Work Operating System
An operating system for teams, money and documents
Your own teams, units, outsourcing and contractors in one installation. Payroll and payouts with the whole ledger behind them, a document store with signing, HR processes, a wiki, and permissions that reach the record. Not a set of services — one system where these are the same records.
- Teams and units
- Outsourcing and contractors
- Payroll and payouts
- Transactions and invoices
- Documents and signing
- File storage
- HR and grades
- Calendar
- Wiki
- Permissions
- One-time notes
| Person | Rail | Amount | Security |
|---|---|---|---|
|
Anna Kowalczyk
Backend
|
Revolut | €4,275.00 | Paid |
|
Marek Wisniewski
Design
|
Wise | €3,910.00 | Paid |
|
Ivan Petrov
QA
|
Payoneer | $2,400.00 | Sent |
|
Lena Sørensen
Frontend
|
Bitcoin | 0.0412 BTC | Paid |
Every row carries its signed act and its transaction. Nothing is matched by hand.
Works with what you already run
Work
- Jira
- Tempo
- Slack
Jira · Tempo · Slack · Google
Money
- Revolut
- Wise
- Payoneer
Revolut · Wise · Payoneer
And blockchain
- Bitcoin
- Ethereum
- TON
- Tron
where a contractor prefers it
The chain
From tracked hours to a payout
Most teams stitch this out of five services and a spreadsheet, and the join between hours and money rests on somebody’s memory. In WOS it is one chain, and every step leaves a record that points at the next.
-
Step 1
Tracked hours
Worklogs arrive from Jira and Tempo, grouped by task and carrying the real task names — not just the keys.
-
Step 2
Contract act
A billing scheme turns them into a numbered act, ready for signature. Polish umowa o dzieło works today; schemes are pluggable.
-
Step 3
Payroll run
Generated monthly, checked by a person, approved once. The act and the payment are linked, not matched by hand.
-
Step 4
Payout
Revolut, Wise or Payoneer; routes and methods are set per person and per company. Crypto when somebody is paid that way.
-
Step 5
Signed and filed
Signed online, hashed for integrity, and filed with the rest of the paperwork.
Money
Not just payouts — the whole ledger around them
Every operation leaves an account, a transaction and a document. Who pays whom, for what and under which contract are records in the system, not a thread in a chat.
| Type | Counterparty | Document | Amount | Transactions |
|---|---|---|---|---|
| Sent | Anna Kowalczyk Revolut · contractor | FV 04/2026 | −€4,275.00 | Paid |
| Received | Veter LLC vendor · services | INV-2214 | +€12,400.00 | Credited |
| Sent | Marek Wisniewski Wise · contractor | FV 04/2031 | −€3,910.00 | Paid |
| Sent | Ivan Petrov Payoneer · contractor | FV 04/2032 | −$2,400.00 | Sent |
| Received | Contoso GmbH vendor · licences | INV-2215 | +€8,900.00 | Expected |
Every row is tied to a company, a contract and a document — the link is made once.
-
Transactions
Sends and receipts with their history and status: draft, sent, paid, failed.
-
Invoices
Incoming and outgoing, tied to a company, a contract and a period.
-
Accounts and routes
Company accounts and the payout route per person: Revolut, Wise, Payoneer.
-
Links
Who pays whom and for what: people, companies and contracts are the same records.
Documents
Written, signed, sent and safely stored
The act from a payroll run lands here on its own. Everything else — offers, NDAs, annexes — starts from a template, goes to the recipient and stays in the same store.
- Signature — contractor p.2 · 118 × 42
- Date — company p.2 · 88 × 24
SHA-256 · 9f4c…b127 — matches the signed copy
-
Templates that know the record
Markers pull the person, the company and the contract in, so a document is generated rather than retyped.
-
Signing with placed fields
Signature, date and initials are positioned on the page per recipient, in order or all at once.
-
Integrity you can prove
Every signed file is hashed, so a later copy can be checked against what was actually signed.
-
One store, tagged
Kept on S3 with tags and reachable by the same permissions that gate the record it belongs to.
-
Absences and holidays
Requests, approval by a lead, and public holidays per country rather than per office.
-
Probations and grades
Review dates that come round on their own, five levels, and a record of who decided what.
-
Salary reviews
Proposed, discussed and approved in place, then carried into the run without re-entry.
-
Feedback that stays
Collected against the person and alive at the next review, instead of sitting in somebody’s notes.
People
The part of HR that touches the money
Not a second HR system to keep in sync — the same records the payroll run reads. A grade change moves the next salary, because it is the same row.
Grade L3 → L4
Approved 2 April · the next run picks it up on its own
What’s inside
Ten modules, one application
Not a set of products under a shared logo — one system where the people, the contracts and the money are the same records.
-
Finances
Payments, salaries, accounts, transactions and payment routes.
-
Documents
Templates, signing with placed fields, tagged file storage on S3.
-
HR
Absences, probations, grades, feedback and salary reviews.
-
Calendar
Team calendar, public holidays per country, Google Calendar sync.
-
Wiki
Internal documentation: spaces, a page tree of any depth, Markdown and search.
-
Vendors
A registry of the companies you pay, and what you pay them for.
-
Permissions
Rights narrowed to the records they reach, not just the pages they open.
-
SSO
WOS as an OAuth2 identity provider for the rest of your internal tools.
-
Audit
Every action recorded — who, when, and which rule allowed it.
-
One-time notes
Hand over a password or an access link that can be read once and then disappears.
Security
Built for the data it holds
This system knows what everyone is paid and holds the keys that move money. That decides how it is built.
-
A separate database per customer
Your installation is yours alone. No shared tables and no tenant column for one wrong query to forget.
-
Permissions that reach the record, not the page
A grant is a rule, not a checkbox: this role reaches these projects, accounts and spaces. The list and the policy run the same rule and cannot drift apart.
-
Two-factor, and again where it matters
Sensitive actions ask a second time, even inside a session that already passed two-factor.
-
Everything audited
Every change is recorded with the rule that permitted it, so an access question has an answer rather than a theory.
| Permission granted | Ewa Bonk Payroll lead | 3 days ago 9 Apr 2026, 11:04 |
access.role.grant
|
→ QA · 2 projects |
| Payout approved | Ewa Bonk Payroll lead | 2 days ago 10 Apr 2026, 14:02 |
finances.payout.approve
|
€14,812.00 |
| Transfer failed | System Payoneer webhook | 2 days ago 10 Apr 2026, 14:06 |
beneficiary_mismatch
|
retried, then paid |
No slide deck. We open your data and walk the chain.
See it on your own numbers
A short call, your actual contracts, and a walk through the chain end to end.
Swapping between assets is planned.