Founding plan · v0.2 12 August 2026 Aspirtek / SoftNext 9 research missions

InvoiceNext

A stripped-down receivables and payables product for Oman and the UAE, with full five-corner e-invoicing native on day one and Arabic as the default language of the document — sold self-serve at a published price, into a market where not one accredited provider will quote you without a sales call.

v0.2 — name, database and AP scope now decided; this displaces the next2 demo-ready mandate
Source confidence
Verified read from the primary text or tested directly
Secondary credible third party, not the issuing body
Unverified claimed, not confirmed — do not act on alone
Section 01

The decisions

Nine parallel research missions produced roughly 10,000 lines of findings. These are the conclusions that survived them. Everything after this section is the evidence.

00
This is the main line now, not a side quest

Ruled 12 Aug 2026: InvoiceNext displaces the next2 demo-ready mandate and runs to completion — demo-ready with several providers integrated — before next2 resumes. Next2 is paused at 85 demoable / 86 partial / 32 missing of 204 capabilities, main green, everything deployed. Nothing is abandoned; the burn-down waits.

01
Oman first, the UAE second — and this is not the obvious choice

Oman has 47,700 VAT registrants against the UAE's ~743,000 in-scope businesses. We go there anyway because Wafeq, Qoyod, Daftra and Odoo have no Oman offering at all, Zoho prices it in USD with no e-invoicing claim, and we already hold a client, a reseller, an ASP relationship and a client-funded 313-field data dictionary there. Oman is the beachhead; the UAE is the market.

02
Launch on someone else's accreditation, behind our own adapter

We are a corner-1 software vendor. Creating an invoice is not a regulated activity in either country, and both regulators put the duty to appoint a provider on the taxpayer, not on us. SMARTeIS is primary for both jurisdictions; the adapter is already ~85% written and its documentation covers the UAE too.

03
Start ISO/IEC 27001 in Q4 2026 — the only item that cannot wait

OpenPeppol now requires ISO 27001 of every service provider for a first production certificate from 1 January 2027, and white-labelling does not exempt us. It takes 6–12 months and cannot be compressed. Defer it and the option to ever run our own access point moves 18 months away instead of three.

04
No local partner, and no equity for one

Oman permits a wholly-owned foreign company to be an accredited provider: mainland registration with two IT activities, capital of about €13,500, no fee, no Omani ownership requirement — and a new Omani entity may rely on its parent's operating experience. Keep Abu Retham as the reseller channel and Al Naba as a customer and reference.

05
Month one ships the fallback, not a connector

CSV/Excel import with a real validator, a public REST API with keys and a sandbox, and an email/SFTP drop. Four weeks buys 100% coverage; the first ERP connector takes three months and buys 30%. We sell compliance in month one and automation in month six — selling compliance late is fatal.

06
Separate repository, own VM, PostgreSQL, our own kernel

286 of next2's 321 migrations touch the tenancy and security schemas, interleaved throughout the chain — it cannot be split against a live database. And with PostgreSQL chosen, next2's raw T‑SQL kernel does not port at all. We take the patterns and the pure-Python modules, and write the tenancy layer fresh.

09
Full five-corner — payables as well as receivables

Not scope creep, the moat. Both regulators require a business to use one provider for both directions, so payables is part of the same purchase, not a second product — and Zoho Invoice has no payables at all. Inbound Peppol inbox, automatic bill registration, supplier liability, VAT input. No ledger.

07
Arabic is the default output, not a translation layer

Oman's VAT Executive Regulations make Arabic the default language of a tax invoice and English the conditional exception. One bilingual document with paired labels, mirrored RTL, Arabic typographically primary — rendered by WeasyPrint, which was the only engine of four to produce a clean, searchable Arabic text layer.

08
The unit economics are unresolved and gate the pricing model

The only published provider price is $1.10 per B2B invoice. Against a market ceiling of AED 57–80 per month, a customer issuing 100 invoices costs seven times what they pay. Nothing ships until we have a wholesale rate — and the structure of that rate matters roughly twelve times more than the number.

Section 02

The clock

Both mandates are phased by turnover. Our customer is in the later band of each, which is more build runway than the headline dates suggest — and the reason the connector business earns revenue before the app does.

Jurisdiction & bandAppoint provider byGo liveNote
UAE voluntary pilot1 Jul 2026Open now
UAE ≥ AED 50m30 Oct 20261 Jan 2027Extended from 31 Jul by MD 66/2026
UAE < AED 50m — our market31 Mar 20271 Jul 2027Large-ERP accounts are already gone; this is the app's market
UAE government31 Mar 20271 Oct 2027B2B and B2G only — B2C is out of scope
Oman pilot (100 firms)end Aug 2026Voluntary
Oman > OMR 5m1 Apr 2027Reset by Decision 189/2026, 9 Aug — most vendors and the OTA's own FAQ still publish the superseded schedule
Oman ≤ OMR 5m — our market1 Oct 2027

Verified — UAE dates from Ministerial Decisions 243, 244 of 2025 and 66 of 2026; Oman from Decision 189/2026. Three independent streams converged on the UAE dates.

Why this ordering falls out of the dates

The UAE's first wave is AED 50m+ businesses. They are not SMBs and they do not need our app — they run SAP, Sage, Oracle or Tally and need a bridge. Our app's buyers arrive on 1 Jul 2027 (UAE) and 1 Oct 2027 (Oman). So the connector business earns first and the product business earns second, roughly nine months apart. Build accordingly.

The compliance model, in one paragraph each

Both countries run Peppol five-corner networks, and neither has a clearance gate. The invoice travels supplier → supplier's provider → buyer's provider → buyer, while a tax data document is reported to the authority in parallel. Oman's own architecture document — authored by OpenPeppol — states the authority validates that document against Schematron only, explicitly "not for tax compliance."

Design consequence — do not copy Saudi

Because nothing blocks, a rejection can arrive after the customer already holds the invoice. The product needs compensating actions and an active withdrawal path, not a blocking gate. Building this by analogy to ZATCA's clearance model would be wrong in a way that only surfaces in production.

What is ours, and what is not

ConcernOwnerNote
UBL / PINT XML generationProviderSpec requires the provider to build and validate it
Digital signature & AS4 transportProviderNo signing or hashing requirement falls on us at all — a false gap in the April assessment
Seller UUIDUsSpec: "generated by the seller"; UUIDv5, deterministic
QR codeUsSpec: "the supplier must generate and print". No provider API returns one
ArchivalUsProviders hold documents in transit then delete. Retention sits on the taxpayer — so durable archive is a feature we can charge for
Pre-flight validationUsA business-rule rejection is non-retryable; catching it before submission is the whole game
IdempotencyUsNo provider offers an idempotency header; all require a client-minted key
Section 03

Market and the gap

743k
UAE businesses in scope — scope ignores VAT registration
47.7k
Oman VAT registrants
42
UAE accredited providers — none publishing a price
0
Mass-market SMB invoicing products that are accredited

The UAE's 156,000-business gap between VAT registrants and corporate-tax registrants is entirely sub-threshold businesses that are in scope and unserved. At AED 50–100 per month, one percent of the combined market is AED 3.8–7.6m ARR.

Where the gap actually is

Every mass-market SMB product — Zoho, Xero, QuickBooks, Odoo, Wafeq, Qoyod, Daftra — is absent from the accredited layer. Only Tally bridges both, and Tally is desktop-first with no Arabic UI. Meanwhile not one of the 42 accredited UAE providers publishes a price or offers self-serve signup.

Honest correction — the gap is contested, not empty

A direct competitor already exists. nazm.ae positions itself verbatim as "not an ASP — connect your accounting software to any accredited ASP through Nazm," which is architecturally the same product. Ten of the 42 accredited providers already claim Sage support, and two — Advintek and KGRN — run Sage-specific UAE landing pages and hold accreditation. What remains genuinely unoccupied is narrower than "the compliance bridge": it is the self-serve, published-price, Arabic-first end of it. Oman is where that is attackable, because there almost nobody is present at all.

Competitive set

ProductPositionEntry priceUAE accreditedOman
Zoho Invoice / BooksIncumbent; free tier is the price anchorAED 0 / 60NoNone
WafeqArabic-first, unlimited users — sets the ceilingAED 57NoNone
TallyDesktop, perpetual licence, no Arabic UIAED 2,340YesPartial
QoyodArabic-native, ~25k Saudi customersSAR 120Saudi onlyNone
DaftraAll-in-oneUSD 20NoNone

Two watch items

  • Zoho's UAE e-invoicing intentions are unknown and decisive. They already shipped full ZATCA Phase-2 clearance inside the free product for Saudi — so they can do this, and if they do it for the UAE the SMB opportunity narrows sharply. They have shipped nothing for Oman.
  • Odoo already runs its own Peppol access point and SMP but excludes the Gulf — a product decision, reversible quickly.
Section 04

ASP posture

Four providers, one abstraction, and a deliberate decision not to become one of them yet — with a single exception that has a hard deadline.

ProviderOmanUAESandboxStatus APIInbound / APVerdict
SMARTeISAccreditedPINT AEYesPer-cornerFull inbox + ack Primary, both countries. 22 endpoints, pre-flight validation, rate limits, durable queue. Adapter ~85% built. Its docs reference its own UAE product — one adapter, two jurisdictions.
ClearTaxAccreditedAccreditedYes4 states≤3-day windows Oman fallback and the GCC expansion path — the only one covering Saudi, Bahrain, Qatar and Kuwait. Best multi-tenant primitive of the four.
ComplyanceNot supportedAccredited3 envs7 statesRead-only UAE fallback, and the abstraction's stress test. Best-engineered API of the four; the most structurally different, so building it proves the interface.
TaxillaClaimedListedNoneNoneNone Commercial conversation only. Four endpoints, no status endpoint, no sandbox, three error codes, a bespoke per-customer transformation. Not buildable as documented.

Verified UAE listings — read from the Ministry of Finance register (42 entries). Unverified Taxilla's Oman accreditation — claimed on their own site with no date, number or register link; the OTA publishes no public directory we could find. Ask them for the reference in the commercial conversation.

Should we become an ASP ourselves?

Not yet — the financial case is off by one to two orders of magnitude. Break-even on per-message pricing is roughly 5,300 customers white-label or 9,200 building it ourselves. We have zero.

But negotiate structure, not price

With a per-tenant floor instead of per-message pricing, break-even falls to 443–767 customers — reachable. Peppox publicly charges €9–29 per company per month. The pricing structure matters about twelve times more than the rate. That is the single most valuable thing to win in the procurement sprint.

The one thing that cannot be deferred

OpenPeppol's Managing Committee mandated ISO/IEC 27001 for every Peppol service provider on 24 June 2026: "From 1 January 2027 onwards, a New Service Provider will only be issued a first Peppol PKI Production certificate if it holds a valid ISO/IEC 27001 certificate." White-labelling does not exempt us — OpenPeppol's own security FAQ says so. Certification takes 6–12 months.

This is also counterparty risk on the providers we are about to depend on: non-compliant providers are publicly blacklisted on 1 May 2028 and their certificates revoked on 1 Jun 2028. "Do you hold ISO 27001, and will you by October 2027?" is a pass/fail procurement question for all four.

Fast-track options, ranked

  1. Press all four for programmatic tenant provisioning — weeks, near-zero cost. This solves the real blocker without any accreditation. Complyance already exposes company creation and an integration-partner source type; ClearTax scopes every call by entity header.
  2. White-label an accredited access point under our brand — 1–3 months.
  3. Accredit through a wholly-owned Omani company on a licensed stack — 9–14 months, roughly €55–80k. The OTA sanctions every element of this in writing. This is the genuine fast-track.
  4. UAE only: be the product supplier, not the licensed provider — the amended decision lets the partner carry the licence, business-continuity certification and insurance while we carry ISO 27001. Design toward it; it is a later option.
  5. Acquire an accredited provider — 3–9 months, six to seven figures. Only worth revisiting if a small Oman provider is available cheaply.

Peppol certification, PKI, testbed status and ISO 27001 transfer between countries. National accreditation, the local entity and the country data specification do not.

Section 05

The product

Zoho Invoice feature-for-feature is the brief. Their help guide, API reference and pricing gave us the real surface — fourteen modules, and a boundary they draw sharply.

Core — Zoho parity

ModuleWhat it must doSize
CustomersContacts, contact persons, labelled tax identifiers, placeholder-composed address formats, portal access, statementsM
ItemsProduct and service master with tax category, unit of measure mapped to UNECE codes, price lists. Does not exist in next2 — build from zeroM
Quotes → InvoicesFull lifecycle: draft, sent, viewed, partially paid, paid, overdue, void. Progress invoicing by amount, percentage or lineL
Recurring invoicesSchedules, auto-charge with a retry ladder, suspend on exhaustion, excess-payment and credit application orderM
Credit & debit notesCoded reasons. Debit notes are a deliberate addition — Zoho ships them only in Saudi, and Oman mandates 383 as a distinct typeM
Payments receivedFIFO and specific allocation, part-payment, cap at outstanding. Logic lifts from next2 largely intactS
ExpensesCategories, receipt capture, per-organisation forwarding address, triage queueM
Time trackingProjects, tasks, timers, billable hours → invoiceM
Customer portalView, accept a quote, pay, see statement. This is what makes the product feel modernM
Reminders & dunningThree-level suppression, recipient axis, expected-payment-date series. Tiering engine lifts from next2S
ReportsThe standard set, all Excel-exportable — free, because export short-circuits inside the grid runnerM
SettingsOrganisation, tax rates, numbering series, templates, reminder rules, users, portal, email. Routinely underestimated at ~40% of the real buildL

Payables — the deliberate departure from Zoho

Zoho's own line is Invoice = receivables; Books = receivables, payables and accounting. We move payables inside the boundary and leave the ledger outside it. No chart of accounts, no journals, no bank feeds, no financial statements — but a full inbound side, because both regulators require a business to use one provider for both directions. A receivables-only product loses the deal to whoever does both.

Payables capabilityWhat it doesSize
Inbound Peppol inboxReceive supplier e-invoices at corner 4, filterable and paginatedM
Acknowledge / disputeWire actions, not internal status — the acknowledgement drives the corner 3→4 transition and the tax document to the authority; a dispute is a message-level rejectionM
Supplier masterMatch on tax identifier or Peppol ID, auto-create on first receiptS
Automatic bill registrationInbound document → payable, with supplier liability accrued and VAT input recordedL
Approval & payment schedulingLight approval route, due dates, AP aging, payment runsM
VAT input / output summaryBoth sides of the book in one placeS
Where this leads — and where the AI features land

Once we hold both directions of a business's invoicing, a VAT return helper is nearly free — the data is already reconciled and coded. That is also the natural home for the paid AI tier: duplicate-supplier-invoice detection, anomaly flags on inbound bills, coding suggestions, and supplier-behaviour analytics. None of it needs a general ledger.

The interface consequence: the payables inbox has buttons that change state on the Peppol network, which is unusual for an AP screen. Acknowledge and dispute must read as irreversible outbound actions, not as list-management. This is a specific thing to get right in the UI work.

Where we beat Zoho

  • The e-invoice cockpit. Already built — see below.
  • Retainer / prepayment invoices with a real UI. They exist in Zoho's API with no interface. Gulf contracting runs on advances, and Oman has a dedicated prepayment type (386).
  • Debit notes, period locking, immutable numbering, outbound webhooks, real role-based access — all absent from Zoho Invoice, all cheap for us, all things a compliance buyer asks about.
  • Arabic, properly. Zoho's Saudi edition does Arabic fields; we do the whole document and the whole interface.

The cockpit — already built, twice

The e-invoicing engine is a port, not a greenfield build. Two implementations exist: the JobNext production system (16 SQL migrations, a worker, QR, crypto, an ASP adapter layer, two UI screens, deployed) and a partial port already inside next2 in our exact target stackapi/app/einv/ at 1,571 lines, web/src/einv/ at 970 lines, three Alembic migrations, fully nav-wired, already fixing two defects the production version carries.

The best idea in the whole OIG build

The validator is the worklist. Everything derivable is derived, everything defaultable is defaulted, and what remains in "Needs attention" is genuinely a human decision — presented as seven dropdowns, each labelled by its business term and bound to the right code list, with Save & resubmit. For a self-serve SMB product that is the difference between compliance being terrifying and compliance being seven dropdowns. The enrichment layer is the main piece missing from the next2 port.

Arabic on day one

Oman's VAT Executive Regulations Article 144: "The issuance of the tax invoices shall be in Arabic. The tax invoice may be issued in English provided an Arabic translation is provided upon the Authority's request." Arabic is the default; English is the exception. The UAE imposes no language requirement but its authority can demand Arabic on audit.

PDF enginePresentation formsArabic title recoverableAmounts recoverable
WeasyPrint — already next2's engine0ExactExact
Chromium print-to-PDF504PartialExact
wkhtmltopdf469Not foundExact
ReportLab + reshaper280PartialNot found

Verified — four engines rendered the same bilingual Omani invoice, checked three ways. Presentation forms count baked-in shaped glyphs; zero means a clean logical-order text layer, which PDF/A-3 with embedded XML, search and audit all depend on.

A production bug caught in the probe

A phone number rendered reversed in every HTML engine when uninsulated. The standard fix — wrapping in <bdi>works in the browser and silently fails in WeasyPrint, because a digit-only string has no strong directional character. Correct in development, wrong in the customer's PDF. The fix is to inject Unicode isolate characters in the data layer, which then holds across browser, PDF, email and CSV. No mainstream i18n library does this for you.

Two more traps: ar-OM, ar-SA, ar-QA, ar-KW and ar-BH all default to Arabic-Indic numerals (ar-AE does not), so invoice numbers and tax registration numbers must be pinned to Western digits to match the machine-readable payload. And no production-grade Arabic font is installed on our build box — Noto Sans Arabic must be pinned as a build artifact, and it was the only candidate of five carrying tabular figures, without which decimal points do not align in an amounts column.

Connectors

Eighteen targets were assessed. The order is set by GCC installed base, not by API quality — and those turn out to be inversely correlated.

  • Month 1: CSV/Excel import with a real validator, a public REST API with keys and a sandbox, email/SFTP drop. The public API turns every GCC reseller and systems integrator into a channel building at their own cost.
  • Months 2–3: the on-prem agent and Tally together — one project, because Tally forces the agent to be genuinely general.
  • Months 3–4: the cloud tier — Zoho Books, QuickBooks Online, Xero, Odoo.
  • Months 4–6: SAP Business One, Sage 300, Dynamics 365 Business Central.
  • Beyond: deal-led only.
Design this in now, not later

On-prem write-back is inherently asynchronous. Saudi clears in about two seconds; the customer's Tally machine may not be switched on until tomorrow. CLEARED_PENDING_WRITEBACK must be a first-class state with retry, TTL and alerting — not an error. Also: no ERP field is large enough to hold a QR payload (300–700+ characters against 30–60 available), so status write-back belongs in a side table keyed on the document number, in every ERP.

Build the connectors; buy nothing. The unified-API vendors cover 7–14 of the 18, but Tally, Focus and Sage 300 are covered by none of them, our payload fits no unified model, and not one has a Middle East region — a live commercial objection when the payload is GCC tax data. The sharpest single opportunity found: UAE PINT AE for SAP Business One, where the incumbents are all chasing S/4HANA.

Section 06

Pricing

This section is a hypothesis, not a plan

Every number below moves once we have a wholesale provider rate. Nothing here should be published or quoted until the procurement sprint closes.

The constraint

Zoho Invoice is free, forever — two users, 500 invoices a year, no paid tier at all; you upgrade sideways to Zoho Books. Wafeq sets the practical ceiling at AED 57 per month with unlimited users. We cannot win on price. We win on the mandate.

Against that, the only published provider cost is $1.10 per B2B invoice at list. A customer issuing 100 invoices a month would cost roughly $110 in cost-of-sale against about $16 in revenue. Per-invoice provider pricing at anything near list destroys the subscription model outright.

Three things that soften it

  • That is a list price; volume wholesale rates will be materially lower — and none of the four will quote without a conversation.
  • Every UAE business gets 100 free e-invoices per customer per year by law. Our exchange cost at the true bottom of the market is zero, which is what makes a free tier viable.
  • Unlimited network access exists in the market at around €300 per year, and per-company pricing at €9–29 per month.

Working shape

TierWhoIndicativeIncludes
FreeMicro-businesses, the long tail0Invoicing, Arabic documents, and e-invoicing within the statutory free allowance. The allowance is the tier boundary — a regulatory gift, not a subsidy
StandardSMB, our coreAED 55–75/moUnlimited documents within a fair-use band, cockpit, AP inbox, portal, reminders
BridgeCompanies keeping their ERPper connectorConnector, agent, write-back, archive. Sold on the mandate, priced against the cost of non-compliance rather than against Zoho
Metered overageHigh-volume issuersper documentOnly above the fair-use band, and only once our own wholesale rate is known

Publishing a price is itself the differentiator. No accredited provider does. A business facing a deadline and unable to discover the cost of compliance without a sales call is the customer we are built for.

Section 07

Name and website

Decided: InvoiceNext, joining JobNext, EstimateNext, BidNext and TalentNext. Mizan was rejected as too wide, Raseeda because it reads as receipt rather than balance.

invoicenext.com.ai.io.ae.om
Status, 12 Aug 2026ParkedFreeFreeFreeFree
Act within 20 days

invoicenext.com was registered in 2020, sits parked at CrazyDomains with no address record and nothing served — and its registry expiry is 1 September 2026. Place a drop-catch backorder now, and register .ai, .io, .ae and .om immediately as cheap insurance. If the .com drops we take it; otherwise launch on .ai.

Verified availability — whois and dig, 12 Aug 2026, with random-string probes confirming the regional registries have no wildcard. Unverified trademark — no formal search has been run. Nothing gets registered until UAE Ministry of Economy, Oman MOCIIP and WIPO searches are complete.

Two things to carry into the trademark work

  • InvoiceNext is a descriptive mark, which is weak by construction — hard to register, hard to defend against an "InvoiceNow" or a "NextInvoice." A known trade-off, accepted for family fit and clarity.
  • FatooraNext was rejected for a reason worth recording. ZATCA's Saudi portal is Fatoora and Oman's system is Fawtara — both target markets plus the largest neighbouring one. Beyond trademark weakness, searching the brand name would return the government portal, making us permanently invisible for our own name; and a name one letter from the national tax platform risks reading as official endorsement, which is exactly wrong for a vendor that is deliberately not accredited.

Website

A separate marketing site from the application, both served by the existing reverse proxy, which already handles multiple hostnames with automatic certificates. The site's job is narrow and unusual for this market: state the price, state the deadline, and let someone sign up. A deadline countdown by turnover band, a two-question "am I in scope and when" checker, and pricing above the fold. Bilingual from the first commit, not retrofitted.

Section 08

Architecture

PostgreSQL, and what that does to reuse

Decided: PostgreSQL. Native row-level security, no per-tenant licensing, and the right engine for thousands of small tenants on a free tier — a different shape entirely from next2's handful of large ones.

The honest consequence

Next2's kernel is raw database access with no ORM, written in T‑SQL. On PostgreSQL it does not port — not statement by statement, not at all. The shared-kernel package idea therefore shrinks to pure-Python modules plus design patterns, and we write the tenancy and security layer fresh for Postgres. This is a simplification, not a loss: one kernel, one engine, no dialect abstraction to maintain across two products.

Repository structure

Separate repository, own VM, our own kernel. Independent of the database choice, the numbers rule out sharing next2's: 286 of its 321 migrations reference the core or security schemas, 214 of them altering the row-level security policy, with kernel DDL interleaved at chain positions 1, 2, 3, 5, 2950, 3000, 3050, 3120, 4020 and 5002. That chain cannot be split against a live production database, which rules out both "a module inside next2" and "a monorepo with a shared schema kernel."

What crosses over is a versioned pure-Python package — money and currency, the import framework core, the approvals effects registry, grid and export — plus the conformance-test technique already keeping next2's Python and TypeScript money modules in sync. No shared schema, no shared migration chain, no cross-repository revision link.

The binding constraint is CI, not hosting

A second website is one line in the reverse-proxy config. But there is one self-hosted runner with one job slot, and next2's own traffic already produces measured queue waits of 30 and 37 minutes against a 34.5-minute median. Adding a second product would slow both. A separate VM at roughly $30 per month resolves it. Incidentally, the current box holds 38 GB of reclaimable build cache — the deploy script prunes images but never the builder.

What we take from next2

ComponentVerdictNote
Money & currency moduleLift313 lines, zero non-standard imports, already knows OMR/BHD/KWD are 3 decimals and AED/SAR are 2
E-invoicing moduleLiftDescribed as already regime-neutral; only ~12 lines couple it to the ERP's invoice table
Import framework coreLift1,534 lines, fully domain-neutral
Grid + Excel exportLiftExport short-circuits inside the grid runner — every register gets it with no router changes
Approvals kernelLiftThe effects registry imports no domain module; 20 modules register into it
Print / PDF engineLiftWeasyPrint, server-side resolution — and the Arabic winner
Tenancy & security kernelRewriteDesign is unusually clean and worth copying — but it is T‑SQL, so PostgreSQL means writing it fresh
Inbound / AP railsBuildSupplier master, bill registration, acknowledge and dispute as wire actions — none of it exists
Dunning, aging, settlement allocationExtract~1,100 Python and 900 TypeScript lines lift; the engines are job-coupled but the invoice tables are not
Document numberingExtractNo central module exists — ten near-identical copies. Consolidate to one
Item / product masterBuildDoes not exist at all in next2
Tax determinationBuildCurrently one line of arithmetic — no reverse charge, place of supply or exempt categories
Signup, plans, meteringBuildNothing exists. For this product it is the entire commercial layer
Legacy screens moduleDiscard4,460 lines, every file embedding legacy SQL
Two defects not to inherit

Next2's invoices carry no customer identifier — identity joins on a free-text customer name. And aging sums across currencies blindly. Both are exactly the kind of thing that gets copied forward silently in a fork.

The one guard to carry over regardless

The information-architecture budget test: a CI-enforced numeric ceiling on navigation — total rows between 45 and 95, no workspace over 28, and every rail row must exist in the command palette. It is what stops a product accreting screens until it is unusable, and it is the most transferable thing in the repository.

Section 09

Build plan

Same methodology as next2: parallel worktree missions with disjoint ownership, each on its own database, a checkpointed build journal, adversarial review before merge, and a burn-down matrix as the single instrument of progress.

Nowweeks 0–4

Commercial and legal — consumes no engineering capacity

Owner-led and calendar-bound. None of it competes with the build.

  • Domain drop-catch on invoicenext.com before 1 September; register the other four now.
  • Settle the ISO 27001 certificate-holder question, then sign the engagement letter.
  • Procurement sprint across all four providers. Pass/fail: programmatic tenant provisioning, a per-tenant price floor, and ISO 27001 held or committed by Oct 2027.
  • Trademark searches before any registration.
  • Written questions to the Oman Tax Authority and the UAE Ministry of Finance — including Taxilla's accreditation reference.
  • Confirm the corner-1 reading with UAE tax counsel.
Phase 1weeks 1–6

Spine and the universal on-ramp

  • Repository, kernel package, CI, second VM, domain and certificates.
  • Tenancy, auth, signup — the self-serve flow next2 has never had.
  • Customers, items, invoices, credit and debit notes, receipts.
  • CSV/Excel import with a real validator; public REST API with keys and a sandbox.
  • Bilingual document rendering with the isolate-injection rule from the first commit.
Phase 2weeks 5–10

Compliance engine — both directions

  • Port the e-invoicing module out of next2 (Python lifts; the SQL layer is rewritten for Postgres) and cut the twelve-line ERP coupling.
  • Build the enrichment layer — the missing half, and the product's best idea.
  • Inbound rails: Peppol inbox, supplier matching, automatic bill registration, and acknowledge/dispute as wire actions.
  • SMARTeIS adapter completed and the four documented defects fixed; Complyance adapter built against its free sandbox as the abstraction's stress test.
  • QR constants verified against the OTA specification — currently best-guess.
  • Archive, audit trail, withdrawal and compensating actions.
Phase 3weeks 9–16

Product depth and the Arabic interface

  • Quotes, progress invoicing, recurring, retainers, expenses, time tracking.
  • Customer portal, reminders and dunning, reports.
  • Full Arabic interface with logical properties, pseudo-locale QA and RTL regression tests.
  • The settings surface — budgeted honestly at 40% of the build.
Phase 4weeks 13–24

Connectors and the Oman pilot

  • On-prem agent and Tally as one project.
  • Cloud tier: Zoho Books, QuickBooks Online, Xero, Odoo.
  • Oman pilot with a real customer through SMARTeIS.
  • Marketing site, published pricing, the scope-and-deadline checker.
Triggeron evidence

Reopen the accreditation question

Not on a date — on any of: provider spend reaching €130k a year or 2.6m documents; no vendor offering both self-serve provisioning and floor-free pricing; a counterparty failing its own ISO deadline; or a funding event.

Section 10

Decisions taken, and what remains

Resolved 12 August 2026. Three items remain open, and two of them have external clocks.

Settled

 QuestionRuling
APriority against the demo-ready mandateDisplaces it. Run to completion — demo-ready with several providers — then return to next2
BISO 27001Start it. Certify via the India entity for audit cost, scoped to the service end-to-end
CDatabasePostgreSQL
DNameInvoiceNext, joining the –Next family
EProvider conversationsOwner-led, handled separately
FScopeFull five-corner — payables as well as receivables. AI features later, on paid tiers

Open, with clocks

1
Which entity holds the ISO 27001 certificate — before the engagement letter

The scope statement is printed on the certificate and is what a regulator reads. OpenPeppol requires it of the entity holding the Peppol production certificate; Oman requires it of the accreditation applicant. If an Omani entity applies, a certificate naming only the India company may not satisfy. Resolve with the certification body and the OTA first — either a multi-site certificate covering both entities, or one issued to the applicant with India as an in-scope location. Expensive to change after the Stage 2 audit.

2
Domain backorder — 20 days

invoicenext.com expires 1 September 2026. Drop-catch now; register the other four immediately.

3
Trademark searches before any registration

UAE Ministry of Economy, Oman MOCIIP, WIPO. InvoiceNext is descriptive and therefore a weak mark — worth knowing what is already registered nearby before committing to signage.

ISO 27001 — the practical shape

  • It certifies a management system with a scope you define — neither inherently organisation-wide nor per-product. Scope it to the InvoiceNext service, not to "the India company's operations."
  • Use an accredited certification body (an IAF signatory — NABCB in India). Non-accredited certificates are cheap and get rejected.
  • Budget three months of the system genuinely operating before the Stage 2 audit. The 6–12 month estimate is real, not padded.
  • The UAE additionally requires ISO 22301 for business continuity — same scope logic, and cheaper done alongside than twice.
Section 11

What we don't know

Listed because the failure mode of a sweep this size is a confident, plausible, wrong finding surviving into the plan.

  • Unverified Taxilla's Oman accreditation. Claimed on their site with no date, number or register link. I previously reported the opposite based on a list published by a competitor — that was wrong to state as fact. The OTA appears to publish no public directory.
  • Unverified Oman's accredited-provider count. Two streams say 11 and 22. Neither is the OTA's own register.
  • Unverified Trademark clearance on every candidate name. No formal search has been run.
  • Unverified Which Sage X3 version ships the GraphQL API, and whether it is cloud-only. This single unknown gates our largest connector estimate. A one-day spike against the public sandbox resolves it.
  • Secondary Money precision in Oman — 2 or 3 decimals. The provider has not answered since 15 July. The architecture's own QR examples use 3; the scenario workbook assumes 2. Make it configurable.
  • Secondary The corner-1 "no accreditation needed" reading. Drawn from the operative texts; the Ministry has never published those exact words. Confirm with counsel before contracting.
  • Unverified Our own QR implementation. The tag numbers and UUID namespace in the existing code are explicitly best-guess constants, never validated against the OTA specification. Deliberately isolated so verification is a constants edit — but it is not done.
A live defect found along the way

The SMARTeIS adapter running in JobNext production has four bugs against the v2.1 specification — a wrong inbound list path, a malformed acknowledgement call, and an inbound mapper using outbound field names that would return empty records. That is the OIG pilot, not this product. It needs raising separately.

Section 12

Research index

All findings are on disk at ~/projects/einvoicing/research/. Roughly 10,000 lines with citations.

DocSubjectHeadline
01Zoho Invoice inventory2,419 lines — 14 modules, the settings surface, the boundary, and no paid tier
02Oman OTA / PINT-OM spec1,437 lines — full business-term table, all 20 use cases, code lists, validation rules
03SMARTeIS + TaxillaBoth flows, the capability flag set, and the proposed adapter interface
04Existing cockpit inventoryScreen-by-screen spec, portable domain logic, 13 lessons already paid for
05Mandate landscape1,130 lines, 73 citations — the dates, the accreditation answer, market sizing
06ERP connectors1,780 lines — 18 targets, the on-prem agent, build-versus-buy
07Arabic/RTL + namingFour PDF engines tested empirically; 40 names, domains checked live
08Next2 reuse600 lines — the reuse table, the i18n cost, the migration mechanism
09Complyance + ClearTaxThe four-way comparison and 14 new capability flags
10Becoming an ASP~20,500 words — requirements, break-even model, the ISO 27001 clock