Distrib — the twelve domains
What the Distrib facet does, domain by domain.
In brief
The twelve domains that follow cover a sale's whole life: what is sold, at what price, to whom, how it is paid, and what is declared from it.
Three ideas run through them. One piece of software for every machine: what differs between a fridge and a bar is configuration, never code. The machine decides on the spot, even offline, and the cloud validates afterwards. And hardware is declared: plugging in a real lock instead of a simulator is a configuration change.
One practical consequence: sales are facts that are never erased. You cancel, you refund, but you never rewrite.
What it brings : You run machines of different kinds with a single team and a single tool.
In detail
Three ideas run through the twelve domains that follow.
- One piece of software for every machine: what distinguishes a fridge from a bar is configuration, never code.
- The machine authorises, the cloud settles: no charge without a recorded fact, and offline, only latency changes.
- Hardware is declared: plugging in a real lock instead of a simulator is a configuration change.
1. Points of sale, sites, organisations
A point of sale is a business identity — not a machine. That distinction carries everything else.
- Replacing the machine loses nothing: neither sales, nor configuration, nor history.
- The type is immutable: changing it means withdrawing then re-declaring.
- Two lifecycles: the business status, and the core one.
- The site carries the time zone, which governs the days in reports.
- Cascading configuration: the type's defaults, then the point of sale's override.
- The "changed, not published" gap is visible everywhere.
- A point of sale serves several organisations, with a priority order.
- A sale with no point of sale is attached by hand, never guessed.
- Hybrid fleet: a machine of another brand enters through a connector.
2. Catalogue
The product describes what it is; the effective price lives in the offer.
- One catalogue per account, shared by every type of machine.
- Selling by measure: by item, by kilo or by litre.
- VAT in classes, never in rates: an old sale keeps its rate.
- Rates are never changed in place.
- Expiry dates: alerts, unsellability, and automatic markdown as the date nears.
- First-class allergens, with personal exclusion on the consumer's side.
- Tags: the single mechanism for targeting a discount or composing a deal.
- Several merchants in one machine, each with their payout.
- You archive, you never delete.
- Spreadsheet import with a line-by-line error report.
3. Offers and publication
The offer says what this machine sells, at what price, laid out how.
- Two layouts: a shelf plan, or a menu.
- Dated offers, editable: immutability lives in the publication.
- The assortment in place is what the driver actually loaded.
- Publishing is an explicit act: nothing is distributed implicitly.
- A signed snapshot that the machine verifies before applying it.
- An inconsistent snapshot is refused: the machine keeps the previous one.
- Automatic delivery when a device is bound to an already published point of sale.
- Revocation: with the binding closed, the machine refuses to sell.
- Visual editor by drag and drop, with a comparison before publishing.
4. Selling and pricing
The price is computed twice — on the machine and in the cloud — and both must agree to the cent.
- The same library on both sides: an identical result.
- A standard order: product discounts, deals, basket discount, then subsidy.
- Exact allocation: the sum of the parts equals the amount, with no privileged line.
- A discount never takes the total below zero.
- Each receipt recomputes identically: it cites its offer and its publication.
- A doubtful sale goes under review instead of being charged.
- A closed list of reasons: low trust, quota, price discrepancy, quality sample.
- The verdict is logged with the person who made it.
- Offline, the sale is never blocked: the price shown is what stands for the customer.
- Sentinel: a forced door becomes a valued loss, never a charge.
5. Promotions and benefits
Four objects, not to be confused.
- The discount is an automatic rule.
- The deal is a bundled price.
- The subsidy is a third-party payer: it reduces the amount due, not the VAT.
- The promotional code is triggered manually.
- A credit voucher is not a promotion: it is a means of payment.
- Targeted discounts by tag, time slot, or approaching expiry date.
- The quota is never exceeded, even when several machines sell at once.
- Employer subsidy by time slot, flat or as a percentage.
- An offline over-subsidy is never charged back to the consumer.
- Basket simulator to check a rule before publishing it.
6. Payment
This whole domain is Octopoda Pay. Here is what Distrib sees of it.
- An isolated module: the rest of the product never reads its data.
- A single concept for anything holding value: wallet, voucher, credit note, subsidy, debt.
- Append-only entries, and an atomic debit with no overdraft.
- Settlement in several parts, in priority order.
- A replay resumes, it never charges twice.
- Debt is recovered at the next top-up, automatically.
- An anonymous sale creates no debt.
- A simulated provider plays the same contract as the real one, for demonstrations.
7. Consumers
The end customer has an account, means of recognition, and a space of their own.
- Badge, personal code or bank card as an identifier.
- You revoke, you do not delete.
- Unknown badge: the machine shows a four-digit code to enter in their account.
- A refusal says why: insufficient funds, unpaid, badge required, disabled account.
- Rate or report a problem from the receipt, with a manager's explained decision.
- Consumer space: wallet, purchases, receipts, badges, automatic top-up.
- Order and collect by time slot, possibly by a third party.
- Opening by visual code, with no application to install.
- Anonymisation: identifiers stay for accounting, personal data goes.
- Refused if a balance or a debt remains.
8. Field work
What the driver does in front of the machine, and what it produces on the management side.
- A badge opens a session: restocking, removal and stocktaking follow without badging again.
- Entry is never blocking: without it, everything derives from detection.
- Batches and expiry tracked per location, consumed closest-to-expiry first.
- Append-only stock movements, each with its reason.
- Photographs at opening and at closing.
- Ranked detection hypotheses, with an arbitration screen.
- Valued losses, explained removals.
- Replenishment orders generated from stock and expiry alerts.
9. Reports and accounting
The figures you invoice to your customers, and those you declare.
- Exact to the cent: sales, VAT, receipts, subsidies per organisation.
- Read "as at" a chosen day, exact by construction.
- Days in the site's time zone, currencies never added together.
- Revenue is what was settled: partials, failures and debts are tracked separately.
- A settled or cancelled sale is no longer modified.
- Accounting chain: frozen VAT report, gapless numbering, signed audit export.
- Ten-year retention.
- Outbound notifications to your system, signed and retried on failure.
10. Recipe machines
Drinks bar and coffee machine: the machine makes the product, so you bill what actually flowed.
- A recipe is a product; strength and size are settings.
- The price comes from a grid crossing category and size.
- Consumables with two thresholds: alert, then unavailable.
- Availability is decided on the machine: a drink greys out as soon as its flavouring runs out.
- The pour is measured: volume served, stopping at the target or on command.
- Billed pro rata to the volume actually served.
- Episode alerts: leak, no flow, gas or pouch empty.
- Usage and sustainability: volumes, bottles avoided, carbon equivalent.
- Scheduled maintenance, with its append-only record and its due date.
11. The machine
One selling program for every type, and hardware described rather than coded.
- Behaviour comes from configuration: no code per machine type.
- A shared kit brings the bus, local authorisation and reporting to the cloud.
- Typed things: lock, door, reader, shelf, probe, terminal, coin mechanism.
- Commands triggered by step: lighting on authorisation, photograph on opening.
- The screen is a stateless view: it displays and returns intentions.
- Without business configuration, the machine refuses to sell — it does not guess.
- One simulator per family, publishing the same list as real hardware.
- An interrupted session becomes a fact in error, never lost data.
12. Integration with the information system
What connects the platform to your own tools.
- Service key and user token, with a role per scope.
- Mandatory idempotency key on every call that moves money.
- Each module publishes its addresses and declares what it needs.
- A missing link cleanly disables the function, and logs it.
- Sortable, paginated, filterable lists; amounts in cents with their currency.
- Incoming and outgoing notifications, and interface keys for your partners.