Product Updates

What's new in OnDeck

Everything we've shipped recently, what's being built right now, and what's next.

In progress & roadmap

Roadmap last updated August 2, 2026.

WhenToWork / Sling roster sync In progress

Pull today's staffing straight from your scheduling tool so certification and training views know who's actually on deck. Configuration, storage, and the nightly sync are live; the vendor connection turns on per customer.

Cost & usage dashboards In progress

Per-organization visibility into seat, API, email, and storage usage, with nightly snapshots so spend is never a surprise.

Phone-friendly record tables Planned

Turn the highest-traffic tables — submission history, certification overview, staff directory — into clean card layouts on phones so there's no sideways swiping.

AI incident summaries Planned

Auto-draft a plain-language summary for each incident report so directors can triage their queue faster. Held until a zero-data-retention review is complete before any real incident data is processed.

Recently shipped

Customer-facing changes. Internal refactors and dependency bumps are omitted.

Unreleased

Added
  • Scheduling on iPhone, iPad and Mac, matching the web schedule released on 1 August. Your shifts, your availability, time off, and open shifts you can claim — and if you build the schedule, the whole authoring side travels with you: periods, templates applied across several days, publishing, call-outs, and telling someone their shift moved. You can also say you're running late from the phone in your pocket, which is where you'll be when you are.
  • Incident Reports on iPhone, iPad and Mac, rebuilt to match the web release on 2 August. Aquatic emergencies carry their MAHC §6.4.1.4 record, injuries are coded so they can be counted rather than read one by one, and conduct, security, property and child-safety reports each ask only what applies to them.
  • Archive a former staff member, and bring them back. Somebody who leaves no longer has to be deleted to get out of your way — archiving keeps their certifications, training and records intact for your audit trail, and a returning seasonal hire is restored rather than re-entered.
  • Certifications from different certifying bodies now count as what they are. An American Red Cross lifeguarding certificate and its equivalent from another body satisfy the same requirement, instead of one of them quietly reading as missing. Your organization picks which bodies it recognises under Settings → App Configuration. New certifications reach the app without waiting for an App Store update.
  • Choose your Home Screen icon on iPhone and iPad — follow your device's light/dark appearance, or pin the icon to one. Under Account → Appearance → App icon.
  • Your app version, on screen. Account → About shows the exact version and build, with a "Copy version details" button that puts the version, device and OS on your clipboard for a bug report.
  • Swim Test Log on iPhone, iPad and Mac. Look up a swimmer, record a test and hand out a wristband from the deck — the same module that went live on the web on 26 July.
  • Conditioning per discipline on iPhone, iPad and Mac, matching the web behaviour released on 17 July.
  • Your lanyard on iPhone, iPad and Mac, doing whatever it started doing on the web on 30 July. Still worth a poke.
  • Training approvals on iPhone, iPad and Mac, matching the web behaviour released on 28 July. An "Awaiting Approval" list at the top of Training, and your own entries marked Pending approval until they're signed off. Until this reaches you, the app still counts training the web is already holding back — the compliance reports and packets are correct either way.
Changed
  • The Mac app now behaves like a Mac app. Forms, view switchers and list rows use native controls; closing the main window no longer strands you (it reopens from the Dock or the menu bar); and the dashboard, certifications filters and long help text were rebuilt for a pointer and a large screen.
  • The Mac app is substantially faster on large rosters. Training, growth track and analytics are now evaluated once per update instead of repeatedly while scrolling.
Fixed
  • Turning off Scheduled Checklists now turns it off everywhere. The module switch under Settings → App Configuration was respected on the web but not in the app, so an organization that doesn't run scheduled checklists still saw the item on iPhone, iPad and Mac.
  • Opening an incident in its own window works again on Mac (after 1.2.0). Right-click a report in Incidents and choose "Open in New Window" to put two side by side — the way you'd read a pattern across a season rather than one report at a time. The rebuilt incident screen arrived without it, so 1.2.0 still has the gap and the build behind it puts the window back.

August 2, 2026 — Incident reports, rebuilt

Added
  • Incident reports now know what kind of incident they are. Reporting was one long form that asked a drowning and a stolen bag the same questions. It is now built around the record each type actually has to produce: an aquatic emergency carries its MAHC §6.4.1.4 rescue record and its AHJ notification deadline, injuries are coded by body part and type so a year of them can be counted rather than read one by one, and conduct, security, property and child-safety reports each ask only what applies to them.
  • Incidents you can total up. Because injuries and causes are now recorded as coded fields rather than prose, the incident view can show you what actually happens at your facility over a season — which is the report an insurer or a health department asks for and nobody could produce before.
Fixed
  • The staff certification PDF said "Branch: br_4f12aa88bc0e…". The export was handed the branch's internal id where it wanted the name, so the header printed an identifier — or "all" for the all-branches view. It now prints the branch name, and the saved file identifies the organization, the scope, any status filter you had applied, and the date.

August 1, 2026 — Settings that remember you

Added
  • Staff scheduling, rebuilt. Scheduling has been rebuilt from scratch and is no longer the version that shipped in June. Schedule periods can now be a whole season rather than a single week, and you can step week by week inside one; a template can be applied across several days at once; publishing announces itself to the people on it; and someone whose shift moves is told it moved. Staff can call out, say they're running late, and subscribe Apple or Google Calendar to their own shifts.
  • Scheduling now checks what it can, and says what it can't. It catches certifications that lapse partway through a period you're scheduling into, shows you who else is on with you, marks holidays before the schedule goes out, and applies youth employment rules for Massachusetts and Tennessee. Where a youth rule can't actually be checked from what OnDeck knows, it now tells you that rather than implying it passed.
  • Light or dark now follows you, not your browser. Your appearance choice is saved to your account, so setting dark mode at the office desk also sets it on your phone and the deck iPad. On a shared front-desk computer, signing out no longer leaves your theme behind for the next person.
  • Your branch stays put. If you can switch branches, the one you pick is remembered per organization — no more landing on whichever branch happens to sort first after every page load.
  • Administrators can now turn any module on or off. Settings → App Configuration → Modules lists everything, not just the optional add-ons. If your organization doesn't run a conditioning program or logs incidents somewhere else, you can take those out of the navigation yourself. Turning a module off only hides it — nothing is deleted, and switching it back on brings your data with it.
Changed
  • A new look for signing in. The sign-in, signup, email-link and choose-your-organization screens now use the OnDeck wordmark, colours and type instead of a generic blue — arriving from the website, signing in, opening the link in your inbox and landing in your organization now all look like the same product rather than three different ones.
  • Fresh app icons. The browser-tab icon is now the squircle app mark on both the main app and the platform admin console, which previously had no icon at all.
Fixed
  • Signing in with an org picker you didn't need. If you belong to more than one organization, you were shown the picker on every single sign-in even when your session already knew which one you were in. It now takes you straight through.
  • Email addresses are tidied before we look them up, so a stray space from a paste or a capital letter from a phone keyboard no longer gets in the way of signing in.
  • The signup page was wrong about its own link. It said your sign-in link expired in 10 minutes; it's actually good for 3 days. It now says so.
  • "Send a new one" on the signup screen now actually sends one instead of just returning you to the form.
  • Visiting the sign-in page while already signed in now offers to take you back into OnDeck rather than showing an empty sign-in form.

July 31, 2026 — Your season, on paper

Added
  • Your season, in numbers. Growth Track now shows what you actually did over the last twelve months — water tests logged, swimmers passed into deep water, checklists closed, training hours. Nobody knows they tested the water four hundred times until something counts it. If you're new, it shows your firsts instead: first shift signed off, first water test, first training.
  • The team's year, for directors. The same figures for a whole branch or the whole association, with the line that makes them mean something — "that's a water test about one every two hours". Team totals only: OnDeck does not rank your staff against each other, and this will not either.
  • Your achievement PDF now says something that's only true of you. A "Worth Noting" line at the bottom — most days it's the water tests or the swimmers, but if you went in this year, that's what it says.
  • Print the Recognition Beads card. The chart the bead list was built from, handed back as a deck-ready poster, with your criteria on it if you've edited them. Under Awards, beside the bead legend.
  • Print the month's shout-outs for the staff room, and a "Deck Clear" certificate for a branch that closed a calendar month with no flags raised. The certificate prints the numbers it's based on, so it never claims more than the record shows — and a month where nothing was logged doesn't qualify.
  • The Knowledge Base knows more than it lets on. Not everything worth asking is a help topic. Ask anyway — one or two questions have answers that aren't in the contents. And if you're the sort of person who opens the developer tools, there's a hello waiting for you there.
  • The dashboard notices things. Every so often it will remark on something about your pools that nobody typed in. It won't happen often — that's rather the point.
Changed
  • Empty screens now tell you something. Every "No records found" in the app was rewritten to say what's actually absent and what to do about it. Screens that report on safety — chemistry, incidents, interlock tests, expiring certifications — were deliberately left plain.

July 30, 2026 — Something on your lanyard

Added
  • There's something hidden on your lanyard. Your beads on the Recognition screen aren't quite as fixed in place as they look. Have a poke around.

July 28, 2026 — Logged training now waits for approval

Added
  • Training you log is reviewed before it counts. Recording an in-service signs off someone's monthly compliance, so it now waits in an Approvals list on the Training screen until a manager decides on it. A whole session is one decision — approve a forty-person in-service once, not forty times, with the attendee list one tap away so you can see exactly whose compliance you're signing off.
  • You can see why your hours don't add up. Your own entries show Pending approval until someone signs them off, and Rejected with the reason if they don't. Rejecting requires a reason, so a training that needs fixing comes back with an explanation instead of quietly disappearing.
  • Who can log and who can approve is now yours to set, per role, under Settings → Roles & Permissions. Logging defaults to supervisors and above plus LGIs; approving defaults to managers and directors.
Changed
  • Nothing you've already recorded was affected. Every training logged before today counts exactly as it did, marked approved with its original date. Months already closed are untouched.

July 27, 2026 — Tell us when something's wrong

Added
  • Report a bug or request a feature without leaving OnDeck. Help → Send Feedback, on the web app. It records which screen you were on and the exact version you're running, so a report no longer depends on anyone remembering which build they were using — or on describing their setup over the phone.
  • Every OnDeck surface now shows its version. The web app and the admin console display the running version, so a problem can always be traced to an exact release.

July 26, 2026 — Swim testing

Added
  • Swim Test Log (Test · Mark · Protect). Record a swimmer's ability test, assign a wristband colour, and see who's been tested and when. Includes a pool-deck kiosk mode for running tests on an iPad at the water's edge, and a per-manager record count so supervisors can see testing volume at a glance. Live on the web now; the iPhone, iPad and Mac versions arrive with the next app release. Opt-in — ask us to enable it.
Fixed
  • Expired-certification alerts no longer count orphaned records. Deleting a staff member could leave certification rows behind, which kept appearing in the dashboard's expired count.

July 18, 2026 — Recovering from a deploy without losing your place

Fixed
  • A deploy no longer dead-ends the open app. If the app updated while you had it open, the next navigation could fail on a stale file and leave you stuck. It now recovers automatically — and returns you to the page you were heading to, rather than the dashboard.

July 17, 2026 — Conditioning by discipline

Added
  • Conditioning is tracked per discipline. A staff member logs one record per month per discipline (swim, run, brick), instead of a single combined monthly entry, so a lifeguard's swim conditioning is no longer hidden behind their running.

July 16, 2026 — Invitations, exemptions, and admin on a phone

Added
  • Sending someone their login is now a visible button on their profile, instead of a swipe action people never found. Includes a copyable link that works for 24 hours, and a bulk invite for a whole roster at once.
  • Standing training exemptions. Excuse a staff member from a requirement with a recorded reason, and the compliance view shows why someone is excused rather than silently passing them.
Fixed
  • Certification imports no longer split one person into two records. A labelled CSV email column (Jane Doe <jane@…>) was parsed as a second person.
  • Backups now cover every per-org table. The remaining gaps are closed, and an omission now fails loudly instead of quietly shipping an incomplete backup.

July 15, 2026 — Training Report

Added
  • Monthly Training Report PDF for leadership — a printable summary of in-service training across a branch for the month.
Fixed
  • Compliance no longer counts removed staff, and new hires are prorated correctly for their first partial month.

July 13, 2026 — Long forms remember where you were

Added
  • Log Training autosaves as you go, on web, iPhone and iPad. Start a training log on your phone and finish it on the iPad. Drafts are cleared when you sign out.
Fixed
  • Roster imports and invitations no longer create duplicate staff records for someone already on the roster.

July 11, 2026 — OnDeck on Apple TV, names, and a Lock Screen widget

Added
  • OnDeck for Apple TV. Put a live board on the wall: who's on stand, current water chemistry with out-of-range readings called out, open flags, and certifications coming due. Two modes — an internal ops board for staff areas, and a public board for the lobby that shows members an all-clear rather than raw numbers.
  • First and last names are recorded separately, so names appear correctly on lanyards, rosters and reports instead of being split on the first space.
  • Certifications expiring soon, on your Lock Screen (iPhone and iPad).
  • Drop in a photo from your phone for inventory — HEIC images from an iPhone are converted in the browser, so an upload no longer fails on format.
Fixed
  • Editing a signed policy asks staff to re-acknowledge it. The version is bumped and the signed text is snapshotted, so your sign-off records always match the version people actually read.
  • A lanyard name tag never shows an email address, and compound first names ("Mary Beth") stay intact.
  • Accounts with a blank name no longer fall back to showing an email address in the interface.

July 10, 2026 — Shout-outs and service anniversaries

Added
  • Shout-outs. Peer recognition — staff can recognise each other, with a full moderation queue for directors. Opt-in per organization.
  • Service anniversaries and a rendered lanyard. See your lanyard (name tag, whistle and beads) and track milestones with "N Years of Service" beads as your team hits them.
  • Red Cross certificates fill themselves in. Drop the certificate PDF onto a certification record and the number, issuer and expiration date are read from it, on your device — the PDF isn't sent anywhere to do it.

June 29, 2026 — Demo sandbox & backup hardening

Added
  • Fully-seeded prospect demo sandbox. Every module — chemistry, compliance, inventory, training, scheduling, zones, and reporting — now comes pre-populated with realistic sample data spanning several months, so a prospect exploring a demo org sees the product working end-to-end (populated charts and all) instead of empty tables.
Fixed
  • Backups now include incident reports, roster shifts, and email-digest subscriptions. These live tables were missing from the backup set, so a restore could have lost user-submitted safety/incident reports; they're now captured.
  • Hid the "Sync from WhenToWork" staff-import button until the integration ships — it previously pointed at an endpoint that doesn't exist yet and would error.

June 28, 2026 — Native iOS / iPadOS app: full parity

Added
  • OnDeck for iPhone and iPad. A native iOS/iPadOS app with an adaptive split-view shell, covering the full OnDeck feature set: daily chemistry logging, MAHC interlock testing, incident reports, checklists, the staff directory and certifications, cert imports with fuzzy name matching, career reviews and evaluations, recognition beads, onboarding, zone management with a native drawing canvas and drill response-time stopwatch, compliance binders, the chemistry kiosk, and Settings. Sign in with a magic link or a passkey (including conditional-UI autofill), work offline with a write outbox that flushes on reconnect, capture photos and signatures, and export PDFs from the device.
  • Chemistry draft autosave so a half-entered reading survives a backgrounded app or a flaky pool-deck connection.
  • Printable letter-size safety-concern poster generated as a PDF directly on the device.
  • Push notifications for director flags and compliance events, humanized so they read as plain English rather than raw IDs.
  • Siri / App Intents shortcuts plus a full VoiceOver and Dynamic Type pass for accessibility.
Changed
  • Billing is web-only in the app. Plan management and trials live on the web; the iOS app focuses on day-to-day operations.

June 26, 2026 — Platform-admin command center

Added
  • Platform-admin dashboard overhaul. The admin app now opens on a usage homepage with at-a-glance health, plus dedicated troubleshooting and billing views. Per-tenant health metrics surface right on the org list.
Changed
  • Denser, more usable org list. Row actions collapse into a "Manage" button with an overflow menu, and the table now uses the full screen width without wrapping.

June 23, 2026 — Equipment & uniform inventory

Added
  • Equipment & Uniform Inventory module (opt-in). Maintain a catalog of uniforms and gear with per-item photos, track sizes by staff, log receiving and issuance, and pull summary and issued-items reports. Includes a full issuance history log. Available on web and iOS.

June 20, 2026 — Compliance history & audit trail

Added
  • Frozen historical compliance records. OnDeck now captures audit-defensible compliance snapshots and dates each staff member's standing as of any past point, so you can answer "who was compliant on this date?" with a record that doesn't shift under you.
  • Compliance change-log view — the read side of the audit trail — showing the history of writes to compliance records.
  • Tamper-evident audit trail. Compliance-record writes are logged to an append-only audit log with DB-level protection against after-the-fact edits.
  • Excused / exempt handling. Mark staff as excused or exempt for leaves of absence, medical reasons, or new-hire proration, with explicit reasons that show in compliance views.
  • New-hire proration setting so recently-hired staff aren't counted out of compliance for requirements they haven't had time to meet yet.
  • Per-staff training transcript export for an individual's training record.
  • Facilitator credit in the training overview, with clearer denominators so the "X of Y trained" math is unambiguous.

June 19, 2026 — Training library, QR attendance, policies & minor labor law

Added
  • Training-Topic Library (opt-in). An in-service topic bank with an assemble-a-session workflow. Available on web and iOS.
  • QR-code training attendance (opt-in). Staff scan a rotating, signed QR code to mark themselves present at a training session. Available on web and iOS.
  • Aquatic policy-acknowledgment tracker (opt-in). Publish policy documents and track which staff have acknowledged them. Available on web and iOS.
  • Minor labor-law guardrails. Per-branch facility address with jurisdiction auto-fill drives DOB-based shift-limit guardrails for minor staff. Facility addresses also print on reports. Available on web and iOS.
  • Optional Modules toggle in Settings → App Configuration. Admins can enable or disable Inventory, Scheduling, and Training per org so the navigation only shows what a facility actually uses.
Changed
  • Monthly Training gains a top-row agenda upload, custom tags, and named facilitators.

June 15, 2026 — Launch readiness & billing

Added
  • Self-service 45-day trial signup is live, with live-mode Stripe billing behind it for paid plans.
  • One-tap magic-link invitations that greet the new staff member by name.
  • "No Action Required" all-clear state on the dashboard, with an explicit Action Required block surfaced for every branch.
Changed
  • Staff directory cleanup. Condensed actions, normalized branch labels, a sortable Growth Track column, and a layout pass that removes horizontal scrolling on the directory and edit forms.
Fixed
  • Dashboard cert alerts no longer double-count. Cert issues stop appearing twice in Action Required, and the Compliance Gaps denominator now matches the Cert Tracker.

June 13, 2026 — Staff scheduling, water-chemistry tools & certs

Added
  • WhenToWork-class staff scheduling (opt-in). Build availability, auto-fill shifts, materialize a scheduling period, and publish. Turn it on from onboarding or platform admin.
  • Water-chemistry calculator suite. CYA dosing and reduction, the FC:CYA ratio, salt dosing, and an LSI saturation gauge, with a units system applied consistently across dosing outputs and pool volumes.
  • Maintenance & Operations log for backwashing, water fills, chemical deliveries, basket cleaning, media changes, and equipment service.
  • DPD testing-technique animations that walk a guard through the reagent test steps.
  • Per-pool measured fill rate. A bucket test replaces the old pipe-diameter estimate for more accurate manual fill timing.
  • CDC contamination (fecal/vomit) response log with incident types and photo persistence.
  • Non-aquatics compliance role for land-side staff, plus friendly cert-type labels and a place to manage non-standard certs.
  • Scheduled (recurring) checklists — assignable opening, closing, and inspection checklists.
  • Dark mode across the web app, kept on-brand so the navy sidebar and brand colors survive the theme.
Fixed
  • Cert imports recover skipped staff via robust name matching, and cert exports (CSV and PDF) now respect the on-screen filters.
  • Cert PDFs render inline in Safari instead of blanking out.
  • The app auto-recovers from stale code chunks after a deploy instead of erroring on a half-loaded page.

June 8, 2026 — MAHC interlock testing & iOS foundation

Added
  • Monthly MAHC controller interlock testing. Log the required monthly interlock test per controller, in line with MAHC guidance.
  • Chemistry trends widget on the dashboard (Manager+), showing recent readings at a glance.
  • Bulk submission export and additional safety-concern filters.

May 14, 2026 — Phase 6 sweep

Added
  • White-label logo upload. Admins can now upload a PNG, SVG, or JPEG (up to 500 KB) under Settings → Branding. The uploaded logo replaces the OnDeck wordmark in the sidebar for every user in the org. Replace and Remove actions; SVG uploads are scanned for scriptable content before saving.
  • Live QR code on the Safety Concern poster. No more pasting in an externally-generated QR — the poster renders the QR client-side from your branch's report URL. Uses high error correction so a poster taped above a chlorine drum still scans cleanly.
  • Insurance renewal binder. Same one-click export pattern as the MAHC binder, but defaulted to 12 months and reorganized for an insurer audience: incident summary on top, guard credentialing rollup, lifeguard:patron ratio history sampled from chemistry bather-load entries. Find it under Compliance & Reports → Insurance Renewal Binder.
  • Slack / Teams flag alerts. Cross-post director flags to a Slack or Teams channel via the customer's own incoming webhook. Settings → Integrations to wire it up. Includes a "send test message" button so you can verify the webhook before waiting for a real flag. Both vendors are free to use; OnDeck doesn't charge extra.
  • WhenToWork / Sling roster integration (scaffold). Configuration UI, nightly cron, storage, and read endpoints are all in place. The actual vendor API calls are stubbed and will go live once a customer is ready to test against a real account.

May 14, 2026 — Phase 5 sweep + Phase 3 closeout

Added
  • Pending-invite banner on the Dashboard. If you were invited to an organization but the auto-accept couldn't process it (your email isn't verified yet, or the invite is missing its staff-ID marker and needs an admin to reissue), the dashboard now tells you about it. Click "Accept invitation" to retry, or "Not now" to dismiss for the session.
  • Bulk archive / resolve / reopen for Contact Submissions in the platform-admin inbox. Select submissions with the new checkbox column (or use the select-all in the header), then use the floating action bar to transition all of them in one call. Archive / Resolve are always available; Reopen appears when viewing archived or resolved submissions. Capped at 200 per call.
Changed
  • Audit log explorer in platform admin now supports filtering by admin email (substring search), target ID, and time range, plus Prev/Next pagination with a total-count badge. Clicking a target ID in the table pivots the filter to "show me everything that touched this target." Page size is 50.
  • CertTracker and Director Flag history now paginate at 25 per page. CertTracker also resets to page 1 when filters change, and CSV exports still see the entire filtered set — only the rendered cards are clipped to a page.
  • CSV cert imports now parse off the main thread. Large certificate_details_full.csv files (5000+ rows) used to freeze the tab for several seconds during the parse; the tab stays fully responsive now while a small "Parsing CSV in the background…" banner shows progress.

April 27, 2026

Added
  • F1 — Public status page at status.ondeckaquatics.com. Live system state for API, Tenant App, Admin App, Auth, Database, Email, Storage, and Marketing components, plus 30-day uptime % and the last 30 days of incidents and scheduled maintenance.
  • F2 — Self-service trial signup. Visit app.ondeckaquatics.com/signup to start a 45-day free trial with no credit card required. Magic-link sign-in, then a one-screen org-creation form that drops you into the 6-step onboarding wizard.
  • F3 — Compliance gap email digests. Director+ users can subscribe in Settings → Email Digests to a daily/weekly/monthly recap of expired certs, expiring certs, unacknowledged flags, and recent out-of-range chemistry. Customizable thresholds and a built-in preview button.
  • F4 — Mobile-first chemistry kiosk at /kiosk/chemistry. Full-bleed pool-deck UI for a phone clamped to the wall — pick pool, log reading, done in three taps. Auto-rotates back to input after 30s.
  • F5 — Offline submission queue. Forms submitted while offline are saved locally and auto-sent when the connection comes back. Banner surfaces queued submissions with a manual retry button.
  • F6 — Anonymous safety reporting at /report-concern/<your-org-slug>. Public submission form for staff to flag near-misses, equipment issues, or workplace concerns with optional name and optional email. Director+ triage panel under Compliance & Reports.
  • F7 — Cross-facility anonymous benchmarking. Opted-in orgs see peer percentiles on the dashboard for chemistry means and flag acknowledgement times. Two-tier opt-in (org + branch) with a k-anonymity floor of 5 contributing branches per metric.
  • F8 — Auto-suggested corrective action. When a chemistry reading goes out of MAHC range, the "Corrective Action Taken" textarea pre-fills with the standard MAHC-aligned response. Editable — the playbook is a starting point, not a fill-in form.
  • F9 — Chemistry trend anomaly detection. Nightly background scan flags slow drifts (a slowly creeping combined chlorine, declining stabilizer) before they cross a hard threshold. Pure stats — every flag carries the z-score and slope numbers so an inspector asking "why did you flag this?" gets a concrete answer.
Added
  • Lifeguard "My Day" widget on the dashboard with three tiles: today's chemistry status (4-hour MAHC §5.7.3.1.1 cadence), training hours this month, and submissions filed in the last 7 days.
  • MAHC compliance binder export under Compliance & Reports → Compliance Binder. One date range, one button, one print-ready PDF covering chemistry logs, lifeguard observations, every checklist submission, certifications, and active staff.
  • Printable safety-concern poster at /poster/safety-concern for printing the F6 submission link as a break-room poster.
  • Per-org branding. Settings → Branding lets admins override the default OnDeck navy + aqua palette with primary and accent hex colors.
  • 30-day uptime stat on the status page.
  • Platform-admin Status tab (admin app only) — post incidents, flip component state, and append updates from a form instead of curl.
Changed
  • /signin-v2/signin. Old URL still works.
  • App-wide mobile-friendliness pass: outer padding shrinks on phones, multi-column input grids reflow to a single column, in-app tables gain horizontal scroll wrappers.
  • Kiosk auto-pins to the configured branch on single-branch orgs; shows a one-time picker on multi-branch orgs.
  • App Configuration: branches, pools, pool volumes, chemicals, and controllers now persist server-side and sync across devices.
Fixed
  • Stopwatch DRT timing no longer flips a 9.95s pass into a 10.0s fail.
  • Dashboard overdue thresholds now read from compliance config instead of being hardcoded.
  • ManagerView bulk PDF export caps at 25 to avoid filling the user's filesystem with a flood of separate downloads.
  • Org-purge confirmation accepts NBSP-pasted org names (was strict- equality silent-fail).
  • Onboarding strips the invite-token URL parameter before redeem so a hung redeem doesn't leave the token replayable in browser history.
  • Admin "delete all staff" replaces window.prompt with a proper modal that doesn't block the page.
Security
  • Discount-code regex anchored explicitly (HTML5 pattern is implicitly anchored, but the ^…$ makes the intent obvious and matches the server-side regex).
  • Stripe customer + subscription IDs in the admin dashboard now render masked by default with a "reveal" button.
  • Crash + unhandled-error monitoring posts to a Worker route for observability (vendor-neutral; swap for Sentry if/when adopted).
  • Per-IP rate limits on invitation create/redeem and self-serve signup endpoints.
  • Tenant-side audit-attribution helper (getImpersonatingAdminUserId) available so every audit emitter can record the real admin during impersonation instead of the sentinel user.

Have a request or found a bug?

We build OnDeck around what aquatics teams actually need. Tell us what would help, or flag anything that's broken.