# Admin portal parity audit — 2026-07-27

Triggered by the user report: *"راجع كل الصفحة والتابات بتاعة الأدمن — شايف اختلافات كبيرة، يعني مثلاً في النوتيفيكيشن"*
and then *"لا مش هو هو خالص، حتى ده مش نقص العناصر"* (the difference is not merely missing
elements — the screens don't read as the same design).

## ⚠️ Read this before acting on the findings

These five files are a **source-level** audit (React `src/portals/admin/*.tsx` + `en.ts`
vs `backend/views/**` + `Yii::t`). They enumerate columns, labels, tabs and interactions.

They are **NOT a visual audit.** Nobody has seen the portal's admin screens rendered
side-by-side with the demo in this pass, because **the local admin password is unknown**
(rotated; `NavAdmin!2026` is stale — `tests/smoke/render-smoke-admin.sh` fails preflight,
and `backend/models/LoginForm.php` IP-locks after 5 bad attempts, so guessing is unsafe).

That gap is very likely the reason the user's complaint reads as "not the same at all"
while this audit reads as "a list of missing elements". **Do not fix admin screens from
this list alone** — get the password, screenshot demo vs portal per screen, and work from
the images. That is the AURORA_DEMO_PORTING_PLAYBOOK golden rule.

## Files

| File | Screens |
|---|---|
| `notif-marketing-invitations.md` | Notifications (triggers), Marketing, Invitations |
| `shops-subs-catalogue-geo.md` | Shops, Subscription Plans, Catalogue, Geography |
| `finance.md` | Admin Finance hub (Transfers · Invoices · Balances · Charges · Commercial Config) |
| `bookings-people-users-events.md` | Bookings, People, Users & Roles, Events |
| `home-dash-analytics-costs-settings-chat.md` | Home, Dashboard, P&L, Costs, Settings, Live chat |

## Highest-signal findings so far (source-level)

1. **Notifications — per-channel approval is per-trigger in the portal.** The demo approves
   SMS and WhatsApp templates independently (each channel chip owns its `approved`/`pending`
   state + inline Approve button). The portal has ONE `approval_status` for the whole trigger,
   so "WhatsApp pending while SMS approved" is unrepresentable. Schema-level gap.
2. **Notifications — no `event_basis`.** The demo's "Fires" select (6 options) drives the
   human description line ("When a booking is confirmed") shown under every trigger name and
   decides whether timing fields appear. The portal has only free-text `event_key`, which it
   then *displays raw in the table* — the demo never shows a key.
3. **Notifications — table shape differs**: demo 4 columns (Notification / Channels & template
   status / Shop config / Actions) vs portal 6 (adds Timing, Optional, Active as separate
   columns). Plus copy drift on title, subtitle, "Add trigger" → "New Trigger",
   "Shop notifications (free in-app)" → "(in-app)".
4. **Users & Roles — the whole "Roles & Access" matrix editor is missing** (portal shows static
   read-only role cards) while the subtitle still promises "configurable access matrix"; and no
   per-row role select / deactivate / add-user modal.
5. **Marketing — demo is one page with 3 working inline tabs** (Promotions / Ads / Push); the
   portal scatters these across separate controllers.
6. **Finance — drill-downs missing**: shop-balance breakdown waterfall (row click), invoice
   document view, settle-modal audit rows. Formatting drift on ids (`NTR-/INV-/CHG-` vs `TR-/#`)
   and dates (`18 May 2026` vs `18/05/2026`).
7. **Shops** — no avatar-initials tile; TYPE/VAT render as plain text instead of badges; no
   count on the "Shops" tab; no inline status toggle (a wired `actionToggleActive` is dead code).
8. **Events** is the closest port (title/subtitle/columns/time format/detail panel all match);
   gaps are the surface taxonomy (personas vs raw `application` values), missing shop filter,
   and pagination chrome.
9. **i18n bug found in passing**: `backend/views/user/people.php:144` hardcodes Arabic inside an
   English source string — `Yii::t('backend', 'Gender – الجنس')`. Violates the bilingual rule.

## Portal supersets (do NOT remove while fixing parity)

Bookings' extra columns + filters; People's freeze-list modal (NVG-BEA-005); reject-with-reason
+ owner email on shop requests; Events' CSV cap; Finance BEA-002/006/011 additions; shop `view.php`
detail page; pagination everywhere the demo has none.
