# Worksynk: full content > Worksynk unifies work items, sprints, client collaboration, and AI-driven risk detection in one platform — so leaders always know what's on track and what isn't. Index of links: https://www.worksynk.app/llms.txt · Knowledge base: https://docs.worksynk.app ## Key facts - Worksynk is project delivery software for agencies, studios and in-house delivery teams. - Built by Fulgid Software Solutions Pvt Ltd. - Every paid plan is free for 90 days, with no credit card required. - Ships as 31 modules a workspace owner switches on. - Each active project gets a Delivery Confidence Score: it starts at 100, and overdue work, blockers, stale items, unowned critical work and review lag each subtract. - Includes a native MCP server, so Claude, ChatGPT, Cursor and other MCP clients can read and act on workspace data under policy. - Clients get a branded, permissioned portal for approvals, files and handoffs. - Contact: sales@worksynk.app, support@worksynk.app, security@worksynk.app (https://www.worksynk.app/contact). ## Pricing URL: https://www.worksynk.app/pricing ### Starter For small teams proving out a delivery process. Monthly: Free. Billed yearly: Free. - Up to 5 members - Unlimited work items & sprints - 1 workspace - Basic risk detection - Community support ### Team For teams that need delivery confidence, not just tracking. Monthly: $24/user/month. Billed yearly: $19/user/month. - Up to 25 members - Delivery Confidence Score - Client collaboration portal - GitHub & Figma integrations - AI agents (500 credits/mo included) - Priority support ### Business Top-tier for multi-team orgs that need governance, rollups, and scale. Monthly: $48/user/month. Billed yearly: $39/user/month. - Unlimited members - Executive rollups across workspaces - AI policies & approval workflows - Advanced audit & access logs - Dedicated onboarding - Custom contracts & procurement - Dedicated success engineer - Custom data residency - Uptime SLA & security review ## Platform ### Work items, sprints, and milestones in one hierarchy URL: https://www.worksynk.app/platform/work-items-sprints Tasks carry status, type, priority, assignee, and dates. Sprints pace the work, milestones give it a dated outcome, and timers make the hours honest enough to bill from. - Five statuses, fully customisable - Sprints and milestones - Timers, timesheets, billable hours #### From a task to a dated outcome 1. **Set the milestone**: A dated outcome the client is waiting on — beta launch, content migration complete — with tasks associated to it. 2. **Pace it in a sprint**: A fixed window with work in it, for teams that care about throughput over time. Velocity is derived from status categories. 3. **Track the hours**: Start a timer against the item. Timesheets, billable and unbilled splits, and utilisation all follow from it. 4. **Automate the repetition**: Workflows handle the when-this-then-that: status changes, assignments, notifications, and webhook calls. #### The delivery primitives, not a generic ticket queue - **Custom statuses**: Five ship by default. Rename, recolour, reorder, archive, or add your own. - **Types and priorities**: Classify work so the breakdown report tells you something useful. - **Views**: Board, list, and per-project views so each team sees its own slice. - **Comments and mentions**: Discussion sits on the work item, and mentions notify the right person. - **Recurring tasks**: Set a recurrence rule for weekly reports or monthly maintenance instead of recreating them. - **Timer security**: Controls that keep tracked time trustworthy enough to invoice from. #### What you get underneath - **Sprints** (Sprints): Timeboxed cycles with velocity derived from status categories, so throughput is comparable sprint to sprint. - **Milestones** (Milestones): Dated checkpoints that work rolls up to, and that delivery confidence scores against. - **Timesheets** (Time tracking): Per-person timesheets with billable and unbilled splits, feeding utilisation and invoicing. - **Capacity and utilisation** (Reports): Tracked hours against capacity per person — who is stretched and who has room. - **SLA targets** (SLA Management): Response and resolution deadlines per task, aware of business hours and holidays, with breach alerts before you miss. - **Workflows** (Workflows): Drag-and-drop automation for the repetitive parts of delivery, including signed webhook actions. - **Activity log** (Activity log): Every state change recorded, so 'when did this move' has an answer. #### Questions **Q: Can we keep our own workflow states?** A: Yes. Five statuses ship by default and you can rename, recolour, reorder, or archive any of them and add your own under Settings → Statuses. Velocity and reporting read from status categories, so the numbers keep working after you change the labels. **Q: Do we have to use both sprints and milestones?** A: No. Sprints suit teams working to a cadence who care about throughput; milestones suit dated outcomes a client is waiting for. Plenty of teams use one and not the other — both are modules you can leave off. **Q: Is tracked time good enough to invoice from?** A: That is the intent. Timers run against the work item, timesheets split billable from unbilled, and timer security settings exist specifically to keep the hours honest enough to bill. **Q: What happens to work that repeats?** A: Set a recurrence rule instead of recreating the task. The next instance appears on schedule, and editing the rule changes future instances rather than the history. ### AI that works over your real workspace data URL: https://www.worksynk.app/platform/ai-agents-mcp The assistant answers questions about live projects, tasks, and time — and can act on them. It can only do what you can do, and you decide up front whether it can write at all. - Scoped to your own permissions - Read-only unless you grant more - Connect Claude, ChatGPT, or Cursor #### Automation you can put in front of a security review 1. **Ask about the work**: Query real projects, tasks, and tracked time in plain language, and get a morning brief or a drafted standup. 2. **Inherit your permissions**: The assistant can only reach what your account can reach — it is not a back door around access control. 3. **Decide read or write up front**: Write access executes immediately over MCP, with no confirmation prompt — so grant read-only unless an assistant genuinely needs to change work. 4. **Connect your own host**: Point Claude, ChatGPT, Cursor, or another MCP host at the workspace and work from the tool you already use. #### Assistant, reporter, and an MCP server - **AI Assistant**: Ask about your work, draft standups, and get a morning brief over live data. - **AI Client Reporter**: Weekly client status drafted from what actually happened, for you to review before it sends. - **MCP server**: Claude, ChatGPT, Cursor and other hosts connect directly to the workspace. - **Voice input**: Dictate tasks, notes, comments, and instructions to the agent — read it back before saving. - **Credit tracking**: AI usage draws on workspace credits, visible before and after a run. - **Revocable access**: Review connected AI hosts and revoke any of them from settings. #### How the governance actually works - **Permission inheritance** (AI Assistant): The assistant operates strictly inside the permissions of the person asking. It cannot read a project you cannot read. - **Confirmation step** (AI Assistant): In the app, an action that changes data shows you what will happen before it runs. Over a connected MCP host there is no such step — a write tool executes when called. - **Pending AI actions** (AI Assistant): Action types can be held for a human to approve before they execute. - **Supported hosts** (MCP Server): Claude, ChatGPT, Cursor and other MCP-compatible hosts, with per-platform setup walkthroughs. - **Connection limits** (MCP Server): Each connection has defined access and limits, and can be reviewed or revoked at any time. - **Report review** (AI Client Reporter): Drafts are reviewed before they reach a client — the reporter proposes, a person sends. - **Call and action logs** (Activity log): MCP calls and AI actions are recorded against the workspace with full context. #### Questions **Q: Can the assistant see things a user should not?** A: No. It operates inside the permissions of the person asking. If you cannot open a project, neither can the assistant on your behalf. **Q: Will it change data without being asked?** A: In the app, no — an action that changes data shows you what will happen before it runs. Over a connected MCP host it can: a write tool executes the moment it is called, with no confirmation prompt. That is why connections default to read-only, and why you should only grant write access to a host that genuinely needs it. **Q: Which AI hosts can connect over MCP?** A: Claude, ChatGPT, Cursor and other MCP-compatible hosts. Each has its own setup walkthrough, and every connection can be reviewed or revoked from settings. **Q: How is AI usage billed?** A: Usage draws on workspace AI credits. Consumption is visible in the workspace, so spend is something you can watch rather than discover. ### A delivery confidence score, captured daily URL: https://www.worksynk.app/platform/delivery-confidence One score per project, computed from overdue work, blockers, movement, and milestone progress — and snapshotted every day, so you see it trending rather than only today's number. - Daily snapshots, not a one-off - Risk patterns and blocker radar - A prompt to look, not a verdict #### From a falling number to the work behind it 1. **Score from real signals**: Overdue work, blockers, movement, and milestone progress combine into one number per project. 2. **Capture it daily**: A snapshot every day means you read the trend, not just today's reading. 3. **Spot the pattern**: Risk patterns surface recurring shapes that precede trouble — work reopened repeatedly, concentration on one person, blockers that never clear. 4. **Clear the blocker**: Blocker radar shows what is blocked, what it is waiting on, and who owns the thing in the way. #### Three signals, one place to act - **Delivery confidence**: Per project, from overdue work, blockers, movement, and milestone progress. - **Daily snapshots**: Captured every day, so the direction of travel is visible. - **Risk patterns**: Reopened work, single-person concentration, and blockers that never clear. - **Blocker radar**: What is blocked, what it waits on, and who owns the blocker. - **Executive summary**: Every active project on one line, with its delivery confidence. - **SLA compliance**: Response and resolution performance against your targets. #### What feeds the number - **Overdue work** (Analytics): Items past their date, weighted into the project's score. - **Blockers** (Analytics): Blocked work and how long it has been waiting, surfaced through blocker radar. - **Movement** (Analytics): Whether work is actually progressing through statuses, or sitting still. - **Milestone progress** (Milestones): Progress against the dated outcomes the project is measured on. - **Workload balance** (Reports): Who is carrying too much, scored from open work, overdue items, and hours. - **SLA breaches** (SLA Management): Response and resolution targets missed, with alerts before the deadline passes. - **Executive rollup** (Reports): Every active project on one line with its score, for owners and admins. #### Questions **Q: Is the score a prediction?** A: No, and the product is explicit about this. It is a decision aid computed from your data. A low score is a prompt to look at something, not a verdict on whether the project will land. **Q: What exactly goes into it?** A: Overdue work, blockers, movement through statuses, and milestone progress. Because each input is real work in the workspace, you can open the items driving a change rather than trusting a number. **Q: Can we see how it changed over time?** A: Yes. The score is captured daily, so you read it as a trend. A project drifting down over a fortnight is a different conversation from one bad day. **Q: Who can see the executive view?** A: The executive summary and workload reports are visible to owners and admins only, and depend on the Analytics module being enabled. ### A client view of their work, without giving them a seat URL: https://www.worksynk.app/platform/client-collaboration The portal gives clients read-only visibility of progress, updates, and approvals — under your branding, and without consuming a workspace seat. - No seat consumed - Your branding, not ours - Handoff with a certificate #### From client record to signed-off handoff 1. **Create the client record**: Link projects, contacts, and commercial detail so you can answer how the account is doing, not just the project. 2. **Give them visibility**: A portal, a status link, or an external member seat — three levels depending on how much access is appropriate. 3. **Report on cadence**: The AI client reporter drafts a weekly status from real activity, for you to review before it goes. 4. **Close it out**: Handoff packages the deliverables, captures confirmation, and issues a certificate. #### Three ways to let a client see progress - **Client portal**: Read-only view of their projects, progress, updates, and approvals. - **Client records**: Projects, contacts, and commercial detail for one customer in one place. - **White-label branding**: Your name, colour, and logo across every surface a client sees. - **Handoff**: Package deliverables, get confirmation, issue a certificate. - **Invoicing**: Client invoice reporting built from tracked billable time. - **Shared notes**: Notes and decisions shared outside the workspace when they should be. #### Access, matched to the situation - **Portal** (Client portal): A persistent read-only view of their projects. Does not consume a workspace seat. - **Status link** (Client portal): A lighter share for when a client needs to see progress without an account at all. - **External member** (Clients): For a client who genuinely needs to participate, scoped to specific projects. - **Branding** (White-label branding): Replaces Worksynk's name, colour, and logo with yours everywhere clients look. - **Handoff certificate** (Handoff): A record that the client confirmed receipt, rather than a remembered conversation. - **Weekly reporter** (AI Client Reporter): Drafted from real activity — work completed, what is next, and risks worth flagging. - **Budgets and margin** (Budgets): Retainers, profitability, and what has not been invoiced yet. #### Questions **Q: Does a client in the portal use up a seat?** A: No. The portal is a client-facing read-only view specifically so you can give visibility without consuming a workspace seat. **Q: What is the difference between the portal and a status link?** A: The portal is a persistent view of their projects with updates and approvals. A status link is lighter, for when a client just needs to see progress. An external member seat is the third option, for clients who need to participate directly. **Q: Can it look like our studio rather than Worksynk?** A: Yes, with white-label branding — your name, colour, and logo replace ours across the surfaces your team and clients see. **Q: How do we prove a client signed off?** A: Handoff packages the deliverables, captures the client's confirmation, and issues a certificate — so sign-off is a record rather than a recollection. ### Connect the tools your team already works in URL: https://www.worksynk.app/platform/integrations Link repositories so commits and pull requests sit with the work they reference, schedule calls against a project, and push signed events to your own systems. - GitHub and other code hosts - Zoom, Google Meet, and Teams - Signed, verifiable webhooks #### Connect once, then stop re-keying 1. **Connect the provider**: Code hosts, chat, design, meetings, and email are configured under Settings → Integrations, some per project. 2. **Reference the work**: Mention a work item in a commit or pull request and it attaches to the item automatically. 3. **Import what exists**: Bring a backlog over from another tool rather than re-entering it by hand. 4. **Push events onward**: Webhooks deliver signed events to your systems, and back webhook actions inside workflows. #### Where Worksynk plugs in - **Code hosts**: GitHub and other hosts — commits, branches, and pull requests attach to work. - **Meetings**: Zoom, Google Meet, and Teams scheduled against a project, with AI follow-ups. - **Design**: Figma design links kept next to the item they describe. - **Webhooks**: Signed event delivery with verification and full delivery history. - **Import jobs**: Move an existing tool across without a manual re-key. - **Email intake**: Turn inbound mail into work, with quarantine for anything unexpected. #### Integration detail - **Repository linking** (GitHub): Link repositories to projects so code and work sit together, with sync logs per connection. - **Other code hosts** (Integrations): Generic git-host support for teams not on GitHub. - **Signed webhooks** (Webhooks): Deliveries are signed so your endpoint can verify they genuinely came from Worksynk. - **Destination validation** (Webhooks): Webhook destinations are validated rather than blindly called. - **Delivery history** (Webhooks): Every attempt recorded, so a failed delivery is diagnosable. - **Meeting follow-ups** (Meetings): Reminders before the call and AI follow-ups after it, against the project. - **AI hosts** (MCP Server): Claude, ChatGPT, and Cursor connect as first-class consumers of the same data. #### Questions **Q: Do we have to use GitHub?** A: No. GitHub has first-class support, and there is generic git-host support for teams on something else. Both link repositories to projects so commits and pull requests attach to the work they reference. **Q: How do we verify a webhook really came from Worksynk?** A: Deliveries are signed, so your endpoint can verify the signature. Destinations are validated when you create them, and every delivery attempt is recorded so failures are diagnosable. **Q: Can we migrate from our current tool?** A: Yes — import jobs bring existing work across rather than asking someone to re-key a backlog. **Q: What happens after a meeting?** A: Meetings are scheduled against a project with a join link, reminders go out beforehand, and AI follow-ups capture what came out of the call next to the work it concerns. ### Time tracking and budgets that turn hours into margin URL: https://www.worksynk.app/platform/time-budgets Timers and timesheets on every plan, budgets that warn at 80% and 100%, and profitability and unbilled time computed from the hours your team actually logged. - Timers and timesheets on every plan - Budget alerts before overrun - Unbilled time never forgotten #### From a running timer to a clean invoice 1. **Track against the task**: Start a timer from a task or the top bar. One timer runs per person, and a timer left running overnight shows up in the morning digest. 2. **Review the timesheet**: Hours are checked and corrected on the timesheet before anyone bills from them. Owners can fix an entry logged to the wrong project. 3. **Watch the budget burn**: Set a project budget in hours or value. Consumption tracks as time is logged, and crossing a threshold notifies owners and admins. 4. **Bill it and mark it billed**: Unbilled and client-invoice reports list what was delivered but not invoiced. Mark time billed once it is on an invoice. #### Everything between the timer and the margin - **Timers and timesheets**: Start from a task or the top bar, one running timer per person, and a timesheet to review hours before anyone bills from them. - **Budget thresholds**: Alerts at the thresholds you set, commonly 80% and 100%, in owners' notifications and daily digest. - **Profitability**: Cost against value per project and per client, from your people's cost and bill rates. - **Unbilled time**: Billable hours worked but never invoiced, one row per entry. - **Capacity and utilisation**: Tracked hours against capacity per person: who is stretched, who has room. - **Timer security**: Require location, a known network, or both before a timer can start. #### Time and budget detail - **One timer per person** (Time tracking): Only one timer runs at a time for each person, so hours cannot be double-counted across tasks. - **Forgotten timers caught** (Time tracking): A timer left running from a previous day appears in the morning digest instead of quietly inflating a client's hours. - **Owner corrections** (Time tracking): Workspace owners can edit or delete a completed entry after the fact. - **Hours or value budgets** (Budgets and profitability): Budget a project in hours or in value, and consumption tracks against it as time is logged. - **Rate-based margin** (Budgets and profitability): Profitability uses cost and bill rates set on your people; without rates, hours are counted but margin is not. - **Client invoice report** (Budgets and profitability): Unbilled time for one client over a date range, ready to invoice from. - **Location or network proof** (Timer Security): Timers can require the browser's location, a recognised IP, or both. #### Questions **Q: Is time tracking on every plan?** A: Yes. Timers and timesheets are on every plan and switched on by default. Budgets, profitability and timer security are modules you switch on under Settings → Modules. **Q: What happens when a project nears its budget?** A: You set thresholds on the budget, commonly 80% and 100%. When one is crossed, owners and admins are notified and it appears in their daily digest, so an overrun surfaces while there is still time to act. **Q: Why does profitability show hours but no margin?** A: Margin needs cost and bill rates set on your people under Settings → Members, which only admins can do. Without rates, hours are counted but cost and value cannot be. **Q: Does timer security track where people are?** A: Only when a timer starts, and only if you enable it: the browser shares location, the timer must start from a recognised network, or both. Tell the team first, and check your local obligations around employee location data. ### Reports and analytics that show their working URL: https://www.worksynk.app/platform/reports-analytics A catalogue of team, time, work, financial and executive reports, a Summary / Detail switch that shows the rows behind every total, and delivery analytics captured daily. - Summary / Detail on every total - Export exactly what you see - Client reports drafted for you #### From a question to an answer you can defend 1. **Pick from the catalogue**: Reports are grouped by subject (team, time, work items, financial, executive) and only list what you can run. 2. **Set the range and run**: Most reports take a date range. Nothing is calculated until you press Run report, and Update re-runs without leaving the page. 3. **Switch Summary to Detail**: Totals say how much; Detail says which ones, down to every time entry, work item or priced timer. 4. **Export or send it on**: Export CSV downloads exactly the rows and columns you are looking at, and the AI Client Reporter drafts the client-facing version. #### Every question a delivery lead gets asked - **Executive summary**: Every active project on one line with its delivery confidence, or the eight most at risk. - **Utilisation**: Tracked hours against capacity per person, with each person's hours split per project. - **Workload and load balance**: A score per person from open work, overdue items and hours, with each factor behind it. - **Profitability**: Cost and margin per project, down to every timer priced individually. - **Delivery analytics**: Confidence captured daily, risk patterns that precede trouble, and a blocker radar. - **AI Client Reporter**: A client status report drafted from real activity on your cadence, sent only after you approve it. #### Reporting detail - **Summary / Detail switch** (Reports): Time logged, work items, utilisation, workload, profitability and the executive summary each show their working. - **Row drill-down** (Reports): In Utilisation Detail, open any row to see the work items behind that person's hours on that project. - **Honest limits** (Reports): A detail table returns up to 1,000 rows and says so when it hits the limit, so you narrow the range instead of trusting a truncated table. - **Exact exports** (Reports): Export CSV downloads the rows and columns currently shown, including which view you chose. - **Daily confidence snapshots** (Analytics): Delivery confidence is captured daily, so you read the trend rather than only today. - **Risk patterns and blocker radar** (Analytics): Work repeatedly reopened, concentration on one person, and blockers that never clear, with who owns the thing in the way. - **Reviewed client reports** (AI Client Reporter): A drafted report is a first draft; approving it is a deliberate step that cannot be skipped. #### Questions **Q: Why can't I see a report my colleague can?** A: The catalogue only lists reports you have access to, and project access limits what they include. Financial reports also need the Budgets module and rates on your people. **Q: Why do some reports have no date filter?** A: Because they don't use one: workload always scores the last seven days, and the executive summary is a snapshot of right now. They show no period filter rather than one that does nothing. **Q: Is the delivery confidence score a prediction?** A: No. It is a decision aid computed from your own data: overdue work, blockers, movement and milestone progress. A low score is a prompt to look, not a verdict. **Q: Will the AI Client Reporter email a client on its own?** A: No. It prepares a draft on the cadence you set; it sits waiting until someone reads, edits and approves it, and approving is what sends it. ### Security and governance built for a client review URL: https://www.worksynk.app/platform/security-governance An encrypted credential vault AI can never read, IP allowlisting, a workspace activity log and project-level roles: the controls enterprise clients ask about before feature questions. - Vault contents never reachable by AI - IP and CIDR allowlisting - A searchable audit trail #### Four layers, each narrowing the last 1. **Roles decide visibility**: A workspace role plus a role per project decides whether someone sees a project at all, and that also limits reports, search and connected AI tools. 2. **Restrict the network**: IP Whitelist limits workspace access to the addresses and CIDR ranges you nominate, such as an office or a VPN egress. 3. **Keep secrets in the vault**: Client credentials live encrypted against their project, with a one-time code available as a second check before anyone views one. 4. **Audit what happened**: The Activity Log records logins, role and membership changes, settings and module changes, and integration changes. #### The controls a security questionnaire asks for - **Credential Vault**: Encrypted at rest, decrypted only when someone with access views it, and never reachable by AI assistants or integrations. - **Logged credential views**: Every view recorded on the credential itself: who opened what, and when. - **IP Whitelist**: Workspace access limited to nominated addresses and CIDR ranges. - **Activity Log**: A searchable, filterable record of consequential actions across the workspace. - **Project-level roles**: Owner, manager, account manager, member and viewer per project, or your own roles. - **Custom SMTP**: Workspace email sent through your own server, with credentials stored encrypted. #### Governance detail - **AI-proof vault** (Credential Vault): Vault contents are never reachable by connected AI assistants or third-party integrations, whatever access they hold. - **One-time code to view** (Credential Vault): Viewing a credential can require a code sent to you, so a borrowed session is not enough to read secrets. - **Access follows the project** (Credential Vault): Vault access follows project access, so removing someone from a project removes their vault access too. - **Ranges, not just addresses** (IP Whitelist): Allow CIDR ranges for dynamic connections, or a VPN's stable egress for travelling teams. - **Admin audit trail** (Activity Log): Owners and admins filter by action and by person; entries show the actor, what changed and when. - **Two layers of roles** (Workspaces and people): Workspace owners and admins see every project; everyone else sees only projects they are a member of. - **Timer proof** (Timer Security): Billed hours can require location or a known network when a timer starts. #### Questions **Q: Can a connected AI assistant read our client credentials?** A: No. Vault contents are deliberately never reachable by connected AI assistants or third-party integrations, whatever access they have been granted, and that restriction cannot be configured away. **Q: Will IP whitelisting lock us out?** A: It can if you forget yourself. Add your current address, or your connection's range, before enabling it. For remote teams, allow a VPN's stable egress rather than individual addresses. **Q: What does the Activity Log record?** A: Logins, membership and role changes, settings updates, module changes, integration and OAuth application changes, and other administrative actions. For who moved a task, the task's own history is the better place. **Q: Where is the full list of controls?** A: The Security page lists every control with the module it lives in, and we will answer the detail behind any of them for a formal review. ### Meetings, notes and files kept next to the work URL: https://www.worksynk.app/platform/meetings-knowledge Schedule Zoom, Google Meet and Teams calls against a project, keep notes and files beside the work they concern, and automate the repetitive parts of delivery. - Meetings, notes and files on every plan - AI follow-ups you approve - Visual workflows, no code #### From the call to the next piece of work 1. **Schedule against the project**: Connect Zoom, Google Meet or Teams once; a meeting then creates the call, attaches the link and reminds attendees. 2. **Write it down beside the work**: Notes start personal and can be shared with the workspace or attached to a project, where people actually look. 3. **Turn outcomes into work**: With the AI Assistant on, a meeting drafts follow-up tasks as proposals you review and confirm. 4. **Automate what repeats**: Recurring tasks respawn when the last one is finished, and workflows run a trigger, conditions and actions for you. #### The work around the work - **Meetings**: Zoom, Google Meet and Teams calls scheduled against a project, on the calendar with a join link and reminders. - **Notes**: Personal or shared, attached to a project, with reminders and read-only published links. - **File storage**: Attachments on tasks and projects that inherit the project's access. - **Workflows**: Drag-and-drop automation: triggers, conditions, and actions like assign, post, webhook or an AI step. - **Recurring tasks**: Work that repeats, spawned when the last occurrence is completed or closed. - **Voice input**: Dictate tasks, notes, comments and agent instructions, reviewed as text before anything is saved. #### Meetings and knowledge detail - **Three meeting providers** (Meetings): Connect Zoom, Google Meet or Microsoft Teams under Settings → Integrations and scheduling creates the call. - **Follow-ups as proposals** (Meetings): Drafted follow-up tasks are reviewed and confirmed; nothing reaches the board without a person approving it. - **Published notes** (Notes): A note can be published as a read-only link for people without an account; secrets belong in the vault, never in a note. - **Access by project** (File storage): Files are scoped to the project, so project access governs who sees them; share with clients through the portal. - **No piled-up copies** (Recurring tasks): The next occurrence spawns when the current one is completed or closed, so a slipped task never stacks unfinished duplicates. - **Signed webhook actions** (Workflows): A workflow can call your own systems using the same signed-webhook mechanism as Webhooks. - **Confirm before create** (Voice Input): Spoken instructions to the agent show the action they will take and wait for you to confirm. #### Questions **Q: Which meeting tools are supported?** A: Zoom, Google Meet and Microsoft Teams. Connect one under Settings → Integrations and scheduling a meeting against a project creates the call and attaches the link. **Q: Does the AI create tasks from meetings by itself?** A: No. With the AI Assistant enabled, a meeting can draft follow-up tasks, but they are proposals you review and confirm; nothing appears on the board without a person approving it. **Q: Why didn't my recurring task create a new copy?** A: The next occurrence spawns when the current one is completed or closed, not on a fixed calendar tick, so a task that slipped doesn't silently pile up unfinished copies. **Q: Can workflows call our own systems?** A: Yes. A workflow action can call a webhook, using the same signed mechanism as Webhooks, alongside assigning people, posting to a linked chat channel, or running an AI step. ## Solutions by role ### Project management software for agencies, kickoff to handoff URL: https://www.worksynk.app/solutions/agencies-studios Client records, a branded portal, budgets that show margin, and a handoff certificate at the end — so an engagement lives in one place instead of three. - Branded client portal - Retainers and margin - Handoff with sign-off #### The engagement, end to end 1. **Scope and budget it**: Set a budget on the project so tracked time turns into profitability and unbilled answers later. 2. **Watch the drift**: Risk patterns and blocker radar surface trouble while there is still room to have the conversation. 3. **Keep the client close**: A portal under your branding, plus a weekly report drafted from real activity. 4. **Hand off and invoice**: Package deliverables, capture confirmation, issue a certificate, and bill the unbilled time. #### What studios reach for first - **Client portal**: Read-only client visibility that does not consume a seat. - **White-label**: Your brand across every surface the client sees. - **Budgets and margin**: Retainers, profitability per project and client, and threshold alerts. - **Unbilled time**: Billable hours worked but never invoiced, surfaced as a report. - **Handoff**: Deliverables packaged, confirmed, and certified. - **Vault**: Client credentials encrypted, with every access logged. #### The commercial side - **Profitability** (Budgets): Cost against value, per project and per client. - **Threshold alerts** (Budgets): Get warned as a retainer burns down, not after it is gone. - **Unbilled report** (Reports): Billable hours worked but never invoiced — usually the fastest money in the building. - **Utilisation** (Reports): Tracked hours against capacity per person, so you can see who is stretched. - **Credential vault** (Vault): Client secrets encrypted with logged access and extra verification, instead of sitting in a chat message. - **Client invoice view** (Reports): Invoice reporting built from tracked billable time. - **Per-client SLA targets** (SLA Management): Response and resolution targets per priority, aware of your working hours and holidays, with automatic breach alerts to the channel that owns the account. - **Weekly report, drafted** (AI Client Reporter): A client status report drafted from what actually happened that week, for you to review and edit before it sends. - **Recurring account work** (Recurring tasks): Monthly retainer summaries, reporting, and check-ins repeat on a schedule and spawn the next occurrence when closed. - **Your brand, not ours** (White-label branding): The portal, the reports, and the emails carry your studio's brand everywhere the client looks. #### Questions **Q: Can clients see progress without paying for seats?** A: Yes. The client portal is a read-only client-facing view that does not consume a workspace seat, and there is a lighter status link if even that is more than they need. **Q: Will it look like our studio?** A: With white-label branding, your name, colour, and logo replace Worksynk's across every surface your team and clients see. **Q: How do we know a project is profitable?** A: Set a budget, track time against the work, and the profitability report gives you cost against value per project and per client. Threshold alerts warn you as a retainer burns down. **Q: Where do client credentials live?** A: In the vault — encrypted, with every access logged and extra verification available. The point is that they are not in a chat message or a spreadsheet. **Q: How long before a client is actually using the portal?** A: Usually the first week, because there is nothing for them to learn — the portal shows the work your team is already updating. The change that matters is on your side: deciding what each client sees by default and then leaving it alone. **Q: We work differently per client. Does that break reporting?** A: No. Statuses, types, and workflows are configurable, and each project can carry its own. Reporting stays comparable because it keys off the status category — Todo, In Progress, In Review, Done — not the label you gave it. **Q: Can we turn off time tracking for one client?** A: On some plans a module can be switched off for an individual project even when it is on for the workspace, which is exactly the case for a client whose engagement should not carry time tracking or budgets. ### Delivery risk visibility for engineering leaders URL: https://www.worksynk.app/solutions/engineering-leaders Link repositories so code sits with the work it closes, then let blocker radar and risk patterns show you where delivery is actually stalling. - Commits and PRs attach to work - Blocker radar - No extra process for engineers #### Signal from work engineers already do 1. **Link the repositories**: Connect GitHub or another code host and link repos to projects, with sync logs per connection. 2. **Reference work in commits**: Mention an item in a commit, branch, or pull request and it attaches automatically. 3. **See what is blocked**: Blocker radar shows what is waiting, on what, and who owns the thing in the way. 4. **Catch the pattern**: Work reopened repeatedly and load concentrated on one person are both flagged as risk patterns. #### For the person asked why it slipped - **Repository linking**: GitHub and generic git hosts, linked per project with sync logs. - **Blocker radar**: What is blocked, what it waits on, and who owns the blocker. - **Risk patterns**: Reopened work and single-person concentration surfaced automatically. - **Workload balance**: Who is carrying too much, from open work, overdue items, and hours. - **SLA targets**: Response and resolution deadlines, aware of business hours and holidays. - **Activity log**: Every state change recorded and queryable. #### What you can hand to a delivery review - **Confidence trend** (Analytics): Daily snapshots per project, so a slide is visible as a trend rather than a surprise. - **Blocked work** (Analytics): Blocker radar with ownership, so the conversation has a named next step. - **Reopened work** (Analytics): A risk pattern that usually means the definition of done is not landing. - **Concentration risk** (Analytics): Flags when too much of a project depends on one person. - **SLA compliance** (SLA Management): Performance against response and resolution targets, with breach alerts. - **Webhook events** (Webhooks): Signed events into your own systems when work changes state. #### Questions **Q: Does this add process for engineers?** A: No. Once repositories are linked, referencing a work item in a commit, branch, or pull request is enough for it to attach. There is no extra field to fill in. **Q: What if we are not on GitHub?** A: There is generic git-host support alongside first-class GitHub support, so repositories can be linked either way. **Q: How do we see what is actually holding a sprint up?** A: Blocker radar shows what is blocked, what it is waiting on, and who owns the blocker — which is usually a more actionable answer than a burndown chart. **Q: Can events flow into our own tooling?** A: Yes. Webhooks deliver signed events to your systems, with destination validation and a full delivery history for debugging. ### PMO software for consistent delivery across teams URL: https://www.worksynk.app/solutions/pmo-ops One delivery model and one set of definitions across every team, without slowing anyone down — modules, statuses, and workflows each workspace can shape to fit how it actually works. - Modules on or off per workspace - Custom statuses and workflows - Governance you can evidence #### Consistency without a change-management project 1. **Define the model**: One hierarchy of milestones, sprints, and work items, with statuses mapped to categories so reporting stays comparable. 2. **Enable what fits**: Modules are switched on per workspace, so teams get what they need without carrying what they do not. 3. **Measure the same way**: Delivery confidence and SLA compliance mean the same thing across every team. 4. **Evidence the governance**: Activity logs, credential access logs, login history, and AI action records ready for review. #### The controls a PMO gets asked for - **Modules per workspace**: Enable sprints, milestones, analytics, SLAs and more where they fit. - **Custom statuses**: Renamed and reordered per team, still mapped to categories for reporting. - **Workflows**: Drag-and-drop automation for the repetitive parts of delivery. - **SLA policies**: Targets with business hours, holidays, and automatic breach alerts. - **Access logs**: Login history and credential access recorded per user. - **Executive rollup**: Every active project on one line with delivery confidence. #### Governance surfaces - **Activity log** (Activity log): Every state change across the workspace, recorded and queryable. - **Login history** (Workspaces): Per-user sign-in records for access reviews. - **Credential access log** (Vault): Who opened which secret and when, with extra verification available. - **IP whitelisting** (IP whitelist): Restrict workspace access to known networks. - **AI action records** (AI Assistant): What the assistant did, on whose behalf, and whether a human confirmed it. - **SLA reporting** (SLA Management): Compliance against response and resolution targets over time. - **Signed webhooks** (Webhooks): Verifiable event delivery into downstream systems. #### Questions **Q: Do all teams have to work the same way?** A: No — that is usually why standardisation fails. The hierarchy and the definitions stay consistent, but modules, statuses, and workflows are configured per workspace so each team keeps the parts that fit its work. **Q: How do we keep reporting comparable if teams rename statuses?** A: Statuses map to categories. Teams can rename, recolour, and reorder freely, and velocity and reporting continue to read from the underlying category. **Q: What can we show a security reviewer?** A: Activity logs, login history, credential access logs, AI action records, and IP whitelisting — all product surfaces rather than policy documents. **Q: Can SLAs account for our working hours?** A: Yes. SLA policies are aware of business hours and holidays, and warn you before a response or resolution target is missed rather than after. ### An executive dashboard for every active project URL: https://www.worksynk.app/solutions/executives The executive summary puts each project on a single row with its delivery confidence — and because the score is captured daily, you get direction of travel rather than a snapshot. - One row per active project - Daily confidence trend - Owners and admins only #### The answer before the meeting 1. **Open the summary**: Every active project on one line, with its current delivery confidence. 2. **Read the direction**: Daily snapshots mean you see which way a project is moving, not just where it sits. 3. **Find the cause**: Risk patterns and blocker radar name the reopened work, the overloaded person, or the blocker nobody cleared. 4. **Check the commercials**: Profitability and unbilled time sit alongside delivery health for owners and admins. #### Summary and evidence in one place - **Executive summary**: Every active project on one line, with delivery confidence. - **Confidence trend**: Captured daily, so direction of travel is visible. - **Profitability**: Cost against value, per project and per client. - **Unbilled time**: Billable hours worked but never invoiced. - **Workload**: Who is carrying too much, across teams. - **Overview dashboard**: The at-a-glance view across the workspace. #### What sits behind the rollup - **Executive summary** (Analytics): One line per active project with its confidence score. Depends on Analytics being enabled. - **Daily snapshots** (Analytics): Confidence captured every day, so trends are readable rather than inferred. - **Profitability** (Budgets): Requires the Budgets module and rates set for your people. - **Unbilled time** (Reports): Billable hours that have not been invoiced yet. - **Workload and balance** (Analytics): Scored from open work, overdue items, and hours per person. - **SLA compliance** (SLA Management): How the organisation is performing against its own targets. - **Role restrictions** (Workspaces): Financial and executive reports are visible to owners and admins only. #### Questions **Q: Who can see the executive and financial reports?** A: Owners and admins only. Financial reporting also depends on the Budgets module and on rates being set for your people. **Q: Is the confidence score comparable across teams?** A: Yes, because it is computed the same way everywhere — overdue work, blockers, movement, and milestone progress — even when teams have renamed their statuses. **Q: Can I see why a project dropped?** A: Yes. Risk patterns and blocker radar name the cause, and every input is real work you can open from the score. **Q: Do I need to ask someone to build this report?** A: No. It is a standing view that reads live data, which is generally the point — nobody should be assembling a portfolio slide by hand. ### Task management in VS Code, Figma, and Framer URL: https://www.worksynk.app/solutions/developers-designers First-party extensions for VS Code, Figma, and Framer. Select something, file the task, and the selection, file path, or frame comes with it — no tab switch, no re-typing. - 10+ editors, one extension - Figma and Framer plugins - Connect with an API key #### Install once, then file work from where you already are 1. **Install the extension**: Worksynk in the VS Code marketplace, or import the Figma and Framer plugins. Same account, same workspace. 2. **Paste an API key**: Create a personal access token under Settings → API keys and paste it once. The extension remembers your workspace and last project. 3. **Create from the selection**: Highlight code, or select a frame on canvas. The title, file path, and design link fill themselves in. 4. **Work it without switching**: Assign, set priority, move to review, mark done, and leave notes with @mentions — from inside the editor or the design tool. #### Three first-party extensions, not a REST tutorial - **VS Code extension**: Create tasks from code. Selection and file path attach automatically. Works in Cursor and Antigravity too. - **Figma plugin**: Create an issue from a frame and it links automatically. See issues on the current selection. - **Framer plugin**: Templates, notes with @mentions, screenshots on create, and the published design URL filled in for you. - **MCP for AI hosts**: Separate from the extensions: point Claude, ChatGPT, or Cursor's agent at 31 tools over MCP. - **Git activity**: Reference a task in a commit, branch, or PR title and it attaches to the work. - **Signed webhooks**: Push events into your own tooling, signed so you can verify them. #### What each extension actually does - **VS Code: task from code** (Extensions): Pick a project, set a title, choose an assignee. The highlighted selection and the file path are attached to the task without being asked for. - **VS Code: editor coverage** (Extensions): Built against the VS Code extension API, so it runs in VS Code, Cursor, Antigravity, Windsurf, VSCodium, Trae, Kiro, Void, Firebase Studio, and any other fork that loads a VSIX. - **Figma: issues on the selection** (Extensions): List the issues linked to the current frame, section, or page; create a new one that links itself; or search and link an existing issue. Assign and mark done in place. - **Framer: templates and capture** (Extensions): Task, Feedback, Review, Content and Polish templates set type, priority and title prefix. Attach a screenshot by paste, file, or the selected image layer. - **Framer: notes with mentions** (Extensions): Rich-text notes with @mentions that notify people, and reference tasks and projects as chips — the same behaviour as the portal. - **Framer: design URL** (Extensions): The design URL becomes a chip on the task, auto-filled from your published Framer site so the task points back at the live design. - **Framer: triage in place** (Extensions): Search by code or title, filter Open, New, Doing, Review or All, and Start, Review, Done, Assign or Note any row without opening the portal. - **MCP server** (MCP Server): For AI hosts rather than editors: 18 read tools and 13 write tools, scoped to whoever authorised the connection. #### Questions **Q: Which editors does the VS Code extension work in?** A: VS Code, Cursor, Antigravity, Windsurf (formerly Codeium, including Cascade), VSCodium, Trae, Kiro, Void, Firebase Studio — and any other fork that loads a VSIX. Install fulgid.worksynk from the VS Code Marketplace or Open VSX, or import a VSIX directly. Editors that default to Open VSX may not show it in search until you do one of those. **Q: Is there a Framer plugin?** A: Yes. It creates tasks from your canvas selection with templates for Task, Feedback, Review, Content and Polish, rich-text notes with @mentions, a screenshot attached on create, and the published design URL filled in automatically. It also has Tasks and Mine tabs so you can filter and action work without opening the portal. **Q: How do the extensions authenticate?** A: All three use a personal access token from Settings → API keys — create one, paste it once, and the extension remembers your workspace and last project. That is separate from MCP, which uses OAuth and is aimed at AI hosts rather than editors. **Q: What is the difference between the extensions and MCP?** A: The extensions are for you: create and triage work from the tool you have open. MCP is for an AI host acting on your behalf — it exposes 31 tools and runs under the permissions of whoever authorised it. Plenty of teams use both. **Q: Do you support JetBrains, Neovim, or Webflow?** A: Not yet. Webflow is scoped as a thin form and CMS bridge into tasks, but it is not built — there is no plugin to install today. JetBrains, Neovim, and browser-only IDEs have no dedicated extension planned; use MCP or the REST API there. If either would change your decision, tell us, because that is what moves the order. ## Modules (31) URL: https://www.worksynk.app/features ### Plan and track The delivery primitives everything else reports on. - **Projects**: The unit of delivery — status, team, dates, and the settings that drive reporting. Guide: https://docs.worksynk.app/projects - **Tasks**: Statuses, types, priorities, and the settings that make reporting trustworthy. Guide: https://docs.worksynk.app/tasks - **Sprints**: Timeboxed cycles for pacing the team's work. Guide: https://docs.worksynk.app/sprints - **Milestones**: Dated delivery checkpoints that work rolls up to. Guide: https://docs.worksynk.app/milestones - **Recurring tasks**: Work that repeats on a schedule. Guide: https://docs.worksynk.app/recurring-tasks - **Workflows**: Drag-and-drop automation for delivery operations. Guide: https://docs.worksynk.app/org-workflows - **Notes**: Shared and personal writing, kept next to the work. Guide: https://docs.worksynk.app/notes - **File storage**: Attachments on tasks and projects. Guide: https://docs.worksynk.app/file-storage ### Time, cost, and reporting Hours you can bill from, and the numbers behind them. - **Time tracking**: Timers, timesheets, and keeping the hours honest enough to bill from. Guide: https://docs.worksynk.app/time-tracking - **Timer Security**: Require location or a known network when starting a timer. Guide: https://docs.worksynk.app/timer-security - **Budgets and profitability**: Retainers, margins, and what hasn't been billed yet. Guide: https://docs.worksynk.app/budgets - **Reports**: Where the hours went, who's over capacity, what's unbilled, and what to tell the client. Guide: https://docs.worksynk.app/reports - **Analytics**: Delivery dashboards and project intelligence. Guide: https://docs.worksynk.app/analytics ### Clients What the people paying for the work get to see. - **Client directory**: Client records, what they can see, and how work gets handed over. Guide: https://docs.worksynk.app/clients - **Client portal**: A client-facing view of their work, without giving them a seat. Guide: https://docs.worksynk.app/client-portal - **Client handoff**: Package deliverables, get confirmation, issue a certificate. Guide: https://docs.worksynk.app/handoff - **AI Client Reporter**: Weekly client status reports drafted from real activity. Guide: https://docs.worksynk.app/ai-reporter - **SLA Management**: Response and resolution targets, working hours, holidays, and automatic breach alerts. Guide: https://docs.worksynk.app/sla-management - **White-label branding**: Your brand instead of Worksynk's, everywhere clients look. Guide: https://docs.worksynk.app/white-label-branding ### AI Assistance over your real data, scoped to your own permissions. - **AI Assistant**: Ask about your work, draft standups, and get a morning brief. Guide: https://docs.worksynk.app/ai-assistant - **MCP Server**: Connect Claude, ChatGPT, Cursor and other AI hosts to your workspace. Guide: https://docs.worksynk.app/mcp-server - **Voice Input**: Speak instead of typing — dictate tasks, notes, comments and instructions. Guide: https://docs.worksynk.app/voice-input ### Integrations Worksynk sits where the work already happens. - **Integrations**: Connect the tools your team already works in. Guide: https://docs.worksynk.app/integrations - **GitHub**: Link repositories so code and work sit together. Guide: https://docs.worksynk.app/github - **Webhooks**: Signed event delivery to your own systems. Guide: https://docs.worksynk.app/webhooks - **Meetings**: Schedule Zoom, Google Meet, and Teams calls against a project. Guide: https://docs.worksynk.app/meetings ### Security and administration The controls a security review asks about. - **Workspaces and people**: Workspace roles, project roles, and how the two combine to decide what someone sees. Guide: https://docs.worksynk.app/workspaces - **Activity Log**: A workspace-wide audit trail of who did what, and when. Guide: https://docs.worksynk.app/activity-log - **Credential Vault**: Encrypted storage for the secrets a project needs. Guide: https://docs.worksynk.app/vault - **IP Whitelist**: Restrict workspace access to known addresses. Guide: https://docs.worksynk.app/ip-whitelist - **Custom SMTP**: Send workspace email through your own mail server. Guide: https://docs.worksynk.app/smtp-config ## Security controls (19) URL: https://www.worksynk.app/security ### Identity and access Who gets in, and what they can reach once they are in. - **Passkeys**: WebAuthn sign-in with a fingerprint, Face ID, or a hardware key — nothing phishable to hand over. - **Two-factor authentication**: TOTP with recovery codes, or a code by email. The secret and the codes are encrypted at rest and never returned by the API. - **Login history**: Sign-ins are recorded, so an unfamiliar session is something you can actually find. - **Workspace and project roles** (Workspaces): Two role layers that combine: a workspace role sets the floor, a project role narrows it per engagement. - **IP allowlist** (IP Whitelist): Restrict workspace access to known addresses, so a leaked credential is not enough on its own. - **Client access levels** (Client portal): External people get a portal seat, a status link, or external-member access — never an internal seat. ### Data protection How secrets and files are stored and handed back. - **Credential Vault** (Vault): AES-256-GCM, encrypted at rest, decrypted only when someone with project access views it. Viewing can require a one-time code, so a borrowed session is not enough. - **Vault access log** (Vault): Every view is recorded — who opened which credential and when — and the log sits on the credential itself. - **Upload handling**: Attachments are allow-listed by type, double-extension filenames are rejected, and downloads are forced as attachments rather than rendered. - **Timer Security** (Timer Security): Timers can require shared location or a recognised network before they start, for hours that have to withstand scrutiny. ### Auditability Answering “who did that, and when” after the fact. - **Activity log** (Activity Log): A workspace-wide trail of who did what, and when. - **MCP call records** (MCP Server): Every tool call an AI host makes is recorded, so there is a trail of what an assistant did. - **Workspace access review** (MCP Server): Owners and admins see every AI connection and member API key reaching the workspace, and can revoke any of them immediately. ### Integrations and AI What connected systems are allowed to do on your behalf. - **Connections act as a person** (MCP Server): An AI connection runs as whoever authorised it and can never see or do more than they can. - **Read-only by default** (MCP Server): Write access is opt-in and executes immediately over MCP with no confirmation prompt — so grant it only where an assistant genuinely needs it. - **Signed webhooks** (Webhooks): Outbound events are signed so the receiving system can verify the delivery came from your workspace. ### Application hardening Controls in the application layer itself. - **Rich-text sanitisation**: Descriptions and comments are sanitised server-side on write against an allow-list, and sanitised again in the browser before they render. - **Response headers**: X-Content-Type-Options, X-Frame-Options: DENY, and a strict Referrer-Policy on every response, plus HSTS over TLS. - **Module gating**: Disabling a module hides its interface and blocks its endpoints — it is an access boundary, not just a menu change. ## Frequently asked questions URL: https://www.worksynk.app/faq ### Getting started **Q: What is Worksynk for?** A: Running client delivery — projects, people, time, and the reporting that keeps clients informed. It is aimed at teams who are answerable for dates: agencies, studios, and in-house delivery orgs. **Q: Why can I not see a feature I expected?** A: Worksynk ships as modules, and most are off by default even when your plan covers them. A workspace owner or admin turns them on under Settings → Modules. If a settings page looks empty, that is almost always the reason. **Q: Who can turn a paid module on?** A: Only the workspace owner, since enabling one affects what the account is billed. **Q: What happens if we turn a module off later?** A: Disabling a module hides its interface and blocks its endpoints, but does not delete your data. Turn it back on and your policies, budgets, or SLA configuration are where you left them. **Q: Can we move over from another tool?** A: Yes. Connect Jira, Asana, Azure DevOps, or Zoho and import a project — issues arrive as tasks with their status and assignee mapped. Linked projects keep syncing, so a team mid-migration can work in both for a while. ### Work items, sprints, and milestones **Q: Can we keep our own workflow states?** A: Yes. Five statuses ship by default and you can rename, recolour, reorder, or archive any of them and add your own under Settings → Statuses. Velocity and reporting read from status categories, so the numbers keep working after you change the labels. **Q: Do we have to use both sprints and milestones?** A: No. Sprints suit teams working to a cadence who care about throughput; milestones suit dated outcomes a client is waiting for. Plenty of teams use one and not the other — both are modules you can leave off. **Q: Is tracked time good enough to invoice from?** A: That is the intent. Timers run against the work item, timesheets split billable from unbilled, and timer security settings exist specifically to keep the hours honest enough to bill. **Q: What happens to work that repeats?** A: Set a recurrence rule instead of recreating the task. The next instance appears on schedule, and editing the rule changes future instances rather than the history. ### Delivery confidence **Q: Is the score a prediction?** A: No, and the product is explicit about this. It is a decision aid computed from your data. A low score is a prompt to look at something, not a verdict on whether the project will land. **Q: What exactly goes into it?** A: Overdue work, blockers, movement through statuses, and milestone progress. Because each input is real work in the workspace, you can open the items driving a change rather than trusting a number. **Q: Can we see how it changed over time?** A: Yes. The score is captured daily, so you read it as a trend. A project drifting down over a fortnight is a different conversation from one bad day. **Q: Who can see the executive view?** A: The executive summary and workload reports are visible to owners and admins only, and depend on the Analytics module being enabled. ### AI and MCP **Q: Can the assistant see things a user should not?** A: No. It operates inside the permissions of the person asking. If you cannot open a project, neither can the assistant on your behalf. **Q: Will it change data without being asked?** A: In the app, no — an action that changes data shows you what will happen before it runs. Over a connected MCP host it can: a write tool executes the moment it is called, with no confirmation prompt. That is why connections default to read-only, and why you should only grant write access to a host that genuinely needs it. **Q: Which AI hosts can connect over MCP?** A: Claude, ChatGPT, Cursor and other MCP-compatible hosts. Each has its own setup walkthrough, and every connection can be reviewed or revoked from settings. **Q: How is AI usage billed?** A: Usage draws on workspace AI credits. Consumption is visible in the workspace, so spend is something you can watch rather than discover. ### Clients and the portal **Q: Does a client in the portal use up a seat?** A: No. The portal is a client-facing read-only view specifically so you can give visibility without consuming a workspace seat. **Q: What is the difference between the portal and a status link?** A: The portal is a persistent view of their projects with updates and approvals. A status link is lighter, for when a client just needs to see progress. An external member seat is the third option, for clients who need to participate directly. **Q: Can it look like our studio rather than Worksynk?** A: Yes, with white-label branding — your name, colour, and logo replace ours across the surfaces your team and clients see. **Q: How do we prove a client signed off?** A: Handoff packages the deliverables, captures the client's confirmation, and issues a certificate — so sign-off is a record rather than a recollection. ### Integrations **Q: Do we have to use GitHub?** A: No. GitHub has first-class support, and there is generic git-host support for teams on something else. Both link repositories to projects so commits and pull requests attach to the work they reference. **Q: How do we verify a webhook really came from Worksynk?** A: Deliveries are signed, so your endpoint can verify the signature. Destinations are validated when you create them, and every delivery attempt is recorded so failures are diagnosable. **Q: Can we migrate from our current tool?** A: Yes — import jobs bring existing work across rather than asking someone to re-key a backlog. **Q: What happens after a meeting?** A: Meetings are scheduled against a project with a join link, reminders go out beforehand, and AI follow-ups capture what came out of the call next to the work it concerns. ### Operations and governance **Q: Do all teams have to work the same way?** A: No — that is usually why standardisation fails. The hierarchy and the definitions stay consistent, but modules, statuses, and workflows are configured per workspace so each team keeps the parts that fit its work. **Q: How do we keep reporting comparable if teams rename statuses?** A: Statuses map to categories. Teams can rename, recolour, and reorder freely, and velocity and reporting continue to read from the underlying category. **Q: What can we show a security reviewer?** A: Activity logs, login history, credential access logs, AI action records, and IP whitelisting — all product surfaces rather than policy documents. **Q: Can SLAs account for our working hours?** A: Yes. SLA policies are aware of business hours and holidays, and warn you before a response or resolution target is missed rather than after. ### Reporting for executives **Q: Who can see the executive and financial reports?** A: Owners and admins only. Financial reporting also depends on the Budgets module and on rates being set for your people. **Q: Is the confidence score comparable across teams?** A: Yes, because it is computed the same way everywhere — overdue work, blockers, movement, and milestone progress — even when teams have renamed their statuses. **Q: Can I see why a project dropped?** A: Yes. Risk patterns and blocker radar name the cause, and every input is real work you can open from the score. **Q: Do I need to ask someone to build this report?** A: No. It is a standing view that reads live data, which is generally the point — nobody should be assembling a portfolio slide by hand. ## Blog ### Scope creep is an invoicing problem you find too late URL: https://www.worksynk.app/blog/stop-losing-margin-to-scope-creep · Published 2026-09-27 · Guides Scope creep rarely arrives as one big request. It arrives as twenty small ones nobody wrote down — and you meet all of them at once on the invoice. Ignition's 2025 Agency Pricing and Cash Flow Report surveyed 273 US agency owners and senior leaders. 57% said they lose between $1,000 and $5,000 a month to out-of-scope work they never invoice; another 30% said it is more than that. Only 1% said they bill for all of it. That is not a pricing problem or a difficult-client problem. It is a timing problem. By the time anyone notices the extra work, it has already been delivered, and asking to be paid for delivered work is the hardest conversation an account lead has. #### Why it hides until invoicing Scope creep is invisible in the places agencies usually look. The status report says the project is on track because the work is getting done — it is just more work than was sold. The sprint board looks healthy because new items were added and closed. Nothing is late, so nothing is red. The only system that eventually notices is finance, because hours logged against the project keep climbing while the fee stays the same. Finance sees that at month end. The client asked for the extras weeks earlier. #### Four signals that show up before the invoice You do not need a new process to catch creep early. You need to watch a few signals that move while the work is happening, not after: - Hours consumed against budget, not against the calendar. A project that is 40% through its timeline and 70% through its hours is creeping, even if every deadline is green. - Work items with no parent in the original plan. A steady trickle of new tasks that do not roll up to an agreed milestone is the clearest shape of unwritten scope. - Unbilled billable time. If billable hours are piling up with nowhere to invoice them, someone is doing work the contract never priced. - Stale or unowned work. Teams stretched by extra requests quietly drop the planned work instead — it shows up as items nobody has touched in days. #### Turn the signals into alerts, not a monthly review Each of those signals is only useful if it reaches someone while there is still time to have the conversation. In Worksynk, [budgets](/solutions/agencies-studios) track hours or value against each project, and threshold alerts — most teams set 80% and 100% — notify owners and admins and land in their daily digest. The unbilled time report lists billable hours worked but never invoiced, per client, so extras are visible the week they happen. [Delivery confidence](/platform/delivery-confidence) covers the other half. Stale items and unassigned high-priority work both subtract from a project's score, so a team quietly absorbing extra requests shows up as a falling number with named work items behind it, rather than as a surprise at the retro. #### Have the conversation while it is still small The fix for scope creep is almost always a conversation, and conversations are cheap early. "This new report is outside the original scope — want us to add it as a change, or swap it for something already planned?" is an easy question at 80% of budget. At 130% it is a dispute. Giving clients a real view of the work helps too. A [client portal](/platform/client-collaboration) that shows progress and approvals — without your internal notes, rates, or budgets — makes it easier to point at what was agreed and what was added, because both of you are looking at the same list. #### A checklist for your next project Before kickoff, make sure you can answer yes to each of these: - The project has a budget in hours or value, with an alert before it runs out — not only when it does. - Every work item rolls up to an agreed milestone, so anything that does not is visible as new scope. - Billable time is tracked against the project, and someone reviews unbilled time weekly. - The client can see progress without a status meeting, so changes are discussed against a shared record. ### How we built the Delivery Confidence Score URL: https://www.worksynk.app/blog/how-we-built-the-delivery-confidence-score · Published 2026-06-02 · Product Every project starts at 100. Everything after that is subtraction — and each subtraction has to name the work item behind it. The first version of this score tried to predict. It weighted velocity trends against historical outcomes and produced a number nobody could argue with, because nobody could explain it either. A project manager would see 61 and ask what changed. We could not answer without opening a notebook. So we threw out prediction. The score you see now is rule-based and additive in one direction: a project starts at 100, and each thing we can actually detect subtracts from it. #### What subtracts, and how much Five factors do most of the work, and each one is capped so a single bad signal cannot swamp the rest — you can see them laid out on the [delivery confidence page](/platform/delivery-confidence): - Overdue open items — scales with the share of open work past its due date, capped at 35. - Items waiting on dependencies — counts open work whose blocker is itself still open, capped at 25. - Stale items — open work nothing has touched in three days, capped at 15. - Unassigned high or critical work — five points each, capped at 15. - Items stuck in review for more than two days, capped at 10. #### Sprint pressure is separate An active [sprint](/platform/work-items-sprints) adds two more possibilities. If the end date has passed and work remains, that is a flat 20. If the sprint ends within two days and more than a third of the planned points are still open, the score takes a proportional hit up to 15. Keeping these separate matters. A project can be perfectly healthy and still be in a sprint that will not land, and those are different conversations with different fixes. #### Why it is snapshotted daily A single number is a bad interface for risk. 58 means nothing on its own; 58 after three weeks in the seventies means something specific. We capture one snapshot per active project per day, so what you read is a trend line rather than a verdict. That also makes the score falsifiable. If it drops and nothing was actually wrong, the factor list tells you which rule fired and you can go argue with the rule. #### What it is not It is not a prediction, and we are careful not to present it as one. It is a decision aid computed from your own data with rules you can read — a prompt to go look at four specific work items, not a judgement about whether you will ship. The most useful thing it does is not the number at all. It is that the number always comes with the reason. ### Why we built our own MCP server instead of an app marketplace URL: https://www.worksynk.app/blog/why-we-built-our-own-mcp-server · Published 2026-05-14 · Engineering A marketplace makes every integration someone else's roadmap. A protocol makes it nobody's. The obvious move for a delivery platform in 2026 is an app directory: publish an API, invite partners, curate a gallery. We started down that path and stopped, because every entry in that gallery is a promise that somebody will keep maintaining it. MCP inverts the problem. Instead of building an integration per assistant, you expose one tool surface and any compliant host can use it. #### One surface, thirty-one tools The server exposes eighteen read tools and thirteen write tools. Reads cover the questions people actually ask — project status, delivery confidence, the [blocker radar](/platform/delivery-confidence), why something is late, where the hours went. Writes cover creating and updating work, sprints, milestones, notes and time. Claude, ChatGPT, Cursor, VS Code and anything else that speaks the protocol get the same surface. We did not write four integrations; we wrote one server. #### The hard part was authorisation, not tools A connection acts as the person who authorised it and can never see or do more than they can. That sounds obvious and it constrains everything: the tools cannot have their own service identity, they cannot cache across users, and every call has to resolve permissions the same way the UI does. Write access is opt-in and executes immediately — there is no confirmation step between an assistant deciding to change something and it being changed. We say this loudly rather than burying it, because the safe default only works if people know why it is the default. #### What we would not expose [Vault credentials](/security) are unreachable over MCP regardless of the connection's scope, and that restriction cannot be configured away. There is a category of data where the right answer is that the assistant simply does not get it, and stored secrets belong to that category. ### Governing AI agents without slowing them down URL: https://www.worksynk.app/blog/governing-ai-agents-without-slowing-them-down · Published 2026-04-22 · Product Most AI governance is a document. The useful kind is a set of switches in the product. The objection to AI in delivery tooling is rarely capability. It is that nobody can answer what the assistant did last Tuesday, or who let it. So the controls are boring on purpose: policy per workspace and per project, credit budgets so usage cannot surprise the account, and [a record of every call](/security). #### The confirmation boundary Inside the app, an action that changes data shows you what will happen before it runs. Over a [connected AI host](/platform/ai-agents-mcp) there is no such step — a write tool executes when it is called. That asymmetry is real and worth stating plainly, because a policy written on the assumption of a confirmation prompt is a policy that does not hold over MCP. The lever that does hold is scope: grant read-only unless an assistant genuinely needs to change work. #### Review is an interface, not a promise Owners and admins can see every AI connection and every member API key reaching the workspace, and revoke any of them immediately. Meeting follow-ups are drafted for a human to review rather than created silently. None of this makes automation slower. It makes the first conversation about automation shorter, which is usually what was actually blocking it. ### Portal seat, status link, or external member: choosing client access URL: https://www.worksynk.app/blog/choosing-the-right-client-access-level · Published 2026-03-30 · Guides Client access is not one switch. Picking the wrong level is how internal notes end up in front of the client. Most teams reach for the [client portal](/platform/client-collaboration) and stop there. There are actually three levels, and the differences matter enough that it is worth deciding deliberately per relationship rather than defaulting. #### The three levels Ordered from most access to least: - External member — a seat on a specific project, for a client-side counterpart who works alongside you day to day. - Portal seat — a client-facing view of their work, scoped to what you publish. They sign in; they do not get an internal seat. - Status link — a shareable page with no sign-in at all. Convenient, and therefore the one to be careful with. #### How to choose Use the shape of the relationship, not the size of the client. A long retainer where the client has an actual counterpart doing work benefits from external membership. A project where the client wants reassurance rather than involvement wants a portal seat. A one-off where somebody just needs to see whether it shipped wants a status link. The question worth asking before each one: if this person forwarded everything they can see to a competitor, what would that cost you? Answer honestly and the level usually picks itself. #### The status link deserves its own thought A status link is unauthenticated by design. Anyone with the URL has it, which is exactly why it is useful and exactly why it needs scoping. Treat it as public, because functionally it is. If you would not put the contents on a public page, it should be a portal seat instead. #### What clients never see Regardless of level, [vault credentials](/security) are out of reach, and so is anything in projects they have not been given access to. Access is decided by workspace role and project role together — client access narrows that, it never widens it. If you need the client-facing view to carry your brand rather than ours, that is white-label branding, and it applies everywhere clients look. ### Set up statuses so your reporting stays honest URL: https://www.worksynk.app/blog/set-up-statuses-so-your-reporting-stays-honest · Published 2026-03-11 · Guides This is the single most common way a Worksynk workspace ends up with numbers nobody trusts — and it takes two minutes to avoid. Five statuses ship by default, and you can rename, recolour, reorder, or archive any of them and add your own under Settings → Statuses. Teams do this early, which is fine. The part that catches people is what sits underneath. #### Category is what counts, not the label Every status belongs to one of four categories: Todo, In Progress, In Review, or Done. The category — not the name you gave it — is what sprint velocity, completion counts, reports, and SLA resolution all key off. So if you add a status called “Shipped” and leave it in the wrong category, every item sitting in it looks unfinished. Velocity under-reports, the sprint looks behind, and [delivery confidence](/platform/delivery-confidence) reads work as open that is actually done. #### A two-minute audit Worth doing once, and again whenever someone adds a status: - List every status in the workspace and write its category next to it. - Anything that means finished — shipped, delivered, live, closed-won — must be Done. - Anything waiting on someone else to look at it should be In Review, so review-lag detection actually fires. - Archive statuses nobody uses rather than leaving them selectable. #### Board order follows status order Board columns follow your status order, so reordering statuses in settings reorders the board for everyone. That is convenient and occasionally surprising — if a teammate says the board “changed overnight”, someone reordered statuses. #### Why this matters more than it sounds Every number the platform shows you is downstream of this. A [confidence score](/platform/delivery-confidence) is only as trustworthy as the categories behind it, and comparing two teams' reporting only works if both mapped their statuses honestly. It is unglamorous configuration that decides whether anyone believes the dashboards six months from now. ### Passkeys, TOTP, and the rest of the sign-in path URL: https://www.worksynk.app/blog/passkeys-and-the-sign-in-path · Published 2026-03-11 · Security The goal is not one perfect factor. It is that no single stolen thing is enough. Worksynk supports [WebAuthn passkeys](/security) — fingerprint, Face ID, or a hardware key. A passkey is not phishable in the way a password is, because there is nothing to type into the wrong site. Passwords and TOTP are still there, with recovery codes. Both the secret and the codes are encrypted at rest and never returned by the API. #### Layers past the login screen Sign-ins are recorded, so an unfamiliar session is something you can find rather than something you suspect. Workspaces on the right plan can restrict access to known addresses entirely, which turns a leaked credential from an incident into a failed attempt. #### The part people forget Authentication is only half of it. What someone reaches after signing in is decided by a workspace role and a project role together, and by which [modules](/features) are switched on — a disabled module blocks its endpoints, not just its menu item. Reading a credential from the vault can require a one-time code on top of all of that, so a borrowed session is not enough to walk away with secrets. ### Reading a Delivery Confidence drop correctly URL: https://www.worksynk.app/blog/reading-a-delivery-confidence-drop-correctly · Published 2026-02-18 · Product The number going down is not the finding. The factor that moved is the finding. The most common mistake is treating the score as a verdict and reacting to its direction. A drop of eleven because three items are newly blocked is a different situation from a drop of eleven because someone finally set real due dates. The second is a scoring artefact of doing the right thing. Read the factors first. #### Drops that usually mean act now Two patterns are worth interrupting your day for: - A blocker chain where the blocking item is barely started — everything behind it is already late, it just has not shown up as overdue yet. - Unassigned high or critical work. Five points each is deliberately punchy, because unowned urgent work is the failure that compounds fastest. #### Drops that usually mean wait Stale items right after a holiday, or a review queue that grew because one reviewer was out, will recover on their own. The daily snapshot is what tells you which you are looking at: one bad day is noise, five is a trend. #### When the rule is wrong Sometimes the score is simply wrong about your team — a project where three days without an update is normal will look stale forever. That is a real limitation, not a misunderstanding, and the honest response is to weigh the factor accordingly rather than pretend the number is neutral. It is a [decision aid computed from your data](/platform/delivery-confidence). It is allowed to be wrong; it is not allowed to be unexplainable.