Document E-Signatures, a Reworked Time-Tracking Suite, a Redesigned Profile, and a Big Security Pass
This is a large release. The headline is document e-signatures — you can now route a document (or a finalized timesheet) for a dated, audit-trailed signature without leaving the app. Around it, the time-tracking suite was substantially reworked (period timesheets that finalize into a signable PDF, configurable approval routing, a guided setup wizard, multi-day manual entry, and a live Team Status board), the profile page was rebuilt in a tabbed, HR-suite-style layout, documents and onboarding documents got a design refresh, and we closed every open dependency advisory (25 → 0) alongside a round of CSP and SSRF hardening.
New Features
- Document e-signatures — Documents can be sent for signature with field placement, sequential or parallel multi-signer ordering, per-signer due dates, a SHA-256 content hash, a multi-signer completion certificate, and a full audit trail, all stored encrypted. Signers are notified in-app and by email at each step. The signing UI deliberately avoids ESIGN-Act / "legally binding" language.
- Period timesheets that finalize into a signable document — Time entries now roll up into a period timesheet (weekly / biweekly / semi-monthly / monthly) with an
OPEN → SUBMITTED → APPROVED → FINALIZED → SIGNEDlifecycle. When a manager finalizes a period, the system generates a complete, branded timesheet PDF (daily breakdown, regular/overtime/break/leave/holiday totals, pay snapshot) and routes it into/documentsfor a dated e-signature, reusing the same signing pipeline. Finalizing also advances the payroll lockdown window. - Configurable timesheet approval routing — A new Approval routing setting decides who signs a finalized timesheet: No signature (finalize straight to payroll), Single approver (one chosen person signs every sheet), or Department head (routes to the employee's department head, escalating to a chosen approver for heads/admins). Routing is paired with a separate "who signs" order (employee, approver, or employee-then-approver) and a per-signer signing window.
- Time Clock setup wizard — Admins and executives get a guided, three-step setup on
/time-tracking(opened from a "Time clock setup" button): the payroll cycle (week start, cycle, period anchor), location tracking (capture clock-in/out location, or off), and what time is tracked against (nothing, projects, or projects and tasks — wired to the real Projects/Tasks system). It writes straight to the existing settings. - Multi-day and break-aware manual time entry — The Add/Edit time-entry panel now supports an unpaid break (subtracted from the worked total) and a Multiple days mode that stamps one time-of-day across a weekday-filtered date range — one entry per employee per selected day, instead of adding days one at a time.
- Team Status board — A manager-only board (
/time-tracking/team) showing who is on shift right now: a live "who's working" list, a full-width GPS map with a marker per clocked-in user (using their real profile photo), clock-in address and elapsed time, plus an "Everyone" roster with today's hours. - Redesigned profile page — The profile was rebuilt as a tabbed, HR-suite-style layout (Personal, Job, Time Off, Documents, Performance, and more) for a far richer, more navigable employee record.
- Onboarding documents — New hires can be assigned documents to read and sign as part of onboarding, tracked to completion.
- Per-diem provided meals — Individual per-diem meals (breakfast, lunch, dinner) can be marked as provided rather than reimbursed, each with its own source (third party, company card, or a colleague), and the provided meal's value is deducted from that day's per-diem. Providers are managed per-meal in expense settings, and the per-diem grid lets a bookkeeper set the provider per meal per day.
- Guided workspace setup checklist — New organizations get a dismissible "Finish setting up your workspace" card on the dashboard, visible to administrators and executives only, that tracks four quick settings: timezone & business days, public-holiday location, leave types, and expenses & per-diem. Each step's status is auto-detected from real configuration. Crucially, settings we pre-fill at sign-up (timezone, a starter set of leave types, default expense rates) are surfaced as "pre-filled — review" with a one-click Looks good confirmation rather than silently shown as complete, so the values we guessed actually get verified before they count as done. The progress bar reflects only confirmed steps. The first-run welcome dialog and the product tour are now sequenced so they never appear at the same time — the profile dialog comes first, then the tour on the next dashboard load.
Improvements
- Documents design refresh — The documents experience was reorganized (Inbox / Sent / Action Required style surfacing) so it's clearer what needs your signature versus what you've sent.
- Row actions consolidated into an ellipsis menu — Timesheet finalization rows now use a compact ellipsis action menu (Submit / Approve / Reject / Finalize & send / Finalize only / View document) instead of a row of buttons, which also reads cleanly on mobile.
- Finalize actions follow the auto-send setting — When the org has "Automatically send finalized timesheets for signature" enabled, finalizing is a single Finalize & send action (it always routes for signature). With auto-send off, both Finalize & send and Finalize only are offered so a manager can choose per timesheet, and the two are genuinely distinct — "Finalize only" never sends. With no signature configured, a single Finalize for payroll.
- Finalized timesheets file into a Timesheets folder — A signed/finalized timesheet PDF now appears in a dedicated Timesheets folder under
/documents(it was previously only findable via search), and the folder shows a live count. The category is system-managed, so it isn't offered as a manual upload option. - Geofencing available on Pro and above — Plan limits were updated so geofencing is included from Pro upward.
- Faster, reliable approvals counts — The pending-approvals badge cache is now busted immediately on approve/reject, and
/api/approvals/countsis scoped to the caller's approval rights. - Referral tracking — Referral attribution now captures the
?via=parameter and persists it via cookie fallback. - Per-diem bookkeeper summary — The per-diem display was rebuilt as a per-day summary that reads cleanly for bookkeepers, showing each day's meals, their provided/excluded status, and the amount actually paid.
- Redesigned travel route entry — The travel and mileage route entry was redesigned to resemble a turn-by-turn directions view, with address autocomplete that falls back to a plain text input when autocomplete isn't available.
- View Audit Trail from any folder — Administrators, executives, and department heads get a "View Audit Trail" row action on every document folder, opening the document with its History expanded. Previously the trail was only reachable from the Sent view.
- Compact document audit trail — The History timeline is now a fixed-height scroll area and collapses repeated views by the same person into a single counted row, so a heavily-opened document no longer stretches the detail page.
- Upload defaults to signing — The document upload entry points open the send-for-signature flow by default; filing to a folder stays available via the mode toggle or a
?mode=storelink. - Per-recipient field placement — The signing-field placer no longer forces signature/initials parity across signers; it only requires that each recipient has at least one field, and it previews the burned-in "Signed by" label and timestamp around placed signature and initials boxes.
- Themed sidebar counts — The sidebar count badges (Approvals, Action Required, and others) now use the primary color instead of amber.
- Currency-neutral expense settings — The expense per-diem and rate fields now offer a full list of world currencies (up from four) and render the selected currency's symbol live across every input and the per-diem section heading. Region-specific guidance copy was removed so the defaults read neutrally for any organization, wherever it operates.
Responsive layout
- Tables no longer overlap their headers on small screens — Wide data tables (approvals, expenses, timesheets, documents, projects, security logs, and more) compressed their fixed columns on narrow viewports until the header labels overlapped. They now keep a minimum width and scroll horizontally instead, with non-wrapping headers; desktop is unchanged.
- Create/Edit Shift opens as a side drawer — Scheduling a shift now opens a right-side push drawer (matching the time-entry panel) that sits beside the page and collapses the sidebar, rather than a centered modal over the content.
- Sidebar no longer flickers on resize — Crossing the desktop/mobile breakpoint used to briefly animate the sidebar into a broken-looking state; layout transitions are now suppressed while the window is actively resizing.
Security
- All dependency advisories closed (25 → 0) — A sweep of dependency vulnerabilities brought the dependency audit to zero, including switching the PDF rendering library to its legacy build, hardening the PDF worker CSP, and patching an HTTP-client SSRF advisory.
- CSP and framing hardening — The web analytics script was added to the CSP
script-src/connect-src;X-Frame-Optionswas relaxed toSAMEORIGINso in-app PDF receipts render; the PDF worker runs under a tightened policy. - Tighter notification and approval scoping — Leave-submission notifications are scoped to the submitter's department, and approval counts to the caller's rights, so neither leaks cross-team activity.
- Safer defaults — "Remember me" now defaults to off at login.
- Administrators can view security logs — Audit-log, sign-in-log, and leave-transaction views (and their exports) are now open to administrators as well as executives, all strictly org-scoped.
- Sequential signing visibility — In sequential signing, a later signer whose turn hadn't come could view and list the document (including its fields and stored signature data) before the earlier signer signed. Not-yet-their-turn assignments are now excluded from every document read path; administrators, owners, and uploaders are unaffected.
- No signing on another user's behalf — Administrators can open any assignment for monitoring, but the signing page presented the full fill-and-sign UI for it. Non-assignees are now redirected to the read-only document view; the sign endpoint already rejected the submission server-side.
Bug Fixes
- Role changes apply immediately — Promotions, demotions, and deactivations now take effect on the user's next request instead of waiting up to the access-token lifetime, and a role change no longer forces a disruptive re-login.
- Timesheet PDF period dates — The period header on the generated timesheet renders the calendar boundaries in UTC so a "May 18 – May 31" period never shifts a day for a reader in another timezone.
- Timesheet signature/date alignment — On the generated timesheet, the signature image and date were landing below the Signature/Date lines because the signing fields were placed at a fixed position while the lines move with the number of entries. The fields are now positioned to the actual drawn lines (and on the correct page for multi-page timesheets). Applies to timesheets finalized after this release.
- Schedule week-clear fix — Clearing a published week referenced a non-existent model and threw at runtime; it now uses the correct schedule-publication record with timezone-aware week matching.
- Training auto-assignment timing — Corrected a comparison in the training auto-assign scheduler that mis-evaluated due windows.
- Off-by-one expense dates — The expense detail and overview views rendered some calendar-day fields a day early in timezones west of UTC; they now read the stored UTC day correctly.
- Initials-only signers couldn't sign — A signer asked only to initial (with no signature field) submitted an empty signature and was rejected with a 400; the signing flow now uses the initials image as the signature.
- Right-panel space released on navigation — Leaving a page with an open right-side push drawer (for example a schedule or timesheet entry) without closing it left the reserved content-shell width behind; it is now released when the page unmounts.