Changelog

What we shipped, when. Newest first.

Safer, recoverable membership payment choices

14 August 2026

What's new

Families and staff can always retry a replacement Direct Debit

  • Direct Debit setup now remembers the latest safe GoCardless attempt for each

household or member, even after many earlier attempts were cancelled, failed or completed.

  • Concurrent retries still converge on one provider request, so recovery does

not create duplicate mandate journeys.

  • A long history is continued across short, retryable requests instead of

leaving the household permanently unable to set up a new mandate.

Switching payment methods cannot leave Direct Debit collecting

  • Choosing monthly card now pauses future GoCardless subscription cycles before

the portal confirms the switch.

  • Returning to Direct Debit resumes only subscriptions that were paused by that

exact payment-method switch. A membership pause, manual pause or ended subscription is never silently undone.

  • Saving a card or activating a bank mandate makes it ready to use; the member

still confirms the actual switch in the portal.

  • Families are warned that a Direct Debit already submitted to the bank may

still collect even after future cycles have been paused.

Direct Debit mandates can be managed safely

13 August 2026

What's new

Staff can link, reassign, cancel and unlink Direct Debit mandates

  • The household Direct Debit panel can now verify and link an existing mandate

from the club's connected GoCardless account.

  • Staff can search the connected account for unlinked mandates instead of

copying an ID first. Exact Allsorted assignments, likely payer-email matches and ambiguous records are clearly distinguished, with manual confirmation required before ownership changes.

  • Searchable member and household assignment controls include household context

and a short record reference when duplicate names would otherwise look the same.

  • A live mandate can be reassigned to the correct household or member. The

change is blocked while a debit is pending or submitted, and future recurring payments move with the mandate while past invoices and payments stay put.

  • Linking or reassigning a mandate now also checks GoCardless for live recurring

payments that are not yet tracked by Allsorted. Staff must end or migrate those subscriptions first, preventing two systems from collecting the same membership payment.

  • Staff can cancel all future recurring payments and the mandate in one guarded

action. The confirmation makes clear that a debit already submitted to the bank may still be collected.

  • Ended mandates can be unlinked without deleting financial history.
  • A replacement Direct Debit can now be set up after an earlier mandate has

ended; an abandoned setup still resumes safely without creating duplicates.

  • When a household is split, staff explicitly choose whether its Direct Debit

stays with the original household, moves to the destination or is cancelled.

  • Provider-first verification, exact replay protection and the Payments Health

repair queue prevent a GoCardless change from being presented as locally complete when settlement is uncertain.

Clubs can choose how families pay recurring memberships

  • Club payment settings now offer Direct Debit only, monthly card only, or both.
  • When both are offered, families can choose their preferred method in the

member portal and switch without changing or cancelling the membership.

  • Direct Debit remains powered by GoCardless. Families can set up or replace

their bank mandate through the existing hosted flow. Portal setup now keeps its provider metadata within GoCardless's three-field limit, including when Direct Debit is selected automatically after activation.

  • Monthly card is securely set up through the club's connected Stripe account.

Allsorted then collects the existing membership invoice automatically, so proration, pauses, arrears, reports and refunds continue to use one ledger.

  • Families can see safe card details and status, update an expired or failed

card, and return to an active Direct Debit. Full provider identities and bank or card details never reach the browser.

  • Staff impersonation is view-only for payment changes. A selected card that

needs attention never silently falls back to an old Direct Debit.

  • Existing clubs retain Direct Debit as their default until an authorised

staff member deliberately changes the new setting.

Register attendance stays where staff put it

  • Marking someone Present, Late or Absent now keeps that choice visible while

the save completes. An older day refresh can no longer briefly reset the member to Absent before the confirmed attendance appears.

External-event refunds reconcile reliably

12 August 2026

What's new

External-event refund confirmations recover from compact Stripe events

  • Stripe can sometimes send a refund confirmation without embedding its full

refund list. AllSorted now securely loads the authoritative list from the exact connected club account before reconciling the event entry.

  • The existing money safeguards remain unchanged: the provider refund total

must match the charge's exact cumulative refunded pence, and webhook replays remain idempotent.

  • This prevents a correctly completed refund from remaining incorrectly marked

as a failed webhook in Payments Health.

Household plan details load reliably

  • Household plan details now load class usage through the household's exact

memberships instead of relying on a database relationship that does not exist.

  • The read remains explicitly club-bound and fails closed on any incomplete

membership, plan, usage or coverage query, so another club's data cannot be exposed as part of the repair.

  • Local full-journey fixtures now follow the club's UK date through midnight,

exercise an authorised parent portal session and clean their trial-operation ledgers completely after every run.

New-club setup opens the dashboard cleanly

  • Finishing the onboarding wizard now starts a fresh dashboard session after

the server confirms setup is complete.

  • This prevents the earlier cached setup state from sending a new owner back to

a blank onboarding screen even though their club was already ready.

  • A failed completion write still stays on the final step with an actionable

error, and cannot be presented as a successful launch.

Staff enrolments prepare correctly

11 August 2026

What's new

Staff enrolments no longer fail during checkout preparation

  • Fixed a database result mismatch that caused a valid staff-led enrolment to

roll back before Stripe checkout could open.

  • The repair preserves the existing atomic enrolment, tenant, replay and

payment-authority boundaries. A failed prepare still creates no member, household, invoice or payment.

  • Added a real database rehearsal that completes a valid prepare and its exact

idempotent replay; catalogue-only checks cannot miss this failure again.

Stripe invoice checkout now matches AllSorted

  • The secure Stripe form now inherits the active AllSorted colours,

typography, spacing, focus states and reduced-motion preference.

  • Invoice checkout keeps a stable loading panel and shows a clear retry message

if Stripe cannot load, instead of collapsing into an unexplained empty strip.

  • Reopening an unpaid invoice now safely resumes its active Stripe attempt,

blocks a second charge while money is being confirmed, or creates one deterministic replacement when the previous attempt was cancelled.

  • Payment amounts, available methods and settlement behaviour are unchanged.

Faster, more honest local performance assurance

  • Local development now forwards browser errors into the terminal while keeping

full request URLs out of logs, so one-use public tokens are not exposed.

  • Active-club cookie synchronisation now survives hard navigation while retaining

its existing authenticated club-access check.

  • The critical-journey timing report now fails visible not-found pages, covers

the real calendar and external-event surfaces, and includes enrolments and arrears with tighter warm-page budgets.

  • The arrears snapshot now loads issued credits and household display details in

parallel after its club-scoped invoice read. All tenant, capability and fail-closed money checks remain unchanged.

Payments, refunds and privacy stay in sync

  • Paid event bookings now retain the exact Stripe amount in integer pence, so

eligible cancellations can refund the full proven payment instead of failing closed on a missing historical amount.

  • Event cancellation cutoffs now use the club's UK wall-clock time through GMT

and BST. The exact cutoff instant is allowed; one millisecond later is not.

  • Permanently erasing a member now removes their identity from an issued invoice

line while preserving the invoice, description, quantity and every accounting amount unchanged.

  • Family insurance renewals keep the paid member selected long enough to show a

clear confirmation instead of jumping immediately to another renewal due.

  • A local paid LMS course completed the full Stripe test journey: exact charge,

webhook unlock, refund, entitlement revocation and portal relock.

  • Refunded LMS courses can now be bought again. Repeated clicks or a second tab

resume the same verified checkout instead of creating another payable intent, while a genuinely new post-refund purchase receives a fresh payment identity.

Direct Debit pauses now include GoCardless

  • Part-month membership charges now use the number of days in the actual

calendar month. An 11 August to 1 September £12.34 period is £8.36, with dedicated coverage for 28, 29, 30 and 31-day months.

  • Immediate and scheduled membership pauses now use one replay-safe authority:

the GoCardless subscription is paused first, its provider state is verified, and only then is the local billing agreement paused.

  • Staff see a clear warning that a Direct Debit already created or submitted to

GoCardless may still be collected and should be checked before promising that payment has stopped.

  • Scheduled pauses are durably queued and retry safely; provider failures leave

local billing active rather than creating a misleading partial pause.

  • The cancelled-mandate Action Inbox alert no longer ends with duplicated

punctuation.

Membership reactivation and payment recovery are safer

  • Reactivating a paused member now resumes their individual GoCardless billing

before changing their member status. A shared household plan is never resumed silently; staff are directed to the household plan where everyone affected is visible.

  • A reactivation cancels any unclaimed scheduled pause first. If a pause is

already being processed, reactivation stops with a clear retry message rather than allowing an old job to pause billing again afterwards.

  • The daily payment health check now recovers LMS purchases left waiting after

an interrupted checkout. It verifies the exact Stripe payment identity, settles proven successful payments, safely releases abandoned attempts and sends ambiguous cases to Payments Health for staff review.

  • Issued invoices can no longer be physically deleted through a parent cascade.

Draft cleanup remains available, while issued accounting evidence must follow the existing anonymise, void, credit or refund paths.

  • Local GoCardless and enrolment rehearsals now refuse the shared database and a

live GoCardless connection. Their concurrency proof also identifies the real worker instead of accidentally matching its own monitoring query.

Clear email opt-out filtering

10 August 2026

What's new

Club Stripe payments now stay in the club's account

  • Allsorted subscription billing and club/member payments now have separate

Stripe configuration. Charges paid by parents or members are created directly in the club's connected Standard Stripe account; Allsorted takes no transaction fee and is not the merchant in the club-money flow.

  • Clubs can link an existing Standard Stripe account or create their own

Standard account through Stripe-hosted onboarding. Existing legacy Express connections remain readable, but new onboarding no longer creates Express accounts.

  • Browser confirmation, webhooks, refunds, reconciliation and expiry processing

all use the same connected-account identity. Connected webhook events are rejected unless the Stripe account and club metadata agree.

  • In-flight and historical destination charges remain confirmable/refundable

through a strict compatibility path that verifies both the original transfer destination and club metadata. No new destination charges are created.

  • Deployment needs the Connect secret/publishable key and connected-account

webhook configured before code goes live. No database migration is required.

Local six-area critical-journey assurance

  • Added a complete provider-free lead journey for the local Vertical Test Club:

public trial booking, closure-aware dates, attended/no-show outcomes, staff follow-up, existing-family enrolment, one-time portal activation and a conversion that appears exactly once in the pipeline, reports and automation effect ledger.

  • Trial-converted members can now be permanently erased without deleting the

immutable conversion operation. The nullable member identity is released by the database while the exactly-once status evidence remains intact.

  • Added a provider-free member-lifecycle journey covering public enrolment,

family portal switching, membership and classes, default absence, promotion, insurance, leaver/reactivation and permanent erasure.

  • Added one local-only npm run smoke:critical-journeys command for the seeded

Vertical Test Club. It covers reversible critical writes, cross-feature data agreement, tenant/RBAC boundaries, desktop/mobile accessibility, warm-route readiness and mocked provider/background failure contracts without sending messages or collecting payments.

  • The pack reuses one clearly labelled, idempotent assurance member/household

fixture and creates only temporary foreign-tenant/role fixtures for isolation checks. It refuses hosted targets and the wrong local ports.

  • Shared dialogs now move focus inside after their portalled animation shell is

mounted and restore focus to the opener after Escape/close.

  • Register and Settings navigation now matches the same base-role authority as

their routes, and live-register pulse decoration respects reduced-motion.

Email opt-outs can be inspected from Communications

  • The recipient readiness summary already showed how many contacts were

unsubscribed from bulk email, but the nearby opt-out filter applied only to SMS. Communications now has separate, clearly labelled email and SMS reachability filters.

  • Choosing Email → Unsubscribed returns the same contacts counted in the

email readiness summary. Older saved recipient audiences remain compatible and continue to behave as though no email-reachability filter was selected.

Event member search understands full names

  • The staff Add booking picker now matches multi-word names such as

“Chris Wood”, as well as partial names, email addresses and reversed name order. Previously the whole query was compared separately with the first and last name, so a full name could return no results even when either name alone worked.

Event invitation feedback is less intrusive

  • Sending invitations from the calendar event panel now reports created,

queued, sent and failed outcomes in the shared floating toast instead of leaving a result banner inside the event workspace. Partial and failed sends retain their warning or error styling.

Action feedback is clearer and more consistent

  • Short-lived confirmations now use the same floating toast across

Communications, automations, scheduled reports, member and household tools, the register, portal actions, settings, billing and provider-return screens. Confirmed success is green, neutral updates are blue, partial outcomes are amber and failures are red.

  • Messages that still need a decision or correction remain beside the affected

content. Validation errors, retry instructions, invitation delivery concerns, import results, booking conflicts and payment-provider recovery guidance are never hidden in a disappearing notification.

  • Stripe, GoCardless and subscription callback results are consumed once, so

refreshing or revisiting a copied callback URL cannot repeat an old success message. Provider failures and expired-link guidance remain visible until the owner acts on them.

Event booking details and printable registers

  • Requirement completion on the event roster now says Complete rather than

the ambiguous Pass, and has a visible View details action. The same panel shows the booking timeline and recorded requirement answers directly, without making staff navigate through invitation history.

  • Date answers captured as ISO values are displayed in UK DD/MM/YYYY format.

The immutable stored answer is not changed.

  • The Bookings toolbar now includes an Event register PDF. It lists every

confirmed member with their payment state, attendance/result, key roster details and the answers captured when their booking was made. Large event rosters are paged completely rather than silently stopping at a database response limit.

Slow pages now recover instead of loading forever

  • Scheduled status changes, arrears, the enrolment pipeline, calendar trials

and the course workspace now stop a stalled read and show a clear Retry action instead of leaving staff on an indefinite loading state.

  • Moving away from one of these screens cancels its active request, and a newer

filter or retry cannot be overwritten by an older response.

  • Calendar trials now receives invite status from the authenticated,

club-scoped server snapshot instead of a second browser database read.

External-event payment setup now fails safely

  • Viewing an external event no longer initialises Stripe with a missing browser

key. Paid entry journeys now explain that payment is temporarily unavailable and stop before creating an entry or invoice; free entries remain available.

  • Communications and event rich-text editors now register their hardened link

extension once, removing the duplicate-extension warning while retaining the existing safe-protocol and new-tab protections.

Browser-smoke usability repairs

  • Event, task and grading-session editors now use the shared accessible modal,

including Escape dismissal, focus handling and a named close control.

  • Member search, register warnings and date controls now expose clearer names

to assistive technology. Household filter rows show truthful overflow cues, and staff leave dates use the club's familiar UK date format.

  • Automation builders now treat the loaded definition as the saved baseline,

so opening an untouched automation no longer produces a false unsaved warning.

System-wide smoke findings repaired

  • Gymnastics and the assessment matrix now load member and assessment data from

guarded, club-scoped server snapshots. Apparatus result writes also validate the member's active programme enrolment before saving.

  • Student Videos, Payment Options and Deliverability now distinguish a failed

read from an empty result, stop stalled requests and offer a visible retry.

  • Bulk Voice Note rejection preserves failed selections and reports exact

success, partial and failed outcomes instead of silently clearing the queue.

  • Team Sports now uses the same headings, cards, buttons, fields and guarded

confirmation dialogs as the rest of the staff app.

  • The register Health sheet and Communications History now use accessible modal

behaviour. Health acknowledgements are recorded through a permission-checked server route rather than a browser database write.

  • Add Member now keeps its current step and save context visible and warns before

abandoning entered details. Staff Leave saves use the shared toast feedback.

  • Browser payment clients are created only when a publishable key is configured,

preventing unrelated read-only pages from throwing a provider error locally.