Control room.
Every tool that runs the business, on one screen. The band below is live system status; everything under it opens a tool.
Reading system status…
Resolving the band…
System Meter
The public cans-sold meter: snapshots, stages, force-resync, and physical-sales imports.
Reviews
Moderate product reviews: hide, unhide, mark spam, and post an official response.
Subscriptions
View and manage customer subscriptions: pause, resume, skip, and cancel.
Sample Offer
The launch sample offer: create, activate, and end the free-pack campaign.
Wholesale
The wholesale application queue: approve, reject, request info, and manage accounts.
Playbooks
Create, edit, and publish the rhythm playbooks shown on the storefront.
Analytics
Read-only dashboards: revenue, subscriptions, cohort retention, ambassadors, and email.
Experiments
A/B experiment authoring: create, start, pause, conclude, and view per-variant scoreboard.
Money
Cash on hand, monthly burn and revenue, with runway computed from the first two. Every figure records its source and the date it describes.
Payouts
The quarterly ambassador payout queue: mark sent, cleared or failed, void with release, add adjustments, and settle bespoke bonuses.
KPIs
Reading the ladders.
Reading the ladders.
Metrics
Resolving the library.
Resolving the library.
The meter.
Loading…
Loading…
Loading…
Loading…
+ New physical-sales import
Lifecycle.
Search by customer email to manage their subscriptions, or open one from the queue above.
The free pack.
Loading…
The queue.
Loading…
Promos
Reading the discount codes.
Reading the discount codes.
Partners
Reading the programs.
Reading the programs.
Sales home
Reading the order book.
Reading the order book.
The book.
Every order the webhook has recorded, with what was paid and what it was worth after any edit. Reading only, for now.
Who carries us.
Every wholesale account, what it owes, and whether it reaches the public store locator. A stockist appears on the map only while it is both approved and opted in, so the two can disagree and this says when they do.
Moderation.
Loading…
One record per person.
Stage is worked out from what the record shows, never typed, so it moves on its own when someone orders. Email and phone are not in this list. Opening a contact shows them and is recorded in the audit log.
Campaign reach
Contacts
Privacy.
The statutory clock, and who can be reached.
Reading the privacy queue.
The ladder, and what it owes.
Five tiers earned over a rolling twelve months. Upgrades happen the moment an order is paid; downgrades only at the twice-yearly re-evaluation. Credit is an append-only ledger, so what a member can spend is worked out from it rather than stored.
One queue, three states.
Every ticket records a conversation that happened somewhere else and resolves against a contact, so the answer you gave is visible next time they order. Open is your turn, waiting is theirs, closed is done and reopens if they write back.
Everything we can send.
Read straight out of the registry the send pipeline itself imports, so this list cannot drift from the code. Subjects and SMS bodies are rendered by calling each template with its own sample data, not stored as copies.
What is booked, and what it drinks.
Sampling, demos and markets on one calendar, with the cases each one commits. Closing an event asks what it actually drank, because that is the only number that says what is left in the sample run.
Experiments.
A/B tests on email broadcasts: create a draft, start it, read the scoreboard, and call it only when the maths says you can. Significance is computed from the real exposure counts, never stored.
Reading the experiments.
Open an experiment to read its results.
Who wants to carry it.
Ambassador applications. Approving one issues the referral link, queues the starter kit and sends the welcome email, so the decision here is the decision everywhere.
Nothing leaves until you arm it.
A campaign is created as a draft and sends nothing. Arming it queues the send to real subscribers, which cannot be recalled, so arming asks you to type the name.
New campaign
The quarterly run.
Loading…
Bespoke bonuses awaiting negotiation
Loading…
What search sees.
Every route the storefront serves, read live from Shopify, and the one field on it worth editing here. Anything under forty characters gets replaced by copy search writes itself, so thin descriptions are named rather than hidden.
One source for how it looks and sounds.
The tokens are read from the stylesheet the site renders with, not typed out here, so this page cannot quietly disagree with the site. The voice rules are the ones that keep getting broken.
The work before the piece.
Outlines, drafts, and the calendar they publish on. The article itself is written and published in Shopify; a row here records how it got there and links to what it became. The journal is the only top of the funnel that does not cost per click, and it only works when it ships.
Library
Reading the index.
Reading the index.
The library.
Loading…
Editor.
Scheduled status is informational — no cron auto-publishes yet. Publish manually when ready.
Paste an AI-generated playbook JSON (4 modules × 4 toggle levels × 7 days + 4 grocery lists). The server validates on Save — any errors land in the panel below with the exact path and message.
Every sentence, and what stands behind it.
Health Canada regulates both products as Natural Health Products, so a statement about a benefit is a regulatory record rather than a piece of copy. Nothing here is edited: a change is a new version, and the old one keeps saying what it said at the time.
Roadmap.
The stage ladder behind the public counter. Each stage unseals at a cans-sold threshold rather than a date, so the roadmap cannot be late.
Reading the ladder.
Money
Every figure on this page is computed from the ledger, live.
Loading the money home.
Vendors.
Every supplier the ledger has paid, with where the money went and what the bills carried.
Reading the suppliers.
Model.
Reading the assumptions.
Reading the assumptions.
Reading the ledger.
Every balance, and the zero underneath.
Each account with a balance through the chosen date, shown on its debit or credit side. Derived from posted entries on every load; nothing here is stored. The check figure at the bottom must be zero, and if it is not, this screen says so before anything else does.
What the period earned, and what it cost.
The six sections of the income statement over a date range, grouped the way the workbook groups them, with gross profit, operating income and net income underneath. Derived from posted entries on every load; nothing here is stored.
What the company owns, owes, and keeps.
The five sections of the balance sheet as of a date. Retained earnings is computed on every load as net income since inception; it is never posted. Derived from posted entries; nothing here is stored. Assets must equal liabilities plus equity, and if they do not, this screen says so first.
Where the cash came from, and where it went.
The indirect cash flow statement over a date range: net income walked back to cash through operating, investing and financing movements, each line driven by the account's cash flow class. Opening cash plus the net change must equal closing cash, and the reconciliation renders either way.
See it before it writes.
A journal entry, both sides, previewed by the server before anything is posted. The preview runs the exact same write the Post button runs, inside a transaction that always rolls back, and reports the lines, the entry number it would take, and any refusal the books would raise. Post stays off until the preview is clean. An entry system you have to trust blindly is one you check by hand afterwards.
Both sides, previewed first
One entry, and its corrections.
Any entry by its number: the lines, the signature, and the reversal link in both directions. A posted entry is the record; correcting it posts a reversing entry dated today and marks the original void, which moves no statement figure. Imported entries read the same way, marked imported.
The return, derived.
The GST/HST working paper: every line computed from posted entries for a reporting period taken from the live registration. Nothing here is stored and nothing is filed from here. It is what the CPA checks before NETFILE, with the settled non-resident position shown rather than hidden.
Position.
Cash, burn and revenue, each with the date it describes and where it came from. Runway is cash divided by burn and is never stored.
Reading position…
Month close
Closing a month writes its burn and revenue from the ledger and locks the period: nothing can be posted into a closed month until it is reopened, and reopening asks for a reason that goes in the audit trail.
Reading the calendar…
Record a figure
Entries are append-only. To correct a figure, record it again for the same as-of date. The newer entry becomes the value and the older one stays in the history.
History
Expenses
Unlike the figures above, an expense is a record of something that happened rather than a belief about it, so a mistake here is corrected in place rather than superseded. Edit any row, or remove it to the trash below. Removing takes it out of every total straight away, including a closed month, which is why a closed month will then show as needing a re-close.
Trash
A removed expense leaves every total straight away, including any closed month, which is why a closed month shows as needing a re-close afterwards. It stays restorable here for 30 days. After that it is not deleted, it simply stops appearing in this list, so an old figure can still be explained.
Months
Closing a month records its burn from the ledger. The current month cannot be closed while it is still running. Re-closing a month is how a correction is made: the new figure supersedes the old and the old one stays in the history.
Recurring
The numbers.
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Order analytics.
Reading the order book.
Reading the order book.
Who can get in.
Roles decide what every other screen allows. An account with a password and no TOTP is the weak one, so security is a column rather than a detail.
Access is one role per person. The design's per-tool grants are not implemented: that needs a grants table, which is a data-model decision rather than a screen. Two rules are enforced by the server. You cannot change your own role or status, and the last active founder cannot be demoted or suspended. Both would lock the admin out of repairing itself.
Hiring.
Reading the plan.
Reading the plan.
Everything connected.
Whether each service is configured, what it is trusted with, and when its credentials last changed. Never the credentials themselves.
Renewals.
Reading the clock.
Reading the clock.
System health
Reading the run ledgers.
Reading the run ledgers.
Every decision, and who made it.
Written by every admin action that changes anything. Filter to an entity to see everything that ever touched one row, or to a person to see everything they did.
Managed settings.
Every runtime rule this admin can safely change on its own, versioned and audited.
Reading the registry.
Governance.
How this company decides things, written down. Declared commitments, not system-enforced rules.
Reading the record.
Support SLA.
What this company commits to on support response. Declared commitments, not system-enforced rules.
Reading the record.
Privacy posture.
What this company commits to on customer data. Declared commitments, not system-enforced rules.
Reading the record.