Vianordis
--:--:-- UTCVianordis / ED. 02 / 2026
§ 07 — App support

Taktis

Sovereign time, approval, and billing intelligence for professional services.

Taktis helps professional-services teams capture billable work, approve timesheets, manage project budgets, generate invoices, produce reports, and keep customer-ready evidence in one tenant-aware platform.

01Problem

Billable work leaks when time, approval, and invoicing are split apart.

Professional-services teams need accurate time records, fast approval cycles, defensible client evidence, and clean invoices. When these steps live in disconnected spreadsheets, generic trackers, and manual email threads, billing slows down and managers lose visibility into utilization and project profitability.

  • Billable hours are entered late, forgotten, or attributed to the wrong customer or project
  • Timesheet approvals require manual chasing across managers, finance, and customer stakeholders
  • Project budgets and actual hours are reviewed after overruns have already happened
  • Invoices are assembled manually from approved work records and custom spreadsheets
  • Audit evidence for approvals, signatures, exports, and changes is hard to reconstruct
  • Workforce and customer billing data sits in tools that may not match European sovereignty requirements
02Solution

Taktis connects time capture directly to approval, reporting, and billing.

Taktis is a European-sovereign time and billing platform for consultancies, IT service providers, engineering firms, agencies, shared-services teams, and regulated organizations. It gives each tenant a structured model for customers, projects, activities, employees, entries, approvals, invoices, reports, and integrations.

  • Capture manual entries, live timers, imported entries, and AI-assisted entry origins against customer, project, activity, rate, and billable status.
  • Move timesheets through explicit workflow states from draft and submission to operator approval, auditor approval, customer signature, and lock.
  • Generate invoices and PDFs from governed records instead of rebuilding billable work by hand.
  • Expose reporting, exports, REST APIs, webhooks, and MCP tools so time data can support operations and automation.
03Benefits

Business outcomes Taktis is designed to improve

Taktis turns time tracking from an administrative afterthought into an operational record that supports utilization, revenue, approvals, billing, and compliance evidence.

Recover more billable work

Give teams fast daily entry, timers, clear project attribution, activity categories, and billable/non-billable classification.

Shorten approval cycles

Route timesheets through structured states with approval history, comments, rejection reasons, and customer-signature readiness.

Invoice from trusted records

Create invoices, line items, PDFs, sent/paid status, payment references, and signed records from approved work data.

Improve utilization visibility

Use dashboards and reports to understand billable time, project hours, billing totals, and employee or team workload.

Support sovereign operations

Run on European-controlled infrastructure patterns with Keycloak identity, tenant-aware APIs, Kubernetes deployment, and controlled secrets.

Automate through APIs and AI tools

Connect external workflows through REST endpoints, webhooks, exports, chat APIs, and a dedicated MCP server for time and timesheet operations.

04How it works

How Taktis works

  1. 01

    Model customers, projects, and work categories

    Create customers, projects, activities, employees, rates, budgets, billing modes, currencies, and tenant settings that match how the organization sells and delivers work.

  2. 02

    Capture and submit governed time

    Users enter time manually, start and stop timers, import entries, attach descriptions and tags, then submit timesheets for the configured review path.

  3. 03

    Approve, bill, report, and prove

    Managers and finance reviewers approve or reject work, invoices are generated from approved records, reports are exported, and signing/audit evidence is retained where configured.

05Features

Core Taktis capabilities

Customers and projects

Manage customer records, billing contacts, currencies, project codes, project status, budgets, team membership, tags, custom fields, and billable settings.

Activities and rates

Define activity categories, billable defaults, hourly-rate multipliers, icons, colors, and project-specific work types.

Time entries and timers

Create, edit, import, list, start, stop, and monitor time records with duration, date, description, billable status, billing amount, tags, and origin tracking.

Timesheet workflow

Support weekly, bi-weekly, or monthly timesheets with draft, submitted, operator-approved, auditor-approved, customer-signature, signed, and locked states.

Approval operations

List pending approvals, view approval stats, approve, reject, and retain state transitions with comments and responsible users.

Invoice lifecycle

Create invoices and line items, mark invoices sent or paid, track references, generate PDFs, and request signing where signing certificates are configured.

Reports and exports

Produce utilization, billing, and project-hours reports, plus export data for downstream analysis and operational review.

Employee and tenant settings

Maintain employees, default rates, weekly hours, working days, manager relationships, invoice numbering, approval requirements, and integration toggles.

Integrations and webhooks

Connect CRM accounts and opportunities, Zelibri employee data, Admin provisioning, and n8n-style workflow callbacks.

AI and MCP access

Expose MCP tools for listing and creating time entries, controlling timers, listing projects and customers, viewing current timesheets, and submitting timesheets.

06Architecture

Architecture and security model

Taktis is built as a Kubernetes-hosted application with a Next.js UI, Go API, PostgreSQL-backed domain model, Keycloak identity, tenant resolution through the core platform, and a separate HTTPS MCP server for AI-assisted workflows.

  • Next.js application for dashboard, customers, projects, time entries, timesheets, approvals, invoices, reports, login, chat, and health endpoints.
  • Go Fiber API with request IDs, recovery, structured logging, strict CORS origin requirements, Keycloak authentication, tenant middleware, and role-based access checks.
  • PostgreSQL schema for customers, projects, activities, time entries, timesheets, invoices, employees, approvals, settings, signatures, audit-related records, and webhook protection.
  • Keycloak/OIDC authentication with tenant code to UUID resolution through the shared core database.
  • HTTPS MCP server with Bearer-token validation and optional mTLS service-auth path for trusted integrations.
  • Kubernetes deployment for API, UI, and MCP services in the Taktis namespace, with secrets sourced outside git and ingress routing for user and MCP traffic.
  • PDF signing path backed by configured signing certificate material, with endpoints returning unavailable status when signing keys are not provisioned.
07Use cases

Where Taktis fits

Professional services billing

Capture work against clients and projects, approve timesheets, and generate invoices from trusted activity records.

IT service providers

Track customer delivery, support work, billable incidents, internal work, project budgets, and recurring reporting.

Engineering, architecture, and consulting teams

Attribute hours to projects and activities, monitor utilization, and retain defensible approval evidence for client-facing work.

Shared services and internal cost allocation

Allocate time across internal departments, cost centers, projects, and work categories without relying on external PSA suites.

Regulated or audited organizations

Keep approval history, signing status, PDFs, exports, role controls, and tenant-aware records for audit and compliance review.

AI-assisted employee workflows

Allow authorized assistants or internal agents to create entries, control timers, inspect projects, and submit timesheets through MCP.

08Integrations

Integrations and ecosystem connections

Taktis is API-first and designed to connect with identity, CRM, HR, workflow automation, signing, and platform operations inside the GSC ecosystem.

Keycloak OIDC and enterprise SSO

Keeps access tied to organization accounts, roles, and sign-in policy.

LDAP or Active Directory through Keycloak federation

Keeps access tied to organization accounts, roles, and sign-in policy.

GSC CRM customer and opportunity synchronization

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Zelibri employee synchronization

Shows how this service fits into the wider Vianordis environment instead of standing alone.

GSC Admin tenant provisioning

Shows how this service fits into the wider Vianordis environment instead of standing alone.

n8n workflow callbacks

Makes actions reviewable before work is executed or escalated.

REST API endpoints

Lets approved systems connect without ad hoc exports or manual copy-paste.

MCP over HTTPS

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Optional mTLS service authentication for MCP

Shows how this service fits into the wider Vianordis environment instead of standing alone.

CSV and report exports

Shows how this service fits into the wider Vianordis environment instead of standing alone.

PDF generation and signing endpoints

Shows how this service fits into the wider Vianordis environment instead of standing alone.

EJBCA-backed certificate material where provisioned

Shows how this service fits into the wider Vianordis environment instead of standing alone.

PostgreSQL

Stores structured service records in a controlled tenant-aware backend.

Kubernetes and ingress routing

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Infisical-managed runtime secrets

Shows how this service fits into the wider Vianordis environment instead of standing alone.

09Trust

Trust, control, and evidence

Taktis handles sensitive workforce, customer, billing, and utilization data. Its product model emphasizes tenant scoping, explicit approvals, role checks, signing support, and operational evidence.

Identity

Keycloak/OIDC authentication with tenant-aware middleware

Roles

Operator, auditor, and admin checks on sensitive API operations

Tenant context

Tenant code to UUID resolution through the shared core platform

Approvals

Submitted, approved, rejected, signature-pending, signed, and locked workflow states

Signing

Invoice and timesheet PDF signing paths when certificate material is configured

Public signing

Token-authenticated public signing endpoints with rate limiting

Webhook safety

Replay-protection migration and rate-limited webhook callback routes

API control

Strict CORS origin requirement, request IDs, recovery middleware, and health checks

MCP security

Bearer-token validation with optional mTLS service authentication

Secrets

Runtime secrets kept out of git and sourced through deployment-time secret management

10 — Pricing

Scope Taktis by team size, workflow depth, and deployment needs

Taktis pricing is best aligned to user volume, number of tenants or legal entities, reporting and integration scope, signing requirements, deployment model, and support expectations.

11FAQ

Questions technical buyers usually ask.

Who is Taktis for?

Taktis is for professional-services firms, IT service providers, consulting teams, shared-services organizations, and regulated teams that need governed time capture, approvals, billing, and reporting.

What can users track?

Users can track time against customers, projects, activities, dates, durations, notes, billable status, rates, tags, custom metadata, and timesheet periods.

Does Taktis support timers?

Yes. The API and MCP surface include running-timer status, timer start, and timer stop operations in addition to manual and imported time entries.

How do approvals work?

Timesheets move through explicit workflow states including draft, submitted, operator approved, auditor approved, customer signature pending, customer signed, and locked. Approval endpoints support review, approval, and rejection.

Can Taktis generate invoices?

Yes. Taktis models invoices, invoice line items, sent and paid states, payment references, PDF output, and signing requests when signing is configured.

Does Taktis support customer signatures?

The backend includes public token-authenticated and in-app signing endpoints plus signed PDF generation. Some UI signing surfaces and SMTP invitation automation are identified as follow-up work, so rollout scope should confirm which signing flow is enabled.

What reports are available?

The API exposes utilization, billing, project-hours, dashboard metrics, and export endpoints. The UI includes dashboard and reporting surfaces.

Can Taktis integrate with CRM and HR systems?

Yes. The app includes integration hooks for GSC CRM customers and opportunities, Zelibri employees, Admin provisioning, webhooks, and REST/API export paths.

How does the AI/MCP interface work?

Taktis includes an HTTPS MCP server with tools for listing customers and projects, listing or creating time entries, controlling timers, getting current timesheets, and submitting timesheets.

Can Taktis be deployed in a dedicated environment?

Yes. The inspected deployment model uses Kubernetes services for UI, API, and MCP components, with secrets supplied at deployment time and identity through Keycloak.

12 — Next step

Turn billable time into approved revenue faster.

Use Taktis to capture work accurately, route approvals, generate invoices, report utilization, and retain the evidence your clients and auditors need.