User Guide

Document management

File cabinets attached to clients, vendors, purchase orders, and expenses. Distinct from HR compliance doc tracking.

Beyond HR compliance documents (W-4 / I-9 / W-9 — covered under HR & compliance), TimeTrack Pro provides general file cabinets attached to every important entity. Keep the signed MSA next to the client, the COI next to the vendor, the PDF PO next to the purchase order, the receipts next to the expense.

4 file cabinets

🏢

Client attachments

Documents tab on each /clients/[id]. Generic client-scoped file storage — signed MSAs, brand guides, W-9s, SOWs. 25 MB cap, broad MIME allowlist. Scope: management + vendor_admin within vendor_clients.
🤝

Vendor attachments

Documents tab on each /vendors/[id]. Vendor- company-level — W-9, COI, business license, signed MSA. Optional documentType tag at upload links the file to a compliance requirement.
📋

PO documents

One document per inbound PO — typically the client-issued PDF PO file itself. Surfaces as a 📎 paperclip icon next to the PO number on every list. Replaces overwrite.
🧾

Expense receipts

Multi-file per expense. 10 MB cap per file (smaller because phone-camera JPGs land here).
Sensitive-read audit on every download
Every document download writes an audit row (action: send, entityType: tenant, metadata.type: document_downloaded or po_document_downloaded) capturing who downloaded, target entity, type + filename, timestamp + request id, and a redacted IP prefix. Sensitive HR records, signed contracts, vendor tax IDs — every access leaves a trail.

Storage

Files persist under data/ in your install directory:

  • data/client-attachments/<tenantId>/<clientId>/
  • data/vendor-attachments/<tenantId>/<vendorId>/
  • data/purchase-order-documents/<tenantId>/<poId>.<ext>
  • data/expense-attachments/<tenantId>/<expenseId>/

Backup is one rsync of data/ away. No external blob store, no Plaid for files, no S3 dependency.

Tip
Don't confuse these file cabinets with HR compliance documents. Compliance docs (W-4 / I-9 / W-9 / NDA / COI) are type-tagged and feed into the compliance status dashboard. File cabinets are generic — drop anything you want to keep next to the entity. The Compliance guide covers the type- tagged side; this page covers the generic side.