- Stage A (now): tech-powered agency. Own drivers, Heathrow CAP 2330 niche. Fill-rate & compliance-led; price as tactical weapon, not headline — deep cuts reserved for displacing locked-in competitors on specific accounts.
- Stage B: master vendor network (S-02).
- Stage C (Yr 3+): franchise/licence, Driver Hire precedent — franchisee owns local liability, pays royalty + platform fees; the platform is the OS being franchised, not just the brand.
The idea tree. Direction of the whole project as one connected structure. Chips at the bottom of each tile jump to the idea it feeds. Blue chips (where present) still link to implementation items on page ②.
One shift, one record. Employers, agencies and workers around the same object; flat fees when it fills; a subscription floor under it; other people's capital behind it; and a passport that lets a worker walk through any door once. Every tile below opens. Every tile ties into another — follow the chips and any idea leads to the rest of the platform.
THE MODEL
What Crewex is — the shape that survives the pivot.- Client contracts platform/CargoCrew as MV; own pool fills first, overflow cascades to vetted tier-2 agencies who supply their own workers on their own payroll and liability.
- Platform consolidates billing, pays tier agencies, keeps the spread. Fast supplier payment = network recruitment carrot.
- Client shielding: anonymised job cards until assignment + non-solicitation in the Supplier Agreement — that clause is what makes shielding legally real.
- Tier network doubles as the tenant funnel: agencies on overflow → warm upsell to full tenancy.
- Legal work needed: MV schedule for Client ToB v2.0; new Supplier Agreement (compliance warranties, insurance minimums, transfer-fee chain, audit rights); broker confirmation on insurance.
Org layer (private, walled)
- Each agency — CargoCrew included — has its own workspace: own roster, own clients, own rates, own bookings. Invisible to other orgs. This is the existing tenant/SaaS model.
Marketplace layer (shared, cross-org)
- Populated by: MV overflow (S-02) + platform-originated client demand (clients who register directly with the platform, no agency yet) + optional early-publish by an org that knows it's short-handed.
- The marketplace never moves workers — it moves jobs. An org claims a job, then fulfils it with their own people under their own payroll/liability, exactly per S-02's core rule.
- "Platform Direct" (platform itself as an employing agency) explicitly rejected as a core feature — stays available only as an ordinary org anyone (incl. Dan/CargoCrew) could choose to run under standard org rules. No employer-of-record logic in the core.
Open
- Claim mechanism: first-come-first-claimed vs short bidding window. Visibility while listed: rate/location/requirements shown pre- or post-claim.
The kernel (identical for every industry)
- Booking record + three lenses (S-17) · availability patterns + start-time windows · timesheet → approval → invoice → funding → payslip · UK payroll (sector-blind by nature) · AWR clocks (the 12-week rule covers ALL agency workers) · ratings + no-show rule (S-19) · portability protocol (S-20) · marketplace with proposed-price bidding (S-18). Nearly everything already built is kernel — which is why this decision is cheap now and expensive in a year.
The organisation pack (config per tenant, never hardcoded)
- Vocabulary packs: dispatch/planner/allocations · driver/operative/locum · booking/shift/placement. One record, three lenses, three vocabularies — persona-native AND industry-native labels are a config table, not strings in code.
- Role catalogue: HGV Class 1 → registered nurse → sous chef → SIA guard. Roles carry their own rate-guide bands, shift presets, marketplace categories.
- Generic credential engine (the big one): a credential = type + expiry + verification method + blocking rules. CPC, ADR, DVLA checks = rows in the logistics pack. DBS = care pack. SIA licence = security pack. NMC pin = nursing pack. Don't build "CPC checking" — build the engine.
The trap to avoid
- Agnostic platforms fail by being shallow everywhere. The credential engine must be expressive enough for drivers'-hours / tacho / night-out rules — the logistics pack is the proof the engine is deep enough, and it ships first. Architecture agnostic, go-to-market vertical: launch narrow (HGV, one corridor) with the kernel as insurance for sector two.
- Naming consequence: another vote against trucking-flavoured names, for network/work names that carry any industry.
- Demo suites stay trucking-skinned deliberately — they depict ONE CONFIGURED TENANT of the agnostic platform.
The principle (say this sentence to the devs)
- A booking is created once and never duplicated. Each persona's "rota" is a projection of the same records, filtered by relationship: recruiter → bookings where they are the supplier, across all their clients. Employer → bookings at their sites, across all their suppliers. Worker → their own shifts, availability and money. Nothing is copied, so nothing can disagree.
What propagates (the sync contract)
- Worker edits availability / start-time window → every agency roster showing them updates → employer benches stop offering them blocked days. Already demonstrated in the three demo suites.
- Employer places or moves a shift → supplier's bookings calendar updates + worker gets the offer. Worker accepts → both rotas confirm at once.
- Timesheet hours (GPS or manual start/finish) → employer approval grid → approved hours become the SAME numbers on the recruiter's invoice and the worker's payslip. One record, three renderings — this is why nothing is ever re-keyed.
What never crosses the wall
- Recruiter's client list, rate cards and margins: invisible to other recruiters AND to the platform's other tenants. Employer never sees pay rates or margins. Worker never sees charge rates. Other workers: invisible to each other.
- Privacy walls are enforced at the data layer (row-level permissions on the one record), not by building separate apps — the dev-spec way to say it.
The three options weighed
- 1 — Software for employers and agencies, marketplace opt-in inside it. CHOSEN. Nobody is fought: employers escape the ring-round, agencies get handed work, platform carries no employment liability. Only version buildable at 20k with one founder. Closest to Youtemp BUT with the real difference: Youtemp was agency-to-agency job passing, no employer entry point; here the EMPLOYER posts the job.
- 2 — Pure marketplace, platform becomes one big agency. REJECTED. Indeed Flex / Jobandtalent path: heavy capital, all employment liability in-house, head-on competition with every agency instead of selling to them. Wrong fight at this size.
- 3 — Both. NOT A SEPARATE OPTION — it is option 1 later. Direct-employment lane (S-24) stays designed, switched off, door architecturally unlocked. You can add it in year two or three; you cannot un-scare an agency that has already decided you are a competitor.
The unlock — driver registers, AGENCIES compete for him
- Dan's move: the driver signs up directly (licence, CPC, tacho, DBS, availability, travel radius = one verified passport, filled once) and sits in a pool. Agencies pitch for him — their rate, their regular work. Driver picks one, or two, or three. Platform never employs; agencies do what agencies are for.
- Keeps the emotionally central "driver finds his own work" idea alive with none of the EOR, IR35, pensions or insurance weight (all S-24 problems dissolve).
- Cold-start fix: drivers can join before any agency does, because there is day-one value — register once, get found by several agencies instead of filling in five application forms.
- The quiet strategic win: once signed, the driver stays in the app for availability, timesheets and payslips. Platform holds LIVE SUPPLY DATA across every agency on it — which is precisely what makes the employer-side marketplace fill fast.
- Snags to manage: driver acquisition becomes the platform's own job and it is expensive; and leakage — agencies could take the details and sign the driver off-platform. Mitigated by the royalty below plus keeping timesheet/pay flow in-app.
Symmetric origination royalty (Dan) — the fairness keystone
- Whoever introduced the worker earns a small royalty when another party uses them. Agency-originated: any other tenant using that worker pays the origin agency. Platform-originated: any tenant using that worker pays the platform. Same rule, every origin, no exemptions.
- This is the honest answer to the referee-owns-a-team problem (S-23): the platform is not above its own rules, it is simply one more origin among equals.
- GUARDRAIL: the platform's own rate must be visibly EQUAL TO OR LOWER THAN the agency rate. If the house slice is bigger, the fairness story collapses.
- Extends S-20's worker royalty and confirms the doctrine: value crossing a boundary is metered and tolled to whoever built the relationship — never walled, never free.
Open numbers (Covrig session + tenant conversations)
- Royalty percentage, and duration of the tail (12 weeks? 12 months? — S-20 assumed 12 months, S-27 discussion floated 12 weeks; reconcile).
- Whether platform-originated drivers also carry a pair-window, or royalty only.
- Anti-leakage terms: what stops an agency signing a pool driver off-platform.
Dan's five, tested (26 Aug)
- 1 · Employer posts past ASL — S-26 cascade holds. ADD: every market fill is captured as a relationship (rate card + panel entry) so the market permanently thickens each employer's private ASL.
- 2 · Agency signs pool worker, working tomorrow — S-27 pool + S-28 one-tap registration. GUARD: speed never pressures checks; RTW + licence duties stay per-agency, checklist visibly completes. "Fast because the paperwork is digital, not because it's skipped."
- 3 · Worker lists with target rate — third price signal (worker floor / employer proposed price / agency margin between); calculator flags non-viable matches. GUARDS: contact masked until worker accepts an approach; approaches rate-limited.
- 4 · Closed circuit — S-23 Network OFF, refined: opt-out per RELATIONSHIP, not just per tenant (closed with anchor client, open with spare capacity — toggles already support).
- 5 · Agency with workers, no job, browses — fill side of 1; cascade timing applies.
The five that were missing
- 6 · THE RELAY — agency with neither job nor worker connects market job + pool worker, carries employment + compliance, keeps the margin. Liquidity engine of the whole market. Tenant-acquisition weapon: a brand-new one-person agency earns from day one with an empty book — nothing else in the industry offers that. Platform's S-27 origin royalty monetises it automatically.
- 7 · Attached-worker sharing (agency to agency) — legal shape CHOSEN: passport-move (worker one-tap joins Agency A, works under A, origin B earns royalty), NOT subcontract chains (liability blur; many hirer contracts ban second-tier supply). No inter-agency invoicing — S-28 rails settle it.
- 8 · Worker raises hand — worker sees a market job and expresses interest. Attached: own agencies get the lead first (S-24). Pool: routes to any relaying agency. Public listings double as a driver-acquisition channel.
- 9 · Availability broadcast — agency lists idle capacity anonymised (credentials, rating, radius, rate band — no names). Data already exists; it is a visibility switch.
- 10 · Temp-to-perm exit — S-26.3 transfer fee auto-routed; in the matrix because relationships must pay the right people on the way OUT of the market too.
Two new conflicts found + fixed
- Duplicate demand: employer AND their agency post the same need → two fills, two drivers at the gate. FIX = S-17 one-record rule as a BUILD requirement: an agency posting client overflow posts the SAME shift record cascading, never a parallel copy.
- Client exposure: agency-posted jobs must be client-anonymised (radius, shift, rate — no client name) until fill, or the market becomes a client-poaching directory. Employer-posted jobs carry their own name by choice.
Deliberate edges
- Employers browsing pool workers directly: DEFERRED to v2 — anonymised, interest routed through relaying agencies.
- Worker → employer direct employment: EXCLUDED on principle (S-27 launch shape). The door stays architecturally unlocked (S-24), switched off.
- Rules engine — GoRules ZEN (MIT). Rust core, JSON decision models, decision tables, microsecond evaluation, embeddable React editor. This is "rules as data" — name it in the dev spec; the 50–100-case suite runs against it instead of a hand-rolled engine.
- e-passport ingestion — PaddleOCR (Apache 2.0). Photographed licence/CPC/RTW docs → structured fields; human confirms instead of types. Verification itself stays rented (TrustID).
- Notifications — Novu. One hub for the "shift offered" race: push → SMS → email fallback. Licence has shifted over time — read LICENSE before adopting.
- Timers/workflows — Temporal (MIT). Durable cascade windows that survive restarts. Heavy to run: cron + DB column at launch, Temporal at scale.
- Auth — Keycloak / Ory (Apache 2.0). Three user types, orgs, MFA, magic links. Never hand-built.
- Support — Chatwoot (MIT). One inbox for all three sides from day one.
- Analytics — Metabase (AGPL, internal only) or Superset (Apache 2.0, embeddable). The AGPL rule applied: internal use fine, serving it to users triggers source-sharing.
- E-signature — rent it. Documenso is AGPL; at our volumes the licence risk outweighs the saving.
- Growth tools (ours, not the platform): Scrapling for the REC-directory call list; changedetection.io on competitor pricing and the GLAA register.
- The line that holds: the marketplace itself — one record, cascade, fees, matching — has no open-source shortcut, and that is correct. It is the differentiating layer; it is Crewex.
THE MARKETPLACE
How a shift gets filled.- Fills anywhere → closes everywhere the same instant: marketplace, every agency dashboard, employer board.
- Reopen button if a fill falls through — same record, new event, next fill charged as a second fill.
- Never a copied market_jobs row wearing different visibility. Same row, different lenses.
- Post-time choice: agencies first (default on) or straight to network — checkbox, because they may have already phoned round.
- Window 2 hours standard, 1 hour when the shift starts inside 24. Expiry moves it to the network in every view.
- Own agencies are notified the instant a shift posts. They never learn about their client's shift from the network.
1 · Employer-PSL acquisition loop (cold-start solution)
- Employer pitch: "every worker, every supplier, one rota" — useful with ZERO marketplace, day one, with their existing agencies.
- The loop: employer joins for the one-rota convenience → invites their current suppliers to make it work → every invited supplier is a recruiter lead on the platform → each recruiter brings their other clients and workers.
- The employer's own PSL becomes the tenant-acquisition engine — Dan's own move, not borrowed. (Correction 20 Aug: previously mislabelled "Youtemp's wedge". Per Dan's direct conversation with Youtemp, their model is agency-to-agency job passing with a 30% margin share on a credits-SaaS — they never had an employer-led entry. The PSL loop is original to this project.)
2 · Direct bookings — who employs (draft answer)
- Client-as-employer: dead on arrival for ad-hoc temp work (no client payrolls a Saturday driver).
- Ltd/self-employed workers: genuinely direct engagement possible (they are businesses; status-checked; platform as introducer = employment agency regime, lighter than employment business).
- PAYE "direct" bookings: client gets the Uber experience, but employment routes to a TENANT recruiter (worker's preferred agency first). Direct demand becomes a lead the platform GIVES tenants, fee on top — channel conflict inverted into the platform's best gift.
- Legal note: anyone employing + supplying = employment business in law (full Conduct Regs + AWR), whatever the app looks like. "Umbrella" is just an employment business that doesn't find work. The wanted concept = Employer of Record (Jobandtalent/Coople model).
3 · House fulfilment entity (liquidity floor)
- Open marketplace fails without supply-of-last-resort — first unfilled booking kills the client. First-party supply (Amazon Retail pattern) fixes it.
- Separate Ltd, NOT CargoCrew: neutrality optics (infrastructure, not a rival agency), liability ring-fence (employment risk away from platform IP co and CargoCrew's book), and the regulatory container (employment-business status, KIDs, EL insurance, pension, own funding line).
- NOT hidden — "shadow" can't mean secret (KIDs, contracts, Companies House). Openly declared + bound by rules in tenant terms.
- Fulfilment waterfall, codified: ① worker's attached agencies first claim → ② any tenant in the pool → ③ house entity, LAST, only after a defined unclaimed window; never approaches tenant-attached clients/workers; stats visible.
- Model line: platform = rails · tenants = the market · house entity = the liquidity floor. Entity only needed at open-marketplace stage; £12 to incorporate when the time comes. Inherits April 2026 umbrella-liability duties.
OPEN — before this tile can go green
- Monetisation model for the whole stack — how the fee mechanics (S-13b) map onto: one-rota employer accounts, direct bookings, tenant-routed leads, house-entity fills, marketplace vs workspace activity. Dan to think; next working session.
- Conduct Regs review of the introducer (employment agency) lane for direct Ltd bookings.
- Channel-conflict rules drafted into tenant terms (the binding-our-own-hands clause).
Mechanic
- Post = role + day/time + proposed £/hr charge (form pre-fills the network guide band for that role/shift so nobody posts blind).
- Agencies bid: accept the proposed price, undercut to win volume, or bid OVER with justification the employer can see (ADR ticket, 4.9★ driver, guaranteed arrival). A bid attaches a named, rated worker — you're choosing a person at a price, not a price in the abstract.
- Employer's compare view: bid £ vs proposed, worker rating, agency fill-history, time-to-respond. One tap to award; losing bidders auto-notified.
Why bids beat fixed price
- Urgent Friday-night gap: bids come in OVER proposed — the employer pays market rate and the shift fills, instead of a fixed-price post dying quietly.
- Quiet Tuesday: bids come UNDER — employer saves money, hungry agency wins work. Both directions make the network stickier than phone-around.
- Every awarded bid is a real transaction price → feeds the guide band → better proposals next time. The data moat compounds.
Guardrails + open questions
- Floor: bids can never imply worker pay below NLW + on-costs — the calculator engine already knows the legality line per shift and blocks bids under it.
- House entity (S-16) bids LAST and never undercuts a tenant's live bid — the floor supplies liquidity, not price war.
- Monetisation is deliberately NOT part of this feature. Bidding exists because it's good for employers (urgent shifts fill, quiet shifts get cheaper) and good for agencies (win work at prices they choose, over-bid with justification). Whatever charging model comes out of the S-16 working session sits ON TOP of the platform — it doesn't ride inside this mechanic.
- OPEN: sealed bids vs open ledger (do agencies see each other's bids?). Sealed = better margins for agencies; open = faster race to fill. Lean sealed-with-rank-hint; decide with real users.
Rating — the currency of the marketplace
- Employer rates the worker after each shift: stars + optional quick tags (on time, good attitude, knew the kit). Two taps, done on the approval screen — rating capture rides the timesheet-approval moment, so it actually happens.
- Ratings power everything downstream: marketplace bid sorting (S-18 shows ★ next to every bid), "book again" lists, agencies' own dispatch picks. Reliability is THE product in temp work — this is the data moat.
- Design question worth separating: quality stars vs a reliability score. Stars = how good were they on the job. Reliability = did they show up, on time, as booked (computed from clock-ins, not opinions). Two numbers may be fairer and more useful than one — a brilliant driver with one bad week shouldn't look like a bad driver.
Unannounced absence = automatic ★1 (drafted, not settled)
- The rule: booked, didn't show, didn't tell anyone → system applies ★1 for that shift automatically. Evidence is already in the platform: confirmed booking + no clock-in + no cancellation record. Nobody has to argue.
- Why it's right in spirit: no-shows are the single worst event in temp logistics — a truck doesn't leave. The network can only beat phone-around if showing up is priced in.
- Why it's PINNED: genuine emergencies (hospital, accident) where the worker COULDN'T announce — appeal path needed, with the agency as first reviewer? Auto-★1 vs marking it on the separate reliability score instead, leaving stars for quality? Repeat-offence escalation (2nd no-show = suspension from offers?) vs one-strike harshness. Dispute window + who arbitrates (agency employs them; employer was harmed; platform holds the data). Get this wrong and good workers leave; get it soft and the rating means nothing.
Announced absence — the humane half (in worker app spec)
- "Can't make it" button on every confirmed shift: reason category (illness / family emergency / transport / other) + free text. One tap notifies agency AND employer instantly, timestamps the notice, and starts the replacement cascade (agency bench → marketplace) while the shift can still be saved.
- Announcing early protects the worker: an announced absence with decent notice is NOT a ★1 — it's a normal life event, logged. The rating rule punishes silence, not sickness.
- Notice tiers (draft): 24h+ = no mark · under 12h = logged on reliability, no star impact · under 2h / after start = treated as no-show unless emergency-flagged. Exact thresholds to be decided with real agency input.
Cancellation warnings — before, not after
- The app shows consequences BEFORE the worker confirms a cancellation: "Cancelling now (9h before start) will be logged on your reliability record. Unannounced no-shows are an automatic ★1." Informed choice, no surprises, no tribunal-bait.
- Same principle for agencies and employers later: client cancels on a worker inside 24h → worker compensation rules? (Two-sided fairness — parked, but the symmetry question will come.)
OPEN — before this goes green
- Auto-★1 vs reliability-score mark: decide the mechanism after talking to 3–4 real agency owners + a handful of drivers.
- Appeal/dispute flow and who judges. Repeat-offence ladder. Rating visibility rules (public to all employers vs summary only). Minimum shifts before a rating shows. Gaming protection (rating-bombing, mate-rating).
Employer launch package
- "Free for founding clients" (not "first year free" — doesn't teach the market the price is zero, no cliff-edge renewal).
- One rota across all their agencies + direct bookings + marketplace access.
- Own permanent staff on the rota, names-only — no registration, no personal data, no employment relationship, pure planning entries. Turns the product into the complete who's-working picture; the reason they open it every morning. Upsell path later if they want those staff fully onboarded.
Agency assurance
- Encrypted client database = table stakes. The promise that lands is the S-17 wall written into tenant terms with audit rights: no other tenant, no house entity, no platform staff browsing their clients or rates. Contractual, not just technical.
Worker portability — the ground truth
- The agency veto doesn't exist today: HGV temps already sit on 3–4 agency books. Conduct Regs prohibit charging workers work-finding fees or penalising them for working elsewhere. Any "agency doesn't allow the worker to move" design is illegal and fictional — the platform only makes existing portability visible.
- Therefore: protect the agency's INVESTMENT and CLIENT RELATIONSHIPS. Never restrain the WORKER.
The three-layer protocol
- ① Default privacy, worker-triggered activation. Agency-uploaded workers are private roster entries (dormant passport). Network activation happens only in the worker's own app, agency notified. The agency's upload is never the leak.
- ② Client-pair protection window. For N months, a worker introduced by Agency A cannot be supplied to Agency A's existing clients via any other tenant or the house entity. Kills the real nightmare (own worker at own client via a cheaper rival) while leaving the worker free everywhere else. Mirrors Conduct Regs transfer-fee/extended-hire logic between businesses; enforced in tenant terms.
- ③ Introduction royalty. Introducing agency earns a small % on the worker's shifts via OTHER tenants for the first 12 months of network activity. Uploading a roster becomes seeding an annuity, not arming competitors. B2B money via platform terms — permitted; the hard rule is no cost ever touches the worker.
- Provenance (Dan's flag, 20 Aug): the compensate-the-origin-agency instinct is Youtemp's too (their version: 30% of margin per booking). Differences that make ours workable: small % not 30 (gratitude, not rent — at 30% nobody claims the job) · 12-month introduction tail, not a forever toll · the WORKER moves via passport activation, jobs aren't cross-passed · and the fee settles automatically because the platform sits in the money flow — the mechanism Youtemp couldn't name from a credits-SaaS.
- Waterfall alignment: worker's attached agencies already get first claim (S-16) — priority + pair window + royalty together make introducing workers rational.
OPEN
- Numbers: pair-window length (6 vs 12 months?), royalty % and duration — set with real agency input, same session as the rating-rule edges (S-19).
- Sales line to agencies: "we protect your investment and your clients — nobody can imprison workers, and a platform that tried would lose the workers, then the agencies."
The scenario (Dan, 24 Aug)
- Client says to their agency: "use TempCrew so we share the rota and I can book directly from your available drivers." Agency: great idea — until they see the marketplace and think "I lose workers, and the platform owner (a competing agency) harvests my list."
- Reality check in our favour: workers stay for good work and good relationships; multi-registration already happens invisibly today. The fear is bigger than the churn. But the fear decides the sale.
Missing piece 1 — marketplace is a DOOR, not a room
- Tenant-level Network OFF: an agency can run the full ops system (shared rota, client self-serve booking of THEIR drivers, timesheets, invoicing, payroll, compliance) with ZERO marketplace exposure. Workers invisible to the network.
- Per-driver, per-client visibility: "Hellmann sees + books these 14; DHL these 9; nobody sees the rest." Client "booking directly" = self-serve booking THROUGH the agency — agency still employs, still bills, still margins. They lose phone tag, not workers.
- Opt-in with visible upside beats reassurance: "you're not in the marketplace unless you switch it on — and here's what you EARN if you do" (S-20 royalty + pair window).
- → WORKSHOP TASK: add Network ON/OFF master switch + per-client driver visibility toggles to the recruiter suite.
Missing piece 2 — the referee owns a team (say it before they ask)
- Platform = separate legal entity from CargoCrew. CargoCrew joins as a tenant behind IDENTICAL walls — no special data access, no preferential routing, house entity last in the waterfall (S-16).
- Data-use covenant in tenant terms: the platform may never use a tenant's roster, clients or rates for the benefit of any other tenant INCLUDING CargoCrew — with audit rights. This was S-16's open "channel-conflict clause"; it is not a clause, it is the headline.
- Founder names his own conflict unprompted → founder gets believed.
Legal detail (weeks, corrected)
- AWR 12 weeks = equal treatment. Different thing entirely.
- Transfer fees (Conduct Regs reg 10): chargeable to a HIRER taking the temp on, only within 8 weeks of assignment end or 14 weeks from first assignment start (extended-hire option must be offered). Outside: no claim.
- Worker moving BETWEEN agencies: no fee regime exists in law at all — workers are free. So the platform's pair-window + royalty fills a gap the law leaves open = agencies get MORE protection on-platform than off. Selling line, not defence.
- Verify final drafting with Covrig alongside the Conduct Regs introducer review (S-16 open item).
The script (in this order)
- 1. "Your workers stay yours — nothing is visible until each worker switches themselves on. Most won't; people stay where the work is good."
- 2. "The marketplace is OFF for you unless you turn it on. Off = your client books your drivers through you, faster. That's it."
- 3. "If a worker activates and roams: nobody supplies them into your clients for N months, and you earn on their shifts elsewhere for a year. Today a driver joins a second agency quietly and you get nothing. Here you get paid."
- 4. "On me: the platform is a separate company. CargoCrew is a tenant behind the same walls as you — it's in the contract, and you can audit it."
- Worker sees every agency's shifts. Where not registered, the button registers-and-accepts: profile shared exactly as the home agency holds it, revocable any time.
- Fills as a £2 network match charged to the accepting agency. The worker never sees a fee.
- This is the portability protocol in action — the pool becomes real the first time a Brightcare shift is accepted by a DriveLine driver.
- Brief handed to Claude Code: seed data across transport, warehouse, care, hospitality; cascade countdown live; fees shown before the tap; event log with timestamps.
- Section 6 of the brief is this board's rules written as code constraints — the build must say them back first.
THE MONEY
How Crewex earns — flat, flat, floor.- 50p when the shift went to an agency that already had the client. £2 when the platform made the match — network fill, pool worker, relay, or a worker registering with a new agency to accept.
- Rebooks are charged again — a second fill is a second piece of real work.
- No fault logic in a 50p fee. Cancel before any fill: free.
- The fifty pence buys invisibility. A percentage announces a competitor with a stake in their pricing. A flat fee can be raised later; a percentage can never be lowered without looking like gouging.
- Active = paid at least once that month. Idle workers free.
- ~10% of projected revenue but 100% of the certainty; transactions are the upside.
- No minimum term is the anti-GEMS weapon: the reason to join us is that you don't need permission to leave.
- Their cross-hiring concept designs the re-registration problem into the product; correct model moves assignments, not workers (S-02).
- Control of billing = control of network, data, and payment terms. We stay in the chain for MV work; funder-settled deduction for tenant work (S-04).
- Benchmark: agencies pay 2.5–4% today across finance + CRM + payroll on a fragmented stack. 3% bundled undercuts it; for unfundable agencies it's market access.
- Even 1% net at scale accepted — near-zero marginal cost. £10m funded ≈ £100k/yr; £50m ≈ £500k/yr.
- Tiered down at volume so growth never makes leaving look cheaper. Stickiness: cash-flow rails ≠ churn-able software.
- Price the tenant bundle against the 100%-advance rate — frictionless is the promise.
- Rate arguments: channel volume (one integration, many agencies) + de-risked book (client-verified timesheets, credit-gated onboarding → lower disputes/fraud). The anti-Vincere story: our engine produces correctly interpreted invoices their platform can't.
- Sonovate funds via securitisation (£165m BNP/M&G) — sub-1% day one unlikely; ratchet is the credible path. Ask for both ratchet and rebate structures priced.
- Tier-agency early payment: free first 6 months then ~1.5–2%, or fee from day one? (Land-grab logic favours free-then-fee.)
- MV cascade spread: fixed £/hr (rate-engine consistent) vs % of tier charge?
- Bad-debt protection in the 3%: recourse vs non-recourse — price both.
- MV contracting entity: platform brand or CargoCrew Ltd? (links to S-09)
- Year-one funded-volume projection = gating item for the Sonovate commercial meeting.
- Courier Exchange: ~£170/mo, 12-month lock-in, no usage pricing — and members publicly begging for our model. Their price is their vulnerability; ours is the pitch.
- TEG/SmartPay: record-keeper for 24 years, then a wallet — and even now the invoice stays carrier→shipper. Money moved through, title never taken. Externally-factored invoices excluded — the collision to design around with Sonovate.
- Booking.com: the rake works only on demand you originate; parity clauses died in court (DMA, Dec 2024). Build the road, not the toll booth.
FUNDING & PAYMENTS
Other people's capital, our record.- Structure B (tenants): Sonovate's balance sheet, their bad-debt risk. White-labelled — tenant sees "[Platform] Pay"; Sonovate invisible. Fee deducted at settlement → collection ≈ 100%, paid before the agency is. White-label is Sonovate's own productised offering ("name us as a funding partner or white-label our funding").
- Structure A (MV cascade only): our client, our invoice, our facility funds the gap, we pay tier agencies fast.
- Why not full flow for tenants: every debtor lands on our facility → facility limit becomes the network's growth ceiling; re-advancing = functionally lending. Temp Station's model works on one blue-chip debtor (FedEx); our shape is many small debtors — opposite.
- Pipeline: timesheet → rate engine interprets → client approves in-portal → invoice auto-generated → Sonovate → funding → 3% deducted → their slice kept → our share remitted.
- Non-circumvention with 2–3yr tail · platform owns tenant & transaction data · settlement-level fee split with per-invoice reporting · white-label tier by name · no exclusivity without a price · credit-limit visibility/appeals (their declines wear our brand).
- Funder-agnostic architecture (D-03) is the negotiating leverage made real.
Key findings from the reply
- No API. No self-serve API, no docs, no sandbox — roadmap only. Our requirement logged as formal product feedback. Phase 2 (D-06) parked indefinitely; file-based is THE integration, not an interim.
- Two products: Funding Only (invoice CSV import exists; timesheets = individual manual upload, each verified) vs Middle Office (they run timesheets/assignments/invoices/payments incl. full embedded PAYE payroll — PAYE/NI, statutory, pension, HMRC, payslips).
- Middle Office PAYE runs on THEIR calculations — "we calculate, you execute" not available on PAYE side. Their interpretation layer vs our rate engine = the same gap as Vincere. Fork to resolve on the call.
- Sleeper win: Funding Only has a bulk-pay CSV (bank details + amount, paid from available balance) — that IS "we calculate, you execute" for Ltd/supplier payments. The MV fast-payment mechanism exists today.
- Approval evidence: screenshot/PDF from client's own system already acceptable (worker name, hours, authoriser, approval visible). Verification friction is front-loaded: proven history → evidence on only ~50% of invoices + retrospective audits.
- Highest-value action: get our portal's approval-record PDF format pre-approved by their Verification/Risk team BEFORE the devs build it. Garin has offered to forward a sample.
Reply sent + call prep
- Reply drafted & sent: call request (45–60 min, product/solutions + Middle Office pricing), approval-evidence sample spec, invoice CSV template request, bulk-pay CSV template request, Middle Office pricing, API feedback logged.
- Tier-1 call questions: evidence sign-off in writing · can Middle Office run from OUR gross figures · Middle Office pricing · what "proven history" means concretely for the 50% evidence reduction.
- Tier-2: volume pricing tiers · bulk-pay fund timing · client credit-check process/turnaround · 85% vs 100% advance mechanics.
- Tier-3: API timeline + design-partner route · timesheet bulk upload timeline · WHO runs the embedded/partnerships side (get the name).
- NOT on this call: tenant network, white-label, wholesale rates. Reveal from strength later — with the volume projection + 10 weeks of clean batches in hand.
- PILOT UPDATE (13 Aug): Garin — "actively looking for customers to support a pilot scheme of our API features, this could be a good match." Design-partner slot offered unprompted. Posture: yes enthusiastically, but CSV path stays the foundation (pilots = pre-GA, no SLAs); build file-based in parallel, never blocked on pilot timelines. Promoted to Tier-1 call questions: pilot scope (submission/webhooks/settlement?), GA timeline, partner obligations, any cost.
- Sharpened Tier-1 question: "If our system sends fully calculated line items — hours, rates, gross — can Middle Office / the pilot API execute invoicing, payroll and payments from OUR figures without your interpretation layer? Cost per worker per week?" This single answer decides the back-end architecture.
- Trail, not bounty. Ongoing commission on funded volume, life-of-relationship as the anchor; expect a 12–24 month tail as the counter.
- Originated = arrived through us — then every invoice they fund counts, including clients not on Crewex. Fallback: platform-processed invoices only.
- Two non-negotiables: the agency pays not a penny more than going direct, and no exclusivity — funding on Crewex is a menu.
- We can audit the volume: their invoices are generated from timesheets approved in our software.
- Scale honesty: 20 agencies × £40k/mo ≈ £10m/yr through the pipe ≈ £10k/yr at 0.1%. The fee pays for plumbing; the stickiness is the product.
- Lane 1 — pass-through. Employer pays through the platform via a regulated payments partner (Stripe Connect / Modulr shape); money never sits in Crewex's hands; fee clipped in flight. TEG needed a wallet construct for exactly this.
- Lane 2 — referral (launch). Sonovate's capital behind our "get paid day one" button; their loan, their risk, their debenture — on the agency, never on us.
- Lane 3 — later. Ring-fenced spot-factoring in a separate company: buy the approved-hours invoice, recourse terms first, only credit-checked employers. Middle step once lane-1 volume proves the cycle.
- Never: Sonovate funding Crewex itself. No debenture over the platform.
- You enter the employment chain by one act: invoicing the client for the supply of the worker in your own name. So Crewex never does.
- Financing an agency's invoice does not move the supply relationship — banks fund agency invoices all day and employ no drivers.
- Payments are held by the regulated partner, never by Crewex. AWR, Conduct Regs, payroll: always the agency's.
- Shown in-platform as "fundable to £X" — turns funding from an application into a toggle.
- Doubles as free underwriting for lane 3 later: we only ever advance against approved hours of pre-checked employers.
- Questions 6–10 on Neal's list. Must be soft (no footprint) and fast (seconds).
COMPLIANCE & TRUST
The passport that makes the network possible.- Worker profile = RTW status, licences/CPC, work history, ratings — a reusable trust layer across agencies, not a CV dump.
- Two match flows, both live: (1) agency browses/searches the worker pool and sends an offer; (2) client posts a job into the marketplace, an agency claims it and fills it — from their own roster or the worker pool.
- Legal nuance: an agency's statutory RTW "excuse" needs them to have commissioned/relied on a compliant check themselves — inheriting a stored result may not discharge their own duty. Build as "agency re-triggers an instant check via the same IDSP using the worker's existing digital identity," not "agency reads someone else's PDF." Same speed to the worker, correct legal footing for the agency. Needs a real legal review before build.
- Agency always remains the legal employer/engager, whichever flow is used — liability stays fully at the org layer.
Legality (Dan's question, 24 Aug)
- A worker may register with unlimited agencies; agencies CANNOT restrict it. "Fully registered with each individually, made to seem effortless" is exactly the correct architecture.
- Youtemp's "you own the guy for 12 weeks" premise: wrong in law (see S-23 — transfer fees are hirer-facing, 8/14-week windows; NO fee regime for worker moving between agencies). Royalty tail is therefore pure contract — set by platform terms, any length both sides accept. RECONCILE: S-20 assumed 12-month tail; 12 weeks floated. Covrig confirms in writing.
- Royalty rate decided direction: 10-15% of margin, lean 10 (Youtemp's 30% = partner-split psychology, deters placement; 10% = finder's-fee psychology, work flows). Add pence-per-hour floor and cap. Two hard limits: worker never charged or penalised (Conduct Regs), and terms must be proportionate platform rules, not cartel-ish restraints. Movement free, money follows introduction — two layers, workers only ever see the first.
Per-agency duties (each file survives an EAS inspection standalone)
- Own contract + own Key Information Document (pre-assignment pay breakdown) · own right-to-work check (cannot rely on another employer's) · own DVLA licence-check mandate · own suitability assessment.
What the platform reuses (data flows, duties don't)
- Passport holds licence, CPC, tacho, RTW docs once. One-tap join: pre-filled registration + documents pushed → agency reviews, clicks verify → contract + KID out for e-sign. Minutes, not days.
- Accelerators that already exist: digital RTW via certified identity service providers (platform can partner with / become one later) · licence-check industry runs on a driver's standing 3-year e-declaration — capture one consent per agency at join.
- GDPR basis = worker-initiated join; the tap is the consent. NEVER push pool-driver details to an agency uninvited (also the S-27 anti-leakage posture).
The compliance moat — roaming's two dangers only the platform can solve
- AWR continuity: the 12-week clock follows WORKER + HIRER, not the agency; anti-avoidance rules punish structured dodging. Off-platform, Agency B cannot see Agency A's six weeks at the same hirer. Platform tracks the clock across agencies automatically.
- Drivers' hours: driving/rest limits attach to the DRIVER across all employers. Two agencies booking the same man tonight + tomorrow cannot see each other today — collectively illegal, individually "compliant", tired drivers on motorways. Platform sees both bookings; flags or blocks the clash. A safety feature NO incumbent can offer.
- The sentence: "the platform makes free movement safe and legal in ways that are impossible without it."
Settlement rails (from the same session)
- Royalty computed off approved hours — the platform's sacred object — so it works regardless of whose pay-and-bill runs the money. Sonovate = optional partner lane, never mandatory (established agencies have factoring contracts); other lanes: API/export to Xero-Sage etc., or platform invoices + own factoring.
- Monthly netted statement per agency: earned on your workers, owed on theirs, one figure. Collection by direct debit alongside the platform fee; platform transfers to origin agency. Full line-level transparency both sides (worker, shifts, using agency).
- Covrig: handling A-to-B money can tip into regulated payments territory — structure as platform fee + rebate, or run through a licensed provider (GoCardless/Stripe). Not a blocker; don't build a bank account with a spreadsheet.
- Moat: compliance architecture (TrustID RTW, CheckedSafe licences, WTD/tacho gates, AWR, IR35/SDS, PAYE) + daily operational reality of running it.
- InstaCrew teardown confirms: bootstrap listings board (JNX Technology, inc. Oct 2025), £3.99/shift–£19.99/mo, hospitality; no employment, no payroll, liability on their client. Low threat, quarterly glance. Validates demand.
- Landscape: Ubeya closest analogue; Indeed Flex/Coople/Instawork compete with agencies — we build rails for them.
- Steal: £3.99 try-one-booking entry pricing for platform-originated demand later.
- Booking flow, payment, invoice, support, cancellation — always platform-branded regardless of which agency fulfils it. Client never "leaves" the platform experience.
- Fulfilment credit shown but subordinate: "This booking is fulfilled by [Agency], a verified partner" — present for transparency/trust (and likely consumer-law reasons), never prominent.
- Reviews/ratings stay platform-owned — client rates the booking; feeds platform trust signals and optionally the agency's own profile, but the client relationship and "book again" prompt stay platform-side always.
- Consistent visual identity regardless of fulfiller — same confirmation email, tracking screen, invoice format whether it's CargoCrew's own driver or a marketplace agency's.
- Why this matters commercially: it's what makes the "forever" client-origination fee (S-13b) durable — if the experience is genuinely platform-branded end to end, client loyalty stays with the platform rather than drifting to book the fulfilling agency direct next time.
- Open tension (not urgent): the same principle needs to work symmetrically so agencies still feel primary ownership of their own client relationships in aggregate — revisit once further along.
STRUCTURE & LEGAL
Chains we stay out of, fences we build.The one rule
- UK law: anyone who employs AND supplies a worker is an employment business. So a PAYE-shaped shift always needs an employer of record. The platform question is never "agency or no agency" — it is "WHICH company is on the payslip for this shift."
Lane by lane (answers to Dan's three questions, 24 Aug)
- Unattached worker joins the platform: Ltd/self-employed can contract direct (platform = introducer) — but IR35 caution: HMRC targets driver PSCs; a driver in the client's truck rarely passes. Narrow lane, real for some roles, not the mainstream. PAYE free-floaters → offered to tenants FIRST as recruitment leads ("verified Class 1, passport complete — invite to your roster?"), house Ltd employs them only as backstop.
- Can the master agency use them? Yes — but the default employer for free-floaters is the RING-FENCED HOUSE LTD, never CargoCrew the trading agency. If unattached workers auto-flow to CargoCrew, the S-23 "funnel feeding the owner" suspicion becomes true. House employs, house margins = platform floor revenue.
- Attached worker wants a marketplace job "directly": route their INTEREST, not their employment, around the agency. Worker taps "I want this" → his own agencies get first right ("your driver wants this job — bid him in?") → agency places, margins, everyone wins; the worker's tap did the agency's BD for them. Falls through only if his agencies decline → any tenant (pair-window + royalty per S-20) → house last.
Design consequences
- Worker experience stays "tap, work, get paid" — the employment lands lawfully underneath, on agencies before house, every time.
- House employment book stays small BY DESIGN — it only grows where tenants declined. A growing house share = signal to recruit more tenants in that corridor, not a win.
- OPEN: EOR mechanics + contracts with Covrig (alongside introducer review) · umbrella/EOR comparison (Jobandtalent model) · how the house Ltd handles pensions/holiday at small scale.
The structure
- Ops Co — pure software: rota, timesheets, payroll engine, compliance, invoicing. SaaS revenue. Boring, low regulatory weight. Cannot leak workers — owns no marketplace.
- Marketplace Co — the network: bidding (S-18), royalties + pair-windows (S-20), worker activation, transaction revenue. Carries ALL employment-law weight (introducer regime, EOR duties). Owns the house Ltd (S-24) as employer-of-last-resort subsidiary.
- CargoCrew Ltd — a tenant. Same walls as everyone. Nothing else.
What it buys
- S-23 script upgraded: not "you can audit the walls" but "they're different buildings." Agency signs ops SaaS with Company A; joining the network = a second, separate agreement with Company B. Opt-in becomes literal.
- Regulatory containment: a legal hit on the marketplace side leaves the software tenants run on untouched.
- GDPR elegance: the S-20 worker activation toggle IS the consent event sharing their profile ops-co → marketplace-co. Legal mechanism = product feature, same switch.
- Optionality: either business can raise or sell separately (SaaS multiples vs marketplace multiples).
- S-21 side-effect: two entities can carry two names — could resolve the trucking-name vs agnostic-ambition tension. Parked; naming closed.
THE TRAP (fatal if ignored)
- Separate entities ≠ separate products. The marketplace's unfair advantage is reading live availability, ratings and passports from the ops layer — without that it is just another job board (see graveyard). Rule: one codebase, one kernel, one product experience — two legal entities behind the curtain, joined by a consent-gated data bridge. The user never sees the corporate seam.
Costs + timing
- Two sets of accounts + an intercompany agreement (who pays whom for what). Modest, real.
- Timing critical: restructuring AFTER tenants sign = re-papering every contract (novation). Decide before first signature → Covrig session (with introducer review + S-23 drafting + S-24 EOR contracts — one legal session covers all).
- OPEN: holdco on top now or later · which entity owns the brand/IP · transfer pricing once money flows.
- Their clients: they invoice, they own the relationship, we take 50p. The fee buys invisibility.
- Our clients (won by our ads and sales): we contract, we invoice, we subcontract the fill to platform agencies at an agreed rate — the master-vendor lane. Phase 2; capital + licence questions to Covrig first.
- Booking.com proves the split: 15–22% on demand they originate, £0 on the guest who walked in. Nobody pays a rake on their own book.
- Enforceable when reasonable: bounded duration, only clients actually introduced. Blanket-and-forever dies in court.
- Deterrent, never a revenue line — Booking's parity clause was the strongest in the world and a court deleted it.
- The real defence is the road: timesheets, approval, invoicing, AWR clock live here; leaking means going back to WhatsApp for 50p.
1 · Margin erosion — the agency's SECOND fear (serious)
- S-23 answers "will I lose my workers?" — nothing answered "will I lose my RATES?" An employer could reverse-auction their own PSL agencies via marketplace bids.
- FIX — the cascade rule: an employer's shift goes to their own agencies FIRST; reaches the open network only after they pass or a time window expires. The marketplace fills gaps — it never re-shops filled demand. Must be as loud in the pitch as the worker protections.
- Alternatives mapped (24 Aug) — three families: BLOCK (cascade · rate-card floors — rejected: employers hate, unpoliceable, kills price discovery · segmentation to overflow-only — rejected: gameable, rigid), COMPENSATE (incumbent override royalty on unfilled shifts at their client — flips incentive, incumbents WANT the network; same design move as S-20's worker royalty · match rights — rejected: makes incumbent a price-taker, institutionalises the squeeze), BLIND (sealed bids — weak alone, cheap complement · platform-set pricing à la Uber — rejected: price-setter is politically radioactive + no data yet + deletes S-18 mechanic).
- Reframe with legs: cascade as the EMPLOYER'S setting, not the platform's rule — employers configure their own PSL ordering/windows; platform = neutral referee enforcing existing commercial agreements, shipped default incumbents-first. Easier posture to defend.
- CHOSEN POSTURE: launch = cascade-by-default, employer-configurable, incumbents always notified, sealed bids on. v2 once liquidity exists = incumbent royalty. Legibility beats elegance in the trust phase.
2 · Whose data is the performance history?
- Worker activates: credentials clearly travel. But reliability was computed on Agency A's book — A could claim it.
- FIX: platform-computed scores (hours, reliability, ratings) belong to the WORKER and travel; agency-entered private notes never move. State it in terms.
3 · Temp-to-perm leakage → feature
- Employer hires a network driver permanently, bypassing all. Law gives the frame (8/14-week transfer window, S-23).
- FIX: platform-standardised temp-to-perm fee in hirer terms, routed automatically to the supplying agency. Another leak converted to agency revenue.
4 · House entity's quiet incentive
- House margin = platform revenue → micro-incentive for tenant fill-failure. Waterfall fixes behaviour; trust needs proof.
- FIX: S-23 audit rights explicitly cover WATERFALL LOGS — evidence every job was offered to tenants before the house touched it.
5 · Ops Co vs Marketplace Co tension (S-25 corollary)
- Ops Co earns when agencies thrive privately; Marketplace Co earns when work crosses walls. Same founder, opposing incentives.
- FIX — written resolution rule: ops-side trust outranks marketplace-side revenue, always. The marketplace dies without tenants; not vice versa.
The one-paragraph stress-tested pitch (24 Aug)
- "A shift gets posted, worked and paid in one system — and every party is structurally protected from every other." Full paragraph in chat 24 Aug: cascade → bid → approve-creates-invoice-and-pay → EOR waterfall with logs → opt-in portability with royalty + pair-window + transfer fee → two-company structural wall.
What GEMS is
- Agency-only CRM + workflow: candidate/client management (Companies House lookups, duplicate checks, bank-detail recognition), bookings with rate cards, CV parsing + radius search, timesheets feeding THEIR processing department, invoicing + credit control, within-agency AWR tracking, margin/debtor reports.
- Model: software free, locked to Simplicity finance or back-office. Revenue = factoring fees + payroll processing. The software is bait for the funding relationship — Sonovate pattern with a nicer front end.
Structural comparison
- One-sided vs three-sided: employers get a view-invoices portal, workers get a login — neither OPERATES anything. No employer-posted shifts, no worker passport, no cross-agency anything. Each agency is an island.
- Brings the agency zero new work. Sharpest line: GEMS helps an agency administer the business it already has; TempCrew does that AND brings it business it doesn't have.
- They structurally CANNOT follow: a cross-agency network would loosen the finance lock-in the company is built on. Another exhibit for the incumbents-paid-to-keep-corners-separate thesis.
- Where they honestly win today: free price, done-for-you payroll processing, 20 years of trust. Their customer = the one-person agency that wants everything handled. Not the beachhead tenant.
Dan's read (26 Aug) — the hostage mechanics
- "Free" is paid twice: buried in factoring margin where it can't be itemised, and in switching costs once candidates/clients/timesheet history/payroll records are captive. Then rates nudge up, credit tightens, and you swallow it. Case studies all celebrate switching IN; nobody writes the switching-out one.
The mirror + the lesson (tenant-terms commitments)
- Agencies WILL ask: "aren't you doing the same?" Principled answer: their lock-in is structural (captive data, bundled finance, painful exit); ours is earned (network brings work, compliance de-risks, automation saves hours) — with the door visibly open.
- Exit rights in tenant terms: full data export any time in usable formats · pricing as a line item on a statement, never buried in margin · no long minimum terms · finance a chosen lane, never a condition (S-28).
- Sales weapon Simplicity cannot copy: "the reason to join us is that you don't need permission to leave."
Stolen for the backlog
- Companies House lookup + duplicate check + bank-detail recognition in agency client-onboarding · "bring your data in an afternoon" import path (migration friction is the incumbent's real moat) · reinforces S-16 assumption: agency SaaS seat priced light, transaction layer is the business.
BRAND & FRONT DOOR
The name, the rules, the door.- Crewex, trading name of CargoCrew Ltd. Wordmark chosen; the cut in the x is the signature detail.
- Monochrome: white on black in dark, black on white in light. The only colour anywhere is a status signal (green filled · amber urgent · red released). Premium is what you take away.
- Motto: "Crew we exchange." — the motto lives inside the name: Crew·we·ex. Category line "The staffing exchange" stays in titles and meta only.
- crewex.app live; opening animation: the word becomes the sentence, the sentence settles below, the name returns.
- Never "Crew Exchange" spelled out — reads as the third TEG product (Courier Exchange, Haulage Exchange…).
- Never abbreviate: CX is Courier Exchange to every yard in the country; CEX is a high-street chain; CWE is the security-flaw catalogue. Crewex is six letters — that is the short form.
- The x never stands alone. White x on black is Twitter's logo. The x lives inside the word, where the other five letters make it ours.
- Standalone mark direction: the C, filled — the open shift with the worker in it. Final pick pending.
- Two Cloudflare Pages projects, one repo: board at board.cargo-crew.co.uk, site at crewex.app (output dir site). One push updates both. Old /site/ links 301 to the new domain.
- Whole site behind Cloudflare Access — email OTP, allowed list, 24h sessions. Launch = add a Bypass policy, two clicks.
- PWA installable; monochrome migration briefed; marketplace mock next.
v1 · 24 Aug 2026
- The sentence: "One place where temporary work gets booked, worked and paid — and the paperwork does itself." Why it works: ONE PLACE = one record, three lenses (S-17) in two words · BOOKED/WORKED/PAID = the whole flow in three verbs anyone gets · PAPERWORK DOES ITSELF = the emotional sell + not-a-CRM + nothing-typed-twice, in plain English.
- The paragraph: Employers run one rota across all their agencies and can post a shift to the wider network when they're short. Agencies fill the work and run their whole business on it — bookings, invoices, payroll, compliance. Workers carry one verified profile, choose the days and hours they'll work, and get paid without chasing anyone. Underneath: one record, everyone sees it through their own lens — nothing typed twice, nobody sees what isn't theirs.
- The goal (v2, Dan’s correction — identity leads, beachhead follows): "Build the platform any industry’s temporary work can run on — and prove it first in the industry we know best." The platform IS agnostic (S-21); the sentence + paragraph contain zero trucking words. HGV is the beachhead — our unfair advantage, not the product’s limit — the way books were Amazon’s beachhead, not Amazon’s identity. Internal sequencing stays: one corridor, HGV, then packs open other industries.
How to use it
- Build filter: every feature answers "does this help book, work, or pay — or make paperwork do itself?" Fails = out of scope, or the sentence needs revising. Both outcomes are information.
- Field test: say it to three people who know nothing (a driver, a client contact, someone at the pub). If they can repeat it roughly right, it works. If they repeat something DIFFERENT that's better — steal it and revise this tile.
- Revision log lives here. When the sentence stops changing, the product definition is done.
Decision — 12 Aug 2026
- TempCrew adopted as working name (not tattooed — revisitable before public launch). Clean web sweep; tempcrew.co.uk registered (free w/ registrar promo); tempcrew.uk to add.
- tempcrew.com = GoDaddy squatter page, $5,000 ask / $240pm lease. Decision: buy neither. UK-first business lives on .co.uk; revisit the .com only at scale when $5k is a rounding error.
- Known trade-off accepted: "Temp" pulls slightly downmarket vs the compliance wedge — corrected in positioning ("compliance-grade temporary workforce"), not in the name.
- HOMEWORK OUTSTANDING (Dan): ipo.gov.uk class 35 search (TempCrew / Temp Crew) — the one remaining legal gate; Companies House check; social handles. Fallbacks if IPO surprises: TrueCrew, HiCrew, HeyCrew.
- Separate: crew.co.uk appeared available at standard price — register regardless of naming, standalone asset. Plain "Crew" as a brand confirmed impossible (1M-user Crew workforce app, J.Crew WIPO history on crew.com, generic-mark weakness).
Clear (web-search collision only — formal checks still pending)
- HiCrew
- Zero collisions found — cleanest candidate
- HeyCrew
- No staffing/app collision found
- BookCrew
- A company exists (Glassdoor employer page) but industry unclear from search — needs manual look before ruling in/out
Dead
- InstaCrew
- Live UK competitor — direct model match, killed the whole "Insta-" family
- FlexCrew
- US hiring platform + Flexicrew group
- CrewNow
- Aviation staffing + yacht marketplace
- CrewGo/GoCrew
- Existing staff-management app
- CrewUp
- Registered ® film-crew marketplace
- GetCrew
- GetCrew Ltd workforce app
- CrewMatch
- Danish job-matching platform (2022) + apps both stores
- CrewForce
- US union staffing co + crewforce.app + Tyler Tech fire app
- CrewLink
- Lufthansa Systems airline crew rostering (used across aviation — direct clash with our client world) + Among Us app
- LinkCrew
- Established US student mentorship programme, 3,705 schools
- ShiftHub
- Five+ separate products incl. UK rota platform + healthcare shift-booking (near-identical model)
- CrewCloud
- Public-safety scheduling platform + crewcloud.com yacht crew-agency marketplace (same mechanic as Model B)
- iCrew
- Flight-crew scheduling app + lifeboat crew availability app + rowing club system
- CrewOS
- Taken four times over — industrial field service mgmt (crewos.io), event workforce mgmt (Play Store), entertainment booking (crewos.net), yacht crew employment/payroll (Oceanskies/CrewMate). Closest collisions yet — two are functionally the same category (workforce + compliance + payroll) as this platform. Signal that "OS" suffix is over-mined generally.
Naming direction, refined
- Dan liked InstaCrew (instant/speed feeling) and CrewOS (platform/infrastructure feeling) specifically — both dead, but the underlying feelings are worth chasing with different words.
- Marketplace/Uber-angle batch generated, unchecked: CrewMatch, CrewBridge, CrewExchange, CrewMarket, Kru — CrewMatch and CrewBridge stand out as literal descriptions of the actual two-layer org/marketplace mechanic (S-11).
- Speed-angle batch (InstaCrew replacement), unchecked: FlashCrew, RapidCrew, CrewFlash, CrewPulse.
- Platform-angle batch (CrewOS replacement), unchecked: CrewCore, CrewGrid, CrewFrame, CrewEngine, CrewWorks.
- Possible fresh direction: now that the core mechanic is a verified worker passport + matching (S-12), trust/passport/verified-language names may fit better than generic "Crew" and deserve a batch of their own.
Final sweep before commitment (any survivor)
- UK IPO class 35 · Companies House · .co.uk/.com (grab .co.uk ~£10 if clear) · app stores · social handles.
What Youtemp is (from their own site)
- Employer posts once → Preferred Supplier List of agencies compete to fill. Neutral board; FAQ: "approved timesheets generate invoice data — export to your accounting software." They stop exactly where our embedded-finance layer begins. Confirms the credits-only SaaS model we rejected.
- Still pre-launch: waitlist + "Something Big Is Coming," founder quotes instead of customer testimonials.
- Compliance = Photo ID / RTW / DBS / References — generic. No AWR, IR35, licence monitoring, payroll, funding, MV cascade.
Worth stealing / matching
- GPS-verified clock in/out as optional funder evidence (strengthens the approval-record PDF story).
- "Workforce Hive" privacy-safe local demand signals — shows marketplace activity before there's liquidity (Stage 2 idea).
- Employer favourite-and-rebook worker pool — cheap, retention-driving, and exactly the repeat behaviour the client-origination fee rewards.
- Department / cost-centre budgets on the employer side — useful for multi-shed cargo clients.
- Public HGV preset: £18.50/hr · 45h · 18% margin — a competitor's model of our sector to benchmark against.
Shipped: Rate Calculator
- Clean-room build (no code taken). Pay→Charge AND Charge→Pay (reverse, iterative solve) — the direction agencies actually price in. PAYE + self-employed/Ltd routes. Margin % / markup % / fixed £/hr. Finance cost line (1.62%/1.92% presets) nobody else includes. 2026/27 rates. Verified: forward balances to the penny; reverse recovers exact pay; £20.00/£19.20 margin-vs-markup textbook case passes.
- Next: re-skin onto tempcrew.co.uk as the public lead magnet once the name is locked; later, wire it to the real Stage 1 rate engine.
What the decisions require the devs to build — and when. Every item carries a blue chip tracing it back to the strategy decision that spawned it. "Design in now" items are cheap today and expensive to retrofit.
Design In Now (Stage 1 data model)
- Includes Section 10 solicitor briefing (parties, contractor status, IP + moral rights, open-source rules, GDPR processor schedule, covenant enforceability vs Romanian residents, liability caps) and Section 12 change summary.
- Pricing mechanism: guide prices convert to exact per-stage figures via signed post-stage addendum after complexity review. €200/mo debt model retained; early payoff; mid-stage exit = accepted checkpoints only.
- Maintenance: after Stage 2, devs hold first right of refusal on maintenance + updates at the same agreed monthly price (currently €200/mo), 30 days' notice either way.
- Checkpoint 1.5 outputs are vendor-neutral behind the funder abstraction: invoice data, gross-pay instructions, payment instructions — the consumer (Sonovate pilot / Staffology + Telleroo / CSV) is swappable by design.
- Full IP to CargoCrew day one; accounts in company name; no-killswitch; NDA + 2yr non-compete. Supabase approved, RLS enforced from checkpoint 1.1.
- NEXT: dev kickoff working session — refine checkpoints, schema priorities (supplier entity + RLS day one), demo cadence, v2 environment access (Access policy emails, GitHub invites, base permissions).
- Supplier table: agency name, terms, insurance docs + expiry, compliance docs, agreed rates.
- Booking assignable to supplier with buy-rate / sell-rate spread captured per assignment.
- Weekly self-billing invoice generation per supplier.
- UI can wait for Stage 2/3 — the schema cannot.
- Week-12 auto-reprice logic needs an external input: supplier-reported qualifying weeks per worker per hirer.
- Simple ingest (form/CSV) is fine initially; the field must exist in the reprice calculation.
- All funding interactions (submit invoice, credit check, funding status, settlement data) behind an internal interface; Sonovate = first adapter.
- No Sonovate field names or assumptions leaking into core booking/invoice schema.
- Per-supplier early-payment terms (enabled?, discount %, free-period end date) + discount calculation on each self-bill.
- Commercial decision (free-then-fee vs fee-from-day-one) still open at S-13 — schema supports both.
Phase 1 — Build With Stage 1
- Blocked on: Sonovate's CSV field specs + validation rules (S-08 email). ~1–2 dev days once specs arrive.
- Immediate payoff: kills CargoCrew's own weekly manual admin before any tenant exists.
- Role-based approver permissions — do not build a flat "anyone approves" button; approval email evidence requires the named client authoriser directly, so named-approver roles are confirmed necessary.
- NEW ACTION (from Sonovate reply): design the approval-record PDF now — worker name, hours/units per day + total, assignment/site ref, named authoriser (name + email), explicit approval action, timestamp, IP — and send the mock-up to Garin for Verification/Risk sign-off BEFORE build. A screenshot/PDF from the client's own system is already acceptable evidence today, so a signed-off format should clear the pipeline permanently.
- Ltd/supplier side — resolved: Funding Only bulk-pay CSV exists (recipient bank details + amount, from available balance). Platform exports this file weekly = MV tier-agency fast payment, live today. Get template + constraints (timing, limits, refs) — requested in reply.
- PAYE side — resolved (working assumption): Staffology — HMRC-recognised, API-first ("nothing in the app you can't do via API"), Auto Pilot finalises runs, emails payslips, files FPS. ~£43/mo + ~£2.15/payslip (20–50 band). Our rate engine calculates gross → Staffology executes RTI/NI/pension/payslips. This is the "we calculate, you execute" split Middle Office couldn't offer.
- Full back-office stack identified: GoCardless for client DD collection (1% + 20p capped £4/payment — a £5k invoice costs £4 to collect; webhooks feed the booking gate) · Telleroo for automated payouts (FCA-regulated Faster Payments 24/7, no BACS SUN, syncs natively from Staffology, Partner API creates pay runs in clients' own accounts = tenant-model shaped) · PDFMonkey ~€5/mo or in-house render for documents. Total ~£150–200/mo for near-full automation.
- Doctrine logged: OWN the front + middle office (booking, interpretation, invoicing logic — where all differentiation lives); RENT the back office (payroll exec, payments, accounts). Sonovate consolidation acceptable only if 3 gates pass: (1) executes from OUR figures, (2) price beats the DIY stack, (3) dependency priced into the deal. One-liner for the call: "we own interpretation; we're shopping for execution."
Phase 2 — API Integration (with partner deal)
- Our requirement logged as formal product feedback with Sonovate — ask on the call about API timeline and a design-partner / early-access route.
- Settlement reporting requirement stands whenever the API lands: what they collected, their margin, our remittance — reconciliation must be automatic.
- D-03 abstraction layer now doubly justified: the eventual API partner might not even be Sonovate.
- Doubles as network hygiene: mirrors the existing DD-mandate/prepaid gate; protects MV cascade too.
- Consent chain for checking tenants' clients must be in the tenant agreement — one clause, must exist.
Environments & Org Hygiene
- /v2 path on the live domain rejected (shared deploy risk, crawlable, cookie bleed) — v2 as a subdomain adopted instead. Platform ≠ website v2 long-term; app. stays reserved for production.
- DNS confirmed on Cloudflare — subdomains are one proxied CNAME each, protected via Cloudflare Access (same pattern as the ops board).
- SETUP IN PROGRESS: v2.cargo-crew.co.uk → platform repo auto-deploy, Access policy = Dan + dev emails.
- Org Settings → Member privileges → Base permissions: No permission — every repo becomes invite-only (answers new devs' privacy concern natively).
- New work-email GitHub account → second org Owner. Francesco: Write on website only, never platform repos; friendly offboard on company-policy framing.
- New devs: Write on their repos only; platform repos in the org from day one.
- Invite both devs to the org as Members, Write access on the platform repo only.
- Move website.git backup out of C:\Windows\System32 → Documents, zip, store.
Pipeline
- Claude → GitHub (CargoCrew/ops-board, scoped fine-grained token, expires 10 Nov 2026) → Cloudflare Pages auto-deploy → board.cargo-crew.co.uk.
- Access app "board": policy Dan-only, one-time PIN login, 24h sessions. pages.dev URL gated by the same app.
- Update ritual: "push the board" + paste token in-session.
Next
- Split build: sanitised dev-only board at build.cargo-crew.co.uk, second Access app incl. dev emails — content cut TBD next session.
The programme as a decision flowchart. Green = done, amber = live now, grey = ahead. Diamonds are decisions that gate the path. Click any node for detail.