ITSM Financial Command Center

Release Notes

Version 1.0

Released 16 August 2026

Contents

  1. 1. About This Release
  2. 2. Features in This Release
    1. 2.1 Connect your ticketing platforms
    2. 2.2 Executive Command Center
    3. 2.3 Strategic Executive Dashboard
    4. 2.4 Contract and cost configuration
    5. 2.5 Reporting and presentation
    6. 2.6 Accounts, billing and privacy
  3. 3. Establishing Your Financial Baselines
    1. 3.1 Platform connection
    2. 3.2 SLA parameters
    3. 3.3 Financial impact settings
    4. 3.4 Business capabilities
    5. 3.5 Branding, for Enterprise accounts
    6. 3.6 Account details
  4. 4. Technology and Versions
    1. 4.1 Platform and runtime
    2. 4.2 Data, billing and infrastructure
    3. 4.3 Interface and reporting
    4. 4.4 Build and test tooling
    5. 4.5 Version posture
    6. 4.6 Known dependency advisories
  5. 5. Testing and Verification
    1. 5.1 What is covered
    2. 5.2 How we test
    3. 5.3 Platform verification
  6. 6. Security and Data Handling
  7. 7. Getting Help

1. About This Release

Version 1.0 is the first formal release of the ITSM Financial Command Center. It marks the point at which every headline figure on the platform is either counted directly from your own ticketing system or calculated from a rate that you have supplied yourself.

That principle shapes the whole product: we measure, you value. The platform counts what your ITSM tools record, such as tickets resolved, reassignments, response times and queue age. It then multiplies those counts by rates that only you can know, such as your engineer hourly cost and your contractual SLA penalties. No industry benchmark, no default salary and no assumed penalty is ever substituted for a figure you have not given us. Where a rate is missing, the metric that depends on it stays blank rather than showing a number you cannot defend.

Why this matters in a board meeting. Every currency figure on your dashboard can be traced back to two things: a count we can show you, and a rate you chose. If a director challenges a number, the answer is always available and it is always yours.

2. Features in This Release

2.1 Connect your ticketing platforms

2.2 Executive Command Center

The operational picture: what is at risk today, and what it would cost.

MeasureWhat it tells you
SLA Health ScoreThe share of in-scope tickets currently within their agreed thresholds.
Total SLA BreachesTickets already past threshold, counted only on platforms you have placed under contract.
Estimated SLA LiabilityThose breaches priced with the penalty structure you enter. Never a default.
At Risk of SLA BreachTickets approaching a threshold while there is still time to act.
Active Critical IncidentsCritical and High priority work currently open.
Average Ticket Age and Stale TicketsHow long the queue has been waiting, and how much of it has gone untouched.
Total Active TicketsThe whole open queue, including work outside any SLA, so you staff what actually exists.
Critical and High attention tableThe oldest tickets needing a decision today.
Drill-down breakdownsEvery financial and SLA card opens into its own workings, using exactly the same rules as the headline, so a figure and its explanation can never disagree.

2.3 Strategic Executive Dashboard

The financial picture: where the money and the effort are actually going.

MeasureWhat it tells you
Support Capacity per Ticket Your paid support capacity over 90 days divided by the tickets your team resolved in that period, in both hours and currency. A built-in explanation written for directors sets out what the figure does and does not claim, and names the three things that most often explain a large number: unlogged demand and informal channels, misaligned resource allocation, and queue idle time.
Cost of Re-Triage Reassignments counted from your ticket history, priced at the minutes you say each handover costs and your hourly rate.
Revenue at Risk Calculated across the business capabilities you define and value.
MTTR Measured in working hours rather than wall-clock hours, so a ticket raised on Friday evening is not penalised for the weekend.
First Contact Resolution and Resolution Rate Each shown with the counts behind them, so the percentage can be checked.
Ticket Friction The average number of times a ticket changes hands before it is solved.
Average CSAT Where your platform supplies satisfaction responses.
Performance Trends Eight complete calendar weeks of throughput.
Resource Planning Forecaster Projects next week's incoming volume against your team size.

2.4 Contract and cost configuration

2.5 Reporting and presentation

2.6 Accounts, billing and privacy

3. Establishing Your Financial Baselines

The platform counts what your tools record. What it cannot know is what any of it is worth to you, because that comes from your contracts and your payroll rather than from a ticket. These are the figures that turn a queue into a number a board will act on, and each one is yours: entered by you, changeable at any time, and defensible because you chose it.

Until a value is provided, the metrics that depend on it stay blank rather than defaulting to an assumption.

3.1 Platform connection

PlatformWhat we needNotes
Zendesk Your Zendesk subdomain, then authorise via OAuth You approve the connection inside Zendesk. We never ask for your Zendesk password.
Jira Site domain, account email, API token Optionally a project key or a JQL filter, if you want to limit the connection to specific projects.
ServiceNow Instance name, username, and a password or API token Reads the incident table. The account needs read access to incidents and nothing else.
Custom REST API Endpoint URL, method, any authentication headers, and a field mapping Connect a proprietary or in-house system through any JSON endpoint. Reference detail below. Only public endpoints are reachable; requests to internal addresses are refused.
Least privilege. Create the API token against an account that has read access to the projects or incidents you want reported on, and no more. The platform only reads; it never writes back to your ticketing system.

Custom REST API field mapping

Reference detail. Skip this unless you are connecting an in-house system.

If your ticketing system can return JSON, it can be connected. You point the platform at the endpoint and say which of your fields means what. The connection screen comes pre-filled with a worked example, so in practice this is editing field names rather than writing a configuration from scratch, and it is usually a job of minutes for whoever maintains the system.

MappingRequiredWhat it drives
id, title, status, priorityYesEverything. Status and priority also need a value mapping, so the platform knows that your "Urgent" means Critical.
createdAtYesTicket age, the queue figures and SLA liability.
updatedAtRecommendedThe stale ticket count. Without it, a ticket is treated as last touched when it was raised, which is the conservative reading rather than a guess.
resolvedAtRecommendedMTTR, resolution rate, first contact resolution and support capacity per ticket. These stay blank without it, because a resolution with no timestamp has no duration.
category, businessService, slaBreachedOptionalCategory analysis, revenue at risk and breach detection respectively.
Dates. ISO 8601 strings are read exactly. Unix timestamps are accepted in either seconds or milliseconds. A value that cannot be read as a date is treated as absent rather than being guessed at, so a metric will go blank rather than quietly report a wrong duration.

3.2 SLA parameters

Taken from your service contract. Entered separately for Critical and for High priority tickets, because they almost always carry different terms.

SettingWhat it means
Base penaltyThe amount payable the moment a ticket of that priority breaches.
Daily penaltyThe additional amount accrued for each further day in breach.
Maximum capThe ceiling on any single ticket, so one forgotten ticket cannot dominate the total.
Platforms under SLAWhich connected platforms carry contractual SLAs at all. Leave every platform selected unless some of your connected work sits outside any contract.

3.3 Financial impact settings

SettingWhat it means
Reporting currencyGBP, USD or EUR. Every figure in your account is expressed in it.
Engineer hourly costThe fully loaded cost of an hour of engineer time, including employer contributions and overheads, not the salary rate alone.
Minutes lost per handoverYour estimate of the time lost each time a ticket changes hands: re-reading history, re-establishing context, contacting the previous assignee. No ITSM tool records this, so the figure is yours and it is yours to defend.
Team sizeThe number of people funded to work on support. Drives both the resource forecaster and support capacity per ticket.

3.4 Business capabilities

A list of the services your team supports, each with the value you attach to it. This is what turns a degraded service into a revenue-at-risk figure. Capabilities are yours to name; the platform does not presume to know your business.

3.5 Branding, for Enterprise accounts

Your logo file and an accent colour. Applied to dashboards and to exported decks.

Logo tip. The dashboard header and the exported deck both use a dark background. A transparent logo with dark artwork will be difficult to read against it. Supply a version with light artwork, or one with its own background.

3.6 Account details

Name, company name, work email address and an explicit GDPR consent at registration. A contact telephone number is optional.

4. Technology and Versions

Published so that you, or your security team, can confirm the platform is not running on unsupported software. Versions are those shipped in v1.0, checked against the latest published release on 16 August 2026.

4.1 Platform and runtime

ComponentIn v1.0LatestStatus
Next.js16.3.116.3.1Current
React19.2.819.2.8Current
React DOM19.2.819.2.8Current
Node.js22 LTS22 LTSCurrent LTS
TypeScript5.9.37.0.2Major behind

4.2 Data, billing and infrastructure

ComponentIn v1.0LatestStatus
Supabase (PostgreSQL, auth)2.112.32.112.3Current
Stripe (server)22.5.022.5.0Current
Stripe.js (browser)9.13.09.13.0Current
Upstash Redis (rate limiting)1.38.21.38.2Current
Resend (transactional email)6.20.06.20.0Current
undici (HTTP client)8.10.08.10.0Current
Zod (input validation)4.4.34.4.3Current
ipaddr.js (SSRF guards)2.5.02.5.0Current

4.3 Interface and reporting

ComponentIn v1.0LatestStatus
Recharts (charts)3.10.13.10.1Current
Lucide React (icons)1.31.01.31.0Current
date-fns4.4.04.4.0Current
PptxGenJS (PowerPoint export)4.0.14.0.1Current
dnd kit (drag and drop)6.3.16.3.1Current

4.4 Build and test tooling

ComponentIn v1.0LatestStatus
Vitest (unit tests)4.1.104.1.10Current
Playwright (end to end tests)1.62.11.62.1Current
ESLint9.39.510.8.1Major behind
Testing Library (React)16.3.216.3.2Current

4.5 Version posture

Nothing in the stack is unsupported or end of life. Every runtime component sits on a maintained major version, and Node.js is on the current Long Term Support line.

Nineteen of the twenty-one components listed above are on the latest published release. Two are not, and in both cases the constraint is the wider ecosystem rather than a decision of ours:

Neither tool is shipped to your browser, neither runs in production, and neither can affect a figure on your dashboard. Both are checked on each release, and both will be adopted when their ecosystems support them. Everything that does run in production, including the application framework itself, is on the latest published release as of this version.

4.6 Known dependency advisories

Two high severity advisories are reported against image-size, a package reached indirectly through the PowerPoint export library. They are assessed and accepted, not fixed, and we would rather say so plainly than let an audit report surprise you later.

Advisory references: GHSA-w3rx-r6r6-pgpr and GHSA-5p2g-fcmc-qvqq.

5. Testing and Verification

This release ships with over 100 test files and more than 1,500 automated checks, all passing, plus an end to end suite covering security and data export. The full suite runs before every release.

5.1 What is covered

Every test file counts towards exactly one area below, so the figures add up to the total rather than overlapping. Counts are stated as a floor and will only grow.

AreaChecksWhat the tests verify
Billing and entitlement over 370 Subscription lifecycle, upgrade proration, cancellation, plan restrictions enforced on the server, and recovery from a payment event arriving out of order or twice.
Interface and connection state over 350 What each screen shows while data is still loading, when a connection is broken, and when one platform fails while others succeed. A figure is never asserted before it is known.
Financial calculation over 290 SLA liability and penalty caps, cost of re-triage, support capacity per ticket, revenue at risk, MTTR in working hours, resolution rate and first contact resolution. Each figure is checked against its own drill-down, so a headline and its explanation cannot disagree.
Security over 230 Credential encryption, protection against server-side request forgery, rate limiting, PII stripping, administrative authorisation, and an automated scan of the shipped browser bundle for credentials of any known shape.
Platform adapters over 150 The reporting window each connection asks for, pagination limits, resolution timestamps, and the merge when one ticket appears in more than one query. Includes the case of a platform returning nothing, and of a platform failing while others succeed.
Shipped documents over 80 Specific claims in this document and in the user manual are asserted against the code they describe, including every version number in section 4. A document cannot silently go out of date.

Data integrity is not a separate row because it is not a separate area: that missing data stays blank rather than becoming zero, and that an impossible timestamp is excluded rather than counted as a negative duration, are asserted inside the financial and adapter suites where those values are produced.

5.2 How we test, and why it is worth knowing

5.3 Platform verification

Zendesk and Jira are verified against live production instances as well as by automated tests. ServiceNow and the Custom REST API are verified against their documented API contracts, with connection validation performed against your own instance at setup, which reports any authentication or permission problem immediately rather than failing quietly.

What happens if a platform cannot be reached. The connection is shown in red with the reason, that platform is named as not syncing, and it is excluded from the connected list rather than counted among the working ones. Your other platforms keep reporting normally. A partial failure is always visible as a partial failure.

6. Security and Data Handling

7. Getting Help

The User Manual covers day to day use, including how each metric is calculated and what to check when a figure looks wrong. For anything not answered there, use the Contact Us link in the portal.

ITSM Financial Command Center, version 1.0, 16 August 2026.