A delivery promise customers can trust

Validate addresses, allocate stops, guide drivers, stream progress, and prove completion.

Business outcomeFewer failed deliveries and a live, explainable ETA from checkout to doorstep.

The operating situation

At 18:05 a customer places a same-evening grocery order to a loosely formatted apartment address. The promise engine has eight minutes to validate serviceability and a two-hour window; dispatch must combine it with 37 stops, the driver may lose connectivity, and support needs one explainable timeline when the entrance is hard to find.

Checkout customerDispatch plannerDriverCustomer-support agentTransport partner

Keep authority explicit across the stack

01Order system of recordOwns order, customer promise, consent, service window, package constraints, payment, and terminal delivery outcome.
02Location normalizationSearch and address services produce candidates; the accepted Mappls Pin becomes the durable destination identity rather than repeatedly geocoding text.
03Planning and guidanceRoute and matrix boundaries sequence eligible stops, preserve route revisions, and provide driver guidance without making the map UI authoritative.
04Trip evidenceInTouch observations are deduplicated by source identity and event time; ETA revisions and exceptions are derived without rewriting raw telemetry.
05Customer and operations viewsA privacy-reduced tracking projection serves the customer while dispatch/support retain the attributable full journey and proof-review queue.

From intent to reconciled outcome

1
Stage 1

Normalize the destination and retain its Mappls Pin

Capture intent and source evidence without inventing a more precise state than the inputs support.

2
Stage 2

Optimize stops against capacity and time windows

Advance through an idempotent boundary, preserve stable Mappls identity, and expose freshness and ownership.

3
Stage 3

Navigate with live rerouting

Advance through an idempotent boundary, preserve stable Mappls identity, and expose freshness and ownership.

4
Stage 4

Stream driver and order state

Advance through an idempotent boundary, preserve stable Mappls identity, and expose freshness and ownership.

5
Stage 5

Capture geotagged proof and reconcile exceptions

Reconcile the terminal result to every authoritative system and retain attributable evidence.

Records that must survive restarts and retries

Order ↔ destination Mappls Pin and acceptance timestamp

Version, authorize, retain, observe, and reconcile this relationship explicitly; do not recover it later from display text or logs.

Route revision ↔ ordered stop IDs, profile, constraints, provider request identity

Version, authorize, retain, observe, and reconcile this relationship explicitly; do not recover it later from display text or logs.

Telemetry event ↔ source/event/content identity, event time, receipt time, accuracy

Version, authorize, retain, observe, and reconcile this relationship explicitly; do not recover it later from display text or logs.

Proof submission ↔ consent purpose, media hashes, location evidence, reviewer decision

Version, authorize, retain, observe, and reconcile this relationship explicitly; do not recover it later from display text or logs.

Design recovery before rollout

Ambiguous apartment entrance

Offer landmark/entrance candidates, let the customer confirm one stable pin, and preserve the original address plus every selection revision.

Driver telemetry goes silent

Show last verified progress and age, alert dispatch after policy threshold, and avoid inventing a moving ETA.

Provider accepts a route/trip command after timeout

Reconcile by idempotency/provider identity before issuing another command or closing locally.

Products and evidence

Earn the right to automate

1
Rollout gate

Pilot address capture and Mappls Pin continuity on one checkout flow

2
Rollout gate

Add matrix-assisted planning in shadow mode and compare against dispatcher choices

3
Rollout gate

Enable one depot with bounded live telemetry and exception ownership

4
Rollout gate

Expose customer ETA only after freshness/error SLOs pass

5
Rollout gate

Scale by region with cost, privacy, support, and failover reviews

Measure the outcome

First-attempt delivery rateCost per stopETA errorDistance per order

Tutorials and downloadable applications

Advanced · verified app

Care Transfer Desk

Confirm the correct receiving entrance, assign eligible transport, preserve courier custody, review condition exceptions, and reconcile receiver acceptance without retaining patient or clinical data.

Advanced · verified app

Grid Restoration Desk

Correlate an outage, govern independent switching approval, dispatch an assigned crew, preserve rework, and reconcile restoration from telemetry and customer-impact evidence.

Advanced · verified app

Incident Dispatch

Resolve an incident, choose a capable available responder, route, track evidence, enforce arrival, and review.