# Simple MVP upgrade (Laravel 11)

This is a small add-on for the supplied Social Manager code pack. It deliberately avoids a heavy JavaScript frontend and paid analytics integrations. It adds:

- A simple workspace dashboard with post counts and upcoming posts.
- A monthly agenda view for scheduled/draft posts.
- Basic post-count analytics.
- Simple brand profiles to store tone, audience, notes and primary color.
- A lightweight approval queue with approve / request-changes actions.
- A small responsive Blade layout; no extra frontend package is required.

## Important assumptions

This add-on targets the multi-tenant schema in `schema_v2.sql`: `organizations`, `posts.organization_id`, `users.current_organization_id`, and Laravel authentication already exist. It is not a replacement for the original app and does not claim the platform publishers are already production-ready.

## Install

1. Back up the database and project.
2. Copy the contents of `mvp-upgrade/app`, `mvp-upgrade/database`, and `mvp-upgrade/resources` into the matching folders in your Laravel project.
3. Merge `mvp-upgrade/routes/web.php` into your existing `routes/web.php`; do not replace existing routes.
4. Confirm that `Post` is organization-scoped (or that all controller queries remain scoped by `organization_id`).
5. Run `php artisan migrate`.
6. Visit `/social-manager` after signing in.

## Role note

The approval controller expects `user()->role` to be `owner` or `admin` for approval actions. If roles are stored in `organization_user` instead, replace that small check with your existing workspace-role resolver. Do not rely on hiding buttons in Blade for authorization.

## Publishing safety

The approval status is kept separate from the existing publishing `status` to reduce risk to existing queue logic. Before enabling approvals in production, add a guard to the publishing dispatcher/job so posts with `approval_status = pending` or `rejected` cannot be published. Existing posts default to `approved` in the migration so current scheduled posts are not blocked.

## Brand profile note

This adds brand profiles as a place to store brand guidance. The existing AI prompt builder must be updated to load the selected brand profile before the saved guidance actually affects generated captions or media. That connection is intentionally left as a small follow-up, rather than silently changing every provider implementation.

## Analytics note

The analytics page currently reports reliable database counts only. Reach, impressions, clicks and engagement require each platform's insights API, the right permissions, and stored metrics; they are not fabricated by this page.

## Before production

- Verify tenant isolation, workspace roles, and route-model binding.
- Add automated tests for cross-organization access and approval permissions.
- Confirm the publisher refuses pending/rejected posts.
- Add a way to attach a brand profile to a post and pass its notes into the AI prompt builder.
- Check migrations against the actual database; the supplied SQL pack and your existing app may differ.

## Add a “Submit for approval” action

In the existing post list or post detail Blade view, show this form to editors for draft posts:

```blade
<form method="post" action="{{ route('sm.posts.submit-approval', $post) }}">
    @csrf
    <button class="btn" type="submit">Submit for approval</button>
</form>
```

Do not display it for posts already publishing or published. Server-side checks are already included.

## Apply the publishing guard

Follow `patches/DispatchDuePosts-approval-guard.txt`. This is required before using the approval workflow, because an approval screen alone does not stop a publishing queue from dispatching posts.


## Per-business AI provider API keys

For the multi-business setup, use `INSTALL_API_SETTINGS.md` to add the workspace-level AI provider settings page. Each organization owner/admin enters and manages their own AI keys in the database; do not put customer keys in `.env`. Platform OAuth app credentials are different: they usually identify the Social Manager application, while each business authorizes its own social account.
