Roadmap
This is the actual build plan, kept in the open. Everything under “Available now” is in the product today and in use. Below it, the order is what we believe practices need next, with no delivery dates — a roadmap with quarters on it is a promise, and we would rather you trust the order than doubt the calendar. Further down, two sections most roadmaps leave out: what we are still deciding, and what we were asked for and refused.
Available now
Not a preview list. Everything here is shipped and in use by practices.
Website builder
Click-to-edit pages, themes, media library, SEO and a blog, on your own domain.
Online booking
Services, packages, memberships, gift certificates, waitlists and class reservations.
Client portal
Clients see their visits, documents, balances, packages and progress without calling you.
Intake forms & waivers
Built forms, signed waivers with the exact text frozen at signing, and form packets.
Calendar & bookings
Availability rules, time blocks, practitioners, locations and rescheduling.
Check-in station & lobby display
Arrivals, walk-ins, readiness checks and an ambient waiting-room screen.
Client records & clinical notes
Session notes that cannot be rewritten once signed, goals, documents and journey history.
Safety centre
Risk flags, incident reports and emergency protocol steps.
Invoicing & payments
Invoices, card and desk payments, coupons, gift certificates and account credit.
Double-entry bookkeeping
A real general ledger: balance sheet, P&L, cash flow, trial balance, journal and month close.
Bank reconciliation
Tick statement lines against the books; it will not let you close with a difference showing.
Automatic posting
Invoices and expenses post to the ledger, previewed before anything is written.
Insurance claim records
Policies, claims, service lines and remittances — the record layer, not yet the filing.
Email marketing
Campaigns, journeys, segments, deliverability monitoring, consent and compliance — complete.
CRM
Contacts, organisations, pipelines, deals, quotes, sequences and reporting.
Reviews & referrals
Review requests, a referral programme with payouts, and a partner portal.
Analytics & intelligence
Growth analytics, plain-English questions over your own data, and an AI practice coach.
Tenant isolation
Every record is scoped to your practice at the database level, not merely in the interface.
Tamper-evident audit trail
A hash-chained log of who accessed what, which detects an edited or deleted event.
Privacy requests
Server-side data export and erasure with a receipt that cannot be edited afterwards.
Accessibility
Skip links, visible focus, described images, and status never signalled by colour alone.
Building now
Both of these close a gap in something that already ships, which is why they come before anything new.
Memberships can be sold today but not automatically charged, which means chasing an expired card every month. This closes a gap in a feature that already exists, and collections post straight to the ledger.
Choosing and paying for an Attuniva plan from inside the product, with the plan granted by the payment rather than switched on by hand.
Next up
Ordered by how much daily difficulty each one removes, not by how interesting it is to build.
Google, Outlook and Apple calendars: outside commitments block your online availability, and Attuniva bookings appear on the calendar you already look at. The single largest day-to-day friction left.
Two-way messages between practitioner and client inside the portal, with the notification deliberately carrying no health information.
SMS through the same consent, suppression and frequency rules email already passes through, with quiet hours in the recipient’s own timezone and STOP honoured immediately.
Importers for Mindbody, Vagaro, Square, Calendly and Punchpass — but the import is the small half. What matters is that a switching practice does not have to reconstruct what every client is already owed: remaining package credits with their original expiry and restrictions, memberships with their plan, price and paid-through date, future bookings with their practitioner, room and payment status, and signed forms kept as evidence. Attendance history comes across where the export contains it, and where only a lifetime total exists we keep the total and say so rather than inventing visit dates. Financial history is imported as history, never as revenue, so the books do not count the same money twice. You approve a reconciliation report before go-live, and corrections afterwards preserve whatever has happened since — a re-import is never a silent rollback.
The part of switching that nobody warns you about: card details are not a spreadsheet column. Where the two processors support a token transfer we move the mandate; where they do not, each client reconnects a card once through secure hosted checkout, and you get a list of exactly who has and who has not before the first renewal runs. Old and new billing never overlap, and no password or raw card number is ever imported.
Planned
Real commitments without dates attached. If one of these is what decides whether Attuniva works for you, tell your practice administrator — what people are actually waiting on changes this order.
A declined card should be a short workflow, not a discovery three weeks later: the charge fails, the client is told, they get a secure update link, the retry follows a policy you set, and anything unrecovered sits in a queue with your grace period and exceptions visible. Separate from Attuniva collecting its own subscription from you — that is a different problem with a different owner, and solving one does not solve the other.
Freeze a membership for a month, resume it, schedule a cancellation, move someone up or down a plan while keeping the rate they joined on, and roll a limited number of unused sessions forward. Before anyone confirms, both of you see the same preview: what the next charge is, what access changes today, and what happens to remaining credits.
Memberships today carry one session allowance, which cannot express how practices actually sell: unlimited group classes plus two private sessions a month, or four bodywork visits plus one workshop credit with its own expiry. Each allowance is its own bucket, so booking a class can never quietly eat a private session — and the rules a client bought stay as they bought them, even after you edit the plan.
The embeddable widget shows your services and then hands the visitor to a hosted page in a new tab, which is where bookings are lost. This carries the whole journey inline — chosen service, availability, details, waiver, funding, payment, confirmation — with install instructions for the site builders practices actually use and a real test that it works, not a snippet that merely loads. Keep the website you like; connect the booking behind it.
One authoritative process instead of two half ones: a place opens, the next eligible person is offered it for a stated window, and if they let it lapse it moves on. The client can see where they stand, staff can override, one seat can never be promised to two people, and accepting an offer can never quietly take a payment nobody authorised.
Deposits already exist; the policy around them does not. Per-service rules with the exact wording the client agreed to frozen at booking, a late-cancel or no-show fee assessed automatically, and a queue where you can waive one and have that decision recorded and honoured by the payment side. “This fee is fair, and I am waiving it anyway” is a normal thing to want to do.
Rooms and resources are modelled but not yet enforced end to end. Two practitioners free and one suitable treatment room should be one bookable slot, not two — including the preparation and clean-down time between clients, on every channel that can book.
Installable to a phone home screen under your brand, opening on the next appointment, what benefits remain, which form is unfinished and the one useful next action. Deliberately before native apps: the question is whether a client can finish their usual task in under a minute on a phone, and installing an app should not be the price of booking.
A six-week course is not six calendar events. One enrolment, capacity held across the whole run, prerequisites, attendance, transfers and make-up rules — so a client signs up once and you can see who is actually completing it.
Milestones and streaks exist; the thresholds are ours rather than yours, and a migrated client with four hundred visits currently looks like they started yesterday. This makes the thresholds yours and keeps imported history with its provenance. Loyalty is a separate ledger on top: points for attendance, purchases or referrals, with visible rules and reversible entries. We will not reward Google reviews or route only happy clients to them — Google prohibits both, and the penalty lands on your listing, not ours.
Assembling claims from documented visits, matching remittances, and posting payments and contractual write-offs to the ledger.
Products, stock levels, front-desk checkout, and cost of goods posted to the ledger.
Clock in and out, PTO that blocks availability, and payroll posting to the ledger. Deliberately later: most practices of this size use a dedicated payroll provider, and a half-built payroll engine is a tax problem rather than a feature.
1099 and W-2 preparation from the ledger and payroll. Follows payroll, because it depends on it.
Video sessions bound to a booking, with a waiting room and consent-gated recording.
Standard measures administered on a schedule, with per-client trends and practice-level aggregates — and no trend drawn from a single data point.
Licence, insurance and continuing-education records, with escalating expiry alerts.
A content calendar that publishes to Instagram, Facebook and TikTok in your brand voice.
Hours and services kept in step, and reviews from Google and Yelp gathered in one place.
An employer buys sessions and their people redeem against an allocation, with employer reporting that never exposes individual clinical detail.
A workspace under your own brand and domain, with roll-up reporting across locations.
Subscribable events, signed deliveries with retries, and documentation for building against your own data.
iOS and Android for practitioners and clients, with push notifications that deliberately never contain health information. The web app is already usable on a phone, which is why this is not first.
Under consideration
Each of these is the right answer for a particular kind of practice and pure overhead for the rest, so what decides them is who actually turns up. If one of them describes your practice, say so — that is the evidence that moves it.
Choosing reformer 3, a specific bike or a mat position at the time of booking. Worth building the day a Pilates or cycling studio is a real customer, and a pointless configuration screen before then. Different from room scheduling above: that prevents conflicts, this lets a client choose within capacity that already exists.
For studios with several instructors: a request goes up, eligible staff offer or claim it, a manager approves, registered clients are told, and the class, the notifications and the pay record all change once. Two people cannot claim the same cover. Invisible to a solo practitioner, which is why it is here and not above.
A video block on a website is not a learning platform. Member-gated recordings, between-visit resources, class replays and paid courses with real access rules — a separate product decision rather than an extension of the site builder.
Import an attendance export, see which clients have quietly drifted, and judge whether the recommendations are any good — without touching your booking or payments. It also forces us to explain ourselves: “attended roughly fortnightly, last completed visit seven weeks ago” is something you can act on; a churn score out of a hundred is not.
Connecting the books to an external accounting package for practices whose accountant works there. The hard part is not the connection, it is declaring which system is the system of record so one transaction is never posted in both.
Reserve with Google is a partner programme and a different thing from keeping a Business Profile in step, which is already planned. Depends on eligibility we have not established and on whether practices actually want that channel.
Membership rules and reporting across sites, with access boundaries that hold between them. For multi-site groups and franchises; basic multi-location support is separately planned above.
Door access for facilities with unstaffed hours, split working and processing time inside one appointment, sibling and seasonal-program pricing, dated photo comparison, and workout programming. Each serves one kind of practice well. We would integrate the hardware, never build it, and none of them belong in every practitioner’s interface.
Straight answers
A roadmap that only lists arrivals is a wish list. These are the things we were asked for and either refused or cannot yet honestly deliver.
Some platforms run a consumer app where a visitor browses studios and books whoever is cheapest or nearest. That builds the platform’s relationship, not yours. Optional listings in other people’s directories are a reasonable thing to want, and different from us putting your practice in a shop window next to your competitors.
Drafting, suggesting and summarising are useful; a bot answering as you while you are with a client is a liability wearing your name. Anything that speaks outward stays opt-in, bounded to facts you published, and has an off switch that works immediately.
Membership autopay and the new booking-protection path both exist in the codebase and are listed above as still being built, because they have not been verified end to end. Counting them as done the moment the code compiles is how software gets sold on a promise. Nothing moves to “Available now” on this page for existing in a repository.
Eligibility checks and claim submission need a credentialed connection to a clearinghouse. We have built the records and the accounting, and deliberately not a “submit” button that validates a claim and then does nothing — because you would believe it was filed and find out at the filing deadline.
The storage region belongs to the hosting platform, so we have not built a region selector. A dropdown that changes nothing while implying a residency obligation is handled is worse than the gap itself.
We do not measure availability, so there is no honest number to print. We hold no SOC 2 or ISO certification and no platform-level BAA, because nobody outside has examined us yet. The trust centre says the same thing in more detail.
Login methods and second factors are handled by the hosting platform’s authentication settings. Re-implementing them over a session we do not issue would be theatre.