# Keel — the firm app (v1, from Product UI v3)

## Problem
CS/CA practices keep clients' statutory registers in Excel and Word, minutes in files, due dates in heads. When an inspector, investor or court asks, the record is rebuilt after the fact and cannot be shown to be what it was.

## Target user
A practising CS or CA firm in India (5–300 private limited clients). Partner attests and signs; manager runs migrations; trainee records events. Outside the firm: the client's founder (approves and signs from a phone), an investor (cap table), the statutory auditor (read-only evidence).

## Core job-to-be-done
Record what happened to a company once, as an event; get every register, minute, certificate and due date from it; prove later that nothing was changed.

## What makes it distinctive
Registers are read-only views of a hash-chained event log that is attested by the partner, verified nightly, anchored publicly every month, and printable as a court-usable extract.

## MVP features
- Must-have: sign-in with authenticator (TOTP) + password reset; first-run explainer; console (worst first) with empty state; companies list; company file with tabs Overview · Registers · Meetings · Events · Calendar · Documents · Seats · Trail · Packs; record events (allotment, transfer, appointment, resignation, charge, loan/investment, related-party contract, filing/SRN, correction) with live "will write" preview, validation and conflict states; registers as views (MGT-1, directors & KMP, charges, allotments, transfers, MBP-2, MBP-4) with statutory print; board meeting in 8 SS-1 steps (notice, agenda, attendance, minutes, resolutions, circulation, sign, enter in chain) and circular resolutions with founder e-consent; calendar from the rules engine (due / overdue / filed / SRN missing / not applicable / blocked) with exposure, SRN drawer, month and one-company views; trail with entry drawer and in-browser verify; monthly anchors; migration (upload Excel/CSV → map → key paper pages → reconcile → attest); day-one open; sandbox company with three tasks; packs (diligence pack, monthly report, s.63 certificate of extract) and public verifier; seats (founder phone: My book · Approve · Sign · Numbers; investor; auditor with DPDP consent; revocation); documents on letterheads (4 designs), document composer with document classes, signing (scanned signature, typed name for non-statutory), standing authority granted only from the founder seat; rules & glossary; settings (profile, letterhead, DSC registry, users & invitations, notifications); help panel, five-word tooltips, ⌘K palette; assist layer (explain this date, why does it ask this, explain this mismatch, ask the book, draft the minutes, keying help, monthly narrative) with the two refusals; Keel admin (firms, chain health, anchors, rules desk draft).
- Later: real DSC / Aadhaar eSign (v1 records a scanned signed page or a typed name where the law allows and says so); MCA V3 API pull (v1 keys MCA master data by hand); NSDL/CDSL feeds; e-mail delivery of packs; Hindi bilingual letterhead block (design drawn; v1 English only); rules-desk two-reviewer publish (v1 drafts only); per-company letterhead logo upload beyond one image.

## User flows
1. **Partner first day.** Sign in (email, password, 6-digit code) → "How Keel keeps a book" → empty console → "Open a company incorporated today" → enter SPICe+ facts → registers opened, first-year calendar, first-meeting agenda shown → attest with scanned signature → entry 0000 sealed → console shows the company.
2. **Bring in an existing book.** Console → "Start a migration" → upload members .xlsx/.csv → map columns (confirmed / not mapped) → key paper pages (assist proposes fields with confidence; <80% must be checked; accept page) → reconciliation report against keyed MCA master (blocking / explain / agrees) → resolve blocking by recording the missing event → attest (two ticks + scanned signature) → entry 0000.
3. **Trainee records an allotment.** Company → E → allotment drawer → allottees, mode, price, consideration → live preview (register lines, certificates, paid-up, PAS-3 due date with rule caption, chain entry, reconciliation strip) → Confirm → done panel with links → register, calendar, trail, documents all updated. Conflict: if the head changed while editing, "Not recorded … draft is kept".
4. **Board meeting.** Meetings → new → notice (clear-days check) → agenda → attendance roll-call with times → minutes (draft by assist or by hand; refusal if attendance incomplete) → resolutions (link to events) → circulate (acks) → chairman signs (scan) → enter in chain → calendar "entered".
5. **Founder approves and signs.** E-mail link → founder seat → consent on first sign-in → Approve (interest tick → approve → consent entry) → Sign (document sent by the firm; sign with scan/typed where allowed; grant or revoke standing authority) → Numbers (publish monthly figures; investor sees them).
6. **Calendar and SRN.** Calendar → overdue row → SRN drawer → paste SRN (validated) → item filed → console clears.
7. **Prove it.** Trail → entry → Verify (recompute) → Packs → build diligence pack / s.63 extract (printable, reference at foot) → keel.in/verify → Verified / Not verified.
8. **Seats.** Company → Seats → invite auditor (window computed) → auditor accepts consent → sees chained period; firm revokes investor → revoked screen.

## UI
Design: `Keel Product UI v3.dc.html` + `keel-fixture.js` (tokens, chrome, every label). Gaps below are filled in the same style.

## Design gaps (decisions taken)
- **No event catalogue drawn** → a catalogue drawer listing the nine v1 event types with the sections they cite; allotment drawer as drawn; the others follow its two-column pattern (form left, "will write" right).
- **Only Dhruv's book drawn; other companies show an issue card** → every company has a full book; the issue card becomes the top block of Overview when the company has an overdue/mismatch/migration/day-one state.
- **DSC signing** → v1 offers "scanned signed page" (hashed into the entry) for statutory paper and "typed name + consent" for non-statutory; DSC/Aadhaar options shown disabled with "not in this version".
- **Sandbox borrows Dhruv's data** → the sandbox is a real company row per firm, seeded from the fixture, with its own chain, never anchored, resettable.
- **No print stylesheet** → real `@media print` for registers, minutes, certificates, packs, monthly report.
- **Seat revocation only for investor** → any seat can be revoked; seat holder can withdraw consent from their own settings.
- **Consent capture only for auditor** → every seat sees the consent card on first sign-in.
- **Help text missing for Letterheads / Signatures / Draft** → written.
- **States not drawn but required:** loading (mono line), API error (toast + inline), empty registers, empty calendar, empty trail (before attestation), empty documents, no seats, expired invitation, expired reset link, locked out after 10 failed sign-ins, session expired.
- **Migration steps 1–3 marks** → each step marks done only when its data exists.
- **Ask the book** → deterministic queries over the firm's registers (holders as of date; last meeting attendance; a company's next due); refuses penalty estimates.
- **Fixture inconsistencies** (addresses, prev hash, certificate numbering, 99.9%) → the app computes them; nothing hard-coded.
