Product
Changelog
What we shipped — dated and readable. Not a dump of commits; the releases that matter for programmes evaluating Sigmaviu.
Integrations: connect, Automations posts, Calendar due dates, Jira/Linear from tasks
Settings → Integrations connects Discord, Teams, Jira, Linear, Notion, GitHub, Slack, and Google Calendar. Automations can Post to Slack/Discord/Teams. Task due dates sync to Google Calendar when connected. Task detail can create linked Jira or Linear issues. Pro gates Jira/Teams/Linear/Notion. Configure defaults per connection.
- Webhook/API-key connect plus optional platform OAuth
- Automations: Post to Slack, Discord, Microsoft Teams
- Google Calendar due-date push; Configure defaults (channel, project, team, calendar)
- Create in Jira / Linear from task detail with integration links
- Professional+ required for premium connectors
Multi-sheet migration pack + changelog RSS
Import Tasks, Resources, and Risks from one Excel workbook on project WBS → Import → Migration pack. Subscribe to shipped updates via /api/changelog/rss.xml. Public roadmap refreshed so Now only lists active investment themes.
- Excel workbook sheets Tasks / Resources / Risks (aliases: WBS, Team, Risk Register)
- Downloadable multi-sheet template from the Migration pack dialog
- Changelog RSS feed for evaluation committees and IT stakeholders
- Roadmap Now/Next/Later cleaned — shipped themes live on Changelog
Org storage cap bonus and override
Super Admin can add storage capacity or set an absolute byte cap per organization — parity with project-cap bonus/override — enforced on uploads against plan included storage.
- organizations.storage_cap_bonus_bytes and storage_cap_override_bytes
- Effective cap resolves plan + bonus, or absolute override
- Upload paths hard-block when used + new bytes would exceed the cap
Field-level permissions for risk plans and document notes
Custom roles can hide or restrict risk mitigation/contingency plans and DMS document internal notes — same field-policy pattern as HR salary and invoice notes.
- New catalog fields: risk.mitigation_plan, risk.contingency_plan, document.classification
- Settings → Permissions field policy matrix includes the new entities
- getRisks / getRisk mask restricted plan fields for non-permitted roles
- Record-level document/task ACLs remain on the roadmap
Ask Sigma agent work — standup, needs-attention, work packs, AI fields
Ask Sigma can draft standups, search the workspace, list what needs your attention, extract tasks/risks/RFIs from pasted notes (confirm to create), and propose create risk/RFI/comment with confirm. Task comments get an Ask Sigma ambient shortcut. Custom fields add AI Summary/Progress/Sentiment/Categorize/Action Items. Automations add AI Draft Comment and AI Summarize → Comment.
- Slash intents: Needs my attention, Draft standup, Find in workspace, Notes → work pack
- Confirm cards for work pack, risk, RFI, and post comment
- AI custom field types with Generate + credit badge
- Automation AI comment actions (1 credit each)
- Honest scope: not ClickUp Brain Super Agents / AI Notetaker / Brain MAX parity
Plan price display — $99+, ranges, and Contact sales
Super Admin → Plans can set how each tier appears on /pricing: fixed list price, from ($99+), range, custom text, or Contact sales, with a matching Contact Sales or self-serve CTA. Enterprise defaults to From $99+ + Contact sales. Catalog monthly/annual amounts stay for Fixed display and Est. MRR — not a substitute for negotiated quotes.
- Display modes: Fixed, From, Range, Custom text, Contact sales
- CTA label + checkout vs /contact behavior per plan
- Live preview in the Edit plan dialog; Sales-led badge on plan cards
- Honest scope: marketing display metadata — not automatic custom Stripe quotes
Public sector audit pack — ISO 37301 / IPSAS / GAO Yellow Book
One-click Public sector pack from QMS Overview or Settings → Modules → QMS enables ISO 37301, IPSAS/GASB/FASAB-labeled financial evidence, and GAO Yellow Book controls, defaults vendor qualification to Public sector, and adds a combined workbook plus branded Print/PDF of invoices, ledger, POs, and budget vs actual.
- Apply pack (org admin): enable ISO 37301, IPSAS, and GAO frameworks with curated controls
- Combined Public sector workbook plus IPSAS / GASB / FASAB reporting-basis labels on cover sheets
- Evidence packs collect invoices, unified financial ledger, POs, budget vs actual, audit/change logs, and training
- Branded in-app Print/PDF of financial evidence; optional PO block when a public-sector vendor pack is expired
- Honest scope: operational public-sector audit-prep — not certified GAAP/IPSAS statements or GAO audit software
MedTech QMS follow-ups — DHF binders, complaints, EU MDR/MDSAP, Part 11 posture
Healthcare pack now seeds DHF/DMR/DHR DMS folders and document types, defaults vendor qualification to Healthcare, and unlocks QMS Complaints with vigilance/MDR decision tracking. Add-on EU MDR and MDSAP packs plus an honest Part 11 posture card.
- DHF / DMR / DHR / RMF / Complaint / SOP / VAL / IFU document types + Medical Device QMS folder tree
- QMS → Complaints: receive → triage → investigation → vigilance decision (MDR/MIR) → CAPA/close
- Apply Healthcare pack sets Vendors default qualification template to Healthcare / life sciences
- EU MDR + MDSAP one-click control matrices; EU MDR evidence packs
- Part 11 posture: what exists (audit logs, retention, portal e-sign, DMS approvals) vs gaps (no IQ/OQ/PQ)
Healthcare QMS pack — ISO 13485 / FDA QMSR
One-click MedTech pack from QMS Overview or Settings → Modules → QMS enables ISO 13485 and FDA QMSR control matrices, MedTech QMS defaults, seeded audits and acceptance inspection plans, plus ISO 13485 evidence packs and Copilot mapping.
- Apply pack (org admin): enable frameworks, seed curated controls, tighten CAPA/audit defaults
- Seeded planned audits (management review, design controls, production/acceptance) and draft inspection plans
- ISO 13485 evidence pack framework alongside ISO 9001 / SOC 2 / ISO 27001 / HIPAA
- Compliance Copilot frameworks include iso13485 and fda_qmsr
- Honest scope: operational mid-market MedTech QMS — not MasterControl/Greenlight/Qualio parity or certified assurance
One-click compliance evidence pack — ISO 9001 / SOC 2 / ISO 27001 / HIPAA
Compliance → Evidence Packs exports a framework-mapped workbook of control status, audit logs, change history, document approvals, and training records. Training is mapped on ISO 9001, SOC 2, ISO 27001, and HIPAA. Custom audit dates, saved-snapshot download, DMS attachments ZIP, auditor share links, optional portal publish, and Ask Sigma generate/list.
- Curated control catalogs for ISO 9001, SOC 2, ISO 27001, and HIPAA — not a full-standard library
- Collectors: audit logs, QMS NCR/CAPA/changes, DMS approvals, HR training, risks, Copilot mappings
- Custom start/end dates plus quarterly presets; PDF cover sheet; optional 2-credit gap narratives
- Attachments ZIP of linked DMS files (80 file / 25 MB cap) with an included-vs-skipped MANIFEST
- Expiring hashed auditor share links, optional client-portal publish, opt-in SOC 2 CC3–CC5 / ISO 27001 Annex A extras
- Ask Sigma: generateComplianceEvidencePack and listComplianceEvidencePacks
REST API v1 — keys, OAuth M2M, webhooks with retries, documented rate limits
External systems can read and write projects, tasks, comments, risks, and webhook subscriptions over /api/v1, plus read invoices and DMS metadata. Every response publishes X-RateLimit-* headers; the default limit is 60 requests per minute per key.
- Cursor pagination (page[after]), Idempotency-Key (24h), IP allowlists, sk_test_ keys (skip outbound webhooks)
- OAuth 2.0 client-credentials → oat_ tokens (1 hour) — not authorization-code marketplace OAuth
- Webhook retries 1m / 10m / 1h then dead-letter, plus delivery log with Retry now
- Invoices (read), risks, DMS metadata, project WBS — documented 60 req/min with HTTP 429
Custom fields on risks, incidents, and assets — plus formula columns and field RBAC
Configurable capture now covers the risk register, safety incidents, and assets. Formula results show as optional columns on the project Tasks table and WBS tree, Project Updated can fire from a saved formula, and custom roles can hide or lock individual custom fields.
- Settings → Custom fields tabs for Tasks, Projects, Risks, Incidents, and Assets
- SWITCH, DATEADD, and TODAY in the bounded formula language
- Formula columns on the project Tasks table and WBS tree (Columns menu); source fields stay optional
- Permissions → Field policies: hide / view / edit per custom field and role
Custom field formulas, show-when rules, and automations from calculated results
PMOs can capture risk scores and compliance flags without code: formula fields recalculate on save, conditional fields appear when rules match, and automations can trigger when a formula outcome changes.
- Formula language: IF, AND, OR, arithmetic, comparisons, {field_key} references, Try in the editor
- Show-when rules hide fields (e.g. Mitigation Plan when Risk Band is High)
- Custom Field Changed automation trigger — optional field key + from/to values
- One-click Likelihood × Impact risk-score pack and In-scope / Evidence compliance pack on Settings → Custom fields
Daily report approval and RFI respond/close with in-app notifications
Daily logs default to no review — Submit records them as official. You can require a reviewer (org admins, direct manager, or a named person) and optionally let authors approve their own work. RFIs notify on submit/respond/close, gate who can act, and expose Respond/Close on the detail page. Construction shows a Needs action strip for items in your court.
- Daily: review off by default; Settings → Modules → Construction picks the reviewer and self-approve
- In-app ping to reviewer on submit and to the author on approve/reject when review is on
- RFIs: notify assignee on Submit (not draft), submitter on response, optional close ping
- Needs action strip + Awaiting me filters; overdue digest deep-links the record
AI auto-draft for construction daily reports
Construction → Daily → New: Auto-draft builds work performed, tomorrow’s plan, and delays from schedule % complete, open RFIs, field photo capture/upload, approved timesheets, Open-Meteo site weather, and prior-report continuity. Ask Sigma tool + opt-in nightly pre-draft (default off). Human review before save — not Procore Helix Photo AI parity.
- Auto-draft from schedule, RFIs, photos, timesheets, and live site weather (3 AI credits)
- In-dialog camera/upload → Documents; Project Settings → Job site location for geocode
- Ask Sigma draftConstructionDailyReport with Construction → Daily deep link
- Opt-in overnight pre-draft cron (Settings → Modules → Construction, default off)
Compliance Copilot — portfolio scan, manual mapping, calibration, and evidence pack sheet
Compliance Copilot now scans NCRs/CAPAs, HR policies/training, and ITSM tickets/changes in addition to tasks, documents, and change records; can scan an entire portfolio of active projects at once; and adds a Manual map tool for linking any record to a control without an AI suggestion.
- Portfolio scan mode — up to 15 active/planning/on-hold projects in one run
- Manual map: type-to-filter entity + control pickers for staff-linked evidence
- Apply on an ITSM ticket/change now links the control ID to the ticket/change record
- Applied mappings flow into a new "Copilot Mappings" evidence pack sheet
- Calibration badge shows running Apply/Dismiss accept rate and confidence floor
- Optional opt-in nightly scan + digest via Settings → Modules → QMS (off by default)
Compliance Copilot — AI control mapping suggestions
Compliance → Copilot suggests mappings from project tasks, DMS documents, and QMS change records to ISO 9001 / ISO 27001 / SOC 2 / HIPAA / GDPR control IDs. Human Apply/Dismiss writes approved evidence links; Ask Sigma can run and list the inbox.
- Scan project content against seeded framework controls (2 AI credits)
- Suggestion inbox with Apply/Dismiss — never auto-writes to the register
- Ask Sigma: scanComplianceControlMappings + listComplianceControlMappingSuggestions
- Honest scope: curated-template audit prep, not certified auditor parity
Construction closeout — warranties, ZIP, portal, certificate, gate
Closeout follow-ups: warranty register with dates/vendor/asset, CSI trade checklist, attachment ZIP, client portal publish, Certificate of Substantial Completion, package diff/regenerate, DMS HOV/ASB typing, and a project completion readiness gate.
- Warranty register + CSI trade checklist on Construction → Closeout
- ZIP download of linked drawing/submittal files; Certificate of Substantial Completion Print/PDF
- Portal publish on client project hub Closeout tab
- Diff vs last package + Regenerate; project Settings readiness gate
Construction — automated closeout packages
Construction → Closeout assembles as-built drawings, punch/defects, O&M manuals, and warranties into a readiness-scored handover pack with Print/PDF, optional Documents filing, optional AI narrative, and Ask Sigma status.
- Wizard: choose sections → review gaps → generate branded pack
- Sources: Drawings (As-Built), Punch, Submittals (O&M / warranties / certificates / closeout), Safety inspections
- Optional AI executive narrative (2 credits); core packaging is free/deterministic
- Ask Sigma getConstructionCloseoutStatus with deep link to Closeout tab
Automations — escalation queues, inbound trigger, broader webhooks
Delayed automation actions and escalation chains use a durable cancel-on-resolve queue. External systems can fire Inbound Webhook automations with an org API key. Outbound webhooks cover project, sprint, and comment events; conditions support tags, overdue days, and custom field paths; Test evaluates pasted JSON.
- Escalation Chain action + delay_seconds durable queue (cron every 5 min)
- POST /api/webhooks/automation-trigger with API key
- Deliver Org Webhook action picks Settings → Webhooks endpoints
- Project/sprint/comment outbound events + JSON condition harness
Automations and webhooks — multi-condition AND/OR logic
Automation rules and outbound webhooks can filter events with AND/OR conditions and nested condition groups, closing the single-condition gap for realistic PMO escalation and status broadcasting.
- AND/OR match mode plus nested condition groups in /automations editor
- Settings → Webhooks optional payload filters before delivery
- Templates: escalate high/urgent review work; broadcast critical completion via webhook
- Shared condition evaluator used by automation runs, test mode, and webhook dispatch
Document Submit for Review — cleaner templates, AI assist, searchable assignees
Submit for Review no longer lists duplicate one-shot Matrix/Custom templates. Build custom or matrix chains with drag-reorder, type-to-search assignees, AI step/backup suggestions (credit-gated), and a clear fix path when a matrix rule has no steps.
- Template picker hides ephemeral Matrix:/Custom: runs; Settings → Workflows can bulk-hide leftovers
- Create Custom: Suggest steps (2 credits) and Suggest backups (1 credit)
- Searchable people pickers + drag-to-reorder workflow steps
- Matrix match with zero steps links to Documents settings to finish the rule
Switch plan checkout between Clerk Billing and Stripe
Super Admins can set the customer plan checkout provider in Admin → Settings. Clerk remains the default; Stripe Checkout runs 14-day trials and seat quantity updates with Customer Portal for payment methods. Admin MRR data source stays a separate control. Customer-portal invoice Pay is unchanged.
- Admin → Settings → Plan checkout provider (Clerk or Stripe) with readiness checklist
- /choose-plan and seat purchase follow the selected provider
- Settings → Billing opens Stripe Customer Portal when Stripe is active
- Sandbox Stripe Products/Prices seeded for Starter, Professional, and Business
- organizations.stripe_customer_id + webhook sync for SaaS subscriptions
Project Communications hub — RFIs, threads, planned touchpoints, mail
Each project gets a Communications tab that aggregates what needs a response: project-filtered Construction RFIs, stakeholder planned touchpoints, internal threads (typed requests, DMS attachments, promote to RFI), inbound email filing, and Ask Sigma overview deep-links.
- Overview stats: open/overdue RFIs, submittals awaiting, planned (14d), threads, unfiled mail, risk suggestions
- Formal = Construction RFIs filtered to the project (single register)
- Threads with promote-to-RFI + in-app notifications
- Mail: file inbound email into a thread; Risks Inbox remains for AI risk suggestions
- Ask Sigma: listProjectCommsNeedingResponse
Document approval tied to version, role, and risk
DMS documents now carry a risk classification; workflows pin the submitted version/revision; Settings → Documents → Risk approval maps each band to a required custom role, SoD, and optional staff signature. Approvals fail closed on version drift, wrong role, or author self-approve.
- Risk classification on create/edit/register (Low → Critical)
- Workflow pins version + revision; edits frozen while workflow is active
- Org risk→role policies + SoD + staff signature (Critical default)
- Review matrix can match by risk band; role steps notify all role members
- Suggest classification from linked project risk score
- Honest scope: staff document control — not portal e-sign / DocuSign parity
Sprints tab: AI generate from WBS/brief, carry-over, and Ask Sigma
Propose sprint series from a delivery brief or unassigned WBS (with dependency and capacity checks), plan backlog into a sprint, complete with unfinished-work carry-over and optional AI retro, edit dates from the hero, and deep-link into a sprint sheet.
- Generate with AI — WBS or description modes, preview before create, credit badge (3)
- Dependency-aware WBS batching + over-capacity flags vs historical velocity
- Complete sprint: backlog / next sprint / leave + optional AI retrospective
- Plan this sprint backlog pull, burndown sparkline, edit dates on overdue
- Ask Sigma: listProjectSprints, suggestSprintCapacity, generateProjectSprints
- Deep link ?tab=sprints&sprint= opens the detail sheet
Asset EAM lifecycle linked to projects, WBS, PM schedules, and EHS
Assets now track EAM phases with commissioning/decommission WBS links, maintenance schedules on the asset Lifecycle tab, a project Assets tab with schedule milestones, and Safety inspections that can reference an asset.
- Lifecycle tab: phase, project, commissioning/decommission tasks, install/commission/retire dates
- Time- and meter-based maintenance schedules with Generate WO + meter reading
- Project → Assets tab + Schedule Gantt Assets layer for commission/PM markers
- Completing a linked WBS task auto-advances asset phase (commission → in service / decommission → retired)
- Safety inspections + work orders can link assets/projects; Ask Sigma listProjectAssets / getAssetLifecycle
- Honest claim: project-centric EAM — not Maximo/Infor full CMMS parity
Portal payments depth: Connect, partial pay, e-sign certificates
Stripe Connect Express onboarding from Settings → Finance, BYO webhook endpoint per org, partial invoice payments with retainage shown, and downloadable portal e-signature certificates on DMS documents.
- Connect Stripe (Express) button — app fees apply on destination charges
- Org webhook URL /api/webhooks/stripe-portal/{orgId} for BYO keys
- Pay full balance or a custom partial amount in the portal
- DMS → Portal e-signatures gallery + PDF certificate download
Portal e-signature approvals and Stripe invoice payments
Clients sign shared documents in the customer portal (draw or type) before approve, and can pay shared invoices with Stripe Checkout (card or ACH). Super Admin can set a platform app fee (percent or fixed; default 0).
- Sign & Approve on portal documents (+ packet approve with one signature)
- Pay now on shared invoices when org enables Stripe under Settings → Modules → Finance
- Super Admin → Settings: portal payment app fee (0 by default)
- Audit trail in portal_document_signatures and portal_invoice_payments
ESG depth: factors, CSV/PO ingest, portal, closeout gate, Ask Sigma
Org-editable emission factors (region + PO keywords), CSV import, purchase-order emission drafts, client portal Sustainability packs, project closeout gate for final ESG reports, Ask Sigma getEsgSummary, and a daily KPI at-risk digest for admins.
- ESG → Factors library (seed presets, edit kgCO₂e / region / keywords)
- Import CSV + Suggest from POs (keyword match, PO-line dedupe)
- Publish report to portal → client hub Sustainability tab
- Project Settings: ESG closeout gate; cron /api/cron/esg-kpi-digest
- Ask Sigma tool getEsgSummary with Open ESG deep-link
ESG & sustainability reporting on Safety / EHS
Public-sector and infrastructure closeout needs carbon and ESG evidence — Safety now includes Scope 1–3 activity logging (project/WBS-linked), ESG KPIs tagged to GRI/CSRD/ISSB/SASB, multi-framework report packs, Print/PDF, and an optional AI narrative (2 credits).
- Safety → ESG tab: emissions, KPIs, reports
- Indicative emission-factor presets (replace with location factors for assurance)
- Framework sections for GRI, CSRD/ESRS, ISSB, SASB, or custom
- Settings → Modules → Safety: default ESG report framework
Gmail & Outlook OAuth for risk-comms mailboxes
Connect a project mailbox with Google or Microsoft OAuth (readonly mail). Messages sync into the same inbound email corpus used by Scan comms, with Sync now, disconnect, encrypted token storage, and nightly sync before the risk scan cron.
- Risks → Inbox → Email ingest: Connect Gmail / Connect Outlook
- Scopes: gmail.readonly + Mail.Read (offline refresh)
- Nightly cron syncs OAuth mailboxes then runs risk-comms scan
- Forward/webhook/paste remain as fallbacks
AI risk register from project communications (inbox + email + cron)
Scan comms drafts register changes from comments, RFIs, daily reports, stakeholder notes, meeting docs, and inbound email; persists an Inbox; nightly cron skips unchanged corpora; digests notify admins; opt-in auto-apply for mitigation notes; Ask Sigma tools deep-link to review.
- Inbox with Apply / Dismiss + forward/webhook/paste email ingest
- Near-duplicate suggestion merge; source-hash dedupe
- Cron /api/cron/risk-comms-scan + org module settings
- Ask Sigma: scanProjectCommsForRisks + listRiskCommsSuggestions
- Outlook/Gmail OAuth still later — forwarding works today
Predictive schedule risk v2: bands, POs, explainability, supervised blend
Live progress-band feature snapshots, late PO signals, platform cold-start priors, calibration-driven weights, optional supervised delay model, feature-delta explainability, Ask Sigma deep-link, and a step-by-step UI guide.
- progress-band vectors persisted while projects are live (not only reconstructed at completion)
- Late purchase orders + materials in the leading-indicator set
- Platform priors until 3 org late completes; calibrated weights ≥20 outcomes; supervised blend ≥50
- Similar-project “Why” deltas; Open Predictive Risk cite from Ask Sigma; spotlight guide
Predictive schedule risk: late materials + honest ML claim
The portfolio pattern-matching engine now includes late material deliveries alongside velocity, resource clashes, and procurement backlog — so the early-warning claim matches what the model actually scores.
- Late materials from Construction (expected/required vs actual) as a leading indicator
- 4–8 week early-warning lead estimate tightened to the published claim window
- Methodology copy: ML k-nearest neighbors trained on completed portfolio history
- Support guide for Schedule → Predictive Risk
Ask Sigma voice: mic dictation and read-aloud
Talk to Ask Sigma with the mic, listen to spoken replies, and run a voice conversation with check-ins and follow-up chips — plus Auto-speak, org Settings → AI control, and credit badges.
- Hold-to-talk or tap mic; barge-in stops read-aloud when you start speaking
- Voice conversation check-ins + follow-up chips; desk mode & quiet hours for shared spaces
- Per-device voice/locale prefs; spoken summary skips Final answer / Go to tables
- Same voice controls on floating Ask Sigma and full /ai assistant; optional voice event analytics
Ask Sigma coach: multi-guide tours, resume, do-it-for-me
Spotlight guides cover add task, create project, report incident, add document, invite teammate, import WBS, and edit schedule — with permission checks, resume, empty-state CTAs, and confirm-to-create tasks.
- Seven curated tours with live control highlights (including Import WBS + Edit Schedule)
- startUiGuide permission checks + project-scoped navigation
- Resume banner + localStorage funnel analytics (start/step/complete/skip)
- proposeDoItForMe — preview then Create this task (user confirms)
- Show me how CTAs on Tasks, Safety, Projects, WBS, and Schedule
Ask Sigma: what can I do, how-tos, and Add task guided tour
Ask Sigma answers module capabilities and Support-backed how-tos, then can launch a step-by-step spotlight guide for creating a task on the Tasks hub.
- getModuleCapabilities — permission-aware “what can I do” for Tasks, Projects, Safety, Documents, Settings, HR
- searchSupportGuides — Support Central search with clickable article links
- startUiGuide + Start step-by-step guide button — Add task spotlight tour
- Slash intents: What can I do here? / How do I add a task?
Vendor qualification: multi-file evidence, coverage fields, sync gaps
Qualification packs get a searchable grouped document-type picker, multi-file uploads with remove, insurance coverage details, staff Reopen for resubmit, pack gap sync that keeps verified evidence, and org rules for when expiry dates are required.
- Grouped type-to-filter document types (insurance, tax, safety, security, public sector…)
- Multi-file evidence + drag-and-drop on vendor portals; remove individual files
- Carrier / policy # / limit / additional insured on insurance requirements
- Sync pack gaps adds missing items without wiping verified rows; Reopen for resubmit
- Settings → Modules → Vendors: require expiry on insurance_core (default) or broader sets
Vendor qualification depth: supplier portal, gates, risk score
Suppliers upload evidence on vendor-typed Customer Portals; staff get industry pack templates, DMS links, expiry cron alerts, optional PO/sub activation gates, Construction sub↔vendor qualification bridge, and Ask Sigma getVendorRisk.
- Vendor portal → Qualification: upload COI/compliance files for linked vendor
- Industry packs: standard, construction, healthcare, public sector
- Settings → Modules → Vendors: block PO / sub activation when non-compliant
- Daily cron vendor-qualification-reminders (30/7 day) to org admins
- Ask Sigma getVendorRisk + on-vendor risk score badge
Vendor qualification packs: insurance, compliance, and risk rollup
Vendors get a Qualification tab with a default pack (COI, workers' comp, license, W-9, safety, bonding), status/expiry tracking, verification, audit events, and a directory Qualification risk filter — alongside existing performance scores.
- Vendor detail → Qualification: apply default pack or add custom requirements
- Statuses: missing / submitted / verified / expired / waived with expiry countdown
- Rollup badges: Incomplete, Qualified, At risk, Non-compliant
- Directory stat + Qual risk badge for vendors with gaps or expiring certs
- Verify action respects vendor.approve (falls back to vendor.update)
Customer portal: per-invitee access, publish-to-portal, project hub
Sharing is grant-based for invitees (guest links stay for anyone with the URL). Publish selected project documents to the portal, open a client project hub with tabs, view-only PDF watermark, live expiry countdown, square logo crop, and analytics that ignore staff preview sessions.
- Invitee dashboards no longer inherit every portal share link
- Project → Portal: publish/unpublish documents (+ optional grant to active invitees)
- Client project hub: Overview · Documents · Tasks · Risks · Updates
- View-only PDF watermark; access expiry live countdown
- Share create reuses an existing active link (no duplicates); opt-in grant to invitees
- Preview users excluded from DAU / user counts; square logo crop on upload
Customer portal: branded host links, share modal, requests queue
Invite, preview, and share links prefer your org subdomain (/portal/…). Settings can probe DNS/SSL. Share create is denser with Advanced security. Staff Requests adds filters and a queue badge; admins already get in-app notify on new client requests.
- Branded absolute URLs for invites, OTP redirect, Preview, and copy link
- Settings → Organization: Check DNS / SSL for *.sigmaviu.com
- Share link modal: sticky footer, Advanced security (expiry + password)
- Requests tab: Needs action filter + queue badge; Convert to task
- Clear Pro subdomain vs Enterprise apex white-label copy
Customer portal depth: OTP, packet approve, theme, apex domain
Customer Portal is available on every plan above Starter. Clients get live project status, document approve/reject (including packet approve), email OTP sign-in, light/dark themes, raise-a-request, and apex custom domains on Enterprise White Label — no workspace seat.
- Module on Professional, Business, and Enterprise (not Starter/Free)
- Portal Documents: approve/reject + Approve packet for multi-select
- Email OTP at /portal/access — magic-code login for invitees
- Light/dark client theme; hide Powered by when logo is set
- Requests tab + Convert to task for staff; DAU / open requests / approval SLA stats
- Apex custom domain routing when White Label is enabled
Knowledge tab: harvest preview, bulk publish, saved views
The project Knowledge tab now previews harvest sources before commit, bulk-publishes drafts, regenerates closeout packs, runs a closeout AI checklist, persists filter state and saved views, opens a lesson detail sheet, and uses semantic search at 3+ characters — plus Ask Sigma /lessons and programme panel polish.
- Harvest sources opens a preview dialog — select milestones, risks, and RFIs before creating drafts
- Bulk publish: Select drafts → Publish selected on the Knowledge tab
- Regenerate closeout pack from current published lessons (2 AI credits)
- Closeout readiness banner with AI checklist (1 credit); saved filter views in localStorage
- Lesson detail sheet; semantic project search at 3+ chars; Apply framing from org hits
- Ask Sigma slash intent Search lessons; searchProjectLessons links include ?lesson= id
Lessons-learned knowledge base for projects and programmes
Projects get a Knowledge tab that harvests completed milestones, closed risks, and resolved RFIs into lessons (including auto-harvest on status change), AI-generates a closeout pack filed to Documents, branded Print/PDF, semantic search, wizard similar-lessons hints, and optional completion gates — searchable across each portfolio programme.
- Project → Knowledge: harvest sources, add manual lessons, Generate pack (2 AI credits)
- Auto-harvest draft lessons when milestones complete, risks close, or RFIs resolve
- Portfolio → Knowledge: programme-scoped search; wizard surfaces similar past lessons
- Generate pack files a DMS/rich-text document; Print/PDF uses org branding
- Semantic search via embeddings; optional closeout gate (N published lessons)
- Ask Sigma tool searchProjectLessons with clickable project deep-links
Log time: AI fill, week suggest, and timer handoff
The Log time modal gets natural-language fill, description polish, searchable project/task pickers, overlap warnings, recent favorites, duplicate last, keyboard save, Ask Sigma “why non-billable”, Suggest week drafts, and timer handoff to log another block.
- Quick fill: “2h on Alpha standup yesterday” → Fill form (1 credit)
- Suggest week from recent patterns + org holidays (2 credits)
- Timer: Log another while running; Log more after stop
- Overlap soft-warn, Today/Yesterday, sticky entry preview
- Ask Sigma explains non-billable with links to Time, Settings, and Invoices
Time-to-invoice: timesheets, milestones, and recurring billing
Approve billable hours into a billing queue with rate resolution, release milestone and progress fees (including auto-release when a WBS milestone is done), billable expenses and completed work orders, retainage, billing-rule grouping/markup, and recurring retainer schedules.
- Fixed approve → billable_records bridge; Sync timesheets on the billing queue
- Billing rate override on time entries; cascade uses project / role / employee rates
- Project Budget: milestone & progress schedule, retainage %, auto-release on milestone done
- Invoices → Settings billing rules; Recurring billing schedules with daily cron
- Billable expenses and completed work orders stage into the queue
EHS events on the project schedule timeline
Incidents and inspections linked to a project appear on the Schedule Gantt (same day axis as WBS tasks), with optional WBS causal links, stop-work → schedule risk (and optional task date extend), critical-path overlap hints, Print/PDF pack, dashboard PMO alerts, and Ask Sigma coverage.
- Gantt EHS toggle: diamonds for incidents, circles for inspections
- related_task_id + stop-work fields on incidents; Apply stop-work creates a schedule risk
- EHS on schedule panel with Print/PDF branded pack
- Dashboard PMO card surfaces projects with EHS stop-work / linked tasks
- Ask Sigma tool getEhsScheduleCriticalPath for safety vs critical path
- GET /api/projects/:id/ehs-timeline for resilient on-mount reads
SCIM / directory sync lifecycle and attestation
Enterprise organizations can automate join–move–leave via identity-provider directory sync (SCIM) and SSO JIT. Sigmaviu soft-deprovisions memberships when users are disabled, records provision source for audit, optionally blocks manual Team invites, links HR offboarding to access removal, and exports SCIM posture on the Security attestation.
- Directory sync status on Security with enforce + block-manual-invite controls
- Webhook lifecycle: ban/lock → soft deprovision; membership create/update/delete audited
- Team Directory / SSO JIT badges; invite UI hidden when directory is enforced
- Super Admin mark SCIM configured; compliance posture check AUTH-SCIM
- HR termination can soft-deprovision linked org membership
- Attestation CSV/HTML includes SCIM fields and provision-source roster column
- Support guide: Enterprise SSO and directory sync (SCIM)
Admin MFA enforcement with grace period and attestation export
Organization admins and platform super admins can require MFA for all members and/or privileged admins, with a configurable grace period before hard blocking. Export a questionnaire-ready security attestation (CSV + printable HTML) from Security.
- Org-wide and privileged (admin-only) MFA policies with optional/recommended/required
- Grace period (0–30 days) before hard app block; countdown shown on Security
- Enforcement in app layout and request proxy; fail-closed option for regulated tenants
- Business and Enterprise plans auto-require MFA (with grace) when platform flag is on
- One-click security attestation pack for SOC 2 / ISO procurement questionnaires
- Confirm dialogs before requiring MFA; Support Central and Settings deep-links updated
Granular RBAC, persona templates, and field-level permissions
Settings → Permissions now seeds PMO / contractor / client / auditor persona roles, supports project-scoped assignments with expiry, user kinds that further restrict access, field policies for sensitive HR and invoice fields, role simulation, and invoice create/approve separation of duties.
- Persona templates: PMO Staff, External Contractor, Client Stakeholder, Read-only Auditor
- Restrictive roles replace the Member baseline so auditors are not over-permissioned
- Project-scoped role assignment + optional expiry from the Users tab
- User kinds (internal, contractor, auditor, client stakeholder) with hard deny lists
- Field policies for employee salary / rate / DOB and invoice internal notes; hr.view_sensitive enforced
- Simulate-as-role preview and SoD warnings; creators cannot approve their own invoices
SEO fundamentals and bilingual marketing (EN/FR)
Search engines get robots.txt, a locale-aware sitemap, and richer homepage/pricing metadata. The marketing site supports English and French URLs, and signed-in users can set a personal or organization default language — including localized sign-in screens.
- robots.txt + sitemap.xml with hreflang alternates for EN/FR marketing pages
- App and admin surfaces are noindex; homepage/pricing SEO + Open Graph image
- Marketing language switcher (`/fr/…`) and CMS pages can be cloned per language in Admin → Pages
- Settings → Profile language preference; org admins set a default under Organization
- Sign-in and account UI follow the selected language
PLM navigation, BOM CSV import, and keyboard shortcuts
PLM hub polish: a compact pill nav with an always-visible Items tab, CSV import for BOM lines (alongside existing export), named review-board approvers on changes, a where-used graph, one-click AI Studio deep-links, and keyboard shortcuts for power users.
- Pill navigation keeps Dashboard, Products, Items, BOMs, Changes, Requirements, Baselines, and AI Studio on one row — everything else lives in More
- BOM → Imports: upload a CSV to add lines to a BOM revision, with per-row validation and an import job history
- Change review board: route approvals to named people with a running approval trail
- Where-used graph shows every upstream assembly affected by an item before you release a change
- AI Studio deep-links jump straight into item, BOM, and change analysis from wherever you're working
- Keyboard shortcuts: digits 1–8 jump between primary tabs, g then i jumps to Items; mobile More opens as a bottom sheet
- Admin tab documents the permission capability matrix for PLM actions
HR import merges people by email
Bulk employee import detects existing directory profiles, pending invites, and active members by email — then lets admins merge, replace, or skip before importing. Invites link back to the imported HR profile and can prefill name on sign-up.
- Review matches step on HR → Employees → Import
- Merge fills empty fields; Replace overwrites mapped fields without clearing account links
- Invite selected unlinked employees from the directory (org admins)
- Invite acceptance links Clerk users to the matching employee by email
- Sign-up can prefill first and last name from the imported HR record
Scheduled PDF and CSV report delivery
Programme and compliance status reports email as branded PDF/CSV with 30-day download links, optional project scope, report.view recipient resolution, and delivery history — plus finance schedules now attach PDF/CSV too.
- Schedules on /reports: org or per-project scope, Send now, run history
- Recipients: manual emails, everyone with View Reports, or both
- Branded PDF cover (org invoice logo) + CSV; storage links expire in 30 days
- Finance Ask scheduled reports attach PDF + CSV (not HTML-only)
- Distinct from Compliance evidence packs (framework XLSX)
- Table export menus label print dialogs as Print / Save as PDF
Product Lifecycle Management (PLM) module
Controlled items and revisions, EBOM editor, ECR/ECO change control, requirements traceability, baselines, vendor AML/AVL links, and AI-assisted classification — integrated with Documents, QMS, Assets, and Projects.
- PLM hub at /plm with dashboard, products, items, BOMs, changes, requirements, and admin tabs
- Immutable released revisions with checkout/check-in and audit trail
- Lazy-loaded BOM tree, where-used, and revision compare
- Ask Sigma tools: items, changes, BOM explosion, requirements coverage
- Settings → Modules → PLM defaults; Support guides under Product Lifecycle Management
Bulk data import with field mapping
CSV and Excel import with interactive column mapping for WBS, workspace lists, employees, and assets — plus clearer MS Project XML vs .mpp guidance.
- Shared import kit: parse CSV/Excel → map columns → preview → import
- WBS import accepts Excel with the same mapping UI as CSV; maps remembered in-browser
- HR employees and Assets import dialogs with templates and mapping
- MS Project tab shows when native .mpp conversion is configured
- Support guide: Bulk data import
Public roadmap and changelog
Buyers can see where Sigmaviu is investing and what shipped — without a private deck or NDAs.
- New public Roadmap page (Now / Next / Later)
- New public Changelog with dated release notes
- Why Sigmaviu updated so Live vs Coming soon matches the product
Submittal approval chains, attachments, and external review
Construction submittals/RFIs with DMS evidence, CSI library, cross-links, approval chains, overdue digests, branded Print/PDF logs, and portal magic-link consultant review.
- DMS searchable attachments + drawing/material/CO links on the submittal
- Ordered approval chain, revision bumps, ball-in-court, activity log
- External consultant review via /portal/submittal-review/{token} (no seat)
- Daily overdue return-date digests + branded Print/PDF submittal log
- Org CSI/spec-section library with custom codes
Construction submittals and RFIs
Structured submittal and RFI workflows with review status, AI review assist, and project-scoped registers.
- Submittal register with review statuses and bulk actions
- RFI tracking native to the construction module
- AI checklist assist before approving a submittal
Predictive schedule risk
ML pattern matching (k-nearest neighbors) on your completed portfolio flags likely slippage before the critical path shows it — with optional executive narrative.
- k-NN matching against completed projects at similar progress bands
- Velocity, resource clashes, late materials, CO/RFI/submittal leading indicators
- Schedule tab Predictive Risk panel + dashboard heatmap
- Calibration view on Charts for forecast quality
Stakeholders, RACI, and communication plans
Stakeholder register, RACI, and scheduled touchpoints with in-app due reminders — synced from WBS roles.
- Register, matrix, RACI, and comms sub-tabs on the project
- Cron reminders with per-due-date dedupe
- WBS role sync into the stakeholder register
P6 import, baseline variance, and EVM
Primavera XER import with baseline vs actual, Gantt overlay, schedule-slip risks, and earned-value CPI/SPI/EAC.
- P6 XER → baseline and actual dates
- Edit Schedule draft mode on the Gantt
- Honest CPI N/A when actual cost is zero