The solar subsidy documents required for PM Surya Ghar sit in WhatsApp, not in the file

What goes wrong
You win a project on a Tuesday morning. The documents go out to the DISCOM on Friday. On Monday the DISCOM rejects the file for one missing page — a page the salesperson took a photo of three days earlier, WhatsApp message, never uploaded to the system. You ask for it again. Another week passes. The customer rings wondering when the net meter arrives.
Documentation marks each file correct when they land, but there is nowhere to record which copy they checked or which page was blurry. Three months later a spot audit surfaces a missing signature on the bank document nobody documented at the time. You cannot tell who verified it, when, or what changed. The audit trail lives in WhatsApp.
The stage gate stops a project advancing when its checklist still has open items — but a file marked done by a salesperson three days before the paperwork ever reached ops becomes an open item after the fact. The seller never reopens it. The stage sits blocked while ops chases a file that has been done for weeks.
How it works
Photograph at the won moment
The seller lands on the documents screen when the deal closes. The screen lists the papers this project actually needs — property documents only on loan projects. Take photo opens the camera; upload file opens the picker. Both go to R2, a private Cloudflare bucket with short-lived signed links, never a shared folder or WhatsApp. The compression happens on the phone.

Documentation verifies, not collects
Ops opens the same screen from the office or a phone. Each file shows a chip (Awaiting verification, Needs re-upload, Verified) and a button per slot. Correct marks it verified. Incorrect asks for a note the seller will read. A file marked incorrect stays in the slot until it is replaced; the seller sees the reason and the re-upload task in their own list, alongside their site visits and delivery dispatches. The task closes itself when the replacement lands.

The stage gate holds until every required file is verified
The button that moves a project forward is simply not available while documents are still pending or incorrect. You do not discover in week four that a project skipped past documentation because the week was busy. The gate stands in the way of every branch the project can take — loan, non-loan, subsidy stages, board-specific paperwork. Rolling a project back stays free; the gate only stands in the way of pretending work is finished.

KYC papers are visible only to the chain
Aadhar cards, PAN, the customer's photo and signature, property documents and the bank's sanction letter are readable only by the people carrying the project and the company management. The QC team waiting on installation sees installation photos; they never see the Aadhar. Site drawings, survey photos and the feasibility report are standard sensitivity and visible to the ops pipeline. Every access is audited without keeping the contents.
The file survives stage changes and task completion
A document is keyed by project and paper type, not by task id. A completed task is immutable — once a checklist item is done, it cannot be edited or rolled back. But if the project rolls back to an earlier stage, the documents stay. If the stage reopens after cancellation and rejection, the verified papers are still there. Files outlive the tasks that produced them.
Everything else you would ask
What if the customer's papers are missing a page, or the photo is too dark?
Ops marks it incorrect and writes why — 'missing page 2' or 'photo too blurry, retake'. The re-upload task goes to the seller the same moment with the reason attached. They take a new photo or ask the customer for a clearer copy. Once it lands, the file replaces the earlier version and the task closes by itself. There is no back-and-forth in WhatsApp.
What if the project rolls back to an earlier stage?
The documents stay. The verified papers are still there, the incorrect ones are still tagged. If the stage reopens later, after a customer objects or the bank changes its mind, the paperwork is already on record. You are not re-asking for files you already have.
Who is allowed to verify documents?
Management, the current stage owner and their managers, and whoever held the project at Doc Verification. There is deliberately no separate 'documents desk' role. A colleague covering for the ops head becomes stage owner through the existing reassign flow and sees the files only once they do.
Where do the files live? Is it safe?
R2, a private Cloudflare bucket in India. Postgres holds only the metadata and the key. Files are never proxied through the app, never stored locally, never sent over email. Access is session-gated — the server checks the user's permissions before handing out a 2-minute presigned link to the file. Opening a KYC file writes one entry to the audit trail per viewer, per day.
Can we use our own template words for the paper types?
Yes. During setup, every workspace edits its stages, tasks and the days on them. Checklist titles ('Verify Aadhar Card' or 'Collect Aadhar Card') and the file types themselves are yours to reword. The solar module seeds a starting point; you keep it or change it to match your process.
Run one real project through it this month. You will know by the end of it.
30 days free, no card, no call. Then ₹10,000 a month for the whole company, however many people you put on it.