Review date: 2026-07-15
Currency: USD unless explicitly stated
Evidence policy: Current prices and limits use official primary vendor documentation checked on the review date. Architecture facts use the controlling DEC-177 through DEC-191 ledger and integration strategy. Workload quantities remain editable assumptions until telemetry exists.
Accounting boundary: Company-paid software, infrastructure, API and third-party vendor cost only. Human labor and service delivery are outside the workbook, report and every price floor. Client-owned costs, quote-only rights, taxes and unresolved invoices are excluded from priced subtotals and shown as exposures.
1. Executive finding#
The approved architecture supports viable software margins. A 120-property client’s normal buffered software COGS falls from $575.92/month at one client to $63.91 at a 10-client shared allocation, $19.11 at 100 clients, and $16.66 at 1,000 clients.
The corresponding 80% software-only floors are $2,879.61, $319.55, $95.54 and $83.29 per client-month. These are decision-support floors, not commercial prices.
The predecessor $42.45 raw / $58.58 buffered / $0.49 per property result remains verified historical evidence for the former read-only shape. It is not current truth and does not control the production model.
2. Review scope and authority#
DEC-177 through DEC-191 are the sole controlling software architecture ledger. SA-001 through SA-015 are superseded historical evidence and do not drive formulas.
The model covers:
- current fabricated development;
- 48-hour AEB read-only shadow;
- first paid shared-SaaS pilot;
- repeatable shared SaaS;
- dedicated managed deployment;
- client-owned/private deployment.
It separates fixed shared, per-client, per-property, usage-driven, optional/post-MVP, payment/collection, client-owned, and unresolved/quote-only cost classes.
Human onboarding, support, review, incident work and service delivery are not modeled. No delivery progress, frozen 22-gate denominator or MVP milestone source is changed by this economics review.
3. Model method#
3.1 Normal LTA-shaped client#
- 120 properties/client;
- four property cycles/day;
- five Temporal actions/property-cycle;
- 50 Queue messages/property-month, modeled as write/read/delete operations;
- 1,000 API requests/property-month;
- 0.25 GB primary evidence/property and a complete Supabase Storage mirror above its included allowance;
- 0.025 GB Postgres data/property;
- 0.02 GB combined logs/traces/property-month;
- 125 MAU/client;
- 20 transactional emails/property-month;
- 125,000 initial embedding tokens/property amortized over 12 months plus 3,000 query tokens/property-month.
Stress doubles usage-driven quantities but not fixed account/project fees.
3.2 Buffer and margin equations#
buffered software COGS = raw software COGS × 1.20 × 1.15
software-only price floor = buffered software COGS ÷ (1 − target GM)
Quote-only unknowns are not converted into percentage allowances.
3.3 Collection fees#
The workbook separately models no collection fee, Stripe ACH plus Billing, and Stripe online cards plus Billing. Stripe publishes 0.7% of Billing volume, 2.9% + $0.30 for online US cards and 0.8% capped at $5 for ACH Direct Debit; checked 2026-07-15. Stripe Billing · Stripe payments
4. Normal and stress results#
4.1 Normal usage#
| Clients | Raw monthly total | Buffered monthly total | Raw / client | Buffered / client | Buffered / property | Annual raw total | 70% / 80% / 85% floor per client |
|---|---|---|---|---|---|---|---|
| 1 | $417.34 | $575.92 | $417.34 | $575.92 | $4.80 | $5,008.02 | $1,919.74 / $2,879.61 / $3,839.48 |
| 10 | $463.11 | $639.10 | $46.31 | $63.91 | $0.53 | $5,557.36 | $213.03 / $319.55 / $426.06 |
| 100 | $1,384.67 | $1,910.85 | $13.85 | $19.11 | $0.16 | $16,616.06 | $63.69 / $95.54 / $127.39 |
| 1,000 | $12,070.61 | $16,657.44 | $12.07 | $16.66 | $0.14 | $144,847.32 | $55.52 / $83.29 / $111.05 |
4.2 Stress usage#
| Clients | Raw monthly total | Buffered monthly total | Buffered / client | Buffered / property | 80% floor / client |
|---|---|---|---|---|---|
| 1 | $421.62 | $581.84 | $581.84 | $4.85 | $2,909.18 |
| 10 | $516.31 | $712.50 | $71.25 | $0.59 | $356.25 |
| 100 | $2,272.02 | $3,135.39 | $31.35 | $0.26 | $156.77 |
| 1,000 | $20,962.31 | $28,927.99 | $28.93 | $0.24 | $144.64 |
The stress slope is caused by usage-driven actions, retained bytes, telemetry, emails and account/cell limits. It does not invalidate the shared-SaaS thesis.
5. Stage economics#
| Stage | Monthly company software | Per client | Per property | Client-paid software/infra | Treatment |
|---|---|---|---|---|---|
| Current fabricated development | $0 incremental | n/a | n/a | $0 | Not pricing evidence; no live/client/source data |
| 48-hour AEB read-only shadow | $58.58 predecessor | n/a | $0.49 predecessor | $0 | Historical evidence only; not current truth |
| First paid shared-SaaS pilot | $575.92 | $575.92 | $4.80 | $0 | One-client production stack |
| Repeatable shared SaaS | $639.10 total | $63.91 | $0.53 | $0 | Ten-client shared allocation |
| Dedicated managed | $944.38 | $944.38 | $7.87 | $0 | Fully buffered dedicated cell/runtime/drain sensitivity |
| Client-owned/private | $25 company | $25 | $0.21 | $575.92 | Client cloud/vendor invoices stay client-paid |
The client-owned/private row is a boundary sensitivity, not a quote. Acceptance, security, residency and client procurement remain unresolved.
6. Property-count sensitivity#
Normal 10-client shared allocation:
| Properties/client | Buffered software/client | Buffered/property | 70% floor | 80% floor | 85% floor |
|---|---|---|---|---|---|
| 25 | $58.23 | $2.33 | $194.11 | $291.16 | $388.22 |
| 60 | $60.23 | $1.00 | $200.75 | $301.13 | $401.50 |
| 120 | $63.91 | $0.53 | $213.03 | $319.55 | $426.06 |
| 250 | $71.86 | $0.29 | $239.53 | $359.30 | $479.06 |
| 500 | $96.81 | $0.19 | $322.70 | $484.05 | $645.40 |
7. Vendor and subsystem review#
All external facts in this section were checked 2026-07-15.
7.1 Cloudflare perimeter, Workers, Queues and R2#
Workers Paid is $5/account-month and includes 10 million requests and 30 million CPU-ms; request and CPU overages are $0.30/million and $0.02/million CPU-ms. Workers Logs includes 20 million events, and OTel export currently includes 10 million trace events and 10 million log events with $0.05/million additional exported events. Workers pricing · OTel export
Queues includes one million operations, then costs $0.40/million. A typical successful message uses write, read and delete operations; messages over 64 KB and retries add operations. Queues pricing
R2 Standard is $0.015/GB-month, Class A is $4.50/million and Class B is $0.36/million, with 10 GB, one million Class A and ten million Class B included. Internet egress is free. R2 pricing
Allocation: the Workers minimum is shared; requests/CPU, Queue operations and R2 bytes/verbs are tagged to tenant, client, property, job and evidence class.
7.2 Supabase/PostgreSQL and future cells#
Supabase Pro is $25/organization-month and currently includes 100,000 MAU, 8 GB disk/project, 250 GB bandwidth, seven daily backups, 100 GB file storage and one $10 organization compute credit. Small/Large/2XL published compute prices used in sensitivity are $15/$110/$410 per project-month. Disk above the included 8 GB is $0.125/GB-month; the DEC-180 second-provider object mirror is modeled as Supabase Storage at $0.0213/GB-month above the 100 GB organization allowance. Supabase pricing · Compute and disk · Storage pricing
Seven-day PITR is $0.137/project-hour, approximately $100/month, and requires at least Small compute. PITR
Approved model: a fresh project/cell, one cell through 100 clients and four cells at 1,000. Trigger: measured CPU/RAM/I/O/connections, isolation/residency, RPO/RTO or restore-test evidence. Exit: portable PostgreSQL or client-owned deployment.
7.3 Temporal#
Local open-source Temporal remains the development choice. Temporal Cloud is activated only for production/shared triggers. The public AWS Marketplace entry states a $100 monthly plan plus $50/million actions, beginning with the first billable action. Workflow starts, activities, retries, timers and signals can consume actions. Temporal AWS Marketplace
Storage, support, retention and contract nuances remain unresolved and are not guessed.
7.4 Encryption#
AWS KMS customer-managed keys cost $1/key-month; AWS charges an additional $1/month for each of the first two rotations, the first 20,000 standard requests are free, and additional standard requests cost $0.03/10,000. Asymmetric/signing request classes can differ. AWS KMS
The model uses the DEC-181 mature planning case: two keys/cell plus two priced rotations per key, with metered request sensitivity. Client-owned/private deployments can use the client’s KMS or compatible HSM boundary.
7.5 Observability#
OpenTelemetry is the vendor-neutral instrumentation layer. OpenTelemetry
Grafana Cloud Pro starts at $19/month and includes 10,000 active series, 50 GB logs, 50 GB traces and 30-day retention. The workbook uses a $0.55/GB combined first-tier processing/write/retention sensitivity above included volume and marks invoice-meter fidelity Medium. Grafana Cloud
DEC-183 also requires one Supabase OTLP Log Drain per production data cell when unified database logs are required. The model includes the current $60/project-month add-on, whole-million event packages at $0.20/million, and $0.09/GB egress. Until pilot telemetry exists, API-request volume is the editable event-count proxy and combined telemetry GB is the conservative egress proxy. Supabase Log Drains · Log Drain usage
Trigger: unified production database logs for SLO/incident evidence, production SLO evidence, and measured retained GB/events/series/users. Exit: client OTLP/local export profile or private Grafana-compatible backend.
7.6 Managed release runtime#
The approved production boundary uses ECR and ECS/Fargate, with OpenTofu and GitHub Actions for release infrastructure.
Published Linux x86 Fargate rates in us-east-1 are $0.000011244/vCPU-second and $0.000001235/GB-second, equivalent to $0.0404784/vCPU-hour and $0.004446/GB-hour. Fargate pricing
ECR private storage is $0.10/GB-month; same-region transfer from ECR to Fargate is free. ECR pricing
GitHub Free for organizations currently includes 2,000 Actions minutes/month; overage depends on plan and runner mix and remains zero until measured use exceeds the allowance. GitHub included usage
7.7 File ingestion#
ClamAV and Tesseract have no license fee, but their runtime is included in the managed compute boundary. ClamAV · Tesseract
Textract is an optional fallback after a bounded quality trigger. Detect Document Text is $0.0015/page for the first one million pages. Tables and forms use higher feature-specific rates and must be modeled separately when selected. Textract pricing
7.8 Connectors and delivery boundaries#
The approved MVP connector strategy is direct OwnerRez/Breezeway slices where authorized, neutral file delivery, no horizontal connector platform for MVP, Nango Auth-only only after the first DEC-179 trigger, read-only API/MCP surfaces, and client-owned export/Playwright delivery boundaries. Those triggers are: a second distinct OAuth provider enters production, more than 50 OAuth connections are live, or token lifecycle maintenance exceeds one engineer-week in a quarter.
Nango Free currently includes ten API Auth connections. Starter begins at $50/month, includes 20, and lists $1/connection above the tier; other meters are separate. Nango pricing
No RocketHub/Atlas connector counts or provenance are asserted. OwnerRez, Breezeway and other partner/API rights and fees remain written-entitlement gates.
7.9 Embeddings#
Workers AI BGE-M3 is $0.012/million input tokens and has an account-wide free neuron allowance. Workers AI pricing
The model amortizes initial property embeddings over 12 months and separately meters query embeddings. Trigger for the private TEI exit: privacy/residency, quality, volume or cost evidence.
7.10 Transactional email#
Resend’s current public tiers are Free 3,000/month with 100/day, Pro $20/50,000, and Scale $90/100,000; Pro and Scale overage is $0.90/1,000. Resend pricing
This differs from older illustrative values in DEC-189. The model uses the current verified page while preserving the approved Resend-with-SES/client-SMTP exit decision.
SES outbound email is $0.10/1,000 messages before attachment data and optional features. It is an exit sensitivity, not a simultaneous base charge. Amazon SES
7.11 Payment rails#
Stripe is modeled only as invoicing and collection rails. No product price is inferred from Stripe. Collection fees are tied to collected revenue and payment method. Stripe Billing · Stripe payments
8. Upgrade trigger summary#
| Subsystem | Current included/free capacity | First paid treatment | Objective trigger | Exit |
|---|---|---|---|---|
| Workers | 10M requests; 30M CPU-ms in $5 Paid | metered overage | requests/CPU over allowance for two months | rate limits/alternate compute |
| Queues | 1M operations | $0.40/M | ops, lag, retry or DLQ breach | batching/alternate broker |
| R2 | 10GB, 1M A, 10M B | Standard meters | GB/verb allowance | lifecycle/export/S3-compatible exit |
| Supabase | Pro allowances and selected compute | larger compute/cells | CPU/RAM/I/O/connections, isolation or restore | portable Postgres/client-owned |
| PITR | seven daily backups | ~$100/project-month | non-rebuildable writes, RPO <24h or failed replay RTO | backup/replay if policy allows |
| Supabase OTLP Log Drain | none in local development | $60/project + event/egress meters | unified production database logs required for SLO/incident evidence | client OTLP/local export profile |
| Temporal Cloud | local OSS development | $100 + actions | first paid production and SLO/action evidence | self-hosted/alternate engine |
| KMS | 20k standard requests; $1/key plus first two rotations | mature $6/cell two-key plan + request meters | production encryption, isolation, rotation | client KMS/HSM |
| Grafana | Pro included volumes | GB/series/user meters | SLO and retained volume | private OTel backend |
| Resend | 3k/month, 100/day | Pro $20/50k | domain, daily cap or deliverability | SES/client SMTP |
| BGE-M3 | free neuron allowance | $0.012/M input tokens | approved embeddings route and usage | private TEI |
| Textract | none assumed | $0.0015/page basic OCR | bounded Tesseract quality failure | preprocessing/alternate OCR |
| Nango | 10 Auth connections | Starter from $50 | second OAuth provider, >50 live connections, or >1 engineer-week/quarter token maintenance | direct auth adapter |
| Fargate/ECR | no standing free assumption | usage metered | paid runtime, utilization, lag, isolation/SLA | client-owned/alternate OCI runtime |
| Stripe | none before collection | revenue/transaction fee | first collected invoice | ACH/manual procurement |
9. Recovery, backup, retention and evidence#
The model includes or makes explicit daily backups and production PITR, immutable primary evidence plus the sourced Supabase Storage second-provider mirror, mature KMS envelope-encryption rotation, restore-test/RPO/RTO gates, Grafana and per-cell Supabase OTLP Log Drain telemetry retention/export, object operations/egress, audit/security/compliance exposure, and client-owned/private recovery responsibilities.
Required cost dimensions: tenant, client, workspace, property, source, connection, job, evidence class, purpose, environment, payer and occurrence time.
Required meters:
- source entitlement, requests, quota, pages, rows, bytes, retries, 429/retry-after and resync reason;
- Workers requests/CPU, Queue messages/chunks/operations/retries/DLQ;
- R2 retained/new/deleted bytes, object count, Class A/B verbs, lifecycle and export/rebuild reads;
- Postgres CPU/RAM/I/O/connections, size, egress, backup/PITR and restore duration;
- Temporal actions, retries, timers, signals, storage/retention and workflow purpose;
- KMS keys, request class, rotations and client/cell allocation;
- OTel logs/traces/events/GB/sample rate/retention and tenant attribution;
- email delivered/retried/bounced by client/property/payer;
- embedding tokens/neurons/model and Textract pages/features/fallback reason;
- Fargate vCPU/GB-hours/tasks and ECR image GB.
10. Unresolved exposures#
The following are excluded from priced subtotals:
- OwnerRez/Breezeway/other source multi-client rights, quota and fees;
- Temporal Cloud storage, support and retention nuance;
- actual shared vendor invoices and payer allocation;
- private/OpenBao managed operations and private deployment acceptance scope;
- GitHub Actions paid overage and runner mix;
- taxes, FX, regional egress and invoice jurisdiction;
- security/compliance/penetration/certification scope;
- uncapped client export/Playwright/browser delivery.
These exposures prevent a binding software price only when the proposed contract would absorb them. They do not prevent the architecture from proceeding under explicit client-paid, capped or separately priced boundaries.
Human labor and service delivery remain outside this model and must not be inferred from its outputs.
11. Quality status#
The workbook preserves the established identity and visual language while replacing predecessor calculations with a 14-sheet staged model:
- Summary Dashboard;
- Assumptions & Sources;
- Vendor Pricing;
- Unit Cost Drivers;
- Scenario Inputs;
- Architecture Cost Map;
- Scale Model;
- Property Sensitivity;
- Deployment Comparison;
- Margin Floors;
- Upgrade Triggers;
- Unresolved Exposures;
- Change Log;
- QA.
It contains 529 formulas, 38 direct official source links, zero formula errors, no missing cached formula values and all internal QA checks pass after LibreOffice recalculation. No service-delivery inputs are present.
12. Founder decision#
The next software pricing decision is the first paid pilot’s risk boundary:
- source rights and subscriptions that remain client-paid;
- backfill, document fallback, browser/export and collection-fee caps;
- single-client production-stack burden versus an explicitly temporary shared allocation.
Once those boundaries, actual invoices and source entitlements are confirmed, the workbook can produce a binding software floor without changing the architecture.