People gathering at a Ngara Spaces venue
NGARA SPACES SANKARA LABS

CUSTOMER PLATFORM WORKSHOP · SEPTEMBER 2026

LIVE.
WORK. GATHER.
UNDERSTAND.

One trusted operating view across people, places, activity and money.

THE OPERATING VIEW

02 / 20

Four records become one operating view.

Ngara Spaces already produces visitor, venue, event and commercial data. The problem is that each source describes only one part of the relationship.

THE JOINPerson + place + time + sourceA stable profile connects consented touchpoints while every record keeps its origin.
THE RULEConfidence remains visibleObserved, imported, inferred and unidentified activity never become the same kind of fact.
THE RESULTComparable decisionsManagement can compare return visits, attendance, spend, space use and partner performance.
SHARED CONTEXTPROFILE · PLACE · TIME · SOURCE · CONSENTThese keys connect records without erasing their provenance or access rules.
01WHERE

PLACE

Site, block, venue, zone and touchpoint locate where an interaction occurred.

Enables venue and space comparison
02WHO

PEOPLE

Visitor, member, attendee and staff profiles establish the permitted relationship.

Enables repeat-visit and cohort analysis
03WHAT

ACTIVITY

Campaigns, bookings, check-ins and attendance observations describe what happened.

Enables funnel and attendance analysis
04VALUE

MONEY

Bookings, payments and referenced partner transactions show commercial value.

Enables revenue and partner attribution
THE CONNECTED VIEW ANSWERSWho came, what they did, where it happened, whether they returned and what value followed.

THE COMMERCIAL GAP

03 / 20

Activity is visible.
The relationship is not.

Bookings, till reports, attendance lists and website analytics exist as separate totals. Without shared identity and reliable references, Ngara Spaces cannot connect discovery, attendance and spend.

TODAYSeparate totals by channel, event and partner NEEDEDConnected evidence by person, visit, venue and period
QUESTIONEVIDENCE REQUIREDDECISION ENABLED
01Who came back?Stable profile + visit historyRetention, membership and follow-up
02What held attention?Attendance + bounded dwell evidenceProgramme format and scheduling
03Where did they engage?Venue + touchpoint activitySpace use and tenant support
04What did they spend?Booking payment + referenced exportRevenue and visit attribution
05Which partners drive value?Visits + revenue + match qualityCommercial agreement review
06What improves Ngara Spaces?Cohort and period comparisonProgramming and investment priorities

THE ECOSYSTEM

04 / 20

One block.
Different relationships.

The system applies a different data and access rule according to the operating relationship. A location on the same block does not automatically share the same customer model.

MEMBERSProfiles may persist across eligible workspace visits. Report members separately from casual visitors.
EVENTSNgara Spaces manages discovery, registration or booking, consent and attendance evidence.
OPERATING PARTNERSThe partner keeps its POS. A referenced monthly export connects spend to Ngara Spaces visits.
LEASE TENANTSTenants manage their own venue listing. They see guest data only for Ngara Spaces events they host, and only within that event.

RFID IN PLAIN LANGUAGE

05 / 20

UHF RFID · ULTRA-HIGH FREQUENCY RADIO IDENTIFICATION

A wristband confirms attendance without asking Jane to scan again.

A small wireless tag sits inside a wristband or card. A fixed reader detects that tag when it passes through a selected doorway.

WHY USE IT?Busy arrivals create queues and missed check-ins when every visitor must stop for another QR scan.
JANE’S PHASE 1 EVENT ARRIVAL18:24–18:26
01ASSIGN

Peter links RF-0482 to booking 0187

The temporary wristband receives a consented, event-specific association.

02DETECT

The event-door reader sees the tag once

Jane walks through normally. She does not tap or scan again.

03RECORD

Ngara Spaces records attendance

The event stores time, read point, source and confidence. The tag expires after the event.

WHAT THIS DOES NOT IMPLYNo GPSNo exact live locationNo reader in every roomNo continuous surveillance

HOW RFID WORKS ACROSS NGARA SPACES

06 / 20

Selected doorways produce useful evidence.

A temporary tag can be observed at calibrated entrances and venue thresholds. Ngara Spaces knows which selected read points Jane crossed, while the route between them remains unknown.

PHASE 1 · ONE EVENTProve the operating modelAssign the wristband, test one event-door read, measure misses or duplicates and give staff a recovery path.
PHASE 2 · SELECTED TRANSITIONSAdd readers where decisions depend on themEntrances record arrival candidates. Event doors confirm attendance. Shared hubs support approximate occupancy and dwell.
PLATFORM RULEGovern every observationRemove repeated signals, infer direction, attach confidence and aggregate reporting.
ACTIVE BLOCK · ILLUSTRATIVE READER PLANFINAL PLACEMENT FOLLOWS THE SITE WALK
ARRIVAL
PRECINCT WALK
R1PUBLIC ENTRANCEGATE AArrival or exit candidate
R2SHARED HUBNGARA COURTYARDTransition, approximate occupancy and dwell band
R3EVENT VENUESARAKASI HALLAttendance and capacity evidence
R4OPTIONAL VENUE THRESHOLDSOMA NAMI BOOKSVisit window if the use case justifies a reader
R5OPTIONAL EVENT DOORJIKONI STUDIOWorkshop attendance if required
NO READER PROPOSEDQR OR STAFF CHECK-INART CLUB KENYAUninstrumented until a clear operational purpose exists
PHASE 2 EXAMPLE · JANE’S OBSERVATIONS 18:20 R1 · Gate A18:24 R2 · Courtyard18:26 R3 · Sarakasi Hall KNOWN: selected transitions + event attendanceNOT CAPTURED: exact route or purchase · spend comes from the partner file

RFID ROOM + PRECINCT ARCHITECTURE

07 / 20

Door antennas feed shared readers. The platform creates the visit evidence.

Rooms need calibrated threshold antennas, not a reader in every room. Each nearby reader cluster buffers detections locally and sends secure batches to the UAP-owned Ngara Spaces platform.

NGARA SPACES ACTIVE BLOCK · PHYSICAL LAYER TO UAP-OWNED AWS
01
ROOMS + PRECINCTPassive tags cross selected thresholds
RF-0482Jane’s temporary event wristband
R1GATE AEntrance antenna pair
R2COURTYARDTransition antenna pair
R3SARAKASI HALLEvent-door antenna pair
R4+OPTIONAL ROOMSOnly where a use case is approved
Antennas connect by coax to a nearby secure reader cabinet.
COAX
02
BUILDING EDGEOne reader serves several nearby antennas
UHF READER CABINETReader ports · antenna tuning · secure mounting
EDGE GATEWAYLocal queueBurst filterClock syncDevice health
Managed Ethernet + UPS. Buffer locally when the internet link fails.
HTTPS BATCH
03
NGARA SPACES PLATFORMNormalize, classify and preserve provenance
NestJSRFID INGESTION ADAPTERAuthenticated reader batches
DeduplicateInfer directionCheck assignmentAttach confidence
AWS RDSZone event ledger AWS S3Short raw archive AWS CloudWatchReader health
GOVERNED EVENTS
04
OPERATIONS + INSIGHTRole-scoped views and alerts
Event attendanceEntry / exit candidatesApprox. occupancyDwell bandsReader health + alerts
MetabaseMETABASEPrecinct and tenant reporting
IDENTITY LINKStaff app assigns tag ↔ booking or profileAssociation has a purpose, validity window and automatic expiry.
ANONYMOUS FOOTFALLBidirectional counters remain a separate streamTotal visitors are never assumed to equal tagged visitors.
GOVERNANCESelected transitions onlyRole-based access · short raw retention · aggregate reporting by default.
A group taking part in a creative activity at Ngara Spaces

THE VISITOR JOURNEY

08 / 20

JANE WANJIKU · FIRST VISIT

One person.
One identity.
Many moments.

01ARRIVESTracked campaign linkUTM source · medium · campaign
02SELECTSNgara Spaces events pageEvent intent · still anonymous
03REGISTERSPhone + consentMixpanel journey identifies to profile
04BOOKSTicket + event QRServer-confirmed payment state
05ATTENDSTemporary RFID wristbandOne event-door read · attendance only
06RETURNSTracked follow-up linkAttribution continues into the next visit
UTM → MIXPANEL → PROFILE · 01HXT9Mixpanel explains the funnel. Ngara Spaces owns the customer record.

THE COMMERCIAL JOURNEY

09 / 20

Trust comes from a process that can be inspected.

A transaction file can be structurally valid and still carry no usable customer reference. Compliance must be measured partner by partner.

PARTNER · MONTHLY FILE MINIMUM EXPORT CONTRACT
  1. 01Partner and venue identifier
  2. 02Transaction or payment identifier
  3. 03Customer, booking or order reference
  4. 04Amount and currency
  5. 05Transaction timestamp
  6. 06Transaction status or correction reference
VALIDATE
PLATFORMSTRUCTURE + TOTALSDuplicates · states · exceptions
MATCH
IDENTITYDETERMINISTIC FIRSTInferences stay labelled
RECONCILE
FINANCEREVIEWABLE RESULTOriginal · correction · owner
Submission rule: Partners upload an XLSX or CSV file each month. Each row represents one transaction, and the platform preserves the original row for audit.

THE TRUTH MODEL

10 / 20

Every number carries its provenance.

Confidence is part of the data. The platform never promotes an estimate into an observed fact.

01

OBSERVED

We recorded it directly.

  • Registration
  • Ticket or check-in
  • QR touchpoint
  • Referenced transaction
HIGH CONFIDENCE
02

INFERRED

We derived it by a declared rule.

  • Visit boundary
  • Recorded engagement span
  • Time and venue match
  • Cross-block sequence
METHOD VISIBLE
03

UNIDENTIFIED

Service continued without identity.

  • Visitor declined
  • No usable phone
  • Group payment
  • Reference not captured
GAP REPORTED

THE OPERATING PLATFORM

11 / 20

One Ngara Spaces platform. Every interaction joins the same record.

Follow the signal from experience to evidence
NGARA SPACES PLATFORM · UAP-OWNED AWS ACCOUNT
01
NGARA SPACES EXPERIENCESFour ways into one customer record
VISITOR WEBCampaign · events · select · register · book
STAFF APPGuest list · check-in · RFID assignment
ADMIN CONSOLETenants · event insight · users + roles · audit
PARTNER PORTALOwn events · visitors · team · files
Next.jsReactExpo Next.js · React · Expo
SQLite offline outbox
02
SHARED PLATFORMOne governed contract and set of rules
NestJS
VERSIONED REST APINestJS · OpenAPI
Identity
+ consent
Events
+ bookings
Transactions
+ settlement
Tenancy
+ access
Reporting
+ audit
03
TRUSTED RECORDSDurable state, queues and evidence
Amazon RDSPostgreSQL

DATABASE OF RECORDRDS PostgreSQL · private · Multi-AZ · PITR

Amazon ElastiCacheRedis

JOBS + REPLAYElastiCache Redis · BullMQ retries

Amazon S3Amazon CloudFront

FILES + DELIVERYS3 evidence · CloudFront distribution

04
GOVERNED INSIGHTDefinitions people can trust
dbt

MODELdbt rules + lineage

Metabase

DECIDEMetabase dashboards

Amazon CloudWatchSentry OBSERVECloudWatch · Sentry · uptime
NGARA SPACES CONNECTIONSAdapters isolate change outside the core
MM-PESA + PAYMENTS✓SMS + OTP@EMAILTTICKETINGMXMIXPANEL ANALYTICSCSVPARTNER FILESRFRFID READ POINTS
OWNED, SECURED, REPEATABLEAWS Africa (Cape Town) · region confirmed in Phase 0
AWS Secrets ManagerSECRETSManaged credentials
TerraformINFRASTRUCTURETerraform as code
GitHub ActionsDELIVERYDev · staging · production

THE DELIVERY LOGIC

12 / 20

First make identity and attendance reliable. Then expand what Ngara Spaces can observe.

3 WEEKSPHASE 0

Define what counts

Journeys, consent, visit rules, permissions, partner export contract, RFID site survey and pilot measures.

APPROVED FOUNDATION
10 WEEKSPHASE 1

Operate the relationship

Visitor web, booking and payments; partner workspace; event-level RSVP insight; users, permissions, audit trail and a controlled RFID attendance pilot.

WORKING OPERATING PLATFORM
2 WEEKSSTABILISE

Prove daily operations

Training, field use, offline recovery, data-quality baselines, partner samples and pilot readiness.

CONTROLLED EVIDENCE
12 WEEKSPHASE 2

Connect movement + money

Expand RFID to selected transitions, then add occupancy, dwell, reader health, partner imports and reconciliation.

COMMERCIAL + PLACE INSIGHT

PHASE 1 · WHAT IS LIVE

13 / 20

A working operating platform by week 15.

Visitor, staff, partner and administration workflows launch together. RFID stays a bounded attendance pilot.

01VISITOR

Discover + attend

  • Events page and selection
  • Registration and consent
  • Booking, payment and event QR
  • Tracked follow-up links
02STAFF

Operate the day

  • Guest list with RSVP state
  • Check-in and assisted recovery
  • Temporary RFID assignment
  • One controlled attendance read
03PARTNER

Operate own space

  • Create events for review
  • Own visitors and attendance
  • Add scoped partner users
  • No cross-tenant access
04ADMIN

Run + account

  • Tenants and event publishing
  • Users, roles and permissions
  • Searchable admin audit trail
  • Event-level RSVP insights
05MEASUREMENT

Explain the result

  • Views → RSVPs → check-ins
  • UTM source and Mixpanel funnel
  • Confirmed attendance evidence
  • Event CSV and quality status
STAYS WITH PARTNERSMenus · venue ordering · point of sale · venue payments MONTHLY HANDOFFTransaction-level Excel or CSV · reference · amount · timestamp · status

PHASE 1 PILOT → PHASE 2 MOVEMENT INTELLIGENCE

14 / 20

QR starts the relationship.
RFID scales selected observations.

We keep the deliberate action where it builds trust, then remove repeated scanning only where passive observation has a clear purpose.

PHASE 1QR

Explicit, useful, low-cost.

  • Register and capture consent
  • Open an event pass
  • Support deliberate check-in
LIMITEvery scan needs intent. Repeated scanning creates queues, missed observations and biased movement data.
PILOT → EXPANSIONUHF RFID

Bounded first. Scalable next.

  • Assign a temporary Phase 1 event wristband
  • Confirm attendance at one controlled read point
  • Expand to selected Phase 2 transitions
TRUTHThe reader detects a tag—not a person’s exact location. Direction and presence remain calibrated observations.
01 · ASSIGN · PHASE 1JANE’S EVENT WRISTBANDTag RF-0482 ↔ booking 0187One event-door read · expires after event
CONSENTED LINK
02 · READ · PHASE 1 → 2RAW READER EVENT
TAGRF-0482Temporary identifier R3SARAKASI HALLReader + antenna TIME18:26:18Nairobi time RSSI−51 dBmSignal strength
NOT YET A VISITThe reader may emit several detections. Rules must remove repeated bursts, infer direction and attach confidence.
DEDUPE + CLASSIFY
03 · GOVERNZONE EVENTS
AttendanceEntry / exitApprox. occupancyDwell band
Role-based · short raw retention · aggregate by default

THE FIRST 15 WEEKS

15 / 20

Decisions first.
Working software every two weeks.

The programme reduces uncertainty before it compounds into build cost.

WEEKS 1–3

Definition

Model, journeys, privacy, access, partner contract, prototypes.

GATE: FOUNDATION APPROVED
WEEKS 4–7

Identity + publishing

Website structure, registration, consent history, content workflows.

DEMO: FIRST COMPLETE JOURNEY
WEEKS 8–11

Events + operations

Bookings, check-in, staff recovery, payments and offline capture.

DEMO: FIELD-READY OPERATIONS
WEEKS 12–15

Controlled launch

Training, pilot events, outage test, dashboards and acceptance.

GATE: PHASE 1 LIVE

THE OPERATING REALITY

16 / 20

The hardest risks live between the system and daily operations.

RISKCONTROLOWNER
Partner references disappearCompliance report by partner and monthCOMMERCIAL + FINANCE
RFID overclaims precisionCalibrated portals, confidence rules, exception path and explicit pilot acceptancePRODUCT + SITE OPS
Registration slows serviceUnder-60-second target and honest unidentified pathSITE OPERATIONS
Joint control stays on paperOperational request, withdrawal and partner-exit processLEGAL + PLATFORM
Coworking dominates averagesMembers remain a separate reporting populationPRODUCT + ANALYTICS

THE PILOT SCORECARD

17 / 20

Measure what the system controls. Baseline what operations influence.

SANKARA COMMITMENTSSYSTEM
100%Accepted offline records survive recovery
95%Queued records sync within ten minutes
<60sMedian first registration
<0.1%Duplicate activity created by retry
JOINT OPERATING OUTCOMESFIELD
75%Registration completion in controlled pilot
100%Pilot event totals reconcile
WEEK 2Set identified-visitor target after baseline
MONTHLYPartner arrival, validation and reference rate

THE WORKING MODEL

18 / 20

UAP keeps control while we carry delivery accountability.

Working software, decisions and documentation stay visible throughout the build.

ACCOUNTABLE TECHNICAL LEADKELVIN ONKUNDIArchitecture · delivery · production
PRODUCT OWNERBRIAN BICHAGEBacklog · journeys · acceptance
DECISION AUTHORITYUAP SPONSORPriorities · approvals · acceptance
PLANBUILDDEMONSTRATEDECIDE EVERY TWO WEEKS
UAP-OWNED CODEUAP-OWNED CLOUDREPOSITORY FROM DAY ONEEMBEDDED JUNIOR ENGINEER

INVESTMENT + OWNERSHIP

19 / 20

A staged commitment with a separately deliverable first phase.

All figures exclude VAT. UAP owns the commissioned source, architecture, data model, infrastructure configuration, design files and documentation.

FIRST PHASEKES 4.0MDefinition, visitor web, tenant and event admin, users, roles, identity, communications and controlled launchLIVE AT WEEK 15
FULL SCOPEKES 6.5MPhase 1 plus transaction reconciliation, selected RFID expansion, visit logic and partner reporting25–29 WEEKS
OWNERSHIP100% UAPCode, cloud account, data, documentation and operating controlNO LICENCE LOCK-IN
Ongoing operations after warranty: KES 250,000 per month, separately contracted.
An event stage inside a restored Ngara Spaces venue
NGARA SPACES SANKARA LABS

THE IMMEDIATE NEXT STEP

Three weeks to agree the operating model before we write the system around it.

APPROVED ARCHITECTUREWORKING PROTOTYPESPILOT SCORECARDRELEASE PLAN

FROM ONE ACTIVE BLOCK TO A REPEATABLE OPERATING MODEL.

APPENDIX · TECHNOLOGY CHOICES

Mainstream technology. Clear boundaries. Transferable ownership.

A modular application avoids early microservice overhead while preserving the interfaces needed to scale.

EXPERIENCES

Next.jsNext.jsWebsite, admin, partner portal
ReactReactShared web foundation
ExpoExpoNative staff application

PLATFORM

NestJSNestJSVersioned REST API
PostgreSQLPostgreSQLSystem of record and ledger
RedisRedis + BullMQJobs and replay

OPERATIONS

MetabaseMetabaseGoverned dashboards
TerraformTerraformReproducible infrastructure
GitHub ActionsGitHub ActionsBuild and deployment
SentrySentryApplication errors
AWS · UAP-OWNED ACCOUNT · CAPE TOWN REGION, SUBJECT TO LEGAL CONFIRMATIONRDS · S3 + CloudFront · ElastiCache · CloudWatch · Secrets Manager

APPENDIX · CORE DATA MODEL

The profile is stable. Relationships and activity accumulate around it.

IMMUTABLE IDPERSON PROFILEVerified phone · email · age range
VERSIONEDCONSENTPurpose · wording · source · time
CONFIGURABLEPERSON TYPEVisitor · attendee · member · staff
OBSERVEDACTIVITY LEDGERTouchpoint · time · site · source
AUDITABLETRANSACTIONCharge · tax · settlement · state
DERIVEDVISITRule version · evidence · confidence
PRECINCT MODELPLACEBlock · venue · zone · touchpoint

APPENDIX · PERMISSIONS + AUDIT

Each role reaches only the data required for its job.

ROLECUSTOMERCOMMERCIALCONTENTCORRECTIONS
MANAGEMENTPrecinct viewPortfolio totalsApproveReview
FINANCEReference onlyFull reconciliationNoneFinancial states
SITE + EVENT STAFFTask viewNoneEvent operationsAssisted recovery
OPERATING PARTNEROwn resultsOwn venueOwn listingSubmit correction
LEASE TENANTNoneNoneOwn listingNone

Every administrative action records the actor, action, affected record, scope, result, source and time. Sensitive changes also preserve the original and new values; audit records are append-only.