A Hundred Out, Ninety-Seven In
A transfer is the only stock movement with two parties who can honestly disagree about one number. One signature can only ever record one side of that argument — so we take two.
Stock leaves Nairobi Central as 100 units and is counted in at Mombasa Depot as 97. Nobody is lying. The loading clerk counted 100 onto the lorry and believes it; the receiving clerk counted 97 off it and believes that. Three units are missing and both accounts are held in good faith, which is exactly what makes this the hardest ordinary problem in inventory.
Why one signature cannot fix it
Suppose you do the obvious thing and put a signature pad on the transfer. Whose?
Sign at dispatch only
- You have proof the loader believed 100 went out.
- You have nothing about what arrived.
- The receiving site can reject the whole figure and there is no counter-record.
- The gap has one name on it, which reads as an accusation.
Sign at receipt only
- You have proof the receiver counted 97.
- You have nothing about what left.
- The sending site can claim the count was wrong on arrival, not on departure.
- The gap again has one name on it — the other one.
Either way you have documented one half of a two-sided disagreement, which is not evidence so much as a position. And the position you happen to have documented is decided by which screen the developer put the pad on, which is a poor basis for settling money.
A dispute between two parties needs two marks. Anything less is a witness statement filed as a verdict.
What we actually record
A transfer in AWRA carries two independent signatures. One is taken from whoever hands the stock over, and one from whoever takes delivery, each with its own printed name and its own timestamp. The quantity received is recorded as its own figure, and the difference is written to shrinkage.
Transfer TRF-2026-0417 — Nairobi Central to Mombasa Depot
Notice what the record does and does not do. It does not decide who is responsible for the three units — that is a conversation between two supervisors, and no field can hold it. What it does is give the gap two names, two times and a duration, so the conversation has participants and a window instead of a variance report with nobody's name on it.
Each mark gets one moment, and only one
The two signatures are not interchangeable and they are not both available all the time. Each has a single window, and this is stricter than anywhere else in the system.
-
While the transfer is pending
The dispatch signature can be taken. This is the only moment it means anything: a dispatch mark added after the lorry has left is backdating, whatever the intention behind it. When the transfer moves into transit, this window shuts.
-
While the transfer is in transit
The receipt signature can be taken. It is not available before dispatch, because signing for goods that have not arrived is a promise rather than a receipt — and a promise filed as a receipt is worse than no record, since it looks like one.
-
After that
Neither can be added or replaced. Completed, rejected, returned — in each case there is nothing left for that party to attest to, and a mark arriving afterwards attests to a decision it was not present for.
Deliberately narrower than the rest of the system
Goods receipts and asset handovers use a deny-list: signable unless the record has been decided. Transfers use an allow-list — exactly one status per mark — because here each signature has one honest moment rather than a period of usefulness. It is the one place we chose the stricter rule on purpose.
What this changes about the monthly conversation
Transit shrinkage is the loss that most often gets written off without investigation, and the reason is structural rather than lazy. A variance with no names attached has no natural first phone call. Somebody has to decide to start an investigation, from a report, about stock that moved three weeks ago, between two sites that both consider the matter closed.
With two marks, the first phone call is obvious and it is short. Two people signed for two different numbers on the same consignment twelve hours apart. One of them can usually tell you what happened, and quite often it is not theft at all — it is a part-load left on a dock, a miscount of a broken pallet, or units transferred into a second vehicle nobody recorded.
Which is the actual argument for the second signature: it converts a number nobody owns into a question two people can answer. Whether they answer it honestly is not something software decides, but you have at least stopped asking the room.
The limits, stated plainly
What AWRA OpsHub does today
- Two independent signatures on a transfer — dispatch and receipt — each with its own printed name and timestamp.
- A single enforced window per mark: dispatch while pending, receipt while in transit, and neither afterwards.
- Received quantity and shrinkage recorded as their own figures, so the gap is a number rather than an inference.
- Both marks readable back on the record and available to the mobile app, held behind a permission check.
What it does not do
- No attribution of responsibility. The system records who signed for what; it does not decide whose loss the shrinkage is.
- No requirement to sign. A transfer with nobody available to sign at either end still moves and is still recorded.
- No per-line signatures. The marks sit on the transfer, not on each item line within it.
- No legal signing weight — see the wider note in the companion post on what a captured mark is worth.
Not ours, by choice
- Not a proof-of-delivery service for third-party carriers. These are your own sites and your own people; a contracted haulier signing on their own device is a different arrangement and we do not pretend to model it.
The gap between dispatched and received still has to be investigated by a person. What changes is that the investigation has a starting point.
What is not built today can still be built for you
Anything described above as not built is a statement about what ships in the standard product today — not a limit on what AWRA OpsHub can do for your organisation. Kenya's eTIMS integration and its maintained payroll engine are both in the product because clients needed them and commissioned them; neither appeared by itself, and the same door is open for the gap you just read about. Two honest qualifications so this is worth what it claims: a handful of gaps on this blog are deliberate refusals rather than missing work — a statutory ledger we will not sign our name to, a rule that would decide a tax question for you, a clinical or member-funds record that belongs in a regulated system — and where that is true the post says so in those words rather than calling it a gap. Everything else is a scope, a timeline and a price.
The operational work, which is what most commissions actually are
An extra approval stage in a chain that does not match the standard one, a custom field set on employees or assets that only your sector needs, an expiry that has to block an order rather than send an email, a report your board asks for in a shape nothing produces, or a scanner or weighbridge feeding the goods-in door. These are the commissions we are asked for most often and the smallest ones we quote — and unlike a revenue-authority pipeline, none of them waits on a regulator.
The module-shaped gaps, which are the ones this blog admits most often
A price list with real discount authority, a customer-facing quotation that expires, a bill of materials or recipe costing, a staff advance that is issued, acquitted and chased, a member or unit ledger, a matching rule that holds a payment. Each of these is a build rather than a setting, and each has been quoted before — a bigger piece of work than a custom field, with a written spec and a date instead of a roadmap slide.
The report, document or pack nothing currently produces
The board pack in the shape your board actually asks for, a donor or funder layout, an invoice or receipt template carrying what your regulator or your customer expects, a dataset the report builder cannot reach yet. Usually the fastest thing on this list to deliver, because the data is already in the system.
Systems, rails and hardware you already run
The accounting package, CRM, online store, core banking or custom database you intend to keep — connected through our API so a fact is entered once and appears everywhere it is needed. Plus the physical edge: a scanner, a scale, a weighbridge or a till peripheral feeding the door it belongs to.
How it works: you describe the requirement, we return a written scope, timeline and cost, and once agreed it is built into your environment and maintained as part of the product. Nothing here waits on a regulator or a published specification, which is why operational builds are the ones we quote fastest. Tell us the requirement that would otherwise rule us out — that is a better first conversation than a demo.
Tell us what your operation needsOur take
If you only sign one end of a transfer, sign the receiving end — that is where the shortfall is discovered and the count that matters is taken. But sign both if you can. The three units are not the expensive part; the fortnight of unresolvable disagreement about them is, and that is what the second mark actually removes.
This is the second of three posts on handover signatures. The first, The Squiggle Is Not The Evidence, is about why the drawing is the least valuable part of what gets captured. The third, The Approval That Needs No Pad, is about where we deliberately refused to put one.
Frequently asked questions
Why does a stock transfer need two signatures when a goods receipt needs one?
A goods receipt has one party whose account is in question — the person who accepted the delivery. A transfer has two of your own sites that can each hold an honest, different count of the same consignment, with the difference recorded as shrinkage. One signature would document one side of that disagreement and present it as the record.
When can each transfer signature be taken?
The dispatch signature only while the transfer is still pending, and the receipt signature only while it is in transit. Neither can be added or replaced after the transfer is completed, rejected or returned. These windows are enforced, not advisory.
Does the system decide who is responsible for transit shrinkage?
No. It records the dispatched quantity, the received quantity, the difference, and a named signer with a timestamp at each end. Who bears the loss is a decision for your supervisors; the record gives that conversation two participants and a time window instead of an unowned variance.
Can we transfer stock without signing?
Yes. Both signatures are optional, at both ends. A transfer still dispatches, moves and is received with no marks on it — the signature is evidence you may want, never a condition of moving stock.
Are signatures taken per item line or per transfer?
Per transfer. The two marks sit on the transfer record alongside the dispatched and received quantities, not on each individual item line within it.