Chart of accounts
Balances reflect posted journal entries only. Every value traces to a source record and an audit event.
Folder / CSV ingestion
Simulates the watched drop-zone: paste or load a bank CSV, pick its import profile and the cash account it maps to. Re-importing an overlapping file is safe — duplicates are detected by fingerprint.
Imported bank transactions
Categorize and post to the ledger. Posting creates a balanced double-entry journal (cash vs. the chosen category).
New invoice
Issuing posts Accounts Receivable ↔ Revenue. Marking paid posts your cash account (Relay) ↔ Accounts Receivable — optionally matched to an imported deposit.
Invoices
Book a payroll run
Enter the totals from your payroll provider's report (Gusto, ADP, …). Posting books wages + employer taxes against your cash account. Order76 does not calculate, file, or remit payroll taxes — your provider does.
Payroll runs
New settlement from a gross receipt
Enter a vendor's gross receipt for a period. The vendor's active rule withholds tax from the gross, then splits the net into the vendor's share and EBM's commission. The settlement lands in the review queue below — nothing becomes an invoice until you approve it.
Settlement accounts
Royalty money moves through these. Set them on the Accounts tab.
Review queue
Settlements awaiting review. Approve to issue a royalty invoice for the vendor's share; reject to discard. Every action is written to the audit trail.
Add / update a vendor rule
Per-vendor tax withholding and the net vendor/EBM split. Percentages are stored to the basis point; money never rounds twice. Editing a rule from the list below fills this form.
Vendor rules
Royalty invoices
Issued on approval. Amount due is the vendor's share; EBM commission is retained.
All settlements
Classification
Turning raw bank rows into books is three different jobs, so it is three separate steps. Transfers between your own accounts are matched arithmetically. Payees you have written a rule for are treated as data. Everything else is a question for you and will not post until you answer it.
Run the pipeline
Every step previews before it writes. Look at the preview, then commit — or do not.
Waiting on you
Rows no rule could speak for. Pick the account each belongs to. Nothing here posts until it is decided — a wrong guess becomes a wrong figure on a signed return, so uncertainty is surfaced rather than resolved.
Rules
A payee’s treatment lives here as data you can read and change, not buried in code. Patterns are case-insensitive regular expressions; lower priority numbers win. Mark a rule external when it names a counterparty outside the business, so transfer matching leaves it alone.
Past due
Every return this entity owes for the year, its statutory due date, and — for federal returns — an estimate of what being late is costing. Oklahoma sets its own penalties; those returns show the tax but are left unpriced rather than given a federal rate that does not apply to them.
Payroll reconstruction
Where wages were paid without withholding, there are no payroll runs — and a 941, a 940 and a W-2 all read from posted runs. This prices the year from the wages already in the ledger and checks the result against the back-tax accrual in the books. A year that does not tie is never stored.
Targets
What each account should hold each month, in the order it gets funded. The order is decided in advance precisely so that a thin month does not decide it — payroll and tax before a software renewal.
Add or update a target
A target is keyed by account and label, so saving the same pair again updates it rather than adding a second one. The sweep account takes whatever is left after every other target is funded.
What to move today
Enter the cash actually on hand. The plan walks the priorities and funds each target in full before starting the next, so a short month says plainly what it could not reach instead of spreading the shortfall silently across every account.
Filing packet
The numbered lines of the actual returns, assembled from the posted payroll and the ledger. Meant to be read with a blank form open beside it. Nothing here is transmitted — this is what a person transcribes and signs.
Bank accounts
The accounts the business actually holds. Each carries an 8-digit internal reference — quote that anywhere an account needs naming, in a journal, a remittance note or an email, instead of a real account number. The last digit is a check digit, so a transposed pair is rejected rather than silently naming a different account. Numbers are stored encrypted and shown as their last four; revealing one in full is recorded in the audit trail.
What settles where
Which account each part of the business settles through. Screens elsewhere read these, so changing one here changes what the rest of the system says — no account number is written into code.
Match deposits to invoices
Unposted incoming deposits (imported from Relay) on the left; pick the invoice each one pays and post it. Matching amounts are pre-selected. Posting records Cash ↔ Accounts Receivable and marks the deposit as booked.
Ledger invariant demo
The engine refuses to post an unbalanced entry. Try it: debit and credit are independently editable.
Journal entries
Trial balance
Profit & loss
Balance sheet
Quarterly net income
Estimated tax
Category rollup (tax lines)
Tamper-evident audit trail
Every sensitive action is an append-only, hash-chained event. Verify recomputes the chain from genesis.
Reset your own access
If you got in through the break-glass USB after losing your phone, reset your second factor here, then re-enroll a fresh authenticator or security key from the header buttons.
Add user
Creates a login with a one-time temporary password. The person sets up an authenticator on first login, then changes the password.
Users & access
Reset passwords or second factors, lock/unlock, change roles, revoke live sessions, or remove accounts. Every action is written to the audit trail.
Front door
The obscured public entry (enable with ORDER76_FRONT_DOOR=1). Set the passphrase people must supply, review access requests, and unblock IPs that were denied.
Recent access requests
Blocked IPs
Approval devices
The custom sideloaded phone app that approves or denies front-door requests. Pair a device to get a one-time token — type or scan it into the app. A device can only approve/deny; it is not a login. Revoke instantly stops a lost phone.
Shown once. Copy it into the app now — it is never displayed again. If you lose it, revoke this device and pair a fresh one.