Hide the invoice screen and every partner is owed nothing
A request to hide the invoice module read as a menu change. Partner shares, agent commissions and project profit were all worked out from invoices.
You ask for the invoice screen to be hidden. It is a reasonable ask: a menu item you do not use, in the way. From the outside it looks like a setting, and from the inside it looked, for two rounds of planning, like one too. Take away the access, and the menu, the pages and the dashboard’s money tiles all disappear together.
What that would have done, on the day it was switched on, is pay every partner nothing. This owner runs jointly owned boards, and a monthly settlement works out each partner’s share of the profit. Agents earn commission on what they bring in. Each project shows a profit or a loss. All three of those figures were calculated from invoices. Stop raising invoices and all three quietly become zero: every partner is owed a share of nothing, every agent earns nothing, and every project shows a loss exactly equal to its costs. No error, no warning. A screen that vanishes gets noticed; a settlement that confidently reports zero does not.
What was actually going on
An invoice in this system was not only an output, the document that leaves the business. It was an input. Three separate calculations summed the invoice totals to find revenue: the partner settlement, the agent commission and the project profitability on the dashboard. The request to hide the screen was really a request to remove the one place revenue came from, and nothing downstream had a second source.
There was a second wrong assumption, and this one we got wrong twice. The plan was to hide the module by taking away the permission that gates it. That works for ordinary roles. It does nothing for the people who actually use this system, because both the office portal and the server treat an owner or an administrator as holding every permission, and the client’s users are administrators. Revoking the permission would have hidden the invoice screen from nobody, and we had told the owner twice that it would. The check that skipped the owner is the same shape in a different product.
What we changed
The order of work inverted. Revenue had to have a new source before anything was hidden, not after. It now comes from the bookings themselves: the monthly rate spread pro rata across the part of the booking that falls in the period, and the one-off mounting and printing charges landing only in the month the campaign starts. Spreading those across the window would have inflated every later month of a long booking, so that a twelve-month campaign earned twelve mountings. Fourteen tests pin the attribution, the last asserting that a booking earns its full contract value across the months it runs and not a rupee more.
With revenue no longer depending on invoices, a settlement can close as a recorded payment, and agent commissions default to direct payout, so a partnership can actually be settled with the invoice route gone. A per-site profitability screen, rolled up by site group, replaced the money picture the invoice tiles had given. It is gated on the permission to see sites rather than the permission to see invoices, so withholding the second cannot take the replacement with it.
Hiding the module itself became a single switch in the code of all three applications, documented as the part that role permissions cannot override. It is a constant rather than a setting that differs by environment, because a flag that is on in one place and off in another eventually makes two copies of the same system compute different money.
Two more things turned up in the trace: buttons on the campaign and purchase-order screens that would have rendered and then been refused when pressed, because neither checked permission at all, and the mobile app’s Billing tab, whose first screen was the invoice list, so hiding it would have left the tab showing nothing.
What it did not fix
Nothing had been hidden when this was found, so no partner was actually paid nothing; the log records a plan that would have done it. Three references from other records to invoices were deliberately left in place. And the log does not say why the owner wanted the screen gone; the reason is theirs. What the exercise settled is how much of the system was standing on a screen that looked decorative.
The mechanism
Before removing anything, trace what reads it, not only what shows it. Six server endpoints, three revenue calculations, the assistant’s list of things it may do, about a dozen portal components and the mobile tab all touched invoices, and only the last two are visible from a menu. The revenue calculations were the ones that mattered, because they fail by returning a plausible number rather than by breaking.
And where a system bypasses its own permission checks for its most senior users by design, a permission is not a way to hide anything from them. That needs a switch the role system cannot see past.
Partner settlement and agent commission in AdBoard, which runs for Gold Sign Media, an outdoor media operator, now read the bookings, which exist whether or not anyone ever raises an invoice.