The Capability Map

Everything Trakr ships.

One product: issue tracker, Support Desk, ITSM platform, agentic coding layer and MCP server. Grouped below, with a deep dive behind each group. Nothing here is an add-on, a plugin or a higher tier.

Projects

Projects & methodology

  • Three kinds of project — standard, Support Desk and service management — kept apart by a ticket scope so the three worlds never leak into each other's lists or searches
  • Six methodologies as a lens over one data model: none, Kanban, iterative, Scrum, waterfall and SAFe
  • Eight-step guided wizard: basics, workflow, components, labels, people, access, extras, review
  • Components with a lead who becomes the default assignee, and coloured labels
  • Per-area config override — take ticket types, priorities, incident flags, services or SLA over from the organisation, or revert to inheriting
  • Budget line items in mandays and price per manday, with an allocated summary
Routing

Assignment routing

  • Manual, round-robin or least-busy
  • Pools drawn from project members, a group, a skill or named users
  • Fallbacks to the default assignee, the project lead, or nobody
  • Availability-aware — people who are away on delegation are skipped rather than letting the redirect steal turns
  • Live preview naming every candidate, whether they are eligible, why not, their open-ticket count and who is next
  • Applies to every filing path: REST API, bulk create, inbound mail, MCP, automation, issue mirror, AI drafts and the customer portal
Context

Baseline project context

  • Six ingestion channels merged into one block used by every project-scoped AI feature
  • Free text, the bound repository, an external Git URL, an uploaded Markdown document, pasted text, or an AI-generated baseline
  • Known-file registry imports CLAUDE.md, AGENTS.md, .cursorrules, copilot-instructions.md, README.md and more, in order
  • Sources previewed as the merged block, edited, reordered, enabled and disabled, with duplicate detection and a live size meter
  • Bounded on purpose: 16,000 characters merged, 8,000 per source, 256 KB and 25 files per import
Tickets

Tickets

  • Sequential per-project keys that are never re-used, and retired keys kept forever so old links and email threads still resolve
  • Six link types with inverses — blocks, relates to, duplicates, is part of, is task of, causes — plus subtasks and a Mermaid dependency graph per ticket
  • Sparse decimal backlog ranking: a drop between two neighbours writes one row and never renumbers the rest
  • Move between projects with a preview: re-keyed, status remapped, SLA timers restarted under the target policy, attachments relocated
  • Attachment versioning with history and restore; inline preview limited to images, PDF and plain text — HTML, XML, JS and SVG are never previewed
  • Comments with threaded replies, internal notes that never reach the portal, @mentions, per-comment translate and canned responses
At Scale

Merge & bulk operations

  • Merging deletes nothing — the source keeps its row, key, history and portal visibility, resolved as a duplicate and linked to the survivor
  • Comments move or copy, and copy is forced for Support Desk sources so a customer's own words stay on the ticket they can see
  • Bulk update across every field, bulk transition with a comment, bulk link and a bulk-create grid
  • AI bulk edit: describe the change in words, review a diff-style preview of every affected ticket, then execute with an expiring token
  • AI duplicate detection proposes groups with a survivor, a reason and a confidence — and never merges anything itself
  • Preview then confirm on every destructive path, without exception
Templates

Ticket templates

  • Three scopes: personal, project and organisation
  • Auto-apply bindings to a ticket type and/or a request kind, resolved most-specific binding first, then most local scope
  • Pre-fill happens in the create dialog only — never through the API, MCP or automation
  • Never overwrites text you have already typed, and clears its own skeleton when the type changes
  • Carried between organisations by configuration bundles, matched by name
  • AI can draft whole templates for review
Planning

Boards & planning

  • Per-project board over workflow statuses, with drags pre-checked client-side and quick filters carrying counts
  • Portfolio board across every project, and a cross-project board grouped by status category because tickets arrive from different workflows
  • Two-zone backlog planner: open cycles above, backlog below, drag between them
  • Cycles as sprints, PIs, phases or iterations, with parent cycles for SAFe program increments and an estimate- or count-based burndown
  • Roadmap Gantt — epics, children and subtasks, draggable bars, dependency badges, cycle markers, per project or cross-project, TQL-filterable
  • Timeline of phases and program increments, and a calendar by created, resolved or due date
Search

TQL — Trakr Query Language

  • Fields across core, people, dates, collections, time, links, full text and SLA
  • History operators WAS, WAS NOT, CHANGED, CHANGED FROM and CHANGED TO, backed by the activity log
  • Signed relative dates (-7d, -1q, +3d), duration notation and twelve boundary functions from startOfDay() to endOfYear()
  • Validation returns the position of the error and suggests a field name — a clause is never silently dropped
  • The same bar on the ticket list, board, roadmap, calendar, Support Desk, Service Management, report generator and dashboard widgets
  • AI mode turns a plain-language question into TQL you can read and edit before it runs — it returns the query, never results
  • TQL deep dive
Workflow

Workflow engine

  • Statuses carry a category — to do, in progress, on hold, done, cancelled — a colour, a position and a final flag
  • Transitions from a named status or from any status, with JSON conditions
  • Conditions evaluate to a reason rather than a boolean, so a refusal can explain itself
  • An unreadable condition map lets the transition through rather than deadlocking the workflow
  • A refused board drag names both statuses and, for admins, links straight to the state diagram of the workflow that refused it
  • Automation rules are the extension point that would otherwise be post-functions
Support Desk

Service desk & portal

  • Agent queue over Support-Desk projects with the full TQL bar, column manager, grouping, bulk actions, import, export and pagination
  • Guest portal at /portal/{org} with no login: branded landing, project cards and an FAQ link library maintained at organisation and project level
  • Passwordless sign-in — email address, six-digit access code, session token, attempt-limited
  • Three-step submission with draft persistence across reloads, then my-tickets with filter chips and a conversation thread
  • Portal reporters and guests are not agents and are not counted as users
  • Switching the feature off hides the page and 404s every portal — and refuses while a project is still in Support Desk mode, naming them
  • Service desk deep dive
ITSM

ITSM & ITIL

  • Two organisation switches: ITSM adds problems, known errors and a services list; ITIL adds change control and per-ticket approvals
  • Everything is a ticket — service requests, incidents, problems and changes carry a request kind, not a separate record type, key format or permission model
  • Problems carry root cause, workaround and a known-error flag; raise one from an incident and both are linked
  • Changes carry type, risk, planned window, implementation plan, backout plan and outcome
  • Approvals are one named approver answering once, enforced by the workflow's approval condition
  • A flat services catalogue with owner and criticality, linked many-to-many and queryable from TQL
  • ITSM deep dive
SLA

SLA

  • Policies owned by a project or inherited from the organisation, with first-response and resolution targets per priority
  • Breach actions: escalate priority, reassign to a backup assignee, notify named accounts and free-text addresses
  • Pause conditions on status categories — parked minutes accumulate and push out only the pending deadlines
  • Business calendars with timezone, work hours, work days and holidays; an always-on 24×7 calendar is available
  • Every ticket records the policy it started under, because a deadline is a fact about what was promised
  • Editing a policy recomputes deadlines for still-open tickets and clears the pending breach flags
  • SLA deep dive
Automation

Automation & quality rules

  • One engine for flagging bad tickets and for doing work on a schedule, scoped platform, tenant, organisation or project
  • Triggers: hourly, daily or weekly schedules, five ticket events dispatched after commit, Run now, and a dry run that notifies nobody and records nothing
  • Selection by ticket scope and a TQL filter, capped per run
  • Twelve built-in checks, plus general field conditions across text, option, user, collection, date and number fields
  • Actions from set priority through transition, auto-assign, assign by skill, label, comment, link, create ticket and call webhook
  • A rule-authored write raises no rule; a workflow refusal is recorded as a failed action and never overruled; a fixed finding self-closes on the next clean run
  • Automation deep dive
Email

Email

  • Inbound from Microsoft 365 Graph, the Gmail API and IMAP, per mailbox and per project or organisation
  • Reply handling: always a new ticket, match by subject key (retired keys included) or match by thread
  • An auto-response detector skips out-of-office, bounces and list confirmations; a reply parser strips Outlook, Gmail, Apple and Thunderbird quote chains
  • Outbound over SMTP, Outboundly, Microsoft 365, Google or Zoho, resolved organisation → tenant → platform
  • 18 templates with scopes and audiences, subject and body resolving independently down the ladder
  • Templates are deliberately not Thymeleaf, so an admin-authored string can never reach SpEL
  • Integrations deep dive
Time

Time tracking & timesheets

  • Work logs are the only store: work date, description and a billable flag, in 30m / 2h / 1d notation
  • A per-ticket timer that survives a reload and opens the log-work dialog on stop
  • My Timesheet week or month grid where every day in the period is present, including the empty ones
  • Two day metrics side by side — days logged and FTE days — with period-over-period comparison
  • Team timesheets for one person or several, with org-boundary enforcement and log-on-behalf-of
  • Working-day policy resolved organisation → tenant → platform → built-in, per field, reporting which scope won
  • No timesheet approval workflow — approvals belong to change management
Reporting

Reports, statistics & dashboards

  • Report generator from a TQL query or an AI prompt, with breakdowns, a created-versus-closed trend and conversational refinement
  • Billing, budget, SLA, resolution metrics, time in status, team performance, ticket time and AI spend
  • Statistics backed by materialized views with a scheduled refresh, covering age distribution, overdue analysis and bottlenecks
  • Exactly five export formats — PDF, CSV, JSON, XML, XLSX — and an unknown format is refused, never substituted
  • Scheduled delivery carrying the figures in the mail body, and never calling AI on a scheduled run
  • Dashboards with tabs and 17 widget types, shareable as a layout snapshot always rendered with the viewer's own identity
  • Reporting deep dive
Signal

Notifications, activity & audit

  • Eight notification types with per-user email frequency — immediate, daily digest or off — and per-project overrides
  • Project watches as a standing subscription over future tickets, scoped to all tickets or to named components
  • Subscribers are the union of ticket watchers and project subscribers, deduped, excluding the actor, with access re-checked at notify time
  • Activity feed records field changes, comments, work, attachments, links, SLA breaches, and every email and notification sent
  • Audit log across authentication, authorisation, user and project management, system, data access, security and configuration
  • Forwarding to a SIEM over HTTP (JSON per event, HMAC-signed) or syslog RFC 5424, with per-sink filters and delivery health on the row
  • Security deep dive
AI

AI

  • Natural language to TQL, content generation, six suggestion modes, ticket and template generation, translation and report writing
  • Assistant chat with six intents, where every mutating intent returns a proposal you confirm with a single-use five-minute token
  • Cloud providers Anthropic, Gemini and OpenChat, plus fourteen self-hosted OpenAI-compatible runtimes including Ollama, vLLM, LM Studio and llama.cpp
  • Three logical tiers — cheap, standard, smart — mapped per organisation with a per-feature override
  • Rate limits, a per-organisation circuit breaker, a response cache and a pre-flight cost check that refuses a call which would breach the budget
  • Every call costed against an editable price book; self-hosted providers cost nothing, and an empty role allow-list turns AI off entirely
  • AI deep dive
MCP

Built-in MCP server

  • A Model Context Protocol server at /api/mcp, so Claude Desktop, Claude Code, Cursor and other hosts can drive Trakr directly
  • Four protocol versions, with capabilities for tools, resources, prompts and completions
  • Nine tools — search, read, create, update, transition, comment, log work, list projects, stats — all publishing input and output schemas
  • Resources for projects, stats, a full TQL reference and per-ticket comments and activity, with subscriptions pushed after a write commits
  • Five prompts: triage a ticket, file a bug, stand-up, project health and write TQL
  • Per-organisation API keys — the org scope comes from the key, never from a tool argument
  • MCP deep dive
Coding

Coding agent & Git

  • Providers: Trakr-hosted, Forgejo, Gitea, GitHub (including Enterprise), GitLab, Codeberg and Gogs
  • A JGit-backed git server over Trakr's own smart-HTTP endpoint, with browsing, diffs, a commit graph, releases and first-class internal pull requests
  • Agents: Claude Code, OpenCode, Mistral, Aider, Cline, OpenHands and Moon
  • A validation agent judges whether a ticket is ready, returning blocking issues, refined acceptance criteria, a complexity estimate and suggested files
  • A run creates the branch, clones, works under a hard timeout, verifies commits were actually made, pushes and opens a pull request — optionally auto-merging on green
  • The BLOCKED protocol pauses a run to ask a human, and resumes with the answer
  • Coding agent deep dive
Mirroring

Issue mirroring

  • Two-way sync with Forgejo, Gitea, GitHub, Codeberg, Gogs and GitLab
  • Directions inbound, outbound or both, with comments, labels and state each toggled independently
  • Labels map by name and are created on demand; mapping a remote label to an empty local name blocks it from crossing
  • Triggers: cursor-based polling, an HMAC-verified webhook, a manual sync, a full import backfill, and ticket events pushed after commit
  • Loop breaking on a hash over the local field set, so an echo is dropped rather than bounced back
  • One repository can be mirrored by several projects, each verifying its own webhook secret — a monorepo split cleanly
  • Integrations deep dive
Tenancy

Multi-tenancy & restructuring

  • Tenant → organisation → project → ticket, with a globally unique domain mapping to a tenant or an organisation
  • Superadmin context switching, plus an acting-organisation header that administers any organisation through the normal settings pages, with a banner
  • Per-organisation feature flags for to-do lists, timesheets, Support Desk, ITSM and ITIL, plus opt-in agentic coding and the internal git server
  • A drag-and-drop restructuring board with three operations — move to tenant, merge, split — and a dry run that writes nothing
  • Per-user decisions to move, stay or link; config matched by name is reused and everything else cloned
  • Project re-keying with a free-key suggestion, every retired key preserved, and the whole operation audited
  • Self-hosting deep dive
Identity

Identity, roles & SCIM

  • Local accounts, Azure AD / Entra ID, Google Workspace, LDAP / Active Directory and SCIM — several providers active at once, ordered on the login page
  • Seven roles from superadmin to customer, plus a staff-type axis of internal, contractor and customer
  • IdP group to role mapping with the highest rank winning, JIT provisioning, a default role and an email-domain allow-list
  • TOTP MFA with replay protection, recovery codes and a challenge token burned after five failed attempts
  • SCIM 2.0 with create, read, replace, patch and soft-delete on users, and read-only role-projected groups
  • A 12-character password policy with a HaveIBeenPwned k-anonymity breach check, revocable sessions, one-time-use refresh rotation and sign-in rate limits
  • Security deep dive
Migration

Import & configuration transfer

  • Ticket import from CSV, Jira XML and Jira CSV — the XML streamed with DTD and external entities disabled
  • Auto-detected CSV field mappings, 13 accepted date formats, and an external-key map so parents link correctly and re-runs behave
  • Job lifecycle: validate, map external users to Trakr users with suggestions, preview with row-level selection, execute
  • Configuration bundles across 12 sections — carrying group names but never members, webhook endpoints but never signing secrets
  • Import modes skip, replace and rename, matched by name case-insensitively, and nothing is ever deleted
  • Data cleanup previews a permanent deletion, then requires the token and a typed confirmation string
  • Leaving Atlassian Data Center
Deployment

Platform & deployment

  • Java 25 on Spring Boot 4, GraalVM native-image capable, with PostgreSQL as the only database
  • 120 Flyway migrations — the schema is versioned, not hand-managed
  • Server-rendered Thymeleaf and vanilla ES modules: no SPA framework, no build step between you and the page
  • Four deployment modes held in the database, not a properties file: all-in-one, frontend only, backend only, scheduler only
  • Scheduler leadership so background work runs exactly once across a cluster
  • AES-256-GCM field encryption on every stored secret
  • Self-hosting deep dive
Operations

Administration & operations

  • Cluster page with self-registration, heartbeats, a designated backup node, and health checks for coverage, version skew and CORS — each with a remedial action
  • First-run setup wizard: database connection, schema install, account, app settings, systemd service install
  • A superadmin configuration editor over an allow-list of properties, with masked secrets and a confirm-with-password save
  • Organisation and tenant backups streamed to a ZIP and emailed, with cron, retention and a scheduler
  • Software update over SFTP or an uploaded ZIP, with checksum verification and a migration copy step
  • Staggered application garbage collection, a live log viewer, and SSRF-guarded outbound webhooks checked at save time and at delivery time
  • Self-hosting deep dive
Languages

Internationalisation

  • 14 languages shipped: English, French, Dutch, German, Italian, Vietnamese, Spanish, Luxembourgish, Danish, Swedish, Polish, Portuguese, Czech and Romansh
  • Around 7,592 keys in the base bundle, with Romansh openly marked as substantially incomplete
  • Translation admin with a key browser, search, coverage statistics and a show-missing-only view
  • DeepL integration: single, batch and format-preserving translation, translate-all-missing per locale or across all locales, and quota reporting
  • Add a language, seed it from DeepL, sync only the missing keys and reload the cache — all without a restart
  • A per-locale JavaScript bundle served immutable, so client-side translation resolves synchronously
Whitelabel

Whitelabel branding

  • Resolved organisation → tenant → platform → built-in, per field, addressable by organisation, host, slug or tenant
  • A colour catalogue of 26 tokens in six groups — brand, chrome, surface, text, accent and status/priority
  • App name, logo with an IDOR-safe layout and cache-busting version counter, and a font family from an allow-list
  • Whitelabel text: copyright with a {year} placeholder, footer note, tagline, support, privacy and terms URLs — blank means the link is not rendered
  • Every value sanitised on read and write, hex-only colours and allow-listed font keys, so branding can never inject CSS
  • The same branding repaints all outbound email chrome, in nested-table HTML that survives Outlook and Gmail
Interface

Frontend & UX

  • Light, dark and system themes applied before first paint, following the OS live, with self-hosted webfonts only
  • Keyboard shortcuts: / to search, c to create, g-sequences to navigate, j and k to move, o to open, e to edit
  • One ticket-table engine on every list surface — column chooser, drag to reorder, drag to resize, click to sort, group by dragging a header, virtualised rendering, CSV export
  • Inline editing on double-click, including a move-to-project editor with a preview popover
  • A rich editor with AI assist and a draw.io-style diagram editor storing UML, BPMN and ERD inline, re-editable
  • Report drilldown: click any figure, row, cell or chart segment to open the tickets behind it
Docs

Help centre & API

  • A help centre at /help with category cards, a topic tree, client-side search and 60+ Markdown articles
  • Auto-built table of contents with scroll-spy, a was-this-helpful prompt, and contextual help links dropped into settings sections
  • Trakr's own API explorer at /api-docs rather than Swagger UI: operation tree, parameter and schema tables, try-it-out and a server selector
  • Authorise with a bearer token or your existing session token, saved or cleared
  • Code samples generated in eleven languages
  • 134 REST controllers behind springdoc-openapi, so the specification is generated rather than written
Identity

No SAML, no impersonation, no PATs

  • SAML is an accepted provider-type value in configuration but has no runtime handler. OIDC and LDAP do the work
  • No user impersonation — a superadmin acts on an organisation, never as a person
  • No personal access tokens. Machine credentials are MCP API keys and SCIM bearer tokens, and nothing else
  • Invitations are a stub: the endpoints exist and return placeholders
Process

No approval theatre

  • No CAB object, no quorum and no approval stages — a review board is modelled as an approval asked of several people
  • No timesheet approval workflow; the approval machinery belongs to change management
  • No composite productivity score in team reporting, on purpose
  • No permission schemes — access is roles plus project members plus group grants
Scope

No portfolio layer, no clone button

  • No portfolio or hierarchy planning layer — there is no Structure or BigPicture equivalent, and the roadmap does not pretend to be one
  • No project versions or fix-versions, and no project categories
  • No plain ticket clone; AI break-down covers the real use
  • Plan limits on users, projects and storage are stored and reported, not enforced in code
Is every capability on this page included in every tier?

Yes. Trakr is priced on your organisation's revenue, not on seats or on a feature matrix. SLA, SCIM, multi-tenancy, the Support Desk portal, email-to-ticket, AI, the MCP server and self-hosting are present at every tier. The only thing that changes with price is support response time.

Which capabilities are switched off by default?

Agentic coding and the internal git server are opt-in and off by default, and an organisation can only enable agentic coding after its tenant has. ITSM and ITIL are organisation switches that default off, and ITIL can only be on while ITSM is. To-do lists, timesheets and the Support Desk are organisation feature flags that default on.

Does Trakr need any external service to run?

No. Trakr runs on Java and PostgreSQL only, with Flyway-managed schema migrations. Webfonts are self-hosted, so there are no external font requests. AI is optional and can be pointed at a self-hosted OpenAI-compatible runtime such as Ollama, vLLM or LM Studio, in which case no prompt leaves your network and the recorded cost is zero.

How does TQL differ from JQL?

TQL covers the same ground — boolean logic, grouping, IS EMPTY, IN, ordering — and adds history operators (WAS, WAS NOT, CHANGED, CHANGED FROM, CHANGED TO), signed relative date math such as -7d, -1q and +3d, a full-text field backed by a GIN index, and live autocomplete on fields and values in one syntax.

Validation returns the position of the error and suggests a field name. A clause is never silently dropped.

Can Trakr be driven by an AI agent?

Two ways. A built-in Model Context Protocol server at /api/mcp exposes nine tools, five prompts and a set of resources to Claude Desktop, Claude Code, Cursor and other MCP hosts, authenticated by a per-organisation API key whose scope cannot be overridden by a tool argument.

Separately, the agentic coding layer hands a validated ticket to a coding agent — Claude Code, OpenCode, Mistral, Aider, Cline, OpenHands or Moon — which branches, works, pushes and opens a pull request, pausing to ask a human when it hits something it cannot decide.

What happens to a capability I switch off?

It disappears rather than greying out. Turning off the Support Desk hides the page, the portal (every portal URL 404s), the project-settings switch, the wizard option, the scope pickers and the keyboard shortcut — and the switch itself refuses to flip while a project is still in Support Desk mode, naming the projects concerned.

How much of this is actually built?

All of it, with the exceptions listed under "what Trakr deliberately does not do" and one more stated plainly there: invitations are a stub whose endpoints return placeholders. This page is generated from a feature inventory of the codebase — 2,346 Java files, 132 templates, 120 Flyway migrations and 134 REST controllers — not from a roadmap.

One product. One contract. One upgrade path.

Everything on this page is included at every tier, on your own infrastructure, for an unlimited number of users.