For outlets and franchisees
The system your brand picked, built so it is worth your time too
Most franchise software is bought by head office and paid for in your evenings. This one starts at the counter: the day closes in one screen, the cash count is a real check, the royalty bill shows its working, and a request to the brand has a due date on it.
- The day
- declared, counted and closed by you
- Cash over / short
- counted blind, then compared
- Prime cost
- cost of sales + labour, against 60%
- Royalty due
- shown with the arithmetic behind it
Start here
What your day actually looks like
Before anything about the product: this is the day we built it against. If it does not sound like yours, stop us — a page that does not describe your outlet is not worth reading.
What breaks now
- The day’s takings go out as a WhatsApp message. Nobody can reconcile that message six weeks later, and the royalty computed from it inherits every typo.
- You count the till after reading what the till says you should have, so the count agrees with the machine and finds nothing.
- A royalty invoice arrives with one number on it. The only way to question that number is to argue about it.
- Attendance is a paper register. When a shift is disputed there is nothing to point at, and the labour line on your P&L is a guess.
- A request to head office — a discount, a broken chiller, a supply shortage — sits in a group chat with no owner and no due date.
- The trade licence renewal is remembered late, and the inspection that follows is a surprise.
- The brand asks for numbers you already typed into two other places.
Everything below is one workspace you log into, on a phone at the counter or a laptop in the back. Records are unlimited; what the brand pays for is an outlet that has its own logins, which is what switches trading on.
Double entry is the thing we treat as the enemy. Every screen here either replaces a message you were already sending or produces a number you were already being asked for.
The line to leave in the room If this only makes the brand’s life easier, you will stop using it by March. So the first four chapters are yours.
One screen
Open, trade, count, close
First, what this is not: it is not a POS. It does not run a till, print a bill or hold your menu. It records the day — declared, counted, closed and defensible — and it reconciles against your POS export. The trading day is one record with one API call behind it: the guided steps, the takings, the tender split, the cash count and the evidence all arrive together, so a shared counter tablet on two bars of signal still loads.
The trading day
- One screen for the whole day Module ↗
One request returns the guided steps, the KPI strip with 14-day sparklines, the day itself and its evidence — no navigating between screens to answer “how are we doing” and “am I done”.
The screen you use forty times a day loads once and stays useful, instead of costing you four page loads on outlet wifi.
- The guided rail: open → trade → handover → cash up → close Module ↗
The server decides which step is now and which steps exist at all for your kind of business, so an outlet that does not run shifts never sees a handover step.
A new person can close the day correctly on their second shift without being trained on a sequence.
- Opening the day cannot fork it Module ↗
Opening finds or creates the day for that outlet and date, with a unique index on (outlet, date) in the database behind it.
A double tap on a slow phone cannot produce two half-recorded days — which is the single most common way an evening’s takings get lost.
- Quick entry: amount, tender, done Module ↗
One line per sale with how it was paid and where it came from, recomputing the day as it goes.
A counter that is not running a POS still produces a day record you can stand behind at month end.
-
The entry API accepts a caller-supplied id and a unique index makes a replay return the same entry instead of a second one. The console form does not send one yet and there is no offline queue in the app, so a retry from the browser today creates a duplicate.
The protection is in the database rather than in an app check — but until the console sends the id, treat a failed tap as something to check before you tap again.
- Your declaration is the record; entries are the evidence Module ↗
While nobody has stated a figure the day mirrors the sum of its entries exactly. The moment you declare a number, entries stop steering it and the gap is stored as variance.
An outlet that taps in every sale never has to “also declare”, and an outlet that declares a different number has that disagreement on the record instead of smoothed away by software.
10 more in this group
- Tender and channel are two different questions Module ↗
How the money arrived — cash, UPI, card, wallet, bank transfer, credit, aggregator settlement — is recorded separately from where it came from: dine-in, takeaway, delivery aggregator, own online, walk-in, institutional.
“Half our takings are UPI” and “half our orders are delivery” are different facts about your business, and they stop being collapsed into one gross figure.
- Blind cash count Module ↗
You commit a denomination grid — ₹500 down to ₹1 — and only then does the server compute and return over or short. Expected cash never leaves the server for an uncounted day.
A count made after reading the expected figure will always find the missing ₹160 somewhere. Counting blind makes the count a check rather than a formality.
- Expected cash is only what is in the drawer Module ↗
Expected cash is the opening float plus cash-tender takings plus cash movements. UPI, cards and aggregator settlements are deliberately excluded.
Aggregator money is booked today and paid days later. Counting it would manufacture a shortage every single evening and destroy any trust in over/short.
-
Paid out, paid in, deposit and float adjust, each with a grouped reason — supplies, staff advance, maintenance, utilities, owner draw, bank deposit, change float, correction — and expected cash recomputes on every one. The API and the typed client hook are shipped; there is no button for it on the day screen yet.
Over/short stops being an argument about a ₹300 courier payment nobody wrote down, and because the reason is a fixed list your petty cash becomes reportable.
- Closing is one-way Module ↗
A closed day accepts no edits, no deletes, no new entries and no reopen. Every write path checks the lock first.
The number you reported and the number you were billed on stay the same number, so a period that has been invoiced is history rather than a moving target.
- A mistake on a closed day rides forward, signed Module ↗
You correct a closed day with a signed adjustment dated into your current open day, pointing back at the closed one with a reason code — missed sale, duplicate entry, wrong tender, wrong amount, refund after close, POS correction, other. The closed day is marked amended and otherwise untouched.
The correction reaches the money without reaching back into a period that has already been billed, so nobody has to reissue a statement to fix ₹900.
-
A named shift opens with its own float and closes with its own declared take, tender split, cash count, over/short and a handover note stored verbatim; opening the next shift closes the previous one. The API and the client hooks are shipped, with no control on the day screen yet.
The handover is the accountability moment in an F&B or salon outlet, and a handover the software can silently recalculate is not a handover.
- The day summary you send yourself Module ↗
The close-of-day text is built on the server — date, outlet, net, sale count, tender split, cash balanced or over or short, adjustments, and this day against the same weekday last week — and offered as a pre-addressed WhatsApp link with a QR beside it for the counter tablet.
The close that feeds head office pays you first, with a number you can send your own owner in one tap. It is a deep link, never the share sheet, so it cannot be fat-fingered into the wrong chat.
- Tuesday against last Tuesday Module ↗
Every day carries net against the same weekday a week ago, plus week-to-date and month-to-date, with 14-day sparklines where a missing day is a zero rather than a gap.
Same-weekday is the only sales comparison an operator actually trusts, and a zero reads as “closed on Tuesday”, which is what happened.
- Today, as a list of things to do Module ↗
The outlet home returns today’s takings and transactions, month-to-date, royalty outstanding, whether today has been recorded, and alerts for royalty due, reports still owed, expiring licences and open corrective actions.
Your home screen is four things to finish, not a dashboard somebody in head office designed.
Close of day — 21 August, illustrative
The card the outlet sends itself, built on the serverIllustrative figuresExpected cash excludes UPI, card and aggregatorCounted before the expected figure was shown
The surface itself
- The whole console in Hindi
Each person picks their own language in account settings; anything not yet translated shows in English rather than as a blank, and the page switches to a Devanagari-capable face when Hindi is on.
The manager can work in English and the person closing the day can work in Hindi, on the same record, without either of them being the one who compromises.
- Install it on the counter tablet like an app
The console adds to the home screen with its own icon and opens full-screen with the shell already cached, so it loads on a bad connection; sales data is never served from cache, and an update asks before it reloads.
The screen you use forty times a day is one tap from the home screen and does not reload the whole app every time you open it.
- A form and a QR for anything you need answered Module ↗
You build a form with your own fields, mark it a survey or a checklist rather than an enquiry form, publish it to its own link with a printable QR, and read the submissions back. Only an enquiry-purpose form creates a lead.
A counter feedback card, a shift opening checklist or a staff form is something you make in ten minutes instead of asking head office for.
Not built yet — on the plan
Nothing in this group is built yet, and every row is tagged that way. It is here because you will ask, and because a roadmap you can argue with beats one you find out about later — what we build next should be decided by the people paying for it, so tell us which of these actually blocks you.
-
The POS you already run posts each day’s sales, tender split and item mix into the trading day, and the declaration is pre-filled from it.
You stop typing a number into a second system at eleven at night, which is the whole reason day capture gets skipped.
-
You order from the brand’s approved suppliers in the same app, against par levels, and the goods received post to cost of sales.
One place for the order, the receipt and the cost, so the number you argue about with the supplier is the same one on your P&L.
- An app in the store, with notifications Not built yet
A native app for the counter and the owner’s phone, with push notifications for a licence about to expire, a royalty due and a decision from head office.
The things that cost you money when you miss them find you, instead of waiting on a screen for you to open it.
- The rest of the Indian languages Not built yet
Tamil, Telugu, Marathi, Kannada, Bengali and Gujarati join English and Hindi, picked per person rather than set for the outlet.
The person closing the day works in the language they think in, which is what decides whether the day gets closed properly at all.
The line to leave in the room The day is a record you can defend, not a message you hope somebody read.
The asymmetry, stated
What the brand can and cannot see
You are about to type your sales into this, so before anything else: here is exactly what the brand reads and what it does not. Some visibility here exists because your franchise agreement grants it. We are not going to pretend otherwise — but where the product can hold a line without breaking the agreement, it does.
What the brand sees, because the agreement says so
- Your declared sales for the period, and the report you submitted as the royalty basis.
- Your royalty statements and the invoices raised against them, including what is outstanding.
- Your compliance register — a brand’s network portfolio shows a register per unit alongside its own head-office one.
- Audit and visit scores, findings, and the corrective actions raised from them.
- Whether you filed this month’s report at all — missing reports are a board, not a surprise at close.
- Opening sign-offs: only the brand can approve a gate on an opening project.
Where the product holds a line
- Staff go up as an aggregate, not as punch histories Module ↗
The staff summary endpoint returns headcount, total minutes, shift count and the share of shifts that were self-evidenced for an outlet and a date range. It carries no names and no punch rows.
A franchisor gets the labour figure it needs to read a P&L without holding an individual’s attendance history, which is personal data under the DPDP Act that they have no need to hold. Note this holds because your staff records live in your workspace — it is a property of where the rows sit as much as a rule in the code.
- Area developers see rows, not amounts Module ↗
An area-developer workspace has royalty and sales amounts redacted while the rows still list, and the audit queue, clearing splits and local-spend breakdown are refused outright.
A territory developer can do the development job without being handed every unit’s P&L.
- Every action is behind a named capability
Forty-seven named capabilities, default-deny, with role defaults per workspace type — an outlet’s roles use outlet words: manager, senior staff, staff, support, trainee — and per-person grants or revocations on top.
You give one person the money screens by name instead of promoting them to admin and handing over everything else with it.
- A refusal says why, and who can fix it
A refused action returns the reason — capability, desk, operator scope, feature off, AI budget — the capability needed, and the names of the people in the workspace who can grant it. The button greys out and says so rather than disappearing.
Nobody raises a ticket saying “the button is missing”. They read who to ask and ask them.
- Support access is bounded and recorded
Platform support can only enter a workspace with a stated reason, for sixty minutes, in a mode chosen at the time — and a denylist blocks settings writes, access grants, member management, password changes and the whole control plane even in full mode.
When you call for help somebody can see what you see without being able to change your permissions or your team while wearing your name.
- An append-only audit log that survives impersonation
One write path appends action, actor, subject, evidence and IP to a table with no update, and automatically stamps the real admin when someone is impersonating and the seat plus the on-behalf organisation when an operator is acting.
“Who actually did this” survives support access and outsourced operations, which is exactly when you want to be able to ask it.
4 more in this group
- Consent as a receipt, not a checkbox
Each consent record stores the person, the purpose, the legal basis, the collection point, the method, an evidence bag with IP and user agent, and a hash of the notice version shown. Withdrawal appends a new row referencing the grant rather than editing it.
Under the DPDP Act you can show what was agreed to, when and against which notice text — for the customer data you collect as well as your own.
- A rights queue with the response clock on it
Access, correction, erasure, grievance and nomination requests run through a guarded state machine with a 30-day response target set at intake — our default rather than a statutory number, and configurable, because DPDP sets an outer ceiling and expects the brand to publish its own window — identity verification as a first-class step, and an audit row on every edge. Disclosure is blocked until identity is verified.
The illegal shortcuts are closed by the software: nobody discloses to an unverified requester, and nobody jumps a request from received to fulfilled.
- Erasure that does not delete your books
Erasure is planned before it runs — the confirm screen groups the person’s mapped columns into what will be nulled, what will be tokenised and what is under a statutory hold — then executes per column and resolves the request as partially fulfilled when a hold remains.
You honour an erasure request without deleting a GST invoice you are required to keep for six years, and the request says so honestly.
- A data map CI will not let go stale
Every column holding personal data is declared in a code register with its category, purpose, how rows for a person are found and its erasure strategy — and a build check fails when a known personal-data column is unmapped.
Adding a personal-data column without registering it stops the build instead of quietly creating a column an erasure would miss.
Two things we will not overstate
Compliance records carry a brand-only visibility flag. It is stored and returned, and it does not currently filter anything — today’s separation comes from your workspace being a separate workspace, not from that toggle.
A visit’s report can be released to you as a recorded act. Withholding one is not settable through the API today, and the flag does not itself hide a report from you.
The line to leave in the room The brand sees the numbers your agreement gives them. It does not get your staff’s attendance history, and every entry into your workspace leaves a row.
The floor
Staff, shifts and leave
Labour is your largest controllable cost after stock, and the one your staff will dispute. So it is a ledger, not a notebook.
- Staff records at the outlet Module ↗
Name, phone, role, employment type — full time, part time, contract, trainee — joining date, monthly CTC and an opaque payroll reference, held against the outlet they work at.
Who works here is a record rather than a WhatsApp group, and the labour line on your P&L has names behind it.
- One open shift per person, refused by the database Module ↗
A punch-in writes the person into a column carrying a unique index, so a second open session is refused by the storage layer rather than by an application check.
Two taps on a laggy phone, a retried request, or a shared kiosk plus a personal device cannot open two sessions — the race that actually happens in an outlet is closed where it cannot be worked around.
- How presence was evidenced Module ↗
Each punch records its method — GPS, selfie, QR kiosk or manager mark — with coordinates, the selfie reference, and the user who marked somebody else present.
A manager marking the team in is legitimate and common. Recording that it was a manager mark rather than a self-punch is what makes the attendance record arguable later.
- Forgotten punch-outs are surfaced, never guessed Module ↗
Any session still open past sixteen hours is listed with how long it has run, and is never auto-closed.
Guessing an end time puts invented hours into your labour cost. The manager who was there knows what happened, so the product asks instead of assuming.
- Leave as an append-only ledger Module ↗
Entitlement, days taken and corrections are all rows in quarter-days across casual, sick, earned and unpaid. The balance is their sum — there is no balance column anywhere to edit.
Leave is exactly the number staff dispute. “You took two days on the 14th” survives in the record instead of in somebody’s memory.
- Overdrawing paid leave is refused; unpaid always goes through Module ↗
The ledger refuses to overdraw a paid leave type, but never refuses to record an unpaid day, and an adjustment without a reason is rejected.
Refusing to record a day somebody actually took would make the ledger a fiction, which is how leave records stop being trusted.
Where payroll stops
The product records the shift and holds a payroll reference. It does not compute pay, file returns or touch your salary run — that is deliberately a boundary, not a gap we are about to fill.
Not built yet — on the plan
Nothing in this group is built yet, and every row is tagged that way. It is here because you will ask, and because a roadmap you can argue with beats one you find out about later — what we build next should be decided by the people paying for it, so tell us which of these actually blocks you.
-
Worked hours, leave taken and the payroll reference export in the format your payroll provider or accountant ingests, per pay period.
The attendance ledger stops being evidence only for disputes and starts saving the hour someone spends retyping it into a salary sheet.
- Training and certification for your staff Not built yet
Role-based modules and assessments with a certificate per person, tracked against the roster so you can see who is trained on what.
A new hire is productive on a syllabus rather than on whoever was on shift, and you can show the brand your team is certified without a phone call.
The line to leave in the room Hours and leave are rows nobody can edit into a different answer, including us.
What you owe, what you are owed
The royalty statement shows its working
Royalty arguments are almost never about the rate. They are about a number that arrived with nothing attached to it. Here the statement carries the basis, the rate, the floor and cap notices, the ad fund and the tech fee — the same figures the engine stored, not a presentation layer’s re-derivation.
Royalty statement — July 2026, illustrative
Every line is stored on the statement, not recomputed for the pageIllustrative figuresRate from the term effective 1 April 2026Ad fund accrues on gross even when royalty is charged on netBasis: your submitted monthly report
What the number is built from
- The rate that applied in March is still readable in March Module ↗
A royalty term binds your unit to a basis, rate, floor, cap, ad-fund percentage and tech fee for a dated window, carrying a version number and a draft / active / superseded status.
When you question an old period, the answer comes from the record of what was live then rather than from what the rate is today.
- Nobody can edit last quarter’s rate Module ↗
An active or superseded term cannot be edited or deleted. Changing it mints the next version as a draft, ends the old row the day before the new one starts and marks it superseded.
A rate change is a new version with a start date — which is exactly how your agreement works, and the only version of the history worth having in a dispute.
- One live rate per unit, enforced under a lock Module ↗
Activating a draft supersedes any currently-active term for the same unit, with every term row locked first so two people activating at once cannot leave two live rates.
There is never a second opinion about which rate is current, because the database refuses to hold two.
- Percentage, flat, hybrid and slab Module ↗
Where the term has bands, the percentage leg is charged marginally: each band’s rate applies only to the slice of sales inside it, with an open top band catching the rest.
A slab structure that rewards a busy outlet computes correctly instead of being approximated by whoever built the spreadsheet.
- Floor, then cap, each named on the statement Module ↗
If computed royalty falls below the minimum guarantee, the MG is billed; a maximum cap is then applied on top, and the statement stores a flag for each so you can see which one bit.
The statement says “minimum guarantee applied” rather than showing a number you cannot reproduce from your own sales.
- What counts as gross, in the contract’s own words Module ↗
A term can compute the percentage leg on net — gross minus declared deductions — and carries the free-text gross-sales definition copied from the agreement. Ad fund accrues on gross regardless.
The definition you signed sits next to the arithmetic, so a deduction argument is about the clause rather than about the software.
7 more in this group
- You file it, the brand accepts it, then it is billed Module ↗
A period report moves due → submitted → approved, and only a monthly report in a closeable state is ever picked up as a royalty basis.
The number you are billed on was filed by you and accepted by them, so the disagreement happens before the invoice rather than after it.
- The month is built from the days you already recorded Module ↗
The period report rolls up from your business days — declared gross sums up, discounts and refunds become deductions, the per-channel split is preserved, and signed adjustments from closed days are carried into this period’s base.
No retyping at month end, and a correction you made on the 3rd reaches the royalty base without anyone reopening June.
- A weekly report can never be mistaken for the month Module ↗
Reports carry a granularity — weekly, fortnightly, monthly — and only the monthly grain is read as a royalty basis or fed into the trailing median.
Management reporting on a weekly rhythm cannot collide with the royalty basis and flag an honest outlet as an anomaly.
- A missing report is estimated, and the estimate is labelled Module ↗
A unit with an active term and no filed report is still billed, on the median of its last three reported months, with the statement marked estimated. Filing the real report and re-closing replaces it.
Say this one out loud both ways: not filing does not defer royalty, and filing late does not leave you stuck with somebody’s estimate.
- A month already billed is never quietly restated Module ↗
A statement that is invoiced, paid or waived is skipped by the close run, and two simultaneous closes settle on one row rather than duplicating.
The statement in your inbox stays the statement, even when head office re-runs the month for somebody else.
- The close runs on the 4th, on its own Module ↗
A scheduled command closes the previous month for every workspace on the 4th at 08:00, isolating each one so a malformed term somewhere else cannot stop yours.
Royalty lands on a date you can plan cash around, and the 4th is late enough that you have filed.
-
An imported POS gross is stored alongside the declared figure and the variance is computed. The import runs through the API today; there is no import screen in the console and re-importing the same file adds to the imported figure again.
The variance seam exists so a difference is visible and explainable rather than assumed to be under-reporting — but do this one with us, not alone.
The invoice and what you actually pay
- GST heads derived from place of supply Module ↗
Same state charges CGST plus SGST at half the rate each; a different state charges IGST at the full rate; the split is stored on the invoice so it never drifts. With no state code configured it charges no split at all rather than guessing.
The tax head on your bill is right, and a misconfigured supplier produces a visibly incomplete invoice instead of a confidently wrong one.
- A tax invoice carrying the Rule 46 particulars, with the SAC on the line Module ↗
The PDF carries invoice number and date, place of supply, your name and GSTIN, the SAC, taxable value, the CGST/SGST or IGST split, the amount in words and the grand total in rupees, with the reverse-charge line printed even when the answer is no — presenting the stored figures without recomputing them. Not on it yet: the supplier’s signature block, and your full address, where it prints your city.
Your CA gets a document with the fields they ask for, and the PDF can never disagree with the ledger it evidences.
- Invoice numbers that survive an audit Module ↗
Numbers follow a pattern with the financial year and a sequence, allocated from a per-year counter under a row lock inside the same transaction as the invoice, restarting each fiscal year.
No duplicates and no burnt numbers when two invoices are raised at once, which is the thing a GST audit actually looks for.
- TDS shown as expected, not as a shortfall Module ↗
The invoice carries the TDS section and rate, computes the withholding on the pre-GST base, and stores the expected net receipt beside the gross total.
When you deduct TDS correctly, nobody chases you for money that went to the government.
- Part payments settle progressively Module ↗
Each receipt records net cash, TDS withheld, mode — NEFT/RTGS, UPI, cheque, card, cash — date and reference. The invoice settles only when receipts cover the total, and deleting a receipt reopens it.
A part payment stops being either “paid” or “unpaid”. The balance is the truth and it moves on its own.
- The document you were sent is the document you keep Module ↗
An issued invoice is rendered once, hashed, and stored outside the web root; every download re-checks the hash and refuses to serve a file that no longer matches. Re-issuing mints a new record rather than rewriting the old one.
The copy you are holding keeps saying what you received, which is the only basis on which a tax document means anything.
2 more in this group
- Chasing happens on a ladder, and a promise pauses it Module ↗
A daily run records a reminder as each open invoice crosses a configured offset — T-3, T0, T+7, T+15, T+30 by default — once per offset, written to the timeline. An invoice with a future expected payment date is skipped until that date passes.
You are chased on a schedule rather than when somebody is annoyed, and committing to a date buys you that date. Reminders are recorded, not yet emailed.
- Credit notes know the section 34 deadline Module ↗
A credit note records its reason and amount, and a GST-adjusting note is refused after 30 November following the invoice’s April–March financial year, with the message telling you to issue a commercial note instead. Section 34 is the earlier of that date and the day the brand files that year’s annual return — the software checks the 30 November limb.
The date most people miss is enforced by the software rather than discovered by a CA in December, and the return-filing limb is named rather than left to be found.
A month, end to end
- Through the month You open, trade, count and close each day. Nothing is asked of you at month end that you have not already done at 11pm each night.
- The 1st The period report is rolled up from those days — declared gross, deductions, channel split, and any signed adjustments carried forward from closed days.
- You submit, the brand approves The report you file is the report the royalty run reads. Approval is a separate act with its own permission, so the acceptance is on the record too.
- The 4th, 08:00 The close runs for the period. Your statement is written with the basis, rate, floor and cap notices, ad fund and tech fee stored on it.
- The invoice Raised against the statement with the right GST head for the place of supply, the SAC on the line, and the TDS you will deduct already shown as expected.
- If it is wrong You point at a line, not at a total. A correction rides forward as a signed adjustment into the current period rather than reopening a month already billed.
Not built yet — on the plan
Nothing in this group is built yet, and every row is tagged that way. It is here because you will ask, and because a roadmap you can argue with beats one you find out about later — what we build next should be decided by the people paying for it, so tell us which of these actually blocks you.
-
The invoice carries a payment link with UPI, and a standing mandate presents the royalty on the due date so it clears without you initiating a transfer.
You stop being chased for something you always intended to pay, and the reference is always right, so nothing gets marked unpaid because the transfer was untagged.
-
Your royalty statement, the invoice and each reminder are emailed and WhatsApped as they are raised, with the PDF attached.
You find out what you owe on the day it is computed, rather than on the day somebody follows up about it.
The line to leave in the room You can rebuild the royalty figure from your own sales record. That is what ends a royalty argument — not a nicer invoice.
Not just theirs
Knowing your own performance
Everything so far produces a number somebody else reads. This chapter is the half that reads back to you.
- Four-wall P&L for the outlet Module ↗
For your unit and a date range it builds net sales from the declared trading days, groups approved spend into cost of sales, labour, occupancy, marketing and other, keeps aggregator commission on its own line, and reports prime cost and four-wall EBITDA with each ratio scored against a band.
You see the two numbers that decide whether the outlet survives this week, rather than getting a P&L from an accountant in March.
- Bands that are the accepted envelopes, not a grade Module ↗
Ratios are scored against the usual QSR bands — cost of sales around 30–35%, labour 20–25%, prime cost at or under 60%, occupancy 10–15% — and read as unknown when there are no sales to divide by.
You find out you are two points over on labour while you can still do something about the rota.
- Labour is your approved staff spend, and hours sit beside it Module ↗
The labour line is built from approved expense claims in the labour category. Worked minutes from the attendance punches are recorded on the same daily rollup row, next to prime cost, but are not themselves costed into the P&L.
Worth being precise about: the P&L reads your books, and attendance is the evidence beside it — not a payroll engine pretending to be one.
- Aggregator commission read from the settlement Module ↗
Commission is taken from the aggregator’s own imported settlement rather than from a headline rate, because the money is netted at source and never reaches you. Where no settlement has been imported the line is simply zero.
You learn what delivery actually costs you, and where the data is missing the gap stays visible instead of being invented.
- Approving an expense is what posts it Module ↗
A claim is captured with date, category, vendor, invoice number, taxable amount and tax, then approved or rejected. Approval writes the balanced ledger entry, stamps who approved it, and links the entry to the claim.
An approval that does not move the books is a rubber stamp. Here they are the same act, so what was approved and what was spent cannot diverge.
- Reimbursement and recharge are one object Module ↗
Every claim carries who paid — brand or outlet — and whose cost it is. When they differ the cost lands on the other party’s khata instead of in the payer’s expenses, and reimbursing posts the entry that clears it.
What you call “my reimbursement” and the brand calls “recharge” is one record, so the two of you cannot disagree at month end.
7 more in this group
- Pure agent, so a recovery is not a supply Module ↗
A claim carries a GST posture of none, pure agent under Rule 33, or taxable recovery; a pure-agent recovery passes through at gross with no tax added.
A bill the brand paid on your behalf does not accidentally turn either of you into a taxable supplier of the thing that was merely paid for.
- Where the money is Module ↗
Money locations list as accounts with live balances — the bank account, the till, and a khata per counterparty — computed as opening plus the signed lines rather than stored as a figure.
“Where is the money and who owes whom” is one screen, in the vocabulary you already use.
-
Every posting must balance or it is refused, and nothing edits or deletes a posted entry. A reversal primitive exists in the service layer but no screen or endpoint calls it yet.
A figure derived from these rows is evidence rather than an opinion — and we would rather tell you the reversal path is not wired than let you find out during a correction.
- An insight stream you can argue with Module ↗
Coded rules run over your rollups and raise findings into one severity-sorted stream — sales fell against your own average, best month you have had, prime cost past the survival line, negative four-wall EBITDA, a cash-mix jump against your own 30-day history, a mandatory licence missing, overdue royalty, an audit score in the network’s bottom quartile. Each card names its rule and carries the numbers.
You are told what changed instead of being handed twelve charts, and every card can be snoozed, resolved or marked not useful.
- Findings that close themselves Module ↗
Raising the same finding twice updates one row, a finding that stops being true resolves itself and says it closed automatically, and something you resolved by hand is never reopened by a re-run.
The stream stays worth opening, because nobody has to dismiss forty warnings about things they already fixed.
- Thresholds you can move, rules you can mute Module ↗
The number on any rule can be changed per workspace and a rule that does not apply can be muted, while the logic itself stays in readable code rather than a model.
What counts as a sales drop for your format is your call, and you can switch off the rule that keeps firing for a reason that is not a problem.
- A number you can take away Module ↗
The headline tiles on the module pages that carry a stat band open an explorer showing the series behind the figure, and export it as CSV.
Your own accountant gets the number in their model without asking anyone to run a report.
One thing to know about the insight stream
The rules are evaluated when a run is triggered for a period, and the rollups they read are rebuilt on demand. Nothing schedules either yet, and nothing pushes a notification — the stream is a screen you open, not an alert that finds you.
Not built yet — on the plan
Nothing in this group is built yet, and every row is tagged that way. It is here because you will ask, and because a roadmap you can argue with beats one you find out about later — what we build next should be decided by the people paying for it, so tell us which of these actually blocks you.
- Tally and Zoho Books export Not built yet
Your sales, expenses and royalty invoices export in the format your accountant’s package imports, on a schedule rather than on request.
Your CA stops billing you for data entry you already did once, at the counter, every night.
- What your customers actually think Not built yet
Feedback captured at the counter and public review scores trend for your outlet against the network, beside your audit score and your prime cost.
The number that predicts next quarter’s sales is the one nobody currently measures at the outlet, and it is the one you can still do something about.
The line to leave in the room Prime cost and four-wall EBITDA are your numbers. The royalty statement is theirs. Both come out of the same trading day.
Talking upward
A request with an owner and a clock
A message in a group chat has no status, no owner and no due date, which is why it can sit for nine days without anybody being wrong. A typed request has all three.
Say this before anything else
Requests, chat and announcements are queues inside one workspace: everyone who can see them holds a membership in it. Routing a request automatically from a separate outlet console into a separate brand console is not built, so how you and head office share a queue is a setup decision to make together rather than something to assume.
The audience field on an announcement is stored but not yet honoured — v1 sends to every member of the workspace. And a channel per outlet is created by hand today; nothing provisions one automatically.
- Twenty typed request templates, split by who is asking Module ↗
The catalogue is split into outlet-to-brand and brand-to-outlet queues — discount approval, royalty dispute, supply shortage, equipment repair, renovation approval on one side; document request, licence evidence, missing sales report, royalty chase, audit corrective action, inspection follow-up on the other — each with typed fields and a decision SLA in hours. Required fields are refused on the server.
A discount request arrives with the percentage on it instead of as prose somebody has to read and re-key, and both sides can see who owes whom an answer.
- Delegated discount authority Module ↗
A discount request’s approval level is computed from the percentage on it and stored on the record — up to 10% marked self-approve, up to 20% area manager, above that head office — and a percentage that is not a number is marked head office. The level is a label on the request: it does not route it and does not itself block a decision.
Asking for 8% arrives already marked as your own call rather than as prose head office has to read — and what level it carried, plus who actually decided it, are both on the record.
- A decision clock separate from the resolution clock Module ↗
Templated requests carry their own decision due date, and the decision endpoint records the approval or rejection with who decided and when — once, and only on approval-kind requests.
“We answered you” and “we finished the work” are two different promises, and they are tracked as two.
- An SLA that pauses when it is waiting on you Module ↗
Per-priority first-response and resolution targets drive a clock; moving a case to pending banks the paused minutes and slides the resolution date forward.
The clock measures the answer rather than punishing whoever is waiting for a photograph, which is the only way anyone keeps using it.
- A daily sweep that says when something went late Module ↗
Each morning a command walks open and pending cases with a policy and writes a note when the first response target is missed and when resolution breaches — each firing at most once, and re-armed if the case is reopened.
A late request is visible as late rather than as silence, without the system sending the same nag every day.
- A thread, with private handling notes Module ↗
Replies append to the case, can be marked internal so they stay out of the shared thread, and can be pasted from a saved canned response that the message then cites. The first non-internal reply stamps the first-response time.
The clock is stopped by an actual answer rather than by somebody claiming they called.
6 more in this group
- Reopen count and a satisfaction rating Module ↗
Resolving a case can capture a 1–5 rating with a comment; reopening increments a counter and re-arms the breach notification.
A case resolved four times is visibly a case that was never resolved.
- Chat that cannot silently drop a message Module ↗
Every message takes a per-channel sequence number allocated under a lock, and polling reads forward from that sequence rather than from database row ids.
Two people posting at once cannot make one message vanish — which is a real failure of the obvious approach, and the difference between late and gone.
- Removing a message leaves a mark Module ↗
Moderating a message stamps who removed it and when, and the row stays in the thread rather than disappearing.
A network where messages silently vanish is one nobody trusts.
- A message that turns out to be work becomes work Module ↗
A chat message converts into a request carrying its text, and the message keeps a pointer to what came out of it. A message can only be converted once.
Chat deliberately has no status, assignee or due date, so the conversation and the work never drift into two systems that disagree about what is open.
- Announcements with a receipt per person Module ↗
Publishing creates a read and acknowledge receipt for every member at the moment it goes out, tracks reading and acknowledging as two separate acts, and reports how many are still outstanding.
“Nobody told us” has an answer, and so does “we sent it and nobody opened it” — two very different conversations.
- Read-and-sign on a document, with the version you signed Module ↗
A document assigned to people starts unacknowledged; acknowledging stamps the time, the typed name and the IP. Publishing a new version archives the old one and re-creates a pending acknowledgement for everyone who signed the last.
When the operations manual changes you sign the new one, and the version you signed last year is still on file.
Reading and being read
- Unread counts that are yours, not the outlet’s Module ↗
Each channel shows an unread count computed from your own read position, and reading a thread advances your cursor alone.
Your manager opening the channel does not clear your badge, so what you have not read stays what you have not read.
Not built yet — on the plan
Nothing in this group is built yet, and every row is tagged that way. It is here because you will ask, and because a roadmap you can argue with beats one you find out about later — what we build next should be decided by the people paying for it, so tell us which of these actually blocks you.
-
Announcements, reminders and replies run over WhatsApp against your outlet record, so a brand message reaches you where you already are and your reply lands back on the record.
Nothing important stays buried in a group chat where nobody owns it and nobody can find it again.
-
Approved creatives, campaign kits and local-store templates download from one library, always the current version.
Local marketing that does not get you a compliance finding, without waiting two days for somebody at head office to email a file.
The line to leave in the room The point is not the ticket. The point is that “when will you answer” has a number in it.
Renewals
The licence that does not lapse on a Friday
The register starts populated, because a compliance module that starts blank gets filled in from memory and then trusted.
- A seeded India statutory library Module ↗
Every workspace seeds a brand pack — trademark, GST registration, FSSAI central, EPR plastic packaging, POSH committee, Udyam — plus one of five outlet packs for F&B, pharmacy, salon, education or retail, each item carrying its authority, cycle, validity, renewal window, alert ladder, whether it is mandatory, and a paragraph of guidance.
It arrives knowing that FSSAI renewal opens 180 days ahead, that the ₹100-a-day late fee bites inside the last 30 and escalates to 3× and then 5× after expiry before the licence dies at +180, plus the municipal trade licence’s April–March year and the drug licence’s five-year retention fee — instead of asking you to type them.
- Required versus held, worst first Module ↗
The register compares what your unit must hold against what it does hold and sorts by severity — lapsed, expired, missing, due, flagged, ok, not tracked — so a mandatory obligation with no record at all is a row rather than an absence you have to notice.
You open the screen to find the thing you never had, not to browse the filing cabinet you already know is fine.
- Licence clocks that behave differently Module ↗
Fixed-year, annual, perpetual-with-retention, no-expiry and state-variable cycles are modelled separately, and an expiry is derived from the issue date where the statute implies one.
A pharmacy’s Form 20/21 tracks its retention due date rather than a fake expiry, and a GST registration never appears on a renewal ladder it has no business being on.
- A daily sweep on a 60/30/15 ladder Module ↗
Each morning a scheduled command recomputes every licence against a 60/30/15-day ladder and writes a note on the unit’s timeline the day it crosses into expiring or expired.
You hear about a lapse from the system before you hear about it from an inspector, and it costs nobody a diary reminder.
- An append-only review trail per licence Module ↗
Each record stamps who filed it and, on review, the reviewer, timestamp and note; every decision — approve, comment, flag renewal, reject evidence — is written to a separate append-only table with its from and to state. Flagging never erases where the record had got to.
A renewal that was queried in March can be shown to have been queried in March.
- An external inspection is its own kind of record Module ↗
A regulator’s visit is filed with the authority, the notice or reference number, the outcome, the penalty amount and the statutory deadline — completed with no score, because you are recording what somebody else decided.
The scoring is left empty rather than set to zero: a zero would read as a catastrophic audit when nothing was scored at all.
2 more in this group
- Findings become actions that get verified Module ↗
A finding carries a severity and hangs corrective actions with an assignee, a due date, a resolution note and a status of open, in progress, resolved or verified. Marking one verified stamps who verified it and when.
“We fixed that” is checkable rather than asserted, and the same finding stops reappearing next quarter because nothing owned closing it.
- The licences sign-off reads the register Module ↗
On an opening project the licences-verified gate is refused, naming the offending items, when the unit has a mandatory statutory licence missing or expired — and it seeds the statutory library on the spot so the gate cannot pass because nobody opened the compliance screen.
Nobody signs your outlet off as licence-clear in a hurry, which is the version of this that costs you later, not them.
Not built yet — on the plan
Nothing in this group is built yet, and every row is tagged that way. It is here because you will ask, and because a roadmap you can argue with beats one you find out about later — what we build next should be decided by the people paying for it, so tell us which of these actually blocks you.
-
The licence scan, the renewal receipt and the inspection notice attach to the register entry they belong to, versioned, so the record holds the document and not only its number.
When an inspector asks, the certificate is on the phone in your hand rather than in a folder in the back office.
The line to leave in the room A renewal window that the software watches is worth more than one that a diligent person watches, because the diligent person leaves.
If you are not trading yet
The opening plan, with licence time in it
An opening plan that ignores how long paperwork takes is a wish. These templates start from what the processing actually takes in India, as ordinary editable durations.
- Fifteen phases everyone uses the same names for Module ↗
Signing, entity and finance, site selection, LOI and lease, design and fit-out, licensing, construction and equipment, tech activation, hiring, training, stock and supply, pre-launch marketing, soft launch, grand opening, stabilization.
Head office, the field team and you are looking at one plan with one set of names for the same steps.
- Six industry packs with India licence durations built in Module ↗
F&B/QSR, education centre, salon and wellness, pharmacy, retail store and premises-light services packs carry researched processing times — Shops & Establishment 5–10 days, GST registration 7, trade licence 7–15 (15–30 for health trades), fire NOC 15–30, FSSAI state 30–60, eating-house police licence 15–25 where your state requires one, drug licence 30–45 after inspection.
The plan you are held to starts from real paperwork time rather than from an optimistic January.
- The pharmacy pack knows the pharmacist comes first Module ↗
Hiring the registered pharmacist is a real predecessor of the drug-licence application, because the application cannot be made without one.
The sequencing mistake that costs six weeks is already in the template rather than learned once per opening.
- Back-scheduling from the opening date Module ↗
Each task declares an anchor, an offset and a duration, so setting the opening day tells you the week the site has to be signed. Moving the date recomputes every window from the plan’s own data.
The date slips once and thirty dates move with it, instead of thirty dates going quietly stale.
- A projected open driven by real slip Module ↗
The projected date is the target pushed out by the worst slip on a critical task — measured against today for an unfinished one, against when it landed for a finished one. Slippage on non-critical tasks is visible but never moves the date.
The date on the screen is when you will actually open, which is the date you hire and order stock against.
- A phase stays locked until the earlier sign-off is approved Module ↗
Every mutation — complete, block, approve — is checked against the gating on the server, so nobody works ahead by posting straight at the API. Only an approval task clears a gate, and only the brand can give it.
No construction before the drawings are approved. That rule lives in the database rather than in a policy document — and yes, this one runs in the brand’s direction: you cannot sign off your own opening.
3 more in this group
- Blocked, with a reason from a fixed list Module ↗
A task is flagged blocked as awaiting landlord, authority, brand, vendor or funds, plus a free note. Completing the task clears the block.
Because the reasons are a fixed list they can be counted — including how often the network is waiting on the brand, which is the count you want to exist.
- Grand open is refused while a sign-off is outstanding Module ↗
Marking the project opened returns an error counting the unapproved sign-offs; once it succeeds, the actual open date becomes the baseline every downstream clock measures from.
Opening day is a fact the system agrees with, which is what makes the royalty and reporting clocks that start from it trustworthy.
-
An endpoint resolves the opening project belonging to your workspace and returns the journey minus the brand’s internal steps, while gating still evaluates the full list. It is tested, and there is no outlet-side screen wired to it yet.
When the screen lands you see your plan and your next step without seeing internal steps that are none of your business — today the plan is read from the brand’s board.
One honest note on setup: the opening project is created and the template applied by hand. Nothing provisions a journey automatically the moment a franchisee signs, whatever a roadmap slide may once have said.
The line to leave in the room A plan that already knows the fire NOC takes fifteen to thirty days is a plan you can argue with. One built backwards from a launch party is not.
Your rhythm
Six franchise industries, one product
A preset changes the vocabulary, the channels, the tenders, the KPIs, which detail records exist and whether a cash-up runs at all — without the underlying tables ever forking. Your workspace can also override any of those four settings sparsely, so “absent” means “inherit”.
| Industry | The trading day | What gates the opening | What changes |
|---|---|---|---|
| F&B and QSR | Daily. Open, trade, shift handover, blind cash-up, close. | Dine-in, takeaway, delivery aggregator and own online as separate channels. | Opening pack carries FSSAI state licence at 30–60 days, fire NOC 15–30, and the police eating-house licence at 15–25 where the state requires one. |
| Retail and pharmacy | Daily, with cash-up. Walk-in and own online channels. | Pharmacy adds the drug licence and its retention clock rather than a fake expiry. | The pharmacy opening pack makes hiring the registered pharmacist a predecessor of the drug-licence application. |
| Salon and spa | Daily, with cash-up and shift handover. | Trade licence on the health-trade timeline: 15–30 days, not 7–15. | Salon and wellness opening pack, with its own fit-out and hiring sequence. |
| Education | Period regime. The month is canonical; day-chasing and cash-up are switched off entirely. | A fee receipt on the 3rd is simply a receipt in October. | Nagging a coaching centre for “yesterday’s sales” is noise, so the product stops asking. |
| Gym and fitness | Daily, with its own KPI set and channel vocabulary. | Memberships and walk-ins as distinct channels rather than one gross figure. | Same royalty pipeline underneath — only the words and the rhythm differ. No gym-specific opening or compliance pack ships: you clone the premises-light services pack and edit it, and we would rather say that than let you find it on your first opening. |
| Services | Period regime, premises-light. No cash-up. | The services opening pack skips the fit-out weight a store carries. | A services franchise and a QSR use one product and one royalty engine. |
The line to leave in the room The preset decides what you are asked for. It never forks the data, so the brand still reads one network.
Ask us about these
What this does not do
This list is here because a page that only lists strengths is a page you check afterwards. Every line below is something we would rather you heard from us now.
- It is not a POS. The trading day is declared and can be reconciled against a POS export; it does not run a till, print a bill or manage a menu.
- It does not compute payroll. Attendance and leave are records with a payroll reference; pay is calculated somewhere else.
- WhatsApp is click-to-chat and scan-to-chat links only. There is no WhatsApp Business API inbox.
- There is no file upload for licence scans, visit photos or vault documents. The register stores metadata and a reference string; the only upload endpoint in the product is the organisation logo.
- Photo evidence on an audit checklist item is a column, not a feature — nothing uploads to it yet.
- E-invoicing (IRN) is schema-ready with no IRP integration, so the screen says “not connected” rather than implying it is done.
- Reminders and dunning are recorded on the timeline; outbound email is not wired, so a chase is visible in the system rather than landing in an inbox.
- There is no payment link for an invoice a brand raises on a franchisee. Pay links exist for platform subscription invoices only.
- Requests, chat and announcements live inside one workspace; automatic routing between a separate outlet console and a separate brand console is not built.
- A chat channel per outlet is created by hand — nothing provisions one automatically.
- An outlet-side screen for your opening journey is built and tested at the API but has no screen yet; today you read the plan from the brand’s board.
- Cash movements and shift handover are shipped at the API with typed client hooks, and have no controls on the day screen yet.
- Compliance records stamp who filed them; you cannot yet assign a renewal to a different owner.
- Insight runs and analytics rollups are triggered rather than scheduled, and nothing sends a push notification.
- The ledger cannot be corrected by reversing entry from any screen — the primitive exists but is not wired to a route.
- A discount request is labelled by percentage — self-approve, area manager, head office — and the label does not route it or decide it. Someone at head office still presses the button, so do not treat a small ask as automatically cleared.
- Your tax invoice carries almost all of the Rule 46 particulars. The supplier’s signature block is not printed on it, and your address line shows your city.
- The credit-note cutoff checks 30 November following the financial year. Section 34 is the earlier of that and the brand’s annual-return filing date, and only the first limb is enforced.
- A licence record has a visibility setting that nothing reads. It does not hide anything — your register is separate from the brand’s because it is a different workspace, not because of that switch.
- No gym-specific opening or compliance pack ships. A gym clones the premises-light services pack and edits it.
The same honesty applies to the tags earlier on this page. “Partly built” means it works but you cannot reach all of it from a button yet. “Not built yet” means there is nothing to show you — it is listed so you can tell us whether it is the thing that would make this worth your evening. Everything untagged is shipped, and you can ask to see it running now.
The line to leave in the room If one of these is the thing you needed, say so now. A missing feature is a conversation; a discovered one is a broken relationship.
The outlet is where the data comes from
Every number head office reads starts as somebody closing a day at eleven at night. That is why this page led with your screen, your staff and your statement rather than with the brand’s dashboard: if the counter does not find it worth opening, nothing above it is true. Bring the last royalty bill you disagreed with, and we will rebuild it line by line in front of you.