Child Consent Ledger — the spine of every record
Every photo, pickup, medication administration, incident report, billing contact, daily-report message, and third-party data handoff in the platform runs through the Child Consent Ledger. A guardian’s consent is explicit, time-stamped, scoped to a specific use case, and revocable at any time. Revoking photo consent does not require a staff member to manually hunt down images — the platform marks them locked immediately. An authorised-pickup change takes effect the moment a guardian saves it, with the prior record preserved in the audit trail. The consent ledger itself is an audit-export: a director can produce a timestamped consent history for every child in the program for any date range, in a format that holds up in a licensing inspection. The Child Consent Ledger is built and production-ready on the consent substrate.
Child Consent Ledger built · production-ready
QR/PIN check-in, ratio monitoring, and attendance
The check-in engine manages arrivals and departures through QR code or PIN, matched against the child’s authorised-pickup list from the consent ledger. A guardian not on the list cannot check out a child — enforced at the engine, not by a reminder policy. Staff clock in and out against classrooms, and the ratio monitor tracks the licensed child-to-staff ratio in each room in real time, surfacing a warning before a ratio violation occurs rather than logging it after the fact. Late-pickup tracking and classroom transfer logs both land in the same audit trail as the consent records, so a licensing inspector sees a single coherent record. The check-in and attendance engine is built and production-ready on the BAS substrate.
Check-in engine built · production-ready
Tuition billing — plans, subsidies, and exact-cent reconciliation
The billing engine handles tuition plans, deposit schedules, sibling discounts, subsidy tracking, late fees, ACH/card receipts, and annual tax statements. A director configures a tuition plan for a child at enrollment; the engine applies it on the billing cycle without manual re-entry. Subsidy receivables (childcare assistance, agency-funded slots) are tracked separately from family balances so a director can see both at a glance without reconciling two spreadsheets. The failed-payment workflow holds the billing record open and prompts the family through the configured reminder cadence. Tax statements pull from the billing ledger directly. The tuition billing engine is built and production-ready on the tuition.software substrate. The charge rail that moves money is honest-off — present in the platform, not enabled for live transactions today.
Billing engine built · charge rail honest-off
Licensing compliance cockpit — immunizations, incidents, and inspection binder
The compliance cockpit covers the records a licensing inspector asks for on arrival: immunization records per child (with expiration alerts before they lapse), incident reports (written at the time of the event, timestamped, guardian-notified, locked from editing after sign-off), medication-administration logs (authorisation required before administration, dose recorded per administration), staff-certification dates with renewal alerts, and a background-check date per staff member. The CACFP meal-count export and the inspection binder export — which assembles all required records into a portable, printable package — are in active development on top of the built records model. The SC licensing checklist mapping is the initial compliance surface; additional state configurations follow. The underlying records model is built; the binder-export UI surface and CACFP export are in active development.
Records model built · binder export in development
Parent communication — daily reports, announcements, and direct messages
The communications engine sends daily reports, classroom announcements, direct messages, and controlled media shares to opted-in families. Every family communication requires a prior opt-in — a guardian who has not opted in does not receive messages, which is a consent rule, not a rate-limit. Read receipts are logged in the communication record. Translation is available for announcements. Media sharing is controlled: a photo shared in a daily report is matched against the child’s media consent record before it goes to any family, and only the consenting family sees it. Strict retention controls mean the platform does not hold a communication history indefinitely; the director configures the retention window at setup. The channel infrastructure and templates are built. Live carrier delivery (email and SMS) is key-gated — honest-off without configured provider keys.
Channel infrastructure built · carrier delivery key-gated
Photography & yearbook bridge — consent-safe media, roster export, parent ordering
The photography bridge connects the childcare platform to the school-photography and yearbook engine: media consent records from the Child Consent Ledger govern which children can be included in a class photo session; roster exports carry only what a photographer needs (name, class, make-up day flag) without exposing medical, billing, or custody records. A make-up day is configured as a separate session so late-consent families can still participate. Sibling linking handles families with children in more than one classroom. Parent purchase handoff delivers order links to opted-in families without exposing child data to the photo lab or the order platform. The photography and yearbook bridge is built and production-ready.
Photography bridge built · production-ready