Savika Special Ops

The shift you are reading

This screen used to show whatever was happening at the moment you opened it and nothing else, so a manager coming in at seven could not look at the night that had just ended. Everything below follows this choice.

The shift being booked on

One date and one shift for the whole register. Everything below — the control room, reaction and guarding — is who is standing for this shift, and the message that goes out is built from it rather than typed again.

Control room

Who is in the room and which seat they are working. The seat is chosen as they book on, not fixed to the person — somebody on Orex tonight may be 2IC tomorrow, and the shift record should say which.

Reaction

One row per response area. Booking an officer on here is the same record the opening kilo writes, so whichever comes first fills it in and the other one agrees with it.

Reaction managers

The shift manager and the two field managers book on the same way. Their callsigns are not response ground, so an empty one is not counted as an area needing cover — but who is riding under them, on what, is part of the shift.

Guarding

Who is standing each post. The roster — which officer belongs to which post — is set on the Guarding tab; this is the record of who actually pitched, who did not, and who was sent to cover.

Who worked this shift

Compiled off the register at the end of the shift, across the control room, reaction and guarding. Somebody who covered is on it because they worked. Somebody rostered whom nobody confirmed is listed separately, because the month only counts a shift a controller said was stood.

Shift message

The message that goes out when the shift is booked on, built from the register above rather than typed again. Guarding, the control room and reaction, each with who is not there and who took the post. Nothing is written here — correct it above and it changes.

Control room on duty

Who is in the room for the shift being captured. Read only — booking on and off happens once, on the Duty Register.

Shift being captured

Everything you add below is filed against this date, shift and kilo type. Capture the OPENING kilo at shift start and the CLOSING kilo at shift end — the system pairs them to work out distance, fuel used and rounds returned. Shift is which of the three is on — Alpha, Bravo or Charlie. Day or night is which half of the day they are working, and it is kept separate because a shift works both.

Add entry

Nothing is filled in for you. Callsign, vehicle, firearm and rounds are all selected from the message in front of you, every time — vehicles move between areas and officers move between callsigns, and a field that arrives already answered gets accepted without being read. The callsign is the first field of the control room message (MAN, R/BURG, A1, DV3) and identifies the post being worked, not the person.

Entries on this kilo 0

WhatsApp message

Built only from the entries on the shift selected above, in area order.

Shift register

Shift register

One row per officer per shift, newest first. A shift only produces usable analytics once both the opening and closing kilo are captured. The ten most recent are shown; the count under the table is always the full one.

Find a procedure

Search by anything — the site, the client, a word from the procedure itself. Everyone can read everything: an officer sent to cover an unfamiliar post should never find that the orders for it are somewhere they cannot get to.

Reading

Training record

What each officer has been taken through, and who is working a site whose orders nobody has shown them.

Working a site they have not been trained on

Taken from the guarding board — five or more shifts at a site with no training recorded against its orders.

Add or change a procedure

Changing one keeps the previous wording. If an officer followed the procedure as it stood in March, that version can still be produced.

Occurrence Book

The control room's running record. The OB number is issued by the system, in order, and cannot be chosen or changed. Nothing here can be edited or deleted once it is submitted — that is the whole point of an OB. If an entry is wrong, make a correcting entry against it; the original stays where it is and both are read together.

Only incidents already on record appear here. If the incident is opened later, attach this entry from the incident itself — an OB entry cannot be reopened to add the link.

The book

Newest first. Every number issued is shown — a gap in the numbering would mean an entry had been taken out, so there are none to find.

Log a callout

Every call reaction is dispatched to, as it happens. The response time is worked out from the two clocks — you enter when the call came in and when the vehicle arrived, and nothing else. Each one goes into the occurrence book as it is logged.

—

Callouts

Put out a BOLO

The message the group already reads, built as you fill this in and ready to copy. Everything here goes across except the internal reason, which is kept on the record below and is never on the message.

The one thing a BOLO cannot be without.

Whether the plates are the vehicle’s own decides whether the registration is worth looking for at all.

What a vehicle is picked out by at night. A plate is read at two metres and a white bakkie with a bull bar is seen at fifty.

The internal reason

This stays here. It is never on the message. The group is told what the vehicle did; this is why Savika is putting it out — who asked, who recognised it, what we were told and by whom. It is the line that answers “on whose authority did every vehicle in the company start stopping this car” a month later.

The message

Exactly what goes across, in your layout. The *asterisks* are WhatsApp’s bold and the > on the last two lines is its quote, so paste it there and they turn into formatting; paste it anywhere else and every word still reads. The internal reason is not on it.

BOLOs put out

Every one, with who put it out, why it went out on the group, why it went out at all, and whether it is still being looked for.

Report a problem

Waiting on a manager

All problems

How they were handled

Vehicle inspections

The routine inspection when a vehicle is called to the office. Pick it and the form arrives filled in from the register, the kilos and the last inspection — the callsign it runs, the reading on the clock, the date on the disc. Every item is answered on its own: right, put right today, or still wrong. What is still wrong goes into the message and onto the fault log. The message at the end is the one you already send.

Waiting for an inspection

Longest since anybody looked at it, first. The licence disc and the service are read off the register, so a vehicle that is due for something is due whether or not it has been inspected.

The inspection

This is what the message opens with, because that is what the group calls it.

The paper sheet asks for two names and they are not the same person: whoever serviced it, and the manager who tested it before it went back on the road.

Read off the windscreen. A later date is written back to the vehicle register; an earlier one is flagged rather than followed.

The checklist

Three answers, not two. OK is a tick. Fixed means it was wrong and was put right today — that is the line that goes at the top of the message — “Rear left brake light fitted”. Fault is something still wrong, and it shouts in the message instead of disappearing behind a tick. Press an answer again to take it back.

Set what an inspection covers

One standard inspection, and a list of its own for any vehicle that needs a different one. The standard here is a guess at what the yard already does — change it to what it actually is.

The sheet asks a full question because somebody signs under it. The WhatsApp message wants the name of the thing.

Pictures

The light that was fitted, the tyre that was not replaced. Kept whole and listed on the Documents tab, and any fault put on the log carries them with it.

Goes on the bottom of the printed sheet and on the end of the message.

The mechanic’s signature

Whoever serviced the vehicle signing that the work on this sheet was done. Their paper asks for two names because two people sign it — this is the other one. Optional; a sheet with no signature says so rather than leaving a blank where one would go.

—

Grounding a vehicle is your call, not a rule’s. Each fault goes on with this urgency, straight into the occurrence book, and from there it has a clock on it and a route to the workshop.

The message

Built as you fill the form, in the shape the group already reads. The *asterisks* are WhatsApp’s bold and the > on the last line is its quote.

Inspections already done

Site & reaction checks

The check a manager does standing at a gate or beside a vehicle. Pick what you are at and it arrives filled in from the board, the permits and the last kilo — your job is to say whether what is in front of you matches. Anything you correct is a finding and is kept as one. The message at the end is the one you already send, ready to copy.

What you found

Filled from the board. If somebody else is standing it, put their name here.

The post

The site’s own book, not this system’s.

The client’s own

What is on the post that Savika did not put there. It comes up filled in from the last check at this site, so it is confirmed rather than retyped — and anything permanent is worth adding to this site’s own list above, where it gets checked every time.

CCTV

Do the guards view cameras here?

The firearm and the vehicle

Luke, 18 September 2026: “Firearm with officer? confirm serial number & rounds” — these four arrive filled in off the live permit, so the job is to confirm them rather than type them. A serial the permit does not name, or a round that does not add up, is a finding below and is not on the equipment list as well: two lines for one firearm is two answers about one firearm.

The tyres, the lights, the roof lights, the spare and the licence disc are lines on the list below and are answered one at a time, so this tick is no longer standing over them. It goes across as your own line — Vehicle in good condition, no problems reported by officer.

What should be on site

Everything on this post’s list, answered one at a time. “All equipment working” covered everything and named nothing — this names what it covered, and anything that failed goes into the message rather than out of it. Press an answer again to take it back.

Set what should be on site

Every site and every reaction is checked against the standard list plus anything you add here. So a site that carries a kettle and a heater gets two lines of its own and keeps following the standard for the other eleven — change the standard once and it reaches all of them. Things already on the asset register come up on their own, with their serials, and are not asked for twice.

Leave it blank and the line has three answers. Fill it in and it gets a fourth in exactly these words — for something that is not missing because it was never meant to be there. It comes out of the count rather than counting as a fault.

Where you were

A fix from the phone is evidence you were standing there and comes with its own accuracy. A pin you tap onto the map is a note about where — useful, but not the same thing, and the check says which of the two it is. On a guarding site it is measured against where that site is on record.

Pictures

Kept whole, checksummed and listed on the Documents tab like every other file here — nothing is shrunk or re-encoded, because a photograph the portal has quietly altered is not evidence.

The officer’s signature

The officer on duty signing that you were here and that the above is what you both saw. It is what makes this check somebody else’s word as well as yours. Optional — a check with no signature is still a check, and the sheet says so rather than leaving a blank where one would go.

—

The message

Exactly what goes across, built as you fill the form. A check that failed says so here — a message that quietly leaves out the panic test because it did not work is worse than no check. The *asterisks* are WhatsApp’s bold and the > on the last line is its quote, so paste it there and they turn into formatting; paste it anywhere else and every word still reads.

Checks already done

The message can be sent again from here, and any check can be printed as a sheet on the company letterhead — everything the message leaves out on purpose is on it: every finding the check raised, where the phone said you were standing, and the photographs.

Firearm

What is signed out and how long it is covered for. The permit itself is issued by a manager — what is here is what they issued.

Permit photographs

Photograph every permit issued and file it here, for the record. Check that the permit number, the firearm and the dates can be read in the picture before you file it — a blurred photograph is not a record. On a phone Take a photo opens the camera; on a desktop both buttons open the file picker.

Which vehicle he is on. The control room uses this to know whose permit it is looking at.

Issue a warning

A written warning is a formal step. It records what happened, when, and who issued it, and it stands for a fixed period — after that it has lapsed and cannot be counted towards a further step. The officer signs to say they received it, which is not the same as agreeing with it.

The paper form as it was written up. Officers are not on the portal yet, so the paper is the original — attach it and the record and the paper stay together. If it is already signed, sign for it below at the same time.

Warnings

Apply for leave

Applying is not the same as being booked off. It goes to a manager, and until it is approved you are still on the roster.

—

Applications

Not dealt with

Items that have been passed from shift to shift without anyone closing them, and handovers nobody signed for. Being on the handover sheet is not the same as being handled.

Handover sheet

Everything the next shift needs to know. An item stays here until somebody says what was done about it — handing it on does not close it.

Closed off

What was actually done about each item, who dealt with it and when. Closing an item takes it off the sheet above, so this is the only place that answer can be read back — and an item closed before it was ever handed over shows nowhere else at all.

Hand over and acknowledge

The outgoing controller hands over, the incoming controller signs for it. Critical items have to be acknowledged one at a time — an acknowledge-all button on a critical fault is just a quicker way of not reading it.

Handover history

Log an incident

Capture it once, properly. The formatted report for the client group is generated from these fields — nobody retypes anything, and the times are recorded rather than remembered.

What the control room acted on — the panic, the zone, the phone call.

What the officer found on the ground. A panic button pressed during a break-in is a burglary; the panic is how we heard about it.

Click the spot. An address on its own cannot place a pin — working out where “14 Tana Road” is on the ground means sending that address to somebody else’s service, and this system does not do that with a client’s address. You know which gate; one click is all it takes, and the next incident at the same address is pinned for you.

The callsign the incident belongs to. This used to be asked twice on this screen — once as a picker and once as a free-text Callsign box a few lines down — and the two did not have to agree, which is how an incident stopped matching the response call it came from.

Report for the client

Built from the fields above. Check it, then copy and paste it into the client's group — the same way the kilo message works.

Follow up

Case numbers usually land a day or two later, and findings keep arriving after that. Add them here — the account written on the night is never overwritten, and every addition carries the date and the name of whoever made it.

Waiting on a case number

SAPS attended and nothing has come back yet. These are worth a phone call, not a statistic.

Incident register

Incidents map

Where the work is actually happening, from above. One marker per premises, sized by how many incidents are on it — because several incidents at one complex share a position exactly, and scattering them would hide eight of nine under the ninth.

Flat grey takes the colour out of the map so the pins are the only bright thing on it. Mapbox needs a key of yours, set in Data & Settings. None stops every outbound request.

The base

Counted, never stored. Every figure here is worked out from the dates on the contracts each time the screen is drawn — so a month nobody touched reads as a month nothing changed, and a cancellation captured three weeks late corrects the history instead of breaking it.

Won enquiries with no client record yet

An enquiry marked Won is a sale. It is not a client on the books until somebody says so, and nothing is counted until it is. Everything below was already typed by whoever took the call — putting them on the books only needs the date the contract was signed.

Put a client on the books

One customer, however many services they take. Somebody with a panel at home and a guard at their business is one client with two contracts — add the client here, then add each contract against them.

Their first contract

The date they start counting from. Every growth figure in this portal is worked out from it.

Leave blank if it is the same day. A contract signed in November that starts guarding in January is a client from November and a guarded site from January.

Cancellations

The half that decides whether any of this is honest. A win is something somebody wants on record; a cancellation is a phone call nobody has to log, so it gets its own door rather than a button hidden inside a client. Nothing leaves the base until it is recorded here, and nothing is recorded without a reason.

The last day you actually guard them or answer for them — not the day they phoned.

The client list

Take an enquiry

A prospective client calls in. Take the details while they are on the line — a name with no number is not a lead. Leave the assignment blank if the director has not yet decided who it goes to; it will show as waiting until someone is put against it. What the work is worth is not asked here — whoever picks it up adds that once they know what the client actually wants.

Off the staff listing. Left blank until the director decides.

Pipeline

Unassigned enquiries sort to the top, oldest first. Nothing should sit there.

Where the work comes from

Listing of staff

Everyone on the books, and the four things that decide whether a person can be posted at all: their PSIRA number and grade, the certificates behind them, and when those certificates run out. The tiles and the warnings are always here; the list itself waits to be asked for, so this screen is as long as what is wrong rather than as long as the payroll.

Add somebody to the list

The short name is what the kilos, the boards and the training records key on — usually the surname as the control room says it. Leave it blank and it is worked out; where the surname is already taken it becomes initials and a full stop, the way the radio says it. Everything else can be filled in later.

How the boards, the kilos and the training records hold them. Not a radio name — that is the callsign.

The company’s own number for them. Two people cannot share one.

Seen by a manager, HR or a director. Nobody else.

Left blank, the contact number is used.

A CSV with SIRANo, EmployeeNo, Name, IDNo, HighestGrade, Position and CerExpiry. Nobody is overwritten without matching, and a surname already in use gets a number rather than being merged.

Shifts worked this month

Every side of the operation: the control room, reaction and guarding, counted off the duty register rather than off the kilos. One shift is one person on one date on one half of the day, so somebody pulled from a post onto a vehicle counts once. A reaction officer and a guarding officer both carry a minimum of 17,33 shifts a month. A month is only judged once it has finished — the month in progress is shown for information, not as a shortfall.

Certificates falling due

Anything already lapsed, and anything inside the warning window. An officer with an expired PSIRA registration or firearm competency should not be posted.

Officer file

Search a name to open the file, or pick from the list.

Load absences off a roster

One line per person per day: name, date, D or N, post, roster — separated by tabs or pipes.

All officers

Officer performance

Officer performance

Split by the side of the operation each person actually worked in this period, off the boards rather than off their staff file — so a guard pulled onto a vehicle for a fortnight appears under both. Reliability is attendance only. Distance and fuel are averaged across that officer's fully reconciled shifts.

Absence

The absence screen lives here now. It was a second tab asking the same question of the same people, and a manager had to hold both in their head to answer anything. The months below are its own — they are not the period at the top of this tab, because a pattern is read a month at a time.

Who is missing shifts

Measured against how often each person was rostered, not in raw days. Four missed out of twenty is a worse record than five out of ninety, and a plain tally puts them the wrong way round.

Absence pattern by day and shift

Counts of recorded absences. A cluster in one column is what you are looking for.

When

By day of the week

By date of the month

Monday and Friday absence is the oldest pattern in shift work and is invisible a shift at a time. Payday is the 3rd, so the days after it are counted separately.

Worth a second look

Where the absence record disagrees with something else the system knows. A controller marking a sheet at six in the morning is a person, and this is going to be used in conversations that matter.

Every absence

Deployment

Reaction — officer to area

An officer working one area in more than 80% of their shifts is treated as a specialist for that post — useful for leave cover, and a risk if they are the only one who knows the post.

Control room — who has worked which seat

Off the control room board, not off anybody’s file. A seat somebody has actually sat is knowledge that can be called on tonight; a seat written against their name that they have never sat is not. CCTV has a column of its own because it is the one asked for by name.

Guarding — who has stood which site

Off the guarding board. A site an officer has stood before is a site they can be sent to at short notice with nobody walking them round it, and a site with one name against it is a single point of failure.

Area and officer pairing

Who habitually works which ground, as a share of their own shifts. Not the vehicle — a vehicle goes in for a service and the pairing it was measuring disappears with it, and the question this screen is asked is who to send when somebody is off.

Area cover depth

How many different officers have worked each area. A depth of 1 is a single point of failure.

Fuel

Consumption by officer

Bars used per 100 km, lower is better.

Consumption by vehicle

Km per bar, higher is better.

Detailed fuel analysis by vehicle

Only fully reconciled shifts with gauge readings at both ends are included. Refuelling mid-shift shows as negative consumption and is excluded from efficiency, flagged instead.

Monthly consumption trend

Vehicle fuel review

Everything known about one vehicle in one place — gauge readings and odometer from the control room, fills and slips from the garage, and any maintenance that might explain what you are seeing.

Monthly fuel price

South African fuel prices change on the first Wednesday of each month. Capture the new prices as they are announced — every cost figure in this system uses the price that was in force on the day of the shift or the fill, not a single flat rate.

Leave it on all garages for the announced price. Petrol is regulated and the same at every pump in the zone; diesel is the garage’s own, so it is worth capturing per garage.

Which prices are regulated?
Petrol has a single regulated pump price — every station in a zone must charge it, so anything above that on a statement is an overcharge and recoverable. Diesel is deregulated: only a wholesale list price is published and retailers set their own margin on top, so diesel variance is normal and is reported for negotiation rather than flagged as a fault.

Price history

Garage statement

Upload the monthly statement as CSV. Column names differ between garages and fuel card providers, so map them once — the mapping is remembered for next month.

Purchase reconciliation

Every fill checked against the price that was in force that day, the vehicle's tank capacity, and whether the vehicle was actually on duty.

Bought against burnt

The strongest fuel control available: litres paid for on the garage statement, against litres the gauge says were actually consumed over the same period. A persistent gap that the tank level does not explain is fuel leaving the vehicle without being driven.

Tracker

The daily trip street report, read against the odometer an officer typed in, against the callsign the vehicle was working, and against where it actually stood. The tracker is the one distance in this system nobody types by hand.

Load a tracking report

One report per vehicle per day. Load the PDF straight off the tracker, or paste the text out of it — several at once is fine either way, they are split on the header. Before it is filed you say which vehicle it is, which callsign it was working and who was on it: the report itself carries none of the three, and without them a month of tracking cannot be asked a question about a person or a piece of ground.

Long stand offs

Every stop longer than the stand-off threshold, longest first, with the street the vehicle was standing in when it stopped moving.

Patrol patterns

Which streets get driven, by whom, and how much of a shift goes on the same handful of them. A patrol concentrated on four streets is a different night from one spread over forty, and neither is visible a report at a time.

Streets driven

How the area was patrolled

The shift as the tracker recorded it, and the responses that came in while it was running. Reads whatever the filters above are set to — pick a callsign and it becomes that area’s patrol record. There are no coordinates in a DigitFMS street report, so nothing here is a map of the ground; it is a map of the night.

Tracker against odometer

Distance the tracker recorded, against the distance the shift’s odometer readings claim. They should agree. Where they do not, one of the two is wrong — and only one of them is typed by hand.

Fuel slips

Writing the slip, capturing the ones written on the pad, and matching every slip to the fill it produced. The money side — the price in force, the garage statement, litres bought against litres burnt — is on Fuel Costs, and the two reconcile against each other because both read the same slips and the same fills.

Write a petrol slip

The same slip the book holds, typed here and printed rather than written out by hand. The numbering carries on from the printed book, so a line on the station’s month-end statement traces back to the slip that authorised it and to whoever authorised it. Managers write these; a director can, and nobody else.

The slip is valid for this day and expires at midnight.

The slip is authorised for this station only.

Whoever writes the slip. No signature is collected — the name on it is the authorisation.

Printed large on the slip. An attendant reading it at the pump should not have to hunt for which fuel was authorised.

—

The number the next slip will carry.

The two dropdowns above are yours to keep. A station spelled four ways is a station nobody can reconcile against a statement.

Slips written on the pad

For old slips issued before this system, and any still written by hand. Writing a slip above is the authorisation — it is numbered and costed the moment it is written, and there is no second step. This panel is the other direction: a slip off the paper book that the month-end statement will have a line for, captured so it can be reconciled instead of coming back as fuel drawn against no authority at all.

The numbers will not run in step with the ones above. The book is its own series and this system starts at 00001, so a pad slip numbered 16248 sits in the list beside slip 00004 and neither moves the other. Capture the book’s number as it is written on the paper — that is what the garage quotes.

Slip reconciliation

Each slip matched to the fill it produced. Sign a line off once you are satisfied — that is the digital version of marking it green, except it records who accepted it and why, and it can be reported on afterwards.

Leave it empty for every month on record.

How far past the issue date to look for the matching fill. A slip is only valid on its issue day — anything found beyond that is paired so the money reconciles, then flagged as used after expiry.

Open a docket

A crime docket is opened against an incident the control room has already logged — the serious ones, where there is something to investigate and a client who will ask. Choosing the incident brings its own figures across, so nothing captured on the night is typed a second time. Every one of them can be corrected here.

Dockets

Anomalies

Detected anomalies

Recomputed from the underlying records every time this tab is opened. Nothing here is stored or acknowledged yet — treat it as a live worklist.

Thresholds in use

These are the rules actually applied by the code above. Adjust them in Data & Settings.

Permit photographs waiting to be captured

A manager has photographed a permit in the field and said who it is for and which callsign. Open the photograph, read what is written on it, and capture the details here — until that is done the system knows an officer is carrying, but not what on.

Firearms

Issue a firearm permit

The slip that puts a firearm in an officer's hands. Validity carries a time, not just a date, because a permit that lapses at 06:00 is a different thing from one that lapses at the end of the day. The same firearm normally passes to a second officer at shift change — issue it again for the next window, and use Hand to next shift on the register below to carry the permit number and firearm across.

The signed slip as it was issued. Attach it here and the officer sees it on their own screen — the permit and the paper it was written on stay together.

Permit register

Live permits first. A permit whose window has passed is shown as expired whether or not the firearm came back.

Firearm register

Rounds are reconciled by comparing the count booked out on the opening kilo against the count booked in on the closing kilo for the same officer and shift.

Movement history

Select a single firearm above to see its full chain of custody.

Fleet status

Current odometer is taken from the latest kilo captured for each vehicle, so service intervals track themselves off the data your controllers already enter. No separate mileage return is needed.

Log maintenance spend

Every line carries its purchase order, the same way the workshop ledger does. Spend that is not for one vehicle — parts bought into stock, or a mechanic's labour — goes against a cost centre instead.

Every total in the portal counts the invoice where there is one, and the signed-off value where there is not. The quote gets approved and the invoice gets paid, so the invoice is the money that actually left. Where the invoice comes in over the order, the difference is flagged on the row.

Monthly costing

Spend per vehicle per month with a year-to-date total — the view the workshop ledger was built to produce, generated straight off the records above.

Vehicle setup

Fuel grade drives which pump price applies. Tank capacity converts gauge bars into litres — set it per vehicle where they differ, otherwise the fleet default in Settings is used. Service interval and licence expiry drive the alerts above.

Maintenance history

Financial

Cost breakdown

Month on month

Actual recorded consumption only. No forecast is shown until at least three complete months of data exist.

Coverage

Officers on duty by day and shift

Reaction only. Every figure on this tab is worked out from the kilos, and a kilo is a reaction officer’s document — guarding posts and control room seats are in none of it. For those two, read the Duty Register and the Officers tab, which are split three ways.

Area coverage

Shifts each area was manned, against the number of shifts in the period.

Gaps and recommendations

Deployment map

Who held which callsign or site, month by month. Read off the printed name column of each roster — the part with no handwriting in it. One callsign can carry more than one officer, and it says so where it does.

What changed

Month on month. A callsign that stops running is the signal worth watching — it usually means a vehicle went or a client left, and neither shows up anywhere else in the system.

Areas with nobody on them

The first thing a response controller needs to know, before anything about who is absent.

Response board

Which officer is out on which area, in which vehicle. An officer whose firearm competency or driver’s licence has lapsed shows in red even when they are on the board — they cannot legally go out.

Reaction managers pulled onto areas

Reaction rarely carries spares, so an absence is covered by the reaction manager and their vehicle stands still. One night of that is normal; a month of it is a staffing figure with a rand value behind it.

Cover

Ranked on who knows the area. Anyone who cannot be armed or cannot drive is refused outright rather than ranked lower — those two are the law, not a preference.

Who knows which area

Read out of the kilos the control room already captures. Nobody enters this.

Import a roster

A roster says who works when. It rarely says which area, because everyone in the control room already knows — which is fine until that person is on leave. Paste it in and the area is predicted from where each officer has actually worked, with the confidence shown. Nothing is applied until you say so, and nothing already on the board is overwritten.

Response areas

Which areas need a vehicle on them each shift.

The room right now

Who has booked on, which shift they are, and how long they have been sitting there. Booking on and off is the control room’s own — this is the reading of it.

Not on, and not on leave

Everyone on the staff listing who runs the room, who is neither booked on for this shift nor booked off on leave. It is not an absence list — there is no control room roster for it to be measured against — it is who is unaccounted for on this shift, with the last shift they actually worked beside them.

On leave

The room’s own people only. Booked off by a manager on the Guarding screen, read here.

Shifts nobody booked on for

Every day and night over the period, and whether anyone put their name to it. A shift with no name behind it is a handover nobody can be asked about.

Procedures for the room

The room’s general orders, and the ones written for a controller by name. Written and reviewed on the SOPs screen; who has been taken through them is read here. A procedure nobody has been trained on is a procedure that exists only on paper.

Who knows what

Read out of what the room has actually done, not out of a form. Shifts worked, when they were last on, the shift they usually work, and what they have been signed off on.

Site visits

A manager standing on the site. What was looked at, what was found, and whether the guard on duty knew the orders for the post. Without this the only proof anybody went is the guard’s word for it.

Duty board

Who is posted where, who did not arrive, who covered. Fill this in as the shift starts and everything else in this tab looks after itself.

This board is the roster — which officer belongs to which post. Who actually pitched, who did not, and who covered is recorded once, on the Duty Register.

On leave

Who is off, and who goes off next. An officer on leave is never offered as cover, and rostering one onto a post is flagged on the board above rather than found out at the gate.

Who knows what

Built from the board, never typed in. Every shift an officer stands at a site is a shift they learned it — covering counts the same as being rostered.

Guarding sites

What each site needs: how many posts on each shift, the minimum PSIRA grade, and how many of those posts have to be filled by a female officer — sites that search female staff or visitors cannot be covered by anyone.

Overview

The operation in figures rather than lists. Everything here is drawn from what the shifts captured — nothing is typed in on this screen.

Where the callouts are

Every callsign, shaded by how much work came off it. Click one to read it out underneath. The darker it is, the more it carried.

Month by month

All five side by side. A director comparing a rise in callouts against a rise in fuel should not have to remember what the other one looked like.

Response times

Every timed callout in the period, grouped. The line is the limit — everything to the right of it is a callout somebody has to account for.

What each callsign costs

Bought and spent since, read off the asset register and the fuel and workshop records together.

KPIs

What each part of the operation is measured on, over the period chosen. Read from what the shifts captured — a figure nobody enters is a figure nobody can massage.

Managers

Site visits made, orders gone through with guards, training delivered and signed for, warnings issued.

Reaction SOPs

Whether the officers on a callsign have been taken through the procedure for it. Worked out from where they have actually been, not from a roster.

Response officers

Attributed from the board and the kilos — whoever was on the callsign when the call came in. An officer with no shifts on the board in this period does not appear.

Sites

When each site was last stood on, and whether it is being visited as often as it should be.

Put an asset on the register

Anything the company owns that goes out with a callsign or stands at a site. What it cost to buy, and what it has cost since, so the running cost of a vehicle or a post is a figure rather than a feeling.

Book spend against an asset

A repair, a replacement, a service. Fuel and workshop entries already captured against a vehicle are pulled in on their own — there is no need to type those twice.

What each callsign and site is costing

Everything issued to it, what it cost to buy, and what has been spent on it since — including the fuel and workshop entries already on the system for its vehicle.

The register

Worth looking at

Where the spend has stopped making sense — kit costing more to keep than to replace, and the same thing being bought over and over at one place.

What is out there

The same register the Assets tab holds, read by where things are rather than by what they cost. Add a radio here or add it there and it is one radio.

Everything issued to a post or a vehicle, and what each item has cost since the day it was bought — the purchase and every repair since.

Record a cost

A repair, a replacement, or anything bought for a site or vehicle that is not worth tracking as an item of its own.

Where the money went

By site and vehicle

By item

Spend log

Source documents

Every number in this system was read out of a document. The parsed rows are an interpretation; the file is the evidence. Each upload is kept exactly as it arrived and can be downloaded again unchanged.

Luke, 9 September 2026: a tracking report belongs to a vehicle and a callsign, and a folder of files called report(3).pdf belongs to nobody. Say which before you upload and the document is findable a month later. Both are optional — a garage statement is not about one vehicle.

PDFs are kept and retrievable, but the figures still have to be pasted in on the Fuel Costs or Deployment tab — reading a PDF needs a server, which this single file does not have. That is one of the things the Supabase portal fixes.

Backup and transfer

All data lives in this browser only. Export at least weekly — clearing browsing data, using a different browser, or a device failure loses everything otherwise.

CSV opens in Excel for reporting. JSON restores the roster and settings as well as the entries.

Fuel and cost assumptions

Gauge bars are an ordinal reading, not a volume. Cost figures anywhere in this system are an estimate derived from the values below — set them from your actual tank size and fuel invoices, and treat the output as indicative.

Count the segments on a full tank.

Leave blank to keep everything in bars.

Fleet default. What the car shows brimmed — needed to turn a range reading into litres.

Blank means no rand figures are shown.

Savika works to 10. Every callout over this is marked on the screen, in the extract and in the shift email.

72 under SAIDSA. A permit cannot be issued for longer than this.

17,33 is four shifts a week averaged over the year. Applies to reaction and guarding alike.

Override per vehicle on the Vehicles tab.

Only needed for the Mapbox Light style on the incidents map. It is a key on a Mapbox account with a bill attached, so it is yours to create and yours to revoke: Savika has none and this build will never fetch one. With it set, Mapbox receives the map squares being looked at and the key that asked for them, and nothing else — no address, no client name, no incident. Leave it blank and the map runs on OpenStreetMap, which is the default and needs no account at all.

Diesel is deregulated, so some margin is normal.

Connect to Supabase

The portal keeps everything in this browser. Supabase is the database that makes it one record shared by everybody — a BOLO a controller puts out that the manager can see, a check done at a gate that reaches the office. This is where the two are introduced.

Settings → API in the Supabase dashboard, or read it off the address bar: dashboard/project/this-bit with https:// in front and .supabase.co after it.

The anon key, not the service_role one. The anon key is meant to be public — it identifies the project and grants nothing on its own, because the rules in the database decide what anybody may see. The service_role key sits right under it on the same screen and ignores every one of those rules. It must never go in here, and nothing in this build will ever ask for it.

What signing in does and does not do. The database decides the role — which screens open, whose name goes on what, who may put out a BOLO. That part is real and cannot be picked on the page any more. The records are still kept in each browser, so signing in is not yet what protects them; that happens when the records themselves move into Supabase, one register at a time. Until then, treat a browser that has been signed in as one that holds a copy.

Sign in

The role picker at the top of this screen is a dropdown and always has been — it decides what you SEE, not what you may do. This is the real one: the database checks it, and it is the only thing that opens the staff listing.

Roster

Add or retire officers, vehicles, firearms and areas here. Removing an item does not touch historical records that already reference it.

All captured records 0

The raw entry log. Deleting a record here is permanent.

Savika Operations Dashboard · data held locally in this browser ·