This document contains commercial terms and case detail belonging to Nash Group Mobility (Pty) Ltd. It is not for onward distribution.
Confidential to Michael Nash and Rayne Mulder. Access is recorded.
A case platform built on the one thing no competitor in your sector owns: a deterministic model of South African immigration law, running against every file you hold.
You said it plainly on the call: there is no one who can compete. This plan is about the one place that is not yet true, which is capacity.
Every application costs a consultant's attention. That attention is your ceiling, and it is why your fees sit where they sit.
The last seven weeks were not about building a case tracker. They were about moving what lives in Riekus's head, and Claire's, and Brandon-Lee's, into something that runs on every file at once and does not get tired at four in the afternoon.
Two things happened in your own files while I was doing it. A renewal was refused while complying with the rule as the Department publishes it. And an appeal representation left your office citing the wrong section of the Act. Neither was carelessness. Both were caught by a person reading closely, which is exactly what does not scale.
What follows is what gets built, in what order, what has to be true for the dates to hold, and what is deliberately excluded.
A renewal in your book expired on 31 August. The pack was lodged on 1 July, sixty-one days ahead. The Department's published wording says no less than 60 days prior, making the last safe day 2 July. You were compliant with a day to spare.
It was refused under Regulation 9(8)(c). The Department had counted two calendar months back from expiry, which lands on 30 June. On that reading the pack was one day late.
Both facts were true at once. That is why the system never answers with a pass or a fail.
The gap runs from nought to two days depending on the months a case spans. It is computed per file, never assumed. Every renewal is scored against both readings, the earlier governs, and the handler sees both dates.
On top of that sits your own margin, because neither of you works to the legal minimum.
So the warning comes on your day, not the Department's last lawful one. A warning that turns red on the final legal day has arrived too late to act on. The statutory date is never overwritten. You and an auditor both have to see it.

An appeal representation in the submission pack opens on a visitor's visa renewal under section 11(1), and closes by asking the Department to issue a permit so the applicant can work under a General Work Visa in terms of section 19(2). Two different routes, one letter.
I raised it as a question, not a correction. Riekus answered the same week: the 19(2) is a mistake on the letter, yes. He judged the impact nil and the appeal is lodged. Nothing is owed on that file.
What matters is that this is the exact failure Rayne described in the first meeting, months before I found an instance of it:
It took someone reading sixty-eight pages to find it. From the build onward every generated letter has its citations checked against the route before release. A citation that does not belong stops the letter and quotes the sentence back.
I went through the platforms your competitors run and the firms you compete against. Section 11 has it. Every one can tell a client where a case is. Not one can say what goes wrong in the next six months, because none owns a model of South African immigration law. They own workflow software. You would own the rules.
Each assignee's remaining 180-day allowance in the calendar year, projected forward. Runs out 14 October, so the work visa starts now. The recurring disaster for the Indian IT majors, tracked by nobody.
The next application in a person's chain surfaced before it is urgent, with qualification-verification lead time back-computed into a safe start date.
The points calculation run across a corporate's planned hires. Six of your thirty secondments will be refused as packaged, and here is the lever for each.
Every citation checked against the route before release. The 19(2) case, caught by the machine rather than by someone reading late.
This is the part that changes your pricing, and it is your idea rather than mine. When intake stops being limited by what one consultant can hold, the cost of serving an application falls. Fall far enough and you set a floor the firms in section 11 cannot follow, because they would have to rebuild to try. I have modelled it against your fee card and volumes and will walk you through it once you have read this.
Ten services, each doing one job, each able to be tested on its own. Described here by what they do rather than how they do it, for reasons section 12 sets out plainly.
| Service | Its single job | What it talks to |
|---|---|---|
| Case record | One row per matter, one per applicant, scoped so a corporate client can only ever see its own. | Everything. It is the spine. |
| Deadline engine | Turns a visa expiry into every date that follows from it, under both readings, with your margin on top. | Case record, calendar sources, the radar |
| Eligibility scoring | Runs the hundred-point calculation and flags the bands that depend on interpretation. | Case record, letters, the radar |
| Document checklist | Knows which documents a route needs, from the versioned Departmental form, and what is missing today. | Case record, document store |
| Letter assembly | Builds the letter from the record so it cannot contradict the file, then checks every statutory citation before release. | Case record, scoring, document store |
| Document store | Takes custody of a file and can prove what it took custody of. Section 09. | Checklist, letters, audit |
| Notification | Tells the right person the right thing early enough to act, and escalates when nobody does. | Deadlines, case record, mail |
| Client portal | The corporate HR team's own view, so they stop emailing you for status. | Case record, identity |
| Audit and lineage | Append-only record of who did what, when, and which version of a rule applied at the time. | Everything. Nothing writes without it. |
| The radar | Forecasting, not status. The three surfaces in section 04. | Deadlines, scoring, case record |
Interfaces in and out. Sign-in runs against your corporate identity, Microsoft or Google, so nobody manages another password. Mail flows in and out threaded on the case. The document store sits behind one interface so it can be swapped without touching anything above it. An interface for corporate HR systems is designed in from the start and connected when a client asks for it.
Two decisions inside that shape are worth stating, because they are the ones a technical reviewer asks about first. The pages are built on the server and sent finished, with no separate application running in your browser, because the job is forms, tables and queues, and one codebase is easier to secure and to hand on. And documents are generated when somebody needs one, from the audited record, rather than stored: nothing is kept twice, any past version is reproduced from the history, and a submission record holds what actually went to the Department and what came back.
There is no Departmental interface, and any supplier who tells you otherwise is guessing. Nothing in this build assumes one. Qualification verification has no interface either, and each application sits behind the applicant's own mailbox, which is why that part is designed as a countdown you can see rather than an integration nobody can have.
One route at a time, each tested before the next begins, working back from full completion in December 2026. Each stage carries the test that decides it is finished. Those tests were written before the work started, which is the only way a sign-off is worth anything.
Sign-in through your existing Microsoft or Google accounts. Append-only audit. The case and applicant model. Document storage interface. Tenant isolation with one cloud project per client is designed and is deployed in Stage 3. The design is settled; the deployment is not done, and this plan should not say more than the design document does. The rules behind the deadlines, the scoring and the letters carry 279 tests at the logic layer. This is the part already paid for in time rather than money.
Nothing. It is done and it is not part of the payment schedule.
The part Shadi was right about, and the part that was missing. Four review documents, one per reviewer, each holding only your own rows with a closed question against each. The requirements signed. The screens agreed in light mode before anything is built against them. A map from every requirement to the stage that clears it. A written test plan. This stage produces no features. It produces the agreements that make the next three stages verifiable.
Every requirement carries the stage that clears it, and every screen in the six journeys has a version you have approved. The December date depends on this: if the screens are not signed by 2 October, mid-December moves. That is not a threat, it is arithmetic. Stage 3 builds against locked screens, and it cannot start against unlocked ones.
Both readings of the renewal rule with the earlier governing. Your firm's margin on top, per rule. The seven-working-day rule for short visas. The appeal window counted from receipt rather than from the decision date. Where a public-holiday calendar is missing for a jurisdiction, the answer is UNKNOWN and never a guess.
Given the refused case in section 02, the engine returns 30 June and 2 July, governs on 30 June, reports the 1 July lodgement as EXPOSED in plain words, and shows your own margin date alongside. Every deadline requirement in the workbook has a passing test, and the full suite still passes. And you see it for yourself: you watch a three-minute recording of the stage running on your own kind of case, you see the list of requirements it clears with the test that proves each one, and you tick agree or disagree per line. The instalment follows your ticks.
The hundred-point calculation, with interpretation-sensitive bands flagged rather than scored silently. Letters generated from the case record, one template family per client and consulate, every points claim carrying its evidence reference, and the citation check before release.
A case scoring at the threshold is flagged, not passed quietly. A letter citing a section that does not belong to its route is blocked and the sentence quoted back. A points claim with no evidence attached cannot render. Every eligibility and letter requirement has a passing test. And you see it for yourself: you watch a three-minute recording of the stage running on your own kind of case, you see the list of requirements it clears with the test that proves each one, and you tick agree or disagree per line. The instalment follows your ticks.
The staff console your consultants work in all day, sorted by urgency rather than by date received. The corporate client's own view. The qualification-verification countdown, built around the fact that there is no interface and each application sits behind the applicant's own mailbox.
A consultant opens one screen and sees every matter needing attention today, in order. A corporate HR user signs in with their own work account and sees only their own people. A full case runs end to end on your own anonymised data, watched by you. And you see it for yourself: you watch a three-minute recording of the stage running on your own kind of case, you see the list of requirements it clears with the test that proves each one, and you tick agree or disagree per line. The instalment follows your ticks.
The three forecasting surfaces in section 04. This is the part sold to your corporate clients rather than used by your staff, and it is the reason the platform grows your book instead of only tidying it. It is not in this price. It is named here so the architecture leaves room for it, and so you can decide later without rebuilding.
Out of scope for this agreement. Quoted separately when you want it.
Behind all of it sits a workbook of 166 numbered requirements, each with a test written so it can be checked rather than argued about. Sixteen are built. Anything still marked unconfirmed waits for one of you. The workbook is yours to read at any point.
Two lists. The first is what I need from you. If one arrives late, the date moves. The second is what I have taken as true without you confirming it. If one is wrong, the work changes.
| I need from you | Or else | By |
|---|---|---|
| Your answers in the four review documents | One document each, holding only your own requirements, with a closed question against every row: agree, disagree, or here is the answer. Nobody is asked to read all 166. Until they come back, anything marked unconfirmed stays unbuilt, which is the right behaviour and also the slow one. | By 2 October |
| One hour with each consultant, on the screens | Walking the screens with the people who will use them, before they are built. An hour each now is worth a fortnight later: a change to a picture costs minutes, and the same change once the desks are built costs weeks. | Before 2 October |
| The rest of your 11(1) professional fees | I already hold two of them: ETA at R3,000 from Brandon-Lee's own client letter, and the 11(1) visitor's disbursements at R2,925 from Riekus. What is missing is meetings, business, tourist, family visit and eVisa. Your taxonomy marks the category highest volume, so quoting stays incomplete without them. | Before Stage 1 |
| Confirmation that your professional fees are quoted excluding VAT | Your 3 August quotation reads + VAT @ 15%, so I have assumed exclusive. One line confirms it. If I have it backwards, every quotation the system produces is out by fifteen percent. | Before Stage 1 |
| The address status emails should come from | Asked on 8 September and still open. Replies need to land with your team rather than with me, so it has to be an address you own. | Stage 1 |
| A test account on your Microsoft or Google tenancy | Sign-in cannot be tested against the real thing, and I will not ship it untested. | Stage 3 |
| The two hours a week you already put in place | Nothing new. On 14 August you told Riekus and Brandon-Lee to allocate two hours a week, and you were right that the more time spent the better the system gets. It needs to hold through the build, because it is what stops me building what I think you do rather than what you do. | Throughout |
| Whether prohibition and overstay drafting is in or out | It stays switched off. Brandon-Lee offered it unprompted and you have priced the overstay appeal. | Stage 2 |
| Your attorney's written position on data protection | I went through the storage layer, deletion rights and the audit trail with you on 13 August. What is missing is the formal position, and live files cannot move onto the platform without it. Section 10. | Before go-live |
| Written consent for the storage sub-contractor | Clauses 3.4 and 11.5 require it. You asked that this waits for the commercial agreement, and it will. | On signature |
And what I have assumed. Say so now if any of these is wrong.
You will read this and want things changed. That is the point of sending it. And once I am building you will think of something on a Tuesday that was not in the plan. Here is how that works.
Small things are free. Anything under half a day I absorb. Wording, a column in the wrong order, a field you want moved. No paperwork and no conversation about money.
Bigger things get one page. Anything above that gets a single page back from me within three working days: what it is, what it adds in days, what it moves in the schedule, and what it costs. Then you say yes, no, or later. Nothing is built until you have said yes in writing, and nothing is invoiced that you did not say yes to.
Everything agreed goes in a log that sits with the agreement, so in February neither of us is trying to remember what was decided in October.
No surprise invoice, and nothing built that you did not ask for.
Your clients are Kellogg, KLM, Air France, Huawei, Tata, TCS, Infosys and Mediclinic. Procurement at that level does not ask whether you have security. It sends a questionnaire and asks where the data sits, who holds the keys, and what happens when somebody uploads something they should not have. These are the answers.
A document moves through a fixed sequence of states and cannot be moved backwards. There is no path that returns a file to an earlier stage to skip a scan or a review. Rejected and archived are dead ends. Every file takes the same route, and the route is auditable.
Uploads land somewhere deliberately temporary. Only after a clean scan does a file move into the hardened store, which is write-once. A file there cannot be silently altered or replaced, which is what makes a chain of custody defensible rather than merely claimed.
Files are streamed to the scanner rather than handed over as a location on disk. That closes a class of attack where the thing scanned and the thing stored turn out not to be the same thing.
The moment a file arrives clean, a cryptographic fingerprint is taken of it exactly as the sender uploaded it. That becomes the permanent reference for what your client gave you, independent of anything done to the file afterwards.
Each document is encrypted with a key of its own. That key is itself encrypted by a master key that never leaves a hardened key store, and only the wrapped version is ever written to the database. Someone who steals the entire database still cannot read a single passport scan.
Opening the key store by hand requires several separate key-holders acting together. In production it opens against a cloud key service instead, so no person is in the loop at all. Neither you nor I can open it alone.
A corporate client sees only its own organisation. A processor sees only files they have personally handled. A reviewer sees only the review queue. That scoping happens where the data is fetched, not by hiding buttons on a screen.
Clause 4.6 of our agreement requires it and the build honours it: production runs in the South African region, encrypted at rest. Your mail layer sits with a provider holding a current ISO 27001 certificate, number IS 642819, valid to August 2028.
Every control above is designed and specified. The document layer has been independently assessed and I hold the assessment. When your client's security team sends the questionnaire, the answers are already written.
Point-in-time recovery on the database and versioning on the document store, with the recovery point and the recovery time written into the agreement as numbers rather than adjectives. A restore is performed and timed before any live file moves, and repeated on a schedule. A backup nobody has ever restored is a belief, not a backup.
Every material action, meaning what changed, from what to what, by whom and when, kept for the life of the engagement unless you name a shorter period. It is held where the application itself cannot alter it, which is the only version of that promise worth anything.
You are told, by name and by phone, within 24 hours of my knowing, with what happened, what was affected and what I have done about it. Your attorney's position governs what is reported onward and when. I do not get to decide quietly that something was not serious enough to mention.
This is built by one person, and a procurement team is right to ask what happens if I disappear under a bus. The answer is not a promise about my health. It is the design document, the runbooks, the rules in plain text, and a repository whose checks run on every change. Those are the things that let somebody else pick it up.

You have applications running with real deadlines right now. Nothing moves onto the platform until you have approved how it happens and until there is a way back to your current process that works the same afternoon. I will propose the smallest safe version and you sign it off before any live file moves. That plan gets designed against your live caseload, not in advance of seeing it.
The system will hold passport scans, medical reports and qualification records. That is special personal information: lawful basis, retention periods, an operator agreement and a cross-border position all attach to it. Your attorney sets the position and I build to it.
The platform's judgement is deterministic and stays that way; that is what makes it defensible in front of the Department and your clients' auditors. On top of it sits an assistance layer that removes typing and catches mismatches: it reads a passport and asks the person to confirm, it audits a pack against the checklist and the route, it names any known refusal ground that applies, and later it will answer status questions from the record and draft the motivation paragraph a consultant then edits and signs. It never writes a date, a score or a section of the Act, every suggestion is confirmed by a person, every call is logged and metered, and nothing about your applicants leaves South Africa.
None of that layer is in this price, and none of it is switched on for you until it has been shown to work on a set of your own cases where the right answer is already known. You are hearing it from me rather than from a competitor's brochure because you are going to be asked, and the honest answer is more useful to you than an impressive one.
Also deliberately out of scope: anything that automates the submission itself; any model writing letter content or touching a score or a date; the qualification portal, because there is no interface to it and each application sits behind the applicant's own mailbox; any public-holiday calendar I have not been given a source for; outbound visas; and the radar in section 04, which is phase two.
The firms that surface against corporate work-visa searches in South Africa are IBN Immigration Solutions, Xpatweb, IMCOSA, Black Pen Immigration, Work Permit South Africa and Hassle Free Immigration. Black Pen holds a boutique corporate immigration award. Xpatweb markets a success rate. IBN markets its awards. They compete on reputation and on relationships, which is the ground you compete on and the ground you already say nobody can take from you.
I also went through the case-management and mobility platforms firms at this level run on, here and internationally. What matters is not which badge sits on the software. It is what the category can and cannot do.
Everything I found is status software. It records where a case has got to and tells a client the same. I went looking for the two things this build leads with. A scoring hold on a mandatory criterion, and a deadline engine that understands the date-of-entry trap. Neither appears in any product marketing I could find.
| The question a client actually asks | What the category does | What you would have |
|---|---|---|
| Where is my case? | Answers it well. This is what the category was built for. | Answers it too, from the same record your staff work in. |
| When is it actually due? | Stores the date somebody typed in. | Computes both readings of the rule, governs on the earlier, and adds the margin your own people work to. |
| Am I safe if I lodge today? | One date, no view. Safe or late. | Three bands. Exposed names the window where you were compliant as written and refused as applied. |
| What if the holiday calendar is missing? | Returns a date anyway. | Returns UNKNOWN and refuses to guess. A wrong date is worse than no date. |
| Will this application pass? | Not modelled. A human decides and hopes. | Scored, with the bands that turn on interpretation flagged rather than counted silently. |
| Does this letter contradict itself? | Not checked. It is a document store. | Every statutory citation checked against the route before the letter can be released. |
| What goes wrong in the next six months? | Cannot answer it. Nothing in the category models forward. | Day budgets running out, the next application in a chain, and which planned hires will be refused as packaged. |
| Whose rules are these? | The vendor's, applied to every market they sell into. | Yours. South African law, as your people actually practise it, encoded from your own refusals. |
That is the gap. Reputation gets you considered. Capacity, and the price floor that comes out of capacity, stops the conversation happening at all.
And it compounds where it matters most, which is your clients. A mobility manager at a multinational does not change supplier over a nicer portal. They change when an assignee is refused, when a day budget runs out unnoticed, when a renewal is lodged inside a window nobody flagged. Every one of those is a thing this system sees before it happens. The firms in this section will still be answering where a case is. You will be telling a client which six of their thirty secondments will be refused as packaged, and what to change. That is not a better service. It is a different conversation, and it is very hard to leave.

Your numbers, not mine. Two of them decide whether this is worth doing.
Your fee card gives a blended professional fee of about R7,350 an application. That weights core work visas at R10,500, the 11(1) family at R3,000, the 11(6) and 11(2) tier at around R4,000, and permanent residence at R15,000. Against the volume you gave me, that is the table below.
| Applications a month | Professional fees today | At +30% throughput | At +50% |
|---|---|---|---|
| 30 | R2,646,000 / yr | R3,439,800 / yr | R3,969,000 / yr |
| 40 | R3,528,000 / yr | R4,586,400 / yr | R5,292,000 / yr |
| 55 | R4,851,000 / yr | R6,306,300 / yr | R7,276,500 / yr |
At forty a month, a fifty percent gain is R1,764,000 more in professional fees a year. On a thirty percent margin that is R529,200 of profit you are not making today.
That gain is not people working faster. It is the ceiling moving. Today the number of applications you can carry is set by how many one consultant can hold in their head. That is why an influx hurts, and why a holiday hurts. Move the deadlines, the scoring and the document checks out of memory and the same team carries more without anyone working later.
What it costs to run, and who carries it.
Named now rather than later.
| Running cost | Roughly | Carried by |
|---|---|---|
| Hosting and the database | R1,520–3,150 / mo | You, at cost, no margin on it |
| Encrypted document storage | R175–545 / mo | You, at cost |
| Monitoring and alerting | R215–435 / mo | You, at cost |
| Everything used to build it | — | Me. Never on your invoice |
| Support after handover | — | Ninety days of defect fixing included, then a retainer or billed for what is used. Ninety rather than thirty because a firm depending on this needs a full quarter of real cases to find what is actually wrong with it |
One thing to say now rather than when it becomes relevant. Those figures are the floor for one environment, and they are a floor rather than a usage charge: the smallest database and the smallest service still cost that at zero volume. So a second environment, an airline running its own instance for example, carries its own floor from the day it exists, whether or not anybody has used it yet. I would rather you heard that now than at the point somebody asks for one.
No licence fee. No charge per seat. The infrastructure sits in your own cloud account in the South African region. You see the bill, and it goes with you.
Two costs sit with you rather than me. A penetration test before go-live, which procurement at Kellogg or KLM will ask to see. And your attorney's data-protection position, named in section 10. Neither is marked up by me.
My fee and the per-application arrangement are not in this document. They belong in the commercial agreement, which follows your sign-off on the scope in section 06. Agree what gets built first. The money is a shorter conversation once that is settled.
Everything above is one build for one firm. It was not designed as one.
There is a deliberate seam in it. The rules sit apart from the machinery that runs them. That is why the build refuses to guess when a calendar is missing, and why a rule change is a versioned edit rather than a rewrite. It is also why this can go further than South Africa. The machinery does not know which country it is in. Only the rules do.
I have routes of my own that this serves. The United Kingdom, where I work already and where corporate immigration has the same shape and the same refusal-on-a-technicality problem. Latin America, where I have an opening I have been holding rather than spending, because until now I had nothing worth walking in with. Those are mine to develop, and where the platform earns from them I would rather that ran through an arrangement with you than around you.
And you are not one company. Nash Group Mobility sits inside a group, and the parts of this that are not immigration-specific are not specific to visas either. The custody of sensitive documents. The deadline discipline. The forecasting. The client portal. Where any of that is useful to another business under your name, the work is already paid for.
And when you say you would give it to your customers, that is two different things with two very different price tags, so it is worth separating them now. The first is already in this build: an airline's mobility team signs in to your platform as a corporate client and sees only their own people. That is the client portal in Stage 3: no new environment, no new brand, nothing extra to buy. The second is an airline running its own instance, with their branding and their domain and possibly their own consultants. That is a separate project with its own environment and its own fee, and it is priced when you want it. The architecture is built so the second one stays cheap: one codebase for everyone, with what differs per client held in a configuration file rather than in code.
None of that is in this price and none of it is in this scope. It is here because a build plan that ends at handover is a transaction, and I am not proposing a transaction. The first thing we ship together is a system that stops your firm losing visas on a two-day gap. What it becomes after that is a conversation I would like us to be having in a year.
What happens next. Read it. Mark it up. Tell me what is wrong, missing, or not worth building. Section 06 is the one to argue with, and I would rather you argued with it now than in November. Nothing gets built until you have agreed it. When you are happy, the commercial agreement follows and the first payment starts the clock.
Tokelo Mogorosi · Conversion Forge · tk@weareconversionforge.uk
Confidential to Michael Nash and Rayne Mulder. Prepared 11 September 2026.