01What VERO is
VERO is a multi-tenant HR and payroll platform built for Nigerian employers — one system that runs the full loop from who works here → did they show up → what are they owed → money in their bank account.
The one-sentence positioning
VERO is the HR platform that turns attendance into a verifiable payslip and a bank transfer — built for Nigerian pay rules, Nigerian banks, and workforces that clock in at a gate rather than a laptop.
Four surfaces ship today
| Surface | Who uses it | What it is |
|---|---|---|
| Workbench | HR, Payroll, Supervisors | The admin product — employees, attendance, leave, rosters, payroll, reports, settings |
| Staff app | Every employee | Mobile-first self-service — today's attendance, leave, schedule, pay, profile |
| Attendance Agent | Site operators | Windows desktop app syncing fingerprint terminals at the workplace |
| Platform Console | VERO internal | Tenant lifecycle, provisioning, plans, health, support diagnostics |
Plus one public, unauthenticated surface: the payslip verification page a bank or landlord uses to confirm a payslip is genuine.
Who we sell to
| Segment | Size | Why VERO wins | Plan |
|---|---|---|---|
| Field / shift workforces Manufacturing, logistics, hospitality, security, facilities | 50–500 | Daily-rate pay is a first-class citizen. Biometric attendance feeds pay directly | Growth |
| Professional SMEs Agencies, clinics, schools, NGOs | 20–150 | Statutory payroll, leave, and verifiable payslips without a payroll bureau | Starter → Growth |
| Multi-site groups | 250+ | Rostering, per-location devices, custom roles and workflows | Growth → Enterprise |
| Growing startups | <10 | Land motion | Free |
Economic buyer: HR Director or Finance Director. Champion: the payroll officer — the person who currently spends four days a month in a spreadsheet.
02Status legend
Every capability in this brief carries one of four flags. They are the spine of the document — read the chip before you read the row.
| Flag | Meaning | Sales rule |
|---|---|---|
| Live | Built, wired, covered by tests | Sell it. |
| Beta | Built and functional; limited field exposure, or a dependency outside software | Sell with the qualifier and a named implementation step |
| Config | Built, but needs a customer-specific input before it produces value | Sell as part of onboarding, never as "works out of the box" |
| Not built | Designed and/or scoped, no implementation | Roadmap only. Not in the price list, and never a commitment without a written date from Product |
As of this revision, nothing in the published price list is unbuilt. Four features and one limit were removed at v3 because they were not deliverable. Section 07 is the list of what must never be promised.
03Feature inventory
Employee management
| Capability | Status | What to say |
|---|---|---|
| Records, lifecycle, deactivation | Live | One record per employee with full change history |
| Departments & positions as managed entities | Live | Real org structure, not spreadsheet columns |
| Grades, steps, salary structures | Live | Pay bands defined once, applied consistently |
| Bulk import — mapping, validation, error correction | Live | Onboard hundreds in one pass; bad rows are flagged and fixable, never silently dropped |
| Multi-identifier login — email, phone, or employee number | Live | Staff without company email still get accounts |
| Activation codes, offline credential delivery | Live | Onboard a factory floor that has no inboxes |
| Custom employee fields | Not built | Removed from the price list. Roadmap, next quarter |
Competitors assume every employee has a work email. Ours does not. In a 200-person warehouse that is the difference between a rollout and a stalled pilot.
Attendance
| Capability | Status | What to say |
|---|---|---|
| Clock-in / clock-out | Live | |
| Supervisor manual entry, fully audited | Live | Every manual mark carries who, when, and why |
| Bulk historical upload | Live | Migrate history on day one |
| Periods with close / reopen controls | Live | Attendance locks before payroll. Reopening is deliberate and audited |
| Device sync agent — desktop, tray, auto-start | Live | Terminals at the gate sync themselves |
| ZKTeco connectors — LAN and USB | Live | Works with hardware customers already own |
| Durable offline buffering at the site | Live | The internet drops, the punches don't |
| Lateness detection vs. roster + grace period | Live | "Late" is defined by the schedule, not by a guess |
| Lateness penalty policy — on/off, 5–25% of daily pay | Live | Off by default: lateness is recorded whether or not it costs |
| Corrections with mandatory reason + policy versioning | Live | A correction never silently rewrites finalised payroll |
Biometrics
| Capability | Status | What to say |
|---|---|---|
| Fingerprint enrolment, per-finger, with preview | Beta | |
| Two-phase capture with agent-side verification | Beta | |
| Production ZK9500 device helper | Beta | Requires vendor driver and physical hardware. Always scope into the implementation plan |
| Templates only — raw images never stored, sent, or logged | Live | A genuine privacy selling point |
| Templates encrypted at rest; deleted on employment exit | Live | Shortest retention of any data class in the platform |
| Manual capture can never be disabled | Live | The fallback is guaranteed |
Fingerprint capture fails on worn, wet, scarred, or calloused hands — exactly the hands of the daily-rate workers whose pay is their day count. VERO therefore makes manual capture impossible to switch off, and reports the manual-override rate as a payroll-integrity metric rather than an ops statistic.
A machine that cannot read a finger must never cost someone a day's wage. Competitors sell biometrics as pure control; we sell control with a guaranteed human fallback. That lands with HR directors, and it lands with unions.
Biometrics needs terminals, and terminals need sizing. At roughly four seconds per scan, one terminal clears about 200 people in 13 minutes. Under-provision a site and you create a queue that marks people late. Terminal count per site is part of the deal.
Leave & rostering
| Capability | Status | What to say |
|---|---|---|
| Per-type × per-staff-category leave policy | Live | Different rules for different staff classes |
| Paid / unpaid, accrual, carry-forward, encashment | Live | Leaver balances have a path to be paid out |
| Two approval chains, delegation | Live | Approvals don't stall because a manager is away |
| SLA escalation on stalled approvals | Live | Requests escalate on their own |
| Self-approval and circular approval blocked by the engine | Live | Enforced in software, not in a policy PDF. Auditors care about the difference |
| Public holiday calendar, effective-dated, overridable | Live | |
| Shift patterns, roster authoring, publish / duplicate / archive | Live | Build next month from last month in a click |
| Leave-conflict detection before publish | Live | You never publish a roster that schedules someone already on approved leave |
Payroll
| Capability | Status | What to say |
|---|---|---|
| Two staff classes — monthly salaried and daily-rate | Live | Daily-rate is fully modelled, not bolted on |
| Daily-rate pay resolved from roster + attendance evidence | Live | Days worked → days paid, with the evidence attached |
| Pay components — assignable, revisable, cancellable | Live | |
| Payroll formula engine | Live | Model the allowance your industry actually uses |
| Statutory engine — PAYE, pension, NHF, NHIS, ECA, NSITF, reliefs | Config | Structure is live; rates are ratified by a named accountant per client |
| Draft → preview → finalise; immutable finalised runs | Live | A finalised run cannot be edited. Corrections are new adjustment runs |
| Idempotent runs | Live | Retries never double-pay |
| Payroll-officer scoped run access | Live | Separation of duties inside the payroll team |
VERO's tax engine ships empty by design. It knows how a progressive band, a flat rate, and a flat levy are computed; it holds no hard-coded rate anywhere in the codebase. Every figure is data — effective-dated, ratified by the client's accountant — and the engine reproduces the law in force at the payroll date for any historical run.
"VERO never guesses your tax. Nigerian rates change; your accountant ratifies the figures, VERO applies them exactly and reproduces any past period under the law that applied then." A competitor with rates baked into code is one budget speech away from being wrong for every client at once.
Delivery consequence: accountant sign-off is a prerequisite for payroll go-live. Scope it into every implementation plan — it is the longest-lead item in onboarding.
Payslips — branded, downloadable, verifiable
| Capability | Status | What to say |
|---|---|---|
| Branded PDF download — logo, colours, address, signature | Live | A payslip that looks like the employer issued it, because they did |
| QR code on every payslip → public verification page | Live | A bank, landlord, or embassy scans and confirms it is genuine — no account needed |
| Codes minted automatically when a run is finalised | Live | Every finalised payslip is verifiable the moment it exists |
| Rate-limited per IP and per code | Live | Scraping and enumeration are throttled |
| Expiry — configurable, default 180 days | Live | A payslip from three years ago stops being a live disclosure |
| Revocation — by the employee, or by HR | Live | If a payslip leaks, the employee can switch the code off themselves |
| Access audit on every attempt | Live | The employee can be told who checked and when |
| Disclosure notice printed beside the QR | Live | The employee is told what the code reveals before they hand it over |
Employer name, employee name, period, payslip reference, issued date, and net pay. It does not disclose bank details, BVN, TIN, addresses, internal identifiers, or the component breakdown. Do not describe it as revealing nothing — describe it as revealing exactly this, under the employee's control.
Salary disbursement — the wedge
| Capability | Status | What to say |
|---|---|---|
| Per-workplace wallet with virtual account for top-ups | Live | Fund the wallet by bank transfer |
| Salary payout to employee bank accounts | Beta | Requires production PSP activation per environment |
| Account name enquiry before payout | Live | Wrong-account transfers caught before money moves |
| Maker–checker — propose → approve by a different person → execute | Live | The control finance directors ask for on the first call |
| Bank details and BVN encrypted at rest, masked everywhere | Live | No card data stored anywhere |
Most HR systems in this market stop at a payroll register and hand a CSV to the bank. VERO closes the loop: attendance → calculation → approval → money in the account, with dual approval and a full audit trail.
Notifications, reporting, administration
| Capability | Status | What to say |
|---|---|---|
| In-app notifications — the delivery floor, cannot be switched off | Live | |
| Email notifications, per-employee preferences | Live | A channel outage never stalls a leave approval |
| SMS | Not built | Removed from the price list. Seam and spend cap exist; no provider wired |
| Six report families — workplace, attendance, payroll register, daily pay, pay items, leave | Live | |
| Immutable, hash-chained audit log | Live | Tamper-evident across payroll, attendance, leave, administration |
| Tenant isolation at the database layer | Live | Isolation is a boundary, not a filter. The service refuses to start on a database role that could bypass it |
| Custom roles, custom approval workflows, tenant branding | Live | Model your own processes |
| Per-tenant hosting region | Live | Data residency is a provisioning choice, not a custom deployment |
| Plan entitlements enforced by the API | Live | A customer cannot reach a feature they haven't bought by calling the API directly |
| Support diagnostics — read-only, audited, client-visible | Live | See below |
VERO support can see operational facts — run status, job failures, audit entries, entitlement state — and every look is audited and visible to the client. Support cannot see salaries, personal data, or biometric data. There is no override, no back-door, no "admin mode". Most competitors cannot say that.
04The five things to lead with
-
Payroll that actually pays
Attendance → payslip → bank transfer, with maker–checker approval and account-name verification. Most competitors stop at the register.
-
Verifiable payslips the employee controls
Every finalised payslip carries a QR code anyone can scan to confirm it is genuine — rate-limited, expiring, and revocable by the employee at any time. In a market with a real payslip-forgery problem, this protects the employer's name.
-
Daily-rate workers are first-class
Roster-driven payable days, evidence-backed, with a lateness policy the client can switch off entirely.
-
Biometrics with a fallback that cannot be disabled
Control without the risk of a machine's failure costing someone a day's wage.
-
A tax engine that never guesses
Effective-dated, accountant-ratified rates; historical runs reproduce the law that applied at the time.
Secondary, but they close deals: isolation enforced beneath the application · no support back-door into client data · custom approval workflows · a formula engine for bespoke allowances · immutable finalised payroll · login by employee number · offline-tolerant attendance sync.
05The plan ladder
Every feature in this matrix is built and working. Four features and one limit were removed at v3 because they were not deliverable; their entitlement keys are retained so they can be re-added the day they ship.
| Free | Starter | Growth | Enterprise | |
|---|---|---|---|---|
| Per month | ₦0 | ₦30,000 | ₦80,000 | Custom |
| Per year (−15%) | — | ₦306,000 | ₦816,000 | Custom |
| Seats | 10 | 50 | 250 | ∞ |
| Employee management | ✓ | ✓ | ✓ | ✓ |
| Attendance | ✓ | ✓ | ✓ | ✓ |
| Attendance device sync | — | ✓ | ✓ | ✓ |
| Biometric enrolment Beta | — | — | ✓ | ✓ |
| Leave | ✓ | ✓ | ✓ | ✓ |
| Advanced leave policies | — | — | ✓ | ✓ |
| Rostering | — | ✓ | ✓ | ✓ |
| Payroll | — | ✓ | ✓ | ✓ |
| Statutory (PAYE / pension / NHF) | — | ✓ | ✓ | ✓ |
| Payroll formula engine | — | — | ✓ | ✓ |
| Payroll runs per month | 0 | 1 | ∞ | ∞ |
| Branded PDF payslips + QR verification | ✓ | ✓ | ✓ | ✓ |
| Email + in-app notifications | ✓ | ✓ | ✓ | ✓ |
| Custom roles | — | — | ✓ | ✓ |
| Custom workflows | — | — | ✓ | ✓ |
| Custom branding | — | — | ✓ | ✓ |
| Reports | — | ✓ | ✓ | ✓ |
The packaging logic, in one line each
| Tier | The pitch |
|---|---|
| Free | A real product for a very small team, and a land motion. No payroll, 10 seats. |
| Starter | "Run your payroll properly." Payroll, statutory, rostering, device sync, reports, verifiable payslips. One run a month, which is what a 50-person employer needs. |
| Growth | "Run a shift workforce." Biometrics, unlimited runs, formula engine, custom roles and workflows, branding. The target tier and the product's centre of gravity. |
| Enterprise | Currently identical to Growth on features. It differs only on limits. This is the open packaging problem — see decision 01. |
Every gated feature was verified as enforced at the API layer, not merely hidden in the UI. Nothing in the published price list returns an error or does nothing.
Held back, with keys retained: custom employee fields, SMS, API integrations, SSO, document storage. Sales treats these as roadmap, not inventory.
06Pricing issues for management
The remediation closed the compliance and ladder-integrity problems. What remains is pricing. Each item below needs an owner and a decision.
| # | Issue | Why it matters | Recommendation |
|---|---|---|---|
| 1 | Enterprise is now feature-identical to Growth | Since the unbuilt exclusives were pulled, only limits distinguish the tiers. There is no feature story for Enterprise | Most urgent. Re-anchor on unlimited seats, hosting-region choice, dedicated support, custom SLA, priority onboarding — all real today |
| 2 | The Growth jump is 2.7× for 5× the seats | Starter is ₦600/seat at 50. Growth is ₦320/seat at 250. A 60-person client pays 2.7× to add ten people | Add seat overage (~₦500/seat/month above plan) or a mid-tier. The 50–250 gap is where deals stall |
| 3 | Flat per-organisation pricing does not scale with value | A 240-person manufacturer and a 60-person agency both pay ₦80k. The manufacturer gets far more value and costs far more to serve | Consider base + per-seat at Growth and above. Flat pricing is simple to sell and leaves the most money on the table in our best segment |
| 4 | Disbursement is monetised at ₦0 | We move real money at real per-transfer cost, bundled today | Per-transfer fee with margin. It scales with the cost it creates, and buyers already accept it from their bank |
| 5 | Biometrics is priced as software only | Terminals, enrolment, and site sizing are the real cost and the real risk | Price hardware and enrolment as a one-off implementation fee. Never bundle into MRR |
| 6 | No implementation or onboarding fee | Payroll go-live needs accountant-ratified rates, data migration, often terminal deployment. That work is free today | One-off onboarding fee by tier. It funds the riskiest part of the journey and filters clients who will never go live |
| 7 | Verifiable payslips are given away on Free | One of our two strongest differentiators, at ₦0 | Keep it there — deliberately. Every verified payslip puts our brand in front of a bank. It is the best viral surface we have |
| 8 | 15% annual discount | Standard, and good for cash flow | Keep. Push annual hard in year one |
Discounting guidance — proposed, needs ratification
| Situation | Guidance |
|---|---|
| Annual prepay | 15%, already in the ladder. Not stackable |
| Multi-year | Refer to management. Not a standing offer |
| Reference customer | Up to 20% first year, for a signed, publishable case study |
| Above 250 seats | Enterprise conversation, never a Growth discount |
| Non-profit / education | Refer to management. No standing policy |
07Do not sell these
None of these appear in the price list. If a deal depends on one, it is a Product conversation before a commercial commitment — never a promise made in the room.
- SMS deliverySeam and spend cap built; no provider wired. Nearest of the unbuilt items
- Custom employee fieldsRoadmap, next quarter
- Public API, webhooks, integrationsNot built. Funded only against named demand
- Single sign-onNot built. Funded only against named demand
- WhatsApp, Teams, SlackPhase 2
- Native mobile appsMobile-first responsive web is the deliberate choice, and it works. Say so directly
- Document library / contract downloadThe staff Knowledge Base is VERO's own help guides, not the client's uploaded handbooks
- Overtime & shift differentialsNot built. Lateness penalties are; overtime is not. A common ask in shift workforces — qualify early
- ATS, performance, training, expenses, offboarding, org chartsOut of scope, not on the near roadmap
- Accounting / ERP integrationOut of scope — note that VERO pays salaries directly, which is why most buyers ask
- Multi-currency payrollNigeria only
- VERO access to client salary or personal dataBy design. Support sees operational diagnostics only, and every look is audited and client-visible
08Proof points you may publish
Engineering commitments, verified in the codebase and covered by the test suite. These are safe to put in writing.
| Claim | Basis |
|---|---|
| "Zero cross-tenant data leakage" | Row-level security in the database; a dedicated isolation suite exercises every endpoint from an authenticated foreign tenant. Release-blocking |
| "The system refuses to start if it could bypass isolation" | Startup guard rejects an over-privileged database role |
| "A retry never pays twice" | Payroll runs are idempotent by construction |
| "Historical payroll reproduces the law that applied then" | Effective-dated statutory engine; no rate literal exists in the codebase |
| "A finalised payroll run cannot be edited" | Immutability enforced in the database, with a dedicated test suite |
| "Self-approval is impossible" | Blocked by the approval engine, not by policy |
| "Raw fingerprints are never stored" | Templates only, encrypted, deleted on exit |
| "Payslips can be verified in seconds — and revoked by the employee at any time" | Public QR verification with rate limiting, expiry, revocation, and access audit |
| "We cannot see your salaries" | Support diagnostics exclude salary, PII, and biometric data; every access is audited and client-visible |
| "A new client can run payroll on defaults alone" | Every configuration surface ships with a Nigerian default |
| "Attendance keeps working when the internet doesn't" | Durable local queue at the site |
| "Tamper-evident audit trail" | Hash-chained audit log with a dedicated test suite |
If a technical buyer asks about testing: unit, database, and end-to-end suites, including dedicated suites for tenant isolation, authorisation, payroll immutability, and the audit chain. Unit suite currently 201 of 201 passing.
09What changed at v3
A review found three places where the running code and the design documents disagreed. All three have been remediated and re-verified.
| Finding | Resolution |
|---|---|
| Payslip verification disclosed net pay and personal data with no rate limit, expiry, or working revocation | Resolved by keeping the disclosure and adding the controls. Employee number removed from the response; rate limiting per IP and per code; 180-day default expiry; revocation by employee and by HR; full access audit; uniform failure shape; disclosure notice printed on the payslip. The charter was amended so specification and code now agree |
| The ladder sold four features that did not exist | Custom fields, SMS, API integrations, and SSO removed from the published matrix; entitlement keys retained for re-add. Storage limit removed |
| Break-glass access specified but never built | Resolved with a read-only, audited support diagnostics surface. Operational data only; salary, personal data, and biometrics unreachable. Full break-glass remains deliberately unbuilt |
Documentation: the charter's persona matrix still describes verification as returning "valid/invalid + payslip number + period", which the amended decision supersedes. Worth tidying so a future audit doesn't re-raise the finding.
Scale: the verification rate limiter is in-process, so limits apply per instance. Before the platform runs multiple replicas it needs a shared backend. Noted in the code.
10Decisions requested
Priority order. The first three change what sales can do this quarter.
Re-anchor Enterprise
It is now feature-identical to Growth. Blocks every Enterprise conversation. Most urgent item on this page.
Seat overage, or a mid-tier
Between Starter and Growth. Blocks the 50–250 seat segment — our best segment.
How disbursement is monetised
Per-transfer, volume band, or bundled. Unit economics on our strongest differentiator.
Approve a one-off onboarding fee by tier
Cost recovery on go-live, which is currently free and is the riskiest part of the journey.
Confirm Enterprise is "contact us"
Rather than list-priced. Blocks website copy.
Ratify the discount guidance
So field pricing is consistent across the team.
Fund SMS, custom fields, API, or SSO?
SMS and custom fields are small. API and SSO are large and should wait for named demand.