SimpleScrumTools

Developer blog ·

SimpleScrumTools is live, rebuilt from the ground up

The rebuilt SimpleScrumTools went live on the evening of Friday, September 25. What it is, the design decisions under it, and the five things launch night found that no rehearsal could.

On the evening of Friday, September 25, simplescrumtools.com started serving the rebuilt SimpleScrumTools. This blog has one post for each week since then, and this is the first. It covers what went live, the decisions underneath it, and the night it went out.

What went live

SimpleScrumTools is a Scrum tool for small and mid-size teams. It is not a general work tracker with a Scrum template. The Scrum Guide’s own ideas are part of its structure:

  • The Product Goal lives on the project.
  • A sprint cannot start without a Sprint Goal.
  • The Definition of Done is a gate, not a checkbox.
  • The Increment is a query over what is Done, not a list somebody keeps up to date.
  • Sprint Planning, the Daily Scrum, the Sprint Review and the Retrospective each have a screen, and each one records its own notes.

The configuration is small on purpose. An item has a status and a phase, and you define the phases once per project. Access comes from roles, and each role grants some of eight capability bundles. A team role covers that team’s work, and a single per-person override on a project is the only exception. Sprints start on a Monday by default.

The decisions underneath it

One database. An earlier design kept each customer’s projects in their own cloud drive and synced them for offline use. We dropped it before building it. Everything now lives in one managed Postgres database, behind one web app. That one decision removed a sync engine, a mobile app and a set of separate packages from the plan.

Rules in the database. Where a rule can live in the schema, it does. A constraint cannot be skipped by a code path somebody forgot. The catch is that the unit tests cannot see those rules, because they run against fakes in memory. So a separate suite runs every constraint against a real Postgres. It has already found two defects that the unit tests could not see.

No silent overwrites. Every item carries a version. If two people edit the same item, the second save is refused, and that person sees both versions and chooses.

Time. Every time is stored in UTC and shown in your own timezone. A sprint runs on its team’s clock. Anything that depends on a timezone is tested in at least three zones, across a daylight-saving change.

Before launch

On September 21 we paired an automated security scan with an adversarial code review. The scan reported 304 findings, and all of them were false positives: it reads every database query helper as an injection. The review found twenty real problems. We fixed all twenty the next day, before launch.

Launch night

We rehearsed the cutover on the development copy first. Launch night still found five things that no rehearsal could, and each one was fixed where it was found.

  1. A blank setting won. The hosting platform lets a setting live at two levels. A blank copy at one level overrode the real value at the other, so mail had no password. We removed the blank copies.
  2. Google sign-in used the old names. The settings carried the previous app’s names for the Google keys, and Google refused the sign-in until the new address was registered. Then a successful Google sign-in landed on the home page, so a new account looked like a failed sign-in. It now lands in the app.
  3. Mail refused the login until the mailbox’s own password was saved. The first signup after that got its confirmation email, and the link confirmed the account.
  4. A full run through the product, in a real browser with a real account: a team, a project, three stories, a sprint from Scheduled to Active, a conflicting edit, a Daily Scrum, a Retrospective and a calendar file. Fifteen screens rendered with no console error. Then we deleted everything through the product.
  5. The Activity page printed raw codes. It showed entries such as “event.closed”. Every entry now reads as a sentence that names its project.

One more problem showed up within hours: every session ended 15 minutes after sign-in, because nothing renewed it. Pages now renew the session and bring you back to where you were. The fix was in production the same night. At launch, 3,192 tests in 229 files passed.

SimpleScrumTools is free for one Scrum Team of up to 5 members, with no card required. Try the demo or create a free account.

Release notes for September 25, 2026

SimpleScrumTools is rebuilt. Everything below is new in this release.

Plan and run sprints

  • Product Backlog: phases you define per project, epics, your own item types, and import from a CSV file.
  • Scrum built in: a Product Goal on each project, a Sprint Goal before a sprint can start, and a Definition of Done that items must meet.
  • Sprint Planning: capacity, blockers and oversize warnings show as you fill the sprint.
  • Board and Daily Scrum: the board follows the Active sprint. Moving a card changes its status, and the Daily Scrum session records the change.
  • Sprint Review: the Increment is what is Done. Feedback becomes a backlog item in one click.
  • Retrospective: four columns, and everyone writes at the same time. An action item becomes a backlog item in one click.
  • A calendar file for any scheduled session.
  • Each item’s history reads as sentences, and you can add a question to an item.

Teams and access

  • Portfolios, projects and Scrum Teams, with invitations by email.
  • Roles that grant eight capability bundles, and one per-person override on a project.
  • Sign in with an email address and password, or with Google.
  • When two people edit the same item, the second person sees both versions and chooses.
  • Every time shows in your own timezone.

On the website

  • A five-part Scrum primer, a help centre, and a read-only demo you open with one click.
  • The Free plan: one portfolio, one Scrum Team, one project and up to 5 members.

Fixed on launch night

  • A Google sign-in now lands you in the app, not on the home page.
  • The Activity page reads as sentences, not event codes.
  • You stay signed in after 15 minutes.