Runs offline · Sync verified end to end
Every finding becomes a task. Every fix gets verified.
Quontrol runs your branch audits on a tablet and turns each failed item into a tracked corrective action with photo evidence, an owner, and a verification step.
The status quo
You already audit. Then the report goes quiet.
An auditor visits a branch and finds six problems. The report reaches head office as a PDF, or a photo of a page.
Nobody knows whether any of the six were fixed until the next visit. That might be a month away.
When the auditor returns, they re-inspect from scratch. There is no record of what was supposed to have been done.
Branch scores aren't comparable. A branch with no grill section still gets marked down on grill questions.
Quontrol's answer is one loop: finding, fix, verified.
How it works
One loop, from finding to verified fix.
Audit
The auditor runs the checklist on a tablet. Pass, fail, or N/A. The camera opens on a failure that requires evidence.
Finding becomes an action
Every failed item becomes a tracked corrective action the moment the audit is submitted. Nothing is logged by hand.
Manager claims the fix
The branch manager fixes it and claims the fix, with a required photo and a comment.
Auditor verifies
On the next visit, the auditor checks the fix and marks it verified. Or fails it again.
The auditor returns already knowing what to re-check. The loop closes on the next visit.
Corrective actions
Claiming a fix and verifying it are two different things.
A branch manager can mark an action fixed, with a required photo and a comment. That unblocks them immediately and gives head office a signal between visits. But only an auditor can mark it verified. The audited party never grades its own homework.
Every transition records who did it and when. Each action carries the instruction, the branch, the original photo evidence, and its status.
Works offline
No signal at the branch is the normal case.
Pull once, audit anywhere
Checklists sync to the tablet once. After that, audits run with no connectivity at all.
Photos shrink at capture
A 4032×3024 photo becomes about 118 KB on the device, roughly 78% smaller, so a full audit syncs over a bad restaurant connection instead of stalling.
Sync is verified end to end
The device confirms the server received every response and every photo before the audit counts as done. Failed syncs are visible and retryable, and a retry never creates a duplicate.
Drafts survive anything
Close the app, kill it, let the battery die. The draft is still there. Sync runs on launch, on reconnect, and in the background.
Roles and access
Three roles come ready-made. The walls between them don't move.
QA administrator
sees everythingBuilds checklists, manages users and branches, dismisses the findings that don't warrant follow-up.
Auditor
runs auditsChooses which branches to visit. The only role that can mark a corrective action verified.
Branch manager
their branches onlyClaims fixes with the required photo and a comment. Sees nothing beyond their own branches.
These three are the prefilled defaults. QA administrators can create their own roles.
What a branch manager sees
Exactly those two, enforced in the database itself rather than by hiding menu items. One franchisee can never see another's results. Managers can cover several branches, and branches can have several managers.
Dashboards
The questions a Monday morning actually asks.
Which branches are slipping?
Branch ranking and comparison by latest grade. A branch with an all-N/A audit shows N/A, never a misleading zero.
What's still open, and where?
Every open corrective action, by age and location, with its original photo evidence attached.
How much auditing is getting done?
Audit throughput and average audit duration, per branch and per checklist.
Who hasn't been visited?
A coverage view of branches that are overdue for a visit, sorted by staleness, with each branch's last audit date and last grade.
Security and data isolation
Your data sits in its own database. Physically.
Every Quontrol customer gets a physically separate database, not one big shared system where a software filter is all that separates you from the next customer.
Your audit history, your photos, your scores never share storage with another operator's. A bug or a mistake on their side cannot reach your records, because there is no shared place to reach across.
That is the standard we think you should hold anyone to before you put your food-safety record in their software.
- Branch managers are limited to their assigned branches in the database itself, not just in what the screens show.
- Biometric unlock on the tablet.
FAQ
Questions ops directors actually ask.
What if there's no internet at the branch?
Nothing changes. Checklists are pulled to the tablet once; after that, audits run with no connectivity at all. Everything syncs when signal returns, and the device confirms the server received every response and photo before the audit counts as done.
What hardware do we need?
iOS or Android tablets or phones. Two-pane on tablets, single column on phones. One shared tablet at a branch works: the auditor identifies themselves at the start of a shift, and each audit records who performed it.
Can we use our own checklist?
Yes. You build and edit your own checklists in the portal: sections, point weights, critical flags, required photos. Editing a checklist never rewrites history: past audits keep the question text they were run against.
Can we download the reports?
Yes. Any individual audit downloads from the portal as an Excel file, with per-item results and notes. Photos stay attached to the audit in the portal.
Who can see what?
QA administrators see everything. Auditors run audits. Branch managers see their assigned branches and nothing else, enforced in the database itself. And each customer's data lives in its own separate database.
How are different branch layouts scored fairly?
N/A answers are removed from the denominator. A branch with no grill section isn't marked down on grill questions, so grades stay comparable across branches.
Can a branch manager close their own findings?
They can claim a fix, with a required photo and a comment. Only an auditor can mark it verified. The audited party never grades its own homework.
What happens if the app is closed mid-audit?
Drafts survive the app being closed or killed. And if a sync fails, it's visible and retryable, and retrying never creates a duplicate.
How do app updates work?
They ship over the air, without an app-store review cycle. Auditors don't have to update anything themselves.
See the loop run on your own checklist.
In a demo we run an audit, fail an item, and take it from finding to verified fix. Bring your current checklist. Paper is fine.