The controls a regulator asks for, built into the run.
Not a policy document written afterwards to describe what happened. A gate the run has to pass before it can post, and a record of the fact that it did.
Two people, or it does not post.
The two decisions that move money — changing the plan, and posting a period — each require a second operator. The refusal is in the database as well as in the application, so it survives somebody calling the API directly.
Owner
Comp admin — the maker
Finance — the checker
Compliance
Support
Marketing
A section an operator's role does not reach renders an access notice, never data. The distinction matters: a console that renders the figures and hides the buttons has already disclosed the figures.
A hard ceiling on total compensation.
Total compensation for a period is measured against that period's refund-net cash sales. Over the ceiling, the run cannot be approved — not flagged, not warned about. Refused.
This is the number that decides whether a compensation plan is arithmetically capable of paying what it promises. A plan whose payouts can exceed its sales is not generous; it is funded by the next cohort. Measuring it every period, in the approval path, against sales net of refunds, is the difference between knowing that and finding out.
internal/runs · program config cap_pct_bps
An income disclosure computed over everyone.
Members, earners, non-earners, total, mean, median, 90th and 99th percentile and maximum — for a calendar year, over every enrolled position.
- 01
Non-earners are in the denominator
Every member who existed during the disclosed year counts, and a member who earned nothing counts as zero. Dropping non-earners is the standard way this report flatters a programme, and it is the reason a median can read as ten times the truth. - 02
A negative year is zero, not a negative income
Where clawbacks exceed a member's earnings for the year, that member is disclosed at zero. Nobody's loss is netted off somebody else's income to improve the average. - 03
The prior year does not get diluted
The denominator is members enrolled before the end of the disclosed year, so publishing 2025's distribution in 2026 is not quietly improved by everyone who joined since. - 04
It is computed, not written
It comes out of the same ledger the payouts came out of. That is what makes it substantiation rather than marketing, and it is why the platform terms can require an operator making any earnings claim to publish one.
internal/exposure · internal/report
Liability you can age, and hand to an accountant.
What is owed, how long it has been owed, and whether the ledger and the claims agree.
Aging
internal/exposure
A journal, sign-correct
internal/report
Per-member tax statements
internal/report
A liability cross-check
internal/report
Who may take part, and on what evidence.
A geographic policy that ships switched off, a monitor mode that shows you what enforcing it would have done, and identity verification that keeps a decision rather than a document.
Country resolution runs inside the platform's own database rather than through a third-party lookup on the request path. That is a deliberate compliance decision: an answer that arrives over plaintext HTTP from a rate-limited public endpoint can be rewritten by anyone on the path, and a value an attacker can rewrite may inform a risk score but must not decide whether somebody can sign in.
Every blocked country carries a reason code — regulatory, sanctions, licence pending or business — so the list can be defended a year later by somebody who was not in the room. Exceptions are carve-outs, recorded with a name against them, rather than edits to a seed.
Identity verification runs on your own provider account. What comes back to the platform is a decision and a non-reversible handle — enough to enforce one person, one position, and nothing more. XEX does not hold your members' identity documents, because the safest way to hold documents is not to.
internal/geo · internal/verification
Marketing that has to be approved before it ships.
The claim that gets a programme closed is almost never made by the operator. It is made by a member, in a group chat, about earnings.
Assets go through an approval that appends the compliance disclosure to the body — once, idempotently — so an approved asset cannot circulate without it. Team announcements go out from approved templates rather than free text. Marketing cannot approve its own asset; that is a role boundary, not a policy.
None of this stops a member writing whatever they like on their own account. What it does is give you an approved corpus, a record of what was approved and by whom, and a defensible answer when somebody asks what your programme told people.
internal/marketing · /admin/marketing
What we do not claim.
The most useful paragraph on this page, and the one most vendors leave out.
Run it in a sandbox before you take our word for any of this.
The sandbox is the whole product. Configure a plan, buy a package as a member, compute a run, and read the disclosure it produces.