Let's talk

Sazinga Comply

One obligation, from the clause to the evidence

Compliance is rarely lost because nobody cared. It is lost because the obligations sit in one spreadsheet, the certificates in an inbox and the inspection photographs on a phone. Here is the single path all three take instead.

  1. Enter the obligation once, with the clause it comes from

    An obligation is a recurring duty with a source, a period, an owner and a defined artefact that closes it. The record carries the instrument it comes from and the clause within it, so a finding can be argued back to the rule rather than to a policy document nobody has read. It also carries a frequency — daily, weekly, monthly, quarterly, half-yearly, annual, event-driven or once — an anchor that says which day of that period, a due offset in days after the period closes, a reminder lead time, a grace period, a severity, and the kind of evidence that closes it: a form, a document, an acknowledgement, or nothing.

    Designation to certification mapping table listing the certifications each trade must hold, with credential type, validity in days, required flag and coverage across the workforce
    The requirements register. Each trade carries the certifications it must hold and their validity period — 730 days for work at height, 365 for an operator's medical — and coverage shows how many people in that trade hold a current record.
  2. Give it a role, not a person

    The owner is a role at a scope. An obligation owned by the site safety officer resolves, at generation time, to whoever holds that role at that site today. Staff turnover does not orphan a duty, which is the failure mode this column exists to prevent.

  3. Let the calendar fill itself

    Nobody creates the recurring items. A scheduler function walks the active obligations for a period, works out each one’s period boundaries from its frequency and anchor, resolves the owner through the assignments at that scope, and writes an instance with a period start, a period end and a due timestamp. A second function marks the ones past their due date and grace as overdue. Instances exist per scope, so an obligation defined at site level generates one instance per site — a register of thirty obligations across five sites is a real workload figure rather than thirty rows that quietly stand for a hundred and fifty. Event-driven obligations are generated by the thing that triggers them, and record what triggered them.

    September 2026 calendar showing training sessions and certificate end dates by day, with a searchable list of the month's events and a summary of the next seven days
    Toolbox talks, assessments and certificate end dates on one calendar. An expiry appears on the day it falls, so the renewal can be booked before the date rather than found during an inspection.
  4. Run the inspection against a checklist, on a phone, at the property

    One checklist engine runs a food safety audit, a site safety inspection, a facility or building inspection, an equipment and asset inspection, and a property inspection or collateral condition survey. An inspection type is a checklist, a cadence and the evidence that closes it, so adding a type is configuration rather than a new deployment. The inspector works from a phone at the property: photographs are taken in the app rather than chosen from a gallery, and each carries the coordinates and the time the shutter fired — not the time it reached the server, which is the field a dispute actually turns on when the phone had no signal at the site.

    Add certification form on a phone with title, start and expiry dates, issuing training cell, an attached photograph of a signed assessment sheet and notes
    Adding a record from the site: a catalog item or a free-text title, dates, issuer, and a photograph of the signed assessment taken on the phone. The photo field is an addition: the repo has no upload flow, and these phone screens are the portal's responsive layout below 900px rather than a native app.
  5. Show the back office what was actually done

    Each survey appears in the back office as it lands. For Creative Lending Solutions, who arrange finance against commercial property, we added a supervisor role: a manager sees what each member of staff has actually completed, rather than what the schedule says they were sent to do. That distinction is the whole reason the role exists.

    Sazinga Comply executive dashboard for an infrastructure contractor, showing overall compliance, at-risk workers, credentials expiring this week, a compliance-by-site bar chart and a column of rule-based insights
    Executive dashboard for a demonstration tenant: compliance at 86.4% across four construction sites, with at-risk workers, credentials ending this week and the weakest site called out. The insights column is written by fixed rules from the same figures, not by a model.
  6. A failed item becomes a non-conformity with an owner and a due date

    A finding is not a note. It becomes a non-conformity carrying an owner, a due date and a corrective action that has to be evidenced before it closes. Findings work as an event stream — a finding’s state is the result of the events applied to it, so the history of a non-conformity is not something reconstructed from a status column that was edited four times.

  7. Close it against the thing that proves it

    An instance closes against a submission, a document or a filed acknowledgement — a portal reference number and the date it was filed. It cannot close against a tick. Submissions are versioned rather than overwritten: an edit made after submission writes a new revision with the change recorded, so the register that was true in August is still legible in March. Once an output has been produced from a submission — a register, a return, anything issued outside the organisation — the submission is locked by a database trigger, not by a convention.

    Credential record for a work-at-height competency awaiting verification, with a PDF competency card and a photographed assessment sheet as evidence, verify and reject controls, history, and the worker's other credentials
    Verifying one record. The competency card and the photographed assessment sheet are stored with size and SHA-256 hash, the history shows who created and attached what, and a rejection carries a reason that the worker sees on their own record. The evidence tiles, the history panel, the other-credentials table and the verification checklist are additions; the real page is a single column of fields with Verify and Reject, and the repo has no upload flow.
  8. Record who verified it, and keep the entry

    Each piece of evidence records the person who verified it and the date they did so. The audit log is append-only and hash-chained: each entry incorporates the one before it, so deleting or altering a past entry breaks the chain and the break is detectable. Append-only enforcement is a trigger on the table, which means it applies to anything that writes — a script, a console, a future feature — and not only to the code that remembered to behave. A past verification stays visible after the obligation is re-evidenced in a later cycle.

    Audit log timeline grouped by day, listing a verification, a submitted daily site safety inspection, a credential upload, an automatic escalation, a rejection and a mapping change, each with time and actor
    The audit log is read-only and grouped by day. Each entry records the entity, the action, the person or system behind it and the time — including the escalation the system raised when a crane operator's competency reached its end date with no renewal on file. The daily site safety inspection entry comes from the v2 obligations engine, which has a schema and seed data but no portal screen.
  9. Catch the expiry before it lapses

    Licences, training records, insurance and equipment certificates each carry an expiry date and an owner. Warnings are raised on a schedule set per certificate type, ahead of the date, and an item past its date is flagged as non-compliant until a replacement is uploaded. An expiry appears on the calendar on the day it falls, so the renewal can be booked before the date rather than found during an inspection.

    Manager's action center on a phone with tabs for expired, expiring soon, missing required and escalations, showing five credentials ending within 15 days
    The action center on a phone: five credentials end within 15 days, alongside expired records, the eight gaps against the requirements register, and open escalations.

What this sequence does not do

It does not file anything for you. There is no integration that submits a return to a regulator’s portal; Comply records that the filing happened, by whom, and with which reference. It does not interpret regulation either — the obligation templates in a domain pack are a starting register built from published instruments, and they need a compliance officer to confirm which apply.

It is not a document management system, not a learning management system, and not a health and safety incident investigation tool. It knows a training event happened and that a certificate resulted; it does not deliver the training. That gap is what Sazinga Engage is being built for.

Comply is in production at fourteen installations — six in the USA, five in the Gulf, two in the UK and one in Africa — across infrastructure, aviation, food and restaurants, and healthcare (September 2026). Most of those deployments run under somebody else’s brand, so the operators cannot be named; what we can see, because the software is ours, is how hard it is worked — two to three surveys a day in each installation (September 2026). Read the operating context on the construction, food safety and healthcare pages. If your compliance problem is really a traceability problem — which batch, which lot, which customer — that is Sazinga Factory rather than this.

Frequently asked questions

What has to happen before an obligation can be marked done?

Something has to be attached. An instance closes against a submission, a document or a filed acknowledgement — a portal reference number and the date it was filed — and it cannot close against a tick. That single rule is what separates a register you can show an auditor from a spreadsheet of green cells.

Who creates the recurring inspections and audits?

Nobody. A scheduler function reads each active obligation’s frequency and anchor, works out the period boundaries, resolves the owning role at that scope, and writes the instance with its period start, period end and due timestamp. A second function marks the ones past their due date and grace as overdue.

What stops a past verification being edited later?

The audit log is append-only and hash-chained, so each entry incorporates the one before it and any alteration to a past entry breaks the chain detectably. Append-only is enforced by a trigger on the table rather than by the application, so it holds for a script or a console session too. Submissions are versioned rather than overwritten, and a submission that has produced an output is locked by a database trigger.

Why do the photographs need coordinates and a capture time?

Because the person who relies on a property inspection was not at the building and reads what came back months later. Photographs are taken in the app rather than chosen from a gallery, and each carries the coordinates and the time the shutter fired rather than the time it reached the server — which is the field a dispute turns on when the phone had no signal at the site.

Does one installation serve more than one organisation?

Yes, and they are kept apart in the database rather than in the application. Tenant isolation is enforced by Postgres row-level security keyed on an organisation identifier set per transaction, which the application role cannot bypass. Without that value set, every tenant-scoped table returns zero rows — the failure mode is an empty screen, not another organisation’s staff list.

Ready to see Comply on your own numbers?

Know what is due, what is evidenced and what has expired. Tell us how it runs where you are — what is kept by hand, what arrives late, and what it costs when it goes wrong — and we will answer against your own figures rather than against the how it works page you have just read.

A person reads every enquiry and replies within one working day.

Would rather read than write? See the screens — real captured ones, no sign-in.