond more reliably
- Attendance Page: Refined the dashboard attendance experience, navigation links, student status handling, and attendance API responses
- School Settings: Updated check-in configuration surfaces so QR and tablet-mode behaviour can be managed more consistently
Alerts, Admissions & Messaging Persistence
Added incident alert emails for status monitoring, improved admissions outcomes, preserved admin role context when returning to the dashboard, and reduced messaging read churn with persistent unread count support.
- Status Alerts: Added status incident alert emails, template preview and test-send support, queued email delivery, and a super-admin alert test panel
- Uptime Recording: Normalized uptime history to Eastern dates, gated scheduled recording, and records uptime snapshots from public status requests
- Admissions Pipeline: Refined waitlist outcome handling, admissions reporting, dashboard admissions views, and related help documentation
- Admin Role Context: Preserved the active admin role when switching back from super-admin areas to the school dashboard
- Messaging Persistence: Added unread count backfill and persistence, capped message queries, guarded support read marks, and reduced read churn
Public Status Pages & Uptime Monitoring
Added a front-facing CentreCareOS status experience with public service health, admin diagnostics, live refresh, persistent uptime tracking, and mobile layout refinements for the uptime history view.
- Public Status Page: Added a public /status page, footer and navbar entry points, and a public JSON endpoint for current platform health
- Admin Diagnostics: Added an admin status view with private details, service probes, latency checks, and protected JSON diagnostics
- Persistent Uptime: Added persistent uptime history, per-component 60-day history, and persistent percentage calculations across platform services
- Live Refresh: Status pages now poll automatically, expose manual refresh, and report refresh failures without blocking the page
- Mobile Polish: Improved status history spacing, exact 100% uptime display, public route access, and footer link grouping on small screens
Uploaded PDF Forms & Support Conversations
Expanded Paperwork to support uploaded document forms and assignment workflows, while improving support conversations with deletion controls, better unauthenticated access handling, and backend conversation performance work.
- Uploaded PDF Forms: Added document upload handling, uploaded-form metadata, public rendering support, and builder flow refinements for document-based forms
- Assignment Flow: Added form assignment APIs and dashboard controls so uploaded forms can be assigned and tracked through Paperwork
- Support Deletion: Added support conversation deletion in the admin support inbox with-side cleanup handling
- Support Access: Improved unauthenticated support thread handling so inaccessible threads fail gracefully instead of breaking the admin view
- Conversation Performance: Optimized public chat and support conversation data paths with schema and query updates
Session, Messaging & Admin Hardening
Aligned API routes with the newer session and conversation models, improved message thread scrolling, and strengthened billing, notification, parent, staff, and admin data access paths.
- Session Alignment: Sign-in and session handling work more consistently across web pages and APIs
- Messaging: Fixed message-thread scrolling and updated platform and parent messaging routes for the newer conversation model
- Billing & Notifications: Adjusted subscription, invoice, notification, daily report, incident, and parent billing routes for safer session-aware behaviour
- Signatures: Added signature support and connected related schema and API generated types
- Admin Data: Improved admin, schools, users, photos, staff training, and audit log handling across functions and API routes
Permissions, Compliance & Staff Time Controls
Added platform permission management, automated ratio compliance, stronger staff viewer restrictions, staff time entry validation, and API key administration updates.
- Platform Permissions: Added platform permission models, helpers, admin user controls, navigation gating, support access checks, and role-switch integration
- Admin User Dialogs: Improved admin user management dialogs for assigning and reviewing platform permissions
- Ratio Compliance: Added automated ratio compliance calculations, schema support, functions, dashboard indicators, and room/settings integration
- Staff Viewer Restrictions: Restricted school management actions for staff viewers across parents, rooms, and students screens
- Staff Time & API Keys: Added staff time entry controls, timecard validation, API key deletion controls, and clearer API key scope labels
Paperwork - Response Actions & Parent Emails
Added a form-aware response review flow for Paperwork submissions. Admins now see action labels that match the form type and can optionally notify parents with an editable email before confirming the action.
- Form-Aware Actions: Enrollment, waitlist, tour, consent, survey, and general responses now use appropriate labels like Approve, Mark Reviewed, Accept, Decline, or Flag
- Parent Notifications: Review actions can send optional parent emails with editable recipient, subject, and message fields
- Email Templates: Added default messages for enrollment approvals/rejections, waitlist updates, tour updates, consent reviews, and generic response reviews
- Action Endpoint: New submission action API updates review status and logs sent emails with form ID, submission ID, action, and template metadata
Paperwork - Forms, Tours & Submission Reliability
Major Paperwork improvements focused on robust public submissions, tour booking correctness, response PDFs, multi-child workflows, form branding, branching, and notification controls.
- Response PDFs: Added downloadable PDF exports for individual Paperwork submissions with formatted answers and submission metadata
- Multi-Child Workflows: Enrollment and waitlist submissions can now extract and process multiple children with per-child room assignments
- Tour Booking: Removed legacy duplicate tour preference fields, normalized tour form data, and fixed timezone-safe slot validation using date/time metadata
- Published Preview Testing: Published form previews can now be filled and submitted so admins can test the full response and PDF flow
- Form Builder: Added branding, logo support, branching logic, notification emails, answer-in-notification controls, and stronger submission validation/rate limiting
Privacy, Messaging & Platform Hardening
Strengthened account deletion, privacy documentation, invitation handling, signup notifications, messaging security, public chat, upload validation, and SDK-facing developer surfaces.
- Account Deletion: Added deletion and data-retention handling across parent, staff, user, and profile flows
- Privacy & Terms: Updated public policy pages with clearer account deletion, retention, and legal language
- Invitations: Tightened Clerk invitation acceptance, invitation state updates, and signup notification queue behaviour with route tests
- Messaging & Uploads: Hardened public chat, conversations, support and form uploads, and payment confirmation handling
- Developer Tooling: Added agent skills, security remediation notes, and small SDK/documentation updates
Staff Time Clock, Photos & App Review Setup
Added staff time tracking, improved photo metadata editing, hardened incident handling, and introduced a dedicated app review school setup workflow for platform testing.
- Staff Time Clock: Added timecards, timecard summaries, staff dashboard clock controls, and school time clock settings
- Photos: Added photo date editing and normalized photo API payloads for more consistent gallery behaviour
- Incidents: Improved nullable incident field handling and parent email handling in incident routes and UI
- App Review School: Added admin UI, API route, and single save support for creating and managing app review school data
Paperwork, Announcements & Messaging Foundations
Built the foundation for richer Paperwork forms, tour booking availability, form audiences and reminders, announcement management, voice notes, and notification fan-out.
- Tour Booking Forms: Added configurable recurring windows, one-off slots, blocked dates, per-window date bounds, public slot picker, and tour auto-creation
- Form Audiences & Reminders: Added audience targeting, reminder scheduling, user notifications, reminder cron support, and form assignment emails
- Real-Time Public Forms: Public form previews and slot pickers now subscribe through with no-cache API handling and live updates
- Announcements: Added announcement lifecycle management with create, edit, publish, archive, delete, page targeting, and searchable page picker
- Messaging: Added reusable voice note recording and moved push notification fan-out into messaging notifications
State Compliance - Licensing Links Fixed
Researched and verified all external licensing resource links across 10 state ratio pages. Replaced broken URLs with accurate, working alternatives from official state agency websites.
- Texas: Replaced broken HHS licensing and TAC Chapter 746 links with current HHS child care and minimum standards pages
- Florida: Updated DCF child care link after site reorganisation (old URL returned 404)
- Massachusetts: Replaced dead 606 CMR 7.00 regulations link with EEC laws and regulations listing
- California: Replaced broken Title 22 PDF link with provider regulations page
- New York: Replaced dead regs.health.ny.gov link with OCFS Part 418-1 PDF
- New Sections Added: Connecticut, Vermont, Rhode Island, and New Hampshire pages now include official licensing resource links
Homepage & CTA Copy Refresh
Replaced generic AI-sounding call-to-action copy across the homepage, features, and resources pages with human, childcare-specific messaging.
- Homepage: CTA updated from "Ready to simplify?" to "Run your centre, not your admin."
- Features Page: CTA updated to "Your centre deserves better tools."
- Staff Ratios Page: CTA updated to "Stay compliant without the spreadsheet headache."
- Supporting Copy: Refreshed subtext to feel more personal and relevant to childcare operators
Mobile App - Reports API Routes
Created four new API endpoints to power the mobile app's report screens. Fixed "Something went wrong" errors on Financial, Students, and Operational reports.
- Financial Reports:
/api/reports/financial provides revenue summaries, invoice breakdowns by status, transactions, and overdue balances. - Student Reports:
/api/reports/students provides total, active, enrolled, and withdrawn counts, with breakdowns by enrollment status and room. - Attendance Reports:
/api/reports/attendance provides today's attendance rate, present and absent counts, and seven-day trend data. - Admissions Reports:
/api/reports/admissions provides a pipeline derived from enrollments in the last 30 days. - Auth & Context: All endpoints use session-based auth with school context
Mobile App - Super Admin More Tab Overhaul
Built out full functionality for the super admin More tab, including ticket management with conversation threads, announcement CRUD, and push notification settings verification.
- Support Inbox: Full ticket conversation thread view with status filters, reply support, internal notes, and status transitions
- Ticket UX: Live count badges per status tab (Open, In Progress, Resolved, Closed), unread indicators, relative time formatting
- Announcements CRUD: Create, edit, publish, archive, and delete announcements with page/section targeting and optional links
- Announcement UX: Page path picker with presets (Dashboard, Billing, Students, etc.), floating action button, real-time updates via
- Settings Verification: Confirmed push notifications, token registration, Android notification channels, haptic feedback toggle, and system settings link all function correctly
Mobile App - Complete Billing Functionality
Full billing feature parity on mobile includes payments, plans, student billing assignments, reports, and settings, all with create, edit, and delete support.
- Payments Tab: Full payment history with amount, method, date, status tracking, and deposit date display
- Billing Plans: Dedicated screen to create, edit, and delete plans with weekly, bi-weekly, monthly, and one-time frequencies
- Student Billing: Assign and remove billing plans per student, view plan amount, frequency, and discount info
- Billing Reports: Three-tab reports screen (Overview, Overdue, Transactions) with revenue summaries, overdue balances by student, and full transaction history
- Billing Settings: Auto-billing configuration, late fee rules (percentage, fixed, grace period), invoice template customisation (terms, footer, tax rate), and payment reminder scheduling
Mobile App - Apple-Like UI/UX Overhaul
Complete mobile UI rebuild with 12 reusable Apple-inspired components, 15 screen redesigns, a new dashboard, and the More tab. Everything is powered by real-time with REST API fallback.
- Design System: 12 reusable components: MetricCard, SegmentControl, PillFilter, ActionRow, ProgressRing, SearchBar, Badge, ListItem, EmptyState, FAB, SectionHeader, and Card.
- Dashboard Redesign: Hero attendance ring, horizontal metric scroll, quick insights grid, recent check-ins stack, room ratio capacity bars
- Screen Rebuilds (15): Students, Rooms, Parents (new), Waitlist (new), Calendar, Attendance, Daily Reports, Incident Reports, Admin Billing, Staff, Lesson Plans, Schedules, Menu Planning (new), Paperwork, Admissions
- More Tab: Apple Settings-style grouped navigation with coloured icons and role-based feature groups (My School, Daily Operations, Communication, Management, Administrative)
- Technical: Zero TypeScript errors, real-time primary with REST fallback on all screens, pull-to-refresh and haptic feedback throughout
Mobile Form UX Overhaul & API Flow Fixes
Replaced all plain text date/time inputs across the mobile app with native DateTimePicker components. Added proper selector chips for age groups and other categorical fields. Audited every create/submit flow and fixed payload mismatches that were silently dropping user data.
- DateTimePicker: Nap times, incident date/time, lesson plan dates, calendar event dates, attendance report filters, and billing due dates now use native date/time pickers instead of raw text input
- Age Group Chips: Room creation and lesson plans now use selectable chip buttons (Infant, Toddler, Pre-K, etc.) instead of free-text entry
- Lesson Plans Fix: Fixed
objectives → learningObjectives and notes → description field name mismatches that silently dropped learning objectives during save. - Calendar Events Fix: Fixed event type casing (uppercase → lowercase) to match API expectations
- Attendance Fix: Removed unsupported pickup fields and embedded relevant info into notes field
API Endpoint 401 → 404 Fixes
Fixed 8 API detail endpoints that incorrectly returned HTTP 401 (triggering "Session expired" on mobile) when school context was unavailable. These now return proper 404 responses and include super-admin fallback logic.
- Endpoints Fixed: students/[id], daily-reports/[id], incident-reports/[id], lesson-plans/[id], rooms/[id], attendance/[id], staff/[id], admissions/[id]
- Super Admin Fallback: Super admins get a clearer school context when viewing school data
Mobile Real-Time Migration - 18 Screens Now Live
Wired up real-time subscriptions across 18 mobile app screens, bringing coverage from 13% (5 screens) to ~60% (23 screens). All screens use live data as the primary source, with automatic REST API fallback when it is unavailable. Data updates are now instant and automatic. No pull-to-refresh is needed.
- New user data hook: Resolves document IDs from Clerk auth session for real-time query subscriptions
- Tier 1 (Safety): Attendance, Daily Reports, Incident Reports, and Announcements are now real-time.
- Tier 2 (Experience): Students, Photos, Admin Billing, Parent Billing, Parent Photos, Parent Activity, and Dashboards are now real-time.
- Tier 3 (Collaboration): Rooms, Schedules, Lesson Plans, Calendar, Staff Management, and Admissions are now real-time.
- Expanded API refs: Added 50+ query function references for students, dailyReports, incidents, photos, staff, parents, invoices, admissions, forms, notifications
Real-Time Readiness Audit - Web & Mobile
Completed a full audit of real-time usage across the web app and mobile app. The web app has 94 query functions powering ~65% real-time coverage, while the mobile app only uses real-time for messaging (5 of ~40 screens). Identified 14 mobile screens that can be migrated to the backend real-time subscriptions for instant, snappy updates, eliminating pull-to-refresh for attendance, daily reports, incident reports, photos, announcements, billing, and more.
- Web app: 94 queries, 100+ live subscriptions, messaging fully real-time, dashboards live
- Mobile app: 5 real-time screens (messaging only), 35+ screens still on REST API with manual pull-to-refresh
- Tier 1 targets: Attendance, Daily Reports, Incident Reports, and Announcements all have backend queries ready.
- Tier 2 targets: Photos, Student List, Dashboard Stats, and Billing/Invoices support high-impact parent and staff experiences.
- Tier 3 targets: Rooms, Schedules, Lesson Plans, Calendar, Staff Management, and Admissions support staff collaboration.
Fixed “Session Expired” Errors for School Admin on Mobile
Resolved a bug where school admin users (and super admins who switched to school admin) would see “Session expired. Please log in again” when navigating to Photos, Daily Reports, or Incident Reports from the More tab.
- Root cause: The More tab routed SCHOOL_ADMIN users to parent-only endpoints (/api/parent/*) which returned 401, incorrectly displayed as “Session expired”
- Fixed Photos routing from /parent-photos to /staff-photos for admin roles
- Fixed Daily Reports routing from Activity tab (parent-only) to /daily-reports (role-aware)
- Fixed role detection in 4 screens to use activeRole (current role after switching) instead of role (immutable primary role)
Fixed Mobile Conversation List Metadata Clipping
We tightened the right-hand metadata area in the mobile message conversation lists so timestamps and pin actions no longer push list rows past the viewport edge.
- Super admin and dashboard conversation rows now use smaller mobile timestamp/pin clusters with truncation and tighter sizing on the trailing edge
- List items now enforce stronger `min-w-0` and overflow handling so long names and previews stay readable instead of getting cut off by the right-side metadata
Improved Mobile Web Message Sound Playback
We improved in-app message notifications on mobile browsers by priming the web audio system after the user’s first interaction, which helps mobile web sessions play notification sounds more reliably.
- Dashboard and admin message notifiers now unlock the browser audio context on first tap, keypress, or touch interaction instead of waiting for a background unread event to try to create audio too late
- This keeps desktop behavior the same while improving mobile web support where autoplay restrictions are stricter
Removed Competing Scroll Containers from Admin Mobile Threads
We fixed a deeper stability issue in the super admin mobile messages and support views by preventing the outer admin page shell from scrolling on top of the thread’s own message body scroll area.
- Admin messages and support routes now use an immersive mobile layout mode where the page shell stops scrolling and the thread body becomes the single active scroll surface
- This keeps the thread header and composer visually pinned while the message chain itself scrolls, matching the intended mobile chat behavior more closely
Stabilized Mobile Message and Support Threads
We tightened the internal mobile thread layouts for super admin messages and support so the header, message body, and composer behave like stable rails instead of drifting or clipping on narrow screens.
- Platform message threads now isolate scrolling to the message body, keep the top header and bottom composer visually stable, and prevent conversation content from clipping to the right
- The mobile conversation list uses stronger overflow handling and tighter row layout so names, previews, and actions fit small screens more reliably
- Support threads and the support inbox now use the same mobile stability treatment, reducing header wobble and keeping the thread rail layout more consistent while scrolling
Rebuilt Mobile Support and Messages Interiors
We rebuilt the internal mobile layouts for the super admin support inbox and platform messages so they behave like real list-and-thread mobile experiences instead of compressed desktop workspaces.
- The support inbox now has a dedicated mobile list view with horizontal status filters, full-width search, compact conversation cards, and tap-to-open thread navigation
- Support thread detail now adapts for mobile with a stacked header, compact status controls, a lightweight summary strip, and the desktop sidebar hidden off small screens
- Platform messages now use tighter mobile spacing, improved bubble widths, and a full-screen compose flow for starting new conversations on phones
Fixed Mobile Admin Dashboard Tab Always Appearing Active
We corrected a route-matching issue in the mobile super admin shell where the root `/admin` route was being treated like a prefix match, making the Dashboard tab and header stay active on other admin pages.
- The mobile admin bottom nav now only marks Dashboard active on the actual `/admin` route instead of every `/admin/*` page
- The mobile admin menu uses the same corrected route matching, so active styling no longer sticks to Dashboard when another section is open
- The top mobile admin header now resolves the correct section title instead of repeatedly showing Dashboard across other admin pages
Fixed Mobile Shell Compression and Menu Scrolling
We corrected a layout bug in the new mobile authenticated shells where the super admin mobile header could behave like a flex column sibling and squeeze the page content, and we fixed the mobile nav menu so longer menus can scroll cleanly from top to bottom.
- Moved the mobile admin shell into the main column flow so dashboard cards and page content no longer get pushed and crunched to the right on small screens
- Added `min-w-0` and tighter overflow handling to the authenticated shell containers so responsive content can shrink properly instead of breaking the mobile layout
- Fixed the full-screen mobile menus to use a true scrollable content region, preventing menu items from being cut off below the fold
Added Separate Mobile Shells for Dashboard and Super Admin Areas
We introduced dedicated mobile authenticated shells so phones and smaller tablets no longer have to squeeze the desktop sidebar workspace into narrow screens. Desktop keeps the current shell; mobile now gets a different navigation model entirely.
- Dashboard pages now switch to a mobile shell under smaller breakpoints with a sticky top bar, bottom navigation, and full-screen navigation menu while leaving the desktop sidebar intact
- Super admin pages now get their own mobile shell with direct access to dashboard, schools, messages, support, and the rest of the admin navigation from a dedicated menu
- Dashboard and admin navigation are now driven from shared route configs so desktop and mobile stay aligned instead of drifting into separate route maps
More Reliable Mobile Admin Screens
Some mobile admin screens could fail after the app had been open a while even though chat still worked. Session refresh is more reliable so school detail and other admin tools keep loading.
- Mobile admin tools refresh sign-in more like the web app
- Super admin school detail and related screens stay signed in longer
- Live messaging continues to work as before
Added a Fallback Lookup Path for School Detail
We fixed a deeper inconsistency on the super admin school detail route where a school could appear in the working schools list but still fail the direct school-by-id lookup path.
- When the product data source throws for a valid school id, the route now falls back to the product data source and resolves the school from the known-working admin list
- This preserves `404` behavior for genuinely missing schools while avoiding false `500` failures for ids that are clearly present in the admin schools screen
- The stage-specific `school_detail_lookup_failed` diagnostic remains in place if both the primary lookup and fallback path fail
Added Stage-Specific Error Codes to the School Detail Endpoint
We made the super admin school detail route return failure codes on 500 responses so mobile testing can distinguish parameter resolution problems, client setup failures, primary school lookup failures, and generic unhandled crashes instead of only seeing a generic internal-server-error body.
- `school_detail_params_failed` identifies route-param resolution failures before the school lookup even begins
- `school_detail_client_failed` and `school_detail_lookup_failed` distinguish client/auth failures from school record lookup failures
- `school_detail_unhandled` remains as the final catch-all so remaining failures can be isolated more quickly from mobile logs
Hardened the Super Admin School Detail Endpoint
We reduced a brittle failure path on the mobile-facing school detail route so one secondary data lookup no longer causes the entire page request to fail with a 500.
- Changed `/api/admin/schools/[id]` to fetch users, students, rooms, and subscription data with graceful fallback instead of failing the whole response when one dependency throws
- Added `loadWarnings` to the school detail payload so degraded sections can be identified without blocking the main school detail screen
- Improved server logging for partial dependency failures so the backend can pinpoint whether users, students, rooms, or subscription lookups are responsible when a detail screen misbehaves
Added a Concrete Mobile School Detail Implementation Guide
We documented the correct REST contract and React Query screen pattern for the super admin school detail screen so mobile can stop relying on overly defensive field guessing and fix the “School not found” navigation issues more directly.
- Defined the exact route-param rule: navigate with `school.id`, normalize `params.id`, and only fetch when a valid string id exists
- Documented the current `/api/admin/schools/[id]` response contract, including the `school` wrapper alias, counts, stats, subscription, recent users, and rooms
- Added a concrete React Native screen skeleton and normalizer so the mobile team can implement the detail page with a simpler, stable mapping
Clearer Super Admin Mobile Data Guide
We documented the data shapes the mobile app should use for the super admin dashboard, schools list, and platform support inbox so those screens stop depending on REST-era shapes.
- Clarified that live data super admin dashboard data comes from the product data source, not the REST analytics response shape
- Documented the live data schools list shape from the product data source, including where counts, subscription info, and admin details actually live
- Explained the live data platform inbox and thread mappings so mobile reads `conversation.user` and `message.senderFirstName` instead of older REST-normalized name fields
Standardized Messaging Guidance on Direct
We clarified the messaging architecture for web and mobile so chat threads, unread state, typing, and live updates should be built directly on instead of the older REST-plus-Pusher compatibility path.
- Added a messaging guide covering school chat and platform support by role
- Updated the React Native handoff docs to mark REST and Pusher chat routes as compatibility-only rather than the primary mobile messaging contract
- Kept push-token registration as the background notification path while separating that from realtime thread rendering, which should now rely on subscriptions
Completed the Mobile Super Admin Thread Contract
We finished the backend contract the mobile app needs for opening super admin platform-message threads, sending replies, and receiving new incoming user messages in real time.
- Normalized the super admin message thread API so mobile can load a conversation header, participant details, and full message history from one response
- Kept reply sending backward-compatible while documenting the required multipart form-data contract for text, files, images, and audio
- Added live super admin thread updates for incoming user platform messages through the existing Pusher channel and user-inbox update events
Normalized Mobile Admin School Detail and Messaging Responses
We tightened a mobile integration gap on the super admin side by making the school-detail and platform-messaging REST responses explicit and easier to render, instead of requiring the app to infer nested shapes.
- Updated `/api/admin/messages/conversations` to return mobile-friendly conversation fields like `title`, `participant`, `user_display_name`, `last_message_preview`, and `unread_count`
- Updated `/api/admin/messages/[conversationId]` to return structured thread metadata plus normalized message fields such as `sender_display_name`, `sender_profile_photo`, `content_type`, and `created_at`
- Expanded `/api/admin/schools/[id]` with richer counts, billing/status aliases, and a nested `school` detail wrapper to simplify mobile detail screens
Completed the Mobile Profile and Settings API Surface
We added the missing REST profile/settings surface for mobile and aligned more session-backed endpoints with the authenticated server data bridge so profile, notifications, PIN, support, and platform messaging flows behave consistently across web and React Native.
- Added `/api/profile` for mobile profile reads and updates, including names, message sound preferences, and onboarding dismissal state
- Profile, notifications, security, support, and platform messages work more reliably from signed-in mobile sessions
- School admin dashboard stats load correctly from the mobile app
- Made the platform avatar endpoint use the public platform settings path so branded support/profile imagery resolves more reliably
Repaired Mobile School Detail Loading and Clarified Messaging APIs
We fixed a follow-up mobile integration issue where super admin school detail requests were still wired to stale backend query names, and clarified which messaging APIs the mobile app should use for threaded chat versus legacy mailbox flows.
- Fixed the super admin school detail endpoint so tapping a school can load rooms, users, and subscription details again
- Updated the authenticated session profile routes to use the same authenticated server data bridge as the mobile admin APIs
- Documented that React Native should use `/api/conversations*` for school chat threads and `/api/user/platform-messages*` or `/api/admin/messages*` for platform support messaging
Fixed Super Admin Mobile Access
React Native admin requests could pass API auth but still hit as anonymous because mobile session tokens were not carrying a-compatible auth token into the admin API layer.
- Mobile session tokens now capture the active sign-in and mint a matching auth token during mobile sign-in
- Super admin schools, analytics, users, and messaging work correctly from the mobile app
- Mobile session refresh now preserves the Clerk session link and renews the embedded session when possible
Fixed Super Admin API Endpoints Returning Empty Mobile Data
Several admin API routes were authorizing correctly at the HTTP layer but still querying as an anonymous server client, which caused empty arrays and null analytics on super admin mobile screens.
- Reworked the admin API layer to use authenticated server-side server clients instead of anonymous queries
- Fixed empty admin schools responses and restored populated analytics for super admin dashboard cards
- Applied the same authenticated pattern across the broader admin API surface to reduce follow-on mobile failures
Compare Pages Refreshed with Current Competitor Positioning
We refreshed the marketing comparison pages so they reflect current competitor branding and present-day positioning instead of older childcare software messaging.
- Updated the compare hub and competitor pages with current Brightwheel, Lillio, Procare, and Playground positioning
- Replaced the outdated HiMama comparison with a current Lillio comparison while keeping the old route redirected
- Added structured data and metadata improvements across compare pages to strengthen SEO and keep snippets more current
Fixed Google Trial Signup Callback Loop
New free-trial signups coming back from Google now continue into school setup correctly instead of bouncing between the auth callback and the signup page.
- Google trial signups now return through a dedicated callback flow that preserves onboarding intent
- The auth callback now sends un-onboarded trial users into the school setup step instead of retrying session sync forever
- Signed-in Google users also have their Clerk name and email carried into signup so onboarding can complete cleanly after OAuth
Platform-Wide Default Notification Sound with User Overrides
Super admins can now choose a platform default message sound that all roles inherit automatically, while still allowing individual users to override it with their own preference.
- Added a platform default notification sound selector in super admin settings alongside the shared sound library
- Users now inherit the platform default only when they have not saved their own sound preference
- Live unread-message notifiers across the app now resolve sounds through the same fallback chain, keeping background alerts consistent with settings
Cleaner Sticky Settings Tabs and More Intuitive Sound Uploads
The settings tab bar now sits more cleanly against scrolling content, and the shared sound upload flow has been made clearer and easier to understand.
- Added a full sticky backdrop behind settings tab bars so scrolling content no longer peeks above the rounded tab container while you scroll
- Refined the shared notification sound uploader into a clearer choose-file and save flow instead of requiring users to infer the upload sequence
- Added clearer guidance around naming and saving shared sounds before they are published to all user notification settings
Better Settings Tab Navigation and Platform-Wide Custom Message Sounds
Settings tabs now make horizontal scrolling more obvious, and super admins can upload custom notification sounds that become available to every user across the platform.
- Added visible horizontal-scroll affordances to the settings tab bars so it is clearer when more sections are available off-screen
- Super admins can now upload and manage shared custom message sounds directly from admin settings
- Uploaded sounds are now available in notification preferences for all roles and are used by live unread-message alerts throughout the app
School Settings Now Use a Cleaner Top-Tab Layout
The school admin settings experience now mirrors the super admin settings layout, making it faster to move between sections without scrolling through a long page.
- Moved school settings sections into a horizontally scrollable top-tab workspace instead of one long stacked layout
- Added direct tabs for password, check-in PIN, message notifications, onboarding, check-in settings, learning, access, payroll, and API access
- Preserved the existing save and toggle behavior while improving navigation and reducing vertical scanning
Cleaner Message List Truncation and Pinned Conversation Styling
Messaging conversation lists were refined so long names stay neatly truncated and pinned conversations use a cleaner visual accent.
- Fixed long conversation names so they truncate properly inside the list instead of clipping awkwardly into adjacent controls
- Updated pinned conversation rows to use a slimmer, straighter left accent instead of the previous curved edge treatment
- Applied the same cleanup across both the regular dashboard messaging list and the super admin message list for consistency
Cleaner Super Admin Settings Navigation and More Accurate Support Badges
Super admin settings now behave more like a true tabbed workspace, and support inbox badges no longer hang onto unread counts after agent reads or resolved conversations.
- Refined the super admin settings page into a clearer top-tab layout with a sticky, horizontally scrollable tab bar so sections are easier to switch without long vertical scanning
- Fixed support inbox unread counting so only truly unread visitor messages on active threads contribute to the sidebar badge
- Agent replies now clear outstanding visitor unread markers immediately, keeping the inbox count aligned with what support staff actually see
Faster Direct Messaging and Better Composer Fit
The new message composer was refined to feel less cramped and faster to use. Conversation modes now fit more cleanly in the available space, and starting a direct message takes fewer steps.
- Compacted the conversation-mode rail and made it scrollable so all options remain visible instead of clipping at the bottom
- Direct messages now open as soon as you click a person, removing the extra confirmation step from the composer flow
- Simplified the right-side layout for direct messages so the composer uses space more efficiently and feels less heavy
Wider New Message Composer and In-App Platform Support Access
The Messages experience now gives school admins, staff, and parents a cleaner way to start conversations. The new message composer was redesigned into a wider split-panel layout, and platform support can now be opened directly from inside Messages instead of only from the public site chat widget.
- Added a dedicated Platform Support entry inside the new conversation flow so users can jump straight into their support thread from Messages
- Redesigned the new conversation modal into a wider two-panel composer with clearer conversation modes, better room cards, and more breathing room for contact selection
- Improved direct and group messaging setup with clearer role filters, stronger group summaries, and a less cramped contact list experience
Separate Super Admin Sounds for Platform Messages and Support Inbox
Super admins can now configure distinct message sounds for internal platform conversations and support inbox activity, with live unread tracking for both channels directly in the admin experience.
- Added dedicated super admin notification sound controls in admin settings for platform messages and support inbox activity
- The admin shell now listens for unread changes in both message channels and plays the correct saved sound for each one
- Support inbox unread tracking now counts actual unread visitor messages instead of just open threads, and the admin sidebar shows that unread badge separately
Per-User Message Sounds and Cross-Device Welcome Guide Persistence
Messaging alerts and school-admin onboarding now respect saved user preferences instead of relying on browser-only state. Users can choose how message sounds behave, and school admins who dismiss the welcome guide will not be shown the same walkthrough again on another browser or device.
- Added in-app message sound preferences to account settings for all roles, including multiple alert styles and an option to turn sounds off completely
- Background message notifications use each user's saved sound preference instead of a single default alert
- School-admin welcome guide dismissal is now persisted to the account, so skipping or closing it once prevents it from reappearing on a different browser later
- Resetting the welcome guide from settings now clears the saved server-side preference instead of only removing a local browser flag
Messaging Badge Accuracy and New Message Alerts
Messaging badges now track unread conversations more accurately across the dashboard and super admin experiences, and incoming messages can trigger an audible alert when you are away from the current messaging view.
- Fixed sidebar message badges so they reflect total unread messaging state instead of only one subset of conversations
- Open threads now clear unread state more reliably when messages arrive while the conversation is visible, without incorrectly dismissing them while the tab is hidden
- Added a background new-message sound notification for unread increases when you are outside the active messaging view or the browser tab is inactive
Voice Note Duration and Playback Timing Fixes
Audio messages in messaging were updated to handle browser metadata more reliably so voice notes show stable duration values and playback timing on both the sender and recipient sides.
- Fixed message-bubble audio players so voice notes no longer render broken values like `Infinity:NaN` while metadata is loading
- Added safer duration parsing and extra metadata listeners so the total audio length resolves more consistently for sent and received voice notes
- Applied the same defensive timing logic to the file preview modal to keep audio playback displays aligned across messaging surfaces
Mobile App Readiness and React Native Engineering Handoff
The platform backend was tightened to support a first-party React Native app using the existing product architecture. Mobile auth now maps much more cleanly onto the current multi-role session model, and a new engineering handoff documents the live data, API surface, and implementation structure needed to build the mobile app.
- Added a new React Native engineering handoff with detailed guidance for auth, usage, dashboards, domain APIs, and mobile build order
- Expanded mobile session handling so API routes can use a signed-in session that carries the same role, school, impersonation, and billing context the web app uses
- Mobile session refresh resolves the correct user, and trial read-only rules respect multi-role mobile sessions
- Hardened push token endpoints for the mobile app by removing legacy session-field assumptions from registration and debugging flows
Billing Upgrade, Session Recovery, and Custom School Dashboards
Billing and dashboard infrastructure received a major upgrade. School billing now supports richer subscription management flows, stronger exemption handling, faster live data loading through, and configurable school admin dashboards with custom widgets.
- Added yearly billing and more complete subscription management flows, including better provider sync and exemption-aware access handling
- Introduced session recovery and clearer auth loading states so admin and school dashboards recover more reliably after idle periods
- Replaced more SWR and REST-driven dashboard reads with queries, including faster billing snapshots and more live school data
- School admins can now customize their home dashboard widgets, including room ratios, activity summaries, and upcoming holidays
- Added direct deep-linking into the dashboard settings tab and improved save feedback with visible success states and mounted toasters
Server Integration and Platform Reliability Improvements
This release focused on infrastructure and reliability. More server-side routes now talk to the backend directly, maintenance mode became more consistent, invitations and staff creation were hardened, and automated test coverage was added for key flows.
- Added a reusable server client and public-function helper for backend reads like maintenance status and platform settings
- Improved maintenance-mode reliability with better cache control, live polling, and audit-log overrides
- Invitation flows now rely more cleanly on and Resend, with stronger staff record creation, deduplication, and cleanup behavior
- Updated public API auth and key route integrations around billing and attendance endpoints
- Added Vitest-based automated coverage for important invitation, messaging, billing-access, and subscription flows
Super Admin School Impersonation
Super admins can now enter a school context directly from the platform dashboard. The impersonation flow was then tightened with follow-up fixes to make context switching, dashboard rendering, and visual state more reliable.
- Added school admin impersonation from the super admin experience
- Fixed multiple robustness issues around impersonation state, school switching, and dashboard context resolution
- Refreshed the impersonation banner styling to make active impersonation mode more obvious
Enrollment Pipeline and Expanded Real-Time Operations
Admissions, parent access, and school operations all moved forward in this release. Enrollment became more complete end to end, parent views were unified into the dashboard experience, and more operational pages switched over to real-time data.
- Added a fuller enrollment pipeline with one-click enrollment flow, waitlist form support, editable enrollment dialogs, and related invitation fixes
- Unified the parent portal into the main dashboard layout and fixed missing-child, incident, and dashboard data issues for parents
- Added the Data tab with CSV import and export workflows for schools
- Improved room management with bulk assignment support and migrated rooms plus more dashboard tabs to live queries
- Expanded the broader migration by moving more pages onto hooks and standardizing more app data on camelCase field shapes
Auth Import Migration: auth-session to convex-auth
Moved authentication onto the modern sign-in stack used across the product, and removed outdated password-reset and auth leftovers.
- All 148 API routes now import { getSession, isAdminRole } from the current auth module
- Deleted dead auth code: app/actions/auth.ts and app/api/auth/forgot-password/ route
- Billing plans, student plans, and payment-method sync use the same modern backend as the rest of the app
- Migrated Stripe Connect, subscription invoices, forms, push notifications, and platform-fee routes to the backend
- convex-auth.ts provides backward-compatible SessionData interface with Clerk + user lookups
Fix: Email Queue Sends Directly via Resend
Email delivery from the queue is more reliable after simplifying how messages are sent to the email provider.
- Outbound queue emails go straight to the email provider, which is more reliable
- Email HTML template and wrapper are built inline within the action
- Sent emails are still recorded for the admin email log
- Only requires email provider key in the backend env vars; FROM_EMAIL and app base URL are optional
Fix: Email Queue Not Delivering
Fixed a critical bug where the email queue processor could not reach the Next.js email send API. The URL resolution had an operator precedence issue and relied on environment variables not available in the runtime. The processor now reads a dedicated app base URL variable and throws a clear error if it is missing.
- Fixed JS ternary operator precedence bug in base URL construction
- Added app base URL as the primary env var (must be set in the backend dashboard)
- Added explicit error message when no app URL is configured, preventing silent failures
Email Templates: Light Mode Conversion
Converted all email templates from a dark theme to a light theme to fix readability issues when emails are opened on devices with dark mode enabled. Gmail and other email clients will now auto-generate clean dark versions instead of conflicting with an already-dark design.
- Converted shared email wrapper to light theme: white card on light gray background with dark text
- Updated color-scheme meta tags from dark to light for proper email client handling
- Fixed all inline style overrides across 11 email templates (invoices, invites, alerts, contact, careers, etc.)
- Added !important declarations on key colors to prevent email client dark mode from overriding styles
Cleanup: Remove Migrations Tab
Removed the temporary Database Migrations page and its sidebar navigation entry from the super admin dashboard. The migration tooling was only needed during the messaging system refactor and is no longer required.
- Removed /admin/migrations page and its associated sidebar link
- Cleaned up unused Database icon import from the admin sidebar
Rate-Limited Email Queue
All signup notification emails now flow through a platform-backed queue system that respects Resend rate limits. Even if 20 schools sign up simultaneously, every notification is queued instantly and processed one at a time with 1.2-second delays between sends. Failed emails are automatically retried up to 3 times.
- New emailQueue table in the backend with pending/processing/sent/failed status tracking
- Self-scheduling internal action processes jobs sequentially with rate-limit-safe delays
- Automatic retry (up to 3 attempts) for any email that fails to send
- Both live signup and retroactive notifications now enqueue instead of sending directly
Retroactive Signup Notifications
Super admins can now send signup notification emails retroactively for schools that signed up before the notification system was configured. A new card on the Platform Settings page lets you select the last 3 to 20 signups, preview the list, and fire off the notifications in one click.
- New query fetches the most recent school signups with admin details
- Scrollable preview list shows school name, admin, and signup date before sending
- Uses the same beautifully designed email template as live signup notifications
Visual Consistency & Signup Notification Emails
Unified all dashboard stat card icons and numbers across the platform to use the signature teal/primary color. This change spans the super admin dashboard, school admin dashboard, staff dashboard, parent dashboard, API settings, Paystack accounts, Stripe accounts, and email logs -- eliminating the previous mix of green, amber, purple, blue, pink, and red stat colors.
Added a configurable signup notification system so super admins receive beautifully designed email alerts whenever a new school signs up. Notification recipient emails can now be managed directly from the super admin Platform Settings page under "Signup Notifications" -- no environment variable changes needed.
- All stat card icons and numbers now use consistent primary/teal color
- Paystack and Stripe account stat numbers unified
- API settings, email logs, staff and parent dashboard icons unified
- Signup notification emails configurable from admin settings
- Notification system reads from the backend platform settings with env var fallback
Maintenance Mode -- Fully Implemented
The maintenance mode toggle in Super Admin Settings now fully enforces platform downtime. When enabled, all non-super-admin users are redirected to a dedicated maintenance page, and external API calls receive a 503 response.
- Dedicated /maintenance page with custom message display, auto-refresh every 30 seconds, and automatic redirect back to the dashboard when maintenance ends
- Dashboard layout checks maintenance status in real-time and redirects non-super-admin users -- super admins are never locked out and retain full access to both /admin and /dashboard
- Mobile and integration APIs return a clear “service unavailable, try again later” response during maintenance
- All public marketing pages, sign-in, and admin dashboard remain accessible during maintenance
Intervo.ai Chat Widget & Provider Toggle
Added Intervo.ai as a backup AI chat widget alongside Chatbase. Super admins can now switch between providers instantly from the Platform Settings page without any downtime.
- Intervo.ai widget integrated -- loads dynamically via script injection and cleans up when switching back to Chatbase
- Chat Widget card added to Admin Settings with a two-option selector -- clicking a provider saves and activates it instantly
- Provider preference stored in the backend platformSettings and served via a new public query so the front-end widget loads the correct provider on every page
Official JavaScript & Python SDKs
Released official single-file SDK libraries for JavaScript/Node.js and Python, with full documentation on the developer portal including installation guides, usage examples for every resource, and error handling patterns.
- JavaScript/Node.js SDK (centrecareos.js) -- zero-dependency, works in Node.js 18+ and modern browsers using native fetch
- Python SDK (centrecareos.py) -- Python 3.7+ compatible with the requests library, supports context manager pattern
- Both SDKs cover all API resources: students, attendance, billing, rooms, staff, and messages with full JSDoc/docstring annotations
- Developer portal updated with download links, code examples for every resource, error handling guides, and rate limit tracking
Super Admin Invite Emails + Email Logs Dashboard
Fixed a bug where super admin invite emails were never sent after creating a new user. Added a comprehensive Email Logs dashboard in the super admin panel that tracks and previews every email sent from the platform with category filtering.
- Super admin invite now generates a password reset token and sends a branded invitation email with account setup link
- New Email Logs page at /admin/email-logs with full email preview, status tracking, and category filtering
- All 15+ email types now logged automatically: staff invites, parent invites, password resets, invoices, daily reports, incident alerts, and more
- Email preview dialog renders the exact HTML that was sent, with metadata including recipient, subject, category, and sent/failed status
Unified AI + Live Support Chat Widget
The public-facing chat widget now combines an AI Assistant (powered by Chatbase) and Live Support in a single unified interface. Users can switch between AI help for common questions and live human support when needed, all from one floating widget.
- Tabbed interface with "AI Assistant" and "Live Support" tabs inside the chat widget header
- AI Assistant tab embeds Chatbase chatbot for instant answers about CentreCareOS features, pricing, and common questions
- Live Support tab retains all existing functionality including real-time messaging, file attachments, typing indicators, and read receipts
- Unread message badge appears on the Live Support tab when new agent messages arrive while viewing the AI tab
Automatic Room Group Chats
Every room can now have its own group chat that automatically includes all assigned staff, parents of enrolled students, and school administrators. Room chats sync participants when staff or students are added or removed from rooms. Super admins can join any room chat and see the full message history.
- New "Room" tab in New Conversation dialog to create or join room chats
- Auto-populated participants from room staff assignments, student-parent links, and school admins
- Automatic participant sync when room assignments change (staff added/removed, students enrolled/transferred)
- Distinct room chat icon and "Room" badge in conversation list for easy identification
- "Room Chat" label and member count shown in the message thread header
Remove Duplicate Help Center Route
Removed the redundant /help-center page and consolidated all help documentation under the /help route. Updated all references across the footer, sitemap, email templates, billing page, and developers page to point to /help.
Documentation Accuracy & Sync
Complete rewrite of both the in-dashboard and public-facing help documentation based on a thorough audit of every feature in the codebase. Both help pages now contain identical article content, ensuring no conflicting information between the dashboard and public help center.
- Full Content Audit -- Rewrote all 21 help articles across 20 categories based on actual codebase features including schema fields, page flows, form fields, statuses, and role permissions
- Content Sync -- Dashboard and public help pages now share identical article data, categories, descriptions, and role assignments, eliminating all content drift
- New Articles -- Added dedicated articles for Waitlist Management, Menu Planning, and Parent Billing that were previously missing or incomplete
- Accurate Feature Coverage -- Updated documentation for billing plans, auto-invoicing, Stripe/Paystack integration, staff time tracking, training records, admissions pipeline, paperwork form builder, lesson plan frameworks, calendar event types, and all report categories
Role Corrections & Public Documentation Redesign
Fixed incorrect role tags across the entire platform to match the actual four-role system (Super Admin, School Admin, Staff, Parent). Completely rebuilt the public /help page into the same three-pane SaaS-style documentation layout used in the dashboard: left sidebar with collapsible category navigation and search, center content area with breadcrumbs and article rendering, and right-side "On this page" table of contents with scroll-tracked heading highlighting. Also fixed a crash in the chat widget and admin support pages.
- Role System Fix - Removed incorrect "Admin" and "Teacher" roles from sidebar navigation, dashboard help docs, and public help docs. The platform uses only four roles: Super Admin, School Admin, Staff, and Parent
- Public Docs Redesign - Rebuilt the public-facing /help page with the same SaaS-style documentation design as the dashboard version, including sidebar navigation, search, table of contents, and comprehensive articles
- Dark/Light Mode - Public help pages now fully support dark and light mode using semantic design tokens throughout
- Documentation Accuracy - Updated all article content in both dashboard and public documentation to accurately reflect current features, correct role access levels, and detailed usage instructions
SaaS Documentation Redesign
Completely redesigned the in-dashboard help pages into a professional SaaS-style documentation system with sidebar navigation, search, table of contents, and comprehensive articles covering every feature.
- Docs-style Layout - Three-column layout with collapsible sidebar navigation, main content area, and "On this page" table of contents
- Comprehensive Content - 14 documentation categories with 25+ detailed articles covering getting started, attendance, daily reports, messaging, billing, students, parents, rooms, staff, admissions, settings, and more
- Global Search - Full-text search across all documentation articles with instant results dropdown
- Role Tags and Related Articles - Each article shows role-based access badges and links to related documentation
Support Chat: Typing Indicators, Read Receipts & Presence
Added real-time typing indicators, read receipts with double-check marks, and online presence tracking to the support chat system between visitors and admins.
- Typing Indicators - Animated bouncing dots in real-time when visitors or agents are typing, with automatic 3-second timeout
- Read Receipts - Single check for sent, double check for delivered, blue double check when read by the other party
- Presence Tracking - Green pulse dot for online visitors, "last seen" timestamps for offline users, shown in header and sidebar
- Schema Updates - New fields for typing state, read timestamps, delivery tracking, and presence heartbeats on both supportThreads and supportMessages tables
Mobile App Authentication Endpoint
The mobile app can sign in with the same account system as the web and stay signed in for API calls.
- Mobile Session Endpoint - Mobile sign-in exchanges a valid login for a session the app can use on subsequent requests
- Token Refresh - Mobile sessions can refresh quietly so users stay signed in
- Mobile API access - Signed-in mobile requests can reach the same APIs as the web app
Full Paystack Payment Flows, Currency Support & Admin Stability
African schools can now pay platform subscriptions and receive parent fee payments via Paystack, with automatic currency handling and payment status updates. Admin dashboard crashes on reload and sign-out have also been resolved.
- Paystack Subscription Checkout - Schools in Paystack regions can now subscribe to platform plans via Paystack-hosted checkout, with automatic subscription activation on payment verification
- Parent Invoice Payments via Paystack - Parents at African schools can pay invoices through Paystack with subaccount split payments, so schools receive funds directly with the platform fee deducted automatically
- Paystack Payment Confirmations - Payment confirmations update invoices and save payment methods automatically
- Per-School Currency - Currency auto-detected from country (NGN, GHS, KES, ZAR, USD, GBP, etc.) and used across all billing UIs, invoice amounts, and payment displays
- Country Field on Settings - School admins can now set their country in school settings, and super admins can set it on the admin schools page; payment provider and currency auto-update when country changes
- Admin Dashboard Stability - Fixed crashes on page reload, sign-out, and session expiry across all admin queries (getAllSchools, getAllUsers, getAllPlans, getPlatformSettings, getAuditLogs, getAllApiKeys, getAllAnnouncements) by replacing throwing auth checks with graceful empty returns
Paystack Payment Integration for African Schools
Schools in Nigeria, Ghana, Kenya, and South Africa can now accept parent payments via Paystack with automatic bank settlements, alongside the existing Stripe integration for other regions.
- Paystack Subaccount Setup - Schools in Paystack-supported countries see a dedicated bank account linking form in billing settings with real-time account verification via Paystack's Resolve API
- Automatic Provider Detection - The billing settings page auto-detects whether to show Stripe Connect or Paystack setup based on the school's country, with region-specific fee breakdowns
- Bank Search and Verification - Searchable dropdown of banks per country with instant account name resolution before subaccount creation
- Admin Paystack Dashboard - New super admin page to view all Paystack-linked schools, subaccount status, bank details, and settlement schedules
- Expanded Country List - School registration now supports 30+ countries across Africa, Americas, Europe, Asia, and Oceania with proper country codes
- Payment Confirmation and Transaction APIs - Paystack payment confirmation, transfers, and transaction verification
Enhanced Admin Platform Dashboard
Completely rebuilt the super admin platform dashboard to show live, actionable data across all schools with better space efficiency and real-time alerts.
- 8 Live Stat Cards - Schools, users, enrolled students, MRR, open support tickets, unread messages, today's attendance, and pending invoices with clickable links to detail pages
- Alert Banners - Prominent banners for past due subscriptions, overdue invoices, and trials expiring this week
- Subscription Breakdown - Visual breakdown by status (active, trialing, past due, canceled) and by plan with progress bars
- Top Schools - Leaderboard of schools ranked by enrolled students showing staff count and plan tier
- Expiring Trials - Schools with trials ending within 7 days, with urgency badges for immediate attention
Stripe Connected Accounts Management
Super admins can now view and delete Stripe Connect accounts directly from the admin dashboard, enabling easier cleanup of test accounts and orphaned connections.
- Account Overview - Summary cards showing total accounts, active charges, pending onboarding, and unlinked accounts
- Account Table - Detailed table with account ID, business name, email, linked school, status badges, and creation date
- Delete via API - Delete connected accounts using the Stripe API with confirmation dialog and automatic cleanup of linked school records
- Quick Links - Direct links to view each account in the Stripe Dashboard
Platform Messaging Write Conflict Fixes
Resolved critical write conflicts in the platform messaging system that were causing send failures and extra retries in busy platform conversations.
- Infinite Loop Fix - Fixed markAdminMessagesRead re-firing on every subscription update due to object reference dependencies in useEffect
- No-Op Write Guards - Added early-exit checks to skip writes when unread count is already zero or typing state is unchanged
- Typing Debounce - Typing indicators fire once when typing starts instead of on every keystroke
- Both Sides Fixed - Applied same fixes to both admin-side and user-side messaging components
- Batch Limiting - Limited message read marking to 50 messages per call to reduce transaction conflict window
Mobile App Implementation Guide
Created a comprehensive implementation guide for building the React Native mobile companion app, fully updated for the migration.
- Database Schema - Complete database schema documentation with all 45+ tables, field types, and indexes
- API Route Reference - Full reference covering 160+ REST endpoints organized by feature area
- Authentication Flow - Detailed mobile sign-in documentation for app implementation
- Push Notifications - Registration and delivery implementation guide with Expo
- File Uploads - Vercel Blob integration patterns for React Native
- Payments - Stripe Connect payment flow documentation for parent invoice payments
- Multi-Role Support - Implementation details for role-switching between parent and staff views
- Real-Time Data - Polling vs live data React Native subscription options
- Data Flow Diagrams - Visual flows for auth, check-in, and messaging systems
- Migration Notes - All changes documented from Neon/PostgreSQL to the backend
Public API Documentation
Comprehensive public-facing API documentation is now available for developers building integrations with CentreCareOS. The new Developer Portal provides everything needed to get started with our REST API.
- Developer Portal - New /developers page with complete API documentation including authentication, endpoints, scopes, and error handling
- Endpoint Reference - Detailed documentation for Students, Attendance, Billing, Rooms, Staff, and Messages APIs with required scopes and examples
- Footer Links - Quick access to API documentation added to the site footer and API settings page
Super Admin Plan Assignment
Super admins can now assign subscription plans directly to schools from the admin dashboard. This feature enables quick testing of plan benefits and manual plan management for special cases.
- Assign Plan - New menu option in the schools three-dot menu to assign any available plan to a school
- Plan Selection Dialog - User-friendly dialog showing all available plans with pricing for easy selection
- Audit Logging - All plan assignments are logged with details for tracking and accountability
Enterprise API Access
Introducing API access for Enterprise plan subscribers. Schools can now integrate CentreCareOS with their existing systems, build custom integrations, and automate workflows through a secure, rate-limited API.
- API Key Management - School admins can create, revoke, and manage API keys from the dashboard settings with customizable scopes and expiration
- Granular Permission Scopes - Scoped access across students, attendance, billing, staff, rooms, and reporting so integrations can follow least-privilege access patterns
- Rate Limiting - Configurable rate limits per plan (default 1000 requests/minute) to ensure fair usage and platform stability
- Usage Analytics - Real-time API usage statistics including request counts, response times, and top endpoints
- Super Admin Controls - Platform-wide API management dashboard for monitoring all API keys, usage across schools, and ability to revoke access
- Plan-Based Access - API access can be enabled/disabled per subscription plan with configurable rate limits and allowed scopes
SEO Content Pages & Admin Signup Notifications
Added comprehensive SEO-optimized content pages targeting high-value search queries, plus automatic email notifications when new schools sign up for a free trial.
- State Ratio Pages - Dedicated pages for childcare staff-to-child ratios in Pennsylvania, Massachusetts, California, Texas, New York, Florida, Connecticut, New Hampshire, Rhode Island, and Vermont
- Ratios Hub - Central index page linking to all state-specific ratio guides at /resources/ratios
- Software Comparison Guide - Comprehensive childcare software comparison page at /resources/compare
- Attendance Tracking Guide - SEO page for attendance tracking software queries at /resources/attendance-tracking
- Ireland Childcare Page - International SEO page for Irish childcare centers at /resources/ireland
- Signup Notification Emails - Automatic branded email to admin when a new school signs up, including school name, admin details, country, and signup timestamp
Page-Specific Social Media Previews
Added unique Open Graph and Twitter Card metadata to all public pages. Now when you share a link on social media or messaging apps, each page shows its own specific preview with relevant title, description, and image instead of the generic home page preview.
- Pricing Page - Custom preview highlighting transparent pricing and free trial
- Features Page - Preview showcasing complete childcare management capabilities
- Careers & Job Postings - Individual previews for each job listing (e.g., Marketing Lead)
- Contact Page - Preview encouraging visitors to get in touch
- Compare & Resources Pages - Specific previews for software comparisons and guides
- Changelog Page - Preview highlighting latest product updates
Theme Toggle Bug Fixes Across All Public Pages
Fixed the dark mode toggle to work properly on all public-facing pages. Previously, pages like Features, Pricing, Compare, Careers, Resources, and Changelog had fixed light colors that ignored the theme toggle. All pages now use semantic design tokens for proper theming.
- Footer Theme Fix - Updated footer to use theme-aware tokens (bg-muted, text-muted-foreground, border-border)
- Features Page Fix - Converted from bg-white/text-neutral-* to bg-background/text-foreground
- Pricing Page Fix - Updated colors to theme-aware styles
- Compare Pages Fix - Updated main compare page and all sub-pages (Brightwheel, HiMama, Procare)
- Careers & Resources Pages Fix - Converted to theme-aware styling
- Feature Sub-pages Fix - Updated Attendance and Billing feature pages with proper theming
- Changelog Page Fix - Updated all neutral colors to theme tokens
Public Pages Light Mode with Dark Mode Toggle
Initial implementation of light mode default for public-facing pages with a dark mode toggle in the navigation bar.
- New PublicThemeToggle Component - Theme toggle button in the navigation bar
- Home Page Conversion - Initial conversion to theme-aware styles
- Contact Page Update - Converted to use shared Navbar and Footer components
Staff Room-Based Access Control & Email Dark Mode Fix
Major update implementing room-based access restrictions for staff members. Staff can now only see students, parents, daily reports, photos, and incidents related to their assigned classroom. Also fixed email template visibility in dark mode.
- Email Dark Mode Fix - Updated all email templates with high-contrast colors that remain visible in dark mode email clients
- Room Assignment on Staff Creation - New staff can now be assigned to a room during the invitation process
- Staff Access Restrictions - Staff members can only view students, parents, photos, incidents, daily reports, and attendance from their assigned room
- Read-Only Rooms View - Staff see their assigned room in read-only mode without add/edit/delete buttons
- Hidden Settings - School Settings tab is now hidden from staff members in the sidebar
- Filtered Waitlist - Staff only see waitlist entries for their assigned room
- New StaffRoomProvider - Context provider that manages room-based access throughout the dashboard
- Staff assigned rooms load efficiently for the signed-in person
Messaging Empty State Layout Fix
Fixed the layout issue where the "Select a conversation" message was offset to the left instead of being centered in the message pane on all messaging interfaces.
- Added flex class to message thread container for proper centering
- Added flex-1 to empty state container to fill available space
- Fixed on both dashboard messaging and admin messages pages
Platform Messaging Read Receipts
Added read receipts (tick marks) to platform messaging between super admins and users. Now all messaging interfaces have consistent read receipt indicators showing single tick for sent and double tick for read.
- Platform Message Thread UI - Added Check and CheckCheck icons to show read status for user messages
- markPlatformMessagesRead Fix - Now marks individual admin messages as read when user views them
- markAdminMessagesRead Fix - Now marks individual user messages as read when super admin views them
- Cleaned up debug logging from messaging system
Staff Messaging Display and Header Fix
Fixed messaging display issues where conversation headers showed "?" and "Conversation" instead of the other participant's name and avatar for staff members. Updated queries to properly compute display information for direct conversations.
- getConversation Fix - Now computes display name and avatar from other participant for DIRECT conversations
- Message Details - Added senderName and senderAvatar to message query results for proper display
- Typing Indicators - Added userName field to participants for typing indicator display
Invitation Accept Flow and Email Matching Fix
Fixed staff invitation flow where accept-clerk API was creating duplicate users instead of linking to pre-created users. Added email normalization throughout the flow and debug logging for troubleshooting.
- Accept-Clerk Fix - API now checks for pre-created user by email before creating new user
- Email Normalization - All email comparisons now use lowercase for consistent matching
- Debug Logging - Added console logs throughout invitation flow for easier troubleshooting
- Sign-in sync normalizes email before creating or updating a user
Staff Invitation Role Assignment Fix
Fixed an issue where invited staff members were being redirected to the school setup flow instead of the staff dashboard. The problem was that new invited users were briefly treated as parents before the invitation was accepted.
- User Pre-Creation - Staff invitation now pre-creates user with correct STAFF role before Clerk signup
- Invitation Linking - Users are marked as invited with invitation ID for tracking
- Sign-in sync finds the invited user by email and preserves their assigned role
Multi-Role Super Admin Access Fix
Fixed an issue where Super Admin users with multiple roles could not access the admin dashboard when logged in with a different active role. The system now properly checks the roles array in addition to the primary role.
- requireSuperAdmin Fix - helper now checks both role and roles array for SUPER_ADMIN access
- Dashboard Banner Fix - Super Admin banner now shows when SUPER_ADMIN is in the roles array
- Sidebar Button Fix - Super Admin shield button now visible for users with SUPER_ADMIN in roles array
Invitation Management and Acceptance Loop Fix
Added ability to delete and resend pending invitations from the Staff Directory. Fixed an infinite loop issue when accepting invitations after Clerk sign-up, and widened the Clerk SignUp modal for better usability.
- Invitation Management - Added Resend and Cancel buttons to pending invitations in Staff Directory
- Loop Fix - Fixed infinite 400 error loop when accepting invitations by tracking accepted state properly
- Wider SignUp Modal - Increased Clerk SignUp container width from max-w-lg to max-w-xl for better display
- Admins can cancel and update invitations more reliably
Staff Invitation Flow and Clerk Integration
Fixed the staff invitation acceptance flow to properly integrate with Clerk authentication. Invited staff members now see pending invitations in the Staff Directory, and accepting invitations properly creates Clerk accounts.
- Clerk Integration - Invitation acceptance now uses Clerk SignUp component instead of custom password handling
- New Accept API - /api/invitations/accept-clerk endpoint properly links Clerk users to the backend records
- Pending Invitations UI - Staff Directory now shows pending invitations with status badges
- getPendingInvitations Query - New query to fetch school invitations that haven't been accepted
- Room Assignments Fix - API now returns empty array instead of 500 error when no assignments exist
Simplified Role Assignment for Existing Users
Admins can now easily add existing users as different roles directly from the Parents and Staff Management pages. A staff member can be added as a parent with just a few clicks, and vice versa - no need to re-enter any information.
- Add Existing Staff as Parent - New dropdown option in Parents page to select any staff member and instantly add them as a parent, with optional student linking
- Add Existing Parent as Staff - New dropdown option in Staff Management to select any parent and add them as a staff member, with optional room assignment
- New API Endpoints - /api/users/add-role for adding roles to existing users, and /api/users/eligible-for-role to get users who can be assigned a specific role
- Smart Filtering - The system automatically filters out users who already have the target role, showing only eligible users in the selection dropdown
- Query - New getByUserAndSchool query in staff module to check for existing staff records when adding roles
Multi-Role Support for Users
Users can now have multiple roles within the system. A staff member can also be a parent of a child at the same school, eliminating the need for separate accounts. The invite system intelligently handles existing users by adding roles instead of creating duplicate accounts.
- Schema Update - Added roles array and activeRole fields to users table while maintaining backward compatibility with existing single-role users
- Role Management Mutations - New addRole, removeRole, and switchActiveRole single saves for managing user roles
- Smart Parent Invite Flow - When inviting a parent who already exists as staff, the system adds the PARENT role to their existing account instead of rejecting the invite
- Role Switcher UI - New sidebar component allows users with multiple roles to switch between their active role (e.g., Staff View vs Parent View)
- Auth Session Updates - Session now includes roles array, activeRole, and hasMultipleRoles flag with helper functions for role checking
- Switch Role API - New /api/auth/switch-role endpoint for changing active role with automatic dashboard redirection
- Migration Support - Existing users were updated to support multiple roles from their previous single role
Complete Neon to the backend Migration
Final migration phase converting all remaining 27 API routes from Neon PostgreSQL to the backend. The application is now fully migrated to the backend for all data operations, with Clerk handling authentication.
- Billing Routes (7 files) - Settings, overview, student billing, payment processing, reports, and invoice generation now use billing module
- Staff Routes (4 files) - Timecards, training certifications, time-off requests, and staff details migrated to the backend staff module
- Platform Messaging (2 files) - User-to-admin messaging and read receipts migrated to the backend platformMessages module
- Push Notifications (2 files) - Token registration and management migrated to the backend pushTokens module
- Public Chat Widget (3 files) - Visitor chat start, conversations, and messages migrated to the backend publicChat module
- Incident Routes (3 files) - Parent notification, follow-up, and parent incident viewing migrated to the backend incidents module
- Admin Routes (3 files) - School fee management and billing actions migrated to the backend; legacy migration route removed
- Utility Routes (3 files) - Room students, realtime channel auth, and debug endpoints updated to use
- Password Management - Updated to use Clerk API instead of custom bcrypt hashing
- Main Dashboard - School Stripe status now fetched from the backend schools module
Schema Expansion - Supporting All Features
Major schema expansion adding all missing tables to the backend to support the remaining 28 API routes. New functions added for push tokens, staff training, platform messaging, and billing settings.
- Push Tokens Table - New pushTokens schema for mobile push notification token management with user, platform, and device tracking
- Chat Visitors Table - chatVisitors schema for public chat widget with session tracking, visitor metadata, and rate limiting support
- Staff Training - staffTraining table for tracking certifications, expiration dates, and compliance with complete CRUD functions
- Platform Messaging - platformConversations and platformMessages tables for super admin to user communication system
- Billing Settings - billingSettings table with auto-billing, reminders, late fees, and payment term configuration per school
- Student Billing Assignments - studentBillingAssignments for assigning plans, custom rates, and discounts to students
- School Platform Fees - schoolPlatformFees table for custom platform fee overrides per school
- Enhanced Schools Schema - Added Stripe charges/payouts enabled fields, custom platform fee percent, and country field
- New Modules - platformMessaging.ts, pushTokens.ts, staffTraining.ts with full read and write support
API Migration - Phase 4 (Support & Dashboard)
Extensive migration phase converting support, admin, messaging, and core API routes from Neon to the backend. 28 routes remain using Neon for specialized features requiring schema expansion.
- Support System - Thread listing, thread details, canned responses, and agent management migrated to the backend support module
- Admin Routes - Platform settings, school details, user management now use admin and schools modules
- Admin Messaging - User list and conversation start routes migrated to the backend admin.getAllUsersForMessaging and admin.startPlatformConversation
- Dashboard Stats API - Uses getDashboardStats query for real-time attendance, revenue, and student counts
- Conversation Features - Mute toggle, public schools list, and unread count all migrated to the backend
- Remaining 28 Routes - Still use Neon for billing, staff timecards, public chat, push tokens, and cron jobs
API Migration - Phase 3 (Major)
Major migration phase converting parent portal, admin messaging, authentication, and conversation APIs from Neon to the backend. This completes migration of critical user-facing features.
- Parent Portal APIs - Dashboard, children, billing, and daily reports routes now use queries
- Admin Messaging APIs - Platform conversations, messages, and user lists migrated to the backend with preserved Pusher real-time updates
- Authentication APIs - User details (/auth/me) and password change routes now use for data storage
- Conversations System - Full migration including contacts, conversations list, and role-based access control
- Modules Added - New admin.ts and parents.ts modules for platform messaging and parent data
- Schema Expansion - Added platformConversations and platformMessages tables to the backend schema
API Migration - Phase 2
Continued migration of critical dashboard APIs to the backend, including waitlist management, incident reports, forms, and staff invitations.
- Waitlist API - New module with room stats, position ordering, and enrollment conversion
- Incident Reports API - New module with student/reporter details and severity tracking
- Forms API - Migrated to the backend with form builder integration and submission management
- Staff API - Migrated to the backend with invitation system and email integration preserved
- Calendar Events API - New module with month filtering and time-off protection
- School Settings API - New module with upsert support for all configuration options
- Invitations System - Added single saves for creating, accepting, and managing staff/parent invitations
- Schema Updates - Added incident reports table and expanded invitations schema with name fields
API Migration - Phase 1
Major migration of school admin dashboard API routes from Neon PostgreSQL to the backend for real-time updates and improved performance.
- Students API - Migrated to the backend with full CRUD operations, room assignments, and parent linking
- Parents API - Migrated to the backend with welcome email flow and student linking preserved
- Rooms API - Migrated to the backend with staff assignments and student capacity tracking
- Attendance API - Migrated to the backend with real-time check-in/check-out functionality
- Daily Reports API - New module with upsert support and student info enrichment
- Lesson Plans API - New module with room and date filtering
- Photos Module - New module for photo management with Vercel Blob integration
Billing Exemption UI Restoration
Restored the billing exemption and trial reset controls to the admin schools page dropdown menu.
- Billing Exemption Toggle - Added back the option to exempt schools from billing directly from the schools table dropdown menu
- Reset Trial - Restored the trial reset functionality with customizable day count
- Exempt Status Badge - Added purple "Exempt" status badge and filter option for exempt schools
Super Admin Settings & Announcements Migration
Completed migration of super admin settings and platform announcements to the backend, ensuring all admin functionality uses the real-time database.
- Platform Announcements - Info box announcements now stored and managed via with full CRUD operations
- Platform Settings - Branding, general settings, and toggles (signups, email verification, maintenance mode) all use
- Logo Upload - Platform branding avatar upload uses Vercel Blob with URL stored in the backend
Stripe Integration & Pricing Migration
Complete migration of all Stripe payment flows and pricing pages to use, ensuring consistent data handling across the platform.
- Pricing Page - Now displays plans from the backend with Professional ($199/mo) and Enterprise ($399/mo) tiers
- Subscription Checkout - Stripe checkout flow now reads plan data from the backend and updates subscription status in real-time
- Stripe payment notifications update subscriptions and school records on payment events
- Stripe Connect - Create account, onboarding, and dashboard link routes now use for school data
- Billing Dashboard API - Current subscription, portal, and Connect status routes migrated to the backend
Admin Dashboard Migration
Complete migration of the super admin dashboard from Neon PostgreSQL to the backend for real-time data and consistent architecture across the platform.
- Admin Dashboard - Platform analytics, school counts, user stats, revenue, and recent activity now powered by real-time queries
- Schools Management - Create, edit, and delete schools with subscription tracking all stored in the backend with instant UI updates
- Users Management - User CRUD operations with role and school filtering now using reads and writes
- Plans Management - Subscription plans with features, pricing, and Stripe integration migrated to the backend
- Platform Settings - Global settings including branding, trial days, signup controls, and maintenance mode now in the backend
- Audit Logs - Comprehensive activity tracking with filtering and export functionality using backend
Support Enhancements & Canned Responses
Improved support chat experience with sleeker attachment display, in-app file previews, and a new canned responses system to help support staff respond faster.
- Canned Responses System - Pre-written responses for support agents with categories, shortcuts, and usage tracking. Includes 10 default templates for common scenarios.
- Canned Responses Management - New admin page at /admin/canned-responses for creating, editing, and organizing response templates with search and category filters
- In-App File Preview - Click any attachment to preview PDFs, Word docs, and images in a modal instead of downloading, with option to download or open in new tab
- Sleeker Image Attachments - Removed borders and backgrounds from image attachments in support chat for a cleaner, more modern appearance
- Support Upload Fix - Fixed "Unauthorized" error when visitors uploaded files in the support chat widget by adding the endpoint to public API routes
Database Migration & Real-Time Messaging
Major platform upgrade migrating from Neon PostgreSQL to the backend for real-time database capabilities, along with Clerk authentication integration and a completely rebuilt messaging system.
- Database Migration - Complete migration from Neon PostgreSQL to the backend with 40+ tables, enabling real-time data synchronization across all features
- Sign-in now uses Clerk for secure, managed authentication with social login support and enhanced security
- Real-Time Messaging - Completely rebuilt messaging system with instant message delivery, typing indicators, read receipts, and cross-school super admin messaging
- Public Help Desk - Real-time support chat widget for website visitors with instant responses and ticket management for administrators
- School Admin Sign-up - Streamlined onboarding flow with Clerk authentication, automatic school creation, and trial subscription setup
- Streamlined Authentication - Consolidated sign-in/sign-up flows using Clerk with Google OAuth and email/password options, plus automatic post-auth routing to appropriate dashboards
Comprehensive Reports & Billing Enhancements
Major expansion of the Reports section with comprehensive school-wide reports, enhanced billing with Stripe payment method integration, and improved UI consistency across the platform.
- Comprehensive Reports Hub - New Reports section with 9 report categories: Attendance, Students, Financial, Staff, Incidents, Admissions, Activities, and Communications
- Billing Payment Methods - View connected Stripe payment methods per student, including card type (Visa, Mastercard, etc.), last 4 digits, and auto-pay status
- Billing Reports Tab - New reports section within Billing showing overdue balances, deposits, invoice summaries, revenue breakdown, and transaction history
- Attendance Reports UI Fix - Fixed time display to show human-readable format (e.g., 8:30 AM instead of raw timestamps) and removed colored icon backgrounds for cleaner monochrome styling
- Export Functionality - All reports support CSV export for offline analysis and record-keeping
Super Admin Billing Controls
Added new billing management features to the Super Admin dashboard for better control over school subscriptions and test accounts.
- Reset Trial - Super admins can now reset the 14-day trial period for any school, useful for extending evaluations or resolving customer issues
- Billing Exemption - Schools can be marked as exempt from billing, giving them full platform access without payment requirements, perfect for test accounts and demos
- Visual Indicators - Exempt schools display a Test Account badge in the schools list and show Exempt status in their subscription column for easy identification
Pipeline Drag-and-Drop & Waitlist Integration
Enhanced the Admissions Pipeline with drag-and-drop functionality and intelligent integration with the My School Waitlist, creating a seamless workflow from prospect to enrollment.
- Drag-and-Drop Kanban - Cards can now be dragged between pipeline stages with visual feedback, drop zones highlight when hovering, and grip handles indicate draggable items
- Waitlist Integration - Entries from My School Waitlist with status waiting now automatically appear in the Pipeline Waitlist stage, marked with a From Waitlist badge
- Bidirectional Sync - Moving a prospect to Waitlist stage automatically creates a corresponding entry in My School Waitlist for operational management
- Combined Statistics - Waitlist count in pipeline summary now includes both pipeline entries and My School Waitlist entries for accurate totals
Admissions Tab Redesign
Complete redesign of the Admissions section with clearer purpose and separation from the operational Waitlist. The new structure focuses on tracking the full enrollment journey from inquiry to enrollment.
- Pipeline Tab - Visual kanban-style board tracking prospective families through stages: Inquiry, Tour Scheduled, Toured, Applied, Offered, and Enrolled
- Tours Tab - New dedicated tour scheduling system with parent/child info, date/time selection, staff assignment, and outcome tracking (enrolled, waitlisted, declined, no show)
- Enrollment Forms Tab - Renamed from Admissions Packets for clarity, manages digital enrollment forms and documents
- Removed Redundancy - Eliminated duplicate Waitlists tab and confusing Programs tab that was just showing rooms
- Clear Separation - My School Waitlist remains for day-to-day operational management, while Admissions focuses on the marketing/sales pipeline
Staff Management UI Improvements
Refined staff management interface with cleaner summary cards, enhanced time off request form with start and end times, and various mobile messaging improvements.
- Cleaner Summary Cards - Removed colored background circles from icons in staff management summary cards for a cleaner, monochrome look
- Time Off Request Enhancement - Added start and end time fields to the time off request form for more precise scheduling
- Platform Avatar API - Made platform avatar endpoint publicly accessible for mobile app integration
- Unread Message Count API - New dedicated endpoint for retrieving total unread message count for badge display
- Platform Messaging Updates - CentreCareOS support avatar now properly displays in conversation lists and individual messages
Check-In PIN System & Tablet Mode
Enhanced check-in security with PIN verification, redesigned attendance page with unified student view, and new touch-optimized Tablet Mode for streamlined check-in/check-out at childcare facilities.
- PIN Authentication System - Staff, admin, and parents can set 4-6 digit PINs for secure check-in/check-out verification
- PIN + Last Name Verification - Unique identification combining PIN and last name to prevent duplicates
- Attendance Page Redesign - Unified grid view showing all students with color-coded status badges (Not Arrived, Present, Checked Out)
- Clickable Summary Cards - Filter students by status by clicking on summary cards instead of tabs
- Tablet Mode Interface - Touch-optimized full-screen mode with large buttons for use on tablets at facility entrances
- Multi-Child Check-In - Parents can select and check in multiple children at once with individual health screenings
- Staff Room Assignment - Staff see only their assigned rooms in Tablet Mode for streamlined access
- Audit Trail Enhancement - All check-ins/check-outs now log the verified user's name and role for accountability
- Parent Settings Page - New settings page for parents at /parent/settings with pickup PIN management
- Secure Tablet Mode Exit - Only staff/admin can exit Tablet Mode with PIN verification
- Auto-Reset Timer - Success screen automatically returns to main screen after 5 seconds
Mobile App API Documentation & Careers
Comprehensive API documentation for React Native mobile app development, complete careers section with job application system, and enhanced API organization for all user roles.
- Complete Mobile App API Documentation - 140+ documented endpoints with request/response examples
- Screen Design Mapping - Detailed screen layouts and navigation structure for each role (Super Admin, School Admin, Staff, Parent)
- Role-Based API Reference - Organized by user role with permission indicators
- React Native Implementation Guide - Best practices for authentication, file uploads, offline support, and push notifications
- Careers Page - Professional careers landing page with job listings
- Job Application System - Form with file uploads (resume & cover letter) that emails applications with branded HTML emails
- Marketing Lead Job Posting - First role posted with detailed responsibilities and requirements
- Database Schema Reference - Live schema included in documentation for reference
Super Admin Messaging & Platform Enhancements
Platform-level messaging system allowing super admins to communicate directly with any user across all schools, plus configurable platform fees, automatic billing, and email template management.
- Super Admin Messaging - Message any user across all schools as "CentreCareOS Team"
- Email Template Previews - Preview and send test emails for all 9 platform email templates
- Configurable Platform Fees - Set global default and per-school custom platform fee percentages
- Automatic Invoice Generation - Configurable billing cycles with automatic invoice creation
- Invoice Reminders - Automatic reminder and overdue notification emails
- Enhanced Scholarship/Discount UI - Clear discount fields with live preview of effective amounts
- Email From Name - All emails now show sender as "CentreCareOS Team"
- Dark Mode Fixes - Improved dark mode support across super admin dashboard
Complete Billing System with Stripe
Full-featured billing system allowing schools to create billing plans, assign them to students, and enabling parents to view and pay invoices directly through Stripe.
- Billing Plans - Create and manage recurring fee schedules (weekly, bi-weekly, monthly, yearly)
- Student Plan Assignment - Assign billing plans to students with optional discounts
- Parent Billing Dashboard - Parents can view invoices, balances, and payment history
- Stripe Payment Integration - Secure card payments through Stripe Checkout
- Payment Method Management - Parents can add and update payment methods
- Incident Report Follow-up Fix - Follow-up notes now save correctly without duplication
- Billing sidebar access for parents to easily find their billing information
Comprehensive Help Center
New searchable help center with detailed documentation for all platform features, accessible from both the public site and within the dashboard.
- 35+ detailed help articles covering every feature and workflow
- Real-time search with instant results across all articles
- Role-based filtering to show relevant content for each user type
- In-dashboard help page accessible from the sidebar
- Public help page for prospective customers
- Updated sidebar icons with monochrome design
- Terms of Service and Privacy Policy pages with Massachusetts jurisdiction
International Support
Expanded platform availability to support childcare centers in multiple English-speaking countries with full Stripe Connect payment processing.
- Added support for United States, Canada, United Kingdom, Australia, Ireland, and New Zealand
- New country selector on signup page with flag icons for easy identification
- Stripe Connect Express onboarding automatically adapts to each country's requirements
- Country-specific business verification (EIN for US, BN for Canada, Company Number for UK, ABN for Australia)
- Local bank account formats supported for each country (routing numbers, sort codes, BSB, IBAN)
API Dynamic Rendering Fix
Fixed a critical issue where API routes were incorrectly cached during static generation, causing authenticated routes to fail on first load after deployment.
- Added `export const dynamic = "force-dynamic"` to all API routes
- Fixed all attendance, billing, calendar, and messaging API endpoints
- Prevents Next.js from pre-rendering API routes that require session/cookie access
Stripe Connect & Billing System
Complete billing infrastructure with Stripe Connect for accepting parent payments, platform subscription management, and trial enforcement.
- Stripe Connect Express integration - Schools can onboard and accept payments from parents
- Destination charges with automatic platform fee collection (5% per transaction)
- New Billing Settings page for schools to manage payment setup
- Platform subscription management with self-service upgrade
- Trial warning banner and enforcement when trial expires
- Stripe payment confirmation handling
Role-Based Access Control & Staff Permissions
Comprehensive role-based access control system ensuring staff members only see features relevant to their role, with proper API-level security.
- Role-based sidebar navigation - Staff/Teachers see only relevant menu items
- Admin-only features protected: Billing, Staff Management, Admissions, Reports
- API-level role checks on all admin-only endpoints
- Staff invitation system with email notifications and secure password setup
Dashboard & UX Improvements
Enhanced dashboard experience with improved navigation, better visual feedback, and streamlined workflows.
- Redesigned dashboard home with quick stats and recent activity
- Improved attendance check-in flow with health screening
- Smart checkout with parent and emergency contact quick selection
- Fixed dark mode issues across attendance and daily reports pages
Dark Mode Support
Full dark mode support across the entire dashboard with system preference detection and manual toggle.
- System preference detection for automatic dark mode
- Manual toggle in header for user preference
- All dashboard components updated with dark mode variants
- Improved contrast and readability in both modes
SEO & Marketing Pages
New public-facing pages for marketing and SEO with detailed feature explanations and resources.
- Individual feature pages for Attendance, Billing, Communication, Staff, Enrollment
- Resource center with guides and best practices
- Comparison page showing advantages over competitors
- Improved pricing page with detailed plan comparison
Platform Launch
Initial release of CentreCareOS - a comprehensive childcare management platform.
- Student and parent management with detailed profiles
- Room and program management
- Attendance tracking with health screening
- Daily reports for parents
- Messaging system for parent-staff communication
- Photo sharing with galleries
- Incident reporting and tracking
- Lesson planning tools
- Calendar and scheduling
- Waitlist and admissions management
- Staff management with roles and permissions
- Reports and analytics dashboard