Enterprise Resource Planning · Built by W.W.M. Ai Labs
The ERP your AI assistant can actually read.
Most business systems were designed for humans clicking through screens. Our ERP Solution was designed for both — a complete operations platform for multi-entity groups covering people, hiring, payroll, invoicing, immigration, fleet, property, IT infrastructure and tasks, with a native machine interface that lets AI assistants query your real data instead of guessing at it.
Your data is already in a system. It just can't answer a question.
Ask a normal ERP “which of our staff have documents expiring in the next 60 days, across all three entities?” and you get a report you have to build, export and read. Ask it in the middle of a board call and you get nothing at all.
Groups running several legal entities feel this hardest. Headcount sits in one place, leave in another, vehicles and leases in a spreadsheet, recruiting in an inbox, invoices in an accountant's folder — and the only person who can join it up is whoever built the spreadsheet. Every question becomes a small project.
Then the second problem arrives: the things that hurt aren't reports, they're dates you missed. A visa that lapsed. A road tax renewal. A domain that expired over a weekend. A warranty that ran out three months before the laptop died. None of those live in a dashboard anyone opens on purpose.
Our ERP Solution closes both gaps: one system that genuinely holds all of it, one calendar that surfaces every expiry from every module before it bites, and a machine interface that lets an AI assistant answer from the live records — in plain language, in seconds, with permissions intact.
/ 02 — what makes it different
A native machine interface, not a bolted-on chatbot.
Our ERP Solution ships with a Model Context Protocol (MCP) surface — a structured, audit-logged interface exposing the operational modules to AI assistants such as Claude. It is not a chat widget sitting on top of your ERP. It is the ERP, addressable by machines. Your assistant doesn't hallucinate an answer about your business: it queries the same records your staff see, through the same permission model, and returns the actual numbers.
01
Ask, don't build
“Who is on leave next week, and does that leave any department below two people?”“Which vehicles have insurance expiring before the end of the quarter?”“What’s our lead-to-hire time by intake source this month?” No report builder. No export. An answer.
02
Permissions are not optional
Every machine call authenticates as a real ERP user and inherits that user’s row-level security and per-module permission flags. There is no service-role back door. Restricted fields stay restricted — salary, passport, national ID and banking data return as [PROTECTED] or [RESTRICTED], never as plain text, unless the calling identity is explicitly cleared for them.
03
Every call is logged
Every tool invocation writes an audit row with the tool name, the arguments and a timestamp. You can see exactly what was asked, by whom, and when — the machine path is no less accountable than the browser path.
04
Read-first by design
23 tools across 12 business domains. All but eight are read-only. Writes are confined to task workflow (5 tools) and equipment records (3 tools), each gated by the same database rules a human manager faces. Your AI can tell you things; it cannot quietly rewrite your payroll, your employee master data or your financial summaries — those domains have no write surface at all.
05
Hardened like an API, not a demo
Bearer-key authentication with constant-time comparison, 120 requests per minute per instance, a 2 MB response ceiling that forces narrow queries instead of full-table dumps, POST-only, and no CORS headers at all — it is a server-to-server interface, so a browser cannot reach it.
23 MCP tools
12 domains
15 of 23 read-only
Audit-logged per call
Permission-scoped per call
/ 03 — one system
Everything an operating group actually runs on.
Not a starter product with paid add-ons. Every module below is in production today, used daily across a multi-entity group. Fifteen top-level modules, several of which are hubs with their own sub-modules — the Finance hub alone has nine, Equipment & IT has ten — plus the separate self-service portal staff log into.
Sixteen panels, one per entry above. Everything listed is in production, not on a roadmap.
M/01Companies & group structure
Modelled as a group from the first table, not bolted on later.
Multi-entity isn't a licence tier in our ERP; it's the shape of the data. Every employee, asset, lease, invoice and task carries the entity it belongs to, so a cross-entity question is a filter rather than a reconciliation exercise.
Full company records — legal name, short name, registration number, tax number, address, phone, website, contact and finance email addresses.
Multiple office locations per entity.
Company bank accounts with account number, IBAN and currency.
Directors register with personal details, held behind the protected-fields permission.
Tax details including country of incorporation, used by invoicing to decide VAT treatment.
Per-entity settings that change behaviour downstream — for example flagging an entity whose staff require visas, which switches on immigration tracking and missing-visa warnings for its employees.
Per-entity public holiday calendars, consumed by leave calculations and attendance.
Headcount per entity computed live, not maintained by hand.
M/02Employees & departments
The employee record other modules can rely on.
The employee profile is the join point for eight other modules. Open one person and you see their leave entitlement, their visa status, the room they live in, the laptop they carry, the documents about to expire and the notes colleagues left — without opening eight pages.
Complete profiles: personal details, employment details, employee number, position, department, hire date, company assignment.
Reporting lines and manager assignment, used to route leave approvals and notifications.
Employment status lifecycle — hiring, active, terminated — with cross-company checks so a terminated employee cannot quietly reappear under another entity.
Document register per person (passport, national ID, driver’s licence) with issue and expiry dates, and automatic reminder milestones ahead of each expiry.
Emergency contacts.
Protected data — salary, passport number, national ID, IBAN — gated by a separate permission from general record access. Seeing an employee is not the same as seeing their pay.
Notes with author attribution and timestamps; users can edit and delete only their own.
Live cross-module panels on the profile: leave entitlement with pro-rata calculation, visa detail with colour-coded expiry status, accommodation assignment, assigned equipment, financial balances.
Onboarding workflow — one action fans out structured briefs to Finance, IT and HR so nobody’s first day depends on somebody remembering to forward an email.
Offboarding workflow — the same fan-out on termination, covering asset recovery, access revocation and final pay, with the termination reason and date recorded.
Employee self-service account provisioning, and IT service-account provisioning including chat-platform handles.
M/03Hiring
The module most ERPs don't have
A full applicant tracking system, inside the ERP that already knows your headcount.
Recruiting usually lives in a separate tool that cannot see your open positions, your entity structure, or the employee record the candidate eventually becomes. Here it's the same system: a hire is a conversion, not a re-typing exercise.
Get candidates in without touching your ERP
A public intake API your marketing landing pages post to directly — name, contact details, preferences and an optional CV.
Bot and abuse defence built in: Cloudflare Turnstile verification, a honeypot field, per-IP rate limiting, per-site keys and origin checking.
Explicit consent capture on submission.
CVs land in private storage. The public page never receives a downloadable link; recruiters open the file through a short-lived signed URL inside the ERP.
Intake sites let an admin register each landing page or campaign source separately, with full UTM capture — source, medium, campaign, term and content.
Triage, ownership and pools
New applications arrive in a triage inbox rather than straight into someone's list.
A recruiter claims a lead, discards it with a recorded reason, or passes it to a secondary pool for a second opinion.
Two recruiter tiers with different reach, so juniors work a pool while primaries work triage and analytics.
Explicit ownership, claim timestamps, and release with a reason — so “who is actually working this candidate” always has an answer.
Triage ageing surfaced as a column and a metric: how old is the oldest untouched lead, and what's the average.
Run the pipeline
Stage and status model covering the real messy middle: New, one/two/three unanswered call attempts, Contacted, Scheduled, Interviewed, Offer, and the terminal outcomes Hired, Disqualified, Not Suitable and Refused Offer.
Call logging with outcome, feeding both the candidate timeline and recruiter metrics.
Interviews — onsite, video or phone, with outcomes (pending, passed, failed, no-show) and interviewer load tracking.
Scorecards — structured post-interview scoring with an explicit recommendation from strong yes to strong no.
Offers — draft, sent, accepted, declined, withdrawn, with the accepted offer feeding the eventual employee record.
Templated candidate emails — interview invitation, offer, rejection — sent and logged against the candidate.
Open positions with their own approval workflow (pending, approved, denied), status (active, inactive, planned), entity scoping and hiring start date; candidates are assigned to positions, so “how are we doing on this role” is a real question.
Candidate views for how people actually work: sortable and filterable table, kanban board, per-candidate detail drawer that survives a hard refresh and can be shared as a link.
CV viewing in-browser, including Word documents, without downloading files to laptops.
Convert to employee in one action — the candidate becomes an employee record with their offer, position and entity carried across.
Optional third-party KYC/AML screening integration for candidate background checks.
Analytics that answer hiring questions
Funnel from leads to screening, interview, offer and hire, with conversion rates at each step.
Velocity in days: lead to first call, lead to interview, lead to offer, lead to hire.
By source — per intake site: leads, trailing-7-day leads, reached, interviewed, hired, hire rate, with a nested per-campaign breakdown.
By UTM — full funnel across all five UTM dimensions, so you can tell which ad copy produced hires rather than clicks.
By recruiter — owned, claims in the trailing 30 days, reached, interviewed, offers, hires, calls logged, offers accepted, conversion rate.
By outcome — discard and pool-release reasons as a ranked breakdown, so you learn why leads die.
Trend time-series bucketed by day, week or month, zero-filled so gaps read as gaps.
Every one of these numbers is also reachable through the MCP layer, so you can ask for them in conversation.
GDPR built into the module, not promised in a policy
Right to erasure — an admin action that hard-deletes the candidate, their cascading records, the original intake submission, the personal data inside audit rows, and the CV blobs in storage. Not a soft flag.
Automatic retention purge — candidates untouched for 12 months (hired staff excluded) are anonymised and their CVs deleted on a schedule, without anyone remembering to do it.
Erasure is deliberately admin-only and interactive; the automated sweep is a separate, separately-authorised path.
M/04Leave management
Approve leave knowing what it costs you.
Request submission with automatic working-day calculation against the entity's holiday calendar.
Leave types — regular, sick, other, plus explicit adjustments for corrections and carry-over.
Annual entitlement per employee with pro-rata calculation for joiners and leavers.
Live balances: entitlement, used by type, remaining.
Approval workflow with comments, decision history and email notification to both the manager and the employee.
Overlap prevention and balance validation at submission, so invalid requests don't reach an approver.
Coverage visibility before you approve — see who else in the department is already out.
Unpaid leave tracked and fed into the attendance and payroll modules.
Full history per employee, with sorting and filtering across the whole company.
Employees submit and track their own requests through the self-service portal.
M/05Calendar
The page that stops things from expiring.
The calendar isn't a meeting diary. It's an aggregation of every date-shaped risk in the system, pulled from more than seven sources in parallel and rendered as one month you can actually scan.
Event sources
Document expiries — passports with staged reminders months ahead, national IDs and driving licences with their own lead times.
Visa expiries, with days remaining.
Approved leave.
Birthdays and work anniversaries.
Employee first days.
Rental agreement end dates.
Vehicle deadlines — insurance, MOT and road tax.
Per-entity public holidays.
Property and vehicle inspection scheduling.
Filterable by entity and by event type, navigable month to month, and available through the machine interface — so “what’s expiring in the next 60 days across all entities” is a question you can ask out loud.
M/06Equipment & IT
Far more than an asset list
Datacentre-grade asset management, not a spreadsheet with serial numbers.
This module started as equipment tracking and grew into IT operations, because the same team that has to know who holds which laptop also has to know which rack has power headroom and which domain expires next month.
Typed, configurable asset register
Every item belongs to an equipment type that defines its own custom fields. Seven types ship as defaults — Computer, Laptop, Server, Mobile Phone, Networking, Monitor, Rack — and all of them are editable.
Admins create entirely new types through the UI: name, icon, description and a field editor supporting text, number with unit, date, boolean and dropdown fields with defined options.
Real technical attributes, not a notes box: CPU speed, core count, RAM type/amount/speed, storage type and capacity, OS, management interface, IP and public IP, firmware update date, IMEI, screen size, power consumption, rack-mount flag and U height.
Inventory numbers auto-generated on a per-entity, per-type counter.
Status workflow — available, assigned, maintenance, retired — with an enforced rule that an asset is assigned if and only if it has a holder.
Assignment history: who has what, since when, and what they had before.
Templates — save a common configuration once and create the next twenty machines from it.
Financial tracking
Purchase record per asset: date, price, currency, vendor, supplier invoice or PO reference.
Warranty start and expiry with alerting before the window closes.
Depreciation — straight-line or declining-balance, with useful life in months and salvage value — calculated and displayed per asset.
Carrying value in any supported currency.
Rack and facility management
Visual rack elevations rendered as diagrams, not tables: see the front of the rack, the occupied units and the gaps.
Rack assignment with U position and height, and assignment rules that prevent overlapping or overhanging placements.
Power and cooling budgets per rack — declared maximum against the summed draw of what's actually mounted, so you find out you're at capacity before the breaker does.
Physical audit
QR label generation — printable PDF label sheets for the assets you own, so an annual inventory count is a walk with a phone rather than a week with a clipboard.
IT services, credentials and domains
IT service register — the SaaS and internal services your company runs, with owners, support contacts, URLs and status.
Per-employee service accounts on each service with their own lifecycle — pending, active, blocked, deleted — which is what actually makes offboarding verifiable.
Service check history, so “when did we last review who has access to this” has a date.
Credentials vault for internal and external credentials, locked to admins at the database level.
Domain register — registrar, registrar account, DNS provider, live status, expiry date and auto-renewal flag, refreshed automatically against public registry data (RDAP) so the expiry date in your ERP is the real one, not the one somebody typed in 2023.
M/07Rentals & property
Offices and staff accommodation, with the cost per head you can't get from a lease PDF.
Offices and staff accommodation in one register, per entity.
Rental agreements with start and end dates, notice, and archive handling for expired tenancies.
Capacity modelling — beds for accommodation, workspaces for offices — with live occupancy.
Tenant assignment for accommodation, with full move-in and move-out history per person and per property.
Monthly cost breakdown: rent, maintenance and utilities, totalled, plus a cost per bed figure.
Multi-currency cost tracking.
Property inspections in three depths — quick, standard and repair — with condition status (good, minor issues, major issues), notes and damage cost estimates.
Agreement expiry surfaced on the aggregated calendar well before renewal date.
Accommodation assignment visible on the employee profile, and vice versa.
M/08Fleet
Vehicles, drivers and the three renewals that catch everyone.
Vehicle register per entity: make, model, year, registration, VIN.
Driver assignment, with status workflow — available, assigned, maintenance, retired.
Mileage tracking, validated against the previous reading so a typo doesn't rewrite history.
Insurance, MOT and road tax expiry per vehicle, all three surfaced on the aggregated calendar.
Vehicle checks in three depths — quick, standard and repair — with condition status (good, needs attention, needs repair), notes, damage assessment and cost estimation in multiple currencies.
Full check and assignment history per vehicle.
Assigned vehicle visible on the employee profile.
M/09Immigration & visas
Built for groups that move people across borders.
For a cross-border employer, an expired permit isn't an HR formality — it's an unlawful worker, a fine, and a person who can't come to work tomorrow. This module exists so that never arrives as a surprise.
Visa records per employee: visa number, country, issue date, expiry date, supporting documents.
Computed days-to-expiry with colour-coded status — expired, expiring within 30 days, valid.
Per-entity visa requirement flag: mark an entity whose staff need visas and every employee under it is checked, with missing-visa warnings for anyone who requires one and doesn’t have one.
Expiry windows and renewal reminders on the aggregated calendar.
Coverage dashboard across entities, plus a ratios view for the workforce-composition figures cross-border employers have to report on.
Queryable through the machine interface by entity or by “expiring within N days”.
M/10Finance
Nine sub-modules
Payroll, invoicing and everything the finance team currently keeps in a folder.
Monthly payroll entry and review per entity and period — base salary, benefits, advances, bonuses and deductions, with currency conversion where the contract and the payment differ.
Draft, locked and paid states so a period can be closed.
A simulator for modelling gross-to-net scenarios before anything is committed to a payroll run — for offers, raises and budget questions.
Attendance and unpaid leave feed the run rather than being reconciled against it.
Invoicing
Customer register with billing address, country, registration and tax numbers, finance contact email, and multiple named contacts per customer with roles and phone numbers.
Payment terms from due-on-receipt through net 90, plus flags for whether a signed agreement is on file and whether the customer settles in cryptocurrency.
Issue invoices from any entity in the group to internal or external customers.
Line items with quantity, unit, unit price, per-line discount and per-line tax rate.
Tax treatment per invoice — standard, reverse charge, or exempt — driven by the entities' countries of incorporation.
A real lifecycle with enforced transitions: draft → approved → issued → sent → partially paid → paid, with overdue, disputed, cancelled and credited handled explicitly. You cannot skip from draft to paid, and a paid invoice can only be credited.
Payment recording against an invoice — bank transfer, crypto, card, cash or other — with partial payments and remaining balance.
Invoice numbering allocated atomically in the database, so two people clicking at once cannot produce a duplicate number.
Three professional themes with live preview, your entity's logo, and selectable bank accounts per invoice.
PDF generation from the same rendering path as the on-screen preview — what the customer receives is what you approved, not an approximation from a second code path.
Send the invoice by email from inside the system, with the send timestamp recorded on the invoice.
The rest of the hub
Advances & loans — record advances, loans and other employee transactions with a running balance per employee per currency, group totals by currency, and a full audit trail with description and author.
Attendance — monthly worked days against working days in the month as a percentage, unpaid leave days, filterable by entity, with partial attendance highlighted.
Bank accounts — employee IBAN and account details, multiple accounts per person.
Crypto wallets — employee wallet addresses by kind (exchange, cold wallet, other) with declaration tracking and commentary, for groups whose staff are paid or reimbursed in digital assets.
Travel costs — flight cost per employee, linked to the booking records in the Travel module.
Conversion rates — a maintained USD-based FX table used across every multi-currency figure in the system, with staleness indicators (amber past one month, red past two) so nobody reports last quarter’s numbers at today’s exchange rate by accident.
Employees see their own balances and transaction history — and nothing else — through the self-service portal.
M/11Performance
Reviews for everyone; revenue metrics where the role calls for it.
Structured reviews per employee with scoring and bonus tracking.
Retention metrics per employee and period: first-time deposits, load, withdrawals, net deposits and gross commission, with period totals.
Sales metrics per employee and period, filterable by department.
Activity log — a timestamped record of every performance entry, so the numbers have provenance.
Per-employee aggregates and multi-month lookback.
Access is a three-state permission — no access, view, or manage — rather than a single on/off flag, so a department head can see their team’s numbers without being able to write them.
Readable through the machine interface, and writable through it only with manage-level permission.
M/12Investments
An append-only ledger for the money that isn’t payroll.
Groups that lend, hold property, or take positions in other businesses usually track it in the CFO's spreadsheet. This module gives it a record with a history you can't quietly rewrite.
Six lifecycle states: active, pending, on hold, closed, written off, matured.
Financial detail per position: invested amount, authorised amount, interest rate, target return, last known value.
Append-only event log per investment: capital spend, profit and income, periodic interest accrual (tagged by month), periodic depreciation accrual (tagged by month), free-text notes, and structured field-level change records showing old value → new value.
Accrued interest and accrued depreciation derived from the event log, not typed into a field.
Contact person per position, with short and long notes.
Soft delete only — records are never hard-removed, so the audit history survives.
Strictly entity-scoped: every user, including admins, sees only the investments of the entities they're assigned to. Off by default and granted per user.
M/13Travel
Who's flying, what it cost, and did they check in.
Flight bookings per employee: departure and destination airports, travel date, departure time, flight number.
Cost per ticket, feeding the finance module's travel-cost view.
Check-in status flagged, so nobody discovers at the gate that nobody checked in.
Business and personal travel separated.
Past travel hidden by default; full history retained.
Automatic notification fan-out on booking — to the traveller, their manager and finance.
Cost by person, period and purpose for reporting.
M/14Tasks & external companies
Work assignment that includes the people who don’t work for you.
Most task tools assume every assignee has a login. Real operations run on vendors, contractors, landlords, accountants and lawyers. Our ERP Solution models them as first-class assignees.
External companies register — vendors, partners and clients with contacts and primary contact, and every task ever linked to them.
Tasks assignable to internal employees and external companies (optionally to a named contact at that company).
Every task has an explicit owner plus any number of assignees.
Eight statuses covering the real states, including blocked, in review and outsourced.
Four priorities, start and due dates, estimated hours and completion percentage.
Subtasks, one level deep by design — a checklist, not a hierarchy nobody maintains.
Tags with filtering.
Comments with @mentions, resolved against the employee directory and delivered as notifications.
Full activity log per task: every status change, assignment, comment and notification, written by the database rather than by the UI, so it can't be bypassed.
Email notifications on assignment and on status change — employees get a deep link into the ERP, external assignees get the task detail without an account.
Task PDFs — a single-task brief, or an open-task digest for one employee or one external company, which is how you send a contractor their week.
Aggregate stats: total open, overdue, by status, by priority, top assignees.
Entity scoping on every task, and a dedicated permission that lets an automation account act with owner-level task power without being a global admin.
M/15Users, permissions & audit
The part buyers ask about last and care about most
Access control granular enough to actually use.
“Three roles” is where most SME systems stop, and it’s why people end up over-privileged: someone needs one page, so they get admin. Our ERP Solution separates the role from the module list.
Three base roles — Admin, Manager, Employee — plus a per-module visibility flag for every module: companies, employees, hiring, leave, calendar, equipment, rentals, cars, visas, finance, travel, performance, investments, tasks.
Protected-fields permission is separate from everything else. Salary, passport, national ID and banking data are gated independently, so a manager can run their department without seeing pay.
Multi-state permissions where a boolean isn't enough — performance access is none/view/manage; task automation accounts get owner-equivalent power without global admin.
Entity assignment per user, enforced at the data layer: investments and equipment writes are restricted to the entities you're actually attached to.
New-account approval workflow — accounts don't become active because someone knew the signup URL. Public self-registration is disabled outright.
Rules live in the database, not the interface. Row-level security means an unauthorised request fails whether it comes from the browser, the machine interface, or a direct API call. Hiding a menu item is not a security model.
Audit log covering user actions, record changes with before-and-after values, timestamps and actor — including every AI tool call.
M/16Self-service portal
Staff answer their own questions.
A deliberately separate, narrow surface with its own navigation — not the admin interface with things hidden. An employee logging in sees exactly four things, all their own.
Personal dashboard — their leave balance, their open items, their upcoming dates.
Leave — submit requests, watch approval status, see their own history and remaining balance.
My details — review and update personal and employment information, with changes routed for review rather than applied silently.
My finance — personal advances and loans, running balances per currency, full transaction history.
My tasks — what’s assigned to them, with the same comment and status flow.
Nothing cross-employee is reachable, enforced at the database rather than by hiding pages.
/ 05 — how it's built
Modern stack. Boring, deliberate security.
Install it like an app
A progressive web app. Staff install it from the browser on desktop or phone — no app store, no MDM rollout, no separate mobile build to fall behind. The service worker precaches the app shell so a flaky connection degrades instead of failing, and an in-app banner tells users when a new version is ready and reloads them into it.
Mobile-real, not mobile-shrunk
The modules people use away from a desk — inspections, asset checks, candidate calls — are laid out for a phone in hand, not scaled down from a table designed for a monitor.
Roles plus per-module flags, enforced at the database
Admin, Manager and Employee, each combined with per-module visibility flags and a separately-gated protected-fields permission. Rules are enforced by row-level security at the data layer, so the same rules apply whether the request comes from a browser, an AI assistant, or a script.
Sensitive fields stay sensitive
Salary, passport, national ID and banking details are protected independently of general record access, and masked rather than omitted so the interface stays honest about what exists. CVs, documents and uploads live in private storage reached only through short-lived signed URLs.
Hardened at the edges
Network-level IP restriction available for the whole application. Rate limiting on authentication and on the machine interface. Bot defence on every public intake endpoint. Server-side validation on every write. Secret scanning and a blocking dependency-vulnerability gate on every change before it can ship. Error monitoring in production.
Everything that happens is written down
Audit logging across modules, append-only event ledgers where history matters, soft deletes where records must survive, and database-written activity logs that the interface cannot skip.
Data protection designed in
Right-to-erasure that actually removes the person — cascading records, source submissions, uploaded files and the personal data inside audit rows. Scheduled retention purges for recruiting data. Explicit consent capture at the point of collection.
Built and maintained in-house
Designed, written and operated by W.W.M. Ai Labs. One engineering team, one codebase, a direct line to the people who wrote it — no reseller layer between you and a fix.
/ 06 — proof
We run our own group on it.
Our ERP Solution was not built as a product first and sold in hope. It was built because a group of companies operating across multiple jurisdictions needed one, and it has run that group's people, hiring, payroll, invoicing, visas, fleet, property and IT day to day since 2025.
It has already survived the only test that matters: being the thing your own operations team complains to when something breaks.
It's also maintained like a product rather than an internal tool. Every change goes through type checking, linting, an automated test suite, a build, a dependency-vulnerability gate, secret scanning and an automated code review before it can reach production — and the test suite gates the production deploy itself, not just the review.
Live from 2025
15 top-level modules
23 AI tools across 12 domains
Multi-entity, multi-jurisdiction from day one
/ 07 — who it's for
Sized for real businesses, not just enterprises.
Our ERP Solution is built for small and mid-sized companies that have outgrown spreadsheets but have no appetite for a six-figure enterprise rollout. It scales from a single company to a group of entities without changing product or tier.
Growing SMEs
Teams past the point where headcount, leave and assets fit in shared files, but nowhere near needing SAP.
Multi-entity groups
Holding structures where the same person, vehicle, lease or invoice touches more than one company.
Cross-border employers
Where visas, permits and document renewals are an operational risk, not an HR formality.
High-volume recruiters
Organisations hiring continuously from paid traffic, who need to know which campaign produced hires rather than clicks.
Asset-carrying operations
Fleets, equipment, racks, leased offices and staff accommodation that need a register, not a folder.
Groups that invoice from more than one entity
Where which company issues the invoice changes the VAT treatment.
Teams adopting AI seriously
Organisations that want their assistant working from live business records rather than a stale export.
If your whole operation still fits comfortably in one spreadsheet and nobody has ever missed a renewal, you don't need us yet. Tell us anyway; we'll say so.
/ 08 — getting started
Three steps, not a three-month implementation.
01
Scoping call
We map your entities, headcount and the modules you'll actually switch on. Most groups start with three or four, not fifteen.
02
Data migration & configuration
Entities, staff records, documents, historical leave and asset registers loaded and reconciled with you; equipment types, leave entitlements, holiday calendars, invoice themes and permission flags configured to your structure.
03
Rollout & enablement
Accounts provisioned by role with per-module flags set, the self-service portal opened to staff, and the MCP interface connected to your AI assistant if you want it.
/ 09 — questions
The things buyers ask first.
Do we need to use the AI features?
No. The MCP interface is a distinct capability you can leave switched off entirely. The ERP is a complete system without it.
Can the AI change our data?
Only within a deliberately narrow surface: task workflow and equipment records. Employees, payroll, finance, leave, visas, fleet, rentals and hiring have no write path through the machine interface at all — they are read-only by design, not by configuration.
How do you stop an AI assistant seeing salaries?
The same way we stop a person seeing them. The machine interface authenticates as an ERP user with its own permission flags, and protected fields are masked unless that identity is explicitly cleared for them. There is no elevated service account behind the interface.
Can it handle several legal entities?
That's the core assumption of the design, not an upgrade path. Entities, staff, assets, invoices, tasks and finances are modelled as a group from the ground up, and every user's entity assignment is enforced at the database.
Is the recruiting module a real ATS or a candidate list?
A real one: public intake API with bot defence, triage inbox, recruiter ownership and pools, interviews, scorecards, offers, open positions with approvals, templated candidate emails, full-funnel and per-campaign analytics, and one-action conversion to an employee record.
Does it replace our accounting system?
No, and it doesn't pretend to. It runs payroll, issues and tracks invoices, and holds employee financial balances and investment positions. It is not a general ledger — it's the operational layer that feeds one.
What about GDPR?
Consent captured at collection, private storage for personal documents, protected-field gating, full audit trails, a genuine right-to-erasure path that removes files and audit PII as well as records, and automated retention purging for recruiting data.
Can staff use it on their phones?
Yes. It installs as an app from the browser on desktop and mobile, with no app store and no separate mobile build. The field-facing workflows are designed for a phone.
Where does our data live, and can we host it ourselves?
Ask us on the call — the honest answer depends on your entity structure and your regulator, and we'd rather give you the specific one than a marketing one.
What does it cost?
Per-seat, with a platform component and an optional machine-interface tier. We'll quote against your actual entity count and headcount on the call.
Who supports it?
The team that wrote it. One engineering group, no outsourced tier one.
See it against your own operation.
Thirty minutes, your entity structure on screen, and an honest answer about whether this fits. No slide deck.