Bookflow

Run the press, not the spreadsheet

Internal operations for a publishing house. Every title's place in the editorial pipeline, the calendar it has to hit, the people who move it, and the confidential records that come with employing them — in one desktop tool built for people who live in it all day.

The editorial board, with limits that mean something

Five columns follow a manuscript from acquisition to print. Editing, Design and Proofing carry work-in-progress limits, and the column header fills with pips as it approaches them — amber at the limit, red past it. A card blocked by a dependency is drawn dashed with a lock, so the thing that cannot move looks like it cannot move.

BacklogNo limit — acquired, not yet started
Editing5 at a time
Design4 at a time
Proofing3 at a time
PublishedNo limit — done
Bookflow editorial Kanban board with Backlog, Editing, Design, Proofing and Published columns, showing WIP counters, coloured label chips, and blocked cards drawn with dashed borders and a lock badge

What is late, what is stuck, and who is carrying it

The morning view splits your cards into overdue, due today, this week and later. Beside it, bottlenecks name the columns over their WIP limit and the cards that block the most other work. A workload chart shows open cards per person with the blocked portion shaded, so an overloaded editor is visible before they say so.

Bookflow dashboard showing My work cards assigned to the Managing Director, overdue and this-week buckets, and a workload chart

A directory that opens with a warning, and means it

Every HR screen sits under one line: "Confidential — every record you open is logged against your name." That is not decoration. Opening a salary writes a row to an access log with who looked, whose record, and when.

Bookflow HR directory listing employees with department, role and a confidential banner that every record you open is logged

Confidentiality built into the schema, not the styling

Compensation is not a hidden column — it is a separate table. The directory query physically cannot return a salary, because the table it reads has no salary in it. Salaries are fetched one at a time, only when someone presses Reveal, only after a permission check, and they are dropped from the cache thirty seconds after you leave the page.

Separate tableA bulk directory read cannot return salaries, even locally
Per-fetch authorizationEach reveal is checked against the viewer's permissions
Access logActor, subject, resource and timestamp, written on every read
Cache evictionCompensation queries are removed on leaving the HR section
Refused, not maskedA URL you lack permission for redirects, rather than rendering blanks

Ten permissions, and one deliberate gap

Access is a vocabulary of ten verbs granted by role, plus what everyone holds over their own record, plus what a manager holds over a direct report. That last set includes a report's profile and reviews — and pointedly not their salary. Seeing a report's pay requires HR or an executive, on purpose.

StaffRead and write the board
ManagerThe board, the directory, and the recruiting pipeline
HR adminAll ten verbs, including writing compensation
ExecutiveEverything except changing anyone's pay
YourselfYour own record, compensation, documents and reviews
Your reportsTheir record and reviews — never their salary

Career ladders people can actually see

Each of the five departments has a real ladder with named rungs, and an employee's record shows where they stand on it: the rungs behind them, the one they hold, and the ones still locked. Editorial runs seven rungs from Editorial Assistant to Publisher; Design runs six from Design Intern to Design Director; Marketing, HR and Leadership have their own.

EditorialEditorial Assistant · Assistant Editor · Editor · Senior Editor · Executive Editor · Editorial Director · Publisher
DesignDesign Intern · Junior Designer · Book Designer · Senior Designer · Art Director · Design Director
MarketingMarketing Assistant · Marketing Associate · Publicist · Senior Publicist · Marketing Lead
PeoplePeople Coordinator · People Partner · People & Culture Lead
LeadershipDirector · Managing Director

Titles, and the dates they have to hit

Every book carries its stage, genre, ISBN, word count, target publication date and the editor and designer responsible. The editorial calendar draws publication dates, milestones and card due dates on one month grid — each styled differently, each coloured to its book — so a slipping proof and a fixed pub date are visible in the same glance.

Recruiting, through to the awkward column

Candidates move Applied, Screening, Interview, Offer, and then the column that is honest about what happens next: Hired or Rejected. Each card carries a rating, the role applied for, and their résumé. People without permission to move candidates get a read-only board and are told so, rather than discovering it when a drag silently fails.

Built for the person who never closes it

Command-K jumps to any book, card or colleague without a network round trip. Cards open in a slide-over that never unmounts the board behind them, and the URL follows, so a card is a link you can paste to a colleague. Comments take @mentions. Light and dark throughout.