The Kitchen Delivery Co.

ePOD Office

No office accounts exist yet. Create the first one -- it's an Owner account, which can manage everyone else's.

The BOOTSTRAP_TOKEN secret set on the server (fly secrets set BOOTSTRAP_TOKEN=...).

Enter the 6-digit code from your authenticator app.

Lost your phone? Type one of your recovery codes instead.

Set up two-factor login

Owner accounts can see and change everything, so they sign in with a code from a phone app as well as the password. It takes a minute, once.

The Kitchen Delivery Co.

ePOD Office

Connecting…
▾

Operations

Records

Admin

Online

Today at a glance

Routes

Anything needing attention first, then by delivery date

Activity

All routes

0 selected

POD search

Issues

0 selected

Operational report

Every route currently loaded · click a column heading to sort
to

Addresses

Address corrections

Owner-only. When the export's delivery address is wrong or blank for a customer, put the right one here (by customer reference) -- both apps and the printed POD use it, flagged as corrected.

Customer refDelivery address to use

Settings

People, company details, the rules drivers work to, and how the app is run. Your own login and notifications are under your name at the top.

Company

Deliveries

Admin

Driver profiles

Who can log in to the driver app, and with what PIN.

Vehicle profiles

Offered in the assign-driver dialog and the driver's pick-up screen.

Only an Owner can change these settings. You can view them here, but ask an Owner to make changes.

Company / depot details

Printed on every POD as the letterhead, and used for the accent colour in both apps.

Company logo
Used across the manager portal, driver app and printed POD.

Localisation

How dates, times and units are shown in this portal and on printed PODs, and what things are called.

Only an Owner can change these settings. You can view them here, but ask an Owner to make changes.

Workflow rules

How routes move through loading, departure and delivery. These used to be fixed in the code; both apps and the server read them live, so a change applies to the next action a driver takes.

Optional: a loader can load on the loading device and hand over, or the driver loads their own van. Required: drivers can only pick up routes a loader has marked Loading complete. Loaders are people with the Loader role (Drivers & vehicles); every tick records who loaded it.

Lower is more "live"; 4 is a good balance. 2 to 60.

Only an Owner can change these settings. You can view them here, but ask an Owner to make changes.

POD requirements

What the driver must capture at sign-off, on every drop. The driver app shows only the fields turned on here; the server refuses a POD that doesn't meet them. Safe ranges are enforced, so none of these can break the app.

Applies to every photo drivers take from their next photo on. Higher quality uses more mobile data and server space.

POD PDF file names

How each signed POD's PDF is named -- when it's downloaded here and when the POD filing program saves it on the office drive. Put these words in curly brackets where you want them: {date} delivery date, {route}, {drop} drop number, {orders} order numbers, {customer} customer name, {ref} customer reference. Must include {drop} or {orders} so each POD gets its own name.

Example: POD_2026-09-25_Route-4_Drop1_90691195.pdf. Letters, numbers, spaces, _ - . only; spaces become -. PODs already filed keep their old names.

Per-customer overrides

Keyed by the customer reference on the export (the "account code" printed on the POD). A trade counter can need no photos while a site delivery needs three; a POD email on file pre-fills the driver's form.

Customer refMin photosPOD emailNote for the driverNo texts

Address corrections are on the Addresses page now.

Only an Owner can change these settings. You can view them here, but ask an Owner to make changes.

Issue types

Offered in the driver app's "Report issue" dropdown. "Customer refused" and "Grouping mismatch" are built into the app's own workflow and can't be renamed or retired.

Issue handling

How long an open issue can sit before it's flagged, whether loading issues hold a vehicle back, who may close them, and the quick reasons offered when closing one.

Customer texts (SMS)

Owner-only. Texts customers "on the way" messages on the contact mobile from the export (UK mobiles only; landlines are skipped). Each text is charged by your text provider, roughly 4-5p. Start in test mode to see what would be sent without paying for anything.

Off

What customers see it's from: up to 11 letters/numbers. Customers can't reply to a name.

to

Texts due earlier wait until the start; after the end they're skipped.

A safety cap on cost.

Words you can use in a text

Uses the saved settings, so save first. Goes straight away (ignores sending hours).

Recent texts

Email recipients

Owner-only. Who should be emailed for which events. Email sending is not configured on this server yet -- these are saved so they're ready the moment a mail service is connected; nothing is sent today.

Browser pop-ups on each office computer are chosen by each person under their name at the top -- My settings.

Recipients for each event

API tokens (read-only)

Owner-only. Lets another system read routes (with their photo lists), signed POD PDFs, returns, drivers, vehicles, issue types, settings and health with Authorization: Bearer <token>. Filing PODs on the office drive: create a token labelled "POD filing" and give it to the POD filing program on the office PC (scripts/pod-filer.mjs -- see DEPLOY.md); "Last used" below shows it checking in. It can't read the address book, activity, logins or the security log, and can never change anything. The token is shown once when created and expires after 12 months unless you choose another date. Backup token: a separate kind, only for the backup program on the office server (scripts/backup-puller.mjs) -- it can fetch the backup (the whole database and photos, encrypted) and nothing else.

Webhooks

Owner-only. POSTs each event as JSON to your own system the moment it happens (signed with the secret, if set, as X-Epod-Signature: sha256=<HMAC>). Timeout 8s; every delivery is logged below.

Recent deliveries

Access rules

Owner-only. Session length applies to office and driver logins alike, counted from when they logged in -- after that they enter their password/PIN again, even if the app stayed open. A deploy or restart doesn't log anyone out.

to digits

At least 6. Applies to new PINs -- a shorter PIN set earlier keeps working and is flagged under Drivers & vehicles.

Anyone newly included sets it up at their next login -- they're asked to log in again straight away. Drivers use PINs and aren't affected.

Office accounts

Owner manages accounts, settings and data. Staff does everything operational. Planner schedules and assigns but can't resolve issues, authorise exceptions or unlock routes. Viewer is read-only.

Security log

Owner-only. Logins and failed logins, lockouts, account, PIN, settings, token, webhook and text-setting changes, exports and resets -- with who did it and from which address. Kept for the most recent 5,000 events unless changed in Data & backups -> Keeping data; never sent to webhooks.

TimeEventWhoDetails

Hansa link

Owner-only. Routes pulled straight from Hansa through S6K's ColdFusion data page wait in From Hansa (here, or on the Routes page) until an Owner imports them. Nothing goes on the schedule by itself.

Automatic pulls

Only refreshes the From Hansa list. Pull now is always there too.

3 = today and the next 2 days.

Lines shown but never ticked

Delivery charges, notes, adjustments and services -- shown to the driver as reference lines. Separate with commas. Lines with no item code are always headings.

Routes and exports

Import a day's route from its 3 Hansa export CSVs (no redeploy needed), or download every POD with its photos. Routes pulled straight from Hansa are on the Hansa link tab.

Export PODs + photos (.zip)

Clearing up the schedule

Owner-only. Hide the built-in demo routes, and put back routes removed by mistake. A route can be removed from its own page if nobody has started it; one with any loading, photos, issues or PODs is archived instead.

Loading...

Import rules

Owner-only. Column aliases let an export whose headers differ from this app's expected names import without a code change -- one line per canonical column: customer_name: Customer Name, Cust Name. (Auto-archiving moved to Keeping data, below.)

Keeping data

Owner-only. When finished routes are archived, how long things are kept before they're cleared automatically, and when a stopped backup raises the alarm. Signed PODs are never cleared by these.

Finished routes

Archived routes leave the dashboard and route list; they're still in POD search and Reports.

Keeps the working list quick. Stored routes still show with "Show archived" and in POD search.

Clearing up

Shows in the red "needs attention" banner and the uptime monitor.

Logs

Every login, lockout and settings change. More is better for looking back after a problem.

Settings file

Owner-only. Save every setting on this page as one file -- company details and logo, issue types, POD and workflow rules, customer and address overrides, text and email settings -- and load it back here or on another copy of the app (the staging app, a new install). It doesn't contain logins, PINs, vehicles, tokens, webhooks or the text provider's password.

Download settings

Reset demo

Clears the day's route work -- imported routes, ticks, issues, photos, assignments and PODs -- after archiving every completed POD and its photos. Everything else is kept: all settings, office accounts, drivers and PINs, vehicles, tokens, webhooks and the address book.

Who's logged in

Live = app open and active in the last 90 seconds. Idle = still logged in, but the app isn't open right now (phone locked, tab closed). Updates automatically while this tab is open.

Office
Drivers & loaders

Two-factor login

A code from an authenticator app on your phone (Microsoft or Google Authenticator), as well as your password, each time you log in -- so a password alone isn't enough. Required for Owners, and for other roles if an Owner has chosen that (Access & security); anyone else can turn it on. Lost your phone? Use a recovery code, or ask an Owner to reset it.

Loading…

Notifications on this computer

Pops a desktop notification while this portal is open in a tab. Per browser, not per account -- each office computer chooses its own. Saved as you tick.

About this app

Which build is running, and basic server health -- useful when reporting a problem or checking a device has picked up an update.

Version-
Server up since-
Server time-
Last data save-
Off-site backup (storage bucket)-
Backup on the office server-
Routes stored in the archive-Archived routes move out of the working list after the days set in Data & backups -> Keeping data (a week unless changed); tick Show archived to see them.
Free disk space-
What's using the space-
Signed in as-

Set delivery date

Assign driver

No driver can pick this route up in the driver app until it's assigned here. Add a 2nd driver only if they're riding along -- the vehicle is optional and the driver can still change it at pick-up. Clear the assignment to open it back up for requests rather than to any driver.

Who's expected to load this route is a record for planning/reports -- it doesn't restrict who can actually load it in the driver app (see Settings -> Workflow -> Separate loading for that).

Resolve issue

Recorded as .

Authorise exception

Authorised as .

Notes for driver

Shown to the driver as soon as it's saved -- before the route is picked up, or mid-route. Saved as .

Proof of delivery

Drawn signature on record. Email sending is not configured in this test build.

Drop

Photo evidence

Add driver

This is what the driver types to log in on their phone. Leave blank to keep the current PIN.

Add vehicle

Add office account

Leave blank to keep the current password.

Routes from Hansa

Loading...

Pulled routes wait here until you import them. Importing uses the same checks as a CSV import; you then set the route's date and driver on the Routes page as usual.

Recent pulls

Import route

The 3 Hansa export CSVs for one route (same shape as the ones baked in at startup -- see 04_Official_Test_Build/tools). This adds a new route; it doesn't touch any route already loaded.

Add webhook

Add issue type