=== Incidock - Client Request Desk & Incident Board ===
Contributors: davidshum98
Tags: client portal, feedback, kanban, agency, screenshot
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

A "Request a change" button for your clients, with the page and a screenshot attached, and a board where you handle, answer and time every request.

== Description ==

If you build or look after WordPress sites, your clients ask for changes everywhere: WhatsApp, email, phone calls, a comment in passing. Requests get lost, arrive without saying which page they mean, and the client keeps asking "how is my change going?".

**Incidock puts a "Request a change" button in your client's own WordPress, and gives you a board to handle what comes in.**

= For your client: one button =

* Logged-in users see **Request a change** in the admin bar, on the dashboard and while viewing the site. There is an optional floating button too, for clients who hide the admin bar.
* They write what they need. The page they are on, a **screenshot** and their browser details are attached automatically.
* Before sending they see the screenshot. They can **point out** what they mean, **cover** anything private, or not send it at all. Form fields are always hidden in the screenshot, so passwords, emails and card numbers never end up in it.
* They choose how urgent it is and can attach files: images, PDFs, office documents.
* In **My requests** they see the status of each request, reply to your questions and, when you mark a request as done, confirm it or tell you what is still missing.
* If they got something wrong or left something out, they can fix their own request while nobody has started it.

= For you: a board =

* Four columns: Pending, In progress, Waiting for client, Done. Drag the cards, or use the "Move to" menu, which also works with the keyboard.
* Each request has the page, the screenshot, the attachments and a conversation with the client, plus **internal notes** the client never sees.
* **See attachments without leaving the page**: images, PDFs, text files and CSV sheets open right there.
* Screenshots and images open in a viewer on the same page: zoom in with the wheel or the buttons and drag to move around. Opening the file in a new tab is still there, as the last option.
* **Time tracking**: add the minutes each request took with one click (+15, +30, +60 or any amount). The board shows the total for the month.
* Assign requests to someone on your team and change their priority.
* **Search as you type**: the board filters while you write, and says so when nothing matches.
* **Light and dark theme**, chosen by each person, not by the site.
* Add requests by hand for whatever arrives by WhatsApp, email or phone, so everything is in one place.
* **Email notifications** in both directions: new requests reach your team, and the client hears when you reply, need something from them or finish.
* And a notice in the dashboard, so nobody depends on email: your team sees how many new requests came in, and each client sees when a request of theirs is waiting for an answer or for them to confirm it is done.

= Who sees what =

* You choose which roles can request changes (administrators, editors and shop managers by default) and who is on your team.
* Your client can be an administrator: tick yourself as the team and they only see "My requests", never the board.
* Each client only ever sees their own requests.

= Private by design =

* Screenshots and attachments are stored outside the Media Library, in a protected folder with random file names. They are only served to your team and to the person who made the request.
* Choose extra parts of the site to blur in screenshots with CSS selectors.
* Screenshots and attachments are deleted automatically a number of days after a request is done (90 by default).
* It adds a suggested text to your privacy policy and works with WordPress's personal data export and erasure tools.
* No tracking, no accounts, nothing sent to other servers. See "External services" below.

= Incidock Pro =

For agencies that sell maintenance plans by the hour:

* **Central board**: the requests of every site you look after, in your own WordPress. Each client site connects with a one-time code; nothing is installed on your server but this plugin, and the board never gets access to their sites.
* **Answer from the board**: your reply and the column you move a request to reach the client's site, and what they answer there comes back to you. Internal notes stay on your board. You work in one place, and each client keeps everything on their own site.
* **The screenshot, on your board**: you see the screenshot and the attachments of every request without opening each site. The files never move: your board asks for them when you open the request, and if the client site deleted them, they are gone there too.
* Filter the board by site to see one client at a time.
* **Hours bank, one per site**: set the hours included each month for each client. Every minute you add to a request comes out of that client's bank, the hours are topped up on their own each month (and what is left over can carry across), and you can add extra hours whenever you sell them.
* You get an email when the hours are running out and another when they are used up, so nobody finds out at the end of the month.
* Your client sees what is left in "My requests" on their own site, without asking and without seeing your board.
* **Monthly report**: what came in, what was finished, where the time went, and who spent it. Send it to your client by email, download it as CSV or save it as a PDF from your browser.

== Installation ==

1. In your client's site, go to Plugins > Add New and search for "Incidock", or upload the zip file.
2. Activate it. You become the team on that site.
3. Go to Requests > Settings and choose which roles can request changes. If your client is an administrator, check that only you (and your team) are ticked under "Your team on this site".
4. Tell your client: "When you need a change, go to the page and click Request a change at the top."

== Frequently Asked Questions ==

= My client is an administrator. Will they see the board? =

Not if you choose your team. In Requests > Settings, tick yourself (and your colleagues) under "Your team on this site". Everyone else, administrators included, only sees "Request a change" and "My requests".

If nobody is ticked, every administrator counts as the team.

= Can the screenshot show private data? =

Form fields (names, emails, passwords, card numbers) are always hidden in the screenshot. You can add other parts of the site to blur in the settings, and your client sees the screenshot before sending it: they can cover any area or not send it at all.

The screenshot is made in the browser from the page itself. It only shows what that person could already see.

= Some parts of the screenshot are empty =

The screenshot is rebuilt from the page's HTML in the browser, so videos, maps and other content embedded from other sites may appear empty. The request is still sent with everything else.

= Where are screenshots and attachments stored? =

In wp-content/uploads/incidock, with random 32-character file names, never in the Media Library. On Apache the folder is closed with an .htaccess file. On Nginx the files can't be listed and their names can't be guessed. Files are always served through WordPress, which checks that you are on the team or made the request.

= Does it slow down my site? =

No. Visitors who aren't logged in don't load anything. For logged-in users who can request changes, the screenshot library is only downloaded when they click the button.

= Can my client change a request after sending it? =

Yes, while it is still in Pending: nobody has started it, so there is nothing to lose. Once you move it to In progress, only your team can change the text, and the client tells you what is missing in the conversation. Either way, what it said before is kept in the conversation, and you get an email when a client changes a request.

= Can clients send requests by email or WhatsApp? =

Not directly. Use "Add request" on the board to write down what arrives by other channels, with the name of the person who asked. It gets the same columns, conversation and time tracking as any other request.

= Who receives the emails? =

New requests go to each person on your team, or to the addresses you enter in the settings. Clients are emailed when you reply, need something from them or finish their request. You can turn off client emails. Emails are sent through your site's normal email (wp_mail), so they work with any SMTP plugin.

= Does it work on multisite? =

Yes, site by site: each site has its own board, team and settings.

= What happens to the data if I delete the plugin? =

Deleting the plugin from the Plugins screen removes all requests, their conversations, screenshots and attachments, and its settings. Deactivating it keeps everything.

== Screenshots ==

1. The board: every request in its column, with its priority, screenshot, messages and time.
2. A request: what they asked for, the screenshot with what they pointed out, the conversation with internal notes, and the time spent.
3. The "Request a change" window on the client's site: the screenshot is taken there, and they point out what they mean before sending.
4. My requests: what the client sees, with what is waiting for them first.
5. When a request is done, the client confirms it or says what is still missing.
6. Settings: who can request changes, who is on your team, the emails and how screenshots work.

== External services ==

= Your requests stay on your site =

Requests, screenshots and attachments are stored on your own site, and notifications are sent with your site's own email function (wp_mail). The plugin has no server of its own and sends nothing to us.

= Screenshots =

To build a screenshot, the browser of the person making the request reloads the images, fonts and styles the page already uses, from wherever the page loads them (for example a CDN or Google Fonts), exactly as when the page was opened. The plugin doesn't add any address of its own, and the screenshot is only sent to your site.

= Your agency's central board (only if you connect it) =

If the agency that looks after this site uses the Pro central board, an administrator of this site can connect it: you paste the address of the agency's own WordPress and a one-time code they give you. There is no address inside the plugin, and nothing is sent anywhere until you do that.

Once connected, this site sends that board the requests made here — title, description, the page they are about, priority, status, the date and the name of the person who asked — and the replies written here, so that the agency can handle every client from one place. No email addresses and no passwords are sent. Screenshots and attachments stay on this site: only the file name, type and size travel, and the board asks this site for the file itself when somebody there opens the request. The board can send back replies, a change of status and the hours left in your plan, and nothing else: it cannot reach anything else on this site.

Every message is signed with a key shared when you connected, and you can disconnect at any time in Requests > Settings, which deletes that key from this site.

= Freemius =

Incidock uses the [Freemius](https://freemius.com/) SDK to offer the free trial and the Pro upgrade, and to manage Pro licenses and updates.

* The free version doesn't ask you to share any data and sends nothing to Freemius while you use it.
* If you start the trial, buy Pro or activate a license, the plugin sends Freemius basic data such as your name and email, your site's address, and your WordPress, PHP and plugin versions, so that licenses and updates can work.

Freemius: [terms of service](https://freemius.com/terms/), [privacy policy](https://freemius.com/privacy/) and [data practices](https://freemius.com/privacy/data-practices/).

== Third-party libraries ==

Screenshots are made with [modern-screenshot](https://github.com/qq15725/modern-screenshot) 4.7.0 by qq15725, released under the MIT license. It is included unminified in assets/vendor/modern-screenshot, together with its license.

== Changelog ==

= 1.0.3 =
* First release.

== Upgrade Notice ==

= 1.0.3 =
First release.
