Scott Molluso · for Safeguard Properties
Arrow keys to advance
The thesis
The new moat is a system that compounds. Every order, every state, every denial makes the next decision better — so what you own is worth more next year than the day it shipped.
Who is saying it
20+ years in proptech
Property data, disclosure, brokerage, field services.
Founder and operator
Built and ran platforms. Two past $3M ARR. Carried the P&L.
Builder
25+ production systems. Nobody writes them for me.
What you run today
Integration gateway
Vendors, clients, partners
Mobile app + portal
Inspectors
Mobile app + portal
Contractors
Portfolio and results
Clients
Reporting
Clients and internal
Inspect is a card list with map and grid tabs. Preserve is a station checklist that looks a decade older. Two crews at the same address open two apps that do not look like they came from the same company — and Connect exists to join them, which is a product you only build when the things being joined are separate systems.
What I am proposing
The rebuild, running












What needs a decision today, priced by what is still recoverable.
1 / 6The fix, in the field
In SafeView today
Inspect and Preserve are separate applications. A contractor holding both orders for one address opens two apps, and neither knows the other exists.
In Safeguard OS
One queue, both work types, ordered by the drive rather than by which app owns the record. The two orders at 14553 US 33 sit together because they are one stop.
Labels come from the work code, the missing photo is raised on the lot, and there is no Transmit button.
Installable today · native code written
Open safeguardprop.com/app on a phone, then Share → Add to Home Screen. Own icon, full screen, no browser chrome.
The iOS and Android projects are in the repository, so a native binary is a build step rather than a rewrite.
Matching what your crews already have
| Capability | Inspect and Preserve today | Safeguard OS |
|---|---|---|
| Works with no signal | Two queues, two Transmit buttons | One queue, writes when signal returns |
| Getting work to the crew | Push notification | Push notification |
| Photo capture | In-app camera, labels picked by hand | In-app camera, labels from the work code |
| Scheduling and contact attempts | Inspect only, its own tab | On the order, both work types |
| List, map and grid views | Inspect only | One queue, sorted by the drive |
| Background upload | Yes, native | Needs the native build. It is in the repository. |
| Getting a fix to the field | App store release, if the crew updates | The moment it deploys |
Offline is not the thing I would remove — the queue is right and the button on top of it is not. Two of them, in two apps, is the same failure twice.
Which is the whole disagreement
Your ask
An agent built on top of SafeView finds the missing photo at the denial.
My build
An agent built inside Safeguard OS finds it before the truck moves.
Same model either way. I would build the agents you asked for — I would just put them somewhere they can still change the answer.
The fix, underneath
AI, on top
6 agents, each governed by five versioned documents, gated at every irreversible action and scored by an eval suite before a rule change reaches a live order.
One record
Thirteen stages, one row. An order arrives from a servicer, gets routed to a crew, worked, evidenced, bid, claimed, packaged, invoiced and paid without being re-keyed once — which is the only reason the claim can still cite the photograph.
Surfaces
Four ways in, writing to and reading from the same record rather than to four databases that have to be reconciled afterwards.
One stack
The only gateway here faces outward, at servicers. Connect faces inward, between five products that all belong to you — and there is nothing left for it to integrate.
Underneath it
Inspected in March, conveyed in November, one record throughout.
properties · work_orders · inspections · claims
Every decision stamped with the rules in force that day, and they cannot be edited after.
agents · governance_versions · eval_runs
Every irreversible action carries who approved it, what happened, and what it cost.
agent_runs · agent_actions · escalations
HUD rules stored as data with page citations, so changing one does not mean redeploying an agent.
hud_chunks · pp_allowances · schedules
Thirty-two migrations, every one reviewed like code. The rules that matter are enforced by the database itself, so nobody can write a screen that skips them.
One of your asks, already answered
Your brief asks for versioned agent instructions and a regression process that proves a prompt change did not break anything. I built that as its own product, in a day, and the agents in your OS already run inside it.
rulekeeper.aiHow the moat gets built
An agent approves an allowable or drafts an appeal, against the rules in force that day.
Paid or denied, tied to the exact rule that made the call.
What the denial taught gets written down, rather than remembered by whoever was there.
The new rule is tested against every past case before it is allowed to decide anything.
The next call is made on a rule already proven better than the last one.
You do not have to take my word for step four. A rule that scores worse than the one it replaces is refused by the database itself — not by a policy somebody has to remember to enforce.
One more thing
One person. No access to your data, systems or people. Both repositories have a git log.
The proposal
Condition, occupancy and cost history on millions of properties. Insurers, investors and valuation firms buy exactly this today, from companies holding far less of it.
You can tell a servicer which properties will cost them money before they know. That is a subscription, and it is priced differently from a work order.
Publish what share of disputed dollars you get back. Nobody else can put that number in a pitch, because nobody else has the evidence attached to the order.
Insurance inspections, title condition, tax and code. The loop is identical, the corpus is already yours.
Same move, different asset class. Whatever this becomes is a template the next one starts from.
Field services runs on software somebody has to build. We own it together and sell it to the industry.
None of these are software problems any more. They are all the same problem: the knowledge exists and nothing can currently act on it.
The arithmetic
What it costs
One builder, twelve months.
Against the squad this scope normally takes: six engineers, a product manager and a designer, for a year. Price both from your own payroll and the gap is the number.
What it saves in time
Months, against a multi-year bet.
A surface rebuild has carried a two-to-three year estimate for as long as anyone has been quoting it. Twenty-six hours of evidence sits four slides back.
What it costs to run
$25.40
Every model call this system has ever made, across 7 production runs. Read from the database as this slide rendered. The agents are not the expensive part.
Revenue you earned and did not collect. Two attempts exist per decision and most are abandoned.
Cost incurred with no bill behind it, because approval was decided after dispatch.
One SCRA or PTFA finding, against a banner somebody was supposed to remember.
Capacity is the constraint in this business. Every hour re-entering a job is an hour off a property.
I have not seen your claim volume, your denial rate or your engineering budget, and I am not going to invent them. Put your own numbers against these four lines. Every one of them is something the rebuild changes.
The obvious objection
Month one
The new system queries your system of record where it already lives. Nothing is copied, nothing is converted, and your database does not change. If month one fails you have lost a month and no data.
Months two to six
New work is written in both places and the old one stays authoritative. Every screen can be checked against the system you already trust, on the same order, on the same day.
Only then
Migration becomes a decision made with a year of evidence behind it rather than a leap taken on a promise. If the answer is never, the system still works.
A rebuild that needs a data migration on day one is a rebuild nobody approves, because all of the risk arrives before any of the benefit. This one runs beside what you have until you would rather it did not.
The ask
Paid monthly, against an outcome. Month one is your exit.
Measured on what is in production, not in progress.
Listed in writing. Everything built for you is yours.
Give me a month and the keys. If it does not land, you stop. The rebuild runs three to six months after that, depending on whether the servicer integrations and the history come with it.
Why I am confident about the timeline
RoofBoard is the closest to your business: dispatch a crew, prove the work was done, invoice, defend it when somebody disputes the evidence. Draw does the second half of that for construction. The rest are why twelve months is an estimate rather than a hope.
See all 45 at molluso.aiWhere this goes
One module of your five, rebuilt end to end, with your data and your people. If it does not land you have spent a month. If it does, the other eleven build the thing this deck is about.
Appendix · diligence
Every line on the right is a file, a table or a column. All of it is checkable in under a minute, by anyone, without asking me.