Working together
Who a person is#
A person in Qivo is a name and an email address. Nothing else — there is no job title to keep current, because a title nobody could edit after the seat was created only ever described the day it was made.
The name, though, is now yours to change, and that is a recent thing: it used to have exactly the problem the job title had. Whoever created your seat typed it, and it stood for ever — a nickname, the stem of an address, a misspelling, a surname you have since stopped using. On Settings › Your preferences, Picture sits to the left of the Your name field. Type a name and press Save to be called that everywhere the app draws you, including the letters your avatar falls back to when there is no picture.
It follows you, not the seat: if you hold a place in more than one organization — your own and a customer's who shared a project with you — all of them are renamed together, and so is an invitation still waiting on your address that you have not signed in to yet. One name, because a name that differed between two of your seats would not be a name. Each organization records that the change happened and what it was before.
An org admin can also rename anyone in their organization, by typing over the name on Settings › Organization › Users. That door reaches one thing the other cannot: an agent has no login, so it can never rename itself, and before admins could do it the name an agent was created with was permanent for everybody.
The two are not quite the same act, and the difference is deliberate. Renaming yourself renames you everywhere you hold a seat. An admin renaming you changes their organization's copy — their authority stops at their own organization, so a seat you hold somewhere else is not theirs to touch. If the two ever disagree, changing your own name again settles it everywhere.
One last edge: a seat you are invited to after renaming yourself starts from whatever the person inviting you types. Your name follows you forward from the moment you change it, not backwards into invitations that have not been written yet.
The address does two jobs, and it is required for a person — a seat is claimed by matching a login against exactly that address, so a person without one holds a seat nobody could ever sign in to.
The first job, then, is that it is what someone signs in with: an admin adds a person on Settings › Organization › Users by name and address — that first name is the admin's to type and the person's to change afterwards — and the seat reads invited until that person signs in against it. Until then the address can be corrected; afterwards it is shown read-only, because from that moment it is the address their login is tied to. (An agent is the exception that proves the rule: it has no address at all, because its login is a key rather than a mailbox. See Agents below.)
It is also where their picture comes from. An avatar resolves in three steps, and the first one that answers wins:
- A picture you uploaded. Click any avatar you are allowed to change — your own under Settings › Your account › Picture, or, if you are an organization admin, anyone's from a row of the Users list. Hovering veils the picture with a camera glyph to show it can be pressed, and pressing it opens a short menu: it names which of the three steps below you are currently looking at, offers Upload a picture… (or Change picture… if there already is one), and offers Remove picture only when there is an upload to remove. Pictures are scaled down and re-encoded in your browser before they are stored, because an avatar appears on nearly every screen. Remove picture puts you back to step 2.
An uploaded picture is private to your organization. It is stored behind the same rule as the person it belongs to: your colleagues can see it, so can a guest you have invited into the organization, and nobody else — not another customer of Qivo. Downloads use short-lived signed links, and the server checks the requesting account's access when issuing them and when serving the image. The app keeps a prepared decoded copy in memory for use across views. An authenticated browser may also retain uploaded portrait bytes in a local cache scoped to this backend deployment and account; on a reload, portraits present in the current authorized roster can be restored before the workspace paints. The cache belongs to this browser/device, stores bytes rather than signed links, and does not replace the server copy used by other devices. Renewing access keeps the same picture visible; replacing or removing the upload, or an access refusal, clears its local entry. If browser storage is unavailable, portraits continue with normal progressive loading. The public demo does not keep this persistent portrait cache. These temporary links should still be treated as private.
- Gravatar. A free service that serves a picture for an email address. If you have set one there for the address on your seat, it appears here with nothing to configure. Qivo never sends the address itself — only a one-way hash of it. (A Gravatar is public by nature: you put it on that service yourself, and anyone who knows the address can see it. That is the trade for needing no upload — and the switch below turns it off.)
- Your initials, on your profile colour, when no picture is available.
Pictures and fallback initials share a square portrait with rounded corners. Regular portraits are 28px; prominent identities use 40px. Existing full names stay in place, and no extra initials are added beside portraits. When no picture is available, the initials inside the portrait use the first letters of the first two name words. Portrait hover text shows the full name; editable picture controls are also labeled with the change-picture action.
If you would rather your organization asked nobody about its people, turn off Settings › Organization › General › "Profile pictures from Gravatar". It is on by default. With it off, no address hash leaves your browser, step 2 disappears for everyone, and uploaded pictures are unaffected.
- Everything is live. Any teammate's change — tasks, comments, drags, settings, membership — appears in your browser within a moment. Your own edits apply instantly and, if the server refuses, roll back visibly with a toast ("You don't have permission for that — reverted") — the UI never pretends a write succeeded.
- Activity is narrated on the task itself — the Activity section of the task window, oldest at the top and newest at the bottom, like the comments it shares a spine with. Every entry names the actor — an agent signs its own API writes under its own name, and "Someone" is what stands in for departed members. Field edits name both the old and the new value ("reprioritized … from Medium to High"); API updates carry the same from → to diff ahead of their provenance label (description edits quote a short excerpt of the old text and the new). What tells you something happened is your Inbox (below) — one row per task, with read state that follows you across devices. (There used to be a notifications bell in the top bar as well; it counted the same events with a worse memory, so it went.)
- Provenance-honest activity: every automated task write is labeled in the activity feed — the agent's own name plus "via the REST API (key name)", or the user's own name "via MCP" — so you can tell human edits from automation, and which automation. (Comments are the deliberate exception on both tiers: a comment is its own feed entry — REST comments post signed by the agent that posted them, MCP comments by whoever the credential is.)
Appearance preferences: themes and the Canvas background#
In Settings → Your preferences → Appearance, use UI theme to choose Blue, Dark or Light. Each choice is a miniature workspace preview; click anywhere on its card to select it. An outlined card and checkmark identify the selected theme. The three cards sit side by side at every width, including phones, with visible keyboard focus and arrow-key selection. Blue is the default. Your choices save automatically to your account, apply to your planner and settings, and follow you across organizations and devices.
Below the theme cards, Canvas chooses the background image behind your workspace. It is separate from the theme: the selected image appears behind Blue, Dark and Light alike, and changing the theme keeps your Canvas choice.
- Image of the week: the background selected for this Monday–Sunday week in UTC. This is the default; the planner checks for the new week's image automatically at Monday 00:00 UTC, or when you return to a sleeping tab. No page reload is needed. Weeks without an assigned image use the configured default.
- Custom image: choose your own image to make the workspace feel like yours.
- No image: the workspace keeps the theme's solid background, and Qivo requests no background image.
Blue, Dark and Light share the same panel positions, spacing, rounded frames and navigation layout. Panels turn translucent only while a Canvas image is showing. Blue's Sidebar, Settings, Board and Roadmap panels then use an 81% dark blue tint and 10px blur to soften the background detail, and Blue adds a faint blue veil over the image. Dark and Light panels use the same 10px blur: Dark as an 83% graphite tint and Light as a 90% white frost. The image stays visible through the panel material and in the gaps between panels and lanes; Light's board task cards stay solid white. Otherwise, including with No image and while the image loads, Blue and Dark use solid panels framed against a darker workspace background, navy in Blue and graphite in Dark, with controls a shade lighter than the panel and menus lighter still, and Light uses white panels on a pale grey background with dark text. Roadmap's week header, task names and Team utilization names share their panel's background. Your choice also applies to task windows, filters and menus.
Roadmap project and sub-project heading rows use a solid background, keeping their names readable as tasks scroll behind them.
In Blue, while a Canvas image is showing, floating task and focus windows, dialogs and the startup card use the same 81% dark tint and 10px blur over the content beneath them, and menus, pickers, tooltips, editor popups, the search palette and the new-version notice use a slightly lighter 88% tint with the same blur, so they stand a step above the panels. With No image, and while the image loads, they are solid. Existing backdrop dimming and blur remain where present and stack when another window opens above them. The desktop Inbox task pane also uses the panel material, with a clear inner task surface so the tint is applied once. The sidebar Search box shares its navigation panel's background. Menus and pickers use subdued theme borders. Dark and Light keep solid floating surfaces, even while a Canvas image is showing.
Hover help across navigation, Board, Roadmap, task windows, settings and the operator area uses the same compact, rounded tooltip as Inbox, without a pointer triangle. Long explanations wrap within the screen. Keyboard focus shows help on focusable controls, and Escape dismisses it before closing an underlying menu or window. Disabled controls retain their hover explanations.
Desktop Board and Roadmap search fields use one continuous background across the icon, text and clear control, matching their nearby filter buttons. Focusing the text field keeps the same outer frame, without adding an inner border or glow.
Use Settings → Your preferences to change your appearance. While Image of the week is selected, in any theme, a preview of the week's image appears below the Canvas choices, in the same frame a custom image gets, and the current image's available Title, Location and Creator appear as plain text beneath it, in that order and each on its own row. Empty fields have no row; if all three are empty, no image-information block appears. The preview and details follow your selected image, so choosing a custom background shows your own preview instead of the weekly image's.
To add your own image, select Custom image, then Choose your image and pick a JPEG, PNG or static WebP file. Use a landscape image of at least 1600 × 800 pixels, with a ratio of 1.3:1–3:1, up to 32 megapixels and 8 MiB. Qivo checks the file and explains if it is unsuitable. An accepted upload shows a private preview and becomes your Canvas background without changing your theme; use Replace your image to change it or Remove custom image to return to Image of the week. Choosing Image of the week or No image keeps your uploaded file, ready when you select Custom image again. Qivo keeps your original image and creates a small, compressed WebP copy for previews. Admin library thumbnails, image pickers and preview windows also use these compressed copies.
After your session is authenticated, Qivo loads the original full-resolution background while the workspace loads and displays it directly once it decodes, including behind the Qivo loading card. It reuses the cached original when available. The compressed copy is requested for the workspace only if the original fails to load; settings and admin previews still use compressed copies. A week without an available calendar image uses the approved default background selected in Qivo Admin, if one is set. If no image is available, Qivo uses the solid fallback. Once the planner data and saved navigation preferences are ready, the workspace opens without waiting for the image; a slow image continues loading behind it. With No image, the workspace opens without waiting for an image. On later reloads, the saved theme color is restored before the app starts, so Blue and Light do not first flash the Dark theme. Once your account is confirmed, Qivo can show its last cached full-resolution background while checking your current settings. The browser can retain the selected image and preview for that account, including a custom upload, so unchanged images need not download again on each reload. Current settings replace or remove a stale cached selection. Signed download links are not saved in this cache. If browser storage is unavailable, images load normally; the public demo does not keep this persistent image cache. Images fill the workspace with a centered crop; crop controls are not yet available. Personal backgrounds stay within your account and are not displayed in Qivo Admin.
The selected project or wider scope is identified in the sidebar. On phones, the current scope appears above the workspace, with Inbox, My tasks, Projects and Sync in the bottom navigation.
On desktop in every theme, the settings screen uses two panels that fit their contents up to the available screen height. The navigation scrolls independently while Back stays visible. The panels stay side by side with aligned tops, centered together at the settings page's narrower width. Longer settings pages scroll inside the right panel, keeping its rounded top and bottom frame visible. On phones, your portrait opens a rounded settings menu with space above User account, and selecting a setting opens a full page with a Back button. Each settings section opens at the top when you navigate to it. On every settings page the settings sit in outlined boxes named on their border — Profile, Appearance, Inbox and MCP access on Your account — and a hairline with a name marks a further group inside a box; a project's archive and delete controls share a red-outlined Danger zone box.
Your Inbox#
Your Inbox is personal: it collects a message whenever
- someone @mentions you in a task description or comment, or
- a task you subscribe to changes — you get assigned, its reviewer, status, priority, title, dates, remaining hours, pause, project or parent change, it's archived or restored, or someone comments on it —
and never for your own actions.
Subscribing starts with the eye in the task window's top-right corner (§9). Its open or struck-through state shows whether you are subscribed. Clicking it opens a small Subscribers popup. Me stays at the top, with an eye button to subscribe or unsubscribe yourself. A divider separates that row from the other subscribers, listed alphabetically. Anyone who can open the task can see its subscribers, including viewers.
An organization admin or the project lead can also remove other subscribers with their × buttons and use + Add below the list to search for someone to subscribe. The picker includes active users and agents in the same organization who have access to the task. A subscriber who later loses access remains listed and can still be removed. This permission is independent of project access sharing. Other users can change only their own subscription.
Four things also subscribe you automatically: being assigned the task, being handed it, being @mentioned on it, and commenting on it. Creating a task does not — a lead who opens a project's worth of them in an afternoon would have signed up for every change anyone ever makes to any of them. Being taken off a task doesn't unsubscribe you either: losing it is news.
A task is handed to you when it becomes yours to act on (§2): it enters In Review with you as reviewer, you are made its reviewer while it is In Review, or it comes back to you as its assignee because it left Review or its reviewer was removed there. A reviewer handed a task reads Ready for your review, and a hand-off subscribes you again even if you had turned that task's messages off. A task with subtasks always belongs to its assignee, so it is never handed over. Being made reviewer of a task in any other status does not subscribe you; the reviewer shows only in the task window until the task reaches Review. Other subscribers read Reviewer set to or Reviewer removed when the reviewer changes.
An assignee buried in a busy task can turn their own messages off through Me, and someone following the task — a lead watching a risk, a teammate waiting on a fix — can turn them on.
The Inbox envelope carries the unread count on its corner, at the left of the top bar on desktop and in the bottom navigation on phones. It counts tasks with unread updates, not individual messages (see below), shows up to 99 and then 99+, and disappears at zero. The message list does not repeat this count. Once you click Enable notifications in the inbox, new messages also raise a desktop notification — clicking it brings you straight back. The optional Windows/Linux Electron desktop app delivers the same notifications through the operating system's desktop notification service; the desktop shell handles OS permission separately from the browser permission control.
On wide screens, the page is a split view with your messages on the left. The message panel fits a short list and stops growing at the available screen height; longer lists scroll inside its rounded frame while the filters stay visible. The empty or unavailable task pane has its own rounded background. On medium-width screens, the list sits above the task pane. On phones, Unread / Mentions / All sit above a single message list; Filter also contains ordering and browser-notification controls. Tap a message to open the full task, including its Details tab. Back to inbox returns to the queue at its previous scroll position. Each message has an actions button, so read/unread, snooze and removal actions are available by touch. The phone Inbox has no message search box; use the top header's global search to find tasks and projects. A desktop message query is ignored on phones.
A row says what and where: the task's title tops it with the age beside it (minutes/hours up to a day, then days), and the second line is a breadcrumb — project, then sub-project — so you can see which board the task sits on without opening it. What last happened isn't repeated here: the counter beside the title says how much has arrived, and the task's own Activity section says what it was. A sort picker sets newest/oldest order; a filter menu (unread only; show snoozed; mentions / comments / changes) narrows the list. Both menus use the shared Board menu style, including matching row spacing, rounded corners and selection highlights. On desktop, a search field also reaches everything a row is holding, including who changed what, as well as the project names now on the row. Selecting a message marks it read — and so does opening the task itself, so the badge and the task window can never tell you two different things.
One row per task, not per event. Everything that happens to a task joins the one row that task has in your inbox. It does not matter what kind of news it is — a comment counts exactly like a status change — and it does not matter whether you have read that row already: a task can never take up two places in the list. The row moves back to the top whenever something happens, and carries a small counter next to the title saying how much has arrived since you last looked. Open it and the task's Activity section, switched to All, enumerates the lot.
Reading a row settles it. The counter goes back to zero and the row keeps just its last message — so a task you have dealt with is one line, not a pile. Anything new after that starts the count again on the same row. Filters and desktop search still reach every message a row is holding, so a mention that landed behind a status change is never lost, and desktop notifications still fire per event.
Rows you have read don't stay for ever. On Settings › Your account Remove read messages lets you choose how long to keep them — After 1 day, After 7 days (the default for new users), 30 days, 90 days, or Never — and a nightly sweep takes the ones whose last message you read longer ago than that. Unread news is never removed, however old it is, and removing a row never touches the task or its comments. The setting's help puts the period's starting point and the reminder that tasks and comments are kept on separate lines.
The Inbox has two icon buttons: the double check marks all notifications as read, with the hover label Mark all as read; the list with an X clears notifications you have read, with the hover label Remove all read notifications. Both hover labels use the app's standard compact, rounded tooltip without a pointer triangle, with a small gap above the button. Both actions apply across Inbox filters, desktop search and your organization memberships, including notifications beyond the displayed list. The icon buttons use the same filled, bordered style as the board controls; in Blue, the Inbox controls share their panel's surface, translucent over a Canvas image, instead of adding a solid blue fill. The message search uses the same focus styling as the other filter fields. Removing read notifications preserves unread updates, including new updates on a task whose older notifications were read. Marking all as read keeps updates that arrive after the action starts unread. Each button is disabled when there is nothing to act on, and both disable while either action is running. Both actions leave tasks, comments and any open task draft intact.
Right-click a row for Open task in board (leaves the inbox and opens the task where it lives), Mark as read / unread, and Remove notification. The last two act on the whole row, every message it is holding. A separate section offers Mark all as read and Remove all read notifications, which apply to the entire Inbox. These two actions are also available when right-clicking the list background, including an empty filtered list. Both removal entries use the normal menu text color.
Snooze a row from the last section of the same menu, Snooze: an Hours row and a Days row, each with a minus and a plus around a number that starts at 1 and its own Snooze button. Set the number, then press the button on the row whose unit you mean; the other row's number is ignored, and hovering the button shows the exact return time, in the organization's date format with a 24-hour clock. Snoozing marks the row unread and hides it from the Inbox on every device you are signed in on, and the badge stops counting it. When the time is up the server brings it back, unread and at the top of the list, on every device at once, with a desktop notification if you enabled them. A new update on the task brings it back early. Show snoozed in the filter menu lists sleeping rows meanwhile, dimmed, with a clock and the return time in place of the age; opening one does not mark it read, and its menu offers Unsnooze, which brings it back now, unread. Mark all as read, Remove all read notifications and the retention sweep all leave snoozed rows alone.
The task pane holds the task window itself. Selecting a row fills it with the same window the Board and the Roadmap open — title, permanent ID and actions menu on top, then the description, the Activity thread and the comment box. So a message is not something you read and then go and act on somewhere else: reading it and working on the task are the same surface. The address bar names what the pane holds (/app/<org>/inbox/tasks/qn-14), so a reload — or a link you saved — lands you back on it. Esc clears the task first and leaves the inbox only on the second press.
Here the window shows its discussion only — the half of the screen it shares with your messages has no room for the details column beside it — led by a read-only line saying who the task is on (labelled Assignee, or Reviewer while the task waits In Review with one, §2), and then the description, which starts collapsed: press Description, or the arrow beside it, to open it and press again to close. Two things stand in for the column here. The breadcrumb over the task name links to each project or sub-project’s Board, as it does in floating task windows, and the "…" actions menu starts with Open task in board: it leaves the inbox and opens the task on its Board, the same jump as the row's right-click entry. And a pop-out button right beside the name opens the very same window floating over the inbox, with everything the pane left out: status, priority, assignee and reviewer (editable there), remaining hours, due date, plan, labels, attachments, parent, subtasks and links. It is the same task and the same conversation — reply in either — so closing it puts you straight back on the pane, and Esc closes the pop-out before it touches anything else.
Because the pane is the task window, news that arrives while you are looking at a task is marked read as it lands — you are watching it happen. News on any other task waits, bold, on its own row.
A New line says where you stopped reading. The part you hadn't read is separated from the part you had by a single New line, 2px thick — drawn before selecting the row marks anything read, so it stays put while you read instead of vanishing under you. It is the same read state the badge and the row dots use, so the two can't disagree; on your next visit there is nothing unread and no line. When the news is a change rather than a comment — nothing in the conversation to sit above — you get a short note saying so instead of a rule pointing at nothing.
Messages are generated server-side, so automation counts too: a REST script that reassigns a task you subscribe to messages you under the name of the agent whose key it used, and an MCP mention arrives as whoever sent it. What you'll never get is noise you can forge or lose — messages can't be created, edited or re-worded by any client, only marked read or unread, snoozed, or deleted, and nobody but you can see your inbox. A task's subscriber list is visible to everyone who can open that task; organization admins and the named project lead can manage that list as described above. This gives them no access to your inbox. Which row a message belongs to is the server's decision too, and not one anybody can argue with: a message belongs to its task, so gathering them is not a judgement call that could go the other way for one kind of news. While news is unread it is all there; once you have read it, the row keeps the last of it and lets the rest go — the task's own Activity keeps the rest.
✦ What sets this apart — Optimistic UI with honest rollback, an activity feed where automation is labeled as automation instead of hiding behind a bot user, and an inbox whose messages are generated by the database itself — so a change made by a script notifies you exactly like a change made by a colleague.