For multi-entity and chapter organizations
Chapters that share a system without sharing a ledger
A national body and its chapters need separate donor data, separate funds and separate reconciliation, with roll-up reporting that does not leak either way. The tenancy model supports this. The workflow depth does not yet.
- TodayChapters run their own tools, national receives spreadsheets, and consolidated reporting is a quarterly project.
- The riskOne shared login means a chapter can see another chapter's donors — the failure mode that ends the conversation.
- The askScoped access, per-entity funds and reconciliation, and consolidated reporting nobody has to assemble.
Bank side
Deposit
Jul 28 · Operating account
Statement ref
Imported from bank feed
Processor side
Payout PO-2261
21 gifts · gross $4,921.00
Fees
Card and ACH blended
1 exception · $51.46 unexplained
Suggested cause: refund RFD-119 settled in a later payout. Proposal awaits approval — nothing posts until a human accepts it.
What changes
The specific difference, not a benefit list
Each card names the operational change, not an outcome we cannot prove for you.
- What changes
Tenant scope on every operation
Tenant and active scope are mandatory in reads, writes, cache keys, jobs and exports, enforced by database row-level security.
- What changes
Entity-level funds and reconciliation
Each entity holds its own funds, deposits and close batches, rather than sharing one pooled ledger.
- What changes
Roll-up without leakage
Consolidated views aggregate figures without exposing donor records across entities.
The same week, twice
How a multi-entity & chapters week runs before and after
Left is the week as this seat describes it today. Right is the same week once the record carries the terms. Nothing on the right is claimed as available — the status badge above governs that.
Today
- TodayChapters run their own tools, national receives spreadsheets, and consolidated reporting is a quarterly project.
- The riskOne shared login means a chapter can see another chapter's donors — the failure mode that ends the conversation.
- The askScoped access, per-entity funds and reconciliation, and consolidated reporting nobody has to assemble.
Prepared
- 1Tenant scope on every operationTenant and active scope are mandatory in reads, writes, cache keys, jobs and exports, enforced by database row-level security.
- 2Entity-level funds and reconciliationEach entity holds its own funds, deposits and close batches, rather than sharing one pooled ledger.
- 3Roll-up without leakageConsolidated views aggregate figures without exposing donor records across entities.
Described state, governed by the status label on this page.
Where you work
The surfaces you would live in
Workspace administration
Entities, membership, roles and scope.
Scoped switching
An explicit active scope that every query respects.
Not ready yet
What we cannot do for you today
- This is Release 2. The tenancy foundation is in active build; multi-entity workflow depth is designed, not implemented.
- Consolidated reporting and cross-entity permission templates are not built.
Metrics this seat owns
- Scope-leak incidents (target: zero)
- Consolidated close time
- Entity onboarding time
One sentence
Chapters that share a system without sharing a ledger
A national body and its chapters need separate donor data, separate funds and separate reconciliation, with roll-up reporting that does not leak either way. The tenancy model supports this. The workflow depth does not yet.
Chapters run their own tools, national receives spreadsheets, and consolidated reporting is a quarterly project.
Other seats
Same lifecycle, different vantage point
Design-partner program
Tell us what multi-entity & chapters needs first
We are working with a small number of US and Canadian nonprofits who feel the reconciliation and donor-data pain most acutely. Partners shape the sequence, see the honest status of every module, and are never charged for a capability that is still a prototype.