{{ programName }}
Program office
Nightly batch, 06:00 PKT. Rule and pricing changes here are projections, not production writes.
Customer app demo →{{ sectionTitle }}
{{ sectionSub }}
{{ k.value }}
{{ k.delta }}
Engagement index against Trust Score movement. Engagement rising while Trust Score stays flat is reward-chasing, not habit formation — the one signal that invalidates the program.
{{ o.body }}
Everything on this page reads from the demo backend — the same ledger the customer phone writes to. An action on the phone lands here within a second; a nudge sent here pops up on the phone within three seconds.
{{ k.value }}
{{ k.sub }}
Waiting for the first action. Open the customer app, check in or pay a bill, and it appears here.
Rendered from the template library, delivered in-app as a popup. The status ticks Queued → Delivered → Seen as the device picks it up.
{{ liveNudgePreview }}
We compute entitlement and fire a signed trigger; the bank moves the money. Replay re-sends with the same idempotency key — the bank side ignores the duplicate.
No deliveries yet. Redeem something on the phone and the trigger lands here.
Backend: {{ livePairBase }}
Device token (c1 · Ayesha): {{ livePairToken }}
| Layer | Cadence | Participation | Monthly cost | Funded by | Phase |
|---|---|---|---|---|---|
| {{ l.name }} | {{ l.cadence }} | {{ l.participation }} | {{ l.cost }} | {{ l.funder }} | {{ l.phase }} |
Bar length is cadence, not reward value. The top three carry engagement; the bottom three carry meaning.
ADB gating on Root and Harvest is a funding source, not a cost. Rs. 5.7bn of gated balances, measured as 34 bps off blended cost of funds. Tracked jointly with Treasury.
Quiz completion is tracked against fraud-dispute rates by cohort. The gap is what lets Daily Habits be reported as partly self-funding.
{{ selIdLine }}
{{ selLifeLine }}
{{ selPointsFmt }}
{{ selWorthLine }}
{{ c.note }}
Every row carries a decision trace. Open one to see each source that looked at the transaction and the wording to read back to the customer.
{{ selTierSince }}
{{ selTierNext }}
The model ranks, the caps and fatigue rules veto, and every decision carries a trace — offers are explained the way points are.
{{ selLotNote }}
Decision trace
{{ traceRef }}
{{ traceHeadline }}
{{ traceSub }}
Every source that looked at this transaction
{{ s.formula }}
{{ traceWording }}
{{ traceActionNote }}
{{ traceFooter }}
No customers match that filter.
{{ resultCount }} · sample extract, not the full book.
{{ selName }}
{{ selMeta }}
{{ piiNote }}
{{ s.value }}
{{ s.sub }}
{{ selFlags }}
Habit activity is excluded from the score by design. Engagement that does not show up in transaction consistency, bill punctuality or savings held earns points, never pricing.
184.2M
all layers, month end
{{ liabilityTotal }}
{{ bookedBreakageLine }}
72%
rising is the goal, not falling
61%
+4 pts on last quarter
| Layer | Outstanding | Breakage | Cost / point | Liability | Owner |
|---|---|---|---|---|---|
| {{ r.layer }} | {{ r.outstanding }} | {{ r.breakage }} | {{ r.cpp }} | {{ r.liability }} | {{ r.owner }} |
Lower breakage means customers actually redeem — a better program and a larger recognised liability. Audit will ask which direction the assumption was moved, and why.
{{ liabilityTotal }}
{{ liabilityDelta }}
Outstanding Points × (1 − Breakage Rate) × Cost Per Point.
Daily Habits is modelled separately from Moments — one blended rate misstates both, because habit points are earned free and Moments are near-cash. Finance and Audit sign the model before launch, and re-sign each time a rule moves.
{{ draftLine }}
{{ draftSub }}
{{ t.value }}
{{ t.sub }}
{{ mercenaryVerdict }}
Every control below buys attention. It only counts if Trust Score follows — engagement mechanics can move the behaviour the score measures, but they are locked out of the score itself.
No earn rules. Nothing in the program issues points — add one below.
Foundation cashback is cash, not points — the one earn line that never touches the ledger, deliberately modest because it comes from the bank's own margin. Every line above creates a liability the moment it fires.
{{ earnPointsTotal }}
across the enabled lines
{{ earnCostTotal }}
at {{ ratioShort }}, net of breakage
The point-to-rupee ratio prices the whole program, and it is the number Audit traces through the liability model.
{{ f.note }}
{{ ratioHeadline }}
{{ ratioLiability }}
184.2M points outstanding
{{ ratioDelta }}
live is Rs. 0.35 a point
Redemption should be easy and the rate should rise. A ratio tuned to suppress redemption turns the program back into a discount scheme with an audit problem attached.
{{ habitLayerNote }}
{{ f.note }}
What the customer sees on the Habits tab, computed from the values on the left.
{{ habitCostLine }}
This is where “earned” is defined. The Trust Score is a weighted read of how a customer banks. Points are never an input — not base earn, not campaigns, not habits — so no promotion can buy a better score. Owned by Credit Risk; any change here needs model validation before it reaches production.
{{ trustRange }}
These are locked out of the model, not merely weighted at zero. It is what makes the mercenary test a real test.
Thresholds come from the tier ladder — edit them on that tab so the score and the ladder cannot drift apart.
{{ quizCountLine }}
Live questions are served two or three a session with an explanation after every answer. Draft questions never reach a customer.
{{ editorStatus }}
{{ fatigueLine }}
{{ tplStance }}
{{ tEn }}
{{ tUr }}
{{ tRoman }}
{{ tplCostLine }}
{{ tplLangWarn }}
{{ tplNote }}
{{ tplVarLine }}
{{ tplCostLine }}
{{ tplLangWarn }}
{{ tplNote }}
{{ simBasisNote }}
{{ s.note }}
{{ simStance }}
{{ btDraftLine }}
{{ btBaselineNote }}
{{ btHonesty }}
Instant is the whole point of this layer — the customer sees cash before they leave the counter.
Below this, a transaction earns nothing — the first defence against velocity farming.
Caps the tail without touching the median earner.
{{ cbAnnual }} annualised. {{ cbCapLine }}
{{ cbTierLine }}
{{ cbLedgerLine }}
{{ tierWarning }}
One qualifying condition per tier, never four at once. If a customer cannot say in one sentence why they moved up, the ladder is wrong.
Instant, transaction-triggered, capped. A Moment is funds received — the two-hour hold applies and must be disclosed in the reveal copy.
{{ f.note }}
{{ momentsSpend }}
{{ momentsSpendSub }}
Above one reveal a day the mechanic stops being a surprise and starts being an expected discount — at which point the budget line behaves like margin, not marketing.
One catalogue, two consumers. A trigger is an event the engine can react to. Earn rules turn a trigger into points; Moments turns a trigger into an instant reward. Disable a trigger here and it stops firing in both — that is the kill switch.
{{ triggerSummary }}
Volume is per month and drives every cost projection in this console. Units is how many earn increments one event produces — one for a flat per-transaction rule, twelve for an average Rs. 1,200 QR basket earning per Rs. 100.
These rates are what every campaign's cost estimate is built from. Change one here and every campaign in the builder reprices. Rates come from the aggregator contract — Finance owns them, not Marketing.
An SMS is billed per segment. Latin text fits 160 characters a segment; Urdu is UCS-2 and fits 70. A trilingual campaign is costed at the worst case of the two.
Defaults every new campaign inherits. The fatigue cap is a hard stop across all campaigns — a customer cannot be messaged past it, whoever is running the promotion.
Messaging spend is a marketing cost, not a points liability — it never touches the IFRS 15 provision. Budget it separately, and watch the ratio: a campaign spending more on telling people about the reward than on the reward itself is a campaign worth killing.
Move a lever to see the projected effect on cost and liability. Nothing here reaches production.
{{ r.note }}
{{ projCost }}
{{ projCostSub }}
{{ projVsLive }}
{{ projLiability }}
at the sandbox breakage
{{ projPerUser }}
per month, blended
{{ caseAmount }}
{{ caseWho }}
{{ f.value }}
{{ recPrice }}
{{ recSub }}
{{ priceNote }}
{{ decisionLine }}
{{ k.value }}
{{ k.sub }}
{{ pOwedNote }}
{{ pNote }}
{{ pBreachNote }}
{{ catalogueNote }}
{{ stlNote }}
{{ s.note }}
{{ stlStance }}
The purpose track is the one line funded on principle rather than return — literacy sessions and small-business grants, reported beside the commercial partners so the trade-off stays visible rather than buried in marketing.
{{ c.name }}
{{ c.detail }}
{{ c.meaning }}
{{ c.status }}Phase 1 shipped on existing transaction data. Phases 2 and 3 overlap deliberately; games and the full Shariah variant remain Phase 4, sign-off first.
{{ r.risk }}
{{ r.mitigation }}
{{ r.owner }}Name it, say what it fires on and what funds it. Everything else is set in the editor.
{{ c.ref }}
A campaign never replaces base earn — it adds to it. That is the rule that keeps “where did my points go” answerable: the base line is always there, and every campaign shows as its own line on the trace.
Campaigns award points, never Trust Score. They move the behaviour the score measures — a bill campaign lifts bill punctuality — but a promotion can never buy a better score. That separation is what makes the mercenary test meaningful.
{{ campTabNote }}
{{ f.note }}
{{ treatedLine }}
{{ holdoutNote }}
{{ l.formula }}
{{ campPreviewSentence }}
{{ campPreviewWarn }}
{{ campProjection }}
{{ msgPreview }}
{{ msgPreviewUr }}
{{ msgFooterText }}
{{ costSplit }}
{{ costNote }}
{{ campNote }}
Nothing here awards a point until Finance signs the pool and Compliance signs the mechanic. Every change lands in the audit log.
New campaign
Four decisions to open a draft. It awards nothing until Finance and Compliance sign it.
From the trigger catalogue — only active triggers can carry a campaign.
{{ wizSummary }}
{{ confirmTitle }}
{{ confirmBody }}
{{ b.note }}
{{ aggVerdict }}
{{ aggMethod }}
{{ perfEmpty }}
{{ verdictText }}
{{ funnelNote }}
{{ persistNote }}
{{ perfMethod }}
Cost per incremental active divides campaign spend by the extra actives the holdout says the campaign caused — not by everyone who qualified. A campaign with no holdout has no denominator, and stays unranked.
{{ a.ref }}
{{ a.meta }}
Nothing in this state.
Nothing configured in this console reaches a customer without passing through here. An analyst drafts, a second person decides, and the decision is written to the audit log with both names on it.
{{ apprRef }}
{{ apprWho }}
{{ l.text }}
{{ apprNote }}
Reward values move a recognised liability, so a rule change is a financial change, not a marketing setting. The queue is what turns that principle into a control an auditor can test — and the reason maker and checker can never be the same person.
{{ f.note }}
{{ onrampVerdict }}
{{ breakBody }}
{{ opsStance }}
{{ boardNote }}
{{ boardTitle }}
{{ boardHonest }}
{{ alDetail }}
{{ alNote }}
{{ riskStance }}
No cases in this state.
{{ csSummary }}
{{ csNote }}
{{ caseStance }}
No entries match that filter.
The log is append-only and retained seven years. Every reward value, ratio, tier threshold, quiz publication, access change and customer-name unmasking lands here with the before and after values — this is the artefact Internal Audit asks for first, and the reason no lever in this console writes silently.
Change this role?
{{ roleAskBody }}
Configure and publish are deliberately split: an analyst can draft a reward change, only a program admin can raise it, and Finance signs before it reaches production. Credit pricing sits with Credit Risk alone — no program role can touch it.
{{ usersSummary }}
{{ meName }}
{{ meEmail }} · {{ meRole }}
{{ f.value }}
Required for every role that can configure or publish.
{{ meActivityLine }}