Features
Everything between the first call and the 1099
Grouped by the job it does. If your office runs one of these in a spreadsheet today, that is the part worth looking at first — and where something is bounded, the entry says where the boundary is.
Sales
From first call to signed
The part a general CRM does adequately, done for this industry specifically.
- Separate merchant and recruiting pipelines
- Signing a restaurant and recruiting a sub-agent do not share stages. Each pipeline has its own, configurable per office, and a lead cannot drift between the two boards.
- Stages you define
- Rename, reorder, retire. Each stage is typed as open, won or lost, so reporting understands the board without being told again.
- Activities and tasks on the record
- Calls, notes, meetings and follow-ups attach to the lead. What is due, and who owes it, is a property of the record rather than a reminder in somebody’s calendar.
- A public enquiry form, attributed correctly
- A signed form you can put on your own website. A stranger’s submission arrives attributed to the right organisation and lands in triage, rather than in an inbox somebody forwards.
- Proposals and e-signature
- Build a proposal from a template, send it, and track it through viewed and signed, with an ESIGN/UETA audit trail. The signed copy stays attached to the account it created.
- Custom fields
- Add the fields your office actually asks for, to leads and merchants, without a schema change or a release — and see them across the merchant screen rather than on one tab.
- Conversion that carries everything
- The lead becomes the merchant with its documents, contacts, notes, activities and custom field values intact. Nothing is re-keyed, and nothing is left behind on a dead record.
Underwriting
Applications, decisions and boarding
One path from a signed application to a live MID, with the awkward parts modelled rather than assumed.
- Applications with ownership and principals
- Beneficial owners, control persons and their percentages held as structured records rather than as a PDF somebody has to open. That is what makes them checkable.
- Stipulations that block
- Outstanding conditions are attached to the file and hold the decision. A case cannot be approved past an unmet stipulation by clicking a different button.
- Documents against the case
- Applications, statements, licences and signed agreements stored against the account, streamed through a permission check so every open is recorded and nothing is link-shareable.
- OFAC sanctions screening
- Merchants and principals screened against the Treasury SDN list, refreshed nightly. A hit holds the merchant for review rather than rejecting them outright, because a name match is not a finding.
- A screening result that cannot lie
- Screening off, a list that failed to download, a blank name or a provider timeout all record unknown with a reason — never clear. Unknown blocks approval unless somebody signs it off explicitly, so the file always says whether anybody actually looked.
- Boarding to a processor
- A submit-and-poll seam with retries, reconciliation and dead letters, against adapters for NMI, Fiserv, TSYS, Worldpay, Nuvei and Elavon. Capabilities are declared per processor rather than assumed — and every adapter is unverified until it has been run against that processor’s sandbox, which the product enforces by refusing live mode.
- Processor accounts on the record
- The MID, the descriptor and the account’s state live on the merchant, so the answer to “is this one live, and where” is on the screen rather than in somebody’s memory.
- Bank details checked against the Fed’s own directory
- A routing number entered on an application, a payout profile or the merchant portal is checked against the FedACH participant file — the same answer wherever it is typed. The directory is authoritative and the ABA check digit is only a fallback, because several of the largest banks in the country fail the arithmetic and are in the file. A directory that was never loaded answers unknown, never invalid.
- No automated identity or credit decisioning
- Stated plainly: there is no KYC, KYB, MATCH/TMF or credit check behind this. Underwriting here is a structured human workflow with the evidence gathered and the decision recorded.
Portfolio
The account after it is signed
Where most CRMs hand you back to a spreadsheet.
- The whole merchant on one screen
- Deal history, contacts, documents, custom fields, tickets, residuals, processor accounts and payments activity, on the record rather than across five of them.
- Payments data, synchronised and read-only
- Transactions, batches, settlements, funding events, refunds, chargebacks and fraud alerts as the processor reported them, each row naming its source and keeping the provider’s own record verbatim. Nothing here executes a refund, and it is built so it cannot appear to.
- Health scoring
- A weighted score across the signals you have. Factors with no data are excluded and the weights re-normalise around them, so a quiet account reads as unscored rather than as failing.
- A watch list that explains itself
- Twelve conditions swept hourly — volume drops, approval-rate drops, delayed and failed deposits, chargeback and fraud spikes, processor outages, effective rate movement, settlement mismatches, expiring documents, unresolved compliance holds and churn risk — each scored, explained in plain language and tracked until somebody records what they did.
- And it counts what it could not check
- Most of those conditions need a processor feed. On a tenant without one the screen leads with how many checks came back unknown, before showing a single finding — because two problems over a calm background would claim everything else is fine.
- A finding becomes work, not a notification
- One that names an action opens a ticket on its own channel, once — so machine-raised work sits in the same queue as everything else without being mistaken for a customer who wrote in. It reopens if the problem comes back, and resolving it leaves a note rather than closing the ticket over the head of whoever is working it.
- What came back, on an append-only record
- Recovery is kept as a history rather than a single figure, so a problem that recurs cannot erase the money that came back the first time. The report states its own denominator — including how many findings were closed with nobody recording an amount — and refuses to print a rate it cannot compute. It does not claim the recoveries as attributable to the watch, because nothing here observes what would have happened otherwise.
- A merchant-facing portal, optional and off
- Your merchants can see their own deposits, disputes, documents and tickets. A portal login is bound to exactly one merchant, refused on every route not explicitly marked merchant-facing, and an unbound login resolves to nothing rather than to everything.
Money
Residuals, splits and payouts
Exact minor-unit arithmetic throughout. This is the part that decides what people are paid, so it is built to be reconciled rather than trusted.
- Residual calculation
- Import processor residuals and allocate them across agents and partners by the splits you configure, including overrides up a hierarchy.
- Partner payouts with a real hold
- Outstanding is derived as allocations less payouts not yet released. A pending payout holds its amount; a failed, returned or voided one gives it back. Nobody is paid the same residual twice, and there is no stored balance to drift.
- Foreign exchange, stated explicitly
- Rates are directional and effective-dated, a manually entered rate outranks a fetched one on the same day, and a missing rate stops the run instead of silently assuming parity.
- Scheduled runs and approvals
- Monthly runs on each office’s own day, hour and timezone, surviving short months and catching up if a scheduler was down. Runs are assembled and at most approved — never submitted unattended.
- Statements partners can read
- A payout resolves to the allocations behind it, so “why is this number what it is” is answerable without a spreadsheet.
- 1099-NEC on a cash basis
- Box 1 totals built from what was actually paid inside the calendar year — keyed on the payment date, not the period it covered — with year boundaries handled so 31 December is never lost, and payees missing a TIN, address or legal name surfaced before filing season rather than during it.
- It computes; it does not disburse
- The CRM never holds funds and never initiates a transfer. An approved run is handed to a disbursement seam, which is what keeps the approval a control rather than a formality — and is why nothing here is in PCI scope.
Communication
Reaching people, on the record
Four channels, all writing back to the account — because a conversation nobody else can see is a liability the day the rep leaves.
- Email and drip campaigns
- Sequenced outreach with the steps, timing and exit conditions you set. A reply takes the lead out of the sequence. Ten starter templates are seeded for a new office so the first campaign is an edit rather than a blank page.
- SMS with a consent engine
- Consent state, quiet hours in the recipient’s own timezone, and segment counting that matches what the carrier will actually bill — so the number a rep is shown before sending is the number you pay for. Ten starter texts are seeded too.
- Live chat
- In-app chat with a staff queue, history kept against the record, and an unanswered-conversation sweep that escalates to a ticket rather than leaving somebody waiting.
- Voice
- Click-to-call, caller ID and screen-pop on inbound, so a call from a merchant opens the merchant. Calls still in flight are reconciled by asking the provider rather than assuming, and a guess is flagged as a guess.
- Bring your own providers
- Email through SendGrid, or through your own Gmail or Microsoft 365 mailbox over SMTP. Text and voice through Twilio. Your sending reputation, your 10DLC registration, your bill. Every outbound integration is off until you turn it on — a fresh tenant composes messages, runs every consent gate, records what it decided, and delivers nothing.
- Gmail and Outlook, without an OAuth project
- A mailbox and an app password, working the day you paste them in — no Google Cloud project, no consent screen, no verification review. The limits come with it and the screen says so before you commit: it sends as that one mailbox, Gmail rewrites a from-address it does not own, and the daily caps are hundreds rather than thousands. Past a few hundred recipients it tells you to use SendGrid.
- Alerts into Microsoft Teams
- Point the alert webhook at a Teams channel and job failures, dead letters and stalled queues arrive as cards somebody reads. Teams refuses the generic JSON that every other tool accepts, so the payload is built to match the endpoint — a connector gets a MessageCard, a Workflows URL gets an Adaptive Card, everything else gets plain JSON.
- Nothing is sent inline
- Every message goes on a durable queue keyed to the occurrence, delivered with retries and shared backoff, and dead-lettered rather than dropped. A message that failed is a row you can find and retry, not an absence you infer.
Service
Support that sits beside the account
- Tickets with queues and assignment
- Merchant issues become tickets attached to the merchant. The person answering can see the deal, the residuals and the last three conversations without opening a second system.
- Routing rules and agent skills
- Route by queue, priority, merchant or subject, to the people who can actually answer.
- SLA timers and capped escalation
- Tickets past their due time escalate, up to the level the rule allows. The cap is the point — without it an unattended ticket escalates forever and the notifications become noise everybody filters.
Automation
Work that happens without anybody remembering
- A workflow engine on leads, merchants and tickets
- Graphs of triggers, conditions and actions: assign, notify, move a stage, open a task, send a message. Delays resume where they left off, and a run that throws is marked failed rather than retried forever.
- Scheduled processing
- Residual runs, drip steps, health scoring, screening refreshes and reconciliation sweeps, each on a cadence chosen for the thing it watches rather than one global tick.
- Approval gates
- Automation proposes; a person disposes. Auto-approval is off unless you deliberately turn it on.
Administration
Setting up an office, and running several
Built for an operator with more than one tenant, and for the tenant’s own first day.
- Self-serve signup, then approval
- An ISO can sign itself up from the website. That creates a pending organisation and an administrator who cannot sign in until somebody approves them — so a signup form is a queue rather than a door.
- A setup walkthrough that knows what is missing
- Fourteen steps across six groups, each reporting done, still to do, not applicable — or unknown, when the check itself could not run. An office is not marked ready to trade while any required step is unknown.
- Starter content on day one
- Ten email templates and ten text templates seeded for a new office, idempotently, so nobody starts from an empty screen.
- Seven roles, three layers
- Platform operator, org admin, org user, sales rep and the optional merchant portal — enforced on navigation, on routes and on rows, all three, with permission sets configurable per office.
- Suspension that takes effect now
- Suspending an organisation revokes its live sessions rather than waiting for tokens to expire.
- Billing per organisation
- A base subscription, per-seat charges and metered add-ons above an allowance, with usage counted rather than estimated. An add-on you have not enabled costs nothing.
- Activity log, redacted before storage
- Who did what, recorded automatically, with sensitive values stripped on the way in rather than hidden on the way out.
Security
Getting in, and what it takes
The settings an administrator actually has to defend, rather than a page of logos.
- Lockout you set, that lets go on its own
- Six wrong passwords locks an account for fifteen minutes, and both numbers are yours to change. A lock always lapses by itself — one that needed an administrator could be inflicted on any colleague by typing a wrong password six times.
- A session timeout that is a ceiling, not a replacement
- Set it and it caps every user; leave it empty and each person chooses their own. A user may always pick a shorter time than you require, never a longer one — and the screen says so on the control rather than leaving somebody to discover it.
- A sign-in log, separate from the activity log
- Sign-ins, failures, lockouts, password changes and two-factor changes, with the address and IP. Attempts against addresses that are not accounts belong to no organisation, so they are visible only to us — which is the only vantage point from which a run spread across several customers is visible at all.
- Uploads judged by their bytes, not their name
- A file is checked against what it claims to be before it is stored. It is not malware scanning and does not pretend to be: a well-formed PDF carrying something nasty is accepted, and saying otherwise would be worse than saying nothing.
- Nothing that tells a stranger who banks here
- Sign-in, password reset and signup answer identically whether or not the address exists — including for an account that is locked. A reset link is a single-use row that expires, not a signed token that works every time it is found in a mailbox or a proxy log.
- Two-factor, and a way back from it
- TOTP with single-use backup codes, and an administrator who can clear a colleague’s lost authenticator — because the alternative was an UPDATE against the database.
Compliance
The rules that come with the industry
Enforced in the software rather than written in a policy nobody reads at the point of sending.
- TCPA and A2P 10DLC
- Consent captured and honoured, quiet hours applied in the recipient’s timezone, and campaign registration modelled rather than assumed.
- CAN-SPAM
- Unsubscribe handling appended by the engine itself, so a hand-written template cannot omit it.
- ESIGN and UETA
- The signing page records the trail those acts require — intent, consent, attribution and the document as it was signed.
- Truth in Caller ID
- Outbound caller identity is configured per office and confirmed out of band rather than typed in and trusted.
- Subject access and erasure
- Every table holding personal data is registered, and a build guard fails when a new one is not — so an export cannot quietly go stale. Erasure tombstones the rows. Uploaded identity and bank documents are deliberately retained under anti-money-laundering obligations rather than erased, and the subject is told so in the response rather than left to assume the file went.
- The national DNC registry is not checked
- Internal do-not-call state, consent and quiet hours are enforced. The federal registry needs a subscription and is not wired in — and the seam records unknown rather than clear, so it can never be mistaken for a check that ran.
Coming
A mobile application, Q1 2027
Not shipping yet, and deliberately listed apart from everything above — which is all built today. Reps spend their week in front of merchants rather than in front of a desk, and the pipeline, the merchant record and the day's calls are what that needs on a phone. If you want a say in what makes the first release, the conversation is worth having now rather than after it is drawn.
Underneath
And the parts that are not a feature
Tenant isolation enforced in the data layer, a hash-chained and externally anchored audit trail, durable outbound queues, and an alerter that tells somebody when a job stops. Nobody buys a CRM for these; everybody who has been burned once asks first.
Bring the thing you do in a spreadsheet
Residual splits and payout reconciliation are where these demos usually get interesting. Bring a real month and we will run it.