invocation.io

From €12,000 · 3–4 weeks · fixed scope

Wallets, escrow and payouts that balance to the cent — built for your platform, then handed over.

Stored balances, holds and releases, milestone escrow, refunds that reverse exactly what they undo, payouts on a real state machine. Fixed scope, from €12,000, three to four weeks. For platforms that hold user money and can't afford a phantom balance.

Built and still run the escrow, wallets and payouts behind GigSocial's creator marketplace · Built Sponsored's Stripe Connect marketplace · $100M+ in recurring revenue migrated with zero downtime · Stripe Certified Professional Billing Architect.

01 / Fit

Does this sound like your platform?

The moment you hold a user's money, you're running a bank's bookkeeping — usually without having decided to.

Balances are a column on the users table, updated in place. Nobody can replay how a number got there.

Refunds and reversals are handled by hand, and the support inbox knows it.

You release funds on milestones, deliveries or approvals — and the release logic lives in three places.

Top-ups, spends and withdrawals are reconciled against the processor in a spreadsheet, monthly, by whoever loses the coin toss.

Freelancers, creators or vendors are paid from a script someone is afraid to touch.

You're adding wallets to a product that already has customers, and it cannot break during the change.

If any two of those are true, the ledger is already wrong somewhere. The build replaces it with one that can prove it isn't.

Who this works for. Companies with a live product whose money system has outgrown the way it was built, and who want it fixed by someone who owns the decisions — not a team to coordinate, not a change request for every call. You approve outcomes, not steps. If you'd rather be in every decision, an agency is a better fit, and I'll say so on the first call.

02 / Deliverable

What you receive

A ledger-backed wallet and escrow system in your codebase, with the architecture written down. In scope:

Double-entry ledger with wallet, escrow and platform accounts — balances derived from entries, never stored and drifted.

Hold and release flows: milestone, delivery-confirmed, time-based, or admin-released — one implementation, configured per case.

Refunds, partial refunds, reversals and dispute holds that reverse the exact entries they undo.

Payout state machine to your disbursement rail — Stripe Connect, or ACH and card push through your provider — including failed and returned payouts.

Reconciliation against the processor and the bank, with a daily report that says “balanced” or names the difference.

Admin tooling: adjust, freeze, and trace any balance back to its entries.

Architecture document, runbook, and a 90-minute handover. Then it's yours.

03 / Sequence

How it works

  1. 1

    Week 0 — Scope

    What the wallet holds, who can release, what the reversal rules are, which rail pays out, whether live balances need migrating. Written scope, fixed fee, before anything is built.

  2. 2

    Weeks 1–2 — Ledger and flows

    Accounts, entries, holds, releases, reversals — with tests on the invariants. Running in staging by the end of week two.

  3. 3

    Week 3 — Rails and reconciliation

    Disbursement integration, payout state machine with its returns path, reconciliation job, admin tooling.

  4. 4

    Weeks 3–4 — Cut over and hand over

    If you have live balances: a migration that opens the new ledger from a reconciled snapshot of the old numbers, signed off by whoever owns your books. Then docs, runbook, handover.

04 / Access

What I need from you

  • A repository and a staging environment. Your stack — Rails, Node/TypeScript, Python, Postgres — or a recommendation if there's nothing yet.
  • Test credentials for your processor and disbursement provider.
  • Someone who can decide the release and reversal rules, and the current balances if there are any.
  • A weekly 30-minute check-in.

No hourly discovery. The scope is written before the fee, and the fee doesn't move.

05 / Scope

Where the fences are

  • For platforms that hold user funds: gig and services platforms, creator tools, B2B platforms with stored balances or credits, booking platforms with deposits.
  • Full two-sided marketplace money — seller KYC, reserves against dispute windows, tax export — is the marketplace build. If you need both, we scope once and price once.
  • Whether your structure needs a licensed partner, an FBO account or a money-transmitter analysis is a question for counsel. I build to the structure you've been advised to have.
  • Stored-value or closed-loop programs that require regulatory registration are outside this scope.
  • One currency in the base scope. More is a priced add-on, quoted before we start.

06 / Confidentiality

Confidentiality

A mutual NDA is available on request before we start — I'll sign yours or send mine. The code is written in your repository, under your ownership, from the first commit. There is nothing to hand back later.

I keep a private reference architecture that makes every build faster. Nothing specific to your business goes into it.

AI-assisted development tooling is used under the same confidentiality obligations, behind the same review gates I run on my own production systems. You can opt out before we start.

07 / FAQ

Straight answers

Why does a wallet need double-entry?

Because a stored balance can't tell you why it's wrong; entries can. Every balance is the sum of its entries, every transfer touches two accounts, and “the wallet says X but the processor says Y” becomes a query rather than an investigation.

We already have balances in production. Can you migrate them?

Yes. The cutover opens the new ledger from a reconciled snapshot of the old balances. The difference — there is always a difference — is recorded as an explicit opening adjustment your finance person signs off, not swept into a new column.

Is escrow legal for us?

That depends on your structure and jurisdiction, and it's a question for your counsel, not your engineer. What I can do is build hold-and-release flows that fit the structure they advise — and tell you which flows tend to raise the question.

Stripe Connect or a custom rail?

If your payees are in Stripe-supported countries and you don't need to hold funds outside Stripe, Connect is usually right. If you need an FBO structure, several rails, or control Connect doesn't offer, custom. The scoping call decides it; the guide below walks through the trade.

Does the audit fee come off this?

Yes. Come in through the billing health audit and book the build within 60 days, and the audit fee is credited against the build invoice.

What happens after handover?

It's yours. The architecture document and runbook are written so your team can operate it without me. If you want me to stay on, that's a fractional lead engagement at €8–15k a month, agreed separately — never a surprise invoice.

Who does the work?

Andrej Dragojevic, directly. Not an agency, not a junior with a checklist. One senior engineer, a vetted network for design and mobile when scope needs it, EU/US overlap.

Three to four weeks from now, every balance on your platform can be traced to the entries that made it.

From €12,000, fixed scope, handed over. Audit fee credited. Write to me and I'll tell you within a day whether the shape fits.

Prefer email? Write to andrej@invocation.io. I reply within one business day.