Why AgencyDesk
What makes it better
than the alternatives
- 01
Approval workflows with versioning
Clients approve or request changes; staff upload new versions until sign-off
- 02
Desk Assistant trained from Knowledge Hub
Answers client questions from uploaded documents, websites and custom Q&A entries
- 03
Read-only portal preview
Admins and project managers can view any client's portal to see exactly what they see
- 04
Multi-tenant with strict isolation
53 Feature tests enforce agency_id scoping, project visibility and role permissions
- 05
Template system
Project templates, invoice templates and editable email templates speed up recurring work
Projects & Tasks
- Project creation from templates with milestones and progress tracking
- Task board with four columns (todo
- doing
- review
- done) and client visibility toggle
- Status updates posted to client portal
- Team member assignment with role labels
- Project manager and account manager assignment
Approvals & Files
- Share deliverables for approval with due dates and custom messages
- Client decision: approve or request changes with optional comments
- New versions after change requests
- tracked with version numbers
- Pin comments to specific points on images (x/y coordinates)
- Reminders: manual
- 'Remind all' and daily scheduled job
- File uploads with version history and client visibility control
- Password-protected share links with expiry and download toggle
- 30-day soft delete trash
Invoices & Payments
- Invoice creation from templates with line items
- VAT and custom terms
- Milestone-linked invoices (auto-create on milestone completion)
- Record bank transfer
- cheque and cash payments (no live gateway)
- Payment reminders: before due
- on due date and overdue
- Invoice status: draft
- sent
- paid
- overdue
- void
- Duplicate invoices
- void sent invoices
- CSV export of all invoices
- Statement of account for clients
Messages
- Threaded conversations per client or project
- Attachments on messages
- Draft suggestions from project timeline and Knowledge Hub
- Read receipts and unread counts
- Notification preferences: instantly
- hourly digest or off
Desk Assistant & Knowledge Hub
- Train from uploaded documents (PDF
- DOCX
- TXT stored in storage/app/private)
- Train from website URLs (crawls pages
- stores content)
- Custom Q&A entries with keywords for matching
- Unanswered questions log for continuous improvement
- Hand-off to human when assistant cannot answer
- Test chat for admins
- Conversation history and CSV export
- Enable/disable per agency
- show/hide from clients
Team & Permissions
- Four roles: admin
- project_manager
- team_member
- accounts
- Permission matrix: 12 permissions (manage_projects
- manage_clients
- manage_invoices
- view_all_projects
- etc.)
- Email invitations with accept flow
- Project assignment (admins and project managers see all
- others see assigned only)
- Workload view: active projects
- waiting approvals
- unpaid invoices per member
- Session management: view active sessions
- revoke devices
Clients & Contacts
- Client company profiles with internal notes
- Multiple contacts per client (owner
- approver roles)
- Account manager assignment
- Statistics: total invoiced
- paid
- outstanding
- average days to pay
- Portal preview: admins/PMs sign in as client owner (read-only
- logged to activity)
- Client status: active
- inactive
Security & Authentication
- Two-step email verification (optional or required per role)
- Trust device cookie (30 days)
- Password reset with 30-minute token expiry
- Rate-limited sign-in (5 attempts per minute)
- Session timeout: 30 minutes
- 8 hours or 7 days
- Activity log: every create/update/delete with user
- client
- timestamp
- Share-link passwords (bcrypt hashed)
Settings & Branding
- Agency name
- logo and brand colour (6 presets)
- Custom portal domain
- Currency
- VAT rate and invoice number format
- Email templates: 8 editable templates (invitation
- password reset
- approval shared
- etc.)
- Notification switches: approval reminders
- payment reminders
- hand-over alerts
- Portal language: English only or English + Arabic
- Two-factor requirement toggles for team and clients separately
Reports & Dashboard
- Agency dashboard: active projects
- waiting approvals
- unpaid invoices
- recent activity
- Reports page: revenue
- invoices sent/paid
- approvals
- projects over 6 months or 12 months
- Global search: clients
- projects
- files
- invoices
- team (scoped by visibility)
- Notification centre with unread count
- Daily summary email (optional per user)
| Language | Version | Framework | Used for | Share of code |
|---|---|---|---|---|
| PHP | — | — | Web, API | 81.9% |
| SQL | — | — | Database | 9.6% |
| CSS | — | — | Styling | 4.3% |
| JavaScript | — | — | Front-end | 4% |
| Shell | — | — | Scripts | 0.1% |
- Primary language
- PHP 8.3+
- Framework
- Laravel 13.34.0
- Database
- MySQL 8.0+ or MariaDB 10.6+
- Authentication
- Session-based with two-step email verification, password reset, invitation tokens, optional 'trust device' cookie
- Licence
- Single-site
- Screens
- 42
- Database tables
- 23
- Supported languages
- English only (portal_languages setting mentions 'English and Arabic' or 'English only' but no RTL code in views)
- Browser support
- Modern browsers (ES6+, CSS Grid)
| Minimum | Recommended | |
|---|---|---|
| CPU | 2 vCPU | 2 vCPU |
| RAM | 2 GB RAM / 20 GB storage | 4 GB RAM / 40 GB storage |
| OS | Ubuntu 22.04+ or Debian 11+, PHP 8.3+, MySQL 8.0+ or MariaDB 10.6+, Composer 2.x | Ubuntu 22.04+ or Debian 11+, PHP 8.3+, MySQL 8.0+ or MariaDB 10.6+, Composer 2.x |
| Est. monthly hosting | $15 | $15 |
```bash cp .env.docker.example .env docker-compose up -d docker-compose exec app php artisan migrate --seed ```
```bash
sudo apt update && sudo apt install -y php8.3 php8.3-{cli,fpm,mysql,mbstring,xml,curl,zip,gd,bcmath} mysql-server nginx composer git
cd /var/www
git clone <repo> agencydesk && cd agencydesk/Laravel\ Project
composer install --no-dev --optimize-autoloader
cp .env.example .env
php artisan key:generate
# Edit .env: set APP_URL, DB_* and MAIL_*
php artisan migrate --seed --force
php artisan storage:link
php artisan config:cache && php artisan route:cache && php artisan view:cache
sudo chown -R www-data:www-data storage bootstrap/cache
# Configure nginx to serve public/ and run php artisan schedule:work in supervisor
``````bash # Upload Laravel Project folder contents to public_html/agencydesk # Move public/* to public_html and edit index.php paths cp .env.example .env php artisan key:generate # Edit .env via File Manager: set APP_URL, DB_* from cPanel MySQL php artisan migrate --seed --force php artisan storage:link php artisan config:cache # Add cron: php /home/user/public_html/agencydesk/artisan schedule:run ```
```bash cd Laravel\ Project cp .env.example .env composer install php artisan key:generate # Edit .env: set DB_DATABASE=agencydesk.sqlite, DB_CONNECTION=sqlite touch database/agencydesk.sqlite php artisan migrate --seed php artisan serve # Open http://localhost:8000 ```
Quality report
Manually reviewedHow to read the quality report
What this is. Every project on Vibe96 goes through an automated audit of its source code before a reviewer in Dubai checks it by hand. The score is out of 100; 75 is the minimum to be listed, and any single failing check blocks a listing regardless of the score.
- Security
- No real credentials in the code, every data-changing route protected, admin areas role-gated, no SQL built from user input.
- Code structure
- A developer can navigate and extend it: clear module boundaries, no giant files, little copy-paste.
- Docs & completeness
- The setup guide, example config, schema and required files the builder committed to are actually in the archive.
- Dependency health
- Packages pinned, no known critical vulnerabilities, no abandoned libraries in production paths.
- Build & deploy
- A clean machine can restore, build and start it by following the shipped instructions.
Warnings are problems that didn't block the listing; they stay visible here until a later version clears them. The audit reads the code — it does not run it — so always try the live demo before you buy. Lines of code are counted from the same audited archive.
What to know before you buy
2 non-blocking findings shown publicly: database access is safe; minor schema gaps (missing indexes on some foreign keys); strong authentication and role checks; minor ownership gaps on read-only endpoints; good separation of concerns with minor duplication and some oversized controllers; build reproducible with gaps: missing database setup steps and incomplete docker instructions. The seller has been notified; fixes ship in the next version.
Versions & updates
No updates yet. New versions appear here with a changelog.
Buyers receive updates free for 1 year.
What you get
- </>Full source codeThe complete audited source, delivered as a download from your account. No obfuscation.
- ▤DocumentationSetup guide, architecture notes, CLAUDE.md and AGENTS.md.
- ↻One year of updatesEvery new version the builder publishes, free for 12 months.
- ♧30 days of supportInstallation and defect support through Vibe96 tickets.