Turn off — they cannot get in again, starting immediately. It works even if the app is already open on their phone, and Face ID will not get them past it. This is the one to use if someone leaves.
Turn back on — undoes that. They use the same passcode as before.
Sign out everywhere — kicks them off every device they are signed in on, but they can log straight back in with their passcode. Use this if a phone is lost or lent out, not if someone leaves.
New passcode — sets a new one and signs them out everywhere at the same time, so the old passcode is dead the moment you save.
You cannot turn off your own account or sign yourself out here. That is on purpose, so you can never lock yourself out of your own books.
Turning someone off never deletes what they entered. Their past entries stay in the books with their name on them.
A passcode is nine letters and numbers in three groups, like ABC-DEF-123. Whoever you add will need it to log in the first time, so send it to them yourself. It is never shown again after you save it.
Every change on this page — adding someone, turning them off or on, signing them out, changing a passcode — is written to the permanent record with your name and the time. The passcode itself is never written anywhere.
Nothing in these books is ever deleted. Cancelling an entry (Undo, on the entry's own row under Books) leaves the row where it was, marked cancelled, with who did it, when, and why. This page is every one of those rows, of every kind, in one place.
It cancels the entry and puts every number back — the reports, the VAT position and the cash all move together. The row stays visible (greyed, under "show cancelled too") with the reason, so there is always a trail.
To undo a paid invoice, undo its payment first — the app will tell you if you try it the other way round.
An invoice already issued on the tax portal is never plainly undone — it is reversed with a credit note instead.
A closed month refuses changes. If an undo answers "that month is closed", the month must be reopened first — an owner-only step, with a reason. Closing and reopening now live on the Income Statement, next to the month you are looking at.
Undo is for wrong entries. A client who pays less than invoiced is not an undo — that is a credit note or a write-off.
Every Undo, Fix and Credit note button now sits on the row it belongs to, under Books: money in, money out, people and VAT.
Every account, and every pound that moved through it. Balances are computed from the movements below — the same rows the reports read — never typed in by hand.
Money only moves here when something real happens: a client pays, a bill or the payroll is paid, VAT is remitted, equipment is bought, or the owner draws. Each movement points back at the entry that caused it.
Cancelling an entry — Undo, on the entry's own row under Books — cancels its movement here too, so the two can never disagree. Every row that has been cancelled is listed on the Corrections page, with the reason.
The reserve account holds euros; its card shows euros first and the EGP value at the booked rates next to it.
Ticking a month off against the bank statement (reconciling) is not built yet — today this page is the truthful view, not the tick-off.
Every bill ever entered, newest first. Undo cancels one the safe way — the row stays, marked cancelled, with your name, the time and your reason. Fix does the same thing and enters the corrected bill in its place. Receipt holds the photo, and still works on a cancelled row: evidence outlives the undo.
Two different things, in this order. The roster is what your team costs every month — it is already counted in the profit and loss, whether or not anyone has been paid yet. A pay run below is what you actually paid them: it moves real cash out of a real account, once, for the whole month. Changing a salary changes the cost. Paying a run moves the money.
A pay run is the month's payroll as an event: draft it to see every payslip, confirm it when the numbers are agreed, then pay it — only paying moves cash, in one movement for the whole month.
Drafting and confirming move nothing — payroll cost is already counted from each person's salary. Paying posts the one cash movement, from the account you pick.
One live run per month. Cancelling a run puts the cash back and frees the month; the payslip lines stay on record.
Months up to May 2026 are recorded the old lump way and refuse a pay run on purpose.
Paying from the euro reserve needs the day's rate typed in — the app never invents an exchange rate.