What is shared and what differs
| Surface | Product behavior |
|---|---|
| Browser | Full authenticated workspace and specialist configuration |
| Native iOS/Android | Permission-scoped daily work, selected native workflows, bounded offline evidence and explicit web handoffs |
| Desktop macOS/Windows shell | Full hosted workspace with native lifecycle, notification and file/download controls; internet required |
| Guest native check-in | Separate account-free device setup/admission path with its own device credential; no workforce access |
All surfaces retain current workplace/source permissions. An installed application or successful sign-in does not grant membership, employment or module access. A native home being implemented does not establish that every detail action is native or accepted on a physical device.
Workforce navigation and native capability coverage
The stable tabs are Today, Messages, My Work and More. The header workplace selector changes the current authorized context. More shows admitted areas, subject to installed support, source authority and server feature pauses. Search, Profile, Notifications, Support and Pending work provide cross-cutting controls. The profile includes device appearance preferences and app update information.
The supported native home list includes Today, Messages, Tasks, Knowledge, Rotas, Attendance, People, Maintenance, Assets, Lost Property, Ticketing, Bookings, Inbox, CRM, Loyalty, Talent, Purchasing, Stock, Production, EPOS, Assistant and Automation. Portfolio and specialist planning/configuration retain web handoffs. Native rota exchange is explicitly unavailable; the personal schedule remains separate from web management and exchange authority.
Native detail routes include task creation/management/checklists; Knowledge content; personal rota history/brief; attendance/missed-punch review; People profiles; fault reporting; asset scanning/detail; Lost Property item/match/report; Ticketing Orders/Passes/door recovery; Booking creation/detail/table plan/menus/ preorders/private events; Inbox conversations/forms/Booking proposals; Loyalty members; Talent engagements/money; Purchasing approvals/receipts; Stock lot/count/ create/transfer; Production batches; EPOS detail; and Assistant conversations. Each route still checks its source authority and implementation-specific limits.
Offline work and uncertain commands
Encrypted local storage is partitioned by environment, installation, principal and workplace. A server-issued offline lease is bounded to twenty-four hours. Downloaded eligible Tasks/checklists may complete offline; attendance observations retain captured evidence and require later review. Reconnection reauthorizes commands and checks source revisions before applying them.
Native My Work and Today’s cross-product attention counts require a current online source check. My Work does not reopen an old mixed-source offline snapshot, and a removed item cannot publish a late navigation error. This does not change the separate offline contract for downloaded eligible Tasks and attendance evidence.
Approvals, external sends, booking allocation, financial effects, stock posting, custody and redemption require a connection. Message drafts are never sent merely because the device reconnects. A lost online receipt retains the exact operation for recovery instead of inventing a replacement action.
Pending work exposes saved drafts, observations and uncertain/conflicted work. Sign-out considers retained evidence across workplaces so it cannot be submitted under the next person's account. Expired/revoked access preserves evidence for recovery without granting operational access. Explicit discard is separate and can be irreversible. Ticketing door evidence has its own reconciliation/purge protocol and cannot be erased through ordinary queue discard.
Camera/photo/file attachments support permitted report and message workflows. Capture/upload progress, protected source context and installed-device acceptance remain separate from a saved draft or server implementation.
Native updates and availability
Profile distinguishes installed binary version/build from the running downloaded update identity/date. A compatible update can be checked, downloaded and applied by an explicit restart. Downloaded does not mean currently active. Edits, uploads, synchronization and uncertain commands hold restart until safe; retained drafts are flushed without deletion. Native binary changes need a matching signed/store build rather than a JavaScript update alone.
The checked-in public download manifest at this handbook baseline exposes no
public desktop installer. /download labels mobile as in testing and states that
public App Store/Google Play downloads are not available. Internal APKs, signing,
provider setup and private beta acceptance have separate evidence/runbooks.
Update these statements with the public manifest/store evidence when publication
changes; do not infer public availability from a successful build.
Installed desktop behavior
Desktop uses the hosted workspace, including its work-area navigation, settings and source commands. External provider journeys open in the system browser; return links select a destination without granting business authority. The native bridge is limited to approved operations and does not expose arbitrary files or shell commands to hosted pages.
Desktop guards unsaved edits, pending commands and retained evidence before close, reload, update, account change or sign-out. A successful earlier save does not mark text typed afterward as saved. A provider handoff, browser approval or first sign-in is separate from accepted retained-session startup. Beta/stable channels and staging/production identities remain separate; settings must not silently move a stable installation onto beta.