Project management, in depth
Planning and critical path, workload to the hour, finance and profitability — plus AI agents as first-class actors, under governance.
Planning, workload and finance in depth
One dataset, everywhere. Here is how the three pillars of project management work in Vaks-PM.
From backlog to critical path, with no re-entry
The same task lives in the Kanban, the Gantt and the workload. Dependencies feed a real CPM computation (forward + backward pass) that surfaces the critical path and every task's slack.
- ✓4 link types — FS / SS / FF / SF with lag, cycle detection.
- ✓Critical path in red, total slack and milestones computed server-side.
- ✓Real time — every move propagates instantly over WebSocket.
Timeline view — Portal revamp
CPMWorkload planned to the hour
Capacity is derived from real schedules, occupancy, time-off and holidays. The auto-plan spreads remaining effort across the horizon while honoring topological order, slack and each person's free capacity.
- ✓Assisted assignment — who, not just when: skill + real availability score.
- ✓Idempotent — re-planning yields the exact same plan (past is frozen).
- ✓Colour-coded — free / ok / tight / overloaded, drag-drop to reassign.
Team workload — week 24
auto-planProfitability, actual and forecast
Three-level rate resolution (project rate > user default > project default), EVM, burn, expenses, and a consolidated P&L per project then per client at portfolio level.
- ✓Actual vs forecast margin — labour + expenses + AI agent cost.
- ✓Invoicing — line-by-line export, external tickets included.
- ✓Per-client portfolio — revenue, cost and monthly series aggregated.
Project budget — Portal revamp
EVMAI agents as first-class actors
Not a chat gimmick: real identities that claim tasks, produce deliverables and go through review — under full governance, budget and audit.
Identity & human owner
Every agent has a dedicated identity, a mandatory human owner, restricted capabilities (RBAC ∩ scopes ∩ capabilities) and its own token.
Lifecycle & review
Atomic claim, versioned deliverables, human review (reviewer ≠ author), graded evidence verification, € budgets per agent, project and task.
Full traceability
Every agent action is logged actorType=AGENT with owner, natural-language justification and real run cost. Nothing escapes the audit.
Autonomy — but under control
An agent "pulls" an available task, claims it atomically, produces a versioned deliverable, then a human reviews it. The required evidence strength (self-attest, tool output, validator, signed CI, human) depends on the stakes and the agent's trust level.
- ✓€ budgets per agent, project and task — daily/monthly caps, blocked when exceeded.
- ✓Per-client model allowlist + a dedicated "AI administrator" role.
- ✓Usage-based billing — input/output cost per kToken, re-billable to the client.
Agent task lifecycle
serverZero shared secrets, RFC 8693
An agent already running on your Kubernetes cluster, Entra ID or GitHub Actions holds a native token. Vaks-PM exchanges it for a short-lived, scoped PAT — no secret to distribute, rotate or leak.
- ✓Pinned trust issuers — embedded JWKS, air-gap friendly.
- ✓Headless auto-auth — rotating refresh, token-theft detection.
- ✓Per-platform activation gates + a dedicated license.
Token exchange
RFC 8693A complete platform, no compromise
Planning, workload, finance and compliance in a single tool — deployed on your infrastructure. Let's look at it on your use cases.