Changelog & Roadmap
Was wir gebaut haben — und was als Nächstes kommt. Quelle: `plans/`-Verzeichnis im TourOS-Repo.
Foundation
- Plan 08live
Multi-Tenant-Foundation
144 Tabellen tenant-scoped mit Postgres-RLS, NextAuth-Session-Erweiterung um TenantMember-Membership, RBAC-Matrix für 6 Rollen, separate touros_app-Rolle (NOSUPERUSER + NOBYPASSRLS).
- Plan 10live
Super-Admin-App
`super.touros.pro` mit Tenant-Liste + Detail + Anlage-Wizard + Branding-Editor + Custom-Domain-Form + Members-Management + Audit-Log + Plattform-Health.
- Plan 11live
Branding & Domains
Pro-Tenant-Branding (Akzent-Farben, Schrift, Logo-Slots) mit Zod-strict-Validation, BRANDING_PRESETS, dompurify-SVG-Sanitizer, BrandingLoader als Server-Component.
Domain-Module
- Plan 12live
Lokales Tour-CMS
22 neue Tour-Models mit Translations + Variants + FAQs + Categories + Pages + SEO + Media. Ersetzt WordPress-Lock-In; WordPress-Adapter bleibt als optionaler Migrations-Pfad.
- Plan 13live
Booking-Engine + Mollie
BookingService mit Slot-Lock via Redis-TTL, Mollie-Pro-Tenant mit AES-256-GCM-Token-Encryption, RFC-5545-RRULE-Verfügbarkeitsregeln, atomarer pro-Tenant-BookingNumber, ICS-Mail-Anhang.
- Plan 14live
Workforce-Operations
Shift-Schablonen (RRULE) + ShiftSlot-Instanzen, TourAssignment N:M, Match-Score-Engine, GuideAvailability-Override, Auto-Timesheet bei Tour-Completion, pro-Tenant-VAPID für Web-Push.
- Plan 15live
Finance & Invoicing
pdfmake-Rechnungen, lokale VAT-Engine (DE/EU/Drittland + B2B-Reverse-Charge), Storno + Gutschrift als separate Audit-Models (DE-§14-UStG), DATEV-CSV, signed-URL-PDF-Download.
- Plan 16live
Customer-Portal
Path-Routing `<tenant>.touros.pro/account/*` mit Magic-Link (sha256-Token-Hash + DB-Session), DSGVO-Cookie-Banner, Mollie-Re-Payment via persisted checkoutUrl.
- Plan 17live
Guide-PWA
Path `/guide/*` mit dynamischem PWA-Manifest pro Tenant, IndexedDB-Offline-Sync (DB-Name `tos-pwa-${tenantId}`), Web-Push-Subscribe gegen pro-Tenant-VAPID, Tourreports + Absences.
- Plan 18live
Public-Storefront + AEO
Direct-Prisma-Server-Components, AEO-Suite (`/availability` Markdown + `/llms.txt` + `/api/availability.{json,rss}`), Tour-Detail mit Verfügbarkeits-Kalender + Booking-Form, Custom-Domain-Resolver mit 5min-Cache.
- Plan 19live
Tenant-Admin-App
12 Tabs (Dashboard, Touren, Bookings, Customers, Workforce, Agents, Conversations, Knowledge-Base, Finance, Branding, Settings, Audit) + RBAC-Filter, AuditLogService mit Hook-Integration in Mutation-Services.
Migrations + Identity
- Plan 20live
Recras-Import-Wizard
6-Step-Wizard im Super-Admin (Connect → Discovery → Mapping → DryRun → Run → Report) mit SSE-Live-Progress, externalImportRef-Re-Run-Dedup, 91/91 Cross-Tenant-Tests grün.
- Plan 25live
FareHarbor-Adapter (Discovery + Skelett)
Adapter-Workspace mit zwei Quellen: stillgelegter mjptours-Account (CSV-Exports) + walkingcologne-Wix-Embed-Item-IDs. End-to-End-Wizard im Super-Admin + NestJS-Bridge mit Dryrun-Endpoint.
- Plan 26live
Tenant-Identity-Import
Anthropic-Bundle-Import (URL `https://api.anthropic.com/v1/design/h/<id>`), Brandfetch-API, Claude-Sonnet-Agent mit web_fetch_20260209-Tool. Kuratierte Brand-Profile-Library, Logo-Slots, Token-Vokabel-Audit.
- Plan 24live
Design-System
`@touros/design-tokens` (Navy-Halo + Teal-Kompass + Plus Jakarta Sans + Inter Tight + JetBrains Mono) und `@touros/ui` (11 React-Komponenten mit Storybook). 5 von 6 Apps migriert.
Plattform-Reife
- Plan 27live
Containerization + GHCR
11 Container (touros-postgres, touros-redis + 9 App-Container) auf disjunkten Ports/Volumes/Network zu KC-Bookingportal. GHCR-CI/CD, helper deploy/touros-ops.sh Compose-aware.
- Plan 28live
Plattform-RBAC + Tenant-Support-Access
6 Plattform-Rollen (platform_owner/admin, support_lead/agent, finance_admin, readonly_auditor). Plattform-Personal hat KEINEN automatischen Tenant-Zugriff — Support-Sessions laufen über runWithTenantAsSupport mit scoped, zeitlich begrenzten Tenant-genehmigten Grants.
- Plan 29live
Setup-Sandbox + Go-Live-Lifecycle
Lifecycle setup_draft → ready_for_go_live → go_live_pending → live. MockPaymentProvider entkoppelt Mollie-Plattform-Account, MailService-Wrapper mit [SETUP]-Prefix + Whitelist + Owner-BCC, Storefront-Lifecycle-Gate, atomare 9-Schritte-Go-Live-Execution mit Soft-Rollback. 13/14 Milestones live (M5 + M12 deferred).
- Plan 31live
Inbound-Mail-Pipeline
Postmark-Inbound-Stream als Single-Source. Plattform-Inbound (`support@mail.touros.pro`) → PlatformInboundMessage + Auto-Ticket im Super-Admin. Tenant-Inbound via Plus-Addressing (`<tenantUuid>+<conv>@mail.touros.pro`) → tenant-scoped EmailMessage mit RLS, Threading, Reply-Form.
Geplant
- Plan 21in Arbeit
Tenant-Self-Service-Onboarding
Sign-up-Funnel auf `touros.pro/signup`, Mollie-Subscription für Plattform-Charge (statt Stripe), 14-Tage-Trial OHNE CC-Vorabeingabe, Onboarding-Checkliste im Admin. M1+M2+M4+M4b live, M3 wartet auf User-Aktion „Plattform-Mollie-Account".
- Plan 22in Arbeit
KC-Pilot-Migration
Big-Bang-Cutover im 4–6h-Wartungsfenster. Plan komplett geschrieben, alle Voraussetzungen aus Plan 20+21+29 erfüllt. Verbleibende Blocker sind User-Aktionen (Recras-Vertragskündigung, DNS-TTL, Mollie-Webhook-URL-Wechsel).
- Plan 23geplant
Production-Readiness
Doppler statt Vault, Grafana-Cloud-Free-Tier, Self-Hosted Statping, Hard-Quota, DSGVO-Compliance (Right-to-Erasure als Anonymisierung statt Hard-Delete), Disaster-Recovery, Load-Tests, Security-Hardening, Pen-Test, Production-Go-Live-Checkliste.
Diese Seite ist ein kuratierter Mirror der internen Sub-Pläne. Roadmap-Verschiebungen sind möglich, wenn User-Aktionen (z. B. Mollie-Plattform-Account, Wartungsfenster) andere Sequenzen nahelegen.