Your channel-partner panel, on the record.
Every builder runs the same morning: a fresh lead roster goes out to fifteen channel partners on WhatsApp, three of them forward it to two sub-agents each, and by Wednesday one buyer is being called by nine people with your name on the project. Saudaflow replaces the roster with a grant — one partner, one lead, revocable, and written down as it happens.
- Scoped sharing a partner cannot widen
- Ownership by timestamp, never by phone call
- Tranche commission · §194H · 18% GST
- Project → tower → floor → unit
- Row-level isolation, forced
- An audit log nobody can edit
Came here looking for an API?
Then you want the other meaning of the word, and we would rather lose thirty seconds of your time than waste ten minutes of it. In Indian real estate a developer is the firm that builds and sells the project, and that is who this page is written for.
Saudaflow has no public or tenant API. There is no key you can be issued, no specification to generate a client from, and no outbound webhook that calls your systems. The only integration surface is inbound: nine signed lead webhooks that portals and ad platforms call into. That is described in full further down, and so is everything else we do not have.
A share is a grant, not a copy.
The partner signs in to their own portal. They have no seat in your workspace, no password of yours and no permissions record — their identity is the session, and the partner id it carries sits inside the WHERE clause of every statement that reads a lead. Not in a filter applied afterwards. In the query.
Their book, and only theirs
A partner sees the leads they introduced. Because the scoping is in the query rather than in a permission check on top of it, a lead that belongs to another partner and a lead that does not exist produce the same answer: 404, never 403. A 403 would confirm the record exists, which is itself a disclosure.
Projects granted one at a time
Visibility is a row per partner per project, with a revocation timestamp. Revoke it and the project stops appearing, because the grant is joined into the read rather than consulted beside it. Re-granting clears the revocation on the same row — the history of who could see what and when belongs in the audit log, and that is where it is kept.
Commission visibility is a dial
Per partner: nothing, the state of each tranche, or the full figures. It ships set to nothing, so showing a partner their money is a decision you make rather than a default you discover.
Shown
- The buyer’s name and a masked phone — 98XXXXXX10 — even though the partner typed the number in.
- The owner’s first name, so they have somebody to ask for at the front desk.
- Five coarse stages, so they can see the lead is moving.
- Their own attribution trail: when they introduced it, and how long the introduction is protected.
- The projects you granted them, and their own visits, notices and — if you turn it on — commission.
Never selected
- Your internal notes, the activity timeline, dispute notes, and the reason a lead was marked junk or lost.
- Lead score, contactability score, temperature, priority — your private assessment of their referral.
- The raw pipeline status, which includes words like flagged and escalated.
- Whether a competing claim exists. That names a third party’s activity; a partner hears about a dispute from you.
- Your staff directory. One full name per lead, repeated down a list, is a directory.
- Any other partner’s anything.
The masking is not squeamishness. After introduction your team corrects and enriches the contact, so echoing the current stored number back would quietly turn the partner portal into a re-export of your contact master — on a handset several people in a broking office share.
The site-direct argument, settled by a timestamp.
Two people claim the same buyer. One of them registered first. That is the whole rule, and the reason it holds is that a partner’s submission goes through the same de-duplication engine as a portal lead and a walk-in — it never gets to insert a lead directly, which is exactly how a second owned lead for the same buyer would appear.
-
01
The enquiry arrives
From a portal, an ad, your website, a QR, a walk-in or a partner’s portal. The source is stamped at first touch and frozen.
-
02
Identity is matched
On a normalised phone, or an email when there is no phone. An enquiry with neither matches nothing, deliberately — a record with no identity must not be given one.
-
03
Inside the window
A match against an owned lead becomes a duplicate touch on the original, with the new source appended. Never a second owned lead. Never a rewritten owner.
-
04
Outside it
The introduction is claimable and starts fresh. The window defaults to 45 days and is your setting, not ours.
The window is frozen at the event
Each row of the attribution history stores the window that was in force at that moment, not the one configured today. Change the setting next quarter and last quarter’s dispute reads exactly as it did — which is the difference between a record and a report.
You cannot delete the evidence about a partner
The link from an attribution event to the partner who registered it refuses deletion at the database level. Removing a partner mid-dispute would have quietly changed the answer to “who introduced this buyer” to nobody. Offboard them instead — which is what the product actually does, and what the trail then says.
| Event | What it means when an arbitrator reads it |
|---|---|
| introduced | Somebody registered this buyer, at this time, from this source. |
| duplicate_touch | The same identity arrived again, inside the window, and was filed on the first owner’s lead. |
| claim_filed | A formal ownership claim, distinct from an introduction. |
| accepted | The claim was allowed, and by whom. |
| reassigned | Ownership moved, deliberately, on the record. |
| disputed | Two parties disagree. The lead carries the state; nobody has to remember it. |
| resolved | It ended, and the row says how. |
The notes column on that trail is documented in the schema as never carrying a phone number or an email address. It is written for the person adjudicating, and an adjudication record is not a place to spill the buyer’s contact details.
Three states. Everything else is a flag.
A tranche is Accrued, then Scheduled, then Paid. Cancellations, holds, reviews and clawbacks do not invent a fourth state — they are flags on the row, so a tranche never ends up somewhere your finance team has to be told about separately.
- Accrued
- Scheduled
- Paid
Flags that ride alongside: On hold Needs review Clawback flagged Suppressed.
The profile is frozen onto the tranche
Rate, slabs, splits and the payout schedule are copied onto the row as a snapshot at the moment it accrues. Renegotiate the profile next month and last month’s accrual does not silently restate itself. Re-computing is allowed only while every tranche in the group is still unpaid; touch a scheduled or paid one and the server refuses.
A trigger can need two things at once
Not just “on booking”. A tranche can require a payment percentage and a document milestone together — the shipped default releases 30% once 10% of the consideration is in, 30% on a registered Agreement for Sale, and 40% on the possession letter. The evidence that the trigger fired is stored with it.
Co-brokers split before tranching
The gross divides between the partners first, and each one gets their own set of tranches. That ordering is not cosmetic: TDS is a per-deductee calculation, and splitting after tranching would compute one partner’s tax against another’s year-to-date.
The tax, in the order it is actually done.
- GST first. 18% where it applies, with registered and unregistered partners handled differently, inclusive or exclusive as the profile says, and no reverse charge unless a notified category is explicitly configured.
- The TDS base is always the GST-exclusive amount. It is written on the schema in as many words: tax is never computed on GST.
- §194H is financial-year aware. Below the ₹20,000 year-to-date threshold nothing is deducted. The moment the aggregate crosses it, the deduction is taken on the whole aggregate with credit for what was already deducted — the catch-up your CA expects, computed rather than remembered.
- No valid PAN raises the rate under §206AA, and the row records that this is why.
- The financial year is resolved on the Indian calendar day. There is a comment in that file explaining the bug that made it necessary: between midnight and 05:30 IST on 1 April, a naive server clock is still in March, and it booked a partner’s first tranche of the new year against the old one.
A lapsed RERA registration blocks the payout. Tranches still accrue — the work happened — but they insert on hold, with the reason named on the row and a notification raised. Silently skipping the accrual would have been the easy behaviour and the dishonest one.
A cancellation suppresses what is unpaid and flags what is paid. Unpaid tranches are suppressed and never released; a tranche already paid is flagged for manual clawback review. There is no automated recovery of money that has left your bank, and there should not be.
Accrual is idempotent: a booking that already has a live tranche group for that partner will not accrue a second one, however many times the booking is saved.
Saudaflow never touches a rupee of it.
What actually happens
Your buyer pays you the way they already do — transfer, cheque, UPI, whatever was agreed — and somebody on your team records the receipt. Your bank pays your partner. There is no payment gateway inside Saudaflow, no payment link, no collection, no settlement and no payout. We are not a payment service and we will not describe ourselves as one.
What Saudaflow holds is the record: the payment plan and its milestones, the demand schedule, an append-only receipts ledger, and the commission ledger above. A correction is a new negative reversal line, not an edit — so the ledger can be wrong about a fact for an hour, but it can never be quietly made to have always said something else.
The money moves the way it always has. Saudaflow is the record that does not disagree with the bank.
Because every money-in line is stored rather than computed, the RERA Section 13 advance check is stored with it — how much had been received, what percentage of the unit value that was, the cap in force, and whether the Agreement for Sale was registered at that moment. It flags; it does not block. Refusing to record money you have actually taken only moves the truth into a spreadsheet.
Cancellation follows the same instinct. The default refund calculation pays interest per receipt, day-counted, and prints every line — because the Appellate precedent in this country runs towards refund with interest, not towards forfeiture.
Project, tower, floor, unit — and a plotted scheme skips the tower.
The matrix is four levels, and two of them are optional. A plotted development has plots on land, not flats on floors, and the model says so rather than making you invent a tower called “Phase 1” to satisfy a form.
RERA number, state, area unit, price grid, and the layout switch that decides whether towers exist at all.
Optional. Absent on a plotted scheme.
Optional, for the same reason.
Carpet, RERA carpet, built-up, super built-up, balcony, terrace and plot areas each as their own column; floor, corner and PLC premiums; parking; possession type; one status.
Unit numbers stay unique either way
Uniqueness is enforced on a generated key that treats an absent tower and an absent floor as a real value. Left to plain nulls, two plots numbered A-12 would have compared as distinct and both been allowed — the kind of bug that only shows up on a plotted township at handover.
One status at a time
Available, On hold, Booked, Sold. A hold carries its owner, its reason and its expiry, and everybody sees the same state at the same moment — which is the only thing that stops two partners quoting the same flat on the same Saturday.
Loaded by CSV, validated by row
Import validates and normalises each row on its own and reports the failures with their row numbers, rather than rejecting a two-thousand-line file because line 1,384 has a stray comma.
One approval engine, thirteen things it approves.
Discounts, hold extensions, cancellations, price changes, marketing content, marketing budget, discount reversals, refunds, hold-release overrides, booking re-opens, commission exceptions, manual price overrides and named exceptions. One engine, because thirteen separate approval flows is thirteen places for a chain to be subtly different from the one your ops head thinks is running.
Chains are rows, and they are versioned
Steps, approver roles, thresholds, conditions, SLAs and escalation live in the database and are edited in Settings, with a simulator that answers “who would this go to” before you publish. Every edit is written to an append-only chain history: who changed it, and to what.
An in-flight request keeps the chain it was submitted under
The chain as evaluated at submit time is frozen onto the request. Editing the chain tomorrow cannot retro-change a decision made today — which is the property you need the day somebody asks why a 7% discount only needed one signature. Self-approval is refused, and so is overriding your own request: an override is still a decision.
The shipped discount bands are 0–3% automatic, 3–6% to the Sales Manager, 6–9% to the Zonal Head, above 9% to the Business Head — a starting point, not a rule. Discounting runs at 3–9% in NCR, 1–5% in Mumbai and around 2% in Bengaluru, so a fixed band would be wrong in at least two of your markets on day one.
Thirty-three roles, four dimensions, one database that says no.
The role library
33 roles ship, plus the Org Admin your workspace is created with. Business and sales heads, zonal heads, area and sales managers, team leaders, telecallers, site-visit coordinators, field sales, closing, post-sales, documentation, finance, marketing, compliance, IT — and the partner side, from CP Owner to CP Back-office. Every one is cloneable and renamable, one person can hold several, and the effective permission is the union.
Four dimensions, not a checkbox list
Module (21 of them) × action (18, from view to approve to export) × data scope (14, from own to team to project to zone to org, resolved widest-wins across roles) × field visibility (visible, read-only, masked, hidden). A PAN can be masked for one seat and readable for another on the same screen.
Isolation is the database’s job
Row-level security is enabled and forced on the tenant tables, and the policy reads the current organisation from a per-transaction setting through a guard that matches nothing when it is unset. A query that forgets the tenant returns no rows instead of everyone’s. 135 of the 138 tables carry an organisation id; the three that do not are the organisations table itself and two pieces of platform bookkeeping that hold no customer records.
The library is checked against the permission registry at runtime, so a misspelled field name or a role reporting to a manager that does not exist fails loudly at start-up rather than quietly seeding a broken workspace.
Actor, before, after, timestamp — and nothing can edit it.
Every sensitive action writes a row carrying who did it, what they did, which record they did it to, the value before, the value after, the request’s IP and user agent, and the time. That is the shape of the table, not a description of good intentions.
Append-only by database grant
UPDATE and DELETE are revoked from both of the runtime database roles. The application physically cannot amend or remove an audit row — not your administrator, not ours, not a support engineer at three in the morning. It has been append-only by convention since the first week; it is append-only by permission now.
Reading it obeys the same scope
Org breadth reads the whole log. Anything narrower is pinned to the caller and the people under them, and the same clause rides the list, a record’s timeline, the detail view and the export — so there is no door through which a narrowed seat reads wider than their screen.
Exporting evidence is evidence
Downloading the audit log writes its own high-severity audit row. It is on for every workspace on every plan — it has never been a paid tier — and any access to your workspace by Saudaflow staff is written into a separate log that you can read and that neither of our console roles can update, delete or truncate.
Nine signed inbound webhooks. In one direction.
This is the integration surface, in full. Portals and ad platforms call Saudaflow; there is no route in the other direction, no key you can be issued, and no specification to generate a client from. Said once here and once again below, because it is the thing a technical evaluator most needs to know before a trial rather than during one.
- 99acres
- MagicBricks
- Housing.com
- Facebook & Instagram Lead Ads
- Google Ads lead forms
- Website form
- QR & landing page
- Custom partner webhook
- WhatsApp Business (Meta Cloud API)
Signed, and de-duplicated at the door
Each provider declares its own signature scheme — an HMAC-SHA256 over the raw body for the portals, Meta’s prefixed variant for its own feeds, a shared token where that is all a provider offers. The delivery’s own identifier is unique per organisation and provider, so a portal that retries a delivery it already sent produces a duplicate marker, not a duplicate lead.
A lead is never dropped quietly
A failed delivery is recorded, the integration’s owner is notified, and it is retried after one minute, five, fifteen and an hour. After five attempts it goes to a dead-letter queue a human can see and replay. Each feed carries a health score out of 100 and a plain label — healthy, degraded, failing, idle, unconfigured — with the reasons written out rather than left as a colour.
One honest limit on the WhatsApp entry: the module is complete end to end, but no tenant can send or receive a message until live Meta credentials exist. It is listed here because it is built, and marked below because it is not live.
The page this replaces described a product we do not ship. Here is the list.
The previous version of this page carried a cryptography section with a code sample citing a file that has never existed in this codebase, a storage vendor we do not use, and a price card for plans we retired. It was rewritten in September 2026. Everything above is in the product today; everything below is not, in the same place and the same type size.
-
No public or tenant API
No key issuance for customers, no specification, no generated client, no outbound webhook calling your systems. The only keys in the product belong to our own operations console. If your evaluation depends on building against us, it fails here — better now than in week three.
-
Lead data is not encrypted at rest
The old page said each lead name, phone and email was sealed under its own key. They are ordinary database columns. What protects them is the isolation, permission and audit machinery described above, and we would rather write that sentence than the other one. The only per-record encryption in the product seals call recordings, and that is not live.
-
No keyed fingerprints, no blind-index search
Duplicate detection matches on an ordinary one-way hash of the normalised phone or email. It backs de-duplication, not search, and it is not a keyed construction. The chip that said otherwise has gone.
-
We do not raise your partner’s invoice
Saudaflow computes the base, the GST, the TDS and the net, shows the working, and holds the ledger. It does not generate a tax invoice, resolve place of supply, or export to your accounting package. Your finance system raises the document from numbers it can check line by line.
-
WhatsApp and telephony are built, not live
The WhatsApp module is complete and waits on Meta credentials. Click-to-call and call recording are built and wait on a telephony account, and recording additionally needs a key and a per-workspace switch. Transactional e-mail is live. Push notifications wait on Firebase. Buyer and staff sign-in by SMS waits on DLT registration with TRAI.
-
Geofencing is inert until a project has a pin
A check-in captures GPS and a photo and stamps them on the visit, always. Judging whether it happened at the site needs the project’s registered coordinates, and today no screen in either app sets them — so a check-in is honestly recorded as unverified rather than pretending to a verdict. Once a pin exists, an implausible location is flagged for a manager, never silently blocked.
-
Android only, and no map yet
The field app is Android. There is no iPhone build. The in-app map has been written and type-checked but never rendered by anyone, so it is not something we will show you a picture of.
-
No numbers we cannot stand behind
The old page promised revocation in 1.2 seconds, dashboard updates within 2 seconds, 100,000 units without pagination and onboarding in about three hours, and quoted three industry statistics with no source. None of them had a measurement behind them. They are gone rather than softened.
Per seat, published, and the same for a five-seat office as a five-hundred-seat one.
There are no seat bands. Plans are sold by how you work, not by how many of you there are, and any team size can take any plan.
Essential
₹799 per seat per month
Solo, or a small team.
₹2,397 a quarter, or ₹8,628 a year — an effective ₹719 a month.
Professional
₹899 per seat per month
Teams, and builder–partner flows — which is most of this page.
₹2,697 a quarter, or ₹9,708 a year — an effective ₹809 a month.
Custom
₹1,199 per seat per month
Scoped to your process.
₹3,597 a quarter, or ₹12,948 a year — an effective ₹1,079 a month.
Billed quarterly or annually; annual takes 10% off. All prices are plus 18% GST, with a 30-day money-back guarantee. One thing to know before you buy: our GST registration is not yet issued, so until it is, the invoice we send you is a proforma and carries no GST. We would rather tell you that here than let your accounts team discover it. The full comparison is on the pricing page.
Asked on every builder call.
If yours is not here, ask it on the demo — or write to support@saudaflow.in. Support is open 09:30–19:00 IST, every day.
Is this page about property developers or software developers?
Property developers. In Indian real estate a developer is the firm that builds and sells the project, and this page is for the person there who runs the channel-partner panel.
If you arrived expecting an API: Saudaflow has no public or tenant API, no key issuance for customers, no specification to generate a client from, and no outbound webhook. The only integration surface is inbound — nine signed lead webhooks that portals and ad platforms call. That is the whole of it, and it is on the page twice rather than buried here.
What exactly does a channel partner see when I share a lead?
Their own introductions and nothing else. The partner’s identity comes from their portal session, never from anything their browser sends, and the partner id sits inside the WHERE clause of every statement — so a lead that is not theirs and a lead that does not exist return the same 404.
Inside that, the exposure is deliberately narrow: the buyer’s phone is masked even though the partner typed it in, the owner appears as a first name so the list cannot become your staff directory, and your internal notes, lead score, temperature, raw pipeline status, dispute state and lost reasons are never selected at all. Projects are granted one at a time, and revoking a grant stops that project appearing because the grant is part of the query.
How does Saudaflow settle a site-direct ownership fight?
By timestamped registration, not by who telephones you first. An enquiry arriving on a phone or email that already belongs to an owned lead inside its attribution window becomes a duplicate touch on the original lead, not a second owned lead. The window defaults to 45 days and is a setting.
Every event goes into an append-only attribution history that records the source as it was then, who registered it, what matched, and the window in force at that moment rather than today’s setting — so changing the setting later cannot rewrite an old dispute. The link to the partner refuses deletion at the database level, so nobody can remove the evidence by removing the partner.
How is commission calculated, and can I trust the tax?
Commission accrues from the profile in force for that partner on that project, frozen onto the tranche as a snapshot so a later edit cannot restate an old accrual. A payout trigger can require a payment percentage and a document milestone together, which is how a real builder pays: 30% once 10% of the consideration is in, 30% on a registered Agreement for Sale, 40% on the possession letter.
GST is computed first, because the TDS base is always the GST-exclusive amount. §194H is financial-year aware: nothing is deducted until the partner’s year-to-date base crosses ₹20,000, and when it does the deduction is taken on the whole aggregate with credit for what was already deducted. Without a valid PAN, §206AA raises the rate. Every figure is computed on the server, and the working is stored on the tranche so your finance team can check it before anything is marked paid.
Does Saudaflow collect or pay out money?
No, and it is the most important sentence on this page. There is no payment gateway, no payment link, no collection, no settlement and no payout inside Saudaflow. Your buyer pays you exactly as they do today and someone on your team records the receipt; your bank pays your partner.
What Saudaflow holds is the record — the plan, the demand, the append-only receipts ledger where a correction is a new reversal line rather than an edit, the RERA advance check stored on every money-in line as it was evaluated at that moment, and the commission ledger. The money moves the way it always has. Saudaflow is the record that does not disagree with the bank.
What stops one workspace from reading another?
The database, not the application. Row-level security is enabled and forced on the tenant tables, and the policy resolves the current organisation from a per-transaction setting through a guard that matches nothing when it is unset. Deny by default is the literal behaviour: a query that forgets the tenant returns no rows rather than everyone’s. Forcing it matters as much as enabling it, because it applies the policy to the table’s owner too.
135 of the 138 tables carry an organisation id. The three that do not are the organisations table itself, whose primary key is the tenant, and two platform bookkeeping tables that hold no customer records.
Is the audit trail something an admin can tidy up?
No. Each row carries the actor, the action, the entity, the before, the after, the request’s IP and user agent, and the time. UPDATE and DELETE are revoked from both runtime database roles, so the application physically cannot edit or remove a row — and neither can your admin nor ours.
It is on for every workspace on every plan and has never been a paid tier. Exporting it is itself an audited action at high severity, because the export of evidence is evidence. Separately, any access to your workspace by Saudaflow staff is written to a log you can read and that neither of our console roles can update or delete.
What is on this page that I cannot have yet?
Several things, and they are named above in the same type size as everything else. WhatsApp is built end to end but no tenant can send a message until Meta credentials exist. Click-to-call and call recording are built and need a telephony account; recording additionally needs a key and a per-workspace switch. Push notifications wait on Firebase; e-mail is live.
There is no invoice generator for your partner’s brokerage. Geofencing is inert until a project has a pin and today no screen sets one, so a check-in is honestly recorded as unverified. The field app is Android only. And there is no public API.
Bring one live dispute to the call.
Thirty minutes. Bring a project, two channel partners and one argument you are currently having about who introduced whom — we will set the workspace up and run it through the attribution trail and the commission ledger on your own numbers.
Sold through a short call — we load your projects, seats, roles and partners with you. No card, no self-serve signup, and the prices are on the pricing page rather than behind the call.