Account: ERP-AI-Chatbot
Enter 6-digit code from Google Authenticator

Query Logs

IRIS Ecosystem

v1.0 · 2026-07-30

**IRIS** — *Intec Responsive Information System* — is INTEC Engineering's internal software family. It is a manufacturing ERP (`intec-erp-v2`) that owns the database and all business logic, paired with a natural-language chatbot backend (`intec-erp-chatbot`, internally called "IRIS") that reads the same database and answers questions in English or Bahasa Malaysia using a hybrid regex + local vLLM (`iris-v3` / Qwen2.5-14B-Instruct-AWQ) intent engine. Three near-identical client apps — web, Android mobile, and Windows desktop — talk to the chatbot over HTTP so shop-floor and office workers can query work orders, inventory, invoices, BOMs, production, and more conversationally. The ERP is the senior project and the sole schema owner; the chatbot and its clients depend on it, never the other way around.

Audience: a developer who just joined the team and needs to understand the whole family in 10 minutes. This page synthesizes the per-project .cursor/guide/ docs; for any fact beyond what is here, trust those guides — they are the authoritative source this overview synthesizes.

Architecture at a glance

Client Applications (HTTP)
Chatbot Web
React 19 · :3001
Chatbot Mobile
Expo / RN (APK)
Chatbot Desktop
Electron + React 19
↓ POST /api/v1/chatbot/* · client: web | mobile | desktop
Backends
IRIS Chatbot API · intec-erp-chatbot :8001
Laravel 8 / PHP 8 · hybrid regex + vLLM intent engine
 
vLLM
:8002 · 4× Qwen2.5-14B AWQ
↓ read business data via symlinked Eloquent models · shared MySQL, NOT HTTP · writes only chatbot_query_logs
Shared Data Layer & ERP
MySQL · intec_erp
single shared schema
ERP API + Web · intec-erp-v2 :8000
Laravel 5.8 · owns schema · full read/write · 282 models

Key invariants: the ERP is the sole schema owner (never migrate from the chatbot); the chatbot never duplicates ERP business logic — it reuses the same Eloquent models via the symlink; the chatbot inherits ERP's model boot logic, global scopes, and observers; the ERP does not call the chatbot — if the chatbot is down, the ERP keeps running.

Latest Updates

17 entries · 2026-07-30 → 2026-08-03

Consolidated retrospective across the four IRIS chatbot-family repos (intec-erp-chatbot, erp-ai-chatbot-web, erp-ai-chatbot-mobile, erp-ai-chatbot-desktop). Newest first.

2026-08-03
Ollama update + systemd tuning / LLM model research (infra — not in these repos)
Recorded the user's "Ollama update + systemd tuning" and "LLM model research" work streams for completeness — these are server-side / infrastructure tasks outside the four chatbot-family repos (systemd units, Ollama model storage, research notes), so no in-repo change landed this period. The chatbot still pins `qwen3:30b` in `config/chatbot.php`; the in-repo change point for a future model swap is documented.
none in the four chatbot-family repos for the period
2026-08-03
Neural-network hexagon icon rebrand (ecosystem-wide)
Rebranded the entire IRIS ecosystem's app icon from the old "eye/iris" motif to a new "neural-network hexagon" motif (blue squircle + white hexagon line-art with 13 nodes), swapping icon assets across chatbot admin, web, mobile, and desktop while keeping each repo's existing filenames so no manifest references changed. Bumped client versions and published the v1.0.5/v1.0.6 APK + v1.1.4 Windows installer.
2026-08-03
Client version bumps + releases (mobile 1.0.11, desktop 1.1.8, web 0.2.2)
Bumped and published the final client builds of the period (mobile 1.0.11, desktop 1.1.8, web 0.2.2) and raised `VersionController` min versions so the force-update gate retires older 1.0.x / 1.1.x builds. These consolidating releases carry the UAC removal, HTTPS migration, and BOM media to every installed client.
2026-08-03
BOM-image surfacing in chat responses (`media` via ERP URL)
Surfaced the ERP BOM image inline in chat answers so a user asking about a BOM sees the product image, not just the text data. The backend appends a `media` action with the ERP image URL (built from `config/chatbot.php` templates with id sanitization), and the three clients render those URLs in `ImageGallery`.
2026-08-03
Users & UAC — per-user server-side UAC for the chatbot
Moved User Access Control from an unverified client-side toggle to a per-user, server-side, authenticated policy: sync ERP users into the chatbot, give admins a UI to edit each user's allowed intent categories, and enforce UAC from the resolved Sanctum session in the chat pipeline. Clients were simplified to remove the UAC UI and send the Bearer token on every chat request, closing the long-standing auth-token-not-sent gap.
2026-08-03
Mobile production-preset host fix
Fixed the mobile production build, which was baking the wrong backend host (`erp` instead of `chatbot`) so production builds connected to the wrong service. Corrected the preset and bumped to 1.0.9; folded into the HTTPS migration item but called out separately as a distinct production-breaking config bug.
`d6f2ea91` (production preset pointed to wrong host — `erp`→`chatbot` — + bump 1.0.9)
2026-08-03
HTTPS API migration — clients + backend (split-horizon DNS fix)
Migrated the chatbot API and download/update URLs from plain HTTP (`:8001`) to HTTPS behind the reverse proxy, and added an init-time URL migration on mobile and desktop so installed clients transparently rewrite their stored HTTP URL to HTTPS on next launch — fixing the split-horizon DNS issue where the public hostname resolved to the LAN address for internal clients. Also corrected a mobile production-preset bug pointing at the wrong host.
2026-08-03
Android — force-update gate
Added a launch-time force-update gate to the Android client that calls `POST /version/check` and renders a `ForceUpdateScreen` with the Download APK button when an update is required, blocking out-of-date builds from the chat. Both client and backend fail open so a broken check never bricks the app; bumped to 1.0.7.
`449abf7e` (add force-update gate + bump 1.0.7)
2026-08-02
Client releases — uniform-UI desktop + Android builds published
Built and published three successive desktop+Android release pairs (v1.1.1/v1.0.3, v1.1.2/v1.0.4, v1.1.3) to the chatbot's `public/downloads/`, carrying the uniform-UI re-theme and the remade icon to installed clients. Bumped `VersionController` min versions and APK filename constants on each publish so the version-check gate forces the update.
`cd19a8ff` (publish IRIS v1.1.1 desktop + v1.0.3 android with uniform UI/icon), `ede078e0` (publish v1.1.2 desktop + v1.0.4 android with remade icon), `bb405bfe` (publish IRIS v1.1.3 desktop with electron-updater auto-update)
2026-08-02
Admin dashboard — IRIS branding + intent-manager fix
Rebranded the chatbot admin dashboard to IRIS — added a full favicon/PWA/icon set, renamed the tab title to "IRIS Admin", and inlined the logo SVG into the layout to fix a broken-image from stale `/logo.svg` browser cache. Also fixed the intent-manager page, whose missing `@endsection` was preventing the shared top bar from rendering.
`9456a4d5` (apply IRIS brand to admin dashboard — favicons, logo.svg, site.webmanifest, layout), `0aa34be1` (rebrand dashboard tab title to "IRIS Admin"), `2442d62e` (inline IRIS logo SVG in admin layout — fix broken-image from stale `/logo.svg` cache), `c8f13518` (fix intent-manager missing `@endsection` — top bar not rendering)
2026-08-02
Windows cross-compile (Wine + the 3 patches)
Established a Wine-based cross-compile pipeline on this Ubuntu server that produces the IRIS Windows NSIS installer + portable `.exe` via electron-builder — no Windows VM required. Documented the three patches that let the build avoid wine32 entirely (wine32 would break the production `php7.4-gd` stack) and which must be re-applied after every `npm install`.
guide doc `WINDOWS_CROSS_COMPILE_GUIDE.md` (not in the period's commit set — authored as part of the rebuild; the cross-compile output is the installers published in the release commits below)
2026-08-02
Desktop — electron-updater auto-update wiring
Wired `electron-updater` into the desktop main process so the client auto-updates from a published `latest.yml` on launch and on window focus, instead of requiring manual reinstall. Released 1.1.3 as the first auto-update-capable build, closing the desktop force-update parity gap with the mobile client.
`69604040` (add electron-updater auto-update), `8a967e61` (bump 1.1.3)
2026-08-02
Desktop rebuild — Tauri → Electron + IPC HTTP bridge
Replaced the unbuildable Tauri shell (the 29 Dec 2025 regression that had deleted `src-tauri/` and stripped `package.json`) with a working Electron + React shell, restoring a usable Windows desktop client. The new Electron IPC HTTP bridge routes all HTTP methods through the main process, bypassing renderer CORS and fixing the old `clearConversation()` (DELETE) gap that Tauri silently dropped.
`d10f1372` (Electron shell + branded window bg), `7ff8fb0d` (bump 1.1.1 for uniform-UI release)
2026-08-02
Uniform-UI rebuild — IRIS design system + Trust & Authority re-theme (web + desktop + mobile)
Rebuilt all three chatbot clients onto one uniform IRIS visual identity — a "Trust & Authority" enterprise vocabulary (deep trust-blue primary, emerald accent, Plus Jakarta Sans, brand-tinted shadows) — replacing the old consumer-AI purple/indigo gradients and the generic brain-in-a-bubble icon. Vendored a shared token file into each app so one edit propagates across web, desktop, and mobile.
2026-08-01
Intent automation — single-registry source of truth + `intent:generate` / `intent:audit`
Established one canonical intent registry as the single source of truth for the chatbot's intent catalog, with a generator that emits the three downstream config files and an audit command that detects drift — so the intent catalog can no longer go out of sync by hand-editing. Wired two previously-orphaned intents into their handlers and dropped documented drift from 112 to 68.
`3bc009d8` (intent:audit command), `219e9567` (generate from single registry + duplicate-key/new_feature sync), `7d5c49b4` (Intent Manager admin page), `5def6793` (intent system docs), `90862920` (wire `progress_query` → WorkOrderDataHandler), `25b1824c` (wire `new_feature_1764147444` → PurchaseOrderDataHandler), `71016288` (update registry allow-list + regenerate `erp_intents`), `67431a0c` (document drift fixes in `INTENT_AUDIT.md`)
2026-08-01
Admin guide pages — Codebase, Downloads, Intent & Reply Guide
Added three chatbot admin pages — a live Codebase browser over the IRIS repos, a Downloads page that scans release artifacts and audits the electron-updater feed, and an Intent & Reply Guide rendering the catalog with interactive diagrams and a print/PDF view — so operators can reach the deep-dive docs, releases, and intent reference in-app without shell access. Also committed the underlying `.cursor/guide/` docs written during the 07-30 kickoff.
`cfd341289`
2026-07-30
Codebase study + `CODEBASE_OVERVIEW.md` + per-project `.cursor/guide/` docs (kickoff)
Studied the four-repo IRIS chatbot family and wrote a single workspace-root `CODEBASE_OVERVIEW.md` entry point plus per-project `.cursor/guide/` deep-dives, so a new developer can orient on the architecture, the ERP integration contract, and the known issues in ~10 minutes. Delivered the overview on 07-30; the per-repo guides landed in-repo over the following days.
none at workspace root (not a repo); per-repo guide docs landed in-repo later (see 2026-08-01)

Projects

intec-erp-v2
ERP / System of record
The ERP system of record. Owns the MySQL schema, all writes, all business logic, all migrations. 282 Eloquent models.
Tech
PHP 7.1+, Laravel 5.8, Vue 2, Blade, MySQL, Cartalyst Sentinel, InfyOm generator
Port
8000
Path
intec-erp-v2/.cursor/guide/
Deep-dive docs (26)
›.cursor/guide/BOM_SYSTEM_DOCUMENTATION.md
›.cursor/guide/CALENDAR_CACHE_CHAIN_REACTION_GUIDE.md
›.cursor/guide/CALENDAR_DETAIL_CACHES_DOCUMENTATION.md
›.cursor/guide/CHATBOT_EXTRACTION_STATUS.md
›.cursor/guide/DEPLOYMENT_2026-04-21.md
›.cursor/guide/DOMAIN_MODEL_GUIDE.md
›.cursor/guide/EINVOICE_EXCHANGE_RATE_GUIDE.md
›.cursor/guide/EINVOICE_SYSTEM_DOCUMENTATION.md
›.cursor/guide/ERP_ARCHITECTURE_OVERVIEW.md
›.cursor/guide/GLOBAL_UI_DESIGN_SYSTEM.md
›.cursor/guide/INVOICE_CANCELLATION_VERIFICATION_GUIDE.md
›.cursor/guide/IRIS_ECOSYSTEM_CONTEXT.md
›.cursor/guide/MODULE_AUDIT_LOG_GUIDE.md
›.cursor/guide/PERMISSION_SYSTEM_GUIDE.md
›.cursor/guide/PROGRESS_UPDATE_BY_ACTUAL_FG_GUIDE.md
›.cursor/guide/README.md
›.cursor/guide/RECEIVED_EINVOICE_WORKFLOW.md
›.cursor/guide/SENT_EINVOICE_WORKFLOW.md
›.cursor/guide/TERMINAL_API_GUIDE.md
›.cursor/guide/TOOL_DEVELOPMENT_GUIDE.md
›.cursor/guide/WORK_HISTORY_GUIDE.md
›.cursor/guide/WORK_ORDER_EDIT_PROGRESS_DOCUMENTATION.md
›.cursor/guide/WORK_ORDER_MAINTENANCE_USER_GUIDE.md
›.cursor/guide/WORK_ORDER_SYSTEM_DOCUMENTATION.md
›.cursor/guide/WO_INDEX_PERFORMANCE_GUIDE.md
›.cursor/guide/WO_POSITION_BUG_INVESTIGATION.md
intec-erp-chatbot
IRIS API / this project
The "IRIS" chatbot API. Reads the same MySQL DB via symlinked models (not HTTP). Hybrid regex + vLLM intent engine, ~162 intents, 14 data handlers + 14 formatters. Ships admin pages: Codebase, Downloads, Intent & Reply Guide, Intent Manager, Users & UAC. Enforces per-user server-side UAC resolved from the Sanctum session.
Tech
PHP 8, Laravel 8.75, Sanctum, vLLM chat replicas + Unlimited-OCR on GPU 3
Port
8001
Path
intec-erp-chatbot/.cursor/guide/
Deep-dive docs (9)
›.cursor/guide/API_REFERENCE_GUIDE.md
›.cursor/guide/CHATBOT_SYSTEM_DOCUMENTATION.md
›.cursor/guide/CLIENT_INTEGRATION_GUIDE.md
›.cursor/guide/ERP_INTEGRATION_GUIDE.md
›.cursor/guide/INTENT_AUDIT.md
›.cursor/guide/INTENT_AUTOMATION_GUIDE.md
›.cursor/guide/INTENT_SYSTEM_GUIDE.md
›.cursor/guide/README.md
›.cursor/guide/_diagrams_reference.md
erp-ai-chatbot-web
Client / web
React 19 CRA web chat client. Renders markdown, mermaid, charts, image galleries.
Tech
React 19, react-scripts 5.0.1, axios, react-markdown, mermaid, recharts
Port
3001
Path
erp-ai-chatbot-web/.cursor/guide/
Deep-dive docs (6)
›.cursor/guide/API_CLIENT_GUIDE.md
›.cursor/guide/IRIS_ECOSYSTEM_CONTEXT.md
›.cursor/guide/MESSAGE_RENDERING_GUIDE.md
›.cursor/guide/README.md
›.cursor/guide/UAC_AND_AUTH_GUIDE.md
›.cursor/guide/WEB_CLIENT_SYSTEM_DOCUMENTATION.md
erp-ai-chatbot-mobile
Client / mobile
Expo 54 / React Native 0.81 Android client. Most mature client. Force-update + APK sideload.
Tech
Expo ~54, React Native 0.81.5, React 19.1, axios, AsyncStorage
Port
APK (chatbot public/downloads/)
Path
erp-ai-chatbot-mobile/.cursor/guide/
Deep-dive docs (6)
›.cursor/guide/API_CLIENT_GUIDE.md
›.cursor/guide/BUILD_DEPLOYMENT_GUIDE.md
›.cursor/guide/IRIS_ECOSYSTEM_CONTEXT.md
›.cursor/guide/MOBILE_CLIENT_SYSTEM_DOCUMENTATION.md
›.cursor/guide/README.md
›.cursor/guide/UAC_AND_INTENTS_GUIDE.md
erp-ai-chatbot-desktop
Client / desktop
Electron + React Windows client. The renderer routes all HTTP through an Electron IPC bridge (window.electronAPI.httpRequest → main-process Node fetch), bypassing renderer CORS and supporting DELETE. Auto-updates via electron-updater from https://chatbot.inteceng.com.my/downloads/windows/latest.yml on launch and on window focus.
Tech
Electron, electron-updater, React 19, react-scripts 5.0.1
Port
Electron window
Path
erp-ai-chatbot-desktop/.cursor/guide/
Deep-dive docs (6)
›.cursor/guide/API_CLIENT_GUIDE.md
›.cursor/guide/BUILD_REGRESSION_AND_RECOVERY_GUIDE.md
›.cursor/guide/DESKTOP_CLIENT_SYSTEM_DOCUMENTATION.md
›.cursor/guide/IRIS_ECOSYSTEM_CONTEXT.md
›.cursor/guide/README.md
›.cursor/guide/WINDOWS_CROSS_COMPILE_GUIDE.md

Integration contract

FromToMechanismDetail
Web / Mobile / Desktop Chatbot API HTTP POST/GET All three clients call POST /api/v1/chatbot/chat (and /conversation, /config, /health, /version/check, /improve/*) at https://chatbot.inteceng.com.my (local dev http://localhost:8001). Each client sends client: 'web' | 'mobile' | 'desktop' in the body for query-log filtering.
Chatbot API ERP Shared MySQL + symlinked models (NOT HTTP) intec-erp-chatbot/app/Models is a symlink to intec-erp-v2/app/Models. Both projects point .env at the same intec_erp database. The chatbot is read-only for business data and writes only to chatbot_query_logs. Never run migrations from the chatbot.
Chatbot API vLLM HTTP (local) OllamaService (vLLM backend) calls http://127.0.0.1:8002 OpenAI /v1. Four GPU replicas behind nginx least_conn. Model Qwen2.5-14B-Instruct-AWQ (aliases iris-v3, gemma4:12b).
ERP Mobile APK HTTP download + QR MobileTerminalReleaseController renders a QR code encoding the APK download URL; operators scan it to install/upgrade. The APK also lives in the chatbot public/downloads/ and is enforced by VersionController.
All clients ERP /api/login Login flow Clients POST credentials to {chatbot-host}/api/login (host root, with /api/v1/chatbot stripped). The chatbot's AuthController validates against the shared users table and returns a Sanctum bearer token. Clients now send Authorization: Bearer on every chat request; the chatbot's ResolveChatUser middleware resolves the Sanctum session and the chat pipeline enforces per-user UAC (a legacy user_id body fallback is retained during the cutover, so old clients keep working).
Client identity Query log client field in chat body One of web, mobile, desktop. Written to ChatbotQueryLog so logs can be filtered per client. Treat as required for production clients.
UAC Chatbot Server-side, per-user, enforced Resolved from the Sanctum Bearer token by the ResolveChatUser middleware; per-user allowed intent categories are stored in uac_user_settings (ERP users synced into erp_users via the erp-users:sync command). The chat pipeline (ChatbotService) enforces UAC — disallowed intent categories fall through to the no-data / uac_blocked path. The old client-sent uac body field is removed.
APK distribution Chatbot public/downloads/ Filename convention Filename convention erp-ai-chatbot-v{VERSION}.apk. VersionController latest = min for android and desktop/windows. Bump LATEST_* and rebuild both clients on release.
CORS for web config/cors.php (chatbot) Allowed origins The web origin (http://localhost:3001 + production) must be in allowed_origins, with allowed_paths covering /api/*. The desktop client no longer needs a CORS entry: its Electron IPC bridge routes HTTP through the main process (Node fetch), bypassing renderer CORS entirely (Tauri is gone).
Collaborative-query + polling Chatbot /improve/* POST + poll POST /improve/collaborative-query returns a task_id when building is needed; clients poll GET /improve/status/{taskId} until COMPLETE. Currently blocked: routes/api/chatbot/improve.php references App\Http\Controllers\Api\ChatbotImproveController, which does not exist — the REST surface 500s. The self-improvement loop itself works (triggered directly from ChatbotService::processQuery()), but clients cannot poll a taskId.

Which project do I edit?

If you want to change...Edit projectFile(s) to touch
Add or change a chatbot intent intec-erp-chatbot config/chatbot_intents.php (LLM catalog), config/intent_patterns.php (regex), app/Services/ChatbotServices/Core/IntentDetectionService.php (isErpDataQuery()), then the matching DataHandlers/* + Formatters/*. See INTENT_SYSTEM_GUIDE.md.
Change ERP business logic / a model intec-erp-v2 app/Models/, app/Repositories/, app/Services/. Prefer the repository or a service over the controller. The chatbot sees model changes instantly via the symlink.
Change ERP schema (migration) intec-erp-v2 database/migrations/ + app/Models/. Run php artisan migrate here only.
Add a column to chatbot_query_logs intec-erp-v2 Migration here (ERP owns the schema); the chatbot writes through the symlinked ChatbotQueryLog model.
Change the chatbot API endpoints intec-erp-chatbot routes/api/chatbot/*.php (canonical; do not edit the dead routes/api/chatbotAPI.php) + app/Http/Controllers/Api/Chatbot/.
Change the LLM / vLLM integration intec-erp-chatbot app/Services/OllamaService.php, scripts/vllm-serve.sh, scripts/iris-vllm@.service, config/chatbot.php (llm.vllm).
Change the chat UI (web) erp-ai-chatbot-web src/components/Chatbot.js, ChatMessage.js, ChatInput.js, Sidebar.js.
Change the chat UI (mobile) erp-ai-chatbot-mobile src/screens/ChatScreen.js, src/components/ChatMessage.js.
Change the chat UI (desktop) erp-ai-chatbot-desktop src/components/* (survives). Desktop src/ is a forked copy of web src/ — mirror visual edits, keep the Electron IPC logic in src/services/httpClient.js + electron/.
Fix / rebuild the desktop build erp-ai-chatbot-desktop The Tauri shell is gone; the desktop is now Electron + React (electron/main.js, electron/preload.js, package.json). Rebuild with `npm run build && npm run dist:win` (electron-builder + Wine — see WINDOWS_CROSS_COMPILE_GUIDE.md; re-apply the 3 wine32-free patches after every npm install).
Add a mobile feature erp-ai-chatbot-mobile src/screens/, src/components/, then bump version in package.json + app.json + src/config/version.js, build APK, copy to intec-erp-chatbot/public/downloads/, bump VersionController::LATEST_APK. See BUILD_DEPLOYMENT_GUIDE.md.
Change auth (login/token) All clients + chatbot Clients send Authorization: Bearer on every chat request (src/services/chatbotService.js). Chatbot: ResolveChatUser middleware resolves the Sanctum session and ChatbotService enforces per-user UAC. See CLIENT_INTEGRATION_GUIDE.md §8.
Manage ERP users / UAC intec-erp-chatbot UsersUacController + resources/views/admin/users-uac.blade.php (list/search/filter, per-user UAC editor, bulk-assign, manual "Sync ERP users"). erp-users:sync snapshots the ERP users table into erp_users.
Change shop-floor terminals intec-erp-v2 routes/api/terminals/* + app/Http/Controllers/Api/ terminal controllers. See TERMINAL_API_GUIDE.md.
Change e-invoice / MyInvois intec-erp-v2 app/Services/ e-invoice services + Klsheng\Myinvois. See EINVOICE_SYSTEM_DOCUMENTATION.md.
Change CORS (for web) intec-erp-chatbot config/cors.php (allowed_origins, allowed_paths). Desktop needs no CORS entry — Electron IPC bypasses renderer CORS.
Change the mobile minimum version / force-update intec-erp-chatbot app/Http/Controllers/Api/Chatbot/VersionController.php (MIN_VERSIONS, LATEST_APK).

Known issues & next steps (prioritized)

PriorityIssueOne-line detailRead for full detail
P1 Collaborative-query REST 500s routes/api/chatbot/improve.php references App\Http\Controllers\Api\ChatbotImproveController, which does not exist — POST /improve/collaborative-query and the /improve/status polling surface 500. The self-improvement loop itself works (triggered directly from ChatbotService::processQuery()), but clients cannot poll a taskId. intec-erp-chatbot/.cursor/guide/CHATBOT_SYSTEM_DOCUMENTATION.md §8
P2 Web SPA not independently deployed erp-ai-chatbot-web has no version-check / force-update gate (mobile and desktop do), and there is no documented deployment of the web SPA build — web users only get the new build on next page load. Add a web version-check gate and a deploy pipeline. erp-ai-chatbot-web/.cursor/guide/WEB_CLIENT_SYSTEM_DOCUMENTATION.md
P3 Remaining intent drift (61) intent:audit reports 61 remaining: 58 handler-supported intents with no regex pattern (needs regex, left on the LLM path) + new_erp_feature_request (intentional self-improvement trigger, counted twice). The duplicate-key, new_feature_* sync, and progress_query orphan drift is RESOLVED by the intent automation (registry + intent:generate + intent:audit). intec-erp-chatbot/.cursor/guide/INTENT_AUDIT.md §8–§9
P4 DeliveryOrder decision Confirm whether DeliveryOrder exists in intec-erp-v2/app/Models and whether the chatbot delivery domain should keep depending on it (ERP models DOs as Invoice + DeliveryEvidence by design). intec-erp-v2/.cursor/guide/DOMAIN_MODEL_GUIDE.md §9; intec-erp-chatbot/.cursor/guide/ERP_INTEGRATION_GUIDE.md §5.2
P5 Inventory-image follow-up + docs cleanup Inventory images are not yet surfaced in chat (InventoryController reads images from local disk with different part-number sanitization than the BOM URL mechanism — needs reconciling). Plus: ~50 root-level test_*.php scripts in ERP; stale CODEBASE_STUDY.md; .bak files; align chatbot README's "Laravel 10.x" claim with composer.json (^8.75). intec-erp-chatbot/.cursor/guide/ERP_INTEGRATION_GUIDE.md §6; intec-erp-v2/.cursor/guide/CHATBOT_EXTRACTION_STATUS.md §5

Cross-cutting note: the auth-token-not-sent gap (P2) is the single most impactful security item — any future change that enforces auth on /api/v1/chatbot/* will break all three clients at once. Fix the clients first (send the token), then enforce on the backend.

Glossary

IRIS
Intec Responsive Information System — the umbrella name for INTEC's internal software family (the ERP + chatbot + clients). Also the in-chat persona name.
UAC
User Access Control — now a server-side, per-user, authenticated policy. The ResolveChatUser middleware resolves the chatter from the Sanctum Bearer token; per-user allowed intent categories are stored in uac_user_settings (ERP users synced into erp_users via erp-users:sync). The chat pipeline (ChatbotService) enforces UAC — disallowed intent categories fall through to the no-data / uac_blocked path. The old client-sent uac body field is removed.
Intent
A label classifying what the user wants (e.g. work_order_status, invoice_overdue). The canonical source of truth is config/intent_registry.php; `php artisan intent:generate` emits the three downstream files (config/chatbot_intents.php — 162 LLM intents, config/intent_patterns.php — 109 regex groups, config/erp_intents.php — the runtime allow-list) and `php artisan intent:audit` detects drift. IntentDetectionService::isErpDataQuery() reads the generated allow-list at runtime.
Data handler
A class implementing DataHandlerInterface that fetches ERP data for a set of intents and returns a payload array tagged with a type key. 14 handlers, one per business domain.
Formatter
A class implementing FormatterInterface that claims a handler payload by type and renders it to markdown. 14 formatters, paired 1:1 with handlers.
BOM
Bill of Materials — the product master. An n-level tree: Bom -> BomChild (sub-assemblies, self-referential) -> BomInventory (raw-material leaves). Walked by BomExplosionService.
WO
Work Order — the manufacturing order (work_orders), linked to a SalesOrderItem via so_item_id and to a Bom via bom_id. Status 20 = completed.
SO
Sales Order — the customer-facing order (sales_orders), carrying many SalesOrderItem lines.
PO
Purchase Order — a PO to a supplier (purchase_orders), carrying PurchaseOrderItem lines and GoodsReceiptsNote receipts.
DO
Delivery Order — not a separate model. A DO is an Invoice carrying DeliveryEvidence rows, scanned by the logistic terminal by invoice number. Deliberate design decision.
MyInvois
Malaysia's e-invoicing platform (LHDN). Invoice rows are submitted via Klsheng\Myinvois; einvoice_status/einvoice_uuid track submission.
TOTP
Time-based One-Time Password — used as the admin gate for first-run setup and settings on all three clients. Verified client-side against a hardcoded secret (TOTP secret is hardcoded in source; see each client's UAC_AND_AUTH_GUIDE.md).
vLLM
Local OpenAI-compatible inference on :8002. Four Qwen2.5-14B-Instruct-AWQ replicas (GPUs 0–3, ports 8010–8013) behind nginx least_conn. Leftover chat, intent, and Eloquent generate only — IrisUi stays PHP.
Self-improvement loop
When IRIS cannot answer, SelfImprovementService records a task, analyzes the failure with the LLM, builds a prompt, and runs a Cursor agent / Claude CLI in the background to draft a new new_feature_<timestamp> intent + handler + formatter + REST route.
Symlinked models
intec-erp-chatbot/app/Models is a symbolic link to intec-erp-v2/app/Models, so the chatbot uses the exact same Eloquent models as the ERP with no duplication. Model changes in ERP propagate instantly; the chatbot must not edit models directly.