Skip to content

Develop - #36

Merged
ucswift merged 2 commits into
masterfrom
develop
Sep 12, 2026
Merged

ucswift merged 2 commits into
masterfrom
develop

Conversation

@ucswift

@ucswift ucswift commented Sep 12, 2026

Copy link
Copy Markdown
Member

Summary

This PR significantly expands and restructures the Resgrid documentation to better reflect the current product and guide users by role, deployment model, and organization type.

What changed

Documentation overhaul for product coverage

  • Reworked the main introduction and web app overview to present Resgrid as a broader dispatch, records, readiness, and logistics platform.
  • Added or substantially expanded documentation for major product areas, including:
    • Records (RMS) and its sub-features
    • Run cards and automatic dispatch
    • Chat, Assistant, and moderation
    • Checklists
    • Work orders / maintenance
    • Advanced Data Protection
    • Hardware GPS tracking
    • Account security
    • Indoor maps
    • Feature flags and module gates

New Records documentation set

  • Introduced a full Records section covering:
    • Overview and activation
    • Dashboard and work queue
    • Record authoring
    • NERIS incident reports
    • Definitions and templates
    • Accountability, analytics, quality review
    • Occupancies, inspections, hydrants, permits, CRR
    • Investigations
    • Deployments/connectors
    • Legal holds and public-records requests
    • Saved reports/exports and settings

Expanded app documentation

  • Updated mobile/role-based app docs to document newer capabilities:
    • Dispatch app: run card recommendations, chat/Assistant, field records
    • Responder app: chat/Assistant, checklists, field records
    • Unit app: chat, checklists/equipment, field records, hardware trackers

Setup guidance by organization type

  • Added a new setup-guides section with prescriptive configuration guides for:
    • Fire departments
    • EMS agencies
    • Search & rescue teams
    • Emergency management / EOC
    • Incident management teams
    • CERT / community response
    • Security / facilities
    • Industrial emergency response
    • Delivery / transit / field service
    • Multi-agency dispatch centers
  • Linked the generic setup guide to these organization-specific recipes.

Self-hosted documentation refresh

  • Rewrote self-hosted guidance to match current deployment options and architecture.
  • Added/updated guidance for:
    • Single-server quick start
    • General installation
    • Windows laptop/desktop deployment
    • RICK deployment
    • Kubernetes/k3s deployment
  • Updated the architecture/reference docs to reflect current components and supported infrastructure.

Navigation and landing page improvements

  • Reorganized the top navigation into role/task-based dropdowns:
    • Get Started
    • Web App
    • Apps
    • Administer
    • Self-Hosted
    • Developers
  • Rebuilt the homepage with clearer entry points, grouped feature areas, app links, setup guides, and support/contribution links.
  • Added shared icon assets and refreshed homepage/navbar styling.

Broader web app page improvements

  • Updated many existing module pages to:
    • explain the feature in more user-facing terms,
    • add screenshots,
    • include setup examples for different organization types,
    • add clearer technical reference sections,
    • adjust page ordering/navigation positions.

Legacy/retired feature clarification

  • Marked the old Inventory Types page as legacy and redirected readers to the modern inventory workspace documentation.
  • Marked the old Forms module as retired and documented recommended replacements.
  • Clarified the relationship between Logs and Records for departments transitioning to Records.

Functional impact

  • Makes the docs align much more closely with Resgrid’s current product scope and terminology.
  • Gives administrators clearer guidance for enabling gated modules and configuring departments.
  • Adds end-to-end documentation for Records and readiness features that were previously undocumented or lightly documented.
  • Improves discoverability of content through a reorganized homepage and navbar.
  • Adds targeted setup guidance for the different kinds of organizations Resgrid supports.

@ucswift
ucswift merged commit d628331 into master Sep 12, 2026
1 of 2 checks passed
@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Essentials

Run ID: 8f8073ce-8dc9-4aef-abac-fc0ed349c93f

📥 Commits

Reviewing files that changed from the base of the PR and between 3d51f48 and be6cc0c.

⛔ Files ignored due to path filters (322)
  • package-lock.json is excluded by !**/package-lock.json
  • static/img/web-app/account/change-password.png is excluded by !**/*.png
  • static/img/web-app/account/change-username.png is excluded by !**/*.png
  • static/img/web-app/account/delete-account.png is excluded by !**/*.png
  • static/img/web-app/account/enable-2fa.png is excluded by !**/*.png
  • static/img/web-app/account/sessions.png is excluded by !**/*.png
  • static/img/web-app/account/two-factor.png is excluded by !**/*.png
  • static/img/web-app/analytics/accreditation.png is excluded by !**/*.png
  • static/img/web-app/analytics/community-risk.png is excluded by !**/*.png
  • static/img/web-app/analytics/index.png is excluded by !**/*.png
  • static/img/web-app/analytics/readiness.png is excluded by !**/*.png
  • static/img/web-app/analytics/response-performance.png is excluded by !**/*.png
  • static/img/web-app/analytics/workload.png is excluded by !**/*.png
  • static/img/web-app/calendar/index.png is excluded by !**/*.png
  • static/img/web-app/calendar/new-type.png is excluded by !**/*.png
  • static/img/web-app/calendar/new.png is excluded by !**/*.png
  • static/img/web-app/calendar/types.png is excluded by !**/*.png
  • static/img/web-app/chat/chatbot-settings.png is excluded by !**/*.png
  • static/img/web-app/chat/chatbot.png is excluded by !**/*.png
  • static/img/web-app/chat/index.png is excluded by !**/*.png
  • static/img/web-app/chat/moderation.png is excluded by !**/*.png
  • static/img/web-app/checklists/compliance.png is excluded by !**/*.png
  • static/img/web-app/checklists/detail.png is excluded by !**/*.png
  • static/img/web-app/checklists/due.png is excluded by !**/*.png
  • static/img/web-app/checklists/edit-schedule.png is excluded by !**/*.png
  • static/img/web-app/checklists/index.png is excluded by !**/*.png
  • static/img/web-app/checklists/new.png is excluded by !**/*.png
  • static/img/web-app/checklists/readiness-packet.png is excluded by !**/*.png
  • static/img/web-app/checklists/reminders.png is excluded by !**/*.png
  • static/img/web-app/checklists/run.png is excluded by !**/*.png
  • static/img/web-app/checklists/schedules.png is excluded by !**/*.png
  • static/img/web-app/checklists/template.png is excluded by !**/*.png
  • static/img/web-app/checklists/templates.png is excluded by !**/*.png
  • static/img/web-app/command/edit.png is excluded by !**/*.png
  • static/img/web-app/command/index.png is excluded by !**/*.png
  • static/img/web-app/command/new.png is excluded by !**/*.png
  • static/img/web-app/command/templates.png is excluded by !**/*.png
  • static/img/web-app/command/view.png is excluded by !**/*.png
  • static/img/web-app/communication-tests/edit.png is excluded by !**/*.png
  • static/img/web-app/communication-tests/index.png is excluded by !**/*.png
  • static/img/web-app/communication-tests/new.png is excluded by !**/*.png
  • static/img/web-app/contacts/add-category.png is excluded by !**/*.png
  • static/img/web-app/contacts/add.png is excluded by !**/*.png
  • static/img/web-app/contacts/attachments.png is excluded by !**/*.png
  • static/img/web-app/contacts/categories.png is excluded by !**/*.png
  • static/img/web-app/contacts/edit.png is excluded by !**/*.png
  • static/img/web-app/contacts/index.png is excluded by !**/*.png
  • static/img/web-app/contacts/preplan.png is excluded by !**/*.png
  • static/img/web-app/contacts/view.png is excluded by !**/*.png
  • static/img/web-app/custom-maps/import.png is excluded by !**/*.png
  • static/img/web-app/custom-maps/index.png is excluded by !**/*.png
  • static/img/web-app/custom-maps/layers.png is excluded by !**/*.png
  • static/img/web-app/custom-maps/new.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/edit.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/index.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/new-personnel.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/new-staffing.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/new-unit.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/templates-personnel.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/templates-staffing.png is excluded by !**/*.png
  • static/img/web-app/custom-statuses/templates-unit.png is excluded by !**/*.png
  • static/img/web-app/department/address.png is excluded by !**/*.png
  • static/img/web-app/department/api.png is excluded by !**/*.png
  • static/img/web-app/department/call-settings.png is excluded by !**/*.png
  • static/img/web-app/department/delete-department.png is excluded by !**/*.png
  • static/img/web-app/department/dispatch-settings.png is excluded by !**/*.png
  • static/img/web-app/department/invites.png is excluded by !**/*.png
  • static/img/web-app/department/mapping-settings.png is excluded by !**/*.png
  • static/img/web-app/department/module-settings.png is excluded by !**/*.png
  • static/img/web-app/department/profile.png is excluded by !**/*.png
  • static/img/web-app/department/settings.png is excluded by !**/*.png
  • static/img/web-app/department/setup-wizard.png is excluded by !**/*.png
  • static/img/web-app/department/shift-settings.png is excluded by !**/*.png
  • static/img/web-app/department/text-settings.png is excluded by !**/*.png
  • static/img/web-app/department/types.png is excluded by !**/*.png
  • static/img/web-app/department/unit-settings.png is excluded by !**/*.png
  • static/img/web-app/dispatch/add-archived-call.png is excluded by !**/*.png
  • static/img/web-app/dispatch/archived-calls.png is excluded by !**/*.png
  • static/img/web-app/dispatch/call-data.png is excluded by !**/*.png
  • static/img/web-app/dispatch/calls-dashboard.png is excluded by !**/*.png
  • static/img/web-app/dispatch/close-call.png is excluded by !**/*.png
  • static/img/web-app/dispatch/new-call.png is excluded by !**/*.png
  • static/img/web-app/dispatch/scheduled-calls.png is excluded by !**/*.png
  • static/img/web-app/dispatch/update-call.png is excluded by !**/*.png
  • static/img/web-app/dispatch/view-call.png is excluded by !**/*.png
  • static/img/web-app/distribution-lists/edit-list.png is excluded by !**/*.png
  • static/img/web-app/distribution-lists/index.png is excluded by !**/*.png
  • static/img/web-app/distribution-lists/new-list.png is excluded by !**/*.png
  • static/img/web-app/documents/index.png is excluded by !**/*.png
  • static/img/web-app/documents/new-document.png is excluded by !**/*.png
  • static/img/web-app/documents/view-document.png is excluded by !**/*.png
  • static/img/web-app/groups/edit-group.png is excluded by !**/*.png
  • static/img/web-app/groups/geofence.png is excluded by !**/*.png
  • static/img/web-app/groups/index.png is excluded by !**/*.png
  • static/img/web-app/groups/new-group.png is excluded by !**/*.png
  • static/img/web-app/home/dashboard-tutorial.png is excluded by !**/*.png
  • static/img/web-app/home/dashboard.png is excluded by !**/*.png
  • static/img/web-app/home/edit-profile.png is excluded by !**/*.png
  • static/img/web-app/home/search-results.png is excluded by !**/*.png
  • static/img/web-app/home/setup-report.png is excluded by !**/*.png
  • static/img/web-app/incident-reports/details.png is excluded by !**/*.png
  • static/img/web-app/incident-reports/edit.png is excluded by !**/*.png
  • static/img/web-app/incident-reports/index.png is excluded by !**/*.png
  • static/img/web-app/incident-reports/settings.png is excluded by !**/*.png
  • static/img/web-app/indoor-maps/index.png is excluded by !**/*.png
  • static/img/web-app/indoor-maps/new.png is excluded by !**/*.png
  • static/img/web-app/inventory/add-type.png is excluded by !**/*.png
  • static/img/web-app/inventory/adjust.png is excluded by !**/*.png
  • static/img/web-app/inventory/asset-detail.png is excluded by !**/*.png
  • static/img/web-app/inventory/history.png is excluded by !**/*.png
  • static/img/web-app/inventory/manage-types.png is excluded by !**/*.png
  • static/img/web-app/inventory/on-hand.png is excluded by !**/*.png
  • static/img/web-app/inventory/operations-counts.png is excluded by !**/*.png
  • static/img/web-app/inventory/operations-reports.png is excluded by !**/*.png
  • static/img/web-app/inventory/personnel-gear.png is excluded by !**/*.png
  • static/img/web-app/inventory/purchasing-orders.png is excluded by !**/*.png
  • static/img/web-app/inventory/purchasing-vendors.png is excluded by !**/*.png
  • static/img/web-app/inventory/tab-assets.png is excluded by !**/*.png
  • static/img/web-app/inventory/tab-issuance.png is excluded by !**/*.png
  • static/img/web-app/inventory/tab-items.png is excluded by !**/*.png
  • static/img/web-app/inventory/tab-locations.png is excluded by !**/*.png
  • static/img/web-app/inventory/tab-vendors.png is excluded by !**/*.png
  • static/img/web-app/inventory/unit-equipment.png is excluded by !**/*.png
  • static/img/web-app/links/index.png is excluded by !**/*.png
  • static/img/web-app/links/new.png is excluded by !**/*.png
  • static/img/web-app/links/view.png is excluded by !**/*.png
  • static/img/web-app/logs/index.png is excluded by !**/*.png
  • static/img/web-app/logs/new-log.png is excluded by !**/*.png
  • static/img/web-app/logs/view.png is excluded by !**/*.png
  • static/img/web-app/mapping/add-poi-type.png is excluded by !**/*.png
  • static/img/web-app/mapping/index.png is excluded by !**/*.png
  • static/img/web-app/mapping/layers.png is excluded by !**/*.png
  • static/img/web-app/mapping/new-layer.png is excluded by !**/*.png
  • static/img/web-app/mapping/pois.png is excluded by !**/*.png
  • static/img/web-app/mapping/settings.png is excluded by !**/*.png
  • static/img/web-app/messages/compose.png is excluded by !**/*.png
  • static/img/web-app/messages/inbox.png is excluded by !**/*.png
  • static/img/web-app/messages/outbox.png is excluded by !**/*.png
  • static/img/web-app/messages/view-message.png is excluded by !**/*.png
  • static/img/web-app/notes/index.png is excluded by !**/*.png
  • static/img/web-app/notes/new-note.png is excluded by !**/*.png
  • static/img/web-app/notes/view.png is excluded by !**/*.png
  • static/img/web-app/notifications/index.png is excluded by !**/*.png
  • static/img/web-app/notifications/new.png is excluded by !**/*.png
  • static/img/web-app/orders/index.png is excluded by !**/*.png
  • static/img/web-app/orders/new.png is excluded by !**/*.png
  • static/img/web-app/orders/settings.png is excluded by !**/*.png
  • static/img/web-app/orders/view.png is excluded by !**/*.png
  • static/img/web-app/personnel/add-person.png is excluded by !**/*.png
  • static/img/web-app/personnel/add-role.png is excluded by !**/*.png
  • static/img/web-app/personnel/edit-role.png is excluded by !**/*.png
  • static/img/web-app/personnel/index.png is excluded by !**/*.png
  • static/img/web-app/personnel/roles.png is excluded by !**/*.png
  • static/img/web-app/personnel/view-events.png is excluded by !**/*.png
  • static/img/web-app/personnel/view-person.png is excluded by !**/*.png
  • static/img/web-app/personnel/view-role.png is excluded by !**/*.png
  • static/img/web-app/prevention/crr-new.png is excluded by !**/*.png
  • static/img/web-app/prevention/crr.png is excluded by !**/*.png
  • static/img/web-app/prevention/hydrant-details.png is excluded by !**/*.png
  • static/img/web-app/prevention/hydrant-new.png is excluded by !**/*.png
  • static/img/web-app/prevention/hydrants.png is excluded by !**/*.png
  • static/img/web-app/prevention/inspection-code-sets.png is excluded by !**/*.png
  • static/img/web-app/prevention/inspection-programs.png is excluded by !**/*.png
  • static/img/web-app/prevention/inspections.png is excluded by !**/*.png
  • static/img/web-app/prevention/investigation-details.png is excluded by !**/*.png
  • static/img/web-app/prevention/investigation-open.png is excluded by !**/*.png
  • static/img/web-app/prevention/investigations.png is excluded by !**/*.png
  • static/img/web-app/prevention/occupancies.png is excluded by !**/*.png
  • static/img/web-app/prevention/occupancy-crosswalk.png is excluded by !**/*.png
  • static/img/web-app/prevention/occupancy-details.png is excluded by !**/*.png
  • static/img/web-app/prevention/occupancy-new.png is excluded by !**/*.png
  • static/img/web-app/prevention/permit-details.png is excluded by !**/*.png
  • static/img/web-app/prevention/permit-new.png is excluded by !**/*.png
  • static/img/web-app/prevention/permit-types.png is excluded by !**/*.png
  • static/img/web-app/prevention/permits.png is excluded by !**/*.png
  • static/img/web-app/profile/add-certification.png is excluded by !**/*.png
  • static/img/web-app/profile/add-scheduled-report.png is excluded by !**/*.png
  • static/img/web-app/profile/add-staffing-schedule.png is excluded by !**/*.png
  • static/img/web-app/profile/certifications.png is excluded by !**/*.png
  • static/img/web-app/profile/reporting.png is excluded by !**/*.png
  • static/img/web-app/profile/staffing-schedules.png is excluded by !**/*.png
  • static/img/web-app/profile/your-departments.png is excluded by !**/*.png
  • static/img/web-app/protocols/index.png is excluded by !**/*.png
  • static/img/web-app/protocols/new.png is excluded by !**/*.png
  • static/img/web-app/protocols/view.png is excluded by !**/*.png
  • static/img/web-app/records/accountability.png is excluded by !**/*.png
  • static/img/web-app/records/activate.png is excluded by !**/*.png
  • static/img/web-app/records/dashboard.png is excluded by !**/*.png
  • static/img/web-app/records/definition-edit.png is excluded by !**/*.png
  • static/img/web-app/records/definition-history.png is excluded by !**/*.png
  • static/img/web-app/records/definition-layout.png is excluded by !**/*.png
  • static/img/web-app/records/definition-templates.png is excluded by !**/*.png
  • static/img/web-app/records/definitions.png is excluded by !**/*.png
  • static/img/web-app/records/deployment-connector-new.png is excluded by !**/*.png
  • static/img/web-app/records/deployment-connectors.png is excluded by !**/*.png
  • static/img/web-app/records/deployment-new.png is excluded by !**/*.png
  • static/img/web-app/records/deployments.png is excluded by !**/*.png
  • static/img/web-app/records/details.png is excluded by !**/*.png
  • static/img/web-app/records/disclosures.png is excluded by !**/*.png
  • static/img/web-app/records/edit.png is excluded by !**/*.png
  • static/img/web-app/records/export-template-edit.png is excluded by !**/*.png
  • static/img/web-app/records/export-templates.png is excluded by !**/*.png
  • static/img/web-app/records/field-rollout.png is excluded by !**/*.png
  • static/img/web-app/records/health.png is excluded by !**/*.png
  • static/img/web-app/records/index.png is excluded by !**/*.png
  • static/img/web-app/records/legal-holds.png is excluded by !**/*.png
  • static/img/web-app/records/new.png is excluded by !**/*.png
  • static/img/web-app/records/quality-index.png is excluded by !**/*.png
  • static/img/web-app/records/quality-rubric.png is excluded by !**/*.png
  • static/img/web-app/records/quality-trends.png is excluded by !**/*.png
  • static/img/web-app/records/saved-reports.png is excluded by !**/*.png
  • static/img/web-app/records/settings.png is excluded by !**/*.png
  • static/img/web-app/reports/action-logs-params.png is excluded by !**/*.png
  • static/img/web-app/reports/active-calls-resources.png is excluded by !**/*.png
  • static/img/web-app/reports/call-summary-params.png is excluded by !**/*.png
  • static/img/web-app/reports/certifications-report.png is excluded by !**/*.png
  • static/img/web-app/reports/department-activity.png is excluded by !**/*.png
  • static/img/web-app/reports/event-attendance-params.png is excluded by !**/*.png
  • static/img/web-app/reports/flagged-call-notes-params.png is excluded by !**/*.png
  • static/img/web-app/reports/index.png is excluded by !**/*.png
  • static/img/web-app/reports/personnel-hours-params.png is excluded by !**/*.png
  • static/img/web-app/reports/personnel-report.png is excluded by !**/*.png
  • static/img/web-app/reports/personnel-staffing-history-params.png is excluded by !**/*.png
  • static/img/web-app/reports/staffing-report.png is excluded by !**/*.png
  • static/img/web-app/reports/unit-state-history-params.png is excluded by !**/*.png
  • static/img/web-app/reports/upcoming-shift-readiness.png is excluded by !**/*.png
  • static/img/web-app/routes/active-routes.png is excluded by !**/*.png
  • static/img/web-app/routes/archived-routes.png is excluded by !**/*.png
  • static/img/web-app/routes/edit.png is excluded by !**/*.png
  • static/img/web-app/routes/index.png is excluded by !**/*.png
  • static/img/web-app/routes/new.png is excluded by !**/*.png
  • static/img/web-app/routes/view.png is excluded by !**/*.png
  • static/img/web-app/run-cards/edit.png is excluded by !**/*.png
  • static/img/web-app/run-cards/index.png is excluded by !**/*.png
  • static/img/web-app/run-cards/new.png is excluded by !**/*.png
  • static/img/web-app/security/audits.png is excluded by !**/*.png
  • static/img/web-app/security/data-protection.png is excluded by !**/*.png
  • static/img/web-app/security/index.png is excluded by !**/*.png
  • static/img/web-app/security/security-policy.png is excluded by !**/*.png
  • static/img/web-app/security/sso-new-oidc.png is excluded by !**/*.png
  • static/img/web-app/security/sso-new-saml.png is excluded by !**/*.png
  • static/img/web-app/security/sso.png is excluded by !**/*.png
  • static/img/web-app/security/view-audit.png is excluded by !**/*.png
  • static/img/web-app/shifts/edit-shift-days.png is excluded by !**/*.png
  • static/img/web-app/shifts/edit-shift-details.png is excluded by !**/*.png
  • static/img/web-app/shifts/edit-shift-groups.png is excluded by !**/*.png
  • static/img/web-app/shifts/index.png is excluded by !**/*.png
  • static/img/web-app/shifts/new-shift.png is excluded by !**/*.png
  • static/img/web-app/shifts/settings.png is excluded by !**/*.png
  • static/img/web-app/shifts/shift-calendar.png is excluded by !**/*.png
  • static/img/web-app/shifts/shift-staffing.png is excluded by !**/*.png
  • static/img/web-app/shifts/your-shifts.png is excluded by !**/*.png
  • static/img/web-app/subscription/buy-adp-addon.png is excluded by !**/*.png
  • static/img/web-app/subscription/cancel.png is excluded by !**/*.png
  • static/img/web-app/subscription/index.png is excluded by !**/*.png
  • static/img/web-app/subscription/manage-adp-addon.png is excluded by !**/*.png
  • static/img/web-app/subscription/manage-ptt-addon.png is excluded by !**/*.png
  • static/img/web-app/subscription/payment-history.png is excluded by !**/*.png
  • static/img/web-app/subscription/update-billing-info.png is excluded by !**/*.png
  • static/img/web-app/templates/call-notes.png is excluded by !**/*.png
  • static/img/web-app/templates/edit.png is excluded by !**/*.png
  • static/img/web-app/templates/index.png is excluded by !**/*.png
  • static/img/web-app/templates/new-call-note.png is excluded by !**/*.png
  • static/img/web-app/templates/new.png is excluded by !**/*.png
  • static/img/web-app/trainings/edit.png is excluded by !**/*.png
  • static/img/web-app/trainings/index.png is excluded by !**/*.png
  • static/img/web-app/trainings/new.png is excluded by !**/*.png
  • static/img/web-app/trainings/report.png is excluded by !**/*.png
  • static/img/web-app/trainings/view.png is excluded by !**/*.png
  • static/img/web-app/types/edit-call-priority.png is excluded by !**/*.png
  • static/img/web-app/types/edit-call-type.png is excluded by !**/*.png
  • static/img/web-app/types/edit-unit-type.png is excluded by !**/*.png
  • static/img/web-app/types/index.png is excluded by !**/*.png
  • static/img/web-app/types/list-ordering.png is excluded by !**/*.png
  • static/img/web-app/types/new-call-priority.png is excluded by !**/*.png
  • static/img/web-app/types/new-call-type.png is excluded by !**/*.png
  • static/img/web-app/types/new-certification-type.png is excluded by !**/*.png
  • static/img/web-app/types/new-contact-note-type.png is excluded by !**/*.png
  • static/img/web-app/types/new-document-type.png is excluded by !**/*.png
  • static/img/web-app/types/new-note-type.png is excluded by !**/*.png
  • static/img/web-app/types/new-unit-type.png is excluded by !**/*.png
  • static/img/web-app/units/edit-unit.png is excluded by !**/*.png
  • static/img/web-app/units/index.png is excluded by !**/*.png
  • static/img/web-app/units/new-unit.png is excluded by !**/*.png
  • static/img/web-app/units/tracking-index.png is excluded by !**/*.png
  • static/img/web-app/units/tracking-new.png is excluded by !**/*.png
  • static/img/web-app/units/unit-staffing.png is excluded by !**/*.png
  • static/img/web-app/units/view-events.png is excluded by !**/*.png
  • static/img/web-app/units/view-logs.png is excluded by !**/*.png
  • static/img/web-app/user-defined-fields/edit-call.png is excluded by !**/*.png
  • static/img/web-app/user-defined-fields/edit-personnel.png is excluded by !**/*.png
  • static/img/web-app/user-defined-fields/edit-unit.png is excluded by !**/*.png
  • static/img/web-app/user-defined-fields/index.png is excluded by !**/*.png
  • static/img/web-app/user-defined-fields/preview-call.png is excluded by !**/*.png
  • static/img/web-app/voice/index.png is excluded by !**/*.png
  • static/img/web-app/voice/new-audio.png is excluded by !**/*.png
  • static/img/web-app/voice/new.png is excluded by !**/*.png
  • static/img/web-app/weather-alerts/history.png is excluded by !**/*.png
  • static/img/web-app/weather-alerts/index.png is excluded by !**/*.png
  • static/img/web-app/weather-alerts/settings.png is excluded by !**/*.png
  • static/img/web-app/weather-alerts/zones.png is excluded by !**/*.png
  • static/img/web-app/work-orders/bulk.png is excluded by !**/*.png
  • static/img/web-app/work-orders/detail.png is excluded by !**/*.png
  • static/img/web-app/work-orders/edit.png is excluded by !**/*.png
  • static/img/web-app/work-orders/history.png is excluded by !**/*.png
  • static/img/web-app/work-orders/index.png is excluded by !**/*.png
  • static/img/web-app/work-orders/new-recurrence.png is excluded by !**/*.png
  • static/img/web-app/work-orders/new.png is excluded by !**/*.png
  • static/img/web-app/work-orders/operations.png is excluded by !**/*.png
  • static/img/web-app/work-orders/policy.png is excluded by !**/*.png
  • static/img/web-app/work-orders/readiness-pro-billing.png is excluded by !**/*.png
  • static/img/web-app/work-orders/recurrences.png is excluded by !**/*.png
  • static/img/web-app/work-orders/reports.png is excluded by !**/*.png
  • static/img/web-app/workflows/credential-new.png is excluded by !**/*.png
  • static/img/web-app/workflows/credentials.png is excluded by !**/*.png
  • static/img/web-app/workflows/edit.png is excluded by !**/*.png
  • static/img/web-app/workflows/health.png is excluded by !**/*.png
  • static/img/web-app/workflows/index.png is excluded by !**/*.png
  • static/img/web-app/workflows/new.png is excluded by !**/*.png
  • static/img/web-app/workflows/pending.png is excluded by !**/*.png
  • static/img/web-app/workflows/runs.png is excluded by !**/*.png
  • static/img/web-app/workshifts/new.png is excluded by !**/*.png
📒 Files selected for processing (103)
  • docs/apps/dispatch.md
  • docs/apps/responder.md
  • docs/apps/unit.md
  • docs/configuration/inventory-types.md
  • docs/how-tos/setup-department.md
  • docs/intro.md
  • docs/reference/feature-flags.md
  • docs/reference/overview.md
  • docs/self-hosted/installation.md
  • docs/self-hosted/laptop.md
  • docs/self-hosted/multi.md
  • docs/self-hosted/quick-start.md
  • docs/self-hosted/rick.md
  • docs/setup-guides/_category_.json
  • docs/setup-guides/cert-community-response.md
  • docs/setup-guides/delivery-transit-field-service.md
  • docs/setup-guides/emergency-management.md
  • docs/setup-guides/ems-agency.md
  • docs/setup-guides/fire-department.md
  • docs/setup-guides/incident-management-team.md
  • docs/setup-guides/industrial-emergency-response.md
  • docs/setup-guides/multi-agency-dispatch-center.md
  • docs/setup-guides/overview.md
  • docs/setup-guides/search-and-rescue.md
  • docs/setup-guides/security-and-facilities.md
  • docs/web-app/account-security.md
  • docs/web-app/calendar.md
  • docs/web-app/call-checkin-timers.md
  • docs/web-app/chat.md
  • docs/web-app/checklists.md
  • docs/web-app/command-definitions.md
  • docs/web-app/communication-tests.md
  • docs/web-app/connect.md
  • docs/web-app/contacts.md
  • docs/web-app/custom-maps.md
  • docs/web-app/custom-statuses.md
  • docs/web-app/dashboard.md
  • docs/web-app/data-protection.md
  • docs/web-app/department-links.md
  • docs/web-app/department-settings.md
  • docs/web-app/dispatch-calls.md
  • docs/web-app/distribution-lists.md
  • docs/web-app/documents.md
  • docs/web-app/forms.md
  • docs/web-app/groups-stations.md
  • docs/web-app/help-setup.md
  • docs/web-app/indoor-maps.md
  • docs/web-app/inventory.md
  • docs/web-app/logs.md
  • docs/web-app/mapping.md
  • docs/web-app/messages.md
  • docs/web-app/navigation.md
  • docs/web-app/notes.md
  • docs/web-app/notifications.md
  • docs/web-app/overview.md
  • docs/web-app/personnel.md
  • docs/web-app/profile-account.md
  • docs/web-app/protocols.md
  • docs/web-app/records/_category_.json
  • docs/web-app/records/accountability.md
  • docs/web-app/records/analytics.md
  • docs/web-app/records/authoring.md
  • docs/web-app/records/community-risk-reduction.md
  • docs/web-app/records/dashboard-and-queue.md
  • docs/web-app/records/definitions.md
  • docs/web-app/records/deployments.md
  • docs/web-app/records/hydrants.md
  • docs/web-app/records/incident-reports.md
  • docs/web-app/records/inspections.md
  • docs/web-app/records/investigations.md
  • docs/web-app/records/legal-holds-and-disclosures.md
  • docs/web-app/records/occupancies.md
  • docs/web-app/records/overview.md
  • docs/web-app/records/permits.md
  • docs/web-app/records/quality-review.md
  • docs/web-app/records/reports-and-exports.md
  • docs/web-app/records/settings.md
  • docs/web-app/reports.md
  • docs/web-app/resource-orders.md
  • docs/web-app/routes.md
  • docs/web-app/run-cards.md
  • docs/web-app/search.md
  • docs/web-app/security-permissions.md
  • docs/web-app/shifts.md
  • docs/web-app/subscription-billing.md
  • docs/web-app/templates.md
  • docs/web-app/trainings.md
  • docs/web-app/types-configuration.md
  • docs/web-app/unit-tracking.md
  • docs/web-app/units.md
  • docs/web-app/user-defined-fields.md
  • docs/web-app/voice-audio.md
  • docs/web-app/weather-alerts.md
  • docs/web-app/work-orders.md
  • docs/web-app/workflows.md
  • docs/web-app/workshifts.md
  • docusaurus.config.js
  • src/components/HomepageFeatures/Icons.js
  • src/components/HomepageFeatures/index.js
  • src/components/HomepageFeatures/styles.module.css
  • src/css/custom.css
  • src/pages/index.js
  • src/pages/index.module.css

📝 Walkthrough

Walkthrough

The pull request expands documentation for product capabilities, organization setup, Records, and self-hosting. It also redesigns the Docusaurus navbar and homepage with categorized navigation, shared icons, responsive layouts, and new landing-page content.

Changes

Documentation foundation

Layer / File(s) Summary
Product and reference documentation
docs/intro.md, docs/apps/*, docs/reference/*
The documentation now describes current platform capabilities, applications, feature flags, system components, and configuration behavior.
Self-hosted deployment guides
docs/self-hosted/*
The guides now cover Compose, Windows, Kubernetes/k3s, and RICK deployments with installation, operations, backups, updates, and rollback procedures.
Organization setup guides
docs/setup-guides/*, docs/how-tos/setup-department.md
New guides define setup sequences and operational configuration for multiple organization types.

Web application and Records documentation

Layer / File(s) Summary
Web application module guides
docs/web-app/*.md
Module pages now use user-focused guidance, screenshots, setup examples, and consolidated technical references.
Records documentation
docs/web-app/records/*
New Records pages cover authoring, definitions, incident reports, analytics, inspections, investigations, disclosures, reports, quality review, and settings.

Site navigation and homepage

Layer / File(s) Summary
Navbar and shared icons
docusaurus.config.js, src/css/custom.css, src/components/HomepageFeatures/Icons.js
The navbar now uses categorized dropdowns, external links, responsive GitHub presentation, and a reusable inline SVG icon component.
Homepage content and layout
src/pages/index.js, src/pages/index.module.css, src/components/HomepageFeatures/index.js, src/components/HomepageFeatures/styles.module.css
The homepage now contains a redesigned hero, popular-module links, statistics, platform feature areas, application links, setup guides, resources, support links, responsive styling, dark-theme variants, and reduced-motion handling.

Estimated code review effort: 5 (Critical) | ~90 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch develop

Comment @coderabbitai help to get the list of available commands.

@Resgrid-Bot

Resgrid-Bot commented Sep 12, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug
Performance
Security
Business Logic

Access your configuration settings here.

Comment thread docs/self-hosted/multi.md
./setup.sh
```

Without supplied TLS files, setup generates a self-signed certificate containing all three hostnames. Distribute/trust `deploy/generated/tls.crt` on clients.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

TLS guidance in docs/self-hosted/multi.md and docs/web-app/security-permissions.md:106-106 permits self-signed certificates for externally exposed endpoints, weakening trust establishment for public services. Restrict self-signed certificates to local non-production testing and document that public endpoints require TLS 1.2+ with a trusted CA-issued certificate and HSTS enabled.

Kody rule violation: Enforce TLS 1.2+ and HSTS on all external endpoints

Prompt for LLM

File docs/self-hosted/multi.md:

Line 80:

TLS guidance in `docs/self-hosted/multi.md` and `docs/web-app/security-permissions.md:106-106` permits self-signed certificates for externally exposed endpoints, weakening trust establishment for public services. Restrict self-signed certificates to local non-production testing and document that public endpoints require TLS 1.2+ with a trusted CA-issued certificate and HSTS enabled.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.


# Setting Up a Security Company, Campus Security or Facilities Team

For contract security companies with many client sites, campus / healthcare / corporate security departments, and facilities teams that respond to alarms, incidents and service requests. In Resgrid a **client site is a station group**, a **patrol vehicle or post is a unit**, an **incident or request is a call**, and patrol logs and incident reports are **records**.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

Legal-basis omission in docs/setup-guides/security-and-facilities.md and the matching references in docs/web-app/contacts.md:8-8, docs/web-app/unit-tracking.md:44-44, docs/web-app/dispatch-calls.md:127-127, docs/web-app/account-security.md:60-60, docs/web-app/records/reports-and-exports.md:58-58, docs/setup-guides/security-and-facilities.md:27-27, docs/web-app/records/reports-and-exports.md:54-54, docs/web-app/security-permissions.md:76-76, docs/apps/unit.md:152-152, docs/setup-guides/security-and-facilities.md:57-57, and docs/web-app/personnel.md:38-38 leaves sensitive-data handling requirements undefined. State that processing health-related or other sensitive data requires explicit consent or another valid legal basis, require the consent or authorization identifier where applicable, and document consent verification before handling that data.

Kody rule violation: Require explicit consent before processing sensitive data

Prompt for LLM

File docs/setup-guides/security-and-facilities.md:

Line 8:

Legal-basis omission in `docs/setup-guides/security-and-facilities.md` and the matching references in `docs/web-app/contacts.md:8-8`, `docs/web-app/unit-tracking.md:44-44`, `docs/web-app/dispatch-calls.md:127-127`, `docs/web-app/account-security.md:60-60`, `docs/web-app/records/reports-and-exports.md:58-58`, `docs/setup-guides/security-and-facilities.md:27-27`, `docs/web-app/records/reports-and-exports.md:54-54`, `docs/web-app/security-permissions.md:76-76`, `docs/apps/unit.md:152-152`, `docs/setup-guides/security-and-facilities.md:57-57`, and `docs/web-app/personnel.md:38-38` leaves sensitive-data handling requirements undefined. State that processing health-related or other sensitive data requires explicit consent or another valid legal basis, require the consent or authorization identifier where applicable, and document consent verification before handling that data.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

Comment thread docs/web-app/dashboard.md
## Editing profiles from the dashboard

### Custom Staffing Levels
Clicking a name opens the person; administrators can **edit the profile** (name, email, phone numbers and carrier, group and roles, addresses, language, time zone, notification options, department admin / disabled / hidden flags). See [Personnel](personnel) and [Profile & Account](profile-account).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

PII exposure in docs/web-app/dashboard.md lists raw personal data fields without privacy-handling constraints. Minimize direct enumeration of name, email, phone numbers, carrier, addresses, and related profile fields, or state explicitly that diagnostics and telemetry must redact or hash PII by default.

Kody rule violation: Redact PII in logs and metrics by default

Clicking a name opens the person; administrators can edit profile details permitted by policy, with personal data minimized and redacted in diagnostics/telemetry. See [Personnel](personnel) and [Profile & Account](profile-account).
Prompt for LLM

File docs/web-app/dashboard.md:

Line 36:

PII exposure in `docs/web-app/dashboard.md` lists raw personal data fields without privacy-handling constraints. Minimize direct enumeration of name, email, phone numbers, carrier, addresses, and related profile fields, or state explicitly that diagnostics and telemetry must redact or hash PII by default.

Suggested Code:

Clicking a name opens the person; administrators can edit profile details permitted by policy, with personal data minimized and redacted in diagnostics/telemetry. See [Personnel](personnel) and [Profile & Account](profile-account).

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

| Data endpoints | `GetActiveCallsList`, `GetArchivedCallsList?year=`, `GetScheduledCallsList`, `GetCallNotes`, `GetPersonnelForCall`, `GetAllDispatchesForCall`, `GetMapDataForCall`, `GetCallTypes`, `GetCallPriorities`, `GetCallsForSelectList`, `GetCoordinatesFromW3W`, `GetAlertNotesForContact`, `GetDispatchRecommendation`, `CallsYTD`, `CallsTypesInRange`, `CallsStatesInRange` |
| Attachments | 10 MB; images jpg/jpeg/png/gif/bmp; documents pdf/doc/docx/ppt/pptx/xls/xlsx/txt; audio mp3/m4a/ogg/wav; video mp4/m4v/mov/wmv/avi/mpg |
| Soft delete | `IsDeleted`, `DeletedOn`, `DeletedByUserId`, `DeletedReason` |
| Protected data | Name, nature, notes, address and attachments are ADP-protected fields |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Protected-data documentation in docs/web-app/dispatch-calls.md and the matching references in docs/web-app/contacts.md:8-8, docs/setup-guides/security-and-facilities.md:45-45, docs/setup-guides/industrial-emergency-response.md:51-51, docs/web-app/dashboard.md:36-36, docs/apps/unit.md:148-148, docs/web-app/records/authoring.md:102-102, docs/web-app/data-protection.md:59-59, docs/web-app/personnel.md:8-8, and docs/web-app/personnel.md:47-47 enumerates PHI-like fields such as name and address without stating log-handling constraints. Clarify that these fields must be masked or redacted, never written to logs, and, if the section describes storage or protection, documented as protected at rest and in transit and excluded from logs and audit payloads except tokenized metadata.

Kody rule violation: Do not log PHI; mask and drop sensitive fields

Prompt for LLM

File docs/web-app/dispatch-calls.md:

Line 127:

Protected-data documentation in `docs/web-app/dispatch-calls.md` and the matching references in `docs/web-app/contacts.md:8-8`, `docs/setup-guides/security-and-facilities.md:45-45`, `docs/setup-guides/industrial-emergency-response.md:51-51`, `docs/web-app/dashboard.md:36-36`, `docs/apps/unit.md:148-148`, `docs/web-app/records/authoring.md:102-102`, `docs/web-app/data-protection.md:59-59`, `docs/web-app/personnel.md:8-8`, and `docs/web-app/personnel.md:47-47` enumerates PHI-like fields such as name and address without stating log-handling constraints. Clarify that these fields must be masked or redacted, never written to logs, and, if the section describes storage or protection, documented as protected at rest and in transit and excluded from logs and audit payloads except tokenized metadata.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

Comment thread docs/web-app/personnel.md
### Removing someone

**Authorization:** `Personnel_View` policy + `CanUserViewUser` runtime check
**Delete** removes the member from the department. Resgrid recommends **disabling** instead of deleting so history, logs and reports stay intact; underlying data is retained, so clear personal details first if you must delete. A member who still owns unfinished [Records](records/authoring) must have them reassigned first. Deleted members can be **reactivated** by adding them again with the same email.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

Deletion-semantics conflict in docs/web-app/personnel.md retains underlying data and allows reactivation by the same email, which does not satisfy irreversible deletion or anonymization expectations. Document an irreversible anonymization or hard-delete path for deletion requests, including cache purging and retention of only minimal non-linkable audit metadata.

Kody rule violation: Deletion requests: anonymize or hard-delete PII irreversibly

Prompt for LLM

File docs/web-app/personnel.md:

Line 64:

Deletion-semantics conflict in `docs/web-app/personnel.md` retains underlying data and allows reactivation by the same email, which does not satisfy irreversible deletion or anonymization expectations. Document an irreversible anonymization or hard-delete path for deletion requests, including cache purging and retention of only minimal non-linkable audit metadata.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.


Feature flag: `Records.Analytics`. Menu: **Records → Analytics**.

![Analytics](/img/web-app/analytics/index.png)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Image-delivery inefficiency in docs/web-app/records/analytics.md and the matching references uses a PNG without responsive sources, explicit dimensions, lazy loading, or async decoding. Prefer modern formats such as WebP or AVIF and, where supported by the site tooling, document responsive images with explicit sizing and lazy loading to reduce payload and improve rendering performance.

Kody rule violation: Serve responsive images with modern formats and lazy-load

![Analytics](/img/web-app/analytics/index.webp)
Prompt for LLM

File docs/web-app/records/analytics.md:

Line 12:

Image-delivery inefficiency in `docs/web-app/records/analytics.md` and the matching references uses a PNG without responsive sources, explicit dimensions, lazy loading, or async decoding. Prefer modern formats such as WebP or AVIF and, where supported by the site tooling, document responsive images with explicit sizing and lazy loading to reduce payload and improve rendering performance.

Suggested Code:

![Analytics](/img/web-app/analytics/index.webp)

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.


| Item | Value |
|---|---|
| Routes | `/User/Records/Dashboard`, `/User/Records/Index?year=&definitionKey=&state=&q=&owner=&group=&page=`, `/User/Records/ExportList?format=csv|json`, `/User/Records/Bulk` (POST), `/User/Records/Accountability?pivot=person|group|unit&days=`, `/User/Records/FieldRollout`, `/User/RecordsHealth/Index` |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Contract-change ambiguity in docs/web-app/records/dashboard-and-queue.md and docs/web-app/notifications.md:2-2 documents API and UI route contracts without stating whether any path, query parameter, or behavior is breaking. Add a dedicated BREAKING CHANGE section whenever an existing route, query parameter, or behavior changed, including migration guidance for affected consumers.

Kody rule violation: Call out breaking changes explicitly

Prompt for LLM

File docs/web-app/records/dashboard-and-queue.md:

Line 76:

Contract-change ambiguity in `docs/web-app/records/dashboard-and-queue.md` and `docs/web-app/notifications.md:2-2` documents API and UI route contracts without stating whether any path, query parameter, or behavior is breaking. Add a dedicated `BREAKING CHANGE` section whenever an existing route, query parameter, or behavior changed, including migration guidance for affected consumers.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.


# Investigations

Fire and arson investigations, cause-and-origin work and any other case that needs **restricted, need-to-know access**. A case is visible only to its **members**, every read is written to an **access audit**, evidence items carry an append-only **chain of custody**, and findings must be **approved by someone other than their author** before they can be recommended as an amendment to the incident report.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Audit-field omission in docs/web-app/records/investigations.md and the matching references in docs/web-app/unit-tracking.md:44-44, docs/web-app/records/reports-and-exports.md:52-52, docs/setup-guides/industrial-emergency-response.md:51-51, docs/apps/unit.md:152-152, docs/web-app/security-permissions.md:76-76, docs/web-app/contacts.md:146-146, and docs/web-app/personnel.md:64-64 leaves protected-record access auditing underspecified. Define an append-only audit payload for every protected-record read and write that includes user id, patient/subject or case id, action, purpose-of-use, timestamp, and request id.

Kody rule violation: Write immutable audit logs for all ePHI access

Prompt for LLM

File docs/web-app/records/investigations.md:

Line 8:

Audit-field omission in `docs/web-app/records/investigations.md` and the matching references in `docs/web-app/unit-tracking.md:44-44`, `docs/web-app/records/reports-and-exports.md:52-52`, `docs/setup-guides/industrial-emergency-response.md:51-51`, `docs/apps/unit.md:152-152`, `docs/web-app/security-permissions.md:76-76`, `docs/web-app/contacts.md:146-146`, and `docs/web-app/personnel.md:64-64` leaves protected-record access auditing underspecified. Define an append-only audit payload for every protected-record read and write that includes user id, patient/subject or case id, action, purpose-of-use, timestamp, and request id.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

| **Referrals** | Referrals to law enforcement, insurers, prosecutors, with agency and status. |
| **Findings** | Cause classification (accidental, natural, incendiary, undetermined), cause detail, origin description, incident summary, **recommends amendment**. **Record findings** sends them for approval; a reviewer or the lead (other than the author) **approves** or **returns** them. |
| **Access audit** | Who opened the case and when. |
| **Export packet** | A packet of the case for the prosecutor or insurer. |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Export-control omission in docs/web-app/records/investigations.md and the matching references in docs/web-app/records/reports-and-exports.md:52-52, docs/web-app/security-permissions.md:76-76, and docs/setup-guides/security-and-facilities.md:57-57 leaves bulk export of protected investigative data insufficiently controlled. Document approval requirements, step-up MFA, rate limits, watermarking with requestor and timestamp, and an export_id recorded in the audit log for the export packet workflow.

Kody rule violation: Define data export controls and watermarking

Prompt for LLM

File docs/web-app/records/investigations.md:

Line 33:

Export-control omission in `docs/web-app/records/investigations.md` and the matching references in `docs/web-app/records/reports-and-exports.md:52-52`, `docs/web-app/security-permissions.md:76-76`, and `docs/setup-guides/security-and-facilities.md:57-57` leaves bulk export of protected investigative data insufficiently controlled. Document approval requirements, step-up MFA, rate limits, watermarking with requestor and timestamp, and an `export_id` recorded in the audit log for the export packet workflow.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.


# Investigations

Fire and arson investigations, cause-and-origin work and any other case that needs **restricted, need-to-know access**. A case is visible only to its **members**, every read is written to an **access audit**, evidence items carry an append-only **chain of custody**, and findings must be **approved by someone other than their author** before they can be recommended as an amendment to the incident report.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Audit-schema omission in docs/web-app/records/investigations.md and the matching references in docs/web-app/unit-tracking.md:42-42, docs/web-app/security-permissions.md:84-84, docs/web-app/records/reports-and-exports.md:52-52, and docs/web-app/personnel.md:103-103 leaves security-relevant access logging underspecified. State that tamper-evident audit logs must include timestamp, actor.user_id, actor.role, action, resource.id, result, trace_id, ip, and user_agent, and that they are stored immutably or forwarded appropriately.

Kody rule violation: Emit tamper-evident audit logs with required fields

Prompt for LLM

File docs/web-app/records/investigations.md:

Line 8:

Audit-schema omission in `docs/web-app/records/investigations.md` and the matching references in `docs/web-app/unit-tracking.md:42-42`, `docs/web-app/security-permissions.md:84-84`, `docs/web-app/records/reports-and-exports.md:52-52`, and `docs/web-app/personnel.md:103-103` leaves security-relevant access logging underspecified. State that tamper-evident audit logs must include timestamp, actor.user_id, actor.role, action, resource.id, result, trace_id, ip, and user_agent, and that they are stored immutably or forwarded appropriately.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

| **Referrals** | Referrals to law enforcement, insurers, prosecutors, with agency and status. |
| **Findings** | Cause classification (accidental, natural, incendiary, undetermined), cause detail, origin description, incident summary, **recommends amendment**. **Record findings** sends them for approval; a reviewer or the lead (other than the author) **approves** or **returns** them. |
| **Access audit** | Who opened the case and when. |
| **Export packet** | A packet of the case for the prosecutor or insurer. |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

MFA-control omission in docs/web-app/records/investigations.md and docs/web-app/security-permissions.md:76-76 treats export of sensitive case data as a privileged operation without a fresh-authentication requirement. Document that privileged exports require MFA within the last 5 minutes and that the audit log records mfa_verified_at.

Kody rule violation: Require step-up MFA for privileged operations

Prompt for LLM

File docs/web-app/records/investigations.md:

Line 33:

MFA-control omission in `docs/web-app/records/investigations.md` and `docs/web-app/security-permissions.md:76-76` treats export of sensitive case data as a privileged operation without a fresh-authentication requirement. Document that privileged exports require MFA within the last 5 minutes and that the audit log records `mfa_verified_at`.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.


| Item | Value |
|---|---|
| Routes | `/User/RecordInvestigations/{Index,Details,Open,Custody,Export}` |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Authorization-model omission in docs/web-app/records/investigations.md leaves /User/RecordInvestigations/{Index,Details,Open,Custody,Export} without explicit route-level enforcement semantics. State that every investigations route applies deny-by-default authorization by role and resource scope, including case-membership checks for Export and Custody.

Kody rule violation: Implement RBAC with least privilege and deny-by-default

Prompt for LLM

File docs/web-app/records/investigations.md:

Line 49:

Authorization-model omission in `docs/web-app/records/investigations.md` leaves `/User/RecordInvestigations/{Index,Details,Open,Custody,Export}` without explicit route-level enforcement semantics. State that every investigations route applies deny-by-default authorization by role and resource scope, including case-membership checks for `Export` and `Custody`.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

| Field | Notes |
|---|---|
| **Permit type / Occupancy** | What and where. |
| **Applicant, e-mail, phone, contact** | Who applied; can link a [Contact](../contacts). |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

PII-handling gap in docs/web-app/records/permits.md and the matching references in docs/web-app/personnel.md:8-8, docs/web-app/personnel.md:30-30, docs/self-hosted/installation.md:68-68, and docs/web-app/personnel.md:47-47 documents e-mail, phone, and applicant or contact fields without log-safety guidance. Specify that these values must be redacted or hashed if logged and avoid examples or telemetry references that imply raw PII in logs.

Kody rule violation: Mask PII and secrets in logs

Prompt for LLM

File docs/web-app/records/permits.md:

Line 27:

PII-handling gap in `docs/web-app/records/permits.md` and the matching references in `docs/web-app/personnel.md:8-8`, `docs/web-app/personnel.md:30-30`, `docs/self-hosted/installation.md:68-68`, and `docs/web-app/personnel.md:47-47` documents `e-mail`, `phone`, and applicant or contact fields without log-safety guidance. Specify that these values must be redacted or hashed if logged and avoid examples or telemetry references that imply raw PII in logs.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

Comment thread docs/web-app/reports.md

## Technical reference

`ReportsController` (+ `ChecklistReportsController`); routes `/User/Reports/{Index,PersonnelReport,StaffingReport,CertificationsReport,UpcomingShiftReadinessReport,DepartmentActivityReport,PersonnelHoursReportParams,PersonnelStaffingHistoryReportParams,UnitStateHistoryReportParams,ActionLogsParams,CallSummaryReportParams,ActiveCallsResourcesReport,FlaggedCallNotesReportParams,EventAttendanceReportParams,ChecklistComplianceReport,LogReport}`; scheduled delivery via `ProfileController.Reporting` and the worker; module switch `ReportsDisabled`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Endpoint-health evidence omission in docs/web-app/reports.md documents ReportsController, ChecklistReportsController, and routes /User/Reports/{Index,PersonnelReport,StaffingReport,CertificationsReport,UpcomingShiftReadinessReport,DepartmentActivityReport,PersonnelHoursReportParams,PersonnelStaffingHistoryReportParams,UnitStateHistoryReportParams,ActionLogsParams,CallSummaryReportParams,ActiveCallsResourcesReport,FlaggedCallNotesReportParams,EventAttendanceReportParams,ChecklistComplianceReport,LogReport} without production health data. Include the endpoint path or controller name together with current production evidence such as p95 latency and error rate, and, if degraded, document a safe rollout or performance mitigation before adding heavier logic.

Kody rule violation: Warn when modifying unstable or high-latency endpoints

Prompt for LLM

File docs/web-app/reports.md:

Line 171:

Endpoint-health evidence omission in `docs/web-app/reports.md` documents `ReportsController`, `ChecklistReportsController`, and routes `/User/Reports/{Index,PersonnelReport,StaffingReport,CertificationsReport,UpcomingShiftReadinessReport,DepartmentActivityReport,PersonnelHoursReportParams,PersonnelStaffingHistoryReportParams,UnitStateHistoryReportParams,ActionLogsParams,CallSummaryReportParams,ActiveCallsResourcesReport,FlaggedCallNotesReportParams,EventAttendanceReportParams,ChecklistComplianceReport,LogReport}` without production health data. Include the endpoint path or controller name together with current production evidence such as p95 latency and error rate, and, if degraded, document a safe rollout or performance mitigation before adding heavier logic.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

|---|---|
| **Require MFA for all members** | Members without MFA are prompted to enrol at next login. |
| **Require SSO — disable password login** | Needs an active SSO configuration and at least one admin who has tested SSO login. |
| **Session timeout (minutes)** | 0 = system default; 480 = 8 h. |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Session-policy weakness in docs/web-app/security-permissions.md permits an 8-hour setting without distinguishing idle versus absolute timeout or defining cookie protections. Require idle timeout ≤ 15 minutes, absolute timeout ≤ 12 hours, and Secure, HttpOnly, and SameSite=Lax or Strict session cookies.

Kody rule violation: Harden session management with idle and absolute timeouts

| **Session timeout (minutes)** | Idle timeout should be ≤ 15 minutes; absolute timeout should be ≤ 12 hours. Cookies must be Secure, HttpOnly, and SameSite=Lax or Strict. |
Prompt for LLM

File docs/web-app/security-permissions.md:

Line 98:

Session-policy weakness in `docs/web-app/security-permissions.md` permits an 8-hour setting without distinguishing idle versus absolute timeout or defining cookie protections. Require idle timeout ≤ 15 minutes, absolute timeout ≤ 12 hours, and Secure, HttpOnly, and SameSite=Lax or Strict session cookies.

Suggested Code:

| **Session timeout (minutes)** | Idle timeout should be ≤ 15 minutes; absolute timeout should be ≤ 12 hours. Cookies must be Secure, HttpOnly, and SameSite=Lax or Strict. |

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

@@ -0,0 +1,63 @@
---

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Security-and-privacy documentation gap in docs/web-app/unit-tracking.md and the matching references in docs/web-app/records/legal-holds-and-disclosures.md:8-8, docs/web-app/data-protection.md:1-79, and docs/web-app/records/community-risk-reduction.md:40-45 leaves credentials, device identifiers, source networks, retention, monitoring, and location-data processing without a dedicated control model. Add a Security & Privacy section covering credential storage and rotation, IP allowlisting, retention boundaries, audit logging, and how location data is protected and minimized.

Kody rule violation: Capture security and privacy implications

Prompt for LLM

File docs/web-app/unit-tracking.md:

Line 1:

Security-and-privacy documentation gap in `docs/web-app/unit-tracking.md` and the matching references in `docs/web-app/records/legal-holds-and-disclosures.md:8-8`, `docs/web-app/data-protection.md:1-79`, and `docs/web-app/records/community-risk-reduction.md:40-45` leaves credentials, device identifiers, source networks, retention, monitoring, and location-data processing without a dedicated control model. Add a `Security & Privacy` section covering credential storage and rotation, IP allowlisting, retention boundaries, audit logging, and how location data is protected and minimized.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

Comment thread src/css/custom.css
border-bottom: 1px solid var(--ifm-toc-border-color);
}

.navbar__title {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Global-style scope creep in src/css/custom.css and the matching references in src/css/custom.css:140-140, src/css/custom.css:167-167, src/css/custom.css:161-161, src/css/custom.css:208-208, src/css/custom.css:152-152, src/css/custom.css:182-182, src/css/custom.css:147-147, src/css/custom.css:203-203, src/css/custom.css:148-148, src/css/custom.css:156-156, src/css/custom.css:226-226, src/css/custom.css:214-214, src/css/custom.css:235-235, src/css/custom.css:192-192, src/css/custom.css:178-178, src/css/custom.css:191-191, src/css/custom.css:198-198, and src/css/custom.css:197-197 adds styling through a global stylesheet rather than a scoped mechanism. Prefer CSS modules, scoped styles, or component-local styling unless this selector is intentionally top-level app or layout styling.

Kody rule violation: Use component-scoped styling

Prompt for LLM

File src/css/custom.css:

Line 135:

Global-style scope creep in `src/css/custom.css` and the matching references in `src/css/custom.css:140-140`, `src/css/custom.css:167-167`, `src/css/custom.css:161-161`, `src/css/custom.css:208-208`, `src/css/custom.css:152-152`, `src/css/custom.css:182-182`, `src/css/custom.css:147-147`, `src/css/custom.css:203-203`, `src/css/custom.css:148-148`, `src/css/custom.css:156-156`, `src/css/custom.css:226-226`, `src/css/custom.css:214-214`, `src/css/custom.css:235-235`, `src/css/custom.css:192-192`, `src/css/custom.css:178-178`, `src/css/custom.css:191-191`, `src/css/custom.css:198-198`, and `src/css/custom.css:197-197` adds styling through a global stylesheet rather than a scoped mechanism. Prefer CSS modules, scoped styles, or component-local styling unless this selector is intentionally top-level app or layout styling.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants