Skip to content

Platform

An operating layer, not another dashboard.

Most platforms give you screens and leave the work to you. Payra inverts it: you state intent, agents prepare the case, and you decide. The interface exists to make that decision fast and well-evidenced.

The surfaces

What you actually work in

Mission Control

A decision desk, not a wall of numbers. It leads with what needs a human right now — proposals waiting, alerts escalated, onboarding blocked — and routes you straight there. Figures sit alongside as an ambient ribbon, because a metric you can't act on is decoration.

The approval queue

Every action an agent proposes arrives here with the evidence that produced it. Approve or reject, with a note that becomes part of the record. This is the only path that creates state at the card provider — there is no side door.

Fraud

A case-file console. Deterministic rules raise the alerts, an agent assembles the evidence and disposition, and the queue is worked as cases rather than rows. Escalation is the agent's ceiling; the freeze belongs to a person.

Customers & programmes

Cardholders, their cards and their activity, and the programme configuration behind them — spend controls, limits, the rules a card lives under. Changes to a live programme are proposed and approved, not typed into production.

Audit

The trail, readable. Every state change and every AI run, filterable by actor and entity, in plain language rather than raw records — so following what happened does not require a database client.

The agent, everywhere

The agent is a surface of every module rather than a chat bubble in a corner: scoped to whatever you are looking at, reachable from anywhere, and generated from the module registry so a new module inherits it automatically.

White-label

Your brand, your tenant, your data.

Payra is built to be run under someone else's name. Branding flows through the theme rather than being hard-coded, each tenant's data is isolated at the database by row-level security, and platform-only surfaces stay invisible to tenants entirely. The isolation is proven by a test that runs against the live database, not asserted in a diagram.

Underneath

Boring where it counts.

A three-node highly-available cluster with a synchronous database replica, so no acknowledged write is lost if a machine dies; secrets in a vault rather than in config; a web application firewall at the edge; deployments driven from version control so what is running is always what was reviewed. None of this is novel — that is the point.