Newest first · last updated Wed, 30 Sep 2026 21:21:05 GMT · View raw ISSUES.md · Download ISSUES.md
SatelliteHR — issues found during walkthrough recording
Append-only log. New entries go at the bottom. Environment: https://qa.satellitehr.com, Company Super Admin (Ops Maven).
Entries tagged [auto] were appended by the recorder (server 5xx or uncaught page errors) and still need triage.
ISS-237 · No screen can request comp-off; "Use comp-off" only opens the leave form, and there are two comp-off leave types
- Module: Leave / Overtime & comp-off (self-service), Workflow (Comp-Off Request v4) · Severity: Medium · Found: 2026-10-01
- Steps: Ananya Iyer (Demo) → Leave & attendance → Overtime & comp-off → Use comp-off.
- Actual: "Use comp-off" opens Leave → Apply, where "Comp-off" is one of the leave types (spending comp-off). Nothing on any screen sends a comp-off request (asking to be credited for, e.g., a holiday worked). Only
POST /api/me/leave {kind: "comp_off", units}starts the Comp-Off Request workflow (runfd57ac2f…: Manager approval → Credit the comp-off days +1 → "Comp-off granted"). The leave list also has two types, "Comp-off" (where overtime lands) and "Compensatory Off" (always 0), with no explanation of the difference. - Expected: A "Request comp-off" form (day worked, reason, days), and a single comp-off leave type.
ISS-236 · Overtime claim shows the worked hours 5½ hours late ("3:00 PM–5:00 AM" for a 09:30–23:30 day)
- Module: Attendance / Overtime (self-service) · Severity: Medium · Found: 2026-10-01
- Steps: Ananya Iyer (Demo): approved correction for 21 Sep, time in 09:30, time out 23:30. Overtime & comp-off → Claim overtime → Which day 21 Sep.
- Actual: "You worked 3:00 PM–5:00 AM · 5h claimable". The punch times entered in IST are shown shifted by +5:30 (as if converted from UTC twice), and the day looks like a night shift. The claimable hours (5h) are right.
- Expected: "You worked 9:30 AM–11:30 PM", in the company's time zone.
ISS-235 · "Could not send the correction — request timed out" although the correction was created
- Module: Attendance (self-service corrections) · Severity: Medium · Found: 2026-10-01
- Steps: Ananya Iyer (Demo) → Attendance → Request a correction → 28 Sep, forgot to punch, 09:30–18:30, reason → Send for approval.
- Actual: After 20 s the form shows "Could not send the correction — Request timed out after 20s. The server may be slow or unreachable" and stays open. The correction was in fact saved and its workflow started (run
9ded7d25…, waiting on the manager). Pressing Send again would file a duplicate. - Expected: Treat a slow response as unknown, check whether the correction exists before offering to resend, and say so ("It may already have been sent. Check My corrections").
- Evidence: output/workflow-regularization-failure.png
ISS-234 · The designer says Attendance Regularization starts "manually, no module", but the attendance correction form starts it
- Module: Workflow designer (
wf-2277be) · Severity: Low · Found: 2026-10-01 - Actual: The designer copy's trigger is
{event: "manual", module: "No module"}, and Settings → Workflows lists no trigger event for it. Sending a correction from Leave & attendance → Attendance → Request a correction (POST /api/me/attendance/regularizations) does start it (e.g. WF-2026-000131). Overtime Approval and Shift Swap likewise show no trigger. - Expected: Show the real starting point ("Attendance · Correction requested"), so admins can tell which workflows are in use.
ISS-233 · Work From Home and Short Permission requests go through Annual Leave Approval; their own workflows never run, and neither has a screen
- Module: Leave / Workflow (Work From Home Request v4, Short Permission (Hours) v?, Annual Leave Approval v5) · Severity: High · Found: 2026-10-01
- Steps: Ananya Iyer (Demo):
POST /api/me/leave {kind: "wfh", …, startDate/endDate 2026-12-21}and{kind: "permission", …, 2026-12-22}. Leave & attendance offers no screen for either (Leave: Apply/My leave/Balances/Team calendar; Attendance: Request a correction; Overtime & comp-off: Claim overtime / Use comp-off). - Actual: Both requests start Annual Leave Approval (WF-2026-000128, and the next run: Balance check → How long? → Manager approval), are charged against a leave type (the API requires
leaveTypeId, here PTO), and would post a leave debit on approval, like a normal day off. "Work From Home Request" and "Short Permission (Hours)" have no trigger event in Settings → Workflows and show "never ran". The same routing sends cancellations to Annual Leave Approval (ISS-232). - Expected: Each request kind raises its own event (
wfh.requested,permission.requested, …) and runs its own workflow; WFH and short permission don't touch leave balances; the self-service page has a form for each.
ISS-232 · Cancelling approved leave takes the days away again instead of giving them back; the Leave Cancellation workflow never runs
- Module: Leave / Workflow (Leave Cancellation v8, Annual Leave Approval v5) · Severity: High · Found: 2026-10-01
- Steps: Ananya Iyer (Demo) has approved PTO for 7–8 Oct (2 days). Send a cancellation for it:
POST /api/me/leave {kind: "cancellation", leaveTypeId: PTO, startDate: 2026-10-07, endDate: 2026-10-08, units: 2}(there is no Cancel action on approved leave in My leave). Harsh Vardhan Mistry approves it from his Inbox. - Actual:
- The request starts the Annual Leave Approval workflow (WF-2026-000126: Balance check → Manager approval), not Leave Cancellation (trigger
leave.cancellation_requested), so the cancellation workflow's steps (credit the days back, "Leave cancelled") never run. - On approval, "Post to leave ledger" posts
ledgerDelta: -2again: PTO available went from 11 to 9, taken from 19 to 21. The employee loses the days twice. - My leave has no way to ask for a cancellation of approved leave at all, so employees can't start it from the app.
- The request starts the Annual Leave Approval workflow (WF-2026-000126: Balance check → Manager approval), not Leave Cancellation (trigger
- Expected: A Cancel action on approved leave that raises
leave.cancellation_requested, routed to Leave Cancellation, which credits the days back (after the manager's sign-off for more than 3 days).
ISS-231 · The leave form promises loss of pay for Bereavement Leave, then the server refuses for insufficient balance
- Module: Leave (self-service) · Severity: Medium · Found: 2026-10-01
- Steps: Ananya Iyer (Demo), Bereavement Leave with 0 left → 18 Dec, 1 day. The form shows "1 of 1 day exceed your bereavement leave balance and will be unpaid (Loss of Pay)" and asks her to tick "I understand 1 day will be unpaid". Tick it → Send request.
- Actual: Toast "Insufficient balance — Insufficient Bereavement Leave balance: 0 available, 1 requested (INSUFFICIENT_BALANCE · 409)". The form had just offered loss of pay. For Paid Time Off at 0 the same form was accepted as loss of pay (and then rejected by the workflow, ISS-229).
- Expected: The form only offers loss of pay for leave types whose policy allows it; otherwise it says up front that there is no balance and disables Send.
- Evidence: output/workflow-leave-failure.png
ISS-230 · Two branches of Annual Leave Approval can never run: the leave form blocks them first
- Module: Leave / Workflow (Annual Leave Approval v5) · Severity: Medium · Found: 2026-10-01
- Steps: (a) Ananya Iyer (Demo) with an open resignation (last day 30 Oct) applies for 1 day of PTO on 26 Oct. (b) She applies for 14 days of PTO (2–19 Nov).
- Actual: (a)
422 NOTICE_PERIOD — Leave cannot be taken during the notice period, so the workflow's "On notice? → Extend the notice period → Tell the requester and HR" branch is unreachable. (b)422 MAX_CONSECUTIVE — Paid Time Off (PTO) — company default allows at most 10 consecutive days, so the "more than 12 days → department head + leave committee" branch can't be reached with PTO; only leave types without a limit (e.g. Service Leave) get there. - Expected: The policy and the workflow agree. Either allow leave on notice (the workflow already handles extending the notice), or remove the branch; and say on the designer which leave types can reach the extended-leave review.
ISS-229 · A leave request the policy accepts as loss of pay is rejected by the approval workflow for "insufficient balance"
- Module: Leave / Workflow (Annual Leave Approval v5) · Severity: Medium · Found: 2026-09-30
- Steps: Ananya Iyer (Demo), 0 days of Paid Time Off → apply for 1 day (5 Oct).
- Actual: The submit response says
lop: { disposition: "auto_lop", days: 1 }(the policy lets it through as loss of pay). The workflow's first step "Balance check" (employee.balance <= 0) then sends "Leave request cannot proceed — your available balance is exhausted" and rejects it at once (run WF-2026-000116). The employee is told two different things, and the policy's loss-of-pay setting has no effect. - Expected: One rule. Either the workflow respects the policy's loss-of-pay disposition (route it for approval as LOP), or the form refuses the request up front with the same message.
ISS-228 · The leaver's letters are only emailed: My documents stays empty and My journey shows nothing open
- Module: Self service (My documents, My journey) / Workflow (Resignation) · Severity: Medium · Found: 2026-09-30
- Steps: Sign in as Ananya Iyer (Demo) after her resignation was acknowledged (4 times) and relieved (exit
92509449…). - Actual: My documents says "Nothing on file yet". The "We have received your resignation" and "Your relieving letter" letters were emailed but never filed on her record. My journey → "Open on you" says "Nothing waiting on you", although the Knowledge transfer run assigned her three tasks (plan drafted, tickets reassigned, signed KT document; see ISS-223). Her notifications do show the workflow's notices, without her name (ISS-221).
- Expected: Letters released by the workflow are filed under My documents, and her open tasks appear under "Open on you".
ISS-227 · The Assets clearance lane still can't be cleared, even with nothing outstanding (ISS-090 again)
- Module: Lifecycle offboarding · Severity: High · Found: 2026-09-30
- Steps: Ananya Iyer (Demo) exit
92509449…in clearance. The card says "Nothing on the register is outstanding." Set Assets clearance → Mark cleared. - Actual: "Couldn't update the Assets lane — Unexpected server error". Then "The stage gate refused — Every clearance lane must be cleared or waived first". The other five lanes clear normally. The Resignation workflow's "All lanes cleared" step can't be reached without waiving the lane through the API (the card has no Waive action, ISS-095).
- Expected: An Assets lane with nothing outstanding can be marked cleared.
ISS-227 · [auto] Server error 500 on PATCH /api/company/people/lifecycle/exits/92509449-fa95-4806-8030-51da8fa51545/clearance/c3d18590-5648-492b-9a58-55f93b58fb9c
- Module: workflow-resignation
- Found: 2026-09-30
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/lifecycle/offboarding
- Request: PATCH https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/company/people/lifecycle/exits/92509449-fa95-4806-8030-51da8fa51545/clearance/c3d18590-5648-492b-9a58-55f93b58fb9c
ISS-226 · Update to ISS-218: on the 30 Sep afternoon run, the Resignation workflow called the company's own "Clearance and settlement"
- Module: Workflow (Resignation v2 →
om_clearance_ffs) · Severity: Info · Found: 2026-09-30 - Actual: For Ananya Iyer (Demo) (exit
92509449…), the child runa34b869b…used the company versionb91801fc…and genuinely waited at "Until two business days before the last day" (last day 14 Oct). The rehearsal run at 05:52 that day used the platform copy376ff7dd…(ISS-218). Either ISS-218 was fixed during the day, or which version gets called isn't consistent. Worth checking which one it is.
ISS-225 · Overriding a waiting workflow step from the Inbox always fails: it needs a reason but the panel has no comment box
- Module: Inbox / Workflow gates · Severity: High · Found: 2026-09-30
- Steps: Resignation for Ananya Iyer (Demo) (exit
33d8ed85…) waiting at "Stay conversation recorded". Sign in as Kavya Raghunathan (HR Head) → Inbox → "Exit case · Gate stay conversation" → Approve. - Actual: Two toasts: "Something went wrong — Overriding a gate needs a reason — add a comment saying why. (400)" and "Couldn't record the decision". The panel only has Approve / Decline, with no field for the reason. The item's title is the step code ("Gate stay conversation"), and it doesn't say it's an override.
- Expected: An override item says what it overrides and why it's allowed ("the conversation could not be held"), with a required reason field.
- Evidence: output/workflow-resignation-failure.png
ISS-224 · The designer summarises the Resignation steps wrongly
- Module: Workflow designer (
wf-f3e043) · Severity: Low · Found: 2026-09-30 - Actual:
- "Stay conversation recorded", "Retention decision" and "Counteroffer answered" read "Until an event (unset)". They do wait for
exit.stay_conversation_recorded,exit.retention_decidedandexit.counteroffer_answered, but the designer reads the emptyconfig.eventrather thanconfig.gate.event. - "Stay conversation due" and the other notify steps read "Requester · In-app, Email", but they go to the manager and the HR Manager (
recipients). The legacyrecipient: requesterfield is what's shown. - The designer copy (flow doc, "draft") lacks two steps the live v2 has: "Exit accepted: into clearance" and "Settlement not completed".
- "Stay conversation recorded", "Retention decision" and "Counteroffer answered" read "Until an event (unset)". They do wait for
- Expected: Show the event a waiting step listens for, the real recipients, and the steps of the version that's live.
ISS-223 · Workflow checklist items can't be seen or ticked anywhere in the app
- Module: Workflow checklists / Inbox · Severity: High · Found: 2026-09-30
- Steps: Resignation for Probe Leaver (Demo) (exit
4668a0c5…) past the HR Head approval. The child runs "Access and asset switch" (5 items for the HR Manager) and "Knowledge transfer" (3 items for the leaver, 1 for the manager) start. - Actual: None of the items appear in the assignee's Inbox (the
/api/company/inboxpayload doesn't include them), on Home, on /me, on the exit card, or under Settings → Workflows → Operations. The only way to tick them isPOST /api/company/tasks/{id}/act. The KT plan shows its own copy of the KT items, but ticking those doesn't reach the workflow (ISS-217). So "Access and asset switch" can't be finished by anyone through the UI, and the Resignation run stalls there. - Expected: Checklist items listed in the assignee's Inbox (or a Tasks view) with a tick action, and on the exit card.
ISS-222 · The Inbox can't request changes, so every workflow's "Changes requested" branch is unreachable from the UI
- Module: Inbox / Workflow · Severity: Medium · Found: 2026-09-30
- Steps: Sign in as Harsh Vardhan Mistry → Inbox → "Exit case · Approval manager" (a resignation at "Reporting manager accepts").
- Actual: The panel offers only Approve and Decline. The API accepts
changes_requested(POST /tasks/{id}/act), and the designer gives every approval a "Changes requested" branch, but no screen lets an approver choose it. The item is also titled with the step code ("Approval manager") rather than the step name ("Reporting manager accepts"), and Requester/Details show "—" (ISS-093). - Expected: A "Request changes" action (with a comment) wherever the step has that branch, and the step's display name as the title.
ISS-221 · Resignation notifications leave out the employee's name
- Module: Workflow (Resignation v2) / Notifications · Severity: Medium · Found: 2026-09-30
- Steps: Start a resignation for Probe Leaver (Demo). Sign in as the manager (Harsh Vardhan Mistry) → Notifications.
- Actual: "Stay conversation within two working days — has resigned (last working day 2026-10-14). Hold the stay conversation…". "After the exit: PF, mailbox, interview — is relieved. HR: …". Every notify step starts with
{{ request.employeeName }}, which is empty in the run context (ISS-210), so the manager isn't told who resigned. The acknowledgement and relieving letters do carry the name. - Expected: "Probe Leaver (Demo) has resigned (last working day 14 Oct 2026)…", with the date in the company's format rather than ISO.
ISS-220 · A policy acknowledgement due in 9 days locks managers out of the whole app
- Module: Policies / sign-in · Severity: High · Found: 2026-09-30
- Steps: Sign in as Harsh Vardhan Mistry or Kabir Anand.
- Actual: A full-screen "Attendance & Punctuality Policy — Leave & Attendance · v1 · due 9 Oct 2026" covers every page. Its only button is Acknowledge (enabled after scrolling and ticking "I have read and understood"). Escape doesn't close it, and there's no "Later". So a manager can't reach the Inbox to act on pending approvals (e.g. a resignation waiting at "Reporting manager accepts") until they acknowledge a policy that isn't due for 9 days. Kavya Raghunathan and Aarav Krishnamurthy aren't blocked.
- Expected: Allow "Remind me later" until the due date, or at least let people reach their Inbox.
- Evidence: scratch/WF/shots/x2-harsh-home.png
ISS-219 · The Resignation workflow announces "Exit complete" while the exit is still in clearance
- Module: Workflow (Resignation v2) / Lifecycle offboarding · Severity: Medium · Found: 2026-09-30
- Steps: Run a resignation for Probe Leaver (Demo) (exit
26344fb5…) to the end: approvals, KT, access switch, settlement paid, relieving letter sent. - Actual: The run ends with "Exit complete: … accepted, handed over, cleared, settled, relieved". The exit card still says
in_clearance, with every clearance lane (HR interview, assets, IT, manager, KT, Finance) pending and settlementpending. Nothing on the card was cleared: the workflow's "All lanes cleared" step passed without waiting (ISS-218), and the settlement panel's "paid" isn't reflected on the card. - Expected: The workflow waits for the exit's clearance and settlement, and the exit card reflects the settlement recorded through the workflow.
ISS-218 · The Resignation workflow calls the platform copy of "Clearance and settlement": its gates pass instantly and its approvals go to nobody
- Module: Workflow (Resignation v2 →
om_clearance_ffs) · Severity: High · Found: 2026-09-30 - Steps: Resignation for Probe Leaver (Demo) (exit
26344fb5…) through all three approvals, then KT and access switch. The main run calls the sub-process "Clearance and settlement". - Actual: The child run (
7b895301…) uses the platform version (376ff7dd…, placeholders), not the company's ownom_clearance_ffs(v1b91801fc…, real HR Manager / HR Head approvers). In that run:- "Until two business days before the last day", "All lanes cleared", "Inputs ready", "Tentative amount sent" and "Vendor statement received" all finish within 12 s as
genericauto steps. Nothing waits for the exit to be cleared or for any settlement input. - "Settlement review, level 1" is assigned via
relationship:placeholder_hr_manager (unresolved)to nobody (assignedUserId: null), so the run and the parent Resignation run are stuck.
- "Until two business days before the last day", "All lanes cleared", "Inputs ready", "Tentative amount sent" and "Vendor statement received" all finish within 12 s as
- Expected: Call the company's version of the sub-process, and have its gates wait for their events (
exit.cleared,ffs.inputs_ready, …).
ISS-217 · Knowledge-transfer checklist and KT plan don't sync, and the fallback sign-off closes the checklist with required items open
- Module: Workflow (Knowledge transfer,
om_knowledge_transferv4) / Lifecycle knowledge transfer · Severity: Medium · Found: 2026-09-30 - Steps: Resignation run for Probe Leaver (Demo) → child run "Knowledge transfer" (
b5d52966…). HR ticks the leaver's three tasks on the KT plan (Lifecycle → Knowledge transfer). Harsh ticks "Weekly checkpoint held" from his task. - Actual:
- The plan shows 4/4 and completes itself, but the workflow's three leaver items stay
pending(the plan ticks never reach the checklist). HR can't act on them (404 Task not found), so only the leaver could. - After Harsh's tick, a sign-off approval goes to the HR Manager as
fallback:escalation … ← unassigned("no approver could be routed"). Approving it completes the checklist step and the child run, with the three required leaver items still open.
- The plan shows 4/4 and completes itself, but the workflow's three leaver items stay
- Expected: Ticking a KT plan task completes the matching checklist item (and vice versa). The sign-off should route to a named approver and not close a checklist whose required items are open.
ISS-216 · Withdrawn exits leave their knowledge-transfer plans active
- Module: Lifecycle knowledge transfer / offboarding · Severity: Low · Found: 2026-09-30
- Steps: Start and withdraw several resignations for Probe Leaver (Demo) (withdrawn by a counteroffer acceptance, a rejection or "changes requested"). Open Lifecycle → Knowledge transfer.
- Actual: Each exit created a "Leaving — no due date" plan marked "Counts toward exit clearance". All of them stay active after their exit is withdrawn, so the probe has 6 plans. "Active plans" counts them all (10).
- Expected: Withdrawing an exit cancels its KT plan, or at least marks the plan as belonging to a withdrawn exit.
ISS-215 · Every ticked checklist item re-opens the checklist's sign-off, so the approver gets one inbox item per tick
- Module: Workflow (Access and asset switch,
om_access_switchv2) · Severity: Low · Found: 2026-09-30 - Steps: Resignation run for Probe Leaver (Demo) → child run "Access and asset switch" (
5c0d40e0…). The HR Manager ticks the 5 checklist items one by one. - Actual: Each tick starts a new "checklist_access" approval for the Department Head, routed as
fallback:escalation (relationship:role:department-head) ← unassigned. Kabir Anand gets 5 identical approvals. Approving one completes the step and the other 4 turn "skipped" (acting on them returns409 already skipped by someone else). - Expected: One sign-off task, created once every item is done, assigned to the sign-off relationship directly rather than through the "unassigned" escalation fallback.
ISS-214 · "Changes requested" on a resignation approval silently ends the case
- Module: Workflow (Resignation v2) / Lifecycle offboarding · Severity: Medium · Found: 2026-09-30
- Steps: Resignation for Probe Leaver (Demo) (exit
c909ff9a…). At "Reporting manager accepts", Harsh Vardhan Mistry chooses Changes requested. - Actual: The "Changes requested" branch has no steps. The run ends as
rejected, the exit is withdrawn, and nobody is told: no "Resignation not accepted" notice goes to HR or the employee, unlike a rejection. HR has to start a new exit to continue. - Expected: Send the request back to HR (or the employee) to change and resubmit, or at least notify HR, as the Rejected branch does.
ISS-213 · After HR overrides the "Stay conversation recorded" step, the exit card still won't take a retention decision
- Module: Lifecycle offboarding / Workflow (Resignation) · Severity: Medium · Found: 2026-09-30
- Steps: Resignation for Probe Leaver (Demo) (exit
e628cbe6…). The run waits at "Stay conversation recorded". The HR Head uses the override task ("the conversation could not be held"). The run moves on to "Retention decision". On the exit, record the retention decision. - Actual:
409 DECISION_ORDER — record the stay conversation first. The workflow accepted the override, but the exit card still requires the stay conversation. HR must either record one after saying it couldn't be held, or override the retention step too. - Expected: An overridden stay conversation should count as done on the exit, so the retention decision can be recorded.
ISS-212 · Cancelling one Resignation run withdraws the exit, while the other run keeps going
- Module: Workflow runs / Lifecycle offboarding · Severity: Medium · Found: 2026-09-30
- Steps: Exit
0c3f32e2…(Probe Leaver (Demo)) had two runs (ISS-211). Cancel the duplicate WF-2026-000077 (933c59ec…,POST /workflows/instances/{id}/cancel). - Actual: The exit case becomes
withdrawn, but the other run (fd5b825b…) staysrunningat "Acknowledgement drafted", with its task still in the HR Manager's inbox for a case that no longer exists. - Expected: Cancelling one run of a case shouldn't withdraw the case without saying so. Withdrawing an exit should cancel all of its runs and remove their tasks.
ISS-211 · Correction to ISS-210: every resignation still starts two Resignation runs (v2), and only the duplicate lacks the employee's name
- Module: Workflow (Resignation v2
88f78c82) / Lifecycle offboarding · Severity: High · Found: 2026-09-30 - Steps: Start exit (Resignation) for Probe Leaver (Demo) (exit
0c3f32e2…). - Actual: Two runs of the same version start 3 s apart (WF-2026-000076
fd5b825b…and WF-2026-000077933c59ec…). The first drafts "We have received your resignation, Probe Leaver (Demo)" and waits for the HR Manager to approve it. The second has noemployeeName, so it raises the "Employee · Name" gap task (ISS-210). Both assign the HR Manager, and every later step would run twice (two inbox items per approver, two sets of notifications). Same as ISS-131, still happening on v2. - Expected: One run per exit.
ISS-210 · The Resignation workflow's first step always stalls: the trigger doesn't pass the employee's name, so the acknowledgement letter becomes a gap task for the HR Manager
- Module: Workflow (Resignation,
wf-f3e043) / Lifecycle offboarding · Severity: High · Found: 2026-09-29 - Steps: Start exit (Resignation) for any employee → open the run (e.g.
fe74e6f5…, exit2937ce21…). - Actual: "Acknowledgement drafted" (template
exit_resignation_ack) mergesemployee_namefrom{{ request.employeeName }}, but theresignation.submittedcontext carries onlyemployeeId,exitCaseIdandlastWorkingDay. The engine logsmerge_gap missing: ["employee_name"]and creates a form task "Employee · Name" for the HR Manager role. That role's only member is Harshit Bhalla, so the run has waited there since 28 Sep and nothing downstream (stay conversation, approvals, offboarding) starts. The run context'semployeeblock is also empty (department, location null). The same{{ request.employeeName }}is used by every notify step and the relieving letter. - Expected: Put
employeeName(and the employee's department/location) into the trigger context so the letter drafts without a gap. If a gap does happen, route it to a group that has more than one person in it.
ISS-209 · Security says two-factor adoption is "0 of 26 members" while Users lists 25 accounts
- Module: Settings → Security · Severity: Low · Found: 2026-09-29
- Actual: Adoption so far: "0 of 26 members". Settings → Users: "25 accounts · 4 invitations pending".
- Expected: The same population on both pages, and say whether invited or suspended accounts are counted. Related: ISS-170 (member counts).
ISS-208 · Roles people still hold show an active Delete button
- Module: Settings → Roles · Severity: Low · Found: 2026-09-29
- Actual: Every company role card, including Employee (16 members) and Reporting Manager (3), has an enabled trash button ("Delete Employee",
disabled=false). The footer says roles "can be … deleted once nobody holds them". Not clicked on held roles; the empty "Demo – Auditor" role deleted fine (DELETE /api/company/roles/{id}→ 200,archived: true). - Expected: Disable Delete (with a tooltip) while a role has members, so nobody learns the rule by trying.
ISS-207 · "Delegate added" says new approvals will go to the delegate even when the delegation is scheduled for later
- Module: Settings → Delegation · Severity: Low · Found: 2026-09-29
- Steps: Add Harsh Vardhan Mistry as delegate From 21 Dec Until 24 Dec 2026.
- Actual: Toast: "New approvals assigned to you will go to Harsh Vardhan Mistry." The row correctly says "Scheduled", Dec 21 – Dec 24. Removal has no confirmation (the demo delegation was removed straight away).
- Expected: "From 21 Dec, new approvals will go to …" for a scheduled delegation.
ISS-206 · Notification preferences are lost without warning when you leave the page before "Save preferences"
- Module: Settings → Notifications · Severity: Low · Found: 2026-09-29
- Steps: Turn on "Announcement published via Email" → open another settings page, or reload.
- Actual: The switch moves at once and nothing says it's unsaved. The Save preferences button is at the very bottom of a ~93-row list, and leaving drops the change silently. Saving works (
PUT /api/company/notification-preferences→ 200) and survives a reload. - Expected: Save each switch when it's flipped, or show a sticky "Unsaved changes" bar and warn when leaving.
ISS-205 · Profile shows the role as "Hr Head 82628593", its internal key, instead of the role's display name
- Module: Settings → Profile · Severity: Low · Found: 2026-09-29
- Actual: Under the name and in the read-only Account card, ROLE reads "Hr Head 82628593" for Kavya Raghunathan and "Employee 82628593" for Zoya Kirmani: the role key with the company id appended, title-cased. The sidebar correctly shows "HR Head" / "Employee".
- Expected: The role's display name, as in the sidebar. Related: the audit-log issue where a deleted role shows as "demo leave reviewer 82628593".
ISS-204 · [auto] Server error 500 on POST /api/company/delegations
- Module: settings-personal
- Found: 2026-09-29
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/settings/delegation
- Request: POST https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/company/delegations
ISS-202 · HR has no screen to read or answer feedback
- Module: Feedback / Performance · Severity: Medium · Found: 2026-09-29
- Actual:
GET /api/company/perf/feedback-casesexists and answers 200 for HR, but no page uses it:/company/{id}/feedbackis Not Found, Performance has no feedback tab, and Cases covers only disciplinary matters and grievances. - Expected: An HR inbox for feedback with status updates, so the "Track a code" status on the employee side can move.
ISS-201 · Sending feedback fails with a 500 even for a user who has Feedback access
- Module: Feedback · Severity: High · Found: 2026-09-29
- Steps: As Kavya Raghunathan (HR Head,
submissionEligibility.canSubmit: true), send a suggestion, named or anonymous. - Actual:
POST /api/me/perf/feedback-cases {"category":"feedback","subject":"…","body":"…","anonymous":false|true}→500 INTERNAL_ERRORevery time (requestIds48985043-1b63-4090-b229-611e13844aa2,bc91f8e8-4175-4c14-87b8-6cb2a50da5aa,b0d6fb11-a535-4c1d-aa27-02aff0617ad0,77ffa988-154c-4498-94ac-8973d836ef35). Nothing is saved and no reference code is issued. - Also: The API only accepts
categoryfeedbackorgrievance("concern"gives 400). "A suggestion" is sent asfeedback; what the form sends for "A concern" wasn't checked, because every submit fails first. - Expected: 201 with a case id (and a reference code when anonymous).
ISS-200 · Employees and managers get the Feedback page but can't send anything (403), and the page gives no sign of it until they submit
- Module: Feedback (/me/feedback) · Severity: High · Found: 2026-09-29
- Steps: As Zoya Kirmani (employee) or Harsh Vardhan Mistry (manager), open Feedback → fill a suggestion → Send feedback.
- Actual:
POST /api/me/perf/feedback-cases→403 FORBIDDEN "Submitting feedback requires edit access". On load,GET /api/me/perf/feedback-casesalso returns 403 ("Viewing feedback requires Feedback access"), but the page silently shows "Nothing sent yet" and an enabled form. - Expected: The employee role can send feedback (the page says "It goes straight to the People team"), or the page is hidden or explains the missing access before someone writes a message.
ISS-203 · [auto] Uncaught page error: undefined
- Module: performance-feedback
- Found: 2026-09-29
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-202 · [auto] Server error 500 on POST /api/me/perf/feedback-cases
- Module: performance-feedback
- Found: 2026-09-29
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me/feedback
- Request: POST https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/perf/feedback-cases
ISS-201 · [auto] Server error 500 on POST /api/me/perf/feedback-cases
- Module: performance-feedback
- Found: 2026-09-29
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me/feedback
- Request: POST https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/perf/feedback-cases
ISS-200 · [auto] Uncaught page error: undefined
- Module: performance-feedback
- Found: 2026-09-29
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-199 · The manager's "Overall" rating is not part of the score, which the form doesn't explain
- Module: Performance · Severity: Low · Found: 2026-09-29
- Steps: Rate Nithya's KRAs 2 (60%) and 4 (40%) and Overall 3 → score 2.8. Rate Zoya 4/4/3 (40/35/25) and Overall 4 → 3.75, shown as 3.8.
- Actual: The score is the weighted goal average; the required Overall rating has no effect and nothing on the form says so.
- Expected: Say on the form that Overall is for context only, or make it optional, or include it in the score as configured.
ISS-198 · "Closing next" on My reviews still lists deadlines of a cycle that has been released
- Module: Performance / self service · Severity: Low · Found: 2026-09-29
- Steps: After release, open /me/reviews as Zoya Kirmani.
- Actual: "Closing next" still shows Goal setting 15 Oct, Self assessment 20 Oct, Reviewer rating 28 Oct, Release 30 Oct for the released Demo – Q4 review pilot.
- Expected: Once a cycle is released, only the acknowledgement due date (if not acknowledged) should remain.
ISS-197 · A cut-off can be extended for a stage the person has already finished
- Module: Performance · Severity: Low · Found: 2026-09-29
- Steps: Cycle actions → Extend a cut-off → Zoya Kirmani, stage Reviewer rating (already submitted), new date 28 Oct, reason → Extend.
- Actual: 201, recorded under Extensions. Zoya's "Closing next" list then shows Reviewer rating 28 Oct.
- Expected: Only offer people and stages that are still open, or warn that the stage is complete.
ISS-196 · "Close cycle" says 1 review is still open when both reviews are submitted and awaiting release
- Module: Performance · Severity: Low · Found: 2026-09-29
- Steps: Demo cycle with 2 participants: both ratings in, the cockpit shows both "Awaiting release". Cycle actions → Close cycle.
- Actual:
PATCH …/review-cycles/{id} {"status":"closed"}→409 CYCLE_HAS_UNFINISHED_REVIEWS, "1 person has a review still open",unfinished: 1. With 2 unreleased reviews, 1 is neither count. - Expected: A count that matches the cockpit (2 awaiting release), and a message that says they are awaiting release rather than "still open". Cancelled; nothing was closed.
ISS-195 · Self-assessments and ratings are accepted before the review period starts and while the cycle is still in goal setting
- Module: Performance · Severity: Medium · Found: 2026-09-29
- Steps: Publish a cycle with period 2026-10-01 → 2026-12-31 (goal setting closes 15 Oct). On 29 Sep, as soon as the goal sheet is saved, the employee submits a self-assessment and the manager submits ratings.
- Actual: All accepted (200). The cycle still shows "Goal setting". HR could release the same day, so a quarter's review was complete before the quarter began.
- Expected: Self-assessment and rating open only when their stage starts (after goal setting closes), or at least not before the period start date.
- Evidence: cycle
bcd07503-a6c2-4d4d-88dc-cea7a028bdb8(Demo – Q4 review pilot).
ISS-194 · The "is any of" operator in the review audience builder only accepts one value
- Module: Performance / rule builder · Severity: Low · Found: 2026-09-29
- Steps: New review cycle → Who is included → Add conditions → Name "is any of".
- Actual: The value is a single text box. Pressing Enter after a name replaces it; "Zoya Kirmani, Nithya Sundaram" (with or without spaces) matches 0 people. Picking two people needs two conditions plus "Match any".
- Expected: A multi-value picker (chips, or a list of people) for "is any of".
ISS-193 · A closed survey round can't be reopened, and Close has no confirmation, so one wrong click ends a live round for good
- Module: Surveys · Severity: Medium · Found: 2026-09-29
- What happened: While recording, a Close click intended for the demo round landed on the real round "feedback survey — Sept 2026" (0 / 6 responded). It closed at once ("Survey closed · 6 unanswered links expired").
POST /form-campaigns/{id}/openreturns409 CAMPAIGN_NOT_OPENABLE("Only draft or scheduled campaigns can open"), so it can't be undone. - Expected: A confirmation before closing, and a way to reopen a round closed by mistake (at least before its planned close date). Related: ISS-158.
- Evidence: campaign
01a0d773-97bb-77d4-beb9-d9e6f5152a96, closed 2026-09-28T23:34:03Z by the recording script (Kavya's session).
ISS-192 · [auto] Uncaught page error: undefined
- Module: surveys-respond
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-191 · [auto] Server error 503 on GET /api/v1/templates/variables
- Module: surveys-build
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/templates/01a0ea28-75bd-701e-8a2f-b644f96d71d8
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/v1/templates/variables
ISS-190 · [auto] Server error 503 on GET /api/v1/templates/variables
- Module: surveys-build
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/templates/01a0ea28-75bd-701e-8a2f-b644f96d71d8
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/v1/templates/variables
ISS-189 · [auto] Server error 503 on GET /api/v1/templates/variables
- Module: surveys-build
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/templates/01a0ea28-75bd-701e-8a2f-b644f96d71d8
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/v1/templates/variables
ISS-188 · [auto] Server error 503 on GET /api/v1/templates/variables
- Module: surveys-build
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/templates/01a0ea28-75bd-701e-8a2f-b644f96d71d8
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/v1/templates/variables
ISS-187 · Performance dates and counters: mixed formats, stale "Closing next", and filter counts that don't change
- Module: Performance · Severity: Low · Found: 2026-09-29
- Actual:
- Harsh's "Closing next" lists "Self assessment Q2 in 3 days", "Reviewer rating 9 Oct" and "Release 16 Oct", but he is on the KRA track (no self-assessment) and already released.
- Clicking the cockpit KPI cards (Self-assessments in, Reviewer ratings in) filters the list to 1 or 3 people, but the header still says "12 participants".
- Dates appear as
2026-10-02,2 Oct,9/24/2026(Extensions "recorded"),Saved 9/23/2026, 6:45:15 PMand a raw ISO timestamp in the inbox.
- Expected: Show only the stages relevant to the person, filtered counts, and one date format.
ISS-186 · Every review cycle is labelled "Annual"
- Module: Performance · Severity: Low · Found: 2026-09-29
- Actual: The New review cycle wizard has no type field and always sends
cycleType: "annual". So "Q2 2026 Quarterly Review", "Monthly review" and "5 Days review" all show the tag "Annual" in the cycle list. - Expected: A cycle type choice (Annual / Half-yearly / Quarterly / Probation…) or no tag.
ISS-185 · Review banners and help text contradict the actual state
- Module: Performance · Severity: Low · Found: 2026-09-29
- Actual:
- Closed cycles (Monthly review) and the released Q2 cycle both say "…read-only — HR has locked this cycle. Nothing can be changed unless it is released."
- On Kabir's review, released at 4.0, Harsh's reviewer page still says "Kabir Anand has not submitted their self-assessment yet. You can still rate…".
- The guide says "Goals-track reviews open for rating once the person submits their self-assessment", but managers can rate before that. Kabir's goals-track review was rated and released with no self-assessment.
- "Live … Goals, reviews or calibration under way" mentions calibration, which the product doesn't have.
- Expected: Banners that match the status (Closed, Released, Locked), and guide text that matches the rules.
ISS-184 · HR's per-person page in a cycle shows only the goal sheet, and its "Employees" breadcrumb is Not Found
- Module: Performance · Severity: Medium · Found: 2026-09-29
- Steps: Admin → Performance → Q2 2026 Quarterly Review → click Ishita Bhattacharya (Acknowledged, 3.8).
- Actual:
- The page shows "Ishita Bhattacharya — goals" with 4 goals and weights. It has no self-assessment, manager ratings or comments, score, band, acknowledgement or remarks.
- So HR cannot read the reviews it releases, and there is no HR sign-off view.
- The breadcrumb "Employees" links to
/performance/cycles/{id}/employees, which shows "Not Found".
- Expected: A read-only review view (both sides, score, band, acknowledgement) for HR, and a breadcrumb that goes back to the cycle.
ISS-183 · Reporting Manager role has company-wide Performance admin (all cycles, every rating and comment)
- Module: Performance / RBAC · Severity: Medium (needs confirmation) · Found: 2026-09-29
- Actual:
- Harsh Vardhan Mistry (Reporting Manager) has
performance.cycle.viewandperformance.cycle.manage. - He can open Performance with "New cycle", every cycle's cockpit (all 12 Q2 participants, including the CEO and CTO), Reports (rating distribution by band, department and manager, with CSV), and Extend a cut-off / Close cycle.
GET /api/company/perf/reviewsreturns every manager's ratings and comments company-wide, including his own review written by Kavya. This goes against the product's promise "Until you release, nobody sees anybody else's words."
- Harsh Vardhan Mistry (Reporting Manager) has
- Expected: Managers see only their own reports' reviews, through their review queue. Cycle admin stays with HR. Related: ISS-086, ISS-150.
ISS-182 · "Close cycle" closes a review cycle in one click, with no confirmation
- Module: Performance · Severity: Medium · Found: 2026-09-29
- Actual: In the cycle "⋯" (Cycle actions) menu, "Close cycle" calls
PATCH …/review-cycles/{id} {status:"closed"}directly. A confirm ("Close it anyway?") appears only if the server rejects withCYCLE_HAS_UNFINISHED_REVIEWS. When all reviews are finished, one mis-click closes the cycle permanently ("closing is final"). This was found from the client code and was deliberately not clicked. The same pattern as ISS-158 (Surveys). - Expected: A confirmation dialog that states the consequences, like "Lock this cycle?" and "Release this cycle?".
ISS-181 · Feedback page: employees get 403 on their own submissions, but the page says "Nothing sent yet"
- Module: Performance → Feedback (Me) · Severity: Medium · Found: 2026-09-29
- Steps: Sign in as Zoya Kirmani, Nithya Sundaram (Employee) or Harsh (Reporting Manager) → Feedback.
- Actual:
GET /api/me/perf/feedback-casesreturns 403 "Viewing feedback requires Feedback access" (the Employee role has no feedback permission).- The page shows "My submissions — Nothing sent yet" and still offers "Send feedback", which may fail the same way.
- For Kavya and Vikram the same call returns 200 with
canSubmit: true. The admin getscanSubmit: false, reason: employee_link_required.
- Expected: Employees can list their own submissions (or the feature is hidden). A load failure shows an error, not an empty state.
ISS-180 · 13 duplicate "Performance review · HR signoff" approvals for Kavya go to a manager and point at no review
- Module: Performance / Inbox / Workflows · Severity: Medium · Found: 2026-09-29
- Steps: Harsh Vardhan Mistry → Inbox → Performance (13). Open one; do not act.
- Actual:
- There are 13 pending
hr_signofftasks, all titled "Performance review · HR signoff · Kavya Raghunathan", created 22 Sep 18:49–18:57 and due 30 Sep. They were assignedrelationship:hr_partnerto Harsh, a Reporting Manager. - The workflow designer ("Performance review sign-off", trigger "Review finalization requested") sets the assignee to
hr-admin. - None of the 13
entityIds matches a review in any current cycle. - The detail panel is labelled "Leave request". It shows DUE twice ("tomorrow, 12:00 pm" and raw
2026-09-30T06:30:03.207Z), with no link to the review, no score and no comments, only Approve/Decline. - Releasing Q2 raised no sign-off at all.
- There are 13 pending
- Expected:
- One sign-off per review, routed to HR, showing the review and linking to it.
- Orphaned tasks are cancelled, and the panel shows the right kind label and date format.
ISS-179 · Employee profile → Performance tab shows the same unrelated review for everyone (?employeeId is ignored)
- Module: Performance / Organization profile · Severity: High · Found: 2026-09-29
- Steps: Admin → Organization → open Harsh Vardhan Mistry (or Kavya) → Performance tab.
- Actual:
GET /api/company/perf/reviews?employeeId=<id>&limit=25returns the same company-wide list for any employee id. It is 32 reviews across cycles, starting with Aarav's manager review.- So every profile shows "Latest review · Cycle (blank) · Reviewed by their manager · Pending" and "No goals set — Quarterly goals and key results will show up once planning is done."
- Harsh's real released review (3.3, Meets expectations) and his 4 KRAs don't appear.
- Anyone with
performance.cycle.viewalso gets every review's ratings and comments from this endpoint.
- Expected: Filter by employee. Show that person's latest cycle name, stage, score and band, and their goal sheet.
ISS-178 · Performance: after a partial release, 9 people are stuck in a "Released" cycle, still asked to self-assess but blocked
- Module: Performance · Severity: High · Found: 2026-09-29
- Steps: Admin → Performance → "Q2 2026 Quarterly Review" (status Released, released 23 Sep with 3 of 12 ratings in). Then sign in as Kavya Raghunathan → Performance review.
- Actual:
- The release dialog says "Release anyway — I understand 9 employee(s) will be released without a rating". But those 9 participants have
releasedAt: null(GET …/participants), so they were never released. - The cockpit still lists them under "Self-assessment · 2 Oct · 3d left" or "Reviewer rating · 9 Oct".
- Kavya's page says "Needs you · 1 waiting — Write your self-assessment · closes 2026-10-02". The form then says "Self-assessment is read-only — HR has locked this cycle. Nothing can be changed unless it is released." The cycle is not locked; it is already released.
- Managers' queues (
/api/me/perf/my-reviews/reviewing) are empty. The cycle actions offer only "Extend a cut-off…" and "Close cycle", not Release. - So these 9 reviews can never finish or be released. They also never get the "Your review was released without a rating" state.
- The release dialog says "Release anyway — I understand 9 employee(s) will be released without a rating". But those 9 participants have
- Expected: Either release marks all participants released (unrated ones get "released without a rating"), or the cycle stays open for them. Employees should not be asked to do something they cannot do.
ISS-177 · Notification settings show all 93 topics to everyone, including candidate emails and engine alerts
- Module: Settings → Notifications · Severity: Low · Found: 2026-09-29
- Actual: Zoya (Employee) gets the same 93 rows as the super admin. These include "Application received (candidate)", "Offer released (candidate)", "Reference request (referee)", "Engine health alert/recovered", "Reviewer overdue (HR)" and "Inbound email needs triage". None of these reach an employee, and the "(candidate)" ones are emails to outsiders. Email is off for every topic by default, and Slack is disabled everywhere without saying why. Quiet hours says "Times are in UTC", while Profile's timezone and the rest of the app use IST. The helper text says "How mutable notifications are bundled".
- Expected: Show the topics that apply to the user's role, mark or hide Slack when it isn't connected, and use the user's timezone. See also ISS-051 and ISS-113.
ISS-176 · Test and probe workflows are visible to the company and offered in pickers; Campaigns lists duplicates and retired flows
- Module: Settings → Workflows · Severity: Low · Found: 2026-09-29
- Actual:
- Authoring lists "Dead-letter probe" (
deadletter_529f1c92, Active, Leave, Platform, ontest.deadletter_13d1c934) and "Demo Workflow" (module "Demo Module", which also appears in the Module filter). - Events shows "Test deadletter 13d1c934 starts Dead-letter probe" with an on/off switch. New approval chain → Process offers "When test deadletter 13d1c934".
- New campaign → Workflow lists Leave Cancellation, Attendance Regularization, Shift Swap, Annual Leave Approval, Requisition Approval, Performance review sign-off and Resignation twice each. It also offers retired flows (Leave Encashment, Probation review due) and the probe.
- Operations keeps a parked
test.deadletter_13d1c934event.
- Authoring lists "Dead-letter probe" (
- Expected: Test fixtures are hidden from tenants, and pickers list each published, non-retired workflow once.
ISS-175 · Platform SLA policies escalate to "placeholder hr head", "placeholder ceo" and "placeholder hr manager"
- Module: Settings → Workflows → SLA policies · Severity: Low · Found: 2026-09-29
- Actual: Most platform policies' ladders read like "after 5 business days: tell placeholder hr head" or "after 10 business days: tell placeholder ceo", and a corrective action goes "for placeholder hr head". Role mappings has no "placeholder" entries, so it's unclear who is told when these clocks breach.
- Expected: Ladders name real (mapped) roles, and an unmapped rung is flagged.
ISS-174 · The delegate picker leaves out Kavya Raghunathan and Aarav Krishnamurthy, but offers people who have never signed in
- Module: Settings → Delegation · Severity: Medium · Found: 2026-09-29
- Steps: Settings → Delegation → "Who decides for you" (as Ops Maven, Kavya or Zoya).
- Actual: The list (
GET /api/company/people/directory-basic, 19 people) never includes Kavya Raghunathan (HR Head) or Aarav Krishnamurthy (Executive/CEO), so nobody can delegate to HR or the CEO. It does include Aditya Ranganathan, Asha Rao, Meera Kulkarni and Ritika Chourasia, whose invitations are still pending. - Expected: Everyone with an active sign-in who can approve, and not accounts that can't sign in yet.
ISS-173 · Active sessions: 100 sessions all at 127.0.0.1, no "this device", and idle sessions are never ended
- Module: Settings → Sign-in & security · Severity: Medium · Found: 2026-09-29
- Actual:
- Every session for Ops Maven, Kavya and Zoya shows IP 127.0.0.1, while the audit log records real IPs (171.76.87.33, 2401:4900:…).
- The list stops at 100 rows, with no paging, and doesn't mark the current device.
- Sessions last active "5 days ago" are still listed, although Security sets "Sign out when idle: After 15 minutes".
- The page heading says "Security", the same as Workspace → Security; the menu calls it "Sign-in & security". Update password is enabled while the fields are empty.
- Expected: Record the client IP, mark this device, and page the list. Expire idle sessions per policy. Give the heading the menu's name.
ISS-172 · Audit log "Type" filter only offers types from the rows already loaded
- Module: Settings → Audit log · Severity: Medium · Found: 2026-09-29
- Steps: Settings → Audit log → Filter by type.
- Actual: Page 1 offers only Company, Lifecycle, Platform and Travel & expenses. After paging, "Workflows" appears. The last 1,000 entries (
GET /api/company/audit-events) also have Recruitment (106), Employees (76), Assets (13), Attendance, Leave, Documents, Notifications, Performance, Policies and Access, which can't be chosen. Most module records (asset, talent_offer, talent_requisition, attendance_override, shift, search…) are typed "Platform" (see ISS-048). - Expected: The filter lists every type from the server, and records carry their module's type.
ISS-171 · Workflow designer: the cost-threshold branch opens as "Requested days is 999999", and Test run uses leave fields
- Module: Settings → Workflows (designer) · Severity: Medium · Found: 2026-09-29
- Steps: Workflows → Asset request approval → designer → click the branch pill "request.estimatedCost > 50000" under "Over the cost threshold?".
- Actual: The inspector shows the rule as WHERE Requested days · is · 999999, not estimatedCost > 50000. Editing and saving from there would probably replace the real rule. The canvas prints the condition twice (as the pill and again as a caption). Test run's sample payload for this asset flow is
request.days, request.type, employee.department, employee.balance, which are leave fields, so the cost branch can't be exercised without adding a field by hand. The designer has no version history, although the list says "v6 live · 6 versions". - Expected: The inspector round-trips the stored expression, Test run offers the trigger's own fields, and versions can be listed and compared.
ISS-170 · Roles: Company Super Admin card says "13 members", but its member list has 1
- Module: Settings → Roles · Severity: Low · Found: 2026-09-29
- Actual: The card reads "13 members" (
memberCount: 13inGET /api/company/roles), but Members shows "1 MEMBER" (Ops Maven), which matches Users. The count seems to include holders in other companies. The inherited role's permission grid also has 246 enabled checkboxes, although the page says inherited roles are read-only. Save stays disabled, so this is only confusing. - Expected: Count only this company's holders, and show read-only checkboxes on inherited roles.
- Note: ISS-043 looks fixed: cards now read "137 of 137 + 21 self-service" = 158, which matches the editor.
ISS-169 · "Invite user" defaults the role to Company Super Admin
- Module: Settings → Users · Severity: Medium · Found: 2026-09-29
- Steps: Ops Maven → Settings → Users → Invite user.
- Actual: Role is pre-selected as Company Super Admin (hint "One company, all of it"). An admin who fills in only the name and email grants full company access.
- Expected: No default, or the least-privileged role (Employee).
ISS-168 · Settings → Users: the Status filter does nothing, and paging is broken
- Module: Settings → Users · Severity: Medium · Found: 2026-09-29
- Steps: Settings → Users → Status = Invited (or Suspended). Separately: press Next page.
- Actual: With Invited or Suspended selected, all 25 accounts still show, including Active ones. Page 1 shows all 25 rows while the footer says "1–12 of 25 · Page 1 of 3". Page 2 shows no rows while the footer says "13–24 of 25".
- Expected: The filter narrows the list, and each page shows the rows its footer describes.
ISS-167 · HR Head sees Workflows and Roles in Settings but is denied them, and "Invite user" has an empty role list
- Module: Settings / RBAC · Severity: Medium · Found: 2026-09-29
- Steps: Kavya Raghunathan (HR Head) → Settings. Then Users → Invite user → Role.
- Actual:
- The Settings menu lists Workflows and Roles, but both open "This page is not yours to see". The HR Head role lacks
settings.workflows.*andsettings.roles.*. - Invite user opens, but the Role list is empty ("Pick a role") because
GET /api/company/rolesreturns 403. HR can't invite anyone, and no message explains why. - The row menu offers Suspend on the Company Super Admin (Ops Maven), the only super admin. This was not clicked, so it is unverified whether the server refuses it.
- The Settings menu lists Workflows and Roles, but both open "This page is not yours to see". The HR Head role lacks
- Expected: Hide menu entries the user can't open. Load the roles the inviter may grant, or hide Invite. Don't offer to suspend a higher-privileged account.
ISS-166 · A Reporting Manager can't open any Settings page, not even Profile, Notifications, Delegation or Sign-in & security
- Module: Settings / RBAC · Severity: High · Found: 2026-09-29
- Steps: Harsh Vardhan Mistry (Reporting Manager) → account menu → Settings (or open
/settings/profile,/me/settings/delegation, etc. directly). - Actual: Every page shows "This page is not yours to see", with no settings menu. Harsh can't change his password, set up two-factor, revoke sessions, set notification preferences or name a delegate. Managers need delegation more than anyone. Zoya (Employee) can open all six personal pages. The Reporting Manager role has 16 self-service permissions against the Employee role's 21, and lacks
settings.me.manage,assets.me.view/manage/acknowledgeandpayslips.me.view(GET /api/company/roles/{id}/permissions). - Expected: Every signed-in user can open the personal Settings pages. Scoped roles include every self-service permission the Employee role has.
ISS-165 · Form builder logic: condition picker shows internal keys ("answers.q_mugmmc6c1") instead of question text
- Module: Surveys / Templates (form builder) · Severity: Low · Found: 2026-09-29
- Steps: Edit questions → expand Q4 "Will you recommend your friends this workspace?" → Show when… → field combobox.
- Actual: The options read
answers.q_mugmmc6c1 ; answers.q_mugmmc6c2 ; answers.q_mugmmc6c3 ; answers.q_mugmo4zx1. Only the summary line above ("Show when 'How likely…' is at least 5") uses the question text. The Logic map's edge label ("shows") is also clipped behind the zoom controls in dark mode. - Expected: List questions by number and label, e.g. "1 · How likely are you to recommend…".
ISS-164 · Surveys: Distribute → "Invitation email" lists every company email template (Termination letter, Offer released…)
- Module: Surveys / Templates · Severity: Low · Found: 2026-09-29
- Steps: Admin → Surveys → Edit questions → Distribute → Invitation email.
- Actual: Beside "Default invitation", the list has 23 unrelated templates, including "Termination letter", "Offer released", "Application rejected" and "Investigation summary pack (to the CEO)". Any of them can be sent as a survey invitation.
- Expected: Offer only invitation-type email templates, or at least group them.
ISS-163 · Surveys: anonymity wording differs between builder and Launch, and "Anonymous — no reminders possible" still offers reminders
- Module: Surveys · Severity: Low · Found: 2026-09-29
- Actual:
- The builder's Settings → Anonymity offers "Off — responses carry the respondent / Optional / Forced — one-way anonymous".
- The Launch dialog offers "Optional — respondents are recorded unless the form forces anonymity / Anonymous — no reminders possible, identity never stored / Attributed — responses carry the respondent".
- With "Anonymous" chosen, "Remind every (days)" stays enabled at 7.
- Expected: Use the same three terms in both places, and disable or hide the reminder cadence when the round is anonymous.
ISS-162 · Surveys: Launch lets you pick an audience smaller than the minimum response count, so results can never unlock
- Module: Surveys · Severity: Medium · Found: 2026-09-29
- Steps: Admin → Surveys → Launch → Audience "IT Audiencei" (2 people). The survey's Settings → "Minimum responses before results show (min-N)" is 5.
- Actual: The dialog shows no audience size and no warning, and Schedule is enabled. The existing round was launched this way. Its Results say "Distributions unlock at 5 responses to protect individual answers — 0 so far", which can never happen with 2 people (see also ISS-159).
- Expected: Show the audience count in the Launch dialog, and warn or block when it's below min-N, pointing to Settings to lower min-N.
ISS-161 · Form builder: "Insert variable" is always empty — GET /api/v1/templates/variables returns 503
- Module: Surveys / Templates (form builder) · Severity: Medium · Found: 2026-09-29
- Steps: Admin → Surveys → Edit questions → expand any question → "Prefill from (optional)" → Insert variable.
- Actual: Every time a question is expanded,
GET /api/v1/templates/variablesreturns 503. The picker shows "No matching variable.", so prefill paths (placeholderemployee.first_name) have to be typed blind. - Expected: The variable catalogue loads. If it fails, show an error instead of "No matching variable."
ISS-160 · Surveys: invited employees can't find the survey anywhere in the app
- Module: Surveys · Severity: High · Found: 2026-09-29
- Steps: Zoya Kirmani is in audience "IT Audiencei" and has 3 open links for "feedback survey — Sept 2026". Sign in as Zoya → Home (/me), Inbox, notifications bell.
- Actual: No survey appears anywhere: no Home card, no Inbox item ("6 things are waiting on you" lists only asset items), and no notification. Surveys isn't in her sidebar, and /surveys redirects to /me. The only way to answer is the emailed one-time link. Settings → Notifications has no survey topic either, so no in-app or Slack channel can be enabled.
- Expected: Open survey invitations appear in the employee's Inbox/Home ("To do: answer survey"), along with reminders and a survey notification topic.
ISS-159 · Surveys: launching a round made 3 invitation links per person (audience of 2 → "0 / 6 responded")
- Module: Surveys · Severity: Medium · Found: 2026-09-29
- Steps: Admin → Surveys → "feedback survey". Its round "feedback survey — Sept 2026" was launched on 25 Sep to audience "IT Audiencei", which has 2 people (Zoya Kirmani, Harsh Vardhan Mistry). Open Results → Links & runs.
- Actual: The round shows "0 / 6 responded", and the campaign's progress says
invited: 6. Links & runs lists Zoya Kirmani 3 times and Harsh Vardhan Mistry 3 times, all open and all created within a few seconds of each other (12:54–12:55). Each run isrespondentKind: "external"even though they are employees. So each person got 3 one-time links, and the response rate can never go above 33%. - Expected: One link per audience member per round (idempotent launch). "Invited" should equal the audience size, and employees should be recorded as internal respondents.
ISS-158 · Surveys: "Close" ends a live survey round in one click, with no confirmation
- Module: Surveys · Severity: Medium · Found: 2026-09-29
- Steps: Admin → Surveys → "feedback survey" card → round row "feedback survey — Sept 2026 · open · 0 / 6 responded" → Close.
- Actual: The click sends
POST /api/company/templates/form-campaigns/{id}/closeat once. (In QA the request was blocked, so the round is still open.) There is no confirm dialog and no note that open links will stop working. The control is a small checkbox-style icon labelled "Close", right beside the response count, so it's easy to hit by mistake. - Expected: Ask for confirmation, e.g. "Close this round? N people haven't responded; their links stop working." The action should also look like an action, not like a checkbox.
ISS-157 · A claim can't be tied to its trip, so the advance is never netted
- Module: Expenses · Severity: High · Found: 2026-09-29
- Steps: Zoya's trip "Demo – Client visit Pune" is approved and an ₹8,000 advance issued (DEMO-ADV-001). She files claim "Demo – Pune visit" (₹16,900) from Travel & expenses → New claim.
- Actual: The New claim form has no trip field, and the client sends
travelRequestId: null. The approved claim shows "Advance already paid ₹0.00 · To be reimbursed ₹16,900.00", so the ₹8,000 advance stays outstanding and would be paid twice. The claim also went through manager endorsement, which a trip-linked claim would skip. - Expected: Claims raised for a trip carry
travelRequestId(the trip page has a "Claim expenses" button that should start one), and the advance is netted.
ISS-156 · A claim with any line over its category limit can't be sent, and the reason is never shown
- Module: Expenses · Severity: Medium · Found: 2026-09-29
- Actual: The claim form shows "Above the Demo – Client meals limit." under the line but still lets you press Send claim. Submit then fails with
422 OVER_LIMIT("Some lines are above their category limit and cannot be submitted"), with no message; the claim stays a draft. (Before that it needsIf-Match; without it,428 IF_MATCH_REQUIRED.) - Expected: Either block Send claim with a clear message, or allow an over-limit line with a justification, for finance to reduce. The claim page already has a "Reduce" decision for this.
ISS-155 · An expense claim sent late evening in India fails ("cannot be dated in the future") and leaves an empty draft
- Module: Expenses · Severity: High · Found: 2026-09-29
- Steps: At 02:50 IST on 29 Sep (still 28 Sep in UTC), Zoya → Travel & expenses → New claim. The item date defaults to "29 Sep 2026". Fill the item → Send claim.
- Actual:
- The client creates the claim (201,
items: []), then adds the item → 400 "Expense date: An expense cannot be dated in the future", because the server compares against UTC. - No error is shown. The dialog closes, and an empty ₹0 Draft claim stays in the list; everything typed is lost.
- The client creates the claim (201,
- Expected:
- Validate dates in the company's time zone (Asia/Kolkata), and default the item date to a date the server accepts.
- On any item failure, keep the dialog open with the error instead of leaving an empty draft.
ISS-156 · [auto] Uncaught page error: undefined
- Module: expenses-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-155 · [auto] Uncaught page error: undefined
- Module: expenses-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-154 · Asset receipt "Acknowledge" does nothing
- Module: Assets / Inbox · Severity: High · Found: 2026-09-29
- Steps: Kavya Raghunathan → Inbox → "Return: LOA-0001 — Demo – Loan laptop 01" (Acknowledgement) → tick "I have read and understood this document" → Acknowledge.
- Actual: No request is sent and no message is shown. The receipt stays open, and My things keeps "Needs you — Sign for Demo – Loan laptop 01". Asset receipts therefore can't be signed. Related: ISS-143, receipts shown to every user.
- Expected: The acknowledgement is recorded on the movement, and the receipt leaves the inbox.
ISS-154 · [auto] Uncaught page error: companyId is not defined
- Module: assets-request
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/inbox
- Stack:
ReferenceError: companyId is not defined | at $ (https://qa.satellitehr.com/assets/inbox-L0tfbPlc.js:1:5237) | at onAcknowledge (https://qa.satellitehr.com/assets/inbox-L0tfbPlc.js:1:15029)
ISS-153 · Asset "Hand one over" only reserves the unit; the hand-over receipt vanishes once the asset is returned
- Module: Assets · Severity: Medium · Found: 2026-09-29
- Actual:
- On an approved request, "Hand one over" moves the unit to Reserved ("Handed over against a request") with no holder, so nobody gets a receipt. A second "Hand over" on the asset page is needed to actually issue it.
- The pending "Hand over: LOA-0001 …" receipt then disappears from the holder's inbox once the asset is returned, replaced by "Return: LOA-0001 …". The hand-over was never acknowledged.
- Expected: "Hand one over" issues the unit to the requester in one step. Receipts stay until they are acknowledged or explicitly cancelled.
ISS-152 · Employees can no longer request an asset: "This action needs view access to asset-requests"
- Module: Assets / RBAC · Severity: High · Found: 2026-09-29
- Steps: Zoya Kirmani (Employee role) → My things → Request something → Loan laptop → fill in → Ask for it.
- Actual: Toast "Could not ask for loan laptop — This action needs view access to asset-requests". Nothing is created. The same employee raised a Mobile phone request on 23 Sep, so the Employee role seems to have lost a grant since then.
- Expected: The Employee role can create and view its own asset requests. Better still, don't offer "Request something" to people who can't use it.
ISS-151 · Copy mismatches in Assets
- Module: Assets · Severity: Low · Found: 2026-09-29
- Actual: The "What you can do in Equipment" help points to "Equipment → Reports", but there is no Reports tab (Register / Requests / Who has what / Catalogue), and the module is called "Assets" in the sidebar. The Report lost dialog says "No signature is collected — A recovery completes without the holder signing". Laptop rules say "5 units follow it" while the register lists 4 laptops. History timestamps are US-style ("9/28/2026, 6:40:00 PM") while the rest of the page uses "September 28, 2026". The My things page carries a "Refer someone / Refer a candidate" block. The asset request workflow's "Over the cost threshold?" reads request.estimatedCost, but the request form has no cost field.
ISS-150 · Manager Harsh can open company-wide Expenses (all claims, File for a colleague) but not "My things"
- Module: Access · Severity: Low · Found: 2026-09-29
- Actual: /expenses/claims shows every company claim to Harsh. /me/things and /assets/* say "This page is not yours to see", and his self-service sidebar has no "My things", so he can't request equipment for himself.
- Expected: A manager sees only their team's claims, and has self-service My things like other employees.
ISS-149 · Finance employee (Arnav Deshmukh) has no finance access; the finance approver group is CEO/CTO/HR/admin
- Module: Travel & expenses / Access · Severity: Medium · Found: 2026-09-29
- Actual: Arnav (Finance) lands on /me and has no Expenses admin screens and no approvals. The "Finance Approver" tasks for EXP-00003 went to Aarav, Vikram, Kavya, Harshit Bhalla and the admin.
- Expected: Check that this is intended. It blocks a demo of a "Finance" persona.
ISS-148 · Claim marked Approved (finance_approved) before any line has a finance decision
- Module: Travel & expenses · Severity: Medium · Found: 2026-09-29
- Actual: EXP-00001 (₹2,000) shows as Approved, with Approved ₹2,000 in the list. Its page still has "Finance decisions … 1 line still to decide · Record the decisions", and the line status is "claimed". The finance step in the Inbox is only Approve/Decline, labelled "Leave request" (see ISS-078), with no link to the line decisions.
- Expected: One place to settle the claim, or the Inbox task opens the claim's finance bar.
ISS-147 · Expense totals disagree across screens
- Module: Travel & expenses · Severity: Medium · Found: 2026-09-29
- Actual: Zoya has claimed ₹3,200 over 2 claims (the Reports tab says the same). Her "Your claims, all told" card says Claimed ₹2,000.00 / Waiting ₹2,000.00. Categories says "In use 0" and Accommodation "Claim lines 0", while Spend shows 2 Accommodation lines. The Spend report labels ₹2,000 approved as "Reduced". Claim names read "Expense claim" on Claims but "Untitled" on Reports. The EXP-000nn references appear nowhere in the UI.
- Expected: Figures that agree, and the claim reference shown.
ISS-146 · Expense claim that the manager approved still says "With your manager" / "Awaiting approval … This claim was approved"
- Module: Travel & expenses · Severity: Medium · Found: 2026-09-29
- Steps: Zoya's claim EXP-00003 (₹1,200). Harsh approved the manager step on 25 Sep; it now waits on finance (6 parallel tasks, relationship finance_approver).
- Actual: Zoya's My claims shows "With your manager". The admin claim page shows "Awaiting approval · With an approver" and, underneath, "This claim was approved — Harsh Vardhan Mistry decided on 2026-09-25."
- Expected: "With finance" (the status filter has that option) and no "was approved" banner until the whole chain finishes.
ISS-145 · Employee profile → Assets says "No assets assigned" for someone who holds an asset
- Module: Organization profile / Assets · Severity: Medium · Found: 2026-09-29
- Steps: Assets → Who has what shows Sneha Vaidyanathan holding LAP-0001 (Issued). Open her profile → Assets tab (waited 6 s).
- Actual: "No assets assigned — Laptops, monitors, and access cards issued to this employee will appear here."
- Expected: The tab lists LAP-0001.
- Evidence: scratch/AE/x-cross/sneha-assets-long.png
ISS-144 · Receipt titles keep the asset's old name
- Module: Assets · Severity: Low · Found: 2026-09-29
- Actual: LAP-0005 is now called "Demo – Spare laptop", but its receipts are still titled "Issue: LAP-0005 — Demo – Laptop for Rohan".
- Expected: Show the current name, or say it was renamed.
ISS-143 · Asset receipts for other people show up in every user's Inbox and Home, with an Acknowledge button
- Module: Assets / Inbox · Severity: High · Found: 2026-09-29
- Steps: Sign in as Zoya Kirmani, Arnav Deshmukh, Harsh Mistry or Kavya Raghunathan → Home ("Needs a look") and Inbox → Acknowledgements.
- Actual: Everyone sees "5 things are waiting on you: Issue: LAP-0004 — Demo – Probe laptop · Return: LAP-0004 … · Issue: LAP-0005 — Demo – Laptop for Rohan …". These are the receipts of Probe Joiner (Demo) and Rohan Verma (Demo). Opening one shows "I have read and understood this document" with Acknowledge / Decline with follow-up, so anyone could sign someone else's receipt.
- Expected: A handover or return receipt goes only to the person who holds the asset.
- Evidence: scratch/AE/x-AE-zoya.kirmani/inbox.png, inbox-item-0.png
ISS-131 · A resignation now starts two "Resignation" workflow runs that wait on Harshit Bhalla, not the manager
- Module: Lifecycle offboarding / Workflow · Severity: High · Found: 2026-09-29
- Steps: Start exit (Resignation, last day 29 Sep) for Rohan Verma (Demo), whose manager is Kabir Anand.
- Actual: Two instances of the same workflow version (
fe74e6f5…andaf8b5f3c…, versionad037c73…) start for exit2937ce21…. Both wait at "Acknowledgement drafted" on Harshit Bhalla. No "Exit authorisation" run (manager acceptance) starts; the day before, that run correctly went to the manager. Workflow runs today also show a different initiator, so the workflow configuration seems to have changed. - Expected: One authorisation run per exit, starting with the leaver's manager.
ISS-142 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-offboarding
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-141 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-kt
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-130 · The KT plan counterpart sees the leaver as "Employee" instead of their name
- Module: Lifecycle knowledge transfer · Severity: Low · Found: 2026-09-29
- Steps: Rohan Verma (Demo)'s transfer plan has a task where Harsh Vardhan Mistry is the counterpart. Sign in as Harsh → Lifecycle → Knowledge transfer.
- Actual: The card is titled "Employee — Transferring — no due date", with no name, while HR sees "Rohan Verma (Demo)". The counterpart can't tell whose handover it is.
- Expected: Show the leaver's or mover's name to anyone who is a counterpart on the plan.
ISS-140 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-kt
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-129 · After a department transfer, the department headcount doesn't change and the position stays in the old department
- Module: Lifecycle transfers → Organization · Severity: Medium · Found: 2026-09-29
- Steps: Transfer Rohan Verma (Demo), Information Technology → Backend Developer, effective 29 Sep. The transfer shows "effected" and his profile department reads Backend Developer. Then open Organization → Departments.
- Actual: The Backend Developer card shows Headcount 0, while the employee list filtered by that department includes him. His position is still "IT Helpdesk Engineer", a position that belongs to Information Technology. The transfer form offers no way to change position (see ISS-084).
- Expected: Headcount follows the employee's department. A department transfer also moves or re-picks the position, or flags the mismatch.
ISS-139 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-138 · [auto] Uncaught page error: undefined
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-137 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-136 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-135 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-134 · [auto] Uncaught page error: undefined
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-133 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-132 · [auto] Uncaught page error: undefined
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-131 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-130 · [auto] Server error 503 on GET /api/me/identities
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-129 · [auto] Uncaught page error: undefined
- Module: attendance-daily
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-128 · [auto] Server error 503 on GET /api/me/identities
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-127 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-126 · [auto] Server error 503 on GET /api/me/identities
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-125 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-124 · [auto] Server error 503 on GET /api/me/identities
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-123 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-122 · [auto] Server error 503 on GET /api/me/identities
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-121 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-120 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-119 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-118 · [auto] Uncaught page error: undefined
- Module: leave-journey
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/me
- Stack: ``
ISS-117 · [auto] Server error 503 on GET /api/me/identities
- Module: leave-setup
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-116 · [auto] Server error 503 on GET /api/me/identities
- Module: leave-setup
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-115 · Employee "People" directory shows only yourself
- Module: Me → People · Severity: Low · Found: 2026-09-28
- Actual: As Zoya, "Find a colleague — who they are, what they do, who they work with. Everyone" lists only Zoya Kirmani. Harsh sees his 4 reports.
- Expected: At least the teammates (the Swap a shift dialog already lists them), or a message that the directory is limited.
ISS-114 · Home approval counts don't match the Inbox
- Module: Home / Inbox · Severity: Low · Found: 2026-09-28
- Actual: Kavya's Home says "2 approvals are waiting for you" but Inbox shows "Awaiting your decision 7". Harsh's Home says "13 approvals are waiting for you" but Inbox shows 6. Zoya's sidebar badge shows Inbox 13 while her inbox has 5 open.
- Expected: The same number everywhere, or labels that say what each one counts.
ISS-113 · Notification settings have no leave events
- Module: Settings → Notifications · Severity: Low · Found: 2026-09-28
- Actual: There are rows for "Attendance corrected by HR", "Attendance correction decided", "Overtime decided" and "Shift swap decided". There's nothing for a leave request submitted, approved or rejected, or for leave cancelled, although the leave workflow sends those messages in-app.
- Expected: Leave events can be switched per channel like the attendance ones.
ISS-112 · Worked hours and overtime contradict each other on an HR-corrected day
- Module: Attendance → Calendar / My attendance · Severity: Low · Found: 2026-09-28
- Actual: Zoya, Mon 21 Sep: "Present · 10:12 am – 7:04 pm · 7.4h worked · 1.1h overtime". 7.4h is below the shift, yet 1.1h of overtime is shown. The Edit day entry dialog for the same day says "Derived hours: 7.9h".
- Expected: One consistent worked-hours figure, and no overtime on a short day.
ISS-111 · Employee profile → Timesheets has no dates
- Module: Employees → profile → Timesheets · Severity: Low · Found: 2026-09-28
- Actual: For Zoya the tab shows "Hours recorded 125.6h · 14 of 14 days", but every row's Date (and Status) is "—", so the hours can't be matched to days.
- Evidence:
scratch/LA/x/zoya-timesheets.png
ISS-110 · A Reporting Manager sees company-wide Leave and Attendance admin, including HR-only pages
- Module: Leave / Attendance / RBAC · Severity: Medium · Found: 2026-09-28
- Steps: Sign in as harsh.mistry (IT, Reporting Manager of 4). Open Leave and Attendance.
- Actual: Leave → Requests lists all 7 company requests ("Every request across the company"). Balances tracks 26 people, with the "Adjust balance…" lever. Policies offers "New policy". Attendance shows everything: the Manual sheet (labelled "HR-only surface"), Settings with Save buttons, Bulk assign roster, Overtime policy. At the same time these pages call
/organization/departments,/location/locationsand/location/jurisdictionsand get 403, so the department filters are empty. His Home counts "Total employees 3". - Expected: Managers see their team's requests, balances and attendance. Policy, settings and the manual sheet stay with HR.
- Note: I didn't check whether Harsh holds extra roles beyond Reporting Manager.
GET /api/mereturns 500 for him.
ISS-109 · Leave and attendance inbox items show internal step codes ("Mgr quick · … · at mgr quick")
- Module: Inbox / Workflow · Severity: Low · Found: 2026-09-28
- Actual: Harsh's Inbox → Decided → Leave lists "Mgr quick · Zoya Kirmani · at mgr quick". Attendance lists "Mgr regularize", "Mgr swap", "Mgr ot review", "Hr ot confirm". These are the step codes
mgr_quick,hr_ot_confirm… The step names are "Manager approval", "Manager review" and "HR confirmation". - Expected: The step name and the request (e.g. "Paid Time Off · 1–2 Oct").
ISS-108 · Comp-off wallet says "2 days to use" when the credits add up to 1.5
- Module: Me → Overtime & comp-off · Severity: Low · Found: 2026-09-28
- Actual: The wallet heading reads "2 days to use" above chips of 0.5d (lapses 19 Dec) and 1d (lapses 21 Dec). The leave balance shows Comp-off 1.5.
- Expected: "1.5 days to use".
ISS-107 · Earned comp-off is shown as negative "taken"
- Module: Leave balances / Overtime · Severity: Low · Found: 2026-09-28
- Actual: Zoya's two approved overtime credits (+0.5d, +1d) show as "Comp-off -1.5 used this year" (Me → Leave → Balances), "Taken -1.5d" (HR Balances and ledger panel) and "-1.5 taken · 0 encashed" (Employee → Time off).
- Expected: Credits count as accrued/earned. Taken stays 0.
ISS-106 · Leave policy entitlements are never credited ("Policies not applied."), so almost everyone has 0 days
- Module: Leave → Policies / Balances · Severity: High · Found: 2026-09-28
- Actual: The "Paid Time Off (PTO) — company default" policy is Active with 20d / year (Edit shows Entitlement 20, Carry-forward 30, Annual grant). Still, every balance shows Opening 0 / Accrued 0, and Harsh, Kavya and the other 23 people have 0 PTO. Zoya has 12 only because of a manual "+20d · Adjustment · Policies not applied." in her ledger. The self-service cards read "Paid Time Off (PTO) 12 / 0 days" (entitled 0). The other 8 default policies list "—d / year". The leave workflow starts with "Balance check: employee.balance <= 0 → Insufficient balance", so these people can't get leave through.
- Also: In the balances table the +20 adjustment isn't counted in any column (Opening 0d, Accrued 0d, Taken 8d, Available 12d), so the row doesn't add up.
- Expected: An active policy grants (or accrues) the entitlement to everyone in its audience, and adjustments appear in the row breakdown.
- Evidence:
scratch/LA/dlg-leave/balance-action-0.png,scratch/LA/dlg-leave/policy-detail-PTO.png
ISS-105 · Approved leave doesn't show on the attendance calendar: those days read "No record"
- Module: Leave → Attendance · Severity: High · Found: 2026-09-28
- Steps: Zoya Kirmani has approved PTO for 24–25 Sep, 29 Sep, 1–2 Oct and 5–6 Oct (Leave → Requests → All). Open Attendance → Calendar (Sep and Oct) as HR, or Me → Leave & attendance → Attendance as Zoya.
- Actual: Every one of those days reads "Zoya Kirmani: Thu 24 Sep · No record. Mark or correct this day." (Oct: "Thu 1 Oct · No record", "Mon 5 Oct · No record"). No day uses the "L · Leave" legend. Zoya's own calendar leaves 24/25 Sep blank, although her Home says "3 away". "On leave today" and the audit "Absences — Unplanned, without approved leave" depend on this link.
- Expected: Approved leave marks the day L on the muster and on My attendance, and those days don't count as missing or absent.
- Evidence:
scratch/LA/x/attcal-oct.png,scratch/LA/emp-zoya.kirmani/me-attendance.png
ISS-101 · A fully approved transfer stays "In approval": generating the transfer letter fails with "Missing required fields"
- Module: Lifecycle transfers / Templates · Severity: High · Found: 2026-09-28
- Steps: Transfer Rohan Verma (Demo), Information Technology → Backend Developer, effective 29 Sep. Releasing manager (Kabir), receiving head (Harsh) and HR (Aarav) all approve.
- Actual: Workflow
2f4a6f05-e4bb-4225-832d-5bc02d489b4dreaches "Mint the transfer letter" (templatetransfer-letter-inter-office). The step fails with "Missing required fields" on every retry. The transfer record staysrequested/ "In approval", with every approval ticked. The page doesn't say which fields are missing. - Update: after about 5 minutes of retries the "Letter failed to mint" branch ran and the transfer became
approved, with no letter produced. - Expected: The letter template's required merge fields come from the transfer and the employee, and generation succeeds on the first attempt.
ISS-104 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-transfer
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-100 · The HR approver group lists Aarav Krishnamurthy twice, so he gets duplicate approval tasks
- Module: Workflow / RBAC · Severity: Low · Found: 2026-09-28
- Actual: "HR review · any one of 5 — Aarav Krishnamurthy, Ops Maven, Vikram Raghavan, Kavya Raghunathan, Aarav Krishnamurthy, Harshit Bhalla" (six names, one repeated). For the Rohan Verma (Demo) transfer (instance
2f4a6f05…), Aarav's inbox shows two identical "Approval 7 · Lifecycle" items. - Expected: De-duplicate resolved approvers.
ISS-103 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-transfer
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-102 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-transfer
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-101 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-onboarding
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-100 · [auto] Server error 503 on GET /api/me/identities
- Module: lifecycle-onboarding
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-099 · Ticking an onboarding task right after uploading its document fails with "Changed elsewhere"
- Module: Lifecycle onboarding · Severity: Medium · Found: 2026-09-28
- Steps: Rohan Verma (Demo) onboarding panel → drop a document (it attaches to the Docs task) → tick "Identity & education documents".
- Actual: "Changed elsewhere — Someone updated this record first — it has been reloaded", and the task stays open. The upload bumped the task's rowVersion, but the panel kept the old one. The next tick then fails with "Couldn't update the task — Complete or waive the preceding onboarding stage first (ONBOARDING_STAGE_ORDER · 409)".
- Expected: Refresh the task after an upload, so the tick succeeds first time.
ISS-098 · The probation-review auto case shows "Manager —" and the rehearsal confirm needed no confirmation step
- Module: Lifecycle confirmation · Severity: Low · Found: 2026-09-28
- Actual: "Confirm" on the review panel applies immediately (the employee becomes permanent) with no confirm dialog or note, unlike Extend and Initiate separation, which confirm first.
ISS-097 · One resignation starts two approval workflows, and one of them can't find the manager
- Module: Lifecycle offboarding / Workflow · Severity: High · Found: 2026-09-28
- Steps: Start exit (Resignation) for Probe Joiner (Demo), a second exit after a withdrawn one.
- Actual: Two instances ran for exit
1a62fd53…:- "Exit authorisation" (
d1138515…), with Manager acceptance correctly assigned to Harsh Vardhan Mistry; - a "Resignation" flow (
e31d483b…), whose "Reporting manager accepts" step saysrelationship:manager_or_hr_partner (no subject; HR admin). It re-creates the task for each HR admin in turn (Aarav → Ops Maven → Vikram → …), so it never finishes.
- "Exit authorisation" (
- Expected: One authorisation workflow per exit, and the subject (the leaver) passed so the manager resolves.
ISS-096 · Waivability is read from the live template, contrary to the template's own text
- Module: Lifecycle offboarding · Severity: Low · Found: 2026-09-28
- Actual: The template says "an exit already in flight keeps the lanes it was created with". But an exit created while the Assets lane was waivable returned
409 CLEARANCE_NOT_WAIVABLEonce the template was switched back. Switching the template on again made the same waiver succeed.
ISS-095 · The exit card has no way to waive a lane or record the final settlement
- Module: Lifecycle offboarding · Severity: High · Found: 2026-09-28
- Actual:
- Lane menus only offer Mark cleared / Mark pending / Mark blocked. There's no "Waive" option, even on lanes the template marks "HR may waive with a reason" (KT by default). The API accepts
{status:'waived', waiverReason}. - "Mark settled" returns
409 SETTLEMENT_PENDING("Finance settlement must be completed first"). No screen lets anyone record that settlement. It only works viaPATCH /exits/{id} {settlement:'completed'}.
- Lane menus only offer Mark cleared / Mark pending / Mark blocked. There's no "Waive" option, even on lanes the template marks "HR may waive with a reason" (KT by default). The API accepts
- Expected: A Waive action (with a reason) on waivable lanes, and a settlement panel for Finance/HR.
ISS-094 · A transfer to a department without a head can't finish its approval chain
- Module: Lifecycle transfers · Severity: Medium · Found: 2026-09-28
- Actual: Moving someone to Delivery: "Receiving department head — Nobody yet · department has no head". The chain waits for no one, and only the HR override moves it on (afterwards the step shows "Skipped"). Only 3 of 11 departments have a head.
- Expected: Escalate an unresolved step (e.g. to HR), or block submission with a clear message.
ISS-093 · Lifecycle approval tasks in the Inbox are titled "Approval 5 · Lifecycle" with no details
- Module: Inbox / Lifecycle · Severity: High · Found: 2026-09-28
- Actual: Transfer and exit approvals show as "Approval", "Approval 2" or "Approval 5". The detail says only "Kavya Raghunathan · at approval 5", with no employee, transfer destination or last working day. Same root cause as ISS-078.
- Expected: Name the case (e.g. "Transfer · Probe Joiner (Demo) → Delivery", "Resignation · last day 30 Sep") and link to it.
ISS-092 · The exit card's "Routes through" text doesn't match the workflow that runs
- Module: Lifecycle offboarding · Severity: Low · Found: 2026-09-28
- Actual: The card says "Reporting manager accepts → Functional manager accepts → HR Head approves the last working day". The instance actually ran Manager acceptance → HR confirms the last working day (any HR partner) → Exit interview. The transfer card likewise lists every branch (Releasing HR review, Skip-level, Finance…) for a simple department move.
- Expected: Show only the steps that apply to this case.
ISS-091 · Lifecycle actions fail silently: rejected requests show no message
- Module: Lifecycle · Severity: Medium · Found: 2026-09-28
- Actual: No toast or inline error is shown for any of these:
- Start exit with a past last day:
409 INVALID_EXIT_DATE. The date picker also offers past dates. - Open review:
409 LIFECYCLE_CASE_EXISTS. - Clearance lanes:
409 KT_CLEARANCE_PENDING,500. - Mark cleared:
409 CLEARANCE_PENDING.
- Start exit with a past last day:
- Expected: Show the server's message.
ISS-090 · Clearing the Assets lane of an exit always fails with a 500, so no exit can finish
- Module: Lifecycle offboarding · Severity: Critical · Found: 2026-09-28
- Steps: Exit for "Probe Joiner (Demo)" in clearance → Assets lane ⋯ → Mark cleared. Tried with no asset ever issued, and again after issuing and returning LAP-0004 in Assets. Tried as HR Head and as super admin.
- Actual:
PATCH /people/lifecycle/exits/{id}/clearance/{assetsLaneId} {status:'cleared'}→ 500 INTERNAL_ERROR (requestIds ba4ce80c…, c0419da6…, 8ce69180…). The lane isn't waivable by default (409 CLEARANCE_NOT_WAIVABLE), and "Mark cleared" on the exit then fails with409 CLEARANCE_PENDING. The exit is stuck in clearance, and the UI shows no error. - Expected: The lane clears once nothing is outstanding on the asset register, which the card itself says: "Nothing on the register is outstanding."
- Evidence: exit
df383db9-acc5-4fe1-9962-3226fd7419c8, lane71fa1902-4ff9-4900-b0f8-6410a9338fd1.
ISS-089 · Onboarding document upload attaches to the last stage ("Induction"), not the current one
- Module: Lifecycle onboarding · Severity: Low · Found: 2026-09-28
- Actual: With only Offer complete, the panel says "Attaching to the current step: Induction · Day-1 induction session". The uploaded file is filed against Induction, not Docs.
- Expected: Attach to the earliest open document step.
ISS-088 · The probation-confirmation questionnaire is assigned to HR instead of the manager, and appears in no inbox
- Module: Lifecycle confirmation / Workflow · Severity: High · Found: 2026-09-28
- Steps: Schedule a periodic check-in on the review above (Kavya Raghunathan).
- Actual: The "Probation confirmation" workflow instance
c1dd6b94-6773-4aa0-8a70-b914e9765e5fwaits on "Confirmation review questionnaire" assigned to Kavya (the initiator), not the employee's primary manager (Harsh). The task doesn't appear in Kavya's Inbox or on her Home page. - Expected: The form goes to the primary manager and shows in their Inbox with the SLA.
ISS-087 · The confirmation review auto-opened at onboarding completion is incomplete and blocks a proper review
- Module: Lifecycle confirmation · Severity: High · Found: 2026-09-28
- Steps: Probationer "Probe Joiner (Demo)" (manager Harsh Vardhan Mistry) completes onboarding, and a review opens automatically → Lifecycle → Confirmation → open it.
- Actual:
- The review shows Manager "—", "No approval chain is attached to this review", and question set "Demo Question Set" with 0 questions.
- Its periodic check-ins can't be recorded: "“Demo Question Set” has no questions yet".
- Opening a proper review with the "Probation confirmation — standard" set fails with
409 LIFECYCLE_CASE_EXISTS. So the only way forward is the HR override (Confirm / Extend / Initiate separation). - The failed "Open review" gives the user no feedback.
- Expected:
- The auto-opened review carries the manager, the approval chain (manager → HR) and the company's standard question set.
- Otherwise "New review" should attach to the existing review instead of failing silently.
- Evidence: employee
2f2563e3-c478-438e-8f22-d1afd05fb003, reviews33724294…andc97baefa….
ISS-086 · Hiring managers and department heads get full Lifecycle admin controls
- Module: Lifecycle / RBAC · Severity: Medium (needs confirmation) · Found: 2026-09-28
- Actual: Harsh Vardhan Mistry (hiring manager) and Kabir Anand (IT department head) see Edit template and Start onboarding and the full module.
- Expected: Confirm whether this is intended. Managers usually see only their own reports' lifecycle items.
ISS-085 · Duplicate reference data: seven identical "Review questions" sets, and "Intern" listed twice as an employee class
- Module: Lifecycle confirmation / transfers · Severity: Low · Found: 2026-09-28
ISS-084 · Transfer "impact checks" are free-text tags; a transfer can't change manager or position
- Module: Lifecycle transfers · Severity: Medium · Found: 2026-09-28
- Actual: The Request transfer dialog promises "Impact checks run automatically", but the impact section is a set of editable tags ("Assets to reassign", "Open approvals re-route"…). No computed preview is shown (org chart, approvers, leave policy, payroll). There's no field for a new manager or position.
- Expected: Show the computed impact, and allow a manager or position change with the move.
ISS-083 · The "Laptop & access card issued" onboarding task isn't linked to the Assets module
- Module: Lifecycle onboarding / Assets · Severity: Low · Found: 2026-09-28
- Actual: The asset-issue task is a plain checkbox. Ticking it doesn't request, issue or check any asset on the register.
- Expected: An "Asset issue" task links to an asset assignment, or at least checks that the joiner holds an asset.
ISS-082 · Converting a candidate to an employee skips the "New joiner onboarding" workflow and leaves the record incomplete
- Module: Recruitment → Lifecycle · Severity: Medium · Found: 2026-09-28
- Steps: Convert "Rohan Verma (Demo)" from pre-onboarding (EMP-0207, 2026-09-28).
- Actual:
- No
employee.hiredworkflow instance ran, so there's no joining letter and no manager notification. - The position is "IT Helpdesk Engineer" while the offer says "IT Support Associate (Demo)".
- There's no department, manager or work email.
- The pre-onboarding documents don't appear on the profile's Documents tab.
- The Timeline reads "Joined the company in the company" and shows three phantom "Performance review" entries.
- No
- Expected: Conversion fires the same hire workflow as manual hiring. It carries over department, manager, title and the verified documents.
ISS-081 · Profile Actions → "Offboard…" is a dead end
- Module: Lifecycle / Employee profile · Severity: Low · Found: 2026-09-28
- Actual: It shows "Offboarding runs from Lifecycle." with no link and no dialog.
- Expected: Open the Start exit dialog prefilled with this employee, or link to Lifecycle → Offboarding.
ISS-080 · "Nudge owner" (New joinees) and "Mark verified" (onboarding documents) show a message but call no API
- Module: Lifecycle · Severity: Medium · Found: 2026-09-28
- Actual: Both buttons only show a toast. The page code has no server call behind them, so no reminder is sent and nothing is verified.
- Expected: Send the nudge through notifications, and record the verification on the checklist item.
ISS-079 · The /lifecycle route (the "Lifecycle" breadcrumb) renders a blank page
- Module: Lifecycle · Severity: Low · Found: 2026-09-28
- Steps: Click "Lifecycle" in the breadcrumb, or open /company/{id}/lifecycle.
- Actual: The main area is empty. The sidebar link goes to /lifecycle/onboarding instead.
- Expected: Redirect to /lifecycle/onboarding or show an overview.
ISS-078 · The inbox approval panel labels an offer approval as "Leave request" and shows no offer details
- Module: T4 Offer Management / Inbox · Severity: High · Found: 2026-09-28
- Steps: HR Head submits an offer for approval (OFR-2026-0052) → sign in as her manager (Vikram Raghavan) → Inbox → open the "Approval · Hiring" item.
- Actual: The side panel says "Approval — Leave request". It shows only Requester, "Request: Approval", "Details: Kavya Raghunathan · at approval" and two due dates (one as a raw ISO timestamp). There's no candidate, role, CTC, joining date or link to the offer, so the approver can't review what they are approving, and it looks like a leave request.
- Expected: Show the offer summary (candidate, role, CTC if permitted, joining date, offer code) with a link to the candidate profile, and label it "Offer approval". Show the due date once, formatted.
- Evidence: Vikram's inbox, 2026-09-28 10:29 IST. Seen in the R3 walkthrough at about 1:30.
ISS-080 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-offer
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-079 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-hiring
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-077 · "Convert to employee" sometimes doesn't open when clicked right after the last checklist item is ticked
- Module: T4 Pre-onboarding · Severity: Low · Found: 2026-09-28
- Steps: Pre-onboarding panel → tick "Mark Bank account details form as done", which makes the checklist complete → click "Convert to employee" in the panel footer straight away.
- Actual: No dialog opened (the button re-renders while the checklist refreshes), so a second click was needed.
- Expected: Keep the button disabled until the refresh settles, or keep it stable so the first click registers.
ISS-076 · Cancelling a candidate's pre-onboarding silently rejects their application
- Module: T4 Pre-onboarding · Severity: Medium · Found: 2026-09-28
- Steps: A candidate with an accepted offer and a pre-onboarding checklist → cancel the checklist (
POST /pre-onboarding/{id}/cancel {reason, notifyCandidate:false}). - Actual: The offer is cancelled too, and the application becomes
rejected, a terminal state. Moving it back returns409 APPLICATION_TERMINAL(allowed: []). The cancel toast only says "Pre-onboarding cancelled", and the candidate now faces a 180-day reapply cooldown. - Expected: The cancel dialog should say that it also cancels the offer and rejects the application. Better, let HR choose between returning the candidate to the offer stage and rejecting them.
- Evidence: application
14561f53-7f30-42ae-aa9e-ab13c49f3ac8, offer OFR-2026-0051, checklist02f95a34-e2b4-4140-8c07-106f93c5e970.
ISS-078 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-offer
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-077 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-hiring
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-076 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-hiring
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-075 · Posts and requisitions can't be closed from their obvious REST routes; only /transition works
- Module: T3 Recruitment · Severity: Low · Found: 2026-09-28
- Actual:
POST /posts/{id}/closereturns 404. The client usesPOST /posts/{id}/transition {to:'closed', rowVersion}andPOST /requisitions/{id}/transition {to:'cancelled', reason, rowVersion}.GET /interviews/{id}does not exist, so an interview's rowVersion is only available fromGET /interviews?applicationId=. - Expected: Document the transition routes, and give interviews a GET-by-id like the other recruitment records.
ISS-074 · Withdrawing an application leaves its interviews scheduled, so the panel stays blocked
- Module: T3 Recruitment pipeline · Severity: Medium · Found: 2026-09-28
- Steps: Schedule and book an interview for a candidate (chair: Harsh Vardhan Mistry) → withdraw the application (
POST /applications/{id}/withdraw) → schedule another candidate with the same chair in an overlapping slot. - Actual: The withdrawn application's interview stays
scheduled. The new booking fails with "Panelist conflicts — Already interviewing (Hiring manager round)" (PANELIST_CONFLICTS, 409). The panel keeps the calendar hold for a candidate who has left. - Expected: Withdrawing or rejecting an application cancels its open interviews and notifies the panel, or at least says in the withdraw dialog that interviews are still booked.
- Evidence: interview
112df6e8-14fa-4d2f-8ae3-49bc0ceb8af7on withdrawn applicationdaa1f934-2967-4526-b3dc-f0e3d541e0b1. It was cancelled by hand viaPOST /interviews/{id}/status {status:'cancelled'}.
ISS-073 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-hiring
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-072 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-hiring
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-071 · [auto] Server error 503 on GET /api/me/identities
- Module: recruitment-hiring
- Found: 2026-09-28
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-070 · Offers raised by the Company Super Admin get stuck: the approval goes to an unresolved "primary manager"
- Module: T4 Offer Management / F6 Workflow · Severity: High · Found: 2026-09-28
- Steps: As Company Super Admin (no linked employee record) → candidate → New offer → Draft offer → Submit for approval.
- Actual: The Offer Approval workflow opens one task with
assignedVia: "relationship:primary_manager (unresolved)",assignedUserId: null,assignedRoleId: null. Nobody sees it in their inbox (checked the CEO, the IT department head and the CTO). The offer shows "pending approval" indefinitely, until escalation at the 7-day SLA, if that resolves at all. - Expected: When the relationship can't be resolved, fall back to a role (e.g. HR Head) or block submission with a clear message. The workflow list should flag instances whose tasks have no assignee.
- Evidence: workflow instance
28bf2363-acd8-4960-bf0f-6da01197a778(offer OFR-2026-0049).
ISS-069 · "Propose to candidate" leaves the scheduling dialog open with no confirmation
- Module: T3 Pipeline & Interviews · Severity: Low · Found: 2026-09-28
- Steps: Candidate profile → Schedule → round name, chair, two slots → Propose to candidate.
- Actual:
POST /talent/recruitment/interviewssucceeds (the profile later shows the round with "Book …" buttons), but the dialog stays open with the form filled in and no toast. It's easy to click again and create a duplicate proposal. - Expected: Close the dialog and confirm "Slots sent to the candidate".
ISS-068 · Override approval is offered to the requester, then refused by segregation of duties
- Module: T1 Requisitions / F6 Workflow · Severity: Low · Found: 2026-09-28
- Steps: As Company Super Admin, raise a requisition → after the department head approves, open it → Approve → "Approve on the approvers' behalf" → give a reason → Approve.
- Actual: The panel invites the admin to decide "for them — the override is audited", but the request fails with
403 "You raised this request — segregation of duties requires a different approver to decide it." - Expected: Don't offer the override to the requester (or explain up front that the requester can't approve their own request).
ISS-067 · Requisition checklist picker lists "Pre-onboarding Default" and "Pre-onboarding default"
- Module: T1 Requisitions · Severity: Low · Found: 2026-09-28
- Steps: Raise requisition → Pre-onboarding checklist.
- Actual: Options: Company default, Pre-onboarding Default, Employee onboarding, Pre-onboarding default, + New checklist… Two near-identical names, and nothing to tell them apart.
- Expected: Unique names (or the template's version/owner shown).
ISS-066 · Department heads get a policy-acknowledgement modal they're not allowed to acknowledge, and the policy text has unfilled merge fields
- Module: O8 Policies / F2 RBAC · Severity: High · Found: 2026-09-28
- Steps: Sign in as Kabir Anand (Department Head role) → any page.
- Actual: A full-screen modal opens with "Attendance & Punctuality Policy · due 9 Oct 2026" and "You can read this now, but acknowledging needs the Acknowledgements grant. Ask your HR administrator to enable it". The only buttons are "I'll ask my administrator" and Close, and it comes back on each sign-in. The policy body shows raw placeholders: "Company Name", "I, Employee Name (Employee No. Employee Number, Department)…" (same root cause as ISS-036).
- Expected: Every employee who is sent a policy can acknowledge it: either the built-in role includes the grant, or distribution skips people who can't. Merge fields resolve to the reader's details.
ISS-065 · Public careers site is unreachable (Cloudflare 522)
- Module: T2 Sourcing / Careers site · Severity: High · Found: 2026-09-28
- Steps: Open the public address shown in Settings → Recruitment → Careers site:
https://ops-maven.satellitehr.com/careers. - Actual: Cloudflare "Error 522 · Connection timed out". The host is reachable through Cloudflare but the origin never answers. Candidates can't see jobs or apply, although the "IT Helpdesk Engineer" posting is marked Live.
- Expected: The careers page loads, lists live postings and accepts applications.
ISS-064 · Requisition approval summary lists an approver twice
- Module: T1 Requisitions · Severity: Low · Found: 2026-09-28
- Steps: Recruitment → Jobs → REQ-2026-0081 → Approval progress.
- Actual: "HR approval · any one of 3 — Aarav Krishnamurthy · not needed, Vikram Raghavan · not needed, Kavya Raghunathan · approved, Aarav Krishnamurthy · not needed". Four names for "any one of 3", with Aarav twice.
- Expected: Each eligible approver listed once, and the count matching.
ISS-063 · Workflow approver picker offers archived roles and a duplicate "Department head"
- Module: F6 Workflow · Severity: Low · Found: 2026-09-27
- Steps: Workflow designer → Approval task → Approver 1 type "By role" → role.
- Actual: The list includes "Demo – Leave Checker", a role that was deleted (archived) under Settings → Roles and is hidden there. It shows both "Department head" (relationship) and "Department Head" (company role) with no hint of the difference.
- Expected: Archived roles aren't offered, and relationship-based approvers are grouped/labelled separately from company roles.
ISS-063 · [auto] Server error 500 on GET /api/company/documents/drive/grantee-options
- Module: documents
- Found: 2026-09-27
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/documents
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/company/documents/drive/grantee-options
ISS-062 · Starring a folder fails: "Validation error — Unrecognized key: starred"
- Module: F12 Documents · Severity: Medium · Found: 2026-09-27
- Steps: Documents → ⋯ on a folder → Star.
- Actual: Toast "Validation error · Unrecognized key: "starred"". The folder isn't starred. It's the same pattern as ISS-019: the UI sends a field the API schema rejects, while the API has a separate
POST /documents/drive/starsendpoint. - Expected: Star uses the stars endpoint, and the item appears under Starred.
ISS-062 · [auto] Server error 500 on GET /api/company/documents/drive/grantee-options
- Module: documents
- Found: 2026-09-27
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc/documents
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/company/documents/drive/grantee-options
ISS-061 · Document drive writes succeed but answer HTTP 500 (follow-up to ISS-060)
- Module: F12 Documents · Severity: High · Found: 2026-09-27
- Detail: Further testing shows the drive saves the change and then fails the response. An upload that returned 500 still created "Demo - Onboarding checklist.txt" in Company Library.
POST …/drive/documents/{id}/trashand…/purgeboth returned 500 INTERNAL_ERROR (requestIded1294a2-…), yet the file was then gone from the library and the trash. Because the UI treats the 500 as a failure, users see nothing happen, retry, and create duplicates (or think a delete failed). - Expected: Return success once the write has committed, and fix whatever post-commit step throws (thumbnailing, audit, usage recalculation).
ISS-060 · Document upload fails with HTTP 500, and the UI shows nothing
- Module: F12 Documents · Severity: High · Found: 2026-09-27
- Steps: Documents → Company Library (root, or any folder) → Upload → pick a small PNG (8 KB), TXT (60 B) or PDF (641 B).
- Actual:
POST /api/company/documents/drive/documents?workspaceId=…&fileName=…[&folderId=…]→ 500 with an empty body (e.g. x-request-id8e3de6bb-7ab6-4063-b8f8-6c2ad66e68ab). No toast, no error, no file. It's 100% reproducible for every type tried, all within the allowed formats and the 2 MB limit. - Expected: The file uploads and appears in the folder with its metadata. If it fails, the user sees why.
ISS-059 · Clicking "Download" on a finished export shows raw JSON "Unauthenticated" instead of the file
- Module: F10 Import/Export (Reports) · Severity: High · Found: 2026-09-27
- Steps: Reports → Export CSV → wait for "Download (1)" → click it.
- Actual: The tab navigates away from the app to the export file URL, which renders
{"code":"UNAUTHENTICATED","message":"Unauthenticated","requestId":"…"}on a blank page. No file is downloaded, and the user has to use Back to return. The session cookie lives on the API domain, and the link seems to be a plain navigation without the token/credentials the API expects. - Expected: The CSV downloads (e.g. a signed short-lived URL, or fetch-with-credentials then save), and the user stays in the app.
- Evidence:
scratch/F/export-download-unauth.jpg(frames from the walkthrough recording)
ISS-058 · Report CSV export fails intermittently with a database error, and the UI says nothing
- Module: F10 Import/Export (Reports) · Severity: Medium · Found: 2026-09-27
- Steps: Reports → Export → Current report → Export CSV.
- Actual:
POST /api/company/search/employee/export→ 202 queued; pollingGET /api/company/search/exports/{id}staysqueuedfor ~45s, thenstatus: "failed"witherror: "Failed query: select \"role_id\" …"(raw SQL again, as in ISS-049). The button changes from "Preparing…" back to "Export CSV" with no error or toast. Other attempts minutes apart succeeded in 10–30s ("Download (1)"). - Expected: Exports succeed reliably. On failure the user sees a clear message and a retry, and SQL stays out of API error payloads.
ISS-057 · Custom field types missing: decimal, date-time, lookup/reference, file/attachment
- Module: F9 Custom Fields · Severity: Medium (BRD marks it done) · Found: 2026-09-27
- Actual: Types offered: Text, Long text, Number, Currency, Percent, Date, Select, Multi-select, Checkbox, Email, Phone, URL.
- Expected (BRD F9): Also decimal (if Number is integer-only), date-time, lookup/reference and file/attachment. Input masks are also listed in the BRD; only a regex "Format check" exists.
ISS-056 · Custom fields can only be created for the Company, not employees, locations, departments, groups or positions
- Module: F9 Custom Fields · Severity: High (BRD marks it done) · Found: 2026-09-27
- Steps: Settings → Custom fields → New group / Add field.
- Actual: The page only manages "Company fields", and the New group dialog has no entity choice. The API does accept
GET /api/company/custom-fields?entityType=employee|location|department|group|position(all empty), and the Groups create dialog even asks forentityType=groupfields, but no screen lets an admin define them. - Expected (BRD F9): Custom fields definable on Companies, Locations, Departments, Groups, Positions and Employees.
ISS-055 · Approval detail panel: wrong request type, and a raw timestamp
- Module: F7 Notifications / Inbox · Severity: Low · Found: 2026-09-27
- Steps: Inbox → click an item tagged "Travel & expense".
- Actual: The panel subtitle says "Leave request". "Request" and "Details" just repeat "Approval" / the requester's name. "Due" appears twice, "5 Oct, 12:00 pm" and a raw
2026-10-05T06:30:39.832Z. - Expected: The real request type and details (claim, amount, dates), and one formatted due date.
ISS-054 · Inbox "announcement review" item opens Home instead of the review
- Module: F7 Notifications / Inbox · Severity: Medium · Found: 2026-09-27
- Steps: Inbox → Open → click "Diwali Holiday – Office Closure · Announcement".
- Actual: The app navigates to the company Home page. No review panel, and no Approve/Reject for the announcement.
- Expected: Opens the announcement review with approve / request changes / reject.
ISS-053 · Inbox approval items are titled just "Approval"
- Module: F7 Notifications / Inbox · Severity: Low · Found: 2026-09-27
- Actual: The two travel & expense items read "Approval · Travel & expense — Approval · Zoya Kirmani", with no amount, trip or claim title. The approver can't tell the two apart without opening each.
- Expected: A descriptive title (e.g. "Expense claim ₹4,200 — Client visit, Pune") like the announcement item has.
ISS-052 · Approval counts disagree: sidebar/Home say 15, Inbox shows 3 open
- Module: F7 Notifications / Inbox · Severity: Medium · Found: 2026-09-27
- Actual: The sidebar Inbox badge shows 15 and the Home greeting says "15 approvals are waiting for you", but the Approvals inbox shows "Awaiting your decision 3" and the Open tab "3" (Overdue 0, Decided 7). Home's "Pending approvals" widget lists four items for Kavya Raghunathan that don't appear in the Inbox.
- Expected: One source of truth for pending approvals, so the badge, Home and Inbox agree, and anything counted is reachable from the Inbox.
ISS-051 · Notification settings list "Approval reminder" and "Approval requested" twice
- Module: F7 Notifications · Severity: Low · Found: 2026-09-27
- Steps: Settings → Notifications → Channels.
- Actual: Two "Approval reminder" rows ("A task is still waiting on you, or its deadline is close." / "A pending approval is nearing its SLA.") and two "Approval requested" rows ("A request is waiting for your approval." / "A task is waiting for your decision."), each with its own In-app/Email/Slack switches. The user can't tell which one governs which messages.
- Expected: One row per topic, or clearly different names if they really are separate events.
ISS-050 · "New approval chain" leaves a half-created, active workflow with no audience, and the dialog never closes
- Module: F6 Workflow · Severity: High · Found: 2026-09-27
- Steps: Settings → Workflows → New approval chain → name, Process "When leave submitted", level 1 Manager of requester, audience Quick filters → Location = one location → Create chain.
- Actual: The UI runs
POST /api/company/workflows(201, definition created, status active),PUT …/version/{id}(steps saved) andPOST …/validate→{ok:true}, then stops. There's no publish call and no applicability/audience call, and the dialog stays open with the button idle and no error. The list gains a workflow "Starts on leave request submitted · no live version · never ran" withapplicabilityRuleId: null(i.e. everyone). Clicking Create again creates another one. There's no Delete on these rows (only on some designs), and the API has no delete: onlyPATCH {status: active|paused}. - Risk: An active, audience-less definition on
leave.submittedcompetes with the company's real leave approval as soon as a version gets published. - Cleanup done: the three accidental "Demo – Karimnagar leave approvals" workflows (codes …f6c53c, …6fbbd1, …975cc7) are set to paused. They should be deleted once there's a way to.
- Expected: Create chain completes (publish + audience) or rolls back, shows errors, and closes. Workflow definitions that never went live can be deleted.
ISS-049 · Workflow Operations shows raw SQL errors, and 25 events are dead-lettered (incl. expense claims)
- Module: F6 Workflow · Severity: High · Found: 2026-09-27
- Steps: Settings → Workflows → Operations → "Needs attention".
- Actual: 25 events are parked ("retries exhausted — needs a human"). Their "Last error" column prints full database queries to the admin, e.g.
Failed query: select distinct on (ai."provider_subject") … from "core"."user_scope_role_assignment" a join "rbac_role" …, which exposes schema/table names. Affected events includeexpense_claim.submitted, so those submissions never started their approval workflow. The header also shows "Approvals pending 392 · 37 past due" and "Delivered (24h) 0". - Expected: Show a friendly error (keep technical detail in server logs). Fix the failing approver-resolution query for expense claims, and redrive the parked events.
ISS-048 · Audit entries for company roles are typed "Platform" and name the role by its internal id
- Module: F5 Audit · Severity: Low · Found: 2026-09-27
- Actual: Creating or deleting a company role logs "Created role" (no name) and "Deleted demo leave reviewer 82628593" (the slug plus company id), with Type Platform, although it's a company-tier role. Deleting a delegation is severity Critical, while creating one is Info.
- Expected: Type Company, the role's display name in the activity text, and consistent severities.
ISS-047 · Organization changes are not written to the audit log
- Module: F5 Audit · Severity: High · Found: 2026-09-27
- Steps: Create/edit/deactivate locations, departments, positions, groups, holiday calendars, policies, announcements or agreements (done many times while recording the O1–O10 walkthroughs) → Settings → Audit log → search "Warangal", "Fire", "department", or the demo record names.
- Actual: "No matching entries". The log only holds access events (sign-ins, "Viewed company"), roles and permissions, delegations, employees and assets. None of the create/update/delete/status changes on org structures, calendars, policies, announcements or agreements are audited.
- Expected (BRD F5): Company and org entities audited for all create/update/delete/status changes, with field, before, after, actor and time.
ISS-046 · Company profile can't be reached from the app, and "New company" does nothing
- Module: F4 Company Management · Severity: Medium · Found: 2026-09-27
- Actual: The company profile page (
/company/{id}/profile: legal details, registrations, modules, additional fields) exists, but nothing links to it. Not the sidebar, the "Company" breadcrumb (which goes to Home), the account menu, Settings, or the ⌘K search ("company" finds no profile). Separately, both the ⌘K search and the header "+ New" menu offer "New company", which does nothing when chosen by the Company Super Admin (the page stays on Home, with no dialog and no message). - Expected: A visible entry point to the company profile (e.g. Settings → Company, or the company name in the sidebar header). "New company" hidden for roles that can't create companies, or explaining why not.
ISS-045 · Impersonation ("log in as user") isn't in the product
- Module: F2 RBAC · Severity: Medium (BRD marks it done) · Found: 2026-09-27
- Checked: Settings → Users (row detail: roles, employee link, Suspend), Settings → Roles, Security, the account menu, and the app bundle (no "impersonat…", "Log in as" or "View as" strings).
- Expected (BRD F2): An audited, view-only "login as user" for authorised support roles, with a flow to create the impersonation authorisation.
ISS-046 · [auto] Server error 503 on GET /api/me/identities
- Module: identity
- Found: 2026-09-27
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-045 · [auto] Server error 503 on GET /api/me/identities
- Module: identity
- Found: 2026-09-27
- Page: https://qa.satellitehr.com/company/82628593-49b6-4dad-ad2a-6b9472ab44fc
- Request: GET https://satellite-hr-backend-final-restructure.polished-mud-fefe.workers.dev/api/me/identities
ISS-044 · Company profile shows 0 employees and "0 of 0" modules
- Module: F4 Company Management · Severity: Medium · Found: 2026-09-27
- Steps: Open the company profile (
/company/{id}/profile). - Actual: The header cards read "Employees 0 on the roster" (the company has 24 employees, as the Home dashboard shows) and "Modules enabled 0 of 0 in the catalog", although Leave, Attendance, Recruitment and others are in use.
- Expected: Real employee and module counts, and the Modules section listing what's switched on.
ISS-043 · Roles show more permissions than exist ("158 of 137 permissions")
- Module: F2 RBAC · Severity: Low · Found: 2026-09-27
- Steps: Settings → Roles.
- Actual: Company Super Admin "158 of 137 permissions", Executive "147 of 137", HR Head "153 of 137". The granted count is higher than the catalogue total, so either the total or the count is wrong (e.g. counting per-scope grants or retired permissions).
- Expected: The count never exceeds the total, and both come from the same permission catalogue.
ISS-042 · Agreements status filter has no "Draft" option
- Module: O10 Agreements · Severity: Low · Found: 2026-09-27
- Actual: The Status filter offers All statuses / Active / Expiring soon / Expired / Terminated. Draft agreements (shown with a "Draft" status in the table) can't be filtered.
- Expected: A "Draft" option (and "Pending acknowledgement" if it's a separate state).
ISS-041 · Single-key shortcuts fire while a dropdown is open
- Module: Global (seen on Agreements) · Severity: Low · Found: 2026-09-27
- Steps: Agreements → open "All kinds" → type "Bond" to jump to that option (standard select type-ahead).
- Actual: The keys go to the global shortcuts instead: "n" opens the Notifications panel on top of the open dropdown, and the option isn't selected.
- Expected: Global shortcuts are suppressed while a menu, select or text field has focus, and type-ahead works in selects.
ISS-040 · Bond tracking uses the agreement's validity, not the bond period entered
- Module: O10 Agreements · Severity: Medium (exit clearance reads this number) · Found: 2026-09-27
- Steps: Bond/Service agreement with Bond period 12 months, valid until 31 Mar 2027 → renew +12 mo.
- Actual: API
bondTerms.months = 12butbondMonthsTotal = 18, and Bond tracking shows "0 of 18 months · 18 months remaining". Before the renewal it showed the validity span too, not 12. - Expected: The bond total is the bond period (12 months) from the start date, independent of the agreement's validity or renewals.
ISS-039 · "Renew +12 mo" on a draft agreement makes it Active without publishing
- Module: O10 Agreements · Severity: High · Found: 2026-09-27
- Steps: New agreement (Bond/Service, Asha Rao, Publish immediately off) → Create draft (row shows Draft; Active agreements 0) → ⋯ → Renew +12 mo.
- Actual: The agreement switches to Active ("Active agreements 1", "Service bonds active 1"). Acknowledgement stays "Not requested", so it was never sent to or acknowledged by the employee.
validToalso moves 12 months on from the draft's date. - Expected: Renew isn't offered on drafts, or it only changes the dates and leaves the status as Draft until published.
- Evidence:
output/debug/agreements/024.png(Draft before) vsoutput/agreements-failure.png(Active after)
ISS-038 · A draft agreement can't be deleted from the UI
- Module: O10 Agreements · Severity: Low · Found: 2026-09-27
- Actual: The draft's ⋯ menu offers View / Publish / Edit / Renew +12 mo / Terminate. There's no Delete, although
DELETE /api/company/agreements/{id}works on drafts (204). A draft created for the wrong person can only be "terminated", which leaves a record on that employee. - Expected: Delete for drafts that were never published.
- Also: The ⋯ button's accessible name uses the kind ("Actions for Non-Disclosure Agreement (NDA)"), not the title or employee, so rows can't be told apart by screen readers when an employee has several NDAs.
ISS-037 · Draft agreements show "Signed on" with today's date
- Module: O10 Agreements · Severity: Low · Found: 2026-09-27
- Actual: The View panel of a never-published draft shows "SIGNED ON 27 Sep 2026" next to "STATUS Draft · ACKNOWLEDGEMENT Not requested".
- Expected: "Created on" for drafts, and "Signed on" only once acknowledged/signed.
ISS-036 · Agreement merge fields show their labels instead of the employee's and company's details
- Module: O10 Agreements · Severity: High (this is the text the employee acknowledges) · Found: 2026-09-27
- Steps: Policies & agreements → Agreements → New agreement → employee Asha Rao, kind NDA, template "Non-Disclosure Agreement" → Create draft → ⋯ → View.
- Actual: The document reads "This Non-Disclosure Agreement is made between Company legal name (the "Company") and Employee (the "Recipient")." The fields aren't filled with "OpsMaven Services Pvt. Ltd." and "Asha Rao".
- Expected: Merge fields are resolved per employee copy when the agreement is generated (BRD O10: agreements generated via the Template Engine).
ISS-035 · "Pin to top of feed" is silently dropped on scheduled announcements
- Module: O9 Announcements · Severity: Medium · Found: 2026-09-27
- Steps: New announcement → turn on "Pin to top of feed" (switch shows checked) → pick a Schedule date → Schedule. Or pick the date first, then turn Pin on.
- Actual: Picking a schedule date flips the switch back off. Even with Pin turned on after the date, the request goes out with
"pinned": false, and the scheduled post is saved unpinned. No message says scheduled posts can't be pinned. - Expected: The pin choice is kept and applied when the post goes live, or the switch is disabled with an explanation while a schedule is set.
ISS-034 · Announcement templates load raw {{ placeholders }} and the picker resets
- Module: O9 Announcements · Severity: Medium · Found: 2026-09-27
- Steps: Announcements → New announcement → Start from a template → "Company news".
- Actual: The title becomes
{{ headline }}and the message{{ opening_paragraph }} / {{ detail_paragraph }} / Thank you for everything you do.There's no prompt to fill the variables, the toast reads "Loaded from template — {{ headline }}", and the preview shows the raw tokens too. The template picker then snaps back to "Blank announcement". Nothing stops the author from publishing with the tokens still in. - Expected: Prompt for the template's variables (or show them as highlighted fields), block publishing while tokens remain, and keep the chosen template shown in the picker.
- Evidence:
output/debug/announcements/005.png
ISS-033 · Policy audience preview ignores quick filters
- Module: O8 Policy Library · Severity: Low · Found: 2026-09-27
- Steps: New policy → Applies to → Quick filters → Add audience filter (Department is …).
- Actual: "Who this reaches" keeps showing all 24 people, with the note "Quick filters are applied when this publishes — the people below are everyone before those filters". The admin can't see who the policy will actually reach before publishing.
- Expected: The preview reflects the filters, as the group condition builder already does.
ISS-032 · Policy "Source template" lists letters and agreements, not just policy templates
- Module: O8 Policy Library · Severity: Medium · Found: 2026-09-27
- Steps: Policies → New policy → Source template.
- Actual: The list includes Recruitment · Offer Letter, Appointment Letter, Regret Letter (and its copy), Lifecycle · Joining/Relieving/Transfer letters, Employment Agreement and Non-Disclosure Agreement, next to the real policies. The help text right below says "Only 'Policies & Communications' templates can be used."
- Expected: Only Policies & Communications templates are offered.
ISS-031 · Policy distribution offers only Manual and Scheduled
- Module: O8 Policy Library · Severity: Medium (BRD marks this done) · Found: 2026-09-27
- Actual: The Distribution picker lists "Manual — HR sends it" and "Scheduled — on a set date" only.
- Expected (BRD O8): Also automatic (event-triggered), e.g. on joining or transfer, and bulk distribution.
ISS-030 · A retired policy's name can never be reused (code conflict with no way around it)
- Module: O8 Policy Library · Severity: Medium · Found: 2026-09-27
- Steps: Create a policy "X" (the code is generated from the name, and the form has no Code field) → Archive/retire it → create a new policy named "X".
- Actual:
409 POLICY_CODE_CONFLICT — "Policy code is already in use". The retired policy keeps the code,PATCHrejectscode("Unrecognized key"), and the create form offers no Code field. The only workaround is a different name. - Expected: Either a Code field on the form (as Locations/Positions have), a unique code auto-generated with a suffix, or retired policies releasing their code.
ISS-029 · Two holiday calendars can be created for the same location and year
- Module: O7 Calendar & Holidays · Severity: Medium · Found: 2026-09-27
- Steps: Attendance → Holidays → New calendar → Year 2026, Applies to a location, Name "X" → Create. Repeat with the same year and location.
- Actual: Both succeed (
POST /api/company/organization/calendars→ 201 twice). The Calendar picker then lists "Location · X" twice, and it's unclear which one drives leave and attendance for people at that location. - Expected: The second create is refused ("A calendar for this location and year already exists"), as the dialog text promises ("One calendar per year and scope").
ISS-028 · Holiday calendar "Applies to" offers inactive locations
- Module: O7 Calendar & Holidays · Severity: Low · Found: 2026-09-27
- Steps: Attendance → Holidays → New calendar → Applies to.
- Actual: The options include "Hyderabad Office", which is inactive under Organization → Locations, next to the active locations.
- Expected: Only active locations, or inactive ones marked as such.
ISS-027 · Chart options menu stays open after choosing "Full screen"
- Module: O6 Org Chart · Severity: Low · Found: 2026-09-27
- Steps: Employees → Chart → Options → Chart → Full screen.
- Actual: The chart goes full screen, but the options popover stays open on top of it, and it now reads "Exit full screen".
- Expected: The menu closes once an action is picked, as it does for Fit to view.
ISS-026 · Org chart: functional view, PDF export and dotted-line managers not found
- Module: O6 Org Chart & Hierarchy · Severity: Medium (BRD marks these done) · Found: 2026-09-27
- Checked: Organization → Employees → Chart. It's a reporting tree from each person's manager, with expand/collapse, zoom, Fit to view, Full screen, Save as PNG and Saved views. The department-based tree is under Departments → Chart.
- Missing vs BRD O6: (1) no functional view; (2) export is PNG only, no PDF; (3) no dotted-line (secondary manager) links or toggle in the chart; (4) no contact-field privacy setting found near the chart.
- Expected: Confirm whether these are built elsewhere; otherwise update the BRD checkboxes.
ISS-025 · Replacing a group's members with an empty list leaves rule-matched members in place
- Module: O5 Groups · Severity: Low · Found: 2026-09-27
- Steps: Group with condition membership (Department is any of Delivery) → switch it to "Added by hand" via PATCH (
membershipMode:"manual", ruleExpression:null) →POST /groups/{id}/members/bulk {employeeIds:[], mode:"replace"}→ retire. - Actual: The replace returns OK, but the two rule-matched members (
origin:"rule") stay. After retiring, they can't be removed (409 GROUPS_INACTIVE). Switching a group from condition to hand-picked also keeps the old rule matches without saying so. - Expected:
replacesets the exact member list regardless of origin. Switching to hand-picked either clears rule members or asks whether to keep them. - Note: Two retired demo groups ("Archived 6e88/727e – Fire Wardens") still list Harshit Bhalla and Tarun Abraham because of this. They're retired, so they're not offered as audiences.
ISS-024 · Follow-up to ISS-019: the backend can retire groups, but the UI calls the wrong endpoint
- Module: O5 Groups · Severity: High (same bug as ISS-019, root cause narrowed down) · Found: 2026-09-27
- Detail:
DELETE /api/company/organization/groups/{id}withIf-Matchreturns 200 and retires the group (it drops out of the active list;GETstill returns it). The Retire dialog sendsPATCH {status:"inactive"}instead, which the PATCH schema rejects. Fix: point the Retire action atDELETE(as Positions already does for Deactivate), or acceptstatusin PATCH.
ISS-023 · Groups: the same idea has three names each for "condition" and "by hand"
- Module: O5 Groups · Severity: Low · Found: 2026-09-27
- Actual: Rule-based membership is called "By condition" (create/edit tabs), "Condition" (Members from column) and "By rule" (membership filter). Hand-picked membership is "Added by hand" (tab), "By hand" (column) and "Picked by hand" (filter).
- Expected: One term for each, used everywhere.
ISS-022 · Group condition picker offers inactive departments
- Module: O5 Groups · Severity: Low · Found: 2026-09-27
- Steps: Groups → New/Edit group → By condition → Add condition → Department · is any of → open "Department values".
- Actual: The list includes inactive departments and teams (e.g. deactivated "Demo – Probe Dept"), mixed in with active ones and not marked as inactive.
- Expected: Only active departments are offered, or inactive ones are marked and listed separately, as the other department pickers do.
ISS-021 · Accessibility: "Pin __actions to the left" label on the Groups table
- Module: O5 Groups (likely the shared data table) · Severity: Low · Found: 2026-09-27
- Actual: The actions column's pin button has
aria-label="Pin __actions to the left", which exposes the internal column id to screen readers. - Expected: The actions column is not pinnable, or has a readable label ("Pin Actions to the left").
ISS-020 · Group "Manage people" dialog shows the Locations help text
- Module: O5 Groups · Severity: Low · Found: 2026-09-27
- Steps: Groups → ⋯ on a hand-picked group → Manage people…
- Actual: The subtitle reads "Somebody can work out of more than one location, so placing them here does not take them away from anywhere else — or change the jurisdiction they belong to." That's the Locations copy.
- Expected: Group-specific text, e.g. "People can be in many groups. Adding them here doesn't remove them from any other group."
ISS-019 · Retiring a group always fails ("Unrecognized key: status")
- Module: O5 Groups · Severity: High · Found: 2026-09-27
- Steps: Organization → Groups → ⋯ on any group → Retire → "Retire it".
- Actual: The frontend sends
PATCH /api/company/organization/groups/{id}with{"status":"inactive"}. The backend rejects it with400 VALIDATION_ERROR — Unrecognized key: "status", and the dialog shows "Could not change it — Unrecognized key: "status"". The API has no other retire/delete endpoint, so no group can be retired or removed. - Expected: Retire works: either the PATCH schema accepts
status, or the UI calls a dedicated retire endpoint. - Evidence:
scratch/G7-retire-fail.png
ISS-018 · Notifications: "Your 0-day leave request was approved"
- Module: Leave / Notifications (outside Organization; seen in the admin's notification feed) · Severity: Low · Found: 2026-09-27
- Actual: The admin feed has many notifications reading "Your 0-day leave request was approved." (e.g. 2026-09-26 16:36:56Z, 16:36:33Z, 16:35:18Z). Either a zero-day request was allowed through, or the day count in the message template is wrong. Not investigated further, since it's outside the walkthrough scope.
ISS-017 · Copy: "1 of 12 position" when a position branch is focused
- Module: O4 Positions · Severity: Low · Found: 2026-09-27
- Actual: "Show only this branch" on a position shows the count "1 of 12 position". Same pluralisation bug as ISS-009 on Departments, so it's probably a shared component.
ISS-016 · Positions: filled count above sanctioned headcount isn't flagged
- Module: O4 Positions · Severity: Low (confirm intent) · Found: 2026-09-27
- Actual: Several positions show Filled
4 / 1,5 / 1,3 / 1(Admin Executive, IT Helpdesk Engineer, Compliance Officer, Onboarding SPOC) with Openings "None" and no over-headcount warning or badge. - Expected: Over-filled positions are highlighted (and possibly reported), since sanctioned headcount is what the job is funded for.
ISS-015 · Levels and grades can't be deleted or deactivated
- Module: O4 Positions, Grades & Levels · Severity: Medium · Found: 2026-09-27
- Steps: Organization → Positions → Grades & levels → ⋯ on any level or grade.
- Actual: The only action is Edit. The API has create/patch only for
position-levelsandgrades(no DELETE, no deactivate). A level or grade added by mistake stays in every picker forever. - Expected: Deactivate (hidden from pickers, kept for history) at minimum, and delete while unused.
ISS-014 · Chart view ignores "Show only this branch"
- Module: O3 Departments · Severity: Low · Found: 2026-09-26
- Steps: Table → ⋯ on a department → Show only this branch (banner "Focused on …") → switch to Chart.
- Actual: The banner still says "Focused on …", but the chart draws the whole company. The chart has its own separate focus ("Top of chart", set by clicking a node).
- Expected: One focus shared by Table, Cards and Chart, or the banner is hidden in Chart view.
ISS-013 · "Show only this branch" is missing for departments that only have sub-departments
- Module: O3 Departments · Severity: Low · Found: 2026-09-26
- Steps: Departments → Table → ⋯ on "Human Resources" (parent of HR Operations and Talent Acquisition), or on "Delivery" after moving a department under it.
- Actual: Menu is Edit / Manage people… / Add team / Deactivate. "Show only this branch" only appears for departments that contain teams (e.g. Information Technology).
- Expected: Any department with children, departments or teams, can be focused as a branch. That's where it's most useful.
ISS-012 · Teams can't be edited or deactivated from the UI
- Module: O3 Departments · Severity: Medium · Found: 2026-09-26
- Steps: Create a team with ⋯ → Add team. Then try to rename it, change its lead or deactivate it.
- Actual: Teams don't appear as rows in the Table view. In Cards they're plain text under the department. In Chart, clicking a team node only focuses the chart (no menu, right-click or double-click action). So there's no way to edit or deactivate a team. Together with ISS-008, a department that has ever had a team can't be deactivated from the UI either.
- Expected: Teams get the same ⋯ actions as departments (Edit, Manage people, Deactivate), e.g. as nested rows in Table view or a menu on the team node/card line.
ISS-011 · Department chart doesn't fit the tree on first open
- Module: O3 Departments (Chart view) · Severity: Low · Found: 2026-09-26
- Steps: Departments → Chart.
- Actual: At 1920×1080 the first and last departments are cut off at the left and right edges. The user has to press "fit view" or pan.
- Expected: The chart opens fitted to the tree.
- Evidence:
scratch/D2-chart.png
ISS-010 · Departments and teams can't be deleted, only deactivated
- Module: O3 Departments · Severity: Low (confirm intent) · Found: 2026-09-26
- Actual: The API has create/patch/reparent/deactivate/reactivate and no delete (
DELETE /api/company/organization/departments/{id}→ 404 route not found). A department created by mistake (typo, test data) stays forever under the Inactive filter and keeps its code reserved. - Expected: Hard delete allowed while a department has never had people, positions or children. Otherwise deactivate only.
ISS-009 · Copy: pluralisation in department screens
- Module: O3 Departments · Severity: Low · Found: 2026-09-26
- Actual: The deactivate dialog says "1 people are in it" (should be "1 person is in it"). With "Show only this branch" the count reads "1 of 10 department" (should be "1 of 10 departments").
ISS-008 · Deactivating a department that still has an active team fails with a generic error
- Module: O3 Departments · Severity: Medium · Found: 2026-09-26
- Steps: Department with one active team → ⋯ → Deactivate → confirm.
- Expected: The confirm dialog says up front that active teams/sub-departments must be deactivated or moved first, and offers a way to do it. Or the Deactivate button is disabled with that reason.
- Actual: The dialog only warns about people and active positions. On confirm the server returns
409 DEPARTMENT_HAS_ACTIVE_CHILDREN, shown as the toast "Could not save — Deactivate or reparent active child departments first". The dialog stays open. - Evidence:
scratch/D9-after.png
ISS-007 · Row actions (⋯) stop working after searching, clearing the search, then creating a location
- Module: O2 Locations · Severity: High (blocks edit/deactivate/manage people until reload) · Found: 2026-09-25
- Steps: Organization → Locations → Table view → type "Remote" in the search box → clear it → New location → fill in the name and code → Create location → click ⋯ on any row.
- Expected: The row menu opens (Edit / Manage people… / Deactivate).
- Actual: Nothing happens on any row, including rows that existed before. Toggling Cards/Table doesn't recover it. Playwright shows the "Actions for …" button resolving to a node that is no longer attached to the document (
document.contains(el) === false), which suggests the list keeps a stale row tree after the search/filter state is reset and the query refetches. The same steps without the search work fine. - Evidence:
scratch/repro.tsreproduces it reliably;output/locations-failure.png.
ISS-006 · People can't be removed from an inactive location, so it can never be deleted
- Module: O2 Locations · Severity: Medium · Found: 2026-09-25
- Steps: Location with 1 person → Deactivate (confirm dialog warns "People are still there… move them first") → open "Manage people…" (still offered in the menu for inactive locations) and move the person out → save. Or call
POST /api/company/location/locations/{id}/members {mode:"remove"}. - Expected: Removing people from an inactive location is allowed. It is exactly the clean-up the confirm dialog tells you to do.
- Actual:
409 LOCATION_INACTIVE — "An inactive location cannot take placements", which applies the rule for adding to removals too.DELETEthen fails with409 LOCATION_IN_USE (employeeLocations: 1). The only way out is Reactivate → remove people → Deactivate/Delete.
ISS-005 · Session saved via "Keep me signed in" doesn't survive a new browser context
- Module: Auth · Severity: Low (confirm intent) · Found: 2026-09-25
- Steps: Sign in with "Keep me signed in" checked → save cookies → open a new browser context with those cookies a few minutes later.
- Actual: Redirected to
/sign-in. Cookies are__Secure-better-auth.session_token/session_dataon the workers.dev API domain. - Expected: The persisted session is reused until it expires.
ISS-004 · Sign-in page on QA exposes a shared-password hint
- Module: Auth · Severity: Medium (security hygiene) · Found: 2026-09-25
- Steps: Open https://qa.satellitehr.com/sign-in.
- Actual: Banner "Local environment — every login shares the password 1234" with a login picker. It's shown on a publicly reachable QA URL, and the hint doesn't match the actual QA credentials.
- Expected: Dev-only banner hidden outside local builds.
ISS-003 · Company Super Admin cannot view the jurisdiction catalog
- Module: O1 Jurisdictions · Severity: Low (confirm intent) · Found: 2026-09-25
- Steps: As Company Super Admin, open
/platform/jurisdictions, or/company/{id}/organization/jurisdictions. - Expected (BRD O1): Jurisdictions are platform-managed, but a company admin can at least see which jurisdictions the company operates in, and manage them (add/remove) in one place.
- Actual:
/platform/...redirects to company home./organization/jurisdictionsrenders the breadcrumb "Organization › Jurisdictions" with a bare "Not Found" body. The only way to add a company jurisdiction is inside the New location dialog. There is no UI to see or remove company jurisdictions, even though the API supports removal (DELETE /api/company/location/jurisdictions/{id}).
ISS-002 · New US location defaults to America/New_York regardless of jurisdiction
- Module: O2 Locations / O1 Jurisdictions · Severity: Low · Found: 2026-09-25
- Steps: New location → Country: United States → Jurisdiction: Texas.
- Expected: Timezone follows the jurisdiction (Texas → America/Chicago), or the user is prompted to choose one.
- Actual: Locale summary shows
USD · America/New_York · MM/dd/yyyy · en-USfor every US jurisdiction. It can only be corrected through "Change".
ISS-001 · Deleted location's code stays reserved
- Module: O2 Locations (found while recording O1 Jurisdictions) · Severity: Medium · Found: 2026-09-25
- Steps: Create location "Demo – Austin Office" (code auto-generated
DEMO-AUSTIN-OFFICE) → deactivate → delete it (DELETE /api/company/location/locations/{id}returns 204, GET then returns 404) → create a new location with the same name and leave Code empty. - Expected: The code is free again (or the auto-generated code gets a suffix).
- Actual: Toast "Could not save — Location code is already in use". The user can't see which location holds the code, because it no longer exists.
- Evidence:
output/jurisdictions-failure.png(from the draft run)