Confidentiality built into the schema, not the styling
Compensation is not a hidden column — it is a separate table. The directory query physically cannot return a salary, because the table it reads has no salary in it. Salaries are fetched one at a time, only when someone presses Reveal, only after a permission check, and they are dropped from the cache thirty seconds after you leave the page.
| Separate table | A bulk directory read cannot return salaries, even locally |
| Per-fetch authorization | Each reveal is checked against the viewer's permissions |
| Access log | Actor, subject, resource and timestamp, written on every read |
| Cache eviction | Compensation queries are removed on leaving the HR section |
| Refused, not masked | A URL you lack permission for redirects, rather than rendering blanks |
Ten permissions, and one deliberate gap
Access is a vocabulary of ten verbs granted by role, plus what everyone holds over their own record, plus what a manager holds over a direct report. That last set includes a report's profile and reviews — and pointedly not their salary. Seeing a report's pay requires HR or an executive, on purpose.
| Staff | Read and write the board |
| Manager | The board, the directory, and the recruiting pipeline |
| HR admin | All ten verbs, including writing compensation |
| Executive | Everything except changing anyone's pay |
| Yourself | Your own record, compensation, documents and reviews |
| Your reports | Their record and reviews — never their salary |
Career ladders people can actually see
Each of the five departments has a real ladder with named rungs, and an employee's record shows where they stand on it: the rungs behind them, the one they hold, and the ones still locked. Editorial runs seven rungs from Editorial Assistant to Publisher; Design runs six from Design Intern to Design Director; Marketing, HR and Leadership have their own.
| Editorial | Editorial Assistant · Assistant Editor · Editor · Senior Editor · Executive Editor · Editorial Director · Publisher |
| Design | Design Intern · Junior Designer · Book Designer · Senior Designer · Art Director · Design Director |
| Marketing | Marketing Assistant · Marketing Associate · Publicist · Senior Publicist · Marketing Lead |
| People | People Coordinator · People Partner · People & Culture Lead |
| Leadership | Director · Managing Director |
Titles, and the dates they have to hit
Every book carries its stage, genre, ISBN, word count, target publication date and the editor and designer responsible. The editorial calendar draws publication dates, milestones and card due dates on one month grid — each styled differently, each coloured to its book — so a slipping proof and a fixed pub date are visible in the same glance.
Recruiting, through to the awkward column
Candidates move Applied, Screening, Interview, Offer, and then the column that is honest about what happens next: Hired or Rejected. Each card carries a rating, the role applied for, and their résumé. People without permission to move candidates get a read-only board and are told so, rather than discovering it when a drag silently fails.
Built for the person who never closes it
Command-K jumps to any book, card or colleague without a network round trip. Cards open in a slide-over that never unmounts the board behind them, and the URL follows, so a card is a link you can paste to a colleague. Comments take @mentions. Light and dark throughout.