Documentation
SaaSTasks is pre-release. This page documents what the current build does. Anything not listed here is not implemented.
Getting started
- Install SaaSTasks (Windows installer when released). Git for Windows is needed for Git features.
- On first run choose Create demo workspace to explore safely, or + Add project and set its local folder.
- Add an AI source in Settings: install Ollama for free local models, or save an OpenAI / Anthropic key (stored in your OS credential store).
Your data lives in %APPDATA%\SaaSTasks, separate from the program. Uninstalling keeps it.
Projects, tasks and memory
Each project has tasks, a roadmap, activity, and memory: facts, rules, decisions and notes. Edits are versioned; decisions can be superseded and keep their chain. Rules bind the AI. AI may only suggest memory changes - they wait in the Memory inbox until you accept them.
Ctrl K opens search across all projects and a command line: “add task renew domain to NinjaTickets by Friday”, “continue NinjaSkies”, “what’s overdue?”. Commands that change data show what they will do and wait for your confirmation.
Files & Git
Browse and edit text files (not binaries, max 1 MB), see working/staged/untracked diffs, commit, and take snapshots. Rolling back or restoring first snapshots the current state, so it is reversible. SaaSTasks never runs repository hooks, never touches .git, and refuses paths or symlinks that leave the project.
AI and AI code changes
The assistant is given only the current project’s memory, Git status and the most relevant files; files that commonly hold credentials (.env, keys) are never sent, and file contents are treated as untrusted data. Replies stream, with token counts.
AI changes follow: request → inspect → isolated worktree → proposed change → diff → build/test → you approve or reject. Build and test commands are a single allow-listed program (npm, node, python, pytest, cargo, go, make…) with no shell operators, run only in the worktree. If a proposal edits build-defining files (package.json, Makefile…), checks are not run automatically. Approval is bound to the exact diff and refused if the repository moved. Approved changes can be reverted. Runs can be cancelled, and interrupted runs are cleaned up after a crash.
Website tools
Website: start the dev server (static, Vite, Next.js and other npm projects are detected), view it at desktop/tablet/mobile widths, read its output, or open it externally. Sites that forbid framing are detected. Inspector: serves the page through a local proxy on a separate origin with a read-only bridge; click an element to get its source file and line (exact for React/Next/Vue/Svelte dev builds, ranked guesses otherwise). Visual editor (GrapesJS): only for plain static HTML or SaaSTasks templates; framework output and templated files are refused. Each save shows a diff, backs up the file for undo, and takes a Git snapshot.
Data tools
SQLite, PostgreSQL, Supabase (Postgres), MySQL*, JSON, CSV and read-only REST sources. Reads are read-only at the connection level. Writes always go: preview → affected-row count and sample → automatic backup → explicit confirmation (destructive statements need a typed phrase). The AI can write a read-only query for you from a plain-English question and shows you the SQL it ran. *MySQL adapter is implemented but not yet tested against a live server.
Agents and automation
Ten roles (General, Developer, Designer, SEO, Research, Security, Analytics, Affiliate, Database, QA) share one framework: each can use only the tools its role is permitted, tool output is untrusted, runs are step-by-step and cancellable, and at most two run at once. Only the Developer role can propose code changes, and only for your approval.
Automations: trigger (every N minutes, daily/weekly at a time in your time zone, or an event such as deployment failed, build failed, site down, agent failed, task overdue) → condition → action (create task, alert, log, run an agent, run a plugin action, back up). Failures retry with exponential backoff and raise an alert; every run is recorded. Daylight-saving changes are handled.
Plugins
Bundled: GitHub, WordPress, Cloudflare, Supabase, Generic Site. A plugin declares the permissions it needs; you grant a subset per project. Plugins run in a separate process and reach the network and your credentials only through a broker that enforces those permissions and the hosts they declared. Actions that change things outside SaaSTasks ask for confirmation. User-installed plugins are labelled unverified and the isolation is defence-in-depth, not a security boundary - install only plugins you trust.
Backups and recovery
Automatic daily backups plus one before every restore, reset and update, checksummed and pruned by type. Export everything writes a single zip (secrets excluded, or AES-256 encrypted with your passphrase). If the database is ever found corrupt at startup, it is quarantined (never deleted) and the newest valid backup is restored, with an alert.
Security model
- The engine listens on
127.0.0.1only; requests need a per-session token, a matching Host and Origin (blocks cross-site and DNS-rebinding attacks). - The interface runs under a strict Content-Security-Policy with no inline scripts.
- API keys live in the OS credential store, are redacted from AI context, diagnostics and exports, and are excluded from the database and backups.
- Path traversal, symlink escapes,
.gitaccess, shell injection, SSRF from agents and plugins, prompt injection via file or web content, and destructive SQL are each blocked and covered by automated tests. - Updates are installed only if an Ed25519-signed manifest and the package checksum verify; failures roll back code and data.
Known limits: plugin isolation is not an OS sandbox; MySQL and the Windows installer are unverified; no third-party penetration test has been done.
Licence and updates
Paste your licence key in Settings → Licence, then activate the computer online (or paste an activation code for offline activation). Activation lasts 30 days and renews automatically; there is a 14-day offline grace period, and your data is never locked. To move computers, use Move licence to another computer. The licence has no project or site limits.
Troubleshooting
Settings → Create diagnostics file produces a report with counts, versions and recent errors, credentials redacted, for support. Settings → Report a problem saves feedback locally. Settings → Reset clears everything after taking a backup.