Rate limiting
Platform-operator governance for abuse-protection rate limits: declared policies, bounded overrides, provenance-aware enforcement, reset and erasure.
i18n:5
Admin Dashboardsv0.1.0
Configurable admin dashboard with module-provided widgets.
API:10i18n:5
Authentication & Accountsv0.1.0
User accounts, sessions, roles and password resets.
FE:3BE:14API:45i18n:5
Directory (Tenants & Organizations)v0.1.0
Multi-tenant directory with tenants and organizations.
BE:7API:32i18n:5
Activitiesv0.1.0
Polymorphic activities, notes and comments foundation for all modules.
BE:10API:24i18n:5
Notesv0.1.0
Polymorphic notes — attach free-form notes to any entity.
API:5i18n:5
Commentsv0.1.0
Polymorphic hierarchical comments — attach threaded discussions to any entity.
API:5i18n:5
Pipelinesv0.1.0
Universal stage pipelines for any entity — polymorphic subject, stage history with time-in-stage, per-owner bindings.
BE:2API:12i18n:5
Customer Relationship Managementv0.1.0
Core CRM capabilities for people, companies, deals, and activities.
BE:14API:101i18n:5
Counterparties
Counterparties (clients, suppliers, partners) — extends customers with party roles and country-aware requisites.
API:15i18n:5
DaData Enrichment
Enrich Russian counterparties from the EGRUL/EGRIP + bank registry by ИНН/ОГРН/БИК, with ФИО and address autocomplete. Credential-only provider consumed by the counterparties module.
API:5i18n:5
Контур.Диадок (ЭДО)
Legally-significant electronic document exchange (ЭДО) with counterparties via the Kontur.Diadoc operator: invite counterparties, sign documents, send and receive signed documents into the database.
BE:2API:7i18n:5
Inventory
Warehouse topology, item inventory profiles, lot/serial tracking, balances, reservations and an append-only movement ledger. Phase 1 (Core Inventory) — no receiving/putaway/picking yet.
BE:38API:83i18n:5
Table perspectivesv0.1.0
Shared persistence for DataTable perspectives (columns, filters, saved views).
API:4
Custom Entities & Fieldsv0.1.0
User-defined entities, custom fields, and dynamic records storage.
BE:9API:23i18n:5
Configurationv0.1.0
Shared configuration storage and helpers for module settings.
BE:3API:9i18n:5
Egress proxyv0.1.0
System-wide forward proxy for outbound AI/Telegram traffic from restricted regions.
BE:1API:5i18n:5
Cache settingsv0.1.0
Admin-configurable app-cache Redis connection: live switch without restart, connection test, epoch-based cache reset.
BE:1API:4i18n:5
Template Variablesv0.1.0
Thin API host for the shared variables engine (CP-189): the picker tree and the resolve/preview endpoint over {{entity.field}} tokens. Owns no tables; modules declare sources via variables.ts + a DI resolver service.
API:2i18n:5
Message Templatesv0.1.0
Flat text templates (email / SMS / chat / notification / push) authored with {{entity.field}} tokens and rendered through the variables engine (CP-190). Stores and resolves templates; delivery stays with channel owners.
BE:3API:5i18n:5
Document Constructorv0.1.0
Document constructor (CP-191): Aspro-style 3-tier model (document type → template → document) over the shared ProseMirror editor, {{entity.field}} variables through the variables engine, DOCX/PDF render into attachments.
BE:11API:20i18n:5
Document Repositoryv0.1.0
Document repository (CP-192): the company-wide document repository — spaces, nested folders, documents, append-only versions, capped-inheritance permissions, record links (pin/follow), labels, retention classification and a dedicated view/download access ledger — built strictly as a management layer over the shared attachments blob storage.
BE:3API:37i18n:5
Query Indexesv0.1.0
Hybrid query layer with full-text and vector search capabilities.
BE:1API:3i18n:5
Audit & Action Logsv0.1.0
Tracks user actions and data accesses with undo support scaffolding.
BE:1API:5i18n:5
Security Audit
Continuous production security checks — RBAC-grant drift detection, tenant-isolation spot-checks, and synthetic-tenant probing. See .ai/specs/CP-201-2026-07-11-security-audit-coverage.md.
i18n:5
Attachmentsv0.1.0
File attachments and media management.
BE:2API:17i18n:5
Product Catalogv0.1.0
Configurable catalog for products, variants, and pricing used by the sales module.
BE:9API:36i18n:5
Sales Managementv0.1.0
Quoting, ordering, fulfillment, and billing capabilities built on modular pricing and tax pipelines.
FE:1BE:15API:110i18n:5
API Keysv0.1.0
Manage access tokens for external API access.
BE:2API:3i18n:5
Shared Dictionariesv0.1.0
Organization-scoped dictionaries for reusable enumerations and appearance presets.
BE:1API:11i18n:5
Content
Static informational pages such as terms of service and privacy policy.
FE:2
Onboardingv0.1.0
Self-service tenant and organization onboarding flow.
FE:2API:4i18n:5
API Documentation
Auto-generated documentation for all HTTP endpoints.
FE:1BE:1API:1i18n:5
Module Documentation
In-admin, read-only documentation aggregated from each enabled module (CP-180).
BE:2API:2i18n:5
Interface hints
Declarative in-context interface guidance: per-module hint banners with a per-user visibility toggle (CP-231).
i18n:5
Business Rulesv0.1.0
Business Rules Engine for defining, managing, and executing business logic and automation rules.
BE:8API:17i18n:5
Feature Togglesv0.1.0
Global feature flags with tenant-level overrides.
BE:5API:12i18n:5
Workflow Enginev1.0.0
Orchestrate business processes with state machines, transitions, and activities
FE:1BE:10API:23i18n:5
Searchv0.1.0
Unified search module with pluggable strategies (Meilisearch, Vector, Tokens).
BE:1API:15i18n:5
Currenciesv0.1.0
Currencies and Exchange rate management
BE:7API:15i18n:5
Worktime / Availabilitiesv0.1.0
Availability schedules, rulesets, and shared planning rules.
BE:3API:10i18n:5
Resource planningv0.1.0
Assets and resources with scheduling policies.
BE:6API:22i18n:5
Employeesv0.1.0
Teams, roles, and employee rosters.
BE:27API:60i18n:5
Calendar & Bookingv0.1.0
Bookable services, appointments, and the shared booking calendar (CP-237).
BE:4API:14i18n:5
Working groupsv0.1.0
Working groups (Команды) — foundation grouping with role-on-membership.
BE:7API:19i18n:5
Record Sharingv0.1.0
CP-093 Layer 3 — point-in-record access grants (user/department/team), reusable across any record type.
BE:1API:6i18n:5
Saved Viewsv0.1.0
CP-318 — one library of named saved views shared by every surface (tables, sidebar, boards, cards, pipeline templates).
BE:1API:14i18n:5
Events
Event bus and subscriber dispatch
API:2
Notificationsv0.1.0
In-app notifications with module-extensible types and actions.
BE:2API:14i18n:5
Progressv0.1.0
Generic server-side progress tracking for long-running operations
API:6i18n:5
Integrations
Core integration framework — external ID mapping, status badges, and integration registry.
BE:3API:10i18n:5
Data Sync
Streaming data sync hub for import/export integrations.
BE:2API:17i18n:5
Excel / CSV Import
File-upload-based CSV import foundation built on top of the data sync hub.
API:3i18n:5
Messagesv0.1.0
Internal messaging system with attachments, actions, and email forwarding.
FE:1BE:3API:26i18n:5
Communication Channels
Unified hub bridging external chat/email channels (Slack, WhatsApp, Email) to the Messages module. Adapter contract, channel-native payload storage, reactions, and per-channel threading.
BE:3API:42i18n:5
AI Assistantv0.1.0
MCP server for AI assistant integration with multi-tenant support.
BE:7API:38i18n:5
Entity Translationsv0.1.0
System-wide entity translation storage and locale overlay for CRUD responses.
BE:1API:5i18n:5
Schedulerv0.1.0
Database-managed scheduled jobs with admin UI
BE:4API:8i18n:5
InboxOps — Email-to-ERP Agentv0.1.0
Receives forwarded emails via webhook, extracts structured action proposals using LLM, and presents them for human-in-the-loop approval.
BE:4API:20i18n:5
Payment Gateways
Payment gateway adapter contract, registry, transaction tracking, and webhook routing.
BE:1API:10i18n:5
Checkoutv0.1.0
Pay links, checkout templates, public payment pages, and checkout transaction tracking.
FE:3BE:10API:18i18n:5
Stripe Payment Gateway
Accept card payments, Apple Pay, Google Pay, and bank transfers via Stripe.
i18n:5
IMAP + SMTP Email Channel
Connect personal mailboxes via IMAP for inbound polling and SMTP for outbound delivery. Pairs with the Communications Hub (SPEC-045d).
Gmail Email Channel
Connect per-user Gmail accounts via OAuth2. Outbound via gmail.users.messages.send; inbound via History API polling. Pairs with the Communications Hub.
Yandex Mail Email Channel
Connect per-user Yandex Mail accounts via OAuth2. Auth uses Yandex OAuth; transport is IMAP/SMTP authenticated with XOAUTH2 using the OAuth access token. Inbound via UID-based IMAP polling; pairs with the Communications Hub.
i18n:5
Mail.ru Email Channel
Connect per-user Mail.ru mailboxes (@mail.ru, @bk.ru, @inbox.ru, @list.ru) via OAuth2. Transport is IMAP/SMTP authenticated with XOAUTH2 using the OAuth access token. Inbound via UID-based IMAP polling; pairs with the Communications Hub.
i18n:5
Yandex 360 Directory
Provision and manage employee mailboxes on the company domain via the Yandex 360 Directory API. Pairs with the Yandex email channel for auto-connect.
Akeneo Product Sync
Import Akeneo PIM categories, product attributes, and products into the Open Mercato catalog.
API:6i18n:5
Shipping Carriers
Shipping carrier adapter hub with rates, shipment creation, tracking, and webhooks.
BE:1API:7i18n:5
Webhooksv0.1.0
Standard Webhooks compliant outbound webhook delivery for platform events.
BE:3API:24i18n:5
Model Explorerv0.1.0
Interactive entity-model explorer (cards + relations + filters)
BE:1i18n:5
Chatv0.1.0
Unified chat shell for internal team messaging and external client conversations.
BE:2API:37i18n:5
Customer Identity & Portal Authenticationv0.1.0
Customer-facing authentication with two-tier identity model and full RBAC.
BE:7API:50i18n:5
Customer Portalv0.1.0
Self-service customer portal framework with login, signup, dashboard, sidebar navigation, and extensible widget system.
FE:7i18n:5
Callsv0.1.0
Voice and video calls via LiveKit SFU with call journal and participant tracking.
BE:6API:31i18n:6
S3-Compatible Storage
Store attachments and files in AWS S3, DigitalOcean Spaces, MinIO, or any S3-compatible object storage.
API:5