Getting in
Everything here needs an account. The service issues name clients and carry risk ratings, so nothing is open to the link alone.
- Open wscip.vercel.app and click Sign in.
- Sign in with your work email address and the one-time password you were given.
- You will be asked to set your own password before you can continue. Choose anything at least eight characters.
You stay signed in on that browser for 30 days. Password in the header changes it later; Sign out ends the session everywhere on that device.
Two things worth knowing about the one-time password you are given. It stops working after 14 days if you never use it, because until then it is a live credential sitting in whatever message it arrived in — ask for another and you will get a fresh one. And five wrong passwords for the same address locks that address for fifteen minutes, so if you are guessing, stop and use the reset link instead.
Forgotten your password
Click Forgotten your password? on the sign-in box, put in your work email, and add a line about how urgent it is if that helps. There is no automatic reset email — the request shows up for the administrators, who set a one-time password and pass it to you. You then choose your own the next time you sign in.
What you see depends on your account. Some people get the improvement plan and the service issues; some get the escalations only; some can read but not change. If something described here isn't on your screen, that is why.
Finding tasks
Every filter takes more than one value, and they combine.
Pick as many owners, workstreams, RAG values, statuses or sprints as you like. Within one filter the values are an or — Brix or Georgia. Across filters they are an and — those owners and that workstream.
- Each option shows how many tasks carry it, so you can see the size of a slice before you pick it.
- Owner and Sprint have a type-ahead box, useful with 22 owners and 26 sprints.
- Your choices appear as chips underneath with a running count — 31 of 259 tasks. Click the × on a chip to drop just that one, or Reset to clear everything.
Filtering by deadline
Deadline reaches both ways. Ahead covers the next 14, 30, 60 or 90 days or 12 months from today; Back covers the last 30 days, 3, 6 or 12 months; Custom range… opens a From and a To box for any two dates. It starts on Any deadline, which is every task, so nothing is hidden until you ask.
It matches a task's Finish date, so a task with no deadline set is in no window at all. The line under the rail says which dates are in and how many tasks have no deadline, so a task cannot go missing without the screen telling you.
A task owned by "Lee Redshaw, Brix" used to appear in the filter as its own entry, so filtering by Brix missed everything he shares with someone else. Owners are now split into individuals — filter by Brix and you get all 15 of his tasks, shared ones included.
Updating one task
Click any row, on any tab, to open its full detail.
The panel that slides in has everything about the task — objective, context, steps, what good looks like, dependencies — and, when you are signed in, two ways to record progress.
Change the plan now
Under Update the plan directly you can set status, RAG, % complete, priority, owner, sprint, start, finish and whether it is a milestone, plus the latest update and notes. Save changes writes it immediately.
Or capture it for later
Use Capture progress instead when you want to note something without touching the plan yet. That is covered next.
Every change is logged at the bottom of the panel under History — who changed which field, from what to what, and when.
Capture and roll up
Jot progress down as it happens through the week, then fold it all into the plan in one pass.
This is for the way Lee works: note things as they move, rather than opening each task and editing it live, then reconcile at the end of the day or week.
- Open a task and type into Capture progress. Optionally set status and % complete alongside the note.
- Click Capture. Nothing on the plan changes — the task still shows its old status and percentage.
- Keep going through the week. The Roll-up button in the toolbar shows how many are waiting.
- When you are ready, open Roll-up. Each captured item shows what it will change, old value struck through and new value in bold, with the note underneath.
- Drop anything you have changed your mind about with Discard, then Apply all to the plan.
Notes are appended to each task's latest update, oldest first, each stamped with the date and who wrote it — so a week of jottings becomes a readable trail rather than each one overwriting the last. Where two captures set the same field, the later one wins.
What changed
The second tab in Roll-up summarises what has already been applied over the last day, week, fortnight, month or quarter — grouped by task, with who did what. This is the one to read from for a weekly update.
Changing many at once
Filter to the set you mean, select it, apply once.
- Go to the Tasks tab and filter down to what you want — say Leanne Lally's not-started items.
- Tick individual rows, or use the tick-box in the table header to take everything the filters are currently showing.
- A bar appears at the top. Set only the fields you want to change; everything else stays on — leave unchanged —.
- Click Apply to 12. Delete 12 removes them instead.
Setting a field to the value tasks already have records nothing. Applying "High" to a set that is already High reports no changes needed rather than filling everyone's history with edits that changed nothing.
Adding tasks
One at a time, or a batch straight out of a workshop.
A single task
+ Add task asks for a name, workstream, owner, dates, status and priority, then opens the new task so you can fill in the detail.
A batch
+ Add several is for a post-workshop load — the way the 52 balance-sheet items under 1.6.1.6 and 1.6.1.7 went in. Choose the parent task first; the new items are created beneath it.
One per line — paste task names, one to a row, and optionally set a single owner and finish date for the whole batch:
Columns — paste straight out of Excel with a header row. Tabs or commas both work.
Recognised columns are name, owner, start, finish, priority, status, sprint, objective, notes and days. Dates must be written YYYY-MM-DD.
Always Preview first — it shows exactly what will be created. New tasks continue the parent's existing numbering and inherit its workstream.
The whole batch is checked before anything is created, so a bad date fails the lot with the row number rather than half-loading 65 items and leaving you to work out where it stopped. Fix that row and paste again.
Reordering the plan
Move a task among its siblings, or in and out a level.
On the Tasks tab each row has four arrows. Up and down move a task among its siblings; left and right move it out a level or nest it under the task above. Children always travel with their parent.
Reordering acts on the real plan order, so it is only offered on an unfiltered list. On a filtered view "move up" would mean "above the row you can see", which is a different task — an easy way to shuffle the plan by accident. Clear the filters and the arrows come back.
Only the siblings either side of the move are renumbered. Moving something under 1.1 will not renumber anything under 1.2 — outline numbers get quoted in conversation, so they stay put unless the move genuinely affects them.
How RAG is worked out
It is calculated from the real date, not stored and left to go stale.
You can override any task by picking a RAG value yourself — useful for Parked and At risk, which are judgements no rule can infer. Choosing Auto (from dates & progress) hands it back to the calculation. Tasks running on the calculation show a small auto marker.
Reports
The SLT pack, built from the plan and the compliance position.
Reports assembles what normally gets transcribed by hand: the performance scorecard, completeness, timeliness and turnaround, the weekly pair, plan health, each workstream's progress, and what has moved in the month you pick.
The window is a calendar month, because that is the unit the pack is built in. It opens on the first and closes at the end of the last day, so a change belongs to exactly one month and never to two. The month you are in is offered and reads so far, since it has not finished yet.
Download PowerPoint gives you the whole pack as a slide deck with real, editable charts — not pictures of charts, so they can be adjusted in the meeting. Copy as text puts the same thing on the clipboard. What is on screen is the deck: the slides are described once and drawn both ways, so the file cannot show you a figure the page did not.
It shows the halves you already have. With the plan but not compliance you get the plan half and a line saying why the other is missing, rather than nothing at all.
What the four measures mean
P&L, balance sheet, AP weekly run and VAT are all read the same way. Submitted is the share of what was due that came in. On time is the share of those that came in by the deadline. Turnaround is the average days late, counting only the late ones — including the on-time ones as nought would flatter it. A client the book excuses, such as one marked No BS Required, leaves that measure altogether rather than counting as either a success or a miss.
A measure the workbook does not carry is not scored. If an extract has no AP or VAT columns in it, those rows are named on the last slide instead of being drawn at 0% — nought is a claim about performance, and having no figures is not one.
Three things it deliberately will not do. It will not write the highlights — which of the week's changes mattered is a judgement, so it gives you what finished, started and slipped and leaves the sentence to you. It will not score a week that has not happened yet. And it says out loud what it cannot answer, rather than leaving the rows out, because a scorecard quietly missing a row reads as a complete one.
Profitability
What each client earns and what it costs to serve them, month by month.
Five tabs. Dashboard is the month at a glance. Clients is the full matrix — revenue, IT, labour, office recharge, profit and margin per client — which you can filter, sort and search. Movement compares the months loaded and names who turned a profit and who turned a loss. By controller totals each person’s book. People is hours against contract.
Loading a month
Load a workbook takes the monthly .xlsx. It is read in your browser — the file itself never leaves your machine, only the figures do. You are shown what was found and asked which month it is for before anything is saved, because not every edition of the workbook says.
A load replaces that month only. Every other month stays, so the book builds into a history rather than being whichever file went in last. The month-on-month movement is worked out from what is held here, not copied from the workbook’s own trend sheet.
What is yours and what is the workbook’s
Every figure comes from the workbook and is replaced whole when you load that month again. Action, Owner, Status and Notes are yours: type them on the Clients tab and press Save. No import ever overwrites them, and the Change log shows who wrote what and when.
This is the most closely held area in the app. It carries per-client margin and what each person costs, so nobody can see it until an administrator grants it on the people screen — administrators included.
Client scorecards
One client at a time, across everything the app knows about them.
A client losing money is one thing. A client losing money every month while filing late and raising service issues is another — and no single screen could tell you that before. The book lists every client worst first, with the months of profit as a small bar chart, the filing record beside it, and a line or two saying what stands out. Filter to Where we have money and compliance to see only the clients both systems know.
You see the halves your account already has. Without profitability the money is simply not there — not hidden on the screen, not sent.
Reading the book
Order matters more than it sounds. Sorting by the size of the loss shows you where the money is going; sorting by Worst margin shows you which relationships are actually broken, and they are rarely the same clients. A client losing £1,632 on £583 of fees is a worse relationship than one losing more on far more.
Each card carries two small charts on the same months — profit, and the share filed on time — so a client going backwards on both at once stands out. Open gives you everything behind it: the figures month by month, every month-end with its deadline and submission date, and the people whose biggest client this is.
Those people are who, not how much. The workbook records each person’s largest client and their total client hours, so the hours shown are theirs across every client — the hours that went into this one are in the figures above.
Service issues come from a different system that writes a description rather than a name. The screen says how many of those it could not attach to anybody, because a count of zero everywhere looks like good news and usually is not.
Names to link
Each system calls a client something different: the workbook groups it as Allsopps Group, compliance files it under ALLSOPP’S TAVERNS LIMITED across three codes. A spelling the registry already knows is linked for you. Everything else waits on this tab.
A close match is not proof. Big Mamma UK, US, Germany, Spain and Dubai all score 90% against “Big Mamma”, and they are five separate businesses with five separate P&Ls. Keep separate is the right answer for those, and it is remembered — it is a decision, not a way of putting the question off.
A name that is not linked yet still appears in the book, marked as such. It is better to see a client unresolved than not to see it at all.
Compliance
Month-end submissions, weekly reporting, and the root causes behind the late ones.
Five tabs. P&L and BS Dashboard is the month-end position by client, with the outstanding list and the root-cause analysis behind it. Weekly Delivery Control is the same month by working day. Weekly Report & Cashflow is the weekly reporting and cashflow cadence, week by week. VAT and Payment Runs (AP) are the same month-end view for those two.
VAT and Payment Runs
Both read the same way as the P&L and balance sheet: submitted is a dated submission, on time is that date on or before the deadline, and a client marked as owing none that month leaves the rates altogether rather than counting as either a success or a miss. Filter by month, FC, MA, and by what you want to see — everything outstanding, overdue only, submitted late only, or still pending.
The Root cause and Comments cells on the outstanding rows are boxes, not readouts — click one and type, and it saves when you press Save changes. Each measure keeps its own, so a note about a late payment run never overwrites one about a late P&L for the same client. Each tab's Change log shows who wrote what and when, for that measure alone; the Change log button above the tabs still shows everything. The Weekly Report & Cashflow tab works the same way, except that a note there belongs to one client, one metric and one week.
Neither is in the workbook yet. Until an extract carries them the two tabs say so and name the columns that would bring them, rather than showing empty charts or nought per cent. A payment run nobody has told us about is not a payment run that was missed.
The month, and why one might be missing
Pick a month on any tab and every tab follows, so two screens never show different months without telling you. The two sheets do not cover the same ground — the monthly sheet stops where the workbook stopped, the weekly one runs to the end of its last week — so if a tab cannot show the month you picked it shows its own latest and says so in a line above the tabs.
A month you cannot see is a month the workbook has not brought. The app holds what the extract gives it. Months now carry their year, so this June and next June are different months and a root cause written against one never reappears against the other, and each import adds its months to what is already here rather than replacing the lot. The weekly sheet works the same way, a week at a time, so a week that drops out of the workbook's window stays on this screen.
Recording a reason
In the Outstanding / Pending Items table the RCA and Comments cells are boxes, not readouts. Click one and type; it saves when you click away. They start blank because a root cause only exists once something has actually gone in late — an item still outstanding has no cause on record yet, which is exactly what you are there to supply.
The root-cause breakdown further down is a different population: submissions that went in late, and the causes already recorded against them. That is why the same client can be blank in one and filled in in the other.
Who changed what
Change log, at the top of the Compliance tab, is every edit anybody has typed: when, who, which client and month, which field, and both sides of the change. It is written on every save and cannot be turned off. If your account covers your own clients you see your own changes; if it covers everybody you see everybody's.
An update to the figures does not appear there, because it is not an edit. It has its own line in the provenance stamp above the tabs.
What an update keeps
Update figures replaces every number that comes from the workbook. It never touches anything typed in the app — root causes, comments, risk, the action plan — so a manual edit can never block or be overwritten by an update. Before you confirm, the preview names the clients whose typed fields will be kept, so you can see exactly what is carrying over rather than being told a number.
Your clients, or everybody's
Both the P&L and BS Dashboard and Weekly Delivery Control carry the same Deadline window as the improvement plan, over the month-end submission deadlines. A client is in the window if either its P&L or its BS is due in it. It starts on Any deadline, and every figure on the page — not just the tables — is recomputed from what the window leaves in, so the denominators move too. Where there is nothing to measure the rings read —, in grey, rather than a red nought.
Weekly Report & Cashflow counts whole weeks rather than deadlines, so it has a Week range instead: the next 2, 4 or 8 weeks, the last 2, 4, 8 or 13, or a custom range. A week is in if it overlaps the range at all — half a week of work is still that week's work — and a range crosses months on purpose, since a month holds only four or five weeks. While a range is set it is the authority, so Month and Week grey out; The month chosen above hands control back to them. The day-by-day schedule still needs a single week.
An account can be scoped to its own clients. Scoped that way, you see the ones where you are the FC or the MA and nothing else — every donut, table, root cause and count on the page is yours, not a filtered view of the company's. A line at the top says so, so a short list is never mistaken for data that failed to load.
Anyone who sees the whole book gets a roll-up by controller instead: a row per person, worst first, with their clients, what is overdue, what is still outstanding, what went in late, their submitted and on-time rates, and how many of their late items still have no root cause. Click a row and the whole page narrows to that person; click it again for everybody. It is built from the same rules as the cards below it, so the two can never disagree.
Scope is set per account in Admin → People, from the names that actually appear on a client. It is separate from what an account may change: somebody can read the whole book without editing any of it, or edit their own clients and see no others.
Late items with no cause yet
Open Show Root Cause Analysis and an amber panel lists every late item nobody has worked out a reason for. They are not blank — they carry the code Unknown, which is a real entry in the taxonomy, and they count as Unknown in every chart on the page until someone decides otherwise.
Pick a cause from the list beside each one. Choosing sets all five levels of the taxonomy together, so the combination is always a valid one, and it saves the moment you choose. The item drops off the list, the charts recount, and the next import of the workbook leaves your answer alone.
What is yours and what is not
The figures come from the compliance workbook and are replaced whole every time it is imported — deadlines, submission dates, statuses, the counts. Nothing you type here can change them, and nothing an import does can delete what you type. The line at the top of the page says when the figures were produced and when they were loaded.
Yours to fill in: root cause and comments on the outstanding list, risk and projected completion, and the whole action plan — suggested action, owner, target date, status and notes. Click into a cell, type, and press Save changes. Until you do, a red line says how many rows are waiting, and leaving the page will warn you.
Saving is immediate and shared. There is no export step and nothing to paste anywhere — everyone with compliance access sees your root cause the moment you save it.
Updating the figures
Update figures sits beside the line saying when they were produced. Two ways in, and they do exactly the same thing.
| Way | How it works |
|---|---|
| By hand | Choose the extract file. Before anything is written you are told what it holds — the date, the months, how many rows — and what it will replace. Nothing changes until you press Replace the figures. |
| On a schedule | At 6am on weekdays the site fetches the extract from a configured link and imports it. It refuses an extract older than the one already loaded, and records a failure rather than failing quietly. Until a link is configured it runs, finds nothing, and says so on the Automatic refresh tab. |
Either way, the numbers move and your analysis stays attached to the client and month it was written against. A field you have changed by hand keeps your value rather than reverting. What has been loaded lists every import, who did it, and the date of the figures.
An import is all or nothing. If it fails part way — a bad file, a dropped connection — the figures stay exactly as they were rather than ending up half replaced.
Tax & statutory
Accounts and returns by client and period — where each one has got to, what it is waiting on, and who would pick it up.
One row per obligation, per client, per period: statutory accounts, CT600, personal and partnership returns, P11Ds, confirmation statements, ATED. Five views across the top. Work tracker is the book. Hung is what has stopped and who it is waiting on. To-do list is every next action, the ones on a job and the ones that belong to nobody’s job. Handover is who holds what and who would take it on. Procedures is how the work is done, with the CIP task behind it.
Deadlines work themselves out
Give a job its period end and the deadline follows from the rule: nine months after the accounting reference date for accounts, twelve for a CT600, the 31 January after the tax year for a personal return, and so on. The payment date rides alongside where there is one. The drawer shows the rule it came from, so if you think a date is wrong you can see what it was derived from.
Where you have the registry’s own filing date, put it in and it wins. That is the ordinary case rather than the exception: Companies House counts from the actual accounting reference date, which is whatever day the company was incorporated on rather than a month end, and a first or shortened period moves it again. On our own book the rule and the registry agree on 341 accounts jobs and differ on 184. It costs no reason, because it is not a judgement — it is the fact the rule was trying to approximate. The rule is still worked out, and where the two disagree the row is marked registry and the drawer says what the rule would have given, which is worth knowing: it means the period is not what it looks like.
Where neither is right — an agreed extension — you can set the date by hand. That one costs a reason, which is what tells the next person why this job disagrees with the rule, and the job is marked as set rather than derived.
A job with no period end has no deadline and says so. It is never shown as due today, and the strip at the top counts how many are in that state, because an unknown deadline is a gap to fill rather than a date.
Open means live work
A real book carries rows that are not work at all: the client has left, the company is in liquidation, we are not doing it, they file it themselves, it is not required, or nobody has decided yet. About a fifth of ours. Every one still has a year end and a real filing date, so counting them as open would report a backlog nobody owes.
Say so on the job under Is this ours? and it drops out of the open count, the chase list and the handover, and its deadline stops being counted against anybody. It is never deleted — that is a decision somebody made, and a row that disappears is a decision nobody can find again. The strip shows how many there are, so Open jobs can be trusted to mean open jobs, and the Not ours filter finds them again.
The chase list
Everything where the ball is in the client’s court: the draft is with them, they have come back querying, or we asked for records and nothing has arrived. Ordered by deadline, not by how long they have had it — a fortnight on a draft due in March is not this morning’s call.
Days with them are counted from the last thing we did: the last chase, or the day the draft went out, or the day we asked for records. Where nobody recorded any of those it says not recorded rather than reading as a client who replied instantly. A job with no next chase date is not a chase due today; it is nobody having said when.
Stage and hold are different questions
Stage is how far the work has got. Waiting on is why it stopped, and who it stopped on — the client, HMRC, Companies House, another adviser, or us. A job can be at In progress and waiting on records, and both are true. The clock starts when the hold is recorded and does not restart when somebody re-states the same reason: three weeks waiting stays three weeks waiting.
Loading it from a workbook
Your own tracker will do — it does not have to be our template. Columns are found by name so you can put them in any order; a tab that is all one kind of work needs no Work column at all, because you tell it which kind the sheet is; and a workbook of several tabs is loaded a tab at a time. A tax year written 2025/26 is read as 5 April 2026.
Nothing is written until you have seen what it would do: which clients it found, which it did not, which jobs are already on the book, and every row it could not read with its line number. A cell it could not read is named by its column with the rows counted, and the row itself still loads — a phrase in an optional column is not a reason to refuse a real job. Running the same file twice adds nothing and overwrites nothing anybody has typed since.
Working papers
Each kind of work carries a checklist, and the drawer shows what is held and what is missing. What is recorded here is where the paper is, not the paper: the papers stay in the document management system, and a slot counts as held once somebody has said where to find it. A link that opens nothing is worse than no link, so a slot with nothing behind it stays empty.
The handover
Every job has a Successor — who would take it on. The handover view counts, per owner, how many of their open jobs have somebody named against them, how many are overdue, how many are hung, and how many have no deadline. An owner with nothing open reports nothing rather than 100%. Naming a successor is a field on the job, so the list fills in as the work is done rather than living in a separate spreadsheet.
Where it meets the rest
Procedures are held per kind of work and per stage, so one procedure is written once and shows on every job of that kind at the step it belongs to. A procedure can name the CIP task systemising it, and a job can link to one too — which is how somebody picking up unfamiliar work reads the method next to the step, and how whoever is improving that step can see everything it touches.
This area names clients’ tax affairs, so nobody can see it until an administrator grants it on the people screen — administrators included.
People and access
Admins can add colleagues and manage accounts.
If you are an admin you will see an Admin button in the header, from either area of the site. A number on it means someone is waiting for a password reset.
Access is held per area, so the presets are only a starting point: pick one, then change any line that needs it. Somebody who should read the plan but work the escalations, or see compliance and nothing else, is a couple of dropdowns rather than a new kind of account.
| Preset | What they can do |
|---|---|
| Administrator | All three areas, plus adding people, resetting passwords, and reading the account log. |
| Editor | Reads and changes the improvement plan and the service issues. The usual choice. |
| Read-only | Reads all three areas and changes none of them. Every editing control is hidden — no capturing, no bulk edits, no raising tasks. For anyone who needs the picture but not the pen. |
| Issues only | The escalation register and its detail, and nothing else. |
| Compliance only | The compliance dashboard and nothing else. |
| Custom | Anything the presets do not cover. Each of the three areas is set on its own to no access, view, or view and edit. |
| Action | What happens |
|---|---|
| Add person | Creates the account and shows a one-time password once. Pass it to them; they set their own on first sign-in. |
| Reset password | Issues a new one-time password and signs them out everywhere. Clears any outstanding request from that person, and restarts the 14-day clock. |
| Disable | Blocks sign-in and ends their sessions. Their name stays on the history of what they changed. |
The last active admin cannot be disabled or demoted — promote someone else first.
Password requests
When someone uses Forgotten your password? on the sign-in box, an amber panel appears at the top of People naming them, with whatever note they left. Reset password there does the same as the button on their row and shows the one-time code to pass on; Dismiss clears the request without changing anything, for when they got back in another way.
The site sends no email of any kind, so a request only ever reaches an administrator through this panel.
Accounts nobody has signed into yet
A new account carries a tag saying how long its one-time password has been waiting and how many days are left — amber under three days, red once it has expired. An expired code cannot be used; Reset password issues a fresh one. This is why nothing is lost by adding people ahead of time: the account stays, only the code goes stale.
Service issues
Escalations from the shared mailbox and Teams, alongside the plan.
The Service Issues tab shows the live escalation register. It is fed by the service-issues pipeline, which sweeps the mailbox and Teams on a schedule and applies its own triage and closure rules — this app only reads it. Editing an issue is done in that system, not here.
Unlike the plan, it needs a sign-in: issues name clients and carry risk ratings.
Turning an issue into a CIP task
Issues the triage rules flag as candidate improvement work are marked Potential. The amber CIP pill on the tab is how many of those are still open — not an unread count or a fault. Click it and you go straight to them; the same list is behind Only issues flagged as potential CIP.
The change log
Change log shows everything typed against an issue here, newest first, and every time two people or clients were merged into one record — both are changes to the same data. What the pipeline writes on its own sweep is not an edit made here and does not appear, so a change you expected and cannot find was almost certainly made in that system rather than this one.
Open one and use Raise a CIP task from this. The task is created pre-filled — the issue text as the name, its owner, priority from the risk rating, and the root cause in the notes — and the two are linked. The issue then reads In plan and links straight to the task.
The connection is recorded against the CIP task, never written back to the issues database. Two systems, one direction of travel: a change over there can never corrupt the plan here.
Audit trail
Two logs: what changed in the plan, and who had access.
Change log
Every edit is recorded as its own entry — which task, which field, the value before and after, who made it and when. Nothing overwrites it, and a person’s name stays on their entries even if their account is later removed.
Read it three ways: History at the foot of any task panel for that one task, Recent activity on the Exec Summary for the whole plan newest-first, and What changed in Roll-up grouped by task over a period you choose.
Account log
Admins get an Account log tab in Admin recording sign-ins, failed sign-in attempts, and every change to who has access — accounts created, enabled, disabled, access changed, password resets, and password requests. Failed attempts show the address that was tried; the password never is.
IP addresses are deliberately not logged. Say if you need them and they can be added.
Exporting
For sending on, or working offline.
Export CSV downloads the plan as it currently stands — outline, task, workstream, owner, participants, dates, sprint, percentage, status, RAG, priority, days, milestone, objective, latest update and notes. It opens cleanly in Excel.
The export reflects the live plan, not your current filters.
The two audit exports
Change log — the button under Recent activity on the Exec Summary. Every plan edit with when, who, task, field, and the before and after values. Needs a sign-in, because it names people.
Account log — in the Account log tab of Admin. Admins only.