Skip to content
Sami Aktaş

35 entries · September 22, 2026

TR

Ledger by venture

Payda

35 entries — real, dated progress notes for Payda.

Esnaf modu gitti, kişisel panel geldi

Bugün Payda'yı sadeleştirdim: esnaf modunu ve ona bağlı tahsilat, veresiye, üyelik, e-ticaret gibi yan sistemleri önce yedekleyip sildim, yalnız yüzdelik sistem kaldı. Ardından herkesin kendi adını ve fotoğrafını her projede aynı gösterebildiği bir Profilim alanı ekledim. Üstüne YouTube, Instagram, TikTok, Threads ve X için günden güne takip kurdum; artık tek satırda 'bugün toplam kaç beğeni, kaç yorum aldın' görünüyor. Hepsi yine tek Claude üyeliğiyle, testleri yeşil geçerek canlıya çıktı.

Kopilot tek akışa indi, sami skill denetiminden geçti

Kopilot sayfası iki paralel akış taşıyordu; tek kutu, tek gönder tuşu, tek sonuç kartına indirdim ve 12 uzman modlu denetimin bulduğu 20'den fazla açığı (idem anahtarı, metin kaybı, kaydırma, balon-kasa örtüşmesi, uzun sohbette hükmün kaçması) dört turda kapattım. Her tur 13 kapı ve tarayıcı testinden geçti, canlıya çıktı. Hepsi tek Claude Pro üyeliğiyle, kanıtsız tek satır iddia yok.

Numaranın yanına tutar, kartın üstüne 'Şimdi ne oldu?', sohbetten fiyat listesi ve banka kendiliğinden doluyor

Sami'nin üç isteğini tek akışa bağladım: ayrı 'Gelir ekle' tuşu kalktı, müşteri numarasının yanında tutar var; müşteri bulununca kartın en üstünde 'Şimdi ne oldu?' — satış olduysa geliri kaydet, olmadıysa almadı notu — önceki kayıtlar altta. En keyiflisi: yapıştırılan sohbette hangi hazır metin (fiyat listesi, IBAN) geçiyorsa fiyat listesi ve banka alanı kendiliğinden doluyor, yapay zekâ çağrısı yok, ücretsiz. Kural gevşemedi: eşleşme yoksa soru yine sorulur, elle seçim ezilmez. 16 yeni test, 320px'te taşma sıfır, hepsi Claude ile.

Tasarımı canlıya birebir taşıdım: sol menü, tek sütun Özet, Ayarlar grupları

Claude Design'da çizdiğim yenileme canlıda yarım kalmıştı; bugün planı adım adım uyguladım: masaüstünde sol menü ve sayfa başlığı, Özet'te KPI şeridi ile yan yana Kasa ve Ödenecekler, Defter'e tür seçicili Kayıtlar tablosu, Ekip'e hakediş tablosu, Ayarlar'a sol grup listesi. Her parça 13 test kapısından ve parolasız ekran ölçümünden (320px'ten 1280px'e taşma sıfır) geçti. Bir dağıtımı kendim durdurdum — testler koşarken bir belge düzenledim, deploy.sh yakaladı — ve temiz ağaçla yeniden çıkardım. Hepsi Claude ile.

Super-app research: Payda is a very good ledger, but still a ledger

The system has settled, so today I wrote no code at all — I spent it researching the "super app" idea. First I took stock of what exists: 29 endpoints, 8 collections, 1,400 checks; the money side (four-eyes approval, exchange rates sealed at transaction time, partner current account, period close, audit trail) is genuinely solid. But the one-sentence truth is this: every number in Payda is a hand-typed record of something that happened somewhere else — the sale happens elsewhere, the ad spend happens elsewhere, the money lands elsewhere. Measured against the three pillars of the super-app pattern, identity came out strong, payments exist only as bookkeeping, and a mini-app platform is unnecessary at this scale; in my context "super app" means moving from ledger to workbench. I listed five candidate directions — a conversation layer, bank statement matching, an intelligence layer that finally asks questions of the data we already collect, an installable app with real notifications for employees, and multi-team support — and left myself three questions to answer before choosing.

Product Strategy · Research · Super App · Roadmap

A deactivate button shipped, and two test gates turned out to be blind

A short four-item run: a deactivate button on the member card (same button for a suspension or a holiday — a deactivated member can't see the project in their list or write any data, but their earnings and history stay, and I can still pay them while they're inactive), the ability to change an employee's ad-account assignment after the invite, a "spent to date" line on ad-account cards, and manual payment entry closed for good — payment records are now produced only by the system's own flows. The auditor caught a false promise in the confirmation text: it said "a deactivated member cannot log in", but the account isn't closed at all, only project access drops; the wording was pulled back to the truth and the test now also measures the absence of that false promise. The real find of the run was that two gates were blind — yesterday's parity gate couldn't detect a stale exception, and the template-binding gate had never checked the row properties of 16 nested lists; coverage went from 75 blocks to 87. All nine mutations broke the gates by name; commit aa18bb2, 1,400 checks green.

Member Management · Ad Accounts · Test Gates · Emulator Testing · Cloud Functions

Is everything in the backend reachable from the UI? A parity gate plus a dead-code sweep

I turned the question "is everything the backend can do reachable from the frontend?" into a two-way audit: every endpoint, every single op of the multi-op endpoints, and every field the server writes went through one filter — can a user actually reach this? At endpoint level all 26 callables were wired, but at sub-op level five real gaps showed up: an ad account's name and warning threshold couldn't be changed after setup, a mistyped reminder couldn't be deleted, and the endpoint that renames a category while carrying old sales along could never be triggered. I wired all of them. On the dead-code side every deletion came with grep proof (the rotationQueue leftover from the old shift model, the lastProduct field that was written but never read, dead CSS and state), and an independent auditor agent spot-checked both the deletions and the things claimed to be in use. The lasting win isn't the one-off cleanup: the rule "every endpoint is either called from the UI or a justified exception" is now enforced by a test — we sabotaged the gate three ways and it named the culprit all three times. The same run added an optional short note to sales entry, visible on the purchase line of the customer card and never written when left blank; commit 85bfb79, 1,322 checks green.

Dead Code Removal · Parity Gate · Cloud Functions · Code Audit · Testing

Manual shift ordering, the 40-day due-date bug, and split customer records

The five-item run that started last night went live this morning. Every row in the shift list now has ↑/↓ arrows — I can order the rotation by hand, and moving someone doesn't change their working hour, only the rotation sequence. The "40 days" due-date bug I'd spotted was real and deeper than I thought: the formula skipped the template's first unpaid month, and pressing Pay got rejected by the server with "this month is already paid"; the corrected rule was written identically on both server and client, and across a 1,344-combination grid test the rejection window is zero. Customer records weren't disappearing either — they were splitting: the same number landed in separate documents as "0555…", "+90 555…" and so on; the server now reduces every spelling to one canonical key, and all 121 live customer records were migrated copy-verify-delete with zero loss. The group-remainder pie chart and the "pay from which group" hint above the payment form shipped in the same deploy; commit fe7122d, 1,212 checks green.

Shift Rotation · Due Date Logic · Data Migration · Firestore · Testing

Radical simplification to match the business model is live

Payda went through its biggest change yet today: everything that didn't fit the business model was deleted, and everything left now follows a single rule. Commission is one model only — a gross percentage of the sale; salary and per-sale models, task assignment, the banker login role and overhead categories were removed entirely. Entering a sale is down to four required fields (account, bank, category, tone), customer records gained number-based blocking, and tasks were replaced by dated reminders tied to an account. The hardest part of deleting wasn't the code, it was the proof: every removed piece was reported with grep evidence that it genuinely wasn't called any more, an independent auditor agent verified it on a random sample, and the test suite was rewritten for the new model — 1140 checks green.

Simplification · Dead Code Removal · Four-Eyes Approval · 1140 Tests

E-mail verification strip and deliverability work

Users signed in with an unverified e-mail now see a security strip in the panel: 'Send verification e-mail' in one click. A closing bug in the quick-action form was fixed too; both verified live. The next job is clear: we started the deliverability (SPF/DKIM) work so our e-mails stop landing in spam.

Email Verification · Security · UX

Live user testing: sign-in and e-mail verification fixed

I walked the site like a real user with a synthetic account: sign up → sign out → sign back in → transact. Everything the test caught was fixed the same day: new members weren't receiving the verification e-mail, unverified sign-up was possible, and sign-in stalled after a password reset — all fixed. In the UI the top-right bell is gone; notifications moved into the Summary (with 'Read' and 'Mark all read'), and the income/expense form now opens in place. The entire 8-item fix list went live.

Firebase Auth · Email Verification · UX

Shift rotation: the +1-hour rolling queue is live

The shift system now rotates the whole team in turn: each cycle the next person's shift slides +1 hour, and who comes when is visible 9 cycles ahead. The panel got an 'on shift now' badge and a rotation tab (current/next person + notifications). We started on the night of the 16th and finished by dawn; all 182 tests green, deployed.

Rotation Queue · Notifications · 182 Tests

A real app bottom sheet: '+' opens the form in place

I fixed a fair criticism: the 'Add' button opened an empty routing screen and everything funneled to the summary — pointless. Now tapping '+' slides up a real transaction form from the bottom, just like phone apps: pick Income/Expense, enter the amount, save — it records instantly and closes, you never leave the screen. In-place, fluid, native-app feel. Centered card on desktop, full width on mobile. 166 tests green, live.

Bottom Sheet · Mobile UX · Tests

Phone-app feel: bottom navigation + big buttons

I gave Payda a real phone-app feel: instead of tabs on top there's now a fixed floating bottom bar — Summary, Ledger, a huge '+' Add in the middle, Team and Settings. Tapping Add shows two giant cards ('What do you want to add?' Income / Expense) that take you to the form in one touch. One-handed thumb use got much easier. On desktop it sits as an elegant floating bar. Verified everything on the emulator, 166 tests green, live.

Bottom Navigation · Mobile UX · Tests

Tabbed panel (button logic) + dead-code cleanup

I split Payda's long-scrolling admin panel into button-style tabs: three big fixed tabs on top (Summary · Ledger · Team & Shifts), each hiding the others — you switch sections without scrolling, and your personal shift/task summary stays on top. Then I cleaned the dead code left over from features I'd removed earlier (bank presets, the banker balance-top-up panel) — 16 unused bindings and 3 dead functions gone; I walked the banker and admin screens live to confirm no white screens or errors. Desktop+mobile, 166 tests green.

Tabbed UI · Refactor · Tests

Visual depth + tactile buttons + a live experience test

This time I tested Payda by actually using it: opened it in the emulator, clicked through every section, opened settings, added income/expense from the UI — everything worked, zero console errors. I also fixed the 'flat' look people complained about: accent lines and layered shadows on KPI boxes, soft depth and hover lift on cards, tactile feel on all buttons (glow on hover, press-in on click), accent dots on section headers. CSS and copy only; business logic untouched, 166 tests green, solid on desktop+mobile.

Design · CSS · Experience Testing

Shift tracking system + currency-drift fix

Today I added shift tracking to Payda: it computes rotating shifts automatically (e.g. start at 12:00, slide +1 hour daily), everyone sees their own and the team's hours, and a red countdown warning appears half an hour before a shift. I also fixed an annoying bug: fixed-expense amounts drifted with the live exchange rate — now the amount stays fixed in the currency you entered. Managers/partners also got a 'what's left in which bank after deductions' view and a field to note which account was tried for a non-buying customer. 166 checks green, verified on desktop and mobile.

Shifts · Currency Pinning · Tests

Banker without e-mail, automatic partner share, bank clutter gone

I simplified Payda further: you can now add a banker with just a name and percentage, no e-mail needed (we only need to know; the invite can come later). Partner share is now automatic from net profit and each partner sees THEIR own percentage — previously the first partner's percentage showed for everyone; fixed. The confusing 'route payment through bank account' preset is fully removed. Canned texts now fill the screen as a grid instead of one narrow column. 162 automated checks green, live.

Simplification · Profit Share · Tests

Dropped the clutter: notes, banker confusion, canned tone

Today I decluttered Payda: removed the 'notes' feature people found pointless; sales/contact tone is now free text instead of fixed soft/neutral/hard choices; recording a negative customer response now also stores 'which bank was shown'; and the banker's confusing 'top up balance / enter expense' panel is gone — expenses are strictly a manager/partner job now. 159 automated checks green, live.

Simplification · UX · Tests

Wider partner approvals, online indicator, security scan

Four jobs in Payda today: (1) searching a customer number now also shows which account paid into which bank. (2) With a partner present, it's no longer just profit share — changing a member's %, removing a member and deleting a project all require the other partner's approval; no one can break the structure alone. (3) Partners see a green dot for who's online. (4) An OWASP Top 10 security scan: access control, XSS, headers, injection — all clean; the two remaining items (2FA, bot protection) will be toggled from the panel. 163 automated checks green, live.

Four-Eyes Approval · OWASP · Tests

Sales tone + picky-customer tracking + broadcast tasks

I grew Payda's mini-CRM today: every sale now records the tone (soft/hard) and method used. More importantly, we can now log customers who DIDN'T buy — 'tried this number from that account with a soft tone, declined'. So when the same picky customer is tried again from another account, their history shows. Also added one-tap task assignment to everyone. 142 automated checks green, live.

Mini-CRM · Tasks · Tests

Permission audit across all roles + 3 fixes

Today I audited Payda end-to-end through the eyes of all five roles (manager, partner, banker, worker, profit-share partner): each role tried to step outside its permissions and the system rejected every attempt. Along the way I found one hole — an unauthorized worker could delete team notes; closed it. I also removed a useless permission flag and narrowed the banker's default permissions to their actual job. The automated security suite grew from 104 to 131 checks, all green, deployed.

Permission Audit · Security · 131 Tests

The panel now runs on the new UI

The biggest piece of Phase 2 landed: the admin panel now runs on the new React UI — KPIs, period and currency switches, countdown-based upcoming payments, quick income/expense, the ledger and CSV. I verified it all with real flows in the emulator: added a sale, deleted it, paid the rent, watched an invalid entry get rejected. The evidence file and the audit gate are green; the live site still runs the old UI — the migration proceeds safely.

React · TypeScript · Emulator Testing

First screens of the new React UI are working

First concrete step of Phase 2: Payda's new React+TypeScript UI is up — sign-in, sign-up, password reset and the My Projects screen ported one-to-one. The best part: the new UI talks to the backend through a typed contract; I created the first project through that channel and verified it end-to-end in the emulator. The live site still runs the old UI; the migration will proceed screen by screen, with tests.

React · TypeScript · Typed Contracts

Phase 1 done: repo layout, CI and typed contracts

I put Payda on a major restructuring plan and finished the first phase: the project is now a real git repository with a root workspace, architecture/data-model docs and a GitHub Actions test gate. Old prototypes went to the archive, vulnerable packages were updated (no high-risk advisories left) and the 104 tests are still green. On top, I laid the first stone of Phase 2: the typed contracts that will be the shared language of frontend and backend. One Claude session, full transparency.

Git · CI/CD · Typed Contracts

Countdown for upcoming payments

Today I added one of those small things you'll check daily: fixed monthly payments now show with a countdown — 'rent, the 5th of each month, due in 4 days'. An Upcoming Payments card at the top of the panel sorts the nearest one first; anything due today turns red. Verified the math with a unit test and shipped it.

Countdown · Payments · Unit Tests

Payment approvals + backend split into modules

Today I added partial or one-shot payouts for partners paying workers/bankers; if there's a second partner, changes go to them for approval (four-eyes). Then I split the 800-line single-file backend into modules — lib/core + handlers/ (project, transaction, member, finance, tasks, sharing, scheduled) — behavior identical, all 104 tests still green. Removed the dead code too. Still one Claude session.

Cloud Functions · Modular Architecture · Tests

Mini-CRM, a task system and recurring-expense automation

Payda got a real mini-CRM today: search a number and you see whether that person is a customer, what they bought and WHO entered the sale, line by line — with customer notes. Alongside it came a real task system (managers assign, workers complete from 'My Tasks'), a scheduled function that posts fixed monthly expenses automatically, and a profit-share bug fix. Test suite 84/84 green, all in a single Claude session.

Mini-CRM · Task System · Scheduled Functions

Big pre-launch sweep: 10 gaps, 10 fixes

Today I combed through Payda as if launching tomorrow: period filters, CSV export, full reverse entries when deleting a sale, KVKK (Turkish data-protection) pages, an account panel, a PWA manifest and more — found 10 gaps and closed all 10 the same day. The security pass also caught and fixed CSV formula injection and a double-delete race; test suite 68/68 green. Still one Claude session, still build in public.

KVKK/GDPR · PWA · CSV Export · Security Audit

Customer records (mini-CRM) and modular permissions

Sales can now optionally include a customer number and product; search a number and you see who bought what and from which account. Customer data counts as personal data (PII), so only members with that permission can see it. Authorization is now fully modular: the role defines the screen, and every capability can be toggled one by one (a banker can do banking only — or ads too, if allowed). All 61 integration tests passed; backend and UI went live.

Cloud Functions · Firestore Rules · Security (PII) · Integration Tests

Three in one: design, security, SEO

Today I set three expert agents on Payda at once: the designer built an accessible, mobile-friendly design system with OKLCH tokens; the security expert tightened percentage fields and amount limits in an OWASP audit; the SEO agent added hreflang, a favicon and WebSite schema. In between, customer records (mini-CRM) and the fully modular permission system also went live — 61 security tests still green. All in one Claude session; I only steered.

Design System · OWASP Audit · SEO

Bot protection with reCAPTCHA

We added reCAPTCHA to Payda's sign-in and sign-up flows to protect against automated/bot abuse.

reCAPTCHA · Security

Role permissions and project management

We defined who can see and touch what: worker, partner and banker roles. Fixed the project create/delete flow with safe confirmations and applied the debugging and security-audit plan phase by phase.

Firebase · Roles/Permissions · Security

Bank-grade security and data isolation

We made sign-in, e-mail verification and password reset work, and wired every feature to a real backend. Most importantly, we built the architecture role-isolated — an employee cannot see or change anyone else's data — close to banking standards, with all writes server-side.

Firestore Rules · Firebase Auth · Security

The Payda journey begins

We set up Payda — a project management and accounting platform — on Firebase: database, authentication and hosting. Built the entire data layer from scratch.

Firebase · Firestore · Firebase Auth