**MercuryPay**

**Merchant Management System (ePay)**

Current System — Feature List

Prepared for: RFP 52-2026

System: epay-main (Laravel / PHP)

June 2026

**1. System Overview**

The MercuryPay Merchant Management System (epay-main) is a comprehensive Laravel-based web platform that manages the full lifecycle of merchant relationships — from initial onboarding and KYC verification through ongoing compliance screening, risk management, fee configuration, store/terminal management, and transaction reporting. It integrates with LSEG World-Check for sanctions and PEP screening, Signzy for document verification, multiple OCR engines for identity document extraction, and a range of payment gateways. The platform supports multiple user roles including Super Admin, Admin, Manager, Channel Partner, and Merchant with granular permission control.

**2. Merchant Onboarding**

**2.1 Admin-Side Onboarding Workflow**

|                                        |                                                                                                                                                                                               |
| -------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                            | **Description**                                                                                                                                                                               |
| **6-Step Onboarding Wizard**           | Structured multi-step form guiding admins through: Business Information, Registered Address, Authorized Signatory Details, Contact Person, Business Profile, and Bank Account for Settlement. |
| **Business Information Capture**       | Collect legal name, DBA name, entity type, country of incorporation, trade license number and expiry, VAT registration number, and trade licence document upload.                             |
| **Registered Address**                 | Full business address capture including P.O. Box, Emirate/State selection, contact telephone, and website URL with UAE-specific fields.                                                       |
| **Authorized Signatory Details**       | Capture personal information, designation, mobile and email with OTP validation, passport number, Emirates ID, nationality, and upload of passport, visa, and Emirates ID documents.          |
| **Contact Person Setup**               | Option to reuse authorized signatory details or enter a separate contact person as the primary communication contact.                                                                         |
| **Business Profile**                   | Capture business category/sub-category (MCC), years in business, annual turnover, employee count, store locations, and average transaction amounts.                                           |
| **Bank Account for Settlement**        | Collect account number, IBAN, account title, bank name (UAE bank selection), and settlement terms; upload bank statement.                                                                     |
| **Onboarding Progress Tracking**       | Visual step progress indicator; admin\_onboarding\_step field tracks progress (0=not started, 1–6=steps, 7=completed) separately from merchant self-service onboarding.                       |
| **Document Upload with OCR Auto-fill** | Upload identity documents (trade licence, passport, Emirates ID) and automatically pre-fill form fields using OCR extraction with confidence scoring.                                         |
| **Dedupe Check**                       | Before creating a new merchant application, run a deduplication check against existing merchant records to prevent duplicate onboarding.                                                      |
| **Merchant Invitation**                | Send email/WhatsApp invitation to the merchant to complete or review their onboarding application; resend invitation functionality included.                                                  |
| **Step Navigation (Back/Update)**      | Freely navigate back to earlier steps to update information; completed steps are preserved to allow corrections at any stage.                                                                 |

**2.2 Merchant Self-Service Onboarding**

|                                    |                                                                                                                                            |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| **Feature**                        | **Description**                                                                                                                            |
| **Self-Service Onboarding Portal** | Merchant-facing onboarding flow allowing merchants to complete their application, upload documents, and track their own onboarding status. |
| **First-Login Password Change**    | Merchants are required to change their password on first login before accessing any features, enforcing password hygiene from day one.     |
| **Onboarding Step Resume**         | Merchants can log back in and resume onboarding from the last saved step without losing previously entered data.                           |

**2.3 Contract Management**

|                                   |                                                                                                                                                             |
| --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                       | **Description**                                                                                                                                             |
| **Digital Contract Generation**   | Auto-generate a merchant agreement PDF from the onboarding data, combining cover sheet, terms & conditions, and merchant-specific details.                  |
| **Digital Signature (Signzy)**    | Send the generated contract to the merchant via Signzy for legally binding digital signature using UAE ID-verified signing.                                 |
| **Contract Preview & Download**   | Admin can preview the contract PDF in-browser and download the signed version for record-keeping.                                                           |
| **Contract Approval / Rejection** | Dedicated approval and rejection workflows for contracts with reason capture and email notification to the merchant.                                        |
| **Signzy Webhook Callbacks**      | Real-time webhook callbacks from Signzy for contract signing events (contract signed, signer callback, UAE report callback) to update status automatically. |
| **Merchant Declaration**          | Separate merchant declaration step with digital submission and viewable declaration record.                                                                 |

**2.4 Onboarding Approval Workflow**

|                                  |                                                                                                                                     |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                      | **Description**                                                                                                                     |
| **Send for Approval**            | Once all onboarding steps and documents are complete, submit the merchant application for compliance review and final approval.     |
| **Approve / Reject / Return**    | Compliance or admin users can approve, reject, or return the merchant application for corrections with reasons.                     |
| **Revert Approval**              | Un-approve a previously approved application if new information requires re-review.                                                 |
| **Merchant Stage Progress**      | Visual pipeline showing current stage (Application, KYC, Compliance, Approval, Active), with advance/decline/reverse/retry actions. |
| **MDR Assignment at Onboarding** | Assign the appropriate MDR (Merchant Discount Rate) template to the merchant as part of the onboarding completion step.             |
| **Waiting-for-Approval Screen**  | Dedicated screen shown to merchants whose application is submitted and pending admin review.                                        |

**3. KYC & Identity Verification**

**3.1 Document Verification**

|                                      |                                                                                                                                                                                |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Feature**                          | **Description**                                                                                                                                                                |
| **KYC Method Configuration**         | Admin-configurable KYC methods (e.g., Trade Licence, Passport, Emirates ID, Bank Statement, VAT Certificate) with required/optional designation and document type assignments. |
| **Document Upload & Storage**        | Secure document upload with file-type validation; documents stored with encryption and accessible only to authorised roles.                                                    |
| **Admin KYC Review Interface**       | Dedicated admin interface to review all submitted KYC documents, view OCR extraction results, compare against original documents, and annotate documents.                      |
| **Document Annotation**              | Annotate KYC documents with comments, highlight areas of concern, save and update annotations; generate annotation reports for audit trail.                                    |
| **KYC Approval / Rejection**         | Approve or reject individual KYC methods with reason; propagate status to overall KYC status and risk score.                                                                   |
| **Bulk Validation**                  | Trigger validation of multiple KYC documents in one action across all configured third-party validation providers.                                                             |
| **Third-Party Validation Dashboard** | Dashboard showing validation status, provider results, and statistics across all KYC validation providers.                                                                     |
| **KYC Completion Tracking**          | Track completion percentage and status (Pending, In Review, Approved, Rejected) per KYC method and overall for each merchant.                                                  |
| **Signed Contract Download**         | Download the signed merchant contract and audit certificate directly from the KYC request view.                                                                                |
| **Risk Profile Update from KYC**     | Update the merchant's risk profile based on KYC findings (nationality, business type, turnover) directly from the KYC review interface.                                        |

**3.2 OCR Document Processing**

|                                         |                                                                                                                                                                                       |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                             | **Description**                                                                                                                                                                       |
| **Multi-Engine OCR**                    | Support for multiple OCR engines: Tesseract (default), Google Vision API, AWS Textract, and Azure Form Recognizer — with automatic fallback to alternative engines for best accuracy. |
| **Intelligent Field Extraction**        | Extract structured fields from identity documents (passport number, name, DOB, expiry, nationality, address) using keyword-based, regex, position-based, and ML-pattern methods.      |
| **OCR Confidence Scoring**              | Field-level and document-level confidence scores for all OCR extraction results to indicate reliability before auto-population.                                                       |
| **Image Preprocessing**                 | Automatic image enhancement pipeline: deskewing, denoising, contrast enhancement, sharpening, and document type detection before OCR processing.                                      |
| **Auto-Population of Form Fields**      | OCR-extracted data automatically populates onboarding form fields, reducing manual data entry and transcription errors.                                                               |
| **OCR Configuration per Document Type** | Admin-configurable OCR settings per KYC method: engine selection, field mappings, confidence thresholds, and suggested configurations.                                                |
| **Image-to-PDF Conversion**             | Automatically convert uploaded image files (JPG/PNG) to PDF format for consistent document storage and processing.                                                                    |

**3.3 Signzy Integration**

|                                           |                                                                                                                                              |
| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                               | **Description**                                                                                                                              |
| **Aadhaar Verification**                  | Real-time Aadhaar number verification against UIDAI database with Verhoeff checksum validation, name matching, DOB and address verification. |
| **PAN Verification**                      | Verify PAN numbers with the Income Tax Department including PAN format validation, name matching, and PAN status check.                      |
| **UAE Report (Emirates ID Verification)** | Verify UAE Emirates ID with name, date of birth, and nationality extraction for UAE merchant onboarding.                                     |
| **Contract API Integration**              | Submit merchant contracts to Signzy for digital signing workflow; receive real-time status via webhook callbacks.                            |
| **Signzy Document Response Storage**      | Store and retrieve complete Signzy API responses for audit trail and re-verification purposes.                                               |

**4. LSEG (World-Check) Compliance Screening**

|                                    |                                                                                                                                                            |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                        | **Description**                                                                                                                                            |
| **Initial LSEG Case Screening**    | Submit merchant and authorized signatory details to LSEG World-Check for initial sanctions, PEP (Politically Exposed Person), and adverse media screening. |
| **Shareholder / UBO Screening**    | Screen individual shareholders and Ultimate Beneficial Owners (UBOs) against LSEG databases with per-shareholder results and bulk check-all option.        |
| **Ongoing Monitoring**             | Continuous LSEG watchlist monitoring for active merchants; automatic detection and ingestion of ongoing screening updates via webhooks.                    |
| **LSEG Webhook Integration**       | Real-time HMAC-validated webhooks from LSEG for screening update notifications, automatically triggering risk score recomputation.                         |
| **Report Generation & Download**   | Generate structured LSEG compliance reports and download them as PDF/CSV; check report generation status asynchronously.                                   |
| **Secondary Fields Configuration** | Configure additional secondary data fields sent to LSEG for enhanced screening accuracy (e.g., nationality, passport number, country of incorporation).    |
| **LSEG Settings Management**       | Admin interface to create, edit, and delete LSEG field settings; toggle individual fields on/off without code changes.                                     |
| **Manual LSEG Check Trigger**      | Admin can manually trigger an LSEG screening check for any merchant at any time outside the automated schedule.                                            |
| **Signzy Response View**           | View detailed Signzy API responses alongside LSEG results in the document review panel for a consolidated compliance picture.                              |
| **LSEG Cron Job Scheduling**       | Automated cron job to poll LSEG for ongoing screening updates on a scheduled basis; results stored and linked to merchant records.                         |

**5. Merchant Risk Management**

|                                      |                                                                                                                                                                                                   |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                          | **Description**                                                                                                                                                                                   |
| **Automated Risk Score Computation** | Calculate a composite merchant risk score across multiple dimensions: transaction behaviour, KYC data (country, business type, ownership), MCC code, annual turnover, and LSEG screening results. |
| **Risk Category Classification**     | Classify each merchant as Low Risk, Medium Risk, or High Risk based on computed score, with configurable thresholds.                                                                              |
| **Country Risk Tiers**               | Admin-maintained country risk tier table (High/Medium/Low) used as a factor in the merchant risk score computation.                                                                               |
| **Scheduled Periodic Reviews**       | Automated periodic risk reviews: Low Risk every 18 months (weekly cron), Medium Risk every 12 months, High Risk every 6 months; daily overdue review sweep.                                       |
| **Event-Based Auto-Recomputation**   | Risk score automatically recomputed when MCC, annual turnover, or KYC approval data changes, or when LSEG screening results are received.                                                         |
| **Computation Trigger Tracking**     | Each risk score computation records its trigger source (manual, scheduled review, field change, KYC approval, LSEG screening) for full audit trail.                                               |
| **Admin Risk Score Override**        | Admin can manually override a computed risk score or risk category with a reason, subject to audit logging.                                                                                       |
| **Risk Score Review Workflow**       | Structured review workflow where a compliance officer reviews the risk score, records a decision, and marks the review as complete.                                                               |
| **Risk Score Dashboard**             | Overview dashboard showing score distribution across merchants, high-risk merchant list, overdue reviews, and recent recomputations.                                                              |
| **Risk Score Export**                | Export the full merchant risk score table to CSV for reporting or regulatory submissions.                                                                                                         |
| **Compliance Queue**                 | Compliance queue that automatically populates with merchants requiring review; supports start-review, decision recording, reassignment, escalation, and request-for-info actions.                 |
| **Transaction Rules Engine**         | Configurable transaction rules per merchant with enable/disable toggle; rule changes logged with full audit trail.                                                                                |

**6. Credit Score & Loan Management**

**6.1 Merchant Credit Scoring**

|                                      |                                                                                                                                                                                   |
| ------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                          | **Description**                                                                                                                                                                   |
| **Credit Score Calculation**         | Compute a 120-point merchant credit score across 12 parameters in 3 categories: Transaction Behaviour (40 pts), Repayment & Bank Behaviour (30 pts), Business Stability (50 pts). |
| **Credit Categories**                | Classify merchants as Excellent (80–120), Good (66–79), Average (51–65), or Risky (below 51) based on credit score.                                                               |
| **Credit Score Recalculation**       | Admin can trigger a recalculation at any time using the latest transaction data; displays updated score immediately.                                                              |
| **Loan Eligibility Decision**        | Based on credit score, admin can mark a merchant as Approved, Rejected, or Under Review for loan eligibility.                                                                     |
| **Merchant Dashboard Credit Widget** | Credit score prominently displayed on the merchant's own dashboard and sidebar for self-awareness; read-only for merchants.                                                       |

**6.2 Loan Management**

|                              |                                                                                                                                                                          |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Feature**                  | **Description**                                                                                                                                                          |
| **Loan Products Management** | Admin creates and manages loan products per bank (Personal Loan, Business Loan, etc.) with processing charge type (flat/percentage), min/max amount, and min/max tenure. |
| **Loan Offers**              | Create and assign loan offers to merchants, linked to a bank and loan product, with amount and tenure parameters.                                                        |
| **Loan Applications**        | Merchant-facing loan application submission; admin reviews and processes applications with document upload and KYC verification.                                         |
| **Bank-Scoped Loan Access**  | Loan features are scoped to specific banks; each bank independently enables/disables the loan feature.                                                                   |
| **Loan KYC**                 | Dedicated KYC process for loan applications separate from merchant onboarding KYC.                                                                                       |
| **Loan REST API**            | RESTful API endpoints for loan product, offer, and application management for integration with external lending systems.                                                 |

**7. MDR & Fee Management**

|                                         |                                                                                                                                        |
| --------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                             | **Description**                                                                                                                        |
| **MDR Template Management**             | Create and manage Merchant Discount Rate templates with transaction type rates (Sale, Refund, QR, etc.) as flat or percentage values.  |
| **MDR Template Assignment**             | Assign MDR templates to merchants at onboarding or post-onboarding; merchants can only have one active template at a time.             |
| **MDR CSV Import**                      | Bulk import MDR rate data from CSV files; comprehensive import with validation and error reporting.                                    |
| **Merchant-Specific Fee Configuration** | Override template fees with merchant-specific values: transaction fees, fixed fees, settlement fees, chargeback fees, and refund fees. |
| **Fee Calculation Preview**             | Real-time calculation preview showing effective fees for different transaction amounts to verify fee structure before saving.          |
| **Subscription Fees**                   | Create and manage subscription fee plans with billing cycles; toggle plan status active/inactive.                                      |
| **Charge Management**                   | Manage one-time and recurring charges applied to merchants beyond standard MDR.                                                        |
| **MDR API**                             | REST API endpoint for querying merchant MDR rates for integration with the transaction switch.                                         |

**8. MCC Management**

|                                    |                                                                                                                        |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| **Feature**                        | **Description**                                                                                                        |
| **MCC Directory**                  | Maintain a full directory of Merchant Category Codes with descriptions and risk profiles (Low / Moderate / High risk). |
| **MCC Assignment**                 | Assign one or more MCCs to a merchant with effective dates; audit-logged for compliance.                               |
| **MCC Audit Log**                  | Full audit trail of all MCC assignments and changes per merchant with timestamp and operator details.                  |
| **MCC Risk Profile in Risk Score** | MCC risk classification automatically fed into the merchant risk scoring algorithm to reflect business-type risk.      |

**9. Store & Terminal Management**

|                                   |                                                                                                                                 |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                       | **Description**                                                                                                                 |
| **Store / Branch Management**     | Create and manage merchant stores (branches/locations) with address, contact details, product type, and quantity.               |
| **Bulk Store Upload (CSV)**       | Upload a list of stores via CSV template including SMID (15-digit) and STID (8-digit) identifiers for batch creation.           |
| **SMID / STID Management**        | Assign and manage Sub-Merchant IDs (SMID, 15 digits) and Sub-Terminal IDs (STID, 8 digits) per store for provider routing.      |
| **Terminal (Device) Assignment**  | Assign physical POS terminals (Shukria terminals) to merchant accounts and stores; update or force-update terminal assignments. |
| **Device Management**             | Track deployed devices per merchant with model, serial number, and current assignment; add new devices via admin interface.     |
| **Provider Enrollment per Store** | Enrol each store with one or more payment providers (AANI, AlipayPlus, WeChat, UPI); track enrollment status per provider.      |
| **Virtual IBAN for AANI**         | Generate a UAE-compliant Virtual IBAN for each merchant for AANI enrollment; mapped to the merchant's actual settlement IBAN.   |
| **Merchant Reference Update**     | Update the merchant reference identifier used by external systems without re-running the full onboarding flow.                  |
| **Store List Template Download**  | Download a pre-formatted CSV template for bulk store uploads with SMID/STID sample data and field instructions.                 |

**10. Channel Partner Management**

|                                     |                                                                                                                                        |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                         | **Description**                                                                                                                        |
| **Channel Partner Role**            | Dedicated Channel Partner role that can manage their own team members and view all merchants created by themselves and their team.     |
| **Team Member Management**          | Channel Partners can add, edit, and remove team members via a self-service CRUD UI without admin intervention.                         |
| **Merchant Attribution**            | Each merchant created by a team member is automatically attributed to the Channel Partner for reporting and commission purposes.       |
| **Strict Data Isolation**           | Team Members can only see merchants they personally created; cross-team visibility is blocked (403 Forbidden for unauthorized access). |
| **Activity & Performance Tracking** | View individual team member performance metrics including merchant creation count and activity history.                                |
| **Sales Dashboard**                 | Dedicated sales dashboard for Channel Partners and Sales users showing merchant pipeline, active merchants, and revenue metrics.       |

**11. Transaction Management**

|                             |                                                                                                                                                       |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                 | **Description**                                                                                                                                       |
| **Transaction History**     | Full transaction listing for all merchants with filters by date range, type, status, amount, and merchant; supports data table pagination and search. |
| **Transaction Detail View** | Detailed view of individual transactions including ISO 8583 fields, gateway response, timestamps, and linked merchant/store data.                     |
| **Transfer Management**     | View and manage fund transfers between accounts; data table with filters and export.                                                                  |
| **Deposit Management**      | Review, approve, and reject merchant deposit requests; history view with status tracking.                                                             |
| **Request Money**           | View incoming and outgoing money request transactions across all merchants.                                                                           |
| **Payout Management**       | Process and track merchant payouts to their registered bank accounts.                                                                                 |
| **QR Payment Records**      | View all QR-based payment transactions across providers (AANI, AlipayPlus, WeChat, UPI) with provider-specific detail.                                |
| **Dispute Management**      | Manage transaction disputes with document upload, comment thread, and status tracking (Open, In Review, Resolved, Rejected).                          |
| **Transaction Receipt**     | Generate and view digital transaction receipts; publicly accessible via unique URL for merchant/customer sharing.                                     |

**12. Settlement & Reconciliation**

|                                |                                                                                                                            |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                    | **Description**                                                                                                            |
| **Merchant Settlement View**   | View settlement records per merchant including batch number, settlement date, gross/net amounts, MDR deducted, and status. |
| **Settlement Report**          | Generate settlement reports for date ranges; downloadable for accounting and reconciliation.                               |
| **Bank Account Configuration** | Configure and update the merchant's settlement bank account (IBAN, account number, bank name) post-onboarding.             |
| **Income & Charge Tracking**   | Track all income charges (MDR collected) and deductions (refunds, chargebacks) separately per merchant for reconciliation. |

**13. Payment Gateway Integrations**

|                                     |                                                                                                                                                                                         |
| ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                         | **Description**                                                                                                                                                                         |
| **Payment Link (Single Charge)**    | Create unique payment links for one-time charges; customers pay via a hosted page with gateway selection.                                                                               |
| **Invoice Payment**                 | Generate branded invoice PDFs and share a payment link; customers select gateway and complete payment online.                                                                           |
| **QR Code Payment**                 | Generate merchant QR codes; customers scan and pay via their mobile wallet without a physical card.                                                                                     |
| **Donation Payment**                | Create donation payment pages with configurable amounts and causes; donors pay via any configured gateway.                                                                              |
| **Website Form Payments**           | Embed payment-enabled forms on merchant websites; form submissions trigger payment collection via the configured gateway.                                                               |
| **Subscription / Payment Plans**    | Create recurring payment plans; subscribers are automatically billed on the configured cycle via gateway tokenization.                                                                  |
| **Multi-Gateway Support**           | Built-in integrations with PayPal, Stripe, Mollie, Paystack, Razorpay, Worldline, MomentPay, Flutterwave, Thawani, Instamojo, ToyyibPay, PayU, Mercado Pago, and Manual/Custom gateway. |
| **Gateway Configuration**           | Admin interface to enable/disable gateways and configure API credentials per gateway; gateway settings per currency.                                                                    |
| **Payment Success / Failure Pages** | Branded success and failure landing pages after payment completion with order summary and next-steps guidance.                                                                          |

**14. User, Role & Access Management**

|                                             |                                                                                                                                                                  |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                                 | **Description**                                                                                                                                                  |
| **Role-Based Access Control (RBAC)**        | Granular permission system with roles (Super Admin, Admin, Manager, Sales, Channel Partner, Team Member, Merchant) and individual permission assignments.        |
| **Role Management**                         | Create, edit, and delete custom roles; assign fine-grained permissions per role via a permission matrix interface.                                               |
| **User Management**                         | Create and manage admin/merchant user accounts; assign roles, reset passwords, enable/disable accounts.                                                          |
| **Multi-Factor Authentication (MFA)**       | TOTP-based (Time-Based One-Time Password) MFA with QR code setup, backup recovery codes, and admin-enforced enable/disable per user.                             |
| **OTP Password Reset**                      | Email-based OTP (One-Time Password) for secure password reset flow as an alternative to link-based reset.                                                        |
| **Password Complexity Policy**              | Configurable password rules: minimum/maximum length, uppercase, lowercase, numbers, special characters requirements; blocks common passwords.                    |
| **Password History**                        | Prevent reuse of the last N passwords (configurable); enforced on every password change or reset.                                                                |
| **Account Lockout**                         | Lock accounts after configurable number of failed login attempts (default 5) for a configurable duration (default 15 minutes).                                   |
| **Login Attempt Audit**                     | Log every login attempt (success and failure) with IP address, timestamp, and browser agent for security monitoring.                                             |
| **Session Invalidation on Password Change** | All active sessions for a user are automatically invalidated when their password is changed, preventing credential-reuse attacks.                                |
| **Module-Level Permissions**                | Permissions can be configured at the module level (merchant-onboard-create, merchant-onboard-read, etc.) for fine-grained access control beyond role assignment. |
| **Customer (Merchant) Assignment**          | Assign merchants to specific admin users or sales persons for account management and reporting scoping.                                                          |

**15. Audit Logging & Compliance**

|                                      |                                                                                                                                            |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ |
| **Feature**                          | **Description**                                                                                                                            |
| **System-Wide Audit Log**            | Comprehensive audit trail capturing all user actions across the system including create, update, delete operations on all key models.      |
| **Before/After Data Capture**        | Each audit log entry stores the data state before and after the change in JSON format for forensic analysis.                               |
| **Sensitive Action Flagging**        | Sensitive actions (key changes, role modifications, financial adjustments) are flagged and stored with elevated retention priority.        |
| **Authentication Event Logging**     | Log login successes, failures, MFA events, password changes, and session activities.                                                       |
| **Admin Audit Log Viewer**           | Admin interface to search, filter (by user, module, action type, date range), and view all audit log entries.                              |
| **Audit Log CSV Export**             | Export filtered audit log data to CSV for regulatory submission or internal compliance review.                                             |
| **Configurable Retention Policies**  | Configurable retention periods per log type; automated cleanup of aged audit records via cron job.                                         |
| **Audit Middleware**                 | Request-level audit middleware applied to all admin routes, automatically capturing sensitive HTTP requests without per-controller coding. |
| **IP Address & User Agent Tracking** | Every audit record includes the actor's IP address and browser/client user-agent string for forensic traceability.                         |

**16. Notifications & Communication**

|                                 |                                                                                                                                      |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| **Feature**                     | **Description**                                                                                                                      |
| **In-App Notification Centre**  | Real-time in-app notification centre with unread count badge, recent notifications drawer, and mark-as-read / mark-all-read actions. |
| **Email Notifications (Azure)** | Transactional email delivery via Azure Email Communication Service for onboarding events, password resets, and KYC status updates.   |
| **WhatsApp Notifications**      | WhatsApp message delivery integration for merchant communications including onboarding status, payment confirmations, and alerts.    |
| **Promotional Email Campaigns** | Admin-managed promotional email subscriber list and campaign send functionality.                                                     |
| **Newsletter Subscriptions**    | Public newsletter subscribe endpoint; admin manages subscriber list and campaigns.                                                   |

**17. Dashboard & Reporting**

|                                        |                                                                                                                                               |
| -------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                            | **Description**                                                                                                                               |
| **Admin Dashboard**                    | Central admin dashboard showing total merchants, active websites, total earnings, transaction volumes, deposit summary, and order statistics. |
| **Performance Charts**                 | Time-period-based performance charts (daily, weekly, monthly) for transaction volume, revenue, and deposit trends.                            |
| **Order Statistics**                   | Monthly order breakdown showing counts and values by payment type (online, offline, QR, subscription).                                        |
| **Google Analytics Integration**       | Embedded Google Analytics visitor data on the admin dashboard for website traffic insights.                                                   |
| **Sales Dashboard**                    | Dedicated sales-user dashboard with merchant pipeline, new merchant counts, and revenue attributed to the sales person.                       |
| **Merchant Risk Score Dashboard**      | Risk-focused dashboard showing risk distribution, high-risk merchant listing, overdue review counts, and recent score changes.                |
| **Compliance Queue Dashboard**         | Dashboard view of all merchants in the compliance review queue with assignment, status, and age of review.                                    |
| **Validation Statistics**              | Dashboard showing third-party validation usage, pass/fail rates, and provider performance statistics.                                         |
| **Merchant Dashboard (Merchant View)** | Merchant-facing dashboard showing their transaction summary, credit score widget, settlement status, and quick-action links.                  |
| **Report Export**                      | Export transaction, settlement, audit, and risk data to CSV/PDF from various report pages.                                                    |

**18. Additional Platform Features**

**18.1 E-Commerce & Product Management**

|                              |                                                                                                                   |
| ---------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **Feature**                  | **Description**                                                                                                   |
| **Product Catalogue**        | Manage physical and digital product listings per merchant with categories, pricing, images, and inventory.        |
| **Order Management**         | View and process customer product orders; track order status through placed, paid, shipped, and completed stages. |
| **Shopping Cart**            | Customer-facing shopping cart for merchant storefronts with add/remove/update functionality and checkout flow.    |
| **Shipping Rates**           | Configure shipping rate rules per product type, weight, and destination for physical product fulfilment.          |
| **Digital Product Delivery** | Automatic delivery of digital products (download links, access codes) upon payment confirmation.                  |

**18.2 Event & Booking Management**

|                               |                                                                                                                            |
| ----------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| **Feature**                   | **Description**                                                                                                            |
| **Event Management**          | Create and publish events with ticket types, pricing, capacity limits, and event details for merchant-hosted events.       |
| **Event Ticketing**           | Customer-facing event ticket purchase with payment gateway selection and QR-code ticket issuance.                          |
| **Appointment Booking**       | Provider availability management and customer appointment booking with payment at the time of booking.                     |
| **School Fee Payment Portal** | School-specific fee payment portal allowing parents to search by student admission number and pay outstanding fees online. |
| **Chit Fund Payment Portal**  | Chit fund provider portal enabling chit subscribers to pay instalments online with receipt generation.                     |

**18.3 System Administration**

|                               |                                                                                                                    |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| **Feature**                   | **Description**                                                                                                    |
| **Multi-Language Support**    | Language management with admin-configurable translations; merchants can set their preferred display language.      |
| **SEO Management**            | Per-page SEO metadata management (title, description, keywords) for merchant websites.                             |
| **CMS Pages**                 | Admin-managed static content pages (About, Contact, Terms, Privacy) with slug-based URL routing.                   |
| **Blog Management**           | Create and publish blog posts with slug-based URLs and category tagging.                                           |
| **Site Settings**             | Global site configuration: name, logo, currency, timezone, maintenance mode, and third-party API keys.             |
| **Media Library**             | Centralized media library for uploaded images and documents with list view, delete, and reuse across the platform. |
| **Cron Job Management**       | Admin-configurable scheduled cron tasks; manually trigger runs and view execution history.                         |
| **Environment Configuration** | Admin interface for managing environment variables (.env) without direct server access.                            |
| **Menu Builder**              | Drag-and-drop navigation menu builder for admin and merchant portals.                                              |
| **Deployment Tracker**        | Track system deployments with version, date, and deployer for change management.                                   |
| **Altareq OpenFinance**       | Integration with Altareq OpenFinance platform for bank account data retrieval and financial verification.          |

**19. Feature Summary**

The table below provides a high-level count of documented features by domain area.

|                                        |                   |           |
| -------------------------------------- | ----------------- | --------- |
| **Domain**                             | **Feature Count** | **Notes** |
| **2. Merchant Onboarding**             | 18                |           |
| **3. KYC & Identity Verification**     | 22                |           |
| **4. LSEG Compliance Screening**       | 10                |           |
| **5. Merchant Risk Management**        | 12                |           |
| **6. Credit Score & Loan Management**  | 11                |           |
| **7. MDR & Fee Management**            | 8                 |           |
| **8. MCC Management**                  | 4                 |           |
| **9. Store & Terminal Management**     | 9                 |           |
| **10. Channel Partner Management**     | 6                 |           |
| **11. Transaction Management**         | 9                 |           |
| **12. Settlement & Reconciliation**    | 4                 |           |
| **13. Payment Gateway Integrations**   | 9                 |           |
| **14. User, Role & Access Management** | 12                |           |
| **15. Audit Logging & Compliance**     | 9                 |           |
| **16. Notifications & Communication**  | 5                 |           |
| **17. Dashboard & Reporting**          | 10                |           |
| **18. Additional Platform Features**   | 17                |           |
| **TOTAL**                              | **175**           |           |
