Skip to content

Operations Playbook

Document type: Operations reference — user journeys Audience: Kaya Sync Operations Team (non-technical) Status: v1.0 — Approved Last updated: 2026-08-29

A plain-language, step-by-step guide to what every actor in the Kaya Sync ecosystem does, sees, and hears — from the farmer at origin to the regulator receiving quarterly exports.

For the ops team

This is a working reference for the people who run Kaya Sync day-to-day. Written to be read by non-technical staff, printed for onboarding, and quoted in support calls. Every phrase in quote marks (like "Show the number.") is a real prompt the operator sees on their phone.


The five principles behind the platform

Every rule in the platform comes from one of these five ideas. When something looks odd, ask: which principle is this defending?

1. No custody event, no payout

Nobody gets paid because they said they delivered. They get paid because the platform recorded a validated custody event with evidence. Settlement is a consequence of proof, not a button someone presses.

2. The designee phone number is the anchor

Cargo is identified by the designee's phone number, written physically on the container. No QR codes. No printed labels. If the phone number is unreadable, the cargo cannot move until it is fixed.

3. Low-literacy execution is the design floor

The mobile app uses icons, voice prompts, and short spoken phrases. If a step needs the operator to read a paragraph of instructions, the step is broken. This shapes every screen and every SMS.

4. Offline-first, but settlement is never offline

Operators capture scans even when they have no signal — videos are encrypted and stored on their phone until they reconnect. But payouts only happen after the server validates the scan. This stops offline fraud without penalising bad connectivity.

5. Every action creates a permanent record

Every scan, upload, hold, override, payout, dispute, and relabel is stored as an immutable event. Nothing is deleted. This is what makes disputes, audits, and regulator exports possible without special preparation.


Cast of characters

Eleven roles interact with Kaya Sync, in four groups.

Customers (they generate the demand)

RoleWho they are
OriginatorThe person or business that wants to ship cargo. A trader, farmer, market seller, SME, or an enterprise shipper. Uses the mobile app or works through a Market Facilitator.
DesigneeThe person the cargo is going to. Identified only by their phone number. Does not need to install anything — SMS is enough.
Enterprise Client UserA large shipper or corporate buyer that uses the web portal to place orders in bulk, track SLAs, and pull evidence packs for their auditors.

Field workers (they move cargo)

RoleWho they are
Market FacilitatorA trusted local person at a market, staging yard, or loading terminal (often a market queen or loading foreman). Helps originators who can't use the app themselves.
OperatorA transport worker — tricycle, motorbike, small pickup, corridor truck, or bus. One account per person. Which loads they see depends on their assigned lanes: first-mile, mid-mile, relay, last-mile, or hub-handler.

Ops team (Kaya Sync staff, running the platform)

RoleWho they are
Ops DispatcherAssigns orders to operators. Watches the fleet on a live map. Approves aggregation plays.
Internal Ops SupervisorHandles exceptions — reviews holds, resolves disputes, approves repack/relabel, adjusts trust tiers.
Ops Automation AssistantA rules engine plus a human. Sends automatic reminders, chases missing evidence, and creates tasks for humans when it can't resolve alone.
Client ManagerLooks after one or more enterprise clients. Watches their SLAs, approves the first stage of a repack request, escalates disputes.

External + platform (they observe or configure)

RoleWho they are
RegulatorA government reader with scoped, read-only access to custody chains and compliance exports. Never sees fraud logic or trust scores.
Partner OrganisationA financier, bank, DFI, or ESG body that receives scheduled aggregate exports (never raw customer data).
System AdminOur internal platform manager. Onboards new client organisations, configures policy parameters, and manages devices.

The end-to-end journey

Thirteen stages, from an originator first typing an order into their phone to money landing in the last operator's account.

  1. Originator initiates. A trader, farmer, SME, or Market Facilitator creates a draft order in the app — origin, destination cluster, and a list of containers. Every container carries one mandatory field: the designee's phone number.
  2. Cargo is marked. The designee's phone number is physically written on every sack, crate, or bundle by hand. This is the anchor the entire platform uses.
  3. Origin scan. A live guided video captures the written phone number, the container in full, the packaging, and its condition. Capture is guided by icon-first prompts and works offline; encrypted videos sync when connectivity returns.
  4. System validates. The system reads the phone number from the video and compares it to what was declared. AI fingerprints the cargo and checks GPS and timestamp. Result: PASS, PASS_WITH_TOLERANCE, HOLD, or FAIL. The order only enters Ready for Dispatch when every container passes.
  5. First-mile pickup. A first-mile operator (with Valid Start-of-Day attestation) is assigned by the Dispatcher or the auto-allocation nudge. They capture a pickup scan; custody transfers.
  6. Hub aggregation / sorting. A hub handler batches and sorts the cargo onto a corridor with a batch scan.
  7. Mid-mile corridor run. A mid-mile operator carries the cargo along the corridor. Dual scans at every handoff — outgoing "Give load. Scan together." and incoming "Take load. Show number." — both operators co-located and inside the time window.
  8. Optional relay / disaggregation. If a play scores well, cargo is split or transferred to another mid-mile operator. Any relabel or repack in-chain requires Supervisor approval.
  9. Last-mile assignment. At the destination hub the cargo goes to a last-mile operator who picks it up with a receiving scan.
  10. Delivery to designee. Operator arrives; system SMSes an OTP to the designee's phone; operator captures the delivery scan ("Show receiver. Show number.") and enters the OTP the designee reads out. No OTP, no delivery.
  11. Integrity assessed. System compares delivery scan fingerprint to the baseline, matches the phone number, checks geo/time. Result: PASS, PASS_WITH_TOLERANCE, HOLD, or FAIL.
  12. Settlement is a consequence. On a validated pass, payouts flow along the custody chain to each operator's mobile money or bank account. Held custody = held payout, in escrow. Dispute or fraud = reversal. Nobody presses a "pay me" button.
  13. Closure and visibility. Order state closes; the originator sees confirmation and evidence; the Client Manager sees SLA metrics; the regulator and partner org can pull agreement-scoped exports; the event trail is immutable.

Why this matters for ops

Nearly every ops call will be about one of these 13 stages going wrong. Learning them in order means you can locate any incident on the map fast — "we're stuck at stage 7, the mid-mile handoff isn't completing" — and know exactly which role owns the resolution.


Order states in plain language

The internal state names use codes like InTransit and IntegrityHold. Here's what they mean when the ops team is looking at a dashboard.

StatePlain meaningWhat happens next
DraftOriginator has started typing but hasn't captured evidence yet.Awaiting Origin Scan once details and designee phone are entered.
Awaiting Origin ScanOrder exists on the system, cargo is being prepared, waiting for the origin video.Origin Validated on a PASS scan; blocked if the phone number isn't visible.
Origin ValidatedAI has checked the origin scan; cargo identity is baselined.Awaiting Pickup, once ready for dispatch.
Ready for DispatchEvery container has passed origin; waiting for a first-mile operator.In Custody on operator pickup scan.
In Custody / In TransitAn operator has the cargo and is moving it.Awaiting Handoff, Delivery Pending, or a HOLD.
Awaiting HandoffOperator arrived at a handoff point; waiting for both scans to complete.Custody transfers to the next operator once both scans pass.
Delivery PendingOperator is at the designee; delivery scan and OTP are about to happen.Delivery Validation Pending once evidence uploaded.
Delivery Validation PendingSystem is checking the delivery scan and the OTP the designee shared.Delivered on PASS; HOLD or FAIL otherwise.
DeliveredThe designee has received the cargo and confirmed; integrity checks passed.Settlement Eligible.
Settlement EligibleEverything is clean; payouts can go to operators.Payout Released.
HOLD (Integrity Hold)Something looks wrong — a supervisor needs to look. Payout is frozen.Resolved (back to the appropriate active state), FAIL, or Recapture.
FAILIntegrity failure serious enough to stop the chain.Dispute or liability assignment.
CancelledOriginator cancelled mid-transit.Supervisor resolves in-flight containers per cancellation policy.
ClosedDelivered, paid, closed for reporting.Archived.

Common exceptions and how they're handled

A quick reference of the most common problems ops will hear about, and what the platform does to resolve each.

ProblemHandled byWhat happens
Phone number on cargo is unreadable at originOriginator or FacilitatorRewrite the number, rescan. Cannot dispatch until fixed.
Phone number on cargo is unreadable mid-chainOps SupervisorAuthorised relabel/repack event required. Before/after evidence captured. Fresh scan re-baselines the fingerprint.
Designee unreachable at deliveryOps Automation Assistant → SupervisorSecond OTP sent. If still unreachable, human contacts through another channel. Reschedule or dispute.
Designee refuses delivery (wrong phone match)Ops SupervisorDispute opened. Supervisor reviews custody chain and adjudicates.
Operator loses signal mid-transitAutomaticScans stored encrypted on their phone. Uploads and syncs when signal returns. No penalty for connectivity issues.
Start-of-Day attestation expires mid-runAutomaticActive order continues. Operator cannot accept new loads until they re-attest.
Counterparty fails receive scan at handoffOps SupervisorCustody stays with outgoing operator. Payout held. Supervisor investigates.
Repeated GPS jumps or replay suspicionOps SupervisorTrust tier drop recommended. Possible suspension. Every prior scan reviewed for pattern.
Client Manager wants to override an integrity holdOps SupervisorRejected. Only the Supervisor has this authority. Escalation packaged and forwarded.
Operator claims delivery without a completed scanOps SupervisorNo scan = no delivery. Cargo state stays In Custody. Operator's word alone is not accepted.
Repack requested without a valid reasonOps SupervisorRejected. Operator notified with the rejection reason.

The words we use — prompt vocabulary

The exact phrases operators see on their phone and hear through voice guidance. Non-negotiable — every rollout, every language, uses the same anchor concepts.

When ops staff talk to operators over the phone, use these exact words. Consistency reduces confusion, especially when translated.

WhenThe operator sees / hears
Phone number not visible"Show the number."
Too far from cargo"Move closer."
Poor light"More light."
Scan success"Good. Go."
Scan problem"Try again."
Handoff — outgoing"Give load. Scan together."
Handoff — incoming"Take load. Show number."
Delivery"Show receiver. Show number."
Offline capture saved"Saved. Sync later."
Payout waiting"Waiting check."
Payout available"Money ready."
Something held"Problem. Supervisor checking."

Automation-layer SMS to operators (verbatim)

WhenThe SMS says
Late order"Your order [ID] is running late. Please update your ETA."
Missing SOD attestation"Please complete your vehicle attestation to continue receiving orders."
Late upload"Scan [type] for order [ID] is pending upload. Please ensure you have connectivity."

Escalation ladder

Who escalates what, to whom, and when.

                          Ops Supervisor
                     (overrides · disputes · repack
                      · trust-tier changes)


                                │ escalates

   ┌────────────────────────────┼────────────────────────────┐
   │                            │                            │
   Ops Dispatcher      Client Manager           Ops Automation Assistant
   (stuck orders,      (patterns · repack       (unresolved chases · designee
    corridor gaps,      first approval ·         unreachable · connectivity
    fleet welfare)      SLA breaches)            issues escalated to human)
        ▲                     ▲                            ▲
        │                     │                            │
        │ escalates           │ escalates                  │ escalates
        │                     │                            │
     Operator          Enterprise Client              Operator
   (one-tap in app)      (portal ticket)          (one-tap in app)

   Market Facilitator ────→ Ops Supervisor
        (integrity failures they cannot recapture)

Escalation discipline

Two rules only. First, package the context — order ID, container IDs, timeline, evidence links — so the person you're escalating to doesn't have to hunt. Second, never re-escalate the same issue up the ladder more than once without a documented reason. Loops kill response time.


Glossary

Every specialised term in one place.

TermPlain meaning
Aggregation playA system-recommended handoff where cargo from multiple operators is combined onto a single vehicle to save carbon and cost. Phase 1 requires human approval.
AkromaInternal name for the evidence-capture subsystem. Handles guided video capture, OCR, offline sync, and fingerprinting. Ops team don't refer to this by name externally.
Attestation (Start-of-Day)The daily vehicle-photo check every operator must complete before accepting loads.
Custody chainThe end-to-end record of who held the cargo at every point in its journey, backed by scan evidence.
Custody transferThe moment one operator hands cargo to another. Requires two scans — HANDOVER + RECEIVE — both physically co-located.
DesigneeThe intended receiver of the cargo. Identified only by the phone number written on the container.
Device bindingThe pairing of a specific phone to a specific operator account. Cannot use the platform from a different phone without re-binding.
DisputeA formal case opened when a delivery is contested. Locked payout in escrow until the Supervisor adjudicates.
Dual scanTwo coordinated scans at a handoff — one from each operator. Both must be within the geographic proximity radius and the time window.
EscrowA settlement partner holds the operator's earnings until the platform releases them. Kaya Sync never holds funds directly.
Evidence bundleThe complete package of scan videos, integrity results, GPS traces, and event history for a single container.
FAIL / HOLD / PASS / PASS_WITH_TOLERANCEThe four possible integrity check outcomes. PASS is clean. PASS_WITH_TOLERANCE is close enough. HOLD needs a supervisor look. FAIL stops the chain.
FingerprintThe AI-generated identity signature of a cargo item, based on visual features from the origin scan.
Integrity checkThe automated review that runs on every scan. Checks phone-number match, cargo fingerprint match, GPS plausibility, and time-window compliance.
Lane capability flagThe set of job types an operator is authorised for — first-mile, mid-mile, relay, last-mile, hub-handler.
Liability windowThe time between the last PASS scan and the first HOLD or FAIL. Used to assign responsibility for damage or loss.
OCROptical character recognition — the automated reading of the phone number handwritten on the cargo.
OTPOne-Time Password. Sent to the designee's phone at delivery; they read it out to the operator; the operator types it in.
Payout milestoneA point in the custody chain where an operator becomes eligible for their share of the settlement.
Prompt vocabularyThe canonical short phrases the platform uses to communicate with operators (see above).
Relabel / repackAuthorised mid-chain change to cargo. Requires Ops Supervisor approval. Every relabel captures before/after evidence.
SLAService-Level Agreement. The delivery-time commitment made to an enterprise client.
Trust tierAn operator's reliability rating (Tier 1 highest, Tier 3 lowest). Controls what jobs they're eligible for and how fast their payouts arrive.

Deep-dive per role

For a full step-by-step of what each person does — screen by screen, phrase by phrase — see the dedicated journey pages:

Customers

Field workers

  • Market Facilitator — trusted local, on-behalf-of originator
  • Operator — all lanes: first-mile, mid-mile, relay, last-mile, hub-handler

Ops team

External + platform


Also available

  • PDF version for print / offline sharing — see the artifact in the CTO's ops-playbook publish (Aug 2026)
  • Web version (this page) — always current, links live to the detailed per-role journeys

Version

Ops Playbook v1.0 · Prepared 29 August 2026 by Evanson Biwott (CTO) from Kobby Andah's founder journey docs and the internal wiki. For updates, edits, or additions, message Evanson directly.

Kaya Sync Internal Documentation