Appearance
Operations Playbook
Document type: Operations reference — user journeys Audience: Kaya Sync Operations Team (non-technical) Status: v1.0 — Approved Last updated: 2026-08-29
A plain-language, step-by-step guide to what every actor in the Kaya Sync ecosystem does, sees, and hears — from the farmer at origin to the regulator receiving quarterly exports.
For the ops team
This is a working reference for the people who run Kaya Sync day-to-day. Written to be read by non-technical staff, printed for onboarding, and quoted in support calls. Every phrase in quote marks (like "Show the number.") is a real prompt the operator sees on their phone.
The five principles behind the platform
Every rule in the platform comes from one of these five ideas. When something looks odd, ask: which principle is this defending?
1. No custody event, no payout
Nobody gets paid because they said they delivered. They get paid because the platform recorded a validated custody event with evidence. Settlement is a consequence of proof, not a button someone presses.
2. The designee phone number is the anchor
Cargo is identified by the designee's phone number, written physically on the container. No QR codes. No printed labels. If the phone number is unreadable, the cargo cannot move until it is fixed.
3. Low-literacy execution is the design floor
The mobile app uses icons, voice prompts, and short spoken phrases. If a step needs the operator to read a paragraph of instructions, the step is broken. This shapes every screen and every SMS.
4. Offline-first, but settlement is never offline
Operators capture scans even when they have no signal — videos are encrypted and stored on their phone until they reconnect. But payouts only happen after the server validates the scan. This stops offline fraud without penalising bad connectivity.
5. Every action creates a permanent record
Every scan, upload, hold, override, payout, dispute, and relabel is stored as an immutable event. Nothing is deleted. This is what makes disputes, audits, and regulator exports possible without special preparation.
Cast of characters
Eleven roles interact with Kaya Sync, in four groups.
Customers (they generate the demand)
| Role | Who they are |
|---|---|
| Originator | The person or business that wants to ship cargo. A trader, farmer, market seller, SME, or an enterprise shipper. Uses the mobile app or works through a Market Facilitator. |
| Designee | The person the cargo is going to. Identified only by their phone number. Does not need to install anything — SMS is enough. |
| Enterprise Client User | A large shipper or corporate buyer that uses the web portal to place orders in bulk, track SLAs, and pull evidence packs for their auditors. |
Field workers (they move cargo)
| Role | Who they are |
|---|---|
| Market Facilitator | A trusted local person at a market, staging yard, or loading terminal (often a market queen or loading foreman). Helps originators who can't use the app themselves. |
| Operator | A transport worker — tricycle, motorbike, small pickup, corridor truck, or bus. One account per person. Which loads they see depends on their assigned lanes: first-mile, mid-mile, relay, last-mile, or hub-handler. |
Ops team (Kaya Sync staff, running the platform)
| Role | Who they are |
|---|---|
| Ops Dispatcher | Assigns orders to operators. Watches the fleet on a live map. Approves aggregation plays. |
| Internal Ops Supervisor | Handles exceptions — reviews holds, resolves disputes, approves repack/relabel, adjusts trust tiers. |
| Ops Automation Assistant | A rules engine plus a human. Sends automatic reminders, chases missing evidence, and creates tasks for humans when it can't resolve alone. |
| Client Manager | Looks after one or more enterprise clients. Watches their SLAs, approves the first stage of a repack request, escalates disputes. |
External + platform (they observe or configure)
| Role | Who they are |
|---|---|
| Regulator | A government reader with scoped, read-only access to custody chains and compliance exports. Never sees fraud logic or trust scores. |
| Partner Organisation | A financier, bank, DFI, or ESG body that receives scheduled aggregate exports (never raw customer data). |
| System Admin | Our internal platform manager. Onboards new client organisations, configures policy parameters, and manages devices. |
The end-to-end journey
Thirteen stages, from an originator first typing an order into their phone to money landing in the last operator's account.
- Originator initiates. A trader, farmer, SME, or Market Facilitator creates a draft order in the app — origin, destination cluster, and a list of containers. Every container carries one mandatory field: the designee's phone number.
- Cargo is marked. The designee's phone number is physically written on every sack, crate, or bundle by hand. This is the anchor the entire platform uses.
- Origin scan. A live guided video captures the written phone number, the container in full, the packaging, and its condition. Capture is guided by icon-first prompts and works offline; encrypted videos sync when connectivity returns.
- System validates. The system reads the phone number from the video and compares it to what was declared. AI fingerprints the cargo and checks GPS and timestamp. Result:
PASS,PASS_WITH_TOLERANCE,HOLD, orFAIL. The order only enters Ready for Dispatch when every container passes. - First-mile pickup. A first-mile operator (with
ValidStart-of-Day attestation) is assigned by the Dispatcher or the auto-allocation nudge. They capture a pickup scan; custody transfers. - Hub aggregation / sorting. A hub handler batches and sorts the cargo onto a corridor with a batch scan.
- Mid-mile corridor run. A mid-mile operator carries the cargo along the corridor. Dual scans at every handoff — outgoing "Give load. Scan together." and incoming "Take load. Show number." — both operators co-located and inside the time window.
- Optional relay / disaggregation. If a play scores well, cargo is split or transferred to another mid-mile operator. Any relabel or repack in-chain requires Supervisor approval.
- Last-mile assignment. At the destination hub the cargo goes to a last-mile operator who picks it up with a receiving scan.
- Delivery to designee. Operator arrives; system SMSes an OTP to the designee's phone; operator captures the delivery scan ("Show receiver. Show number.") and enters the OTP the designee reads out. No OTP, no delivery.
- Integrity assessed. System compares delivery scan fingerprint to the baseline, matches the phone number, checks geo/time. Result: PASS, PASS_WITH_TOLERANCE, HOLD, or FAIL.
- Settlement is a consequence. On a validated pass, payouts flow along the custody chain to each operator's mobile money or bank account. Held custody = held payout, in escrow. Dispute or fraud = reversal. Nobody presses a "pay me" button.
- Closure and visibility. Order state closes; the originator sees confirmation and evidence; the Client Manager sees SLA metrics; the regulator and partner org can pull agreement-scoped exports; the event trail is immutable.
Why this matters for ops
Nearly every ops call will be about one of these 13 stages going wrong. Learning them in order means you can locate any incident on the map fast — "we're stuck at stage 7, the mid-mile handoff isn't completing" — and know exactly which role owns the resolution.
Order states in plain language
The internal state names use codes like InTransit and IntegrityHold. Here's what they mean when the ops team is looking at a dashboard.
| State | Plain meaning | What happens next |
|---|---|---|
| Draft | Originator has started typing but hasn't captured evidence yet. | Awaiting Origin Scan once details and designee phone are entered. |
| Awaiting Origin Scan | Order exists on the system, cargo is being prepared, waiting for the origin video. | Origin Validated on a PASS scan; blocked if the phone number isn't visible. |
| Origin Validated | AI has checked the origin scan; cargo identity is baselined. | Awaiting Pickup, once ready for dispatch. |
| Ready for Dispatch | Every container has passed origin; waiting for a first-mile operator. | In Custody on operator pickup scan. |
| In Custody / In Transit | An operator has the cargo and is moving it. | Awaiting Handoff, Delivery Pending, or a HOLD. |
| Awaiting Handoff | Operator arrived at a handoff point; waiting for both scans to complete. | Custody transfers to the next operator once both scans pass. |
| Delivery Pending | Operator is at the designee; delivery scan and OTP are about to happen. | Delivery Validation Pending once evidence uploaded. |
| Delivery Validation Pending | System is checking the delivery scan and the OTP the designee shared. | Delivered on PASS; HOLD or FAIL otherwise. |
| Delivered | The designee has received the cargo and confirmed; integrity checks passed. | Settlement Eligible. |
| Settlement Eligible | Everything is clean; payouts can go to operators. | Payout Released. |
| HOLD (Integrity Hold) | Something looks wrong — a supervisor needs to look. Payout is frozen. | Resolved (back to the appropriate active state), FAIL, or Recapture. |
| FAIL | Integrity failure serious enough to stop the chain. | Dispute or liability assignment. |
| Cancelled | Originator cancelled mid-transit. | Supervisor resolves in-flight containers per cancellation policy. |
| Closed | Delivered, paid, closed for reporting. | Archived. |
Common exceptions and how they're handled
A quick reference of the most common problems ops will hear about, and what the platform does to resolve each.
| Problem | Handled by | What happens |
|---|---|---|
| Phone number on cargo is unreadable at origin | Originator or Facilitator | Rewrite the number, rescan. Cannot dispatch until fixed. |
| Phone number on cargo is unreadable mid-chain | Ops Supervisor | Authorised relabel/repack event required. Before/after evidence captured. Fresh scan re-baselines the fingerprint. |
| Designee unreachable at delivery | Ops Automation Assistant → Supervisor | Second OTP sent. If still unreachable, human contacts through another channel. Reschedule or dispute. |
| Designee refuses delivery (wrong phone match) | Ops Supervisor | Dispute opened. Supervisor reviews custody chain and adjudicates. |
| Operator loses signal mid-transit | Automatic | Scans stored encrypted on their phone. Uploads and syncs when signal returns. No penalty for connectivity issues. |
| Start-of-Day attestation expires mid-run | Automatic | Active order continues. Operator cannot accept new loads until they re-attest. |
| Counterparty fails receive scan at handoff | Ops Supervisor | Custody stays with outgoing operator. Payout held. Supervisor investigates. |
| Repeated GPS jumps or replay suspicion | Ops Supervisor | Trust tier drop recommended. Possible suspension. Every prior scan reviewed for pattern. |
| Client Manager wants to override an integrity hold | Ops Supervisor | Rejected. Only the Supervisor has this authority. Escalation packaged and forwarded. |
| Operator claims delivery without a completed scan | Ops Supervisor | No scan = no delivery. Cargo state stays In Custody. Operator's word alone is not accepted. |
| Repack requested without a valid reason | Ops Supervisor | Rejected. Operator notified with the rejection reason. |
The words we use — prompt vocabulary
The exact phrases operators see on their phone and hear through voice guidance. Non-negotiable — every rollout, every language, uses the same anchor concepts.
When ops staff talk to operators over the phone, use these exact words. Consistency reduces confusion, especially when translated.
| When | The operator sees / hears |
|---|---|
| Phone number not visible | "Show the number." |
| Too far from cargo | "Move closer." |
| Poor light | "More light." |
| Scan success | "Good. Go." |
| Scan problem | "Try again." |
| Handoff — outgoing | "Give load. Scan together." |
| Handoff — incoming | "Take load. Show number." |
| Delivery | "Show receiver. Show number." |
| Offline capture saved | "Saved. Sync later." |
| Payout waiting | "Waiting check." |
| Payout available | "Money ready." |
| Something held | "Problem. Supervisor checking." |
Automation-layer SMS to operators (verbatim)
| When | The SMS says |
|---|---|
| Late order | "Your order [ID] is running late. Please update your ETA." |
| Missing SOD attestation | "Please complete your vehicle attestation to continue receiving orders." |
| Late upload | "Scan [type] for order [ID] is pending upload. Please ensure you have connectivity." |
Escalation ladder
Who escalates what, to whom, and when.
Ops Supervisor
(overrides · disputes · repack
· trust-tier changes)
▲
│
│ escalates
│
┌────────────────────────────┼────────────────────────────┐
│ │ │
Ops Dispatcher Client Manager Ops Automation Assistant
(stuck orders, (patterns · repack (unresolved chases · designee
corridor gaps, first approval · unreachable · connectivity
fleet welfare) SLA breaches) issues escalated to human)
▲ ▲ ▲
│ │ │
│ escalates │ escalates │ escalates
│ │ │
Operator Enterprise Client Operator
(one-tap in app) (portal ticket) (one-tap in app)
Market Facilitator ────→ Ops Supervisor
(integrity failures they cannot recapture)Escalation discipline
Two rules only. First, package the context — order ID, container IDs, timeline, evidence links — so the person you're escalating to doesn't have to hunt. Second, never re-escalate the same issue up the ladder more than once without a documented reason. Loops kill response time.
Glossary
Every specialised term in one place.
| Term | Plain meaning |
|---|---|
| Aggregation play | A system-recommended handoff where cargo from multiple operators is combined onto a single vehicle to save carbon and cost. Phase 1 requires human approval. |
| Akroma | Internal name for the evidence-capture subsystem. Handles guided video capture, OCR, offline sync, and fingerprinting. Ops team don't refer to this by name externally. |
| Attestation (Start-of-Day) | The daily vehicle-photo check every operator must complete before accepting loads. |
| Custody chain | The end-to-end record of who held the cargo at every point in its journey, backed by scan evidence. |
| Custody transfer | The moment one operator hands cargo to another. Requires two scans — HANDOVER + RECEIVE — both physically co-located. |
| Designee | The intended receiver of the cargo. Identified only by the phone number written on the container. |
| Device binding | The pairing of a specific phone to a specific operator account. Cannot use the platform from a different phone without re-binding. |
| Dispute | A formal case opened when a delivery is contested. Locked payout in escrow until the Supervisor adjudicates. |
| Dual scan | Two coordinated scans at a handoff — one from each operator. Both must be within the geographic proximity radius and the time window. |
| Escrow | A settlement partner holds the operator's earnings until the platform releases them. Kaya Sync never holds funds directly. |
| Evidence bundle | The complete package of scan videos, integrity results, GPS traces, and event history for a single container. |
| FAIL / HOLD / PASS / PASS_WITH_TOLERANCE | The four possible integrity check outcomes. PASS is clean. PASS_WITH_TOLERANCE is close enough. HOLD needs a supervisor look. FAIL stops the chain. |
| Fingerprint | The AI-generated identity signature of a cargo item, based on visual features from the origin scan. |
| Integrity check | The automated review that runs on every scan. Checks phone-number match, cargo fingerprint match, GPS plausibility, and time-window compliance. |
| Lane capability flag | The set of job types an operator is authorised for — first-mile, mid-mile, relay, last-mile, hub-handler. |
| Liability window | The time between the last PASS scan and the first HOLD or FAIL. Used to assign responsibility for damage or loss. |
| OCR | Optical character recognition — the automated reading of the phone number handwritten on the cargo. |
| OTP | One-Time Password. Sent to the designee's phone at delivery; they read it out to the operator; the operator types it in. |
| Payout milestone | A point in the custody chain where an operator becomes eligible for their share of the settlement. |
| Prompt vocabulary | The canonical short phrases the platform uses to communicate with operators (see above). |
| Relabel / repack | Authorised mid-chain change to cargo. Requires Ops Supervisor approval. Every relabel captures before/after evidence. |
| SLA | Service-Level Agreement. The delivery-time commitment made to an enterprise client. |
| Trust tier | An operator's reliability rating (Tier 1 highest, Tier 3 lowest). Controls what jobs they're eligible for and how fast their payouts arrive. |
Deep-dive per role
For a full step-by-step of what each person does — screen by screen, phrase by phrase — see the dedicated journey pages:
Customers
- Originator — the shipper (farmer, trader, SME, enterprise)
- Designee — the intended receiver
- Enterprise Client User — corporate portal user
Field workers
- Market Facilitator — trusted local, on-behalf-of originator
- Operator — all lanes: first-mile, mid-mile, relay, last-mile, hub-handler
Ops team
- Ops Dispatcher — queue + fleet + assignments
- Internal Ops Supervisor — overrides, disputes, trust tiers
- Ops Automation Assistant — rules engine + human
- Client Manager — client-scoped monitoring
External + platform
- Regulator — read-only compliance access
- Partner Organisation — scheduled aggregate exports
- System Admin — platform configuration
Also available
- PDF version for print / offline sharing — see the artifact in the CTO's ops-playbook publish (Aug 2026)
- Web version (this page) — always current, links live to the detailed per-role journeys
Version
Ops Playbook v1.0 · Prepared 29 August 2026 by Evanson Biwott (CTO) from Kobby Andah's founder journey docs and the internal wiki. For updates, edits, or additions, message Evanson directly.