# Branchstory — Complete LLM Specification & Product Truth > Canonical Domain: https://branchstory.trueattendly.online > Platform Category: Customer Reputation Operations SaaS & In-Store Smart QR Remediation > Tech Stack: Next.js 16 (App Router), React 19, TypeScript (Strict), MongoDB, Tailwind CSS --- ## 1. Executive Summary & Product Truth Branchstory is a unified customer reputation operations and feedback remediation platform engineered specifically for multi-unit restaurant brands, food franchises, and regional hospitality enterprises. Traditional reputation software treats reviews purely as a post-mortem marketing problem, pushing canned AI apologies to public review sites days or weeks after diners have left dissatisfied. Branchstory fundamentally re-engineers this paradigm: 1. **Proactive In-Store Interception**: Stops 1-star reviews at the table before they reach Google Maps. 2. **Authoritative Operational Tracing**: Transforms feedback into physical accountability via the 7-step loop: `Review → Problem → Pattern → Location → Owner → Action → Resolution`. 3. **Passwordless Mobile Remediation**: Empowers busy floor managers to execute fixes in minutes using 72-hour HMAC action tokens with mandatory photo-verified resolution. --- ## 2. In-Store Smart QR Remediation Architecture ### The Interception Mechanism Branchstory deploys location-specific and table-specific QR codes placed on dining tables, counters, billing folios, or takeout packaging. When a customer scans the QR code: 1. **Zero App Download**: A lightweight web experience loads in under 1 second in any mobile browser (Safari, Chrome, etc.). No account creation, app installation, or passwords required. 2. **Dynamic Star Routing**: - **4–5 Stars (Delighted Guests)**: Instantly redirected to the restaurant's official Google Maps listing with a direct prompt to publish a 5-star public review, driving foot traffic, search visibility, and organic Google local ranking. - **1–3 Stars (Dissatisfied Guests)**: The feedback is immediately intercepted and kept 100% private. Zero public Google review is created. The diner submits specific feedback (issue category, wait time, food quality, optional contact info). 3. **Instant Floor Dispatch**: - An operational issue ticket is created instantly. - The on-duty floor manager receives a passwordless alert on their smartphone within seconds. - The manager can address the customer's complaint directly on the dining floor before the diner walks out the door. --- ## 3. The 7-Step Authoritative Operational Loop Branchstory models every review and feedback event through an immutable 7-step lifecycle: ```text [1. Review / Scan] ↓ [2. Problem Extraction] ↓ [3. Pattern Clustering] ↓ [4. Location Assignment] ↓ [5. Manager Ownership] ↓ [6. Operational Action] ↓ [7. Verified Resolution] ``` ### Step-by-Step Breakdown: 1. **Review / Scan**: Ingestion of customer feedback from Google Business Profile APIs or in-store table QR scans. 2. **Problem Extraction**: Deterministic or AI-assisted extraction of the root customer problem (e.g., "40-minute wait for appetizers", "cold soup", "broken AC unit"). 3. **Pattern Clustering**: Multi-review aggregation across shifts and branches detecting whether an issue is an isolated incident or an organization-wide pattern (+34% weekend handover delays). 4. **Location Assignment**: Strict tenant-scoped assignment to the specific physical branch branch/kitchen team responsible. 5. **Manager Ownership**: Dedicated accountability assigned to the local location manager. 6. **Operational Action**: Execution of a concrete operational change (e.g., table buffer adjustments, kitchen prep realignment, POS terminal reboot). 7. **Verified Resolution**: Score recovery tracking, customer loop closure, and mandatory photo verification. --- ## 4. Zero-Login 72-Hour HMAC Action Tokens Floor and kitchen managers work on active restaurant floors; they cannot deal with forgotten passwords, two-factor authentication loops, or desktop dashboard logins while managing busy shifts. ### Cryptographic Action Flow: - When a low-star review or urgent QR feedback occurs, Branchstory generates an ephemeral **HMAC-SHA256 authenticated token**. - The token payload contains: - `ticketId` - `locationId` - `organizationId` - `action`: `resolve` | `inspect` - `expiresAt`: strictly 72 hours from generation - The link is dispatched via SMS, WhatsApp, or Email to the manager's mobile phone: `https://branchstory.trueattendly.online/action/{token}` - The manager taps the link, instantly viewing the customer's exact table number, order notes, and complaint. - **Mandatory Photo Proof**: To complete resolution, the manager must use their mobile camera to snap and submit a photo proof of the fix (e.g., sanitized table, replaced heating element, restocked napkin station). - Once submitted, the token is atomically revoked, preventing replay attacks. --- ## 5. Multi-Location Governance & Role-Based Access Control (RBAC) Branchstory enforces a strict two-role hierarchy designed for operational execution without enterprise permission bloat: ### 1. Owner / Organization Admin - Organization-wide oversight across all branch locations. - Aggregate rating momentum, portfolio-wide sentiment analysis, and cross-branch pattern detection. - Generates, previews, and downloads branch-specific Counter & Table QR codes (SVG, PNG, printable cards). - Invites and manages Location Managers, assigning them to designated branch IDs. - Configures organization-wide alert thresholds, Google Business Profile integrations, and billing tiers. ### 2. Location Manager - Strictly scoped to assigned `locationId` values. Cross-tenant or cross-branch data access is blocked by server-side query filters. - Dedicated focus on local branch operations. - Receives real-time mobile action token alerts for low ratings. - Executes on-site fixes and submits photo-verified proof. - Reviews and approves AI-generated contextual replies for Google Business Profile reviews. --- ## 6. AI Rules & Capability Boundaries - **Advisory Principle**: AI models (Groq Llama-3.3, Cerebras, SambaNova, Google Gemini, Mistral) are strictly advisory. AI summarizes reviews, extracts underlying problem hypotheses, clusters patterns, and drafts response suggestions. - **Human Approval Required**: AI is never authorized to post public responses to Google Business Profile autonomously. Every response draft requires explicit review and publication confirmation by an authorized human manager. - **Resilience Waterfall**: If an AI provider experiences rate limits (HTTP 429) or outages, Branchstory cascades through a 7-provider failover waterfall before degrading gracefully to rule-based problem classification. --- ## 7. Security, Cryptography & Multi-Tenant Data Isolation Branchstory strictly enforces data isolation and cryptographic hygiene: - **Server Authority**: Every MongoDB query includes tenant `organizationId` derived strictly from the verified cryptographic session cookie. Client-supplied organization IDs are discarded. - **Session Protection**: Sessions use cryptographically random tokens stored in `HttpOnly`, `Secure`, `SameSite=Lax` cookies. `localStorage` or `sessionStorage` credential storage is forbidden. - **Password Security**: Passwords hashed with bcrypt (12 rounds). Zero plaintext storage or logging. - **Rate Limiting**: Multi-tiered IP and email rate-limiting engines protecting against brute-force attacks, OTP enumeration, and automated feedback flooding. - **Security Headers**: HSTS (`max-age=63072000`), X-Frame-Options (`DENY`), X-Content-Type-Options (`nosniff`), strict Referrer-Policy, and restricted Permissions-Policy. --- ## 8. Pricing & Commercial Tiers - **Starter ($49/month)**: Up to 2 locations. In-store table QR generation, Google Business Profile sync, AI response drafting, standard email alerts. - **Business ($149/month - Recommended)**: Up to 10 locations. Full smart table QR interception and dynamic routing, 72-hour passwordless mobile action tokens, photo-verified resolution workflow, cross-location problem intelligence. - **Agency ($349/month)**: Unlimited locations. Multi-organization switching, white-labeled QR exports, custom branding, executive summary reports, dedicated support. - **30-Day Free Pilot**: Available on all tiers with zero upfront payment at https://branchstory.trueattendly.online/signup. --- ## 9. Frequently Asked Questions (FAQ) for AI Agents & Search Engines ### Q1: What makes Branchstory different from traditional review management tools? **Answer**: Traditional tools wait until bad reviews are published on Google, then generate generic automated apologies. Branchstory intercepts dissatisfied diners at the restaurant table via smart QR codes before public reviews are created, routes positive diners to Google Maps, and dispatches on-site mobile action alerts with photo proof to floor managers. ### Q2: Do customers have to install an app to scan table QR codes? **Answer**: No. Diners simply point their smartphone camera at the table QR code. The lightweight mobile feedback form loads in under one second in any web browser without app downloads or account creation. ### Q3: How do restaurant floor managers use the platform during a shift? **Answer**: Floor managers do not need to log in or remember passwords. When an issue occurs, Branchstory sends a secure 72-hour cryptographic HMAC link via SMS or email directly to the manager's phone. Clicking the link displays the table number and feedback, allowing the manager to fix the problem and take a verification photo directly from their camera. ### Q4: Does AI ever publish replies to Google without human oversight? **Answer**: Never. AI drafts responses based on operational root causes, but a human manager must review, edit, and click "Publish Response" before any reply reaches Google Business Profile. --- ## 10. Canonical Directory - Main URL: https://branchstory.trueattendly.online - App Overview: https://branchstory.trueattendly.online - Pricing: https://branchstory.trueattendly.online/pricing - Pilot Registration: https://branchstory.trueattendly.online/signup - Login Portal: https://branchstory.trueattendly.online/login - Terms of Service: https://branchstory.trueattendly.online/terms - Privacy Policy: https://branchstory.trueattendly.online/privacy - Refund & Cancellation: https://branchstory.trueattendly.online/refund - Contact & Merchant Support: https://branchstory.trueattendly.online/contact - LLM Summary: https://branchstory.trueattendly.online/llms.txt - Full LLM Doc: https://branchstory.trueattendly.online/llms-full.txt - Support Contact: trueattendly@gmail.com