Skip to content
All guides

Compliance & Security · Updated September 2, 2026

Licences & the Compliance Calendar

A liquor licence is issued to a building and a VAT return is filed once by the business, so the calendar knows which premises a row belongs to, reminds more than once, and tells the people who can actually renew it.


Two kinds of row

Every row on the Compliance Calendar is either:

  • Per premises. A county liquor licence, a single business permit, a fire certificate: these are issued to a building. A group with four bars renews the same six licences four times over, on four different dates, with four different county officers.
  • Company-wide. The VAT return, filed once for the whole business whatever its branches.

The Premises column says which, with company-wide rows shown as Company-wide in italics. There is a Premises filter beside the status tabs, and a Premises picker on the obligation form whose hint puts it plainly: "A liquor licence is issued to a building; a VAT return is filed once for the business."

Somebody restricted to particular premises sees their own premises' rows plus every company-wide row. The VAT return is not one branch's business, but it is every branch's business to know it exists.

Kenya hospitality defaults

Provision Kenya defaults creates the rows a Kenyan bar, restaurant or nightclub has to keep current. It replaced a set of four payroll returns that came from the platform's earlier life, which is why a venue that provisioned defaults months ago may still be carrying PAYE and NSSF rows. Those are left alone: your calendar is your record, and nothing here deletes a filing somebody may be tracking.

ObligationScopeFrequency
County liquor licence (Alcoholic Drinks Control Act)premisesannual
Single Business Permit (county)premisesannual
Public health / food hygiene licencepremisesannual
Fire safety certificatepremisesannual
Tourism Regulatory Authority licencepremisesannual
Music copyright licence (MCSK / KAMP / PRISK)premisesannual
Food handlers' medical certificatespremisesevery 6 months
VAT return (VAT 3, by the 20th)companymonthly

The dialog asks for two things:

  • Premises. Leave it on "Company-wide filings only (VAT return)" and you get the VAT return and nothing else, because a building's liquor licence filed against the whole company is the exact shape this feature exists to end. Choose a premises and its seven licences are created. Run it again for each of your premises.
  • Renewal month, optional. If you know when these premises renew, say so and the annual licences are dated to the end of that month.

If you do not name a renewal month, the annual licences are dated 31 December, and that date is a guess. The dialog warns you before you press and the result says so afterwards. A seeded date is indistinguishable from a typed one once it is on the page, so correct each row as soon as you have the certificate in front of you. A wrong date is worse than a blank one, and the reason the row is written with a date at all is that a dateless obligation cannot be sorted, counted as due, or reminded about.

Provisioning is safe to run twice. Rows that already exist are skipped, and the result tells you how many were created and how many were already there.

One exception has its own answer. If your account is limited to particular premises, you may seed those premises' licences, but the company-wide VAT return is not yours to create. Rather than refusing the whole run, it creates the seven licences and leaves the VAT return, saying so in the dialog: "The VAT return was not added: it is company-wide and your account is limited to particular premises. Ask an administrator." That is counted separately from "already there", because the two look alike in a number and mean opposite things.

Several reminders, not one

A payroll return is a single act on a single day, so one reminder a week out was enough. A licence is not. Renewing a county liquor licence means an inspection to book, a bank slip to pay in, a queue at the county office and a certificate to collect, and the person told about it on the day it expires has already lost.

So each row carries a list of lead times, shown in the Reminders column and edited on the form as text: 30, 7, 0 by default. Start the work, chase the queue, today is the day. Commas or spaces both work.

The rules on that list:

  • At least one. An empty schedule is refused: "At least one reminder is needed. Use 0 for a reminder on the due date itself." It reads like a decision, but on a small list it is far likelier to be the last entry somebody deleted, and the failure would be silent and permanent, with the row sitting on the calendar looking tracked and never saying a word.
  • At most six, and none longer than 365 days. A lead longer than the annual cycle would fire for next year's renewal before this year's was dealt with.
  • Whole numbers of days only.

Each lead fires at most once per cycle, and each is recorded on its own, so the 30-day reminder never silences the 7-day one. If the sweep has not run for a while and two or three windows have opened together, you get one message at the most urgent of them rather than three copies of the same sentence, which is how people learn to ignore a channel.

Moving a due date by hand, or changing the schedule, starts the cycle fresh, so a reminder already sent for the old date does not silence the new one.

Who is told

The reminder goes to the obligation's owner where one is named, and to that person alone: an obligation with somebody's name on it should not wake the whole management team. The calendar screen has no owner picker today, so most rows have none.

Where no owner is named, or where the named person is no longer an active member of the company, it goes to everyone holding manage_compliance who can reach that premises. A manager pinned to Westlands is not told about Karen's fire certificate, and a company-wide row reaches every compliance manager. That is the general rule for anything the platform says about one branch: the event says which branch, and the recipients are worked out from it.

It arrives two ways: an in-app notification, which also pushes to the phone where somebody has the app installed and signed in, and an email from the Compliance Filing Due template. Turning the template off under Company Settings stops the email; the in-app notification and the push keep coming.

The sweep runs nightly at 02:00 UTC, buckets companies by their own timezone, and decides "due" and "overdue" on that company's calendar day rather than the server's.

Marking one filed

Mark filed on a row takes an optional reference (the iTax receipt number, the licence number the county wrote on the certificate) and an optional evidence file: a PDF, PNG, JPEG or WebP, and nothing else ("Only PDF or image files are accepted"). The row records who filed it and when, and the evidence is linked from the Evidence column afterwards.

Recurring rows roll forward on their own once they are filed or waived and their date has passed: the next period's date is set, the status returns to pending, and the previous cycle's evidence, reference and reminders are cleared. A pending row whose date passes is not advanced. It goes overdue and stays there, because auto-advancing would hide a missed filing. Six-monthly rows roll like the rest.

The rule about company-wide rows

Somebody limited to particular premises cannot create, edit, delete or file a company-wide obligation. They will see it, because it is every branch's business, and they cannot touch it: "A company-wide obligation is visible to every branch, so it can only be changed by someone who is not restricted to particular premises. Choose the premises this one belongs to, or ask a tenant administrator."

Marking filed answers to the same rule, and that half matters more than the edit. A bar manager pinned to Westlands marking the company's VAT return filed is exactly the authority the ladder withholds, and the damage is worse than a bad edit, because a filed row stops reminding anybody.

Un-pinning a row from a premises is treated as the same act as creating a company-wide one, since that is what it becomes.

Who can do what

GrantWhat it allowsSeeded to
view_complianceRead the calendarAdmin (add it to any role that needs it)
manage_complianceAdd, edit, delete, mark filed, provision defaults, and receive the remindersAdmin (add it to any role that needs it)

Out of the box only the Admin role holds either grant, so a compliance officer, an outlet manager who renews their own licences, or an auditor needs it added to their role, and adding manage_compliance is also what puts somebody on the reminder list. See Roles & Permissions and Compliance Documents.

FAQ

We have three bars. Do I press Provision three times? Yes. Once per premises, choosing that premises each time, plus one run with no premises chosen if the VAT return is not already there. Repeats are skipped, so there is no harm in an extra press.

All seven licences say 31 December. Is that right? Almost certainly not. That is the date used when nobody named a renewal month, and it is a guess by construction. Open each row and set the date on the certificate. If you know the month for a premises, you can also delete the guessed rows and provision again with the renewal month filled in.

A licence lapsed and nobody was reminded. Check three things, in order: the Reminders column on that row, since a schedule of just 0 warns you on the day and not before; the Premises column, since a per-premises row only reaches managers who can reach that premises; and who actually holds manage_compliance, because that is the recipient list. If nobody holds it, nothing is sent.

Why can I see the VAT return but not edit it? Because your account is limited to particular premises. A company-wide row is visible to every branch and changeable only by somebody who can see the whole business. Ask a tenant administrator.

Our food handlers' certificates are six-monthly. Is that supported? Yes. "Every 6 months" is one of the frequencies, and it rolls forward like the monthly and annual ones.

Can I get these reminders by SMS or WhatsApp? Not yet. In-app, push and email are the channels today.