Back to blog
Product · 28 April 2026 · 4 min read

One Platform, Sold In Pieces

Most multi-module SaaS is a federation of products that share a login. We sell something else: a single nervous system where empty seats at the table are designed in, and the upsell isn't a banner. It's missing data, shown specifically.

Aditya Varma
Aditya Varma
Founder / Director

Most multi-module SaaS platforms are really a federation of products that happen to share a login screen. You buy Incidents, you get incidents. You buy Inspections, you get inspections. The two modules know about the same employees because they have to, but they don’t really talk to each other. A near-miss never triggers a follow-up inspection. An inspection finding never opens a corrective-action loop. The login is shared; the meaning isn’t.

That’s the world we deliberately built away from.

What we actually sell

When a council buys Lattice Look, they aren’t picking items out of a catalogue. They’re choosing how many seats at the same table are filled. The table is the platform: one schema, one auth surface, one nervous system, sixteen modules wired into each other from day one. The empty seats are still part of the table. Adding another module isn’t “installing more software”; it’s lighting up an existing chair.

The distinction sounds semantic. It isn’t. It changes what an empty seat looks like in the UI, and that’s where the strategy lives.

What an empty seat looks like

Most platforms hide what you haven’t bought. The page renders fewer cards, the sidebar shows fewer icons, and the customer never knows what they don’t have. The default mode is concealment.

We do the opposite. On every cross-module surface, a module you haven’t enabled shows up as a placeholder card with the same size, shape, and position as the populated card would have. The dashboard doesn’t reflow when you turn the module on; the empty space simply fills with data.

Inside the placeholder is a single sentence. Not “unlock more features.” Not “upgrade to access advanced reporting.” Something specific:

Enable Risk Management & SWMS to auto-draft risks from inspection findings and surface stop-work counts on the Risk Surface dashboard.

Vague upsell copy is worse than none, because it trains the customer to ignore the prompts. The specific version names the exact join the customer is missing: the answer they would have got on this incident if the next module were on. The upsell engine isn’t a banner ad. It’s missing data, shown precisely.

Why this only works if the schema commits

Cross-module surfaces only earn their keep if the connections are real. A “we’ll join on email at runtime” platform can’t credibly tell you what an enabled module would have shown, because it doesn’t actually know. The placeholders would either be lies or generic.

Our cross-module connections are bidirectional foreign keys, written into the schema across three migrations. An incident row knows the inspection that followed it. An induction row knows the incident that triggered it. A benchmarking snapshot pours metrics from every safety module into the cohort comparison engine. The full architecture is described in multi-tier interoperability; the short version is that the wiring is in the database, not in middleware.

Real foreign keys are what let us promise, and audit, that no module is an island.

What it feels like as a buyer

A council that’s only bought Incidents and Compliance still sees, on every incident detail page, exactly which other modules would have given them more answers, and exactly what those answers would have been. That’s the upsell.

A council that’s bought everything sees the platform we actually wanted to build. A fall-from-height incident at 9:14 a.m. propagates within seconds: a follow-up inspection is auto-scheduled, an RTW induction is queued, the worker’s PPE fall-arrest assignment is reviewed, the controlled SWMS document in force that day is pinned to the case, a working-group thread is shared with peer councils, the cohort benchmark is refreshed, and a new training-demand signal points at provider procurement.

Same data. Same employee. Same incident. Sixteen perspectives that line up and reinforce each other.

The point

We don’t sell modules. We sell more or less of one platform. The architecture has to back that up, and the empty seats have to look like empty seats at the same table, not absences from a different product.

Once you frame it that way, the design choices fall out of it. The placeholder card is the same size as the real one. The upsell sentence names the join, not the feature. The foreign keys are real. And the mechanical audit that keeps all of this honest never grades its own work. That last bit is the engineering story, and it’s a separate post.

For depth on how the connections are wired, see multi-tier interoperability. For specific examples of how the seats fill in, see incident management competency snapshots and inspections and hazard reporting.

platform interoperability product-strategy upsell graceful-degradation

Ready to see Lattice Look in action?

Five minutes to sign up. Free onboarding.