Documenting extra work on site: ScopeStamp & change orders
Your customer's "go ahead and do it" is billable — if the message is actually attached to the line item. ScopeStamp for Windows turns extra work, scattered field photos, and exported customer texts into a numbered change-order packet, with the approval evidence sitting beside every amount before the bill goes out. It runs entirely on the office PC, and the free tier does the whole job.
The change order that never reached the invoice
Here is a month-end scene from almost any trade office. A plumber replaced a water heater on Tuesday, then re-ran two supply lines and swapped a corroded shutoff valve while he was under the sink. The customer texted "yeah go ahead and do it" mid-morning. Photos of the old and new work sit on the tech's phone. Nobody wrote any of it down. At month-end the office bills only what was on the original quote, because nobody can reconstruct the extra — and when a big enough extra does get billed without documentation, the customer asks "what is this?", and payment stalls while the back-and-forth drags on.
The fix is not a legal contract on the job site. It is a habit: give the extra a home while it happens, import the evidence that already exists, and make the approval gap visible before the invoice — not after the dispute.
One job, one currency, exact money
A job in ScopeStamp starts as a dossier: a customer label, the original quote or reference, an operator-entered scope description, and the currency. Each job selects exactly one currency from a built-in registry of around 70 ISO-4217 codes. Prices are stored as integer minor units, and line amounts are quantity × unit price computed with exact decimal math — so the numbers in a packet carry no silent rounding, and mixed currencies are structurally impossible.
The decimal rules are looked up, not guessed: JPY/KRW/ISK/VND/CLP are 0-decimal currencies, BHD/IQD/JOD/KWD/LYD/OMR/TND are 3-decimal, and the rest are 2. A price like "12.5" in a 0-decimal currency is refused rather than silently rounded, and unknown currency codes are refused too. Amounts have caps, and a packet that exceeds them renders "OVER LIMIT" instead of fabricating a figure. For the office manager who reconciles the packet against QuickBooks or Excel at the end of the month, the amounts have to be exactly reproducible — this is what that looks like on paper.
From phone photos and texts to a numbered packet
The workflow follows the way work actually happens, in five steps:
- Create the job. Customer label, original quote reference, scope description, and one currency.
- Import the evidence you already have. Photos (JPG/PNG), PDFs, and exported customer messages (TXT/EML/HTML/HTM/JSON/MD) are dropped in and byte-checked. Every attachment gets a kind (photo, document, message, or receipt), an author (customer, employee, or supplier), and a mandatory source label, with bytes detected from content rather than file name. Imports are copied into the local workspace store — the original file is never modified, moved, or deleted.
- Add the line items. Labor, material, or other — each with quantity and unit price — up to 1,000 items per revision, with a clean refusal at the cap instead of truncation.
- Link evidence to individual items. Select the photos, PDFs, and customer messages that back each amount, so "which photo supports this $237.50 line?" answers itself in the packet.
- Export the packet. One click produces a numbered PDF (page X of Y, with job, quote reference, items, and amounts) plus a CSV of line items and a manifest JSON. The PDF opens on any machine — the customer or institution does not need a ScopeStamp account to read it.
The CSV carries quantity, unit price (minor units and formatted), currency code, amount, and each item's approval status — it drops straight into the office's normal spreadsheet and billing flow.
What your customer actually approved — rules that can't be talked around
This is the heart of the product, and its rules are strict on purpose:
- Only a customer-authored message or document linked to the line item counts as approval evidence.
- A photo alone never counts as approval — not even a photo of a signed form.
- An employee note is not consent.
- Supplier material never counts.
- No dropdown label or checkbox can override the rules.
A line item is approved only when qualifying customer-authored evidence is linked and the operator takes an explicit "verify approval" step. These rules are enforced in the app's code and tests, not in its marketing copy — which is why the packet's approval claims are defensible when a customer disputes them.
And the honesty goes both ways: every packet prints the line "office record — not an electronic signature, not a legal approval determination." The documentation makes the work traceable; it does not pretend to be a signed legal instrument.
Spot the approval gap before the bill goes out
Every job moves through five guarded states — draft, sent, approval evidence attached, approval verified by operator, billed — and every transition is checked and logged with a UTC timestamp. On the decisive screen the app states the situation in plain numbers: "Extra work: N items. Approval evidence missing: M. Ready for billing review: K." Items that still lack qualifying customer approval stay visible, with the evidence openable behind each entry. The gap is seen before the invoice goes out, not after the dispute arrives.
Verification is refused while any item lacks qualifying evidence, so "everyone approved except item 4" cannot slip through to billing. The operator's verification is recorded as its own step, separate from the external invoice reference entered at billing — the two facts, "office verified" and "invoice issued," are never conflated. And once a job is billed, that state is terminal: changing anything starts a new revision, explicitly, not a silent edit.
Revisions that never inherit approval
Revising the work does not stretch yesterday's approval over today's changes. A new revision snapshots the items and attachments but always begins as a draft, and approval is never carried over — the history records that the new revision needs fresh approval review. "But they approved revision 1" cannot cover a changed revision 2.
Prior revisions and every export stay available. History opens a read-only viewer holding that revision's snapshotted customer, scope, state, items, evidence, and exports, so the record outlives the current revision. Exports are never silently replaced: every export is a new file with a job-revision-kind-timestamp name, recorded in the exports table. "Which PDF is current?" stops being an argument.
The tamper-evident manifest — what it proves, and what it doesn't
Every file attached to a job receives a SHA-256 hash of its exact stored bytes, bound into a manifest that also lists each attachment's original filename, source label, kind, author, approval status, and byte count. A built-in verifier re-hashes the stored files and reports each one as missing, changed, or invalid — a missing file never passes. Nobody can credibly claim "the file was swapped": the hash catches it, and anyone can re-hash any file to check.
What it does not do matters just as much. The manifest is a tamper-evident office record — it is not a seal, not an electronic signature, and not a legal approval determination. It proves the bytes you attached are the bytes in the packet; it does not turn a packet into a signed contract.
Pictures inside the packet get the same privacy care: derived report images are re-encoded with GPS and EXIF metadata stripped by default, so the crew's phone location does not travel with the PDF, while the original photos on the machine stay untouched.
Where the supply-house receipts actually go
The copper fittings were $84, and the supply slip is in a pocket. In ScopeStamp, a receipt is its own kind of evidence with author "supplier," bound to the job and sitting beside the material line it backs. The slip is on the record exactly where the money went — filed as evidence, not lost in a drawer.
To be plain about the boundaries: ScopeStamp does not auto-match supply slips to jobs, and it does not calculate margins or markup for you. The tax is one flat operator-entered amount per revision, and every number is what the office entered. The matching judgment is made by the person filing it; the app's job is to keep the slip attached to the line, hashed, and present in the packet. That is the honest version of receipt filing — the office decides which slip backs which line, and the packet makes the connection visible.
The whole workflow on the permanent free tier
The permanent free tier covers one active job at a time with complete line-item documentation, evidence linking, and tamper-evident packet exports — no credit card, account, or time limit required. That is the full workflow: approval records, billing records, and exports, all of it.
- Complete approval, billing-record and export workflow
- One active job at a time; archive to start another
- No account, card or time limit — archived jobs stay readable and exportable
Archive a finished job and the active slot frees up while the data stays readable and exportable; reopen it for editing when a slot is available. Free is not a trial with a meter — it is the product, for one job at a time, forever.
Get ScopeStamp on the Microsoft Store.
Pro — $1.99 a month, $19.99 a year, zero per-seat
Pro is an in-app Microsoft Store subscription with zero per-seat fees — $1.99/month or $19.99/year, flat, whether one person or the whole office touches the job. It is a subscription, not a one-time purchase.
- Multiple concurrent active jobs instead of one
- Existing active jobs remain usable and editable if Pro ends
- Flat one price regardless of how many people touch the job — no per-tech pricing, no annual contract, no implementation fees
Compare that with the contractor software suites that want a sales demo, per-seat fees, and a long contract: ScopeStamp's price does not grow with headcount, and it takes no cut of payment processing, because it processes nothing — the office bills through whatever it already uses, and the packet is the documentation that rides along. The upgrade path is presented in-app as an upgrade; nothing about the free workflow is gated behind it, and if a subscription lapses, existing active jobs remain usable and editable — no data held hostage.
Local, private — and honest about feedback too
Everything lives in one local SQLite workspace under the Windows profile. There is no automatic upload path and no network code in the core: job data leaves the machine only if the operator exports a packet. On the paid path, license refresh is an explicit user-initiated action that sends device-pairing data only — never job content.
Even the feedback path is local-first and honest. In-app "Suggest a feature" validates the suggestion, writes a local audit row first, then hands the user's own mail app a pre-filled draft addressed to features@jehorizon.com. The app never claims it sent anything — delivery status is either logged or handed to your mail app. The volunteered diagnostics with a suggestion are app version, OS/architecture, and a timestamp — deliberately no file paths, job contents, or license keys.
An office checklist for change-order week
- When the extra shows up, create the job with the quote reference and one currency first — before the trail scatters.
- Import the photos and the exported customer message; give every attachment a kind, author, and source label.
- Add labor/material line items with quantity × unit price, and link the evidence that backs each one.
- Before billing, work the approval screen: every item marked "approval evidence missing" gets resolved or stays unbilled.
- Export the packet — numbered PDF, CSV, manifest — and run the built-in verifier once.
- Archive the job when it's done; it stays readable and exportable, and the next extra gets the slot.
Extra work is where the money goes out and rarely comes back. Documented the ScopeStamp way, it becomes a numbered packet with the customer's own words beside every amount — an office record that is honest about what it is, and defensible because of it.