Our own software · built and owned by Mind Links

Every contractor approved,
every certificate still valid.

A stage-gate approval system for companies that work through subcontractors: one queue, mandatory documents at each gate, a signature against every decision, and an alarm before a compliance certificate expires.

Sector
Contracting, facilities management, logistics
Company size
50–500 staff, 20–300 subcontractors
Type
Internal operations system
First release
One month
Languages
Arabic and English, full right-to-left

01 — The problem

The approval nobody owns

A contracting company with 120 subcontractors carries roughly 700 documents that expire. Commercial registration, VAT certificate, GOSI subscription, Saudization certificate, insurance, bank letters. Each on its own date, none of them in the same place.

Approving a new subcontractor takes six people and lives in email. Somebody in procurement collects the file, somebody in HSE checks the safety record, finance checks the bank details, legal checks the contract. There is no queue, so the only way to know where a request is, is to ask.

The expensive failure is not the slow approval. It is the crew that turns up on site on a Sunday morning and cannot work, because a certificate expired eleven days ago and the renewal email went to someone who left.

02 — The system

One queue, five gates, a signature on each

Nothing moves to the next stage until the documents that stage requires are attached and the named approver has signed. The stage a request sits in is the only status there is, so the question “where is it?” has one answer and everybody can see it.

GATE 1Submission CR · VAT · bank letter
GATE 2Commercial Pricing · capacity · references
GATE 3HSE & compliance GOSI · Saudization · insurance
GATE 4Legal & contract Signed agreement · NDA
GATE 5Activation Finance sign-off · supplier code

Gates are configurable per company. A logistics operator replaces HSE with fleet and driver licensing; the mechanism does not change.

The queue

Everybody opens the same list. It is filtered to what is waiting on you, because a queue that shows everything is a queue nobody reads.

Approvals queue filtered to the signed-in role
The approvals queue, filtered to the signed-in role. Documents missing at the current gate are flagged before anyone opens the request.

The request, and who signed what

An approver sees the file read-only, the documents, the position in the flow, and every decision taken before theirs. They approve or reject with a comment. There is no third option, and no way to move it forward without one.

A request at gate three, with documents and decision history
A request at gate 3. The approver sees the file read-only, the documents with their expiry dates, every decision taken before theirs, and two buttons. Approving without a comment is not possible.

The board that prevents the Sunday morning

Every certificate carries its expiry date from the moment it is uploaded. The system counts down and tells the supplier and the owner, on a schedule agreed once, rather than when somebody notices.

Compliance board with expiry countdowns
The expiry board. Every certificate counts down from the day it is uploaded, and the reminder schedule runs whether or not anyone is watching.

What it tells the manager

The queue produces its own measurement. Once every decision carries a timestamp, the question “why does approving a supplier take a month?” stops being a matter of opinion.

Cycle time by gate, with the bottleneck flagged
Median days in gate, over ninety days. The reading underneath is the point of the report: HSE holds requests four times longer than any other gate, two thirds of it waiting for a certificate nobody asks for until gate 3. Move that document to gate 1 and roughly four days come out of every approval.

These are screenshots of a working prototype built by Mind Links for this page. Every supplier, certificate and figure in it is invented. It runs — ask to click through it.

03 — Why this is a Saudi system, not a translated one

The documents are the whole problem

A generic vendor-management product handles a supplier record and an attachment. It has no opinion about which attachments matter, when they expire, or what happens when one does. In this market that is the entire job.

DocumentWhy it gates the approvalRenewal behaviour
Commercial registrationConfirms the supplier legally exists and may trade in this activityAnnual. Blocks activation while lapsed
VAT certificateNeeded before an invoice can be accepted. A wrong-year certificate is the single most common returnChecked against the ZATCA registration number on submission
GOSI subscriptionEvidence that the workers on your site are actually registered employeesMonthly currency check; expiry blocks new work orders
Saudization certificateNitaqat band. A supplier that slips to Red cannot renew work permits, which becomes your delivery problem Band recorded, not only the certificate. A change of band raises an alert
InsurancePublic liability and workers’ cover. The document your own client will ask you forExpiry suspends the supplier and holds open work orders
Bank letterPayment details verified once, in writing, against the CR nameAny change re-enters the approval flow. This is where invoice fraud enters

Arabic first, not Arabic later

The people who upload documents and answer the reminders are often not the people who read English. The interface, the notifications and the exported audit report are all bilingual, and the Arabic is built right-to-left rather than mirrored at the end.

Built for the working week

Sunday to Thursday. Reminder and escalation schedules understand the Saudi week, Ramadan hours and the Eid holidays, because a seven-day warning that lands on a Thursday evening is not a warning.

PDPL by construction

Supplier files hold personal data: identity documents, names, salaries in a GOSI extract. Data location, retention and who can open an attachment are set before the first upload. PDPL is enforced, with penalties reaching SAR 5,000,000 per violation, and the liability sits with the company holding the file.

An audit export that ends the conversation

One PDF per supplier: every document, every version, every approval with a name, a timestamp and a comment. Produced in a click when a client, an insurer or an auditor asks how this contractor came to be on site.

04 — Underneath

What makes it hold up

Configurable gates, not hard-coded ones

Stages, required documents and approver roles are data. A new gate is a configuration change made by the client, not a release by us.

Role routing with real delegation

Approvals route to a role, not a person, so annual leave does not stop the queue. Delegation is explicit and recorded.

An append-only decision log

Nothing in the history can be edited or removed, including by an administrator. That property is what makes the export worth anything.

Documents versioned, never replaced

Uploading a renewal keeps the old file. “What was valid on the day we let them on site?” stays answerable.

Notifications people actually receive

Email and WhatsApp, in the recipient’s language, with escalation when a gate goes past its agreed time.

It connects to what you run

An approved supplier becomes a vendor record in the ERP, with the supplier code written back. No re-keying, which is where the errors come from.

Built with, and where it runs

The highlighted region is live in the Kingdom today. Hosting is settled before the software is, because PDPL and your own client contracts settle it — not us.

05 — What we would build first

One month, one gate, real suppliers

Not the whole system. The narrowest slice that changes somebody’s Sunday.

In the first month

  • The document register for your existing suppliers, loaded from whatever you have now
  • Expiry dates captured, with the 90 / 30 / 7 day reminder schedule running
  • The expiring-soon board, live, on a phone
  • Bilingual notification templates you approve before we send anything

Fixed price, agreed before the work starts. Source code in your repository from the first commit.

Deliberately not yet

  • The full five-gate approval flow
  • ERP write-back
  • The supplier-facing upload portal
  • Reporting beyond the one board

Those follow once the register is real and populated. A workflow over data nobody trusts is a workflow nobody uses.

The reminder schedule alone usually pays for the engagement, and it is the part that takes one month rather than two quarters.

Whose software this is

Built by Mind Links to show how we approach a problem we have seen in several Saudi companies. It is real, running software that we own. It is not a delivered client project, and there is no client behind it.

The screenshots are of a working prototype we wrote for this page. It is real software and we will open it in a meeting, but it is a demonstration rather than a product: no persistence, no authentication, and every supplier, certificate and number in it is invented. Any resemblance to a real supplier is accidental.

We label concepts as concepts. When we have delivered client work and hold written permission to describe it, that will be a different page and it will say so plainly at the top.