03 Scope
The tools businesses ask us for
Six shapes cover most of it, and every one of them exists as a spreadsheet somewhere before it exists as software.
- Registers. Asset, document, complaint, visitor, gate-pass and compliance registers, where the value is a searchable history rather than a current list.
- Trackers. Project, order, dispatch, service-call and recruitment trackers, where the value is knowing what is stuck and with whom.
- Approval tools. Requests, checks and sign-offs with a real routing rule, which is where a spreadsheet and a WhatsApp group are currently doing the work between them.
- Dashboards. Numbers pulled from the source rather than rebuilt every Monday morning from a copy of a copy.
- Field applications. Installed from a browser, working with a poor connection and syncing when it recovers, for staff who are not at a desk.
- Customer or vendor portals. A place for a counterparty to see their own orders, statements or tickets, which removes a surprising amount of inbound email.
04 Design
The two things a spreadsheet can never have
Permissions and a trail. They are also the two things nobody asks for until the week they are needed, which is why we design them before the features.
| Concern | In a spreadsheet | In the software |
|---|---|---|
| Who can see what | Everyone with the link sees everything | Per role, and scoped to a branch or team |
| Who changed a figure | Unknowable | Recorded with the actor and the timestamp |
| Bad data | Accepted silently, discovered later | Rejected at entry, with a reason |
| Approvals | A colour, and a WhatsApp message | A routing rule with escalation and a record |
| Two people at once | A conflicted copy | Both writes land, in order |
| Backup | Whatever the drive does | Scheduled, and tested by restoring |
- Where the tool touches the books it inherits the logging control an external audit already tests: an unalterable, timestamped record of each entry and each later change, which is control A.8.15 of ISO/IEC 27001, retained for as long as the record-keeping rules in your own jurisdiction require.
- Where it holds employee or customer personal data, the General Data Protection Regulation applies wherever those people are in the EU or the UK, and an equivalent regime applies elsewhere. Retention and a deletion path are designed into the schema.
05 Adoption
How we make sure it gets used
An internal tool has one failure mode that matters: the team goes back to the spreadsheet. Everything here exists to prevent that specific outcome.
Step 1: Time the current task
Minutes per record, as it is done today. That number becomes the design constraint: if the software is slower, it will not be used, whatever else it offers.
Week 1Step 2: Read the sheet as the specification
Columns are fields, formulas are rules, coloured cells are statuses nobody wrote down. The most accurate requirements document in the business is already written.
Week 1Step 3: Design the roles
Who sees, edits and approves, and whether a person is scoped to their own branch. Permissions retrofit badly, so they come before features.
Week 2Step 4: Real users in week three
Not a demonstration to a sponsor. The actual team, doing actual work on a staging URL, which surfaces more in an hour than another month of design would.
Week 3Step 5: Migrate and run both briefly
Data migrated after cleansing, with the spreadsheet kept read-only for a short parallel period so nobody feels stranded.
Weeks 6 to 10
Our dispatch sheet had eleven tabs and one person who understood it. Now four people use the tool and the sheet is read-only history, which was the whole point.
06 The people
Who do you actually work with?
Four founders, named. Business software is used by people who did not ask for it, so adoption is owned from the first week rather than the last.
We build for the people who will use it daily, and one of them sits in every review. That is why the screens survive contact with the team.
-
Dhanush Prabha
Co-Founder, CTO and CMO
Designs the data model, builds the screens, connects them to what you already run, and writes the support plan.
-
Sriram Ravichandran
Founder and CEO
Studies how the team works today, agrees one source of truth, and owns the rollout and the training.
-
-
07 Cross-border
How do we work with clients in another country?
None of this needs you to be in any particular country. The work is remote either way, so these are the answers a buyer asks for before signing, and they are the same on every engagement we run.
Working hours
Our day runs on UTC+5:30. The overlap window with your team is written into the scope rather than assumed, and everything outside it runs asynchronously.
How we communicate
One written update a day on the channel you already use, a standing weekly call inside the overlap window, and a named person to escalate to. Nothing important is agreed only on a call.
Who you contract with
Synerdyn Private Limited, the company behind IncorpX, named in the agreement with its registration number. The governing law and the forum are agreed before you sign, not after a dispute.
Currency and payment
Invoiced in your currency or in ours, your choice, and settled by bank transfer. Milestones are tied to deliverables you can see, never to elapsed time.
What you own
Copyright in everything built for you is assigned on final payment: source code, design files, prompts, configuration and documentation. Third-party licences are listed by name so nothing is a surprise later.
Where data sits
You choose the region your data is stored and processed in, and the answer is written down before the build starts, with who at IncorpX can reach it and for how long.
Offset from our working day standard time
- London-5:30
- Dubai-1:30
- Singapore+2:30
- Sydney+4:30
- New York-10:30
- San Francisco-13:30
IncorpX is a brand of Synerdyn Private Limited. The contracting entity, the governing law and the invoicing currency are all named in the proposal before you sign anything.
08 Reference
Terms used on this page
- Spreadsheet risk
- The exposure created when a business-critical process runs in a shared spreadsheet: no audit trail, no permissions, no validation.
- Role-based access control
- Written RBAC: deciding who may see, edit and approve which records, including scoping a view to a branch or team.
- Single source of truth
- One system treated as authoritative for a class of data, so a disagreement between reports has one place to be resolved.
- Progressive web application
- Written PWA: an application installed from the browser that works with a poor connection and syncs when it recovers.
- Low-code platform
- A configurable application platform such as Zoho Creator, genuinely cheaper than custom code for forms, registers and approvals.
- Field validation
- Rejecting bad data at entry with a reason, instead of accepting it silently and discovering it in a report months later.
- GDPR
- The EU and UK data protection regime. Article 83 sets administrative fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher, which is why consent, retention and access control are build decisions here rather than paperwork.
09 Questions
Business software FAQs
Next step
Send us the spreadsheet, formulas and all.
We will come back with what it would take to turn it into software with proper roles and an audit trail, and an honest view on whether a low-code platform would do it for less.
Read by Dhanush Prabha, our CTO, not a form queue. Reply usually within one working day, in your time zone.

