Build with AI

How to build a project & task manager with Bolt

A project tracker built in one browser tab, from a repository Bolt imports on the way in. Projects and boards, one set of tasks shown four ways, comments with files, tracked time that totals itself, and live updates, described a piece at a time, with the running app in front of you.

August 2026 · 52 min read · Updated September 2026

Bolt

$ Build a project and task manager: projects with boards and columns, tasks with priorities, due dates, subtasks, comments and attachments, four views over the same tasks, a start/stop timer that totals onto the task, live updates, and rules deciding who may open which project.

  • Repository imported
  • Views and the live feed checked in the app
  • Ready for you to review
You describe it, Bolt builds it
Start here

What a project & task manager actually is

One list of tasks, viewed four different ways, by a whole team at once. Most of the complexity in project management comes from that single sentence, not from how any app looks.

Strip the design away, and a task manager is surprisingly simple: projects, boards, columns, tasks, and basic details like assignees, due dates, comments, and time spent. That much you could sketch on a napkin.

What makes it powerful is that the same data answers four distinct questions. A board asks where work stands and in what order. A list asks how to sort and filter hundreds of tasks instantly. A calendar focuses purely on deadlines, ignoring tasks without dates. A timeline maps out start and end dates to show project flow. Four views, one dataset, four ways to keep everyone clear on priorities.

Then real teamwork happens. Someone moves a card while a teammate is checking the same task in a list. Someone tracks time, steps away, and returns to find the task updated. This is where a tracker turns from a simple spreadsheet into shared team infrastructure, where the real value is in instant clarity, not just drag-and-drop mechanics.

Four ways to see your work

If you build views as separate features, you end up with conflicting truths, where a deadline shows on your calendar but vanishes from your timeline. Building them on a single dataset means changing a date anywhere instantly updates it everywhere, keeping your workspace reliable and effortless to maintain.

Card position sets team focus

Moving a card isn’t just a visual tweak. It resets team priorities. Storing order directly at the data level ensures that a card sitting third in a column stays third across page refreshes, mobile devices, and colleague screens. Your workflow stays locked in, no matter who moves what.

Real-time accuracy by default

The moment two people use a tracker, a stale screen means two colleagues confidently disagreeing on project status. Instant real-time updates guarantee everyone works from the exact same reality, eliminating double work, constant pings, and manual refreshes.

What work looks like without one place for it

275

interruptions a day (a ping about every two minutes of an eight-hour day) among the most-pinged fifth of the workers in Microsoft’s June 2025 study of its own telemetry and a survey of 31,000 knowledge workers. Read the qualifier rather than the headline: this is the top 20% by ping volume, not the average person. It is still the clearest picture available of what happens when the state of the work lives in everybody’s inbox instead of somewhere both of you can look.

Microsoft Work Trend Index special report, published June 2025 · checked report published June 2025

What a project tracker needs

The parts every project tracker is built from

The first of these six is the foundation for all the rest. Get that one right, and the entire system stays clear, reliable, and effortless to use.

01

One single truth across four views

A board, a list, a calendar, and a timeline aren’t four separate tools: they are four ways to look at the exact same work. When you update a deadline in a list, it must change instantly on the timeline and calendar. Keeping every view synchronized on a single dataset prevents conflicting information and eliminates duplicate work.

02

Card position drives real team priorities

If a task sits third in a column, it represents a team priority. That position needs to survive page refreshes, mobile app views, and colleague updates. Dragging a card isn’t just a visual adjustment: it sets what your team focuses on next, so that order must remain rock-solid for everyone.

03

Instant real-time synchronization

A project tracker is only useful if everyone sees active data. Changes should appear instantly, without requiring anyone to press refresh. The moment information gets stale, two colleagues end up confidently disagreeing on project status or repeating the same work. Live updates keep the entire team aligned.

04

The task is where your team’s memory lives

Beyond due dates and assignees, a task holds essential context: subtasks, attachments, and the discussions behind key decisions. Standard fields tell you what needs to be done, but the conversation explains why. Six months later, that comment thread is the only reliable record of how a project was delivered.

05

Time tracking only works if the numbers add up

A simple start/stop timer is easy, but real value comes from automatic rollups. Time entries must attach cleanly to tasks and people, survive page reloads, and calculate totals automatically. Done right, you instantly know what a project actually cost to complete. Done wrong, you get confusing numbers nobody trusts.

06

Clear permissions and privacy from day one

A solo workspace functions differently than a shared team hub. Establishing who can view or edit specific projects keeps client data private while keeping internal collaboration open. Setting these access boundaries upfront protects sensitive work as your business grows.

Build vs buy

Buy it once or pay per user forever

Popular tools like Trello, Asana, Monday, and ClickUp charge anywhere from $5 to $30 per user every month. Before comparing features, answer one question: how many team members, contractors, and clients will ever need access? Per-seat pricing quietly turns your business growth into a recurring monthly penalty.

Build your own

An app you own has no seat meter on it. The views everybody else keeps behind an upgrade are just queries, and with an AI coding tool writing the schema, the access rules, and the live updates, that build is weeks rather than quarters.

  • The eleventh person to need a look at the board costs nothing, so adding somebody is not also a budget conversation
  • A board, a list, a calendar and a timeline are four queries over one table rather than a plan tier
  • Your projects live on your own domain, not a workspace subdomain somebody else owns
  • Every task, comment, attachment and tracked minute is in your own database, queryable without an export request
  • What a column means, what counts as done, and which fields a task carries are yours to change in a sentence
  • Nothing gets taken away when a vendor reshuffles its tiers, because there are no tiers

Rent the tracker

Trello · Asana · monday.com · ClickUp · Basecamp

Renting a tracker buys you 15 years of ready-made infrastructure: automated workflows, tool integrations, mobile apps, client access, and instant customer support. This template provides none of these out of the box: it trades turn-key convenience for complete data ownership and zero per-seat fees.

  • Working the day you sign up, with mobile apps, notifications that reach a phone, and a support contract behind them
  • Automations and rules, so a card moving can assign somebody without you writing a trigger
  • Integrations with the tools work actually arrives through, a category this template does not attempt
  • Real multi-person collaboration out of the box: invites, guests, and permissions, which this template genuinely does not have
  • Notifications that leave the building. This template raises them inside the app and sends nothing out of it
  • Four of the five bill per person per month, and two of them put the timeline view itself behind that bill
TrelloFree, then $5 (Standard), $10 (Premium), and $17.50 (Enterprise) per user/month billed annually - $6 and $12.50 billed monthly for the first two

Here first because its own pricing page states this guide’s argument more plainly than we could. The Premium column carries the feature line “Views: Calendar, Timeline, Table, Dashboard, and Map”, so the four views this template ships are the reason to upgrade, and neither the Free nor the Standard column lists a view feature at all. Its free tier is generous where it matters least: “Unlimited cards”, but “Up to 10 collaborators per Workspace”, “Up to 10 boards per Workspace”, and “250 Workspace command runs per month”.

trello.com · checked August 2026

Asana$10.99 (Starter) and $24.99 (Advanced) per user/month billed annually, or $13.49 and $30.49 billed monthly, with Enterprise quoted on request

The same story at a higher price point. Its free Personal plan includes “List, board, and calendar views” and stops there. Timeline and Gantt begin on Starter, which the page describes as “a clean, simplified scheduling view” plus “detailed project management features like task hierarchy and progress tracking”. Personal is capped at “Up to 2 users can collaborate for free”, so the free tier is out for a team of three before any feature comparison starts. And read this promise carefully: “Add as many team members as you need without hitting a cap or paying extra per person” is about seat caps, not the per-seat bill, which continues.

asana.com · checked August 2026

monday.comFree (up to 2 seats), then €9 (Basic), €12 (Standard), and €19 (Pro) per seat/month billed annually on its Work Management plans

The clearest per-seat ladder of the five, and the one that prices the same product several ways depending on what you call your team: its CRM and Service plans at comparable tiers run €12 to €28 and €31 to €45 a seat. Two honesty notes. The page served euros rather than dollars, so euros are quoted. And its Work Management columns showed us annual figures only. The CRM columns showed both bases and advertised “billed annually saves 33%”, so month-to-month runs higher here by an amount we cannot state without inventing it. Its team-size selector starts at three seats.

monday.com · checked August 2026

ClickUpFree Forever, then $7 (Unlimited) and $12 (Business) per user/month billed annually - $10 and $19 billed monthly - with AI sold separately at $9 or $28 per user/month

The counter-example on seats, and the one whose free tier fails in an instructive way. Free Forever advertises “Unlimited Tasks” and “Unlimited Free Plan Members”, so the meter is “60MB Storage” rather than people, roughly a dozen photographs, and the wall you meet the first time somebody attaches files to a task. The other thing to notice is the separate AI ladder: the assistant is its own per-user line on top of the plan, at $9 or $28 a user a month.

clickup.com · checked August 2026

Basecamp$15 per user/month billed monthly (Pro), or $299/month billed annually for unlimited users (Pro Unlimited) - free for one project and up to 20 users

The honest exception: one well-known vendor does sell a way off the seat meter, and its page says so: “Unlimited users, no per-user fees”, “Your whole organization for one fixed price”. The arithmetic is ours, not theirs, and it is why this row is here: $299 a month against $15 per user means the flat plan only pays off around twenty people, so for a small team it is the dearer of Basecamp’s own two options. Roughly $3.6k a year, in perpetuity, for software.

basecamp.com · checked August 2026

Rule of thumb: if work arrives from a dozen other systems, if clients need guest access, if people live in the mobile app, or if somebody in compliance needs an audit trail, rent. Those are real products and none of them is a weekend of describing. If what you want is your team’s work in one place, in the views you find useful, with fields that match how you talk about it, and a bill that does not grow every time you hire, that is the half worth owning. Two things to weigh either way. This template ships with a project belonging to one person, and the shared-workspace version is an addition described in the steps below rather than something already built. And the paid tier you would replace is more than a paywall over four views: the automations, the integrations, and the phone in somebody’s pocket.

No dev needed

Why build with Bolt

Screens are the easy part. What actually stalls a solo build is everything underneath them: somewhere real to hold the data people type in, permission checks on who can see it, and a UI that keeps working once more than one person is using it.

Bolt runs the whole thing in one browser tab, right down to the preview:

The build loop
1

Prompt

Describe the screen or rule you want, in plain language.

2

Preview

Watch the running app rebuild itself in the same tab.

3

Try it

Click through the real app, because the preview is the actual build rather than a mockup.

Refine

Ask for the next change, or fix what’s off.

Loop back to Describe

None of that needs an install or a terminal window, and the whole build happens in the tab GitHub just opened, one request at a time.

One tabruns the whole build

Bolt runs your project inside the browser itself, via StackBlitz’s WebContainers, so the preview you’re looking at is the app actually running, rather than a screenshot or a separate deploy you have to wait on.

Auto-committed to GitHub as you go

Once GitHub is connected, Bolt commits each working change on its own and pulls in anything you changed elsewhere, so the two stay in sync without you typing a git command.

Built-in database or your own Supabase

Ask for a database and Bolt wires up its own managed one with no extra account, or connects a Supabase project you already run yourself.

What it costs

Pay a developer, or do it with AI

Neither option charges you per seat. A workspace built for ten colleagues costs the exact same as a workspace built for one.

Hire a developer

Custom build, from scratch
Developer
~$13k-$50k
Supabase (backend)
Free tier · $25/mo (Pro plan)*
Hosting
$0 free tier
Build time
~250 hrs of their work

~$13k-$50k to build, then from $25/mo after launch

Our ~250-hour estimate, priced at the rates in the survey linked below: it has senior US developers at $100-$150+ an hour, and agencies charging 20-40% more than the freelancers they bid against, which is where $50/hr and $200/hr come from rather than from a shrug. Read the distribution rather than the total, though. Roughly a third of those hours go on the access rules, the live updates, and the arithmetic that rolls tracked time onto a task, and none of the three can be photographed. It is why a quote for “a Kanban board” tends to come back at a multiple of what the mockups implied.

Build it with Bolt

From scratch, with Bolt
Bolt
Free (1M tokens/mo) to $25+/month (Pro, from 10M tokens)
Backend (Supabase)
Free tier · $25/month (Pro plan)*
Hosting
Free on Bolt’s own hosting, or Netlify
Your time
~118 hrs

Free for a first look. A real build costs from ~$25/month on Pro once it outgrows the entry token rung, and climbs from there with usage

Bolt bills by tokens, and the sticker price understates what a real build costs: it reloads your whole project as context on every message, so the entry Pro rung (10 million tokens for $25/month) burns down faster than the number implies. Budget for a top-up or a higher rung on a multi-session build, not the $25 floor. Lean on Bolt’s own token-saving tools (clearing context between features, pointing a prompt at specific files) to slow that burn.

* Ignore the 500 MB database limit. Tasks and comments are text, and text is small. Two other free-tier lines matter. The 1 GB of file storage is what attachments spend, and it goes faster than you expect once people start dragging screenshots onto cards. And a free project pauses after a week of inactivity, which for a tracker means the week your team quietly drifts back to a spreadsheet. Pro, from $25/mo, ends the pause, takes file storage to 100 GB and egress to 250 GB (then $0.09 per GB), and keeps a daily backup for 7 days.

What separates the two columns is which way the bill moves. Renting gets more expensive with every person who joins. Owning costs the same at thirty people as at three, and the only line that shifts is whichever AI model you choose to call. One of those two shapes suits a team that is growing, and growing is the only thing anybody is trying to do.

Prices and rates from supabase.com, developex.com and bolt.new, checked August 2026.

Plan first

Decide before you build

Define six core rules before writing a single line of code. Getting the first rule right sets the foundation for your entire system.

01

Whether this is yours or your team’s

Decide early if this tracker is for one person or a team. A solo tracker is simple. A shared system requires access control for every project, view, and live update. Changing this after the system is built means rewriting your security rules from scratch.

02

What a project contains, and how deep it goes

Project, board, column, task is one shape. Project, task, subtask is another. Milestones or sprints are a third. Write two or three of your own real projects out longhand and see which they fall into. Wrong nesting is the thing you feel every day.

03

Which views you will actually live in

Four views is what the products you are comparing against charge for, not automatically what you need. Pick the one you would open by default and build it properly before adding a second. A timeline costs most and gets used least: it needs start dates, and nobody enters those unless forced.

04

What done means, and who is allowed to say so

Your columns are a workflow whether or not you call it that. Write the sequence out, decide whether anybody may move any card or only its assignee, and decide what happens to a finished card: it stays, it archives, it disappears. Cheaper to write now than to migrate later.

05

Whether you track time, and what you will do with it

Tracked time is only worth the friction if somebody reads it. Billing by the hour makes it the point of the application and it should be one press to start. Otherwise it is a field that makes every task feel like paperwork. If you do track it, settle whether one person may see how long a colleague took.

06

Where the files go, and who may open them

Attachments turn a task into a record, and they carry this app’s sharpest privacy edge. A contract or a screenshot of a customer’s account is not a Kanban card. Decide whether a file is readable by anybody with the link or only by people who may see the task: two different systems, and the easy one is the leaky one.

Approaches

Comparing your build options

Designing screens is the fast part. The real work is real-time synchronization, data consistency, and user permissions across four live views. Here is how three build approaches compare in time and complexity.

~250 hrsBuilding by hand

The four views are not the expensive part. What costs you the month is that they are four readings of one set of rows, and every one of them has to stay honest while somebody drags a card, starts a timer, and posts a comment on a different machine. Getting one view right takes an afternoon. Getting the fourth one to agree with the first three, live, is the job.

~185 hrsGeneric UI starter kit

A kit hands you a board, a table, a calendar widget, and a dashboard shell, which looks like most of a project tracker and is the half you would have finished anyway. None of it knows what a project is, who may open one, that reordering a column is a fact to be stored, or that the person in the next room needs to see the card move. All of that is still yours.

~118 hrsBuilt with Bolt

One prompt at a time against a repository Bolt imported, with the app itself running in the tab beside the chat and every working change committed back to GitHub on its own. The task list above it, unchanged, checked in the running app after each piece.

Interactive calculator

Estimate your exact build timeframe

Uncheck any features your team doesn’t need to see your build time drop immediately.

What your project tracker needs

Your estimate

118 hrs

start to finish

Based on the 7 of 7 features you’ve selected, plus ~26h of groundwork. Toggle any on the left to watch the number move, and open the groundwork row to untick what you have already, such as a database that is already running or going live if you are only building a mock-up for now.

A rough estimate, not a quote. Real time depends on how much you customize and how clean your data is.

Setting up your workspace

Let’s set up the tools you need

Bolt runs in the browser, but it can’t open a .zip file, so the only way in is a GitHub repository. Do that first, then create a Bolt account and a plan. Everything after that is a plain description of what you want.

1

GitHub account

Cost: Free

Bolt has no upload button for a folder or a .zip, and the only way to open a project is to import a repository, so a home for the code has to exist before Bolt does. Sign up and create a private repository, then push your project’s files to it.

Create a free GitHub account
2

Bolt account

Cost: Free

Sign up at bolt.new and connect the GitHub account from the step above. Once it’s linked, you pick a repository to import and land straight in a live preview, with nothing to install.

Sign up for Bolt
3

Bolt subscription

Cost: Free (1M tokens/mo), then from $25/month (Pro)

Free gives you 300,000 tokens a day, capped at 1 million a month, which is enough to try Bolt rather than to finish a real app. Pro starts at $25/month for 10 million tokens (unused ones roll over one extra month), but Bolt reloads your whole project as context on every message, so a multi-session build tends to burn past that entry rung faster than the sticker number implies.

Compare Bolt plans
4

Supabase (database)

Cost: Free to start

Where your project keeps its data. Bolt can wire up its own managed database with no extra account, or connect a Supabase project you already run yourself, and both are Supabase underneath. Ask for one the first time a screen needs to save something real, so you have nothing to set up before you get there.

Connect Supabase to Bolt

The GitHub step comes before Bolt exists for you at all. Everything after it happens inside the browser tab Bolt opens, with no install.

Step by step

Build your project tracker, one prompt at a time

Bolt opens a GitHub repository and works in it, with the running app beside the chat. Two things shape the order below. Bolt bills by tokens, so the expensive habit is asking for four views at once and then paying again to unpick them. The schema gets a prompt of its own precisely to avoid that. And the live updates go in before the access rules, so adding the rules forces you to prove they reach the feed.

  1. 01

    A repository first, then the two rules in a file

    Bolt cannot open a folder or a zip, so the way in is a repository. Once it is imported, the first prompt writes down the two constraints everything after it depends on.

    PromptSet up the project
    This repository is a new React 18 + Vite + TypeScript project for a project and task manager. Add Tailwind and the Supabase JS client, with a typed client under src/lib reading VITE_SUPABASE_URL and the publishable key (the sb_publishable_… key that replaced the older anon key) from .env, and confirm .env is in .gitignore so neither value is committed. Then write a short PROJECT_NOTES.md fixing the vocabulary (project, board, column, task, subtask, comment, attachment, time entry, notification) and recording two standing rules to follow for the rest of this build. First: the board, list, calendar and timeline are four readings of one tasks table, so a new field is added once to the model and then shown where it is needed, never duplicated per view. Second: whether somebody may read a row is decided by a database policy rather than a filter in a component, and that applies to rows delivered by a realtime subscription as much as to a query. Start the dev server so I can see it boot.

    Keep those rules in the file rather than only in the chat. Clearing Bolt’s context between features is the cheapest way to keep prompts small, and anything that only ever lived in the conversation goes with it.

  2. 02

    Talk the schema through in Plan Mode, then build it

    The one step where thinking is cheaper than generating. Plan Mode is the right tool here because a schema is exactly the kind of thing you want to argue about before any code exists that assumes it.

    PromptModel it once, and decide whose it is
    Use Plan Mode for this one before writing anything. I want the data model as Supabase migrations, with no authentication yet: projects with a name, description, colour and an owner. Boards belong to a project. Columns belong to a board with a stored position. Tasks belong to a column with a title, description, priority, status, due date, an optional start date for the timeline, an assignee, a stored position within the column, and an optional parent task so a subtask is a task with a parent. Comments belong to a task with an author and an optional attachment path. Time entries belong to a task and a person with a start, an end and a duration. Notifications belong to a person. In the plan, tell me two things before I approve it: how a task’s position within a column works, and which of two access shapes you are assuming: a project belongs to one person, or a project has members. Once I approve, write the migrations and seed three projects of deliberately different shapes: one with two boards, one with sixty tasks, one whose tasks have no due dates.

    Settle the access question in the plan rather than after it. Owner-only is a genuinely good answer for one person with several clients. Members is the answer if colleagues are coming. What you cannot afford is finding out in step 05, because changing it then means regenerating every policy and every view’s query, which on a token meter you feel twice.

  3. 03

    The board, checked in the running app rather than described

    The first view, and the one where the preview is the whole test. It is the running app, so a card that does not stay put is something you can see in ten seconds.

    PromptBuild the board
    Build the Kanban board over the model. Columns in their stored order, task cards inside them in theirs, drag-and-drop within and between columns, a count on each column header, and a card showing priority, assignee, due date, and counts of subtasks and comments. On drop, write the new position and column to the database, then reconcile the screen against what came back rather than leaving a move the database refused. Tell me whether a drop rewrites one row or every card in the column, and what happens if two people reorder at the same moment. Then, in the preview: drag a card, reload, and confirm it is still where I put it, and open the app in a second browser window, drag a card in one, and say plainly that the other window does not update, because live updates are not in this prompt.

    Do that second-window check yourself rather than taking the answer. It costs you a minute, it makes the next step concrete, and it is the moment the difference between a board that draws state and a board that shares it stops being an abstraction.

  4. 04

    The other three views, then the feed: two prompts, context cleared between

    Three views over the rows already on screen, then the subscriptions. These are unrelated enough that clearing context between them is worth doing, and cheap.

    PromptAdd the other three views
    Two prompts, and clear your context between them. First, the remaining three views over exactly the same tasks, with no new fields and no second source of truth: a list view sortable and groupable by column, priority, assignee and due date, filterable, editable in place, with subtasks nested under their parent. A calendar view on a month grid by due date, with a labelled place for tasks that have none rather than dropping them. A timeline view drawing a bar from a task’s start date to its due date, handling a missing start or end honestly instead of inventing a range. Second, live updates: subscribe to changes on projects, boards, columns, tasks, comments, time entries and notifications, feeding one shared cache so a single change reaches all four views rather than each screen re-fetching. Tell me which tables I have to enable realtime on in Supabase, since it is off by default. Then prove it in the preview: two windows, a card dragged in one, the list and the calendar moving in the other.

    Point the second prompt at the specific files the first one created rather than letting it read the whole project. Views and subscriptions barely overlap, and a prompt scoped to a handful of files is both cheaper on the token meter and less likely to come back having quietly rewritten a view you were happy with.

  5. 05

    Sign-in, the rules, and the feed tested from another account

    Everything your team is working on is now in a database with a live feed on it. This is the prompt to read carefully rather than approve quickly.

    PromptAdd auth and the access rules
    Add Supabase Auth with email and password: sign-up, login, logout, a persisted session, a profile row per account created by a trigger, and a useUser hook. Then row-level security on every table, matching the access shape we settled in the step 02 plan. Owner-only: a person reads and writes their own projects and everything beneath them, and a task is additionally readable and updatable by its assignee, and if that is the shape, tell me plainly that an assignee cannot open the board their task belongs to, and offer the smallest policy change that would let them. Members: a membership row grants access, and every policy on boards, columns, tasks, comments and time entries checks it through one SECURITY DEFINER function rather than repeating a subquery per policy. Either way: explicit WITH CHECK on every insert and update, notifications readable only by their addressee, and a deliberate decision about the accounts table, since reading only your own row is the safe default and it means an assignee picker returns one name. Then, in the preview with a second account, prove four things: it cannot read my project, cannot read my tasks, cannot read my time entries, and does not receive my rows through the realtime feed.

    The fourth check is the one that justifies the order of this whole build. A subscription is a read, and before the policies exist it delivers rows the ordinary query path would refuse, so a second account in a second window is the only instrument that finds it.

  6. 06
    Destination

    The drawer, the dashboard, then publish

    Subtasks, comments with files, the timer, the notifications, the charts, then a day worked through with two accounts, and only then a deploy.

    PromptFinish the task, the dashboard, and rehearse
    Finish the app. The task drawer: description, priority, due date, assignee, subtasks I can add and tick off, and a comment thread with file attachments served through signed URLs with an expiry, generated for somebody allowed to see the task, rather than a public bucket. Then time tracking: a start/stop timer on a task, one running entry per person, entries that survive a reload, and a database trigger totalling them onto the task so no component is doing that arithmetic. Then notifications raised by triggers on assignment and on comment, arriving live in a dropdown. Then a dashboard: tasks by status, overdue work, workload by assignee, and where tracked time went, with the headline counts computed server-side and scoped to the signed-in account. Then walk me through a working day with two accounts in two browser windows: create a project, fill a board, drag a card and watch the other window, assign across accounts and see the notification arrive, run a timer and confirm the task total moves, post a comment with a file and check what the other account can and cannot open, and confirm the dashboard agrees with all of it. Then publish, and tell me which environment values I have to set on the host for the deployed app to find the database.

    That last question is the one to ask before you tell anybody the address. A build that cannot find its database URL and key does not show an error, it shows an empty board, which looks exactly like a tracker nobody has put anything in yet, and is the single most common way this app appears broken on day one.

Authentication & security

Who sees what and how your data stays safe

A project tracker stores sensitive details: client budgets, internal notes, and confidential attachments. Here is how to keep your workspace secure and prevent accidental data leaks.

Hand off authentication to standard services

Use built-in database authentication for sign-ups, password resets, and user sessions. Building custom login systems adds unnecessary security risks with zero business upside.

Define clear project ownership and team roles

By default, a project belongs to a single owner while assignees view their tasks. Ensure your access rules allow team members to view the full boards their tasks actually live on.

Protect team profiles and user accounts

Users should only access necessary teammate details like display names and avatars. Restricting full user account rows prevents exposing sensitive user profile data across your workspace.

Enforce security in the database, not the design

Hiding a card in the interface doesn’t make it secure. Setting security rules directly inside the database guarantees that permissions stay intact across every view and future feature.

Test permissions with multiple user accounts

A workspace often looks fully secure when you are the only person signed in. Test access rules with different user roles before launching to spot hidden permission gaps early.

Secure real-time feeds against data leaks

Live updates and instant feeds must obey the exact same security rules as standard queries. Otherwise, real-time updates can accidentally push hidden task details to unauthorized users.

Use private links for file attachments

Public file URLs allow anyone with the link to access your documents. Switch to private, expiring links to protect internal contracts, client screenshots, and sensitive uploads.

Restrict notification preview content

Notifications often include task comments or status updates. Ensure notification feeds inherit access rules so sensitive details aren’t exposed through activity alerts.

Scope dashboard metrics to authorized data

Task counters and dashboard summaries can quietly reveal project activity across restricted boards. Ensure overall totals only count items that the signed-in user is permitted to see.

Treat tracked time as sensitive employee data

Time logs record work patterns and daily schedules. Decide who can view teammate hours upfront and ensure your time-tracking policies align with local privacy obligations.

Enable daily backups before going live

Free database tiers do not create automatic backups of your tasks, discussions, or history. Upgrade to a paid tier ($25/mo) for daily backups before your team relies on this tracker as their main workspace.

PromptCheck who can see what
Review the access rules (row-level security policies) on every table. For each one, tell me in simple terms who can view, add, edit, and delete records, confirm that people can only reach their own data while the right roles can reach more, and flag anything left open that shouldn’t be.

Paste this into the chat before launch so Bolt checks nobody can see data they shouldn’t.

One rule outranks the rest here: the database service key and any AI provider key live on the server and nowhere else: not in the app your team downloads, and not in a public repository. Treat either one that escapes as burned, and replace it the same day.

Workflow rules

What speeds the build, and what slows it

Speeds the build

  • Using Plan Mode to talk a change through before Bolt writes any code
  • Pointing a prompt at specific files or functions instead of the whole project
  • Clearing Bolt’s context between unrelated features, so each prompt has less to process
  • Checking the live preview after each change, since it’s the running app itself
  • Reading the automatic GitHub commits later as a real history, not just a backup

Slows the build

  • Asking for a whole app in one prompt instead of one screen or rule at a time
  • Leaving context loaded from a finished feature while starting an unrelated one
  • Editing the repository directly on GitHub and expecting Bolt to pick it up before its next 30-second check
  • Approving several prompts in a row without checking the live preview after each one
Before you open Bolt

GitHub: the way in, not just a backup

Bolt can’t open a .zip file, so the only way to start a project is to import a GitHub repository. Every other tool in this set treats GitHub as optional, but Bolt treats it as step one.

Why this comes before Bolt

There’s no upload button for a folder or a .zip. Opening a project in Bolt means pointing it at a repository that already exists on GitHub, so a home for the code has to exist first.

Create a free account, then a repository

Sign up, then create a new, private repository for your project and push your files to it. Keep it private, and never commit secret keys or passwords.

Create a free GitHub account

Import it into Bolt

On bolt.new, connect your GitHub account, choose the repository from the list, and click “Import repository”. The project opens straight into a live preview.

After that, it stays in sync on its own

Bolt commits each working change back to that repository automatically, and checks GitHub every 30 seconds for anything pushed from outside it. A commit is a snapshot with a short note, like “added the home page,” and Bolt writes those notes for you.

Version control and GitHub, Bolt docs

It’s also how you leave, if you ever want to

The repository Bolt is syncing is a real, ordinary codebase: clone it, hand it to someone else, or keep working on it directly on GitHub whenever you’re away from the browser tab.

Going live

Where to host your application

Hosting gives your app a home on the internet so anyone can open it via a web link. Choose a service below to make your site live. (Your database, logins, and business records are stored separately in Supabase, covered below).

HostBest forNotesFree tier
VercelOne-click deploysConnect the repository and every push ships itself, with no configuration for a Vite project. Check which plan you belong on first: Hobby is licensed for personal, non-commercial use, and software your company runs its projects through is commercial however few of you there are, so Pro, at $20/user/mo.Pro from $20/user/mo (Hobby is non-commercial)
NetlifyDrag-and-drop or GitPoint it at your repository, or drag the built folder onto the page and be live in a minute. Do add the redirect rule it asks for: skip it and a URL aimed straight at one task answers not-found, which is the URL this app exists to hand out.Free tier
Cloudflare PagesTeams in several countriesThe app is served from wherever the person opening it happens to be. The case for it is a team spread across time zones, which is also the case where two people watching one board update is worth testing rather than assuming.Generous free tier
GitHub PagesNot really this appFree publishing straight from a GitHub project, after one routing setting. Listed to be ruled out: free means a public repository, and this repository sits next to every project your team runs and every file dragged onto a card.Free from a public repo only
Firebase HostingTeams already on GoogleOne round of configuration, then one command per release forever. No argument for it comes from the app itself. The argument is that your logins, documents and calendars are already Google.Free Spark tier
AWS Amplify HostingTeams already on AWSDeploys from the AWS console, and wants the same rewrite rule so a link to one task lands on it. You pick it because AWS is already on the invoice.Free tier (build + hosting)
SurgePublish from the terminalOne command puts the built folder online, no repository involved. Handy for letting a colleague try the board before you commit. Wrong for the address people bookmark.Free - unlimited publishing
DigitalOcean App PlatformDigitalOcean usersBuilds and serves inside the DigitalOcean account you already have. The whole case is one fewer supplier and one fewer invoice, which in a small company is a real one.Free - 3 static sites, 1 GB/mo transfer

All eight serve the app well enough that speed is not the deciding question. Three others are. Does the plan permit commercial use, given Vercel’s Hobby tier does not and a tracker your company works in is commercial by any reading. Does it publish from a private repository, given what this code sits beside. And does a deep link resolve for a browser that has never seen your site, because a URL pointing at one task is the link your team will share most.

One thing to check on the day you go live, and it is not the hosting. The live feed only works on tables you enabled it for. A board that has stopped updating in a second browser is the failure your team meets on day one and you never do, because you are usually the only person looking.

Database & backend

Keep your data in Supabase

Projects, boards, tasks, comments, attachments, tracked time, and the accounts they belong to. This is also where the rules deciding who may read which project live, and where the live feed comes from.

ServiceBest forNotesFree tier
SupabaseData, auth, files, live updatesProjects and tasks live in Postgres, accounts come out of its auth service, attachments and avatars go to its storage, and its realtime feed is the thing keeping your board, list, calendar and timeline in agreement across two browsers. Setting it up is opening a free project and handing the app two values: the project URL and the publishable key. The detail to remember afterwards is that realtime is opt-in per table, so it does nothing at all until you switch it on for each one.Free tier, then usage-based
AI workflows

Where AI genuinely helps a project tracker

There is no AI anywhere in this template, so the first prompt below is two pieces of work in one: it adds a feature, and on the way it creates the single server-side function the other four call through. Each of the rest is then one request.

Turn a wall of notes into tasks you can drag

Most projects begin as a page of meeting notes or a long message, and the tax is retyping it into cards. This is the right first feature: contained, useful the day it lands, and it never writes to your board without you.

PromptTurn a wall of notes into tasks you can drag
Build me a server-side ai function (a single place, with my provider key on it and nowhere else) plus a screen where I can paste notes, a message, or a brief. Send the text to that function and get back proposed tasks: a title, a one-line description, a suggested priority, an assignee only where the text names somebody, and a due date only where the text gives one. Show them as a reviewable list I can edit and delete from, then create into a board I pick, with nothing written until I press create. Where the text is vague, say so rather than inventing a date: “next sprint” comes back as no date and a note saying why, not a Friday you chose.

A weekly summary drawn from what actually happened

The status update is the most-resented recurring task in any team, and it is derivable: the board already knows what moved, what slipped, and what nobody touched.

PromptA weekly summary drawn from what actually happened
Add a “summarise the week” action on a project that gathers what changed over a date range I choose (tasks created, tasks that moved column, tasks completed, due dates passed unmet, and comment activity) and sends only that activity summary to my ai function, with no attachment contents. Have it return a short written update in three parts: what moved, what is stuck, what is due next. Compute every count with a query and let the model only do the writing, so no figure is invented. Print the date range on the result, and where a section is empty say nothing happened rather than padding it.

Find the work that has quietly stopped moving

Every board grows a layer of cards nobody has touched in a month and nobody wants to close. Surfacing them is easy arithmetic. The useful part is a sentence about why each looks stuck.

PromptFind the work that has quietly stopped moving
Add a panel listing tasks that look stalled (no column change, no comment, and no tracked time for a number of days I set), sending each one’s title, age, column and last activity to my ai function for one line on what appears to be blocking it and one suggested next step. Send no attachment contents and no comment text beyond the most recent. Order by how long each has been still, show the actual dates beside each row so I can check the reasoning, and where there is too little activity to say anything useful, have it say so rather than guess.

Estimate from your own history instead of your optimism

Once a few hundred finished tasks carry time against them, the tracker knows something you do not: how long this kind of work really takes here. Better than anybody’s instinct.

PromptEstimate from your own history instead of your optimism
Add an estimate suggestion on a new task. Query my own completed tasks for similar ones (same board, similar title, same priority) with their tracked totals, send those durations and titles to my ai function, and have it return a suggested range plus one line naming which past tasks it drew on. Show the sample size beside the suggestion, and refuse to suggest anything from fewer than five comparable tasks rather than guessing. It is a suggestion in a field I can overwrite, never a value written automatically.

Ask your own board a question in plain words

Your dashboard answers the questions you had when you built it. What comes up later (“which projects slipped this quarter”, “where did the time go”, “who is carrying too much”) are queries you should not have to build a screen for.

PromptAsk your own board a question in plain words
Add a panel where I ask a question about my own projects in ordinary words and get an answer with the numbers behind it. Have my ai function turn the question into a read-only query over my own data, run it under my own access rules so it can never reach a project I cannot see, and use the model only to explain the result. Show the query it ran and the figures it used under every answer, state the period and the number of rows involved, and where the sample is too thin to support the answer, say so.

Pick a lighter model for the high-volume prompts above and save a stronger one for wherever the reasoning actually matters. That is the same token-budget logic as the rest of this page, applied to the app’s own AI calls instead of the build itself. When Bolt flags a missing secret, add the key through its secrets settings instead of pasting it into the chat, and keep every AI feature behind one server-side function so there’s only one key to manage.

Ready-made option

Get a head start with our template

All three routes above start at an empty folder, and that is not the only available starting line. This tracker already exists and already runs, so the weeks that four agreeing views, live updates, and tracked time that adds up properly would have taken become an afternoon of typing in your own projects.

Project & Task Manager

The exact project tracker this guide builds, packaged so you can open it, point it at your own backend, and make it yours from there. A project workspace where your team's work lives in projects and boards and then shows up however suits you, as a Kanban board, a list, a calendar, or a timeline. You assign tasks, track time, comment, get realtime notifications of changes, and watch progress add up in the analytics.

React 18ViteTypeScriptTailwind CSSSupabase
Out of the box

The key benefits of starting with a template

The four views already read one model, the board already remembers where you dropped a card, and every screen already updates itself. That is most of what this saves you. Behind it, subtasks, comments with attachments, the timer, the notifications, and the dashboard are done too.

Building the core from scratch

~118 hrs

Opening the template, already built

~1 hr

~117 hrs of building you skip

Two measurements of deliberately different things. Building it yourself is the ~118 hrs. Adopting the built one is the ~1 hr: open it, aim it at a database of your own, and get a first project and a real board in. Working out your columns, your fields and your definition of done costs the same on either path, so neither figure includes it.

Four views over one set of rows

A Kanban board with drag-and-drop between columns, a list you can sort and filter, a calendar over due dates, and a timeline, all reading the same tasks, so a change in one is a change in all four. Position is stored per task, which is why a card you moved is still where you left it after a refresh and in somebody else’s browser.

Live updates already wired through every view

Subscriptions on projects, boards, columns, tasks, notifications and time entries, feeding a query cache rather than re-fetching the world, so a card moving, a comment landing, or a timer starting shows up without a reload. Fiddly to add later and invisible when it works, which is a bad combination to be building under deadline.

The task, with everything hanging off it

Priority, description, due date, assignee, subtasks (tasks with a parent, so they inherit the board and column rather than living in a second model), comments with file attachments, and a start/stop timer whose entries roll up into the task’s total through database triggers rather than arithmetic in a screen.

Accounts and 85 declared policies over them

Email-and-password sign-in with a profile row per person, and 85 row-level security policies declared across the migrations as the rules were written and tightened, settling on a project owned by one account, with a task also readable by whoever it is assigned to. Read the honest note in the security section above before you plan a shared workspace on top of it: making this a several-people tracker is a described addition, not a setting.

A dashboard and analytics that already count something

Completion, workload, overdue work and where the tracked time went, drawn as charts, with the headline counts coming from a server-side function scoped to the signed-in account rather than a query the browser could widen. Plus notifications raised by database triggers when a task is assigned or commented on, arriving live in an in-app dropdown.

A codebase your AI tool can keep extending

Everything typed, hooks grouped by what they query, folders named after features instead of file extensions, and a comment anywhere the reasoning would not survive a cold read. The views are where that returns the favour: a fifth one is the change you are most likely to ask for, and the four already there demonstrate how a view is supposed to put its question.

Customer story

From founders who build on our templates

We needed a working product in front of users fast. I started from one of these templates instead of a blank repo, customized it in our AI tool, and shipped in days - not the weeks it usually takes.
Jeevan ThomasJeevan ThomasFounder & CEO, Hado.ai
Got questions?

Common questions

As it ships, personal, and this is the first thing to know before you compare it with anything. A project belongs to one account, and the rules on boards, columns and time entries all check that ownership. A task is additionally readable by its assignee, but the board it sits on is not, so a colleague cannot open the board. There is no invite flow, no membership table, and no roles. Making it a genuine several-person tracker is a well-defined addition (a record of who is on which project, and every rule consulting it), and it is a described step in the build below. If you are one person with several clients, none of this is a limitation.

No, and getting that right is most of what makes this application cheap to change. The board, the list, the calendar and the timeline are four ways of asking about one table of tasks: which column and in what order, how to sort several hundred, which have a due date this month, which span a range of days. Build them as projections of one model and a fifth is an afternoon. Decide early what the timeline reads, though: a bar needs a start as well as an end, and most task records only carry a due date until somebody insists.

No. Notifications are rows written by database triggers when a task is assigned or commented on, and they arrive live in a dropdown inside the app. No mail provider sits anywhere in it, so nothing reaches an inbox or a phone. Connecting an email service is a small, well-defined addition, and it is the one most teams want first: a tracker nobody has open is a tracker nobody reads, and one email a day is usually the difference.

That your screen changes when somebody else changes something, without you reloading. The app subscribes to changes on the tables it cares about and updates its own cache as they arrive, which is why a card dragged in one browser moves in another within a second. Two practical notes: the feed is opt-in per table, so it does nothing until you enable it, and it hands out rows like any other read, so your access rules have to apply to it, or it becomes the one place they do not.

No. This is the half an AI coding tool is best at. Say what you want to happen in ordinary language and you get back the tables, the accounts, the rule deciding who may open which project, the stored position that keeps a dragged card where you dropped it, the triggers that total tracked time onto a task, and the subscriptions that keep four views in agreement. The part left to you is opening a free Supabase project for all of it to be written into.

One level, and it is worth knowing how it works: a subtask is an ordinary task with a parent, inheriting the parent’s board and column rather than living in a separate model. That is a good design (everything that works on a task works on a subtask for free) and it means going deeper is a change to the interface rather than the schema. Resist deeper for a while: a checklist inside a task is usually what people actually wanted.

A timer you start and stop on a task, writing entries against a person, with database triggers totalling those entries onto the task itself, so the number on the card is arithmetic rather than a field somebody remembered to update. It records time rather than billing or invoicing for it. If billing is the point for you, the total per task per person is the figure you would export, and that is a query rather than a feature.

Yes, on comments, and the second half of that question needs a real answer rather than a reassuring one. The template writes careful storage rules checking whether the reader uploaded the file, owns the project, or is the assignee, then makes the bucket public so the URLs work, which takes reads back out of those rules. Anybody with the link can fetch the file. For internal notes that may be fine. For a customer’s document it is not, and signed expiring links are a short change the security section above spells out.

Yes. Columns are rows in a table, not code, so renaming, reordering, or adding one is data. What is worth deciding deliberately rather than drifting into is the rules around them: whether anybody may move any card or only its assignee, and what happens to a card once it is done. Two sentences that save a lot of arguing, and much cheaper now than once your team has habits.

The bill has two lines, somewhere to hold the data and somewhere to serve the app, and both have a free tier. When your team is genuinely working in it, the upgrade to make is Supabase Pro from $25/mo: partly for the file storage attachments consume, mostly to stop the pause, because a free project sleeps after a quiet week and a sleeping tracker sends everybody back to a spreadsheet. Nothing else on that bill responds to somebody joining. Add an AI feature and you also pay whichever model you call.

Nothing here is proprietary. Your projects, tasks, comments, and time entries sit in plain PostgreSQL tables any Postgres host will accept from a standard dump, and the attachments are files you can copy like any others. That is worth more than it sounds here: the comment thread explaining why something was built that way exists nowhere else, and it is exactly what makes a platform expensive to leave.

Yes, and do it before anybody bookmarks anything. Each host above attaches a domain in a few clicks, HTTPS included. The reason to hurry is unglamorous: this is an app whose URLs get pasted into chat all day long, and every link shared before you move is a link that breaks the moment you do.

No. You describe what you want in the chat and Bolt writes the code and shows it running in the same tab. The one extra step Bolt asks for that other browser tools don’t is a GitHub account, since that’s how a project gets in. The setup section above covers it.

Bolt only opens projects from a GitHub repository, and it offers no upload button for a folder. Once it’s imported, Bolt keeps the two in sync automatically, so the extra step up front replaces a manual export later.

Free resets daily, and a paid plan’s monthly allotment resets on your billing cycle (unused Pro tokens also roll over one extra month). If you hit the cap mid-session, what you’ve built stays exactly as it is. You wait for the reset or buy more tokens to keep going right away.

References

Sources checked August 2026
  1. 01Breaking down the infinite workday (Microsoft Work Trend Index special report, June 2025). microsoft.com (report published June 2025)
  2. 02Pricing (per-user tiers, free-tier limits, the Premium views feature line), Trello. trello.com
  3. 03Pricing (per-user tiers, both billing bases, free-tier user cap, Timeline and Gantt on Starter), Asana. asana.com
  4. 04Pricing (per-seat tiers across product lines, 2-seat free plan), monday.com. monday.com
  5. 05Pricing (per-user tiers, free-tier storage cap, separate AI plans), ClickUp. clickup.com
  6. 06Pricing (per-user plan and flat-rate unlimited-user plan), Basecamp. basecamp.com
  7. 07Pricing (Pro plan, free-tier limits, project pausing), Supabase. supabase.com
  8. 08Web developer hourly rates 2026 (freelance and agency benchmarks). developex.com
  9. 09Row Level Security, Supabase docs. supabase.com
  10. 10Postgres Changes (realtime), Supabase docs. supabase.com
  11. 11Storage access control, Supabase docs. supabase.com
  12. 12Pricing (Free, Pro, Teams), Bolt. bolt.new
  13. 13Version control and GitHub, Bolt docs. support.bolt.new
  14. 14Connect Supabase, Bolt docs. support.bolt.new
  15. 15What is Bolt Cloud?, Bolt docs. support.bolt.new
  16. 16Netlify deployment (and Bolt hosting by default), Bolt docs. support.bolt.new
  17. 17Maximizing token efficiency, Bolt docs. support.bolt.new

This guide is general information, not legal or employment advice. What you may record about how long an employee worked, and how long you may keep it, varies by country and by state, so check your own rules before you switch time tracking on for other people. Third-party prices, plan terms, and market rates are quoted from the sources above and were last checked on the date shown. Vendors change them without notice, so confirm before you budget. Build hours and the cost estimates derived from them are our own estimates, not quotes. Bolt is a product of StackBlitz. Verify current capabilities and pricing before relying on them.