Skip to content
Flows

What Flows just did

Based on your request to build Build a Youth Soccer Team Management App, Flows created 11 implementation stages and 53 checks.

You asked for: Build a real, usable soccer team operations app with authenticated coach/admin workflows, player and guardian records, event scheduling, RSVP/availability tracking, attendance capture, and announcements that persist correctly in the database.. Flows generated 11 stages because the application requires Create authenticated roles for coach/admin and read-limited participant users, with route protection for coach-only management screens; Implement data models for Team, Player, Guardian, PlayerGuardianLink, Season, Event, AvailabilityResponse, AttendanceRecord, Announcement, and PositionAssignment; Support player roster fields including full name, jersey number, birth year, primary position, secondary positions, medical notes, and active/inactive status. Each stage tells your AI builder what to do, tests whether it actually worked, and gives a repair instruction when it fails. These checks are designed to catch: AI builds a pretty dashboard with hardcoded players, events, and stats instead of real persisted records; Guardians are stored as plain text fields on the player record instead of a proper one-to-many or many-to-many relationship; Attendance and RSVP are conflated into one table, making it impossible to distinguish planned availability from actual presence.

Example failure

The form reported success, but no database record was created.

What Flows does

Flows detects the failure, generates a repair instruction, reruns the test, and stores the passing evidence.

Stages — Plan → Build → Test → Fix → Prove → Ship

11 stages · 53 checks · progressive disclosure — open a stage for details

Copy to external builder

Copies a prompt for Claude/Cursor/etc. Records prompt_copied only — not execution, commits, or checks.

Execute through Oort

Requires Sign in with Oort + a provider connection (BYOK). Keys stay on Oort. A model name in the dropdown is not the same as a live connection.

Next

Check off: There is a distinct PlayerGuardianLink or equiva…

Add a proof note on each check — a checkbox alone is weak proof.

Probes & advanced tools are under “More verification tools”. Experience level: Settings.

Build a Youth Soccer Team Management App
App Builder180-300 minutesGenerated Draft

Project (saved with proof)

Project binding: Unbound — complete project binding before trusting this run · missing repositoryUrl, repositoryStartCommit, environment, stack

More verification tools (probes, timeline, adapters)Show

App persistence (create → read → assert token)

Body template: {"probe":"{{token}}","title":"flows-probe-{{token}}"}. Needs CORS-readable public create/list endpoints (or inconclusive). Badge only when create→read→refresh finds the token (detects false success).

Two-account authorization (User B cannot see/change User A)

Authorization evidence source: Cross-account ownership test (trust level 5/6). These are not equivalent. Unauthenticated probe alone is weaker (source: unauthenticated API probe). Tokens stay in this browser session only — not uploaded to Flows servers.

Generated edge-case tests (review / approve)

  • api_probe Submitting the form empty is rejected with a clear error
  • api_probe Each required field can be omitted and fails validation
  • api_probe Malformed email is rejected
  • api_probe Malformed phone is rejected when phone is collected
  • api_probe Duplicate submission does not create two records
  • api_probe Double-click submit creates only one record
  • false_success_probe Failed request does not show success
  • browser_automation Refresh during submission does not leave corrupt state
  • api_probe Oversized input is rejected
  • api_probe Unsafe strings do not execute or break storage
  • cross_account_probe User B cannot see or change User A’s data
  • cross_account_probe Participant cannot call coach/admin endpoints
  • cross_account_probe URL/body ID tampering cannot cross tenant boundary
  • api_probe Create then refresh still shows the record
  • api_probe Edit then refresh keeps the edit
  • api_probe Delete then refresh removes the record

Generated from this route’s signals — you approve; you do not invent security tests.

Content probe (GET body contains text)

In-product content probe reads response text when CORS allows — not full DOM/click automation. Playwright script is optional and external.

Proof strength

thin · 0/100

Heuristic from notes + probes + gates — not a production certification.

Verification adapters

  • Deploy URL probe · idle
  • API path probe · idle
  • Authz probe (unauth → 401/403) · idle
  • Browser persistence · idle
  • App persistence (create→read) · idle
  • Content / body text probe · idle
  • In-product Playwright DOM · not embedded (download external script)

Filled circles = available here. Empty = not shipped. Probes are not a production audit. Adapter docs

0/11 steps0%
Recording plan identity…

Step 1 of 11

Not started

Create the soccer domain schema for teams, players, guardians, events, RSVP, attendance, and lineup assignments

The app will fail if the data model does not reflect actual youth soccer operations and enforce the right relationships and uniqueness rules.

💡

Start with the database schema before UI generation so later screens bind to real entities instead of fake placeholders.

Flows keeps plan, checks, failures, and next steps connected

Your AI tool writes or changes the code

Repository grounds the plan only after inspect

Checks always carry a validation tier

Not checkedChecks not locked

How this plan was created

Plan from project details

Flows creates steps using the goal, requirements, stack, platform, and details you provide.

  • Project description
  • Selected template / route
  • User-entered stack
  • Constraints and notes
  • Build a Youth Soccer Team Management App

No repository inspection implied. Connect and inspect a codebase to ground steps in real files.

Codebase access

Checking GitHub…

Or paste a repository URL manually
Plan instructions

Use these instructions in Claude, ChatGPT, Cursor, Emergent, or another builder.

Create the full database schema for a single-team youth soccer management app. Requirements: Team table; Season linked to Team; Player linked to Team with fields fullName, jerseyNumber, birthYear, primaryPosition, secondaryPositions, medicalNotes, activeStatus; Guardian with name, phone, email, preferredContactMethod, relationship; PlayerGuardianLink join table so one player can have multiple guardians; Event linked to Team/Season with eventType enum (practice, game, tournament), startAt, endAt, location, fieldName, opponent, notes, status; AvailabilityResponse linked to player and event with one unique row per player-event pair and status enum (available, unavailable, late, no_response); AttendanceRecord linked to player and event with one unique row per player-event pair and status enum (present, absent, late, excused) plus notes; Announcement linked to team with title, body, audienceScope, publishedAt, optional eventId; PositionAssignment linked to game event and player with position, startStatus, notes. Add foreign keys, indexes for event date and player name, and seed one sample team with players, guardians, events, announcements, RSVP rows, and attendance rows.

The AI tool writes code — Flows only organizes the plan · Complete implementation prompt with explicit requirements

Project context

Copies the project goal, technical details, current step, previous progress, and checks so your AI tool understands what it is working on.

Expected after this step

A real database schema and seed dataset that accurately models youth soccer team operations.

Should not happen

  • AI builds a pretty dashboard with hardcoded players, events, and stats instead of real persisted records
  • Guardians are stored as plain text fields on the player record instead of a proper one-to-many or many-to-many relationship
  • Attendance and RSVP are conflated into one table, making it impossible to distinguish planned availability from actual presence
  • Events omit soccer-specific fields like opponent, event type, and field/location, so match workflows break

Verify gate — prove this step works before continuing

Do not move on until every check is true. Add proof notes — a checked box alone is weak proof. Checks are manual by default; deploy/API probes live under “More verification tools” and do not auto-check boxes.

Do not continue if…

  • !AI builds a pretty dashboard with hardcoded players, events, and stats instead of real persisted records
  • !Guardians are stored as plain text fields on the player record instead of a proper one-to-many or many-to-many relationship
  • !Attendance and RSVP are conflated into one table, making it impossible to distinguish planned availability from actual presence
  • !Events omit soccer-specific fields like opponent, event type, and field/location, so match workflows break
  • !Role protection is only hidden in the UI but not enforced on server actions or protected routes
  • !Duplicate availability or attendance rows are allowed for the same player-event combination because unique constraints were not added

Repair path — if this step fails

Use the Repair Prompt when a verify gate fails. Loop: Detected → Diagnosed → Repair issued → Changed → Retested → Resolved

Show repair prompt textShow

The current schema is too generic or not normalized for youth soccer. Refactor it so guardians are separate records linked through a join table, RSVP and attendance are separate tables with unique player-event constraints, and game events support lineup assignments. Then reseed the database with realistic sample soccer data and show the resulting tables and sample rows.

Your notes for this step

Definition of Done

Final route-level requirements. Manual checks — separate from per-step verify gates. Completing step gates does not auto-check these. Route completion is not a production-ready claim.

0/8 · manual