Product · Quality & compliance

Audits that can't be quietly passed

Paper audits share a weakness: they prove an audit happened, not that anything was checked. There's no record of who did it, how long it took, or whether the answers were filled in at the dock or in the break room afterwards.

12 template field types
18 report widget types
4 escalation tiers
Confidential client & operation

Built for a contract-logistics operation with contractual quality- reporting obligations to its end customer.

The problem

Quality performance was a contractual obligation reported to the customer on their fiscal calendar, with fault attribution on every discrepancy and a service- level clock attached. The evidence behind those numbers was paper forms and a general-purpose survey tool that couldn't report across responses.

Separately, a required housekeeping audit ran monthly across the site, and the rule that mattered — auditors must not audit their own area — was enforced by whoever built the schedule remembering to enforce it.

What we built

An audit platform where the audits themselves are configuration, not code. Templates are assembled in the browser from a palette of twelve field types including photo capture and signature capture, and most question types can be set to require a photo, a written note, or both, and the audit will not close until every one of them is satisfied.

Questions carry conditional logic: an answer can reveal a follow-up question, or trigger a side effect. Two of those side effects are the ones that make it a workflow tool rather than a form builder — an answer can open a corrective action item assigned to a named person with a due date and a requirement to attach evidence, or send an alert to a specific distribution list.

  • Weighted scoring per question, rolled up by section and overall
  • Recurring schedules that clone the template and assign it out
  • Assignment to a person or a department, where any member satisfies it
  • Approval routed up the chain of command, or refused if none is configured
  • Overdue action items escalate to the assignee's manager automatically
  • Duration and completion location captured, because paper proves neither

The gate

The verification audit on outbound freight is the piece with real teeth. Every item is scanned and compared against what the order says should be there. Anything that isn't a clean match — a shortage, an overage, an unexpected item, a missing serial — is a failed audit, and a failed audit blocks submission entirely while emailing leadership on every attempt.

The check runs in the browser for immediate feedback and again on the server before anything is recorded, specifically so a stale or modified client can't record a failed audit as passed. Overriding it requires a manager to re-authenticate and type a reason, which is stored with the record and included in every export.

The rotation logic for the housekeeping audit encodes the independence rule directly: never assign an auditor to their own area, never reuse an auditor within a cycle, and prefer whoever has gone longest without auditing that location. Reminders escalate on a ladder as the due date approaches — auditor, then manager, then site leadership, then an overdue notice to all three.

The result

Audit results became reportable. The platform answers which question fails most often across every audit of a given type, how long corrective actions actually take to close, and whose scores are sliding month over month, by person and by department — none of which paper could answer at all.

Saved reports are designed once from a library of widgets, and the same layout drives both the on-screen dashboard and the PDF that goes out on a schedule. The Excel export is deliberately not the layout — it is the flat data behind it, for the people who were going to paste it into their own workbook anyway. Every export is retained and re-downloadable, so a number quoted three months ago can still be traced to the document it came from.

Built with

  • Python
  • Flask
  • SQL Server
  • ReportLab
  • openpyxl
  • Chart.js

On the details we left out

Client, location, system names and volumes are withheld deliberately. We're happy to go deeper on architecture and approach on a call.

Services this draws on

Legacy Modernization & Migrations

Bring decades-old systems into the modern era without a risky rip-and-replace.

See the service →

System Integration

Connect aging systems to modern APIs, data platforms, and SaaS tools.

See the service →

More projects

Safety · Equipment control

Equipment that locks itself out when it fails inspection

Powered industrial trucks were signed out on a clipboard, and the fall-protection harness that some of them require was a separate honour system. We built a badge kiosk where the truck you pick decides the inspection you must pass — and which refuses to release anything that fails.

Read the story →
Controls · Reverse logistics

Financial controls on material leaving the building

End-of-life material left the site on paperwork typed by hand. We rebuilt the chain end to end and added the control nobody had: detection of inventory added after the paperwork was already filed.

Read the story →
Access Control · Internal platform

Adding a permission shouldn't mean altering the user table

Access was a boolean column on the user record, so every new screen was a schema change. We replaced it with roles that map to screens, credential checks that verify a second person without elevating the first, and a suspension path that fails closed.

Read the story →

Got a system like this?

A free assessment gives you a clear picture and a prioritized plan — no commitment.

Book a free assessment