Root & Rise is six reward layers on one wallet, operated from a governed console inside the bank's own data centre. Every reward value in it moves a recognised liability, so the program is run with the controls of a financial process rather than the reflexes of a marketing one.
Points are earned by doing; the Trust Score is earned by banking well. Nothing a customer can play moves the score — that separation is what makes the score usable for credit, and it is the control the board should protect above all others.
| Note | Outstanding points are an IFRS 15 contract liability, revalued nightly and tied to the general ledger daily. Reward values are therefore financial settings, not marketing settings. |
| Approve | The dual-control regime: no change to earning, reward value or campaign is self-service. Draft, submit with a full diff, second signature from a different named person, applied on the next nightly run. |
| Hold | Preferential credit pricing off the Trust Score stays gated on risk-model cohort validation. Commercial pressure to move earlier is refused and routed to Credit Risk. |
Each layer answers a different question, draws on a different budget, and fails in a different way. The funder column is the one to quote whenever a layer is proposed to be made more generous.
| Layer | What it is | Funded by | Fails when |
|---|---|---|---|
| Onramp | One-time bonus for clearing Level 0 to Level 1 | Growth budget | Bonus paid, customer never returns |
| Foundation | Instant cashback — cash, not points | Bank's own margin | Rate creeps above the point value |
| Daily Habits | Check-ins, streaks, fraud quizzes | Marketplace partners | Engagement rises, Trust Score does not |
| Moments | Capped chance reward on a qualifying transaction | Marketing budget | Velocity farming on small tickets |
| Trust Score | Behavioural score that unlocks credit terms | Reduced cost of risk | Used for pricing before validation |
| Marketplace | Where points are spent; literacy and grants | Partners, bank, donors | A redemption fails and nobody notices |
liability = outstanding points × point value × (1 − breakage)
Three numbers with three owners. Outstanding points come from the ledger and are not an opinion. The point value is the single highest-impact setting in the console and needs Finance and Internal Audit. Breakage is an assumption Finance signs and Audit traces, re-signed quarterly; a change appears in the audit log as a re-signature, never a silent edit. A sensitivity slider on screen lets Finance test other assumptions without changing the booked position.
Lower breakage means a larger liability — and a better program, because customers are actually redeeming. A rising liability is not bad news on its own; it should be read with redemption rate beside it. A program with 40% breakage is cheap because it is not working.
Nothing in the engine takes effect when it is saved. An operator builds a draft, prices it (a backtest against real history, a simulation of the forward liability curve), and submits it as a line-by-line diff into the approvals queue and the append-only audit log. A different named person approves. It applies on the next nightly run — the bank's own batch — so the honest answer to stakeholders is always "tomorrow", never "now".
| Change | Required sign-off |
|---|---|
| Point value / rupees per point | Finance + Internal Audit |
| Earn rule or habit value | Finance + Program admin |
| Tier threshold or Trust Score weight | Credit Risk |
| Campaign launch | Finance + Compliance |
| Customer-facing copy or quiz question | Compliance |
| Partner settlement run | Finance + Procurement |
Every campaign carries a holdout of at least 10%. Effect is the gap between treated and control; cost is divided by incremental actives, not by everyone reached. Campaigns without an adequate control are excluded from the blended cost figure rather than assumed to work — and that exclusion is reported as prominently as the successes.
Six detection patterns — circular P2P, agent collusion, QR velocity farming, referral rings, quiz automation, dormant spikes — run on the same nightly batch as the ledger. No points reverse automatically: a claw-back is the mirror of a goodwill credit and carries the same two signatures. Agent and ring cases go to the Financial Crime Unit in parallel.
The points ledger is tied to the general ledger daily, account by account. A variance becomes a break with a named owner and a target date; the ledger is never adjusted to force a tie. Batch reliability is treated as a customer-trust metric rather than an IT metric — a payout job that fails silently becomes a complaint within days and a goodwill adjustment within a week.
The pack is assembled from live console figures — nothing is retyped, so the numbers always match the screens they came from. It leads with DAU/MAU, the north star that moves two to three months ahead of churn. It then reports the mercenary test: engagement and Trust Score read on the same cohort, because engagement rising while the score stays flat means the program is buying attention rather than habit. It closes with what did not work — spend with no detectable lift, spend that cannot be judged at all, SLA breaches, open reconciliation breaks.
The customer can see almost everything the operator can — why an award was what it was, which points expire first, why they received a message, how their case was resolved. The program is built on the assumption that every figure on an internal screen can be read back to the person it belongs to.
This brief quotes no live values by design; current figures are read from the console at the moment of assembly. Thresholds, reward values and tier names remain subject to workshop confirmation. Derived from the Program Console operator manual v1.0 · Program Office, HBL Microfinance Bank.