AI-native service blueprint · 2026-07-16-0112
Final decision: Blueprint

GuardFile Clear: CA PPO SB 513 / BSIS Training-File Completeness Desk

Done-for-you training-file completeness for California Private Patrol Operators—so guard certificates, Powers to Arrest / Appropriate Use of Force records, CE logs, and firearms/baton quals meet SB 513 personnel-file fields, CCR §643 certificate elements, and BSIS inspection readiness without drowning the Qualified Manager in PDF archaeology.

3,077Active CA PPO licenses (BSIS, Feb 25, 2026)
351,170Active security guard registrations
$750Civil penalty / late personnel-file response
~87/100Rubric · Gates ~28/30

Executive summary

On January 1, 2026, California SB 513 amended Labor Code §1198.5 so that education and training records an employer maintains are expressly part of the personnel file employees (and former employees) can inspect and copy. If a PPO keeps training records—which BSIS already requires for Powers to Arrest / Appropriate Use of Force, skills training, and related certificates—those records must include specified fields (employee name, provider, date and duration, core competencies, resulting certification) and must be retained at least three years after termination. Failure to produce records within 30 calendar days exposes the employer to a $750 civil penalty, injunctive relief, and attorneys’ fees—on top of BSIS inspection risk when certificates lack serial numbers, instructor names, DCA compliance statements, or the single combined PTA/AUF certificate.

GuardFile Clear sells a managed outcome: a QM-approved Training-File Completeness Pack (gap scorecard + field remediation tickets + retention/request SOP + evidence vault) and optional monthly Roster File Desk for new hires and annual CE. AI extracts certificate fields from scans/PDFs; rules check SB 513 + CCR §643 + BPC §7583.6; a human ops reviewer QA’s exceptions; the customer’s Qualified Manager approves remediation. Not legal advice. Not BSIS practice. Not a customer-operated HR co-pilot. Outcome pricing by pack/month—never hourly.

Thesis

PPO training documentation is a high-frequency, document-extraction workflow sitting at the intersection of BSIS licensing rules and a brand-new Labor Code access/retention mandate. Buyers already pay office admins, CALSAGA dues for certificate databases, and episodic audit consultants. Frontier models collapse messy certificate PDFs into structured, field-complete personnel artifacts; expert ops + QM approval keep statutory responsibility with the licensee. As models improve, throughput rises and COGS falls without changing the sold outcome: complete, request-ready, inspection-defensible training files.

Discovery rationale

This run restored a truncated manifest.json (concurrent research stub had collapsed history to 1 stub entry; recovered 407 runs from tip fcea9c33 / WDOFile Clear) and steered away from CancelPath-adjacent subscription clones, CareRenew daycare renewals, and WDO Connect filing (just claimed H00). Fresh searches across SB 513/PPO training files, NY WTPA hire notices, dental BBP ECPs, car-wash ARL, marina submeter disputes, HVAC membership cancel pathways, and CBAS/ADHC documentation showed the strongest CODE + budget + narrow MVP signals in CA PPO SB 513 / BSIS training-file completeness: law effective Jan 1, 2026; industry-specific consulting content already selling audits; Sundahl pricing for 3-file site visits; CALSAGA training-database membership spend; 3,077 PPOs / 351k guards.

Candidate comparison

CandidateScore /100Fatal?Why ranked
GuardFile Clear — CA PPO SB 513 training-file desk87NoWinner: Jan 1 2026 trigger, BSIS + Labor Code dual pressure, clear DFY wedge vs. Kearnan/Sundahl/CALSAGA tools
Notice195 Clear — NY LL §195.1 hire-notice pack68NoClear statute + penalties; PEO/payroll incumbents crowd whitespace
DentalBBP Pack — dental ECP annual completeness58SoftReal Cal/OSHA duty; BayArea Compliance-style SaaS+service crowded; templates abundant
WashRenew — car-wash ARL cancel pathway54Near-dupToo close to CancelPath beachhead; defer until fitness vertical proves DFY playbook
MarinaMeter — marina slip submeter dispute pack49PartialTariff rules real; weak public buyer-spend / DFY demand proof this run
HVAC Membership Cancel Desk47Near-dupOverlaps CancelPath + ServiceTitan ops tooling; defer

CODE validation

  • Consumer/buyer trend: SB 513 effective Jan 1, 2026 expands personnel-file rights to training records; BSIS continues PTA/AUF curriculum enforcement (post–Jul 1, 2023 update); PPO complaints remain the largest BSIS complaint category (~42% of Jul 2025–Feb 2026 complaints).
  • Opportunity: Small/mid PPOs store certificates in email folders, paper binders, and mixed LMS exports. Certificates often miss serial numbers, instructor names, duration, or core-competency language. Old WMD-era PTA certificates persist. Former-employee requests and BSIS inspections both need the same field-complete file—and nobody owns the remediation ops.
  • Demand: Kearnan published an industry SB 513 checklist urging immediate audits; Sundahl sells BSIS audit prep from $1,000 (only 3 employee files); CALSAGA sells membership partly for a training-certificate database; CALSAGA PPO Toolbox warns training certificates are a primary BSIS audit item.
  • Economic sizing: 3,077 PPOs × assume ~40% SMB without dedicated compliance staff (~1,230) × $2.5k–$8k/yr DFY spend ⇒ ~$3.1–$9.8M service TAM in beachhead alone (inferred). Guarding revenue in CA estimated ~$1.2B (secondary industry stats; treat as directional). Capture 150 accounts at $4.8k ARR ⇒ ~$720k with 50%+ GM path.

Rubric scorecard (1–5)

DimensionScoreNote
Low trust burden4Already outsourced to office admins / consultants; vendor operates behind QM
Low task-level judgment4Field extraction + checklist mostly deterministic; exceptions reviewable
High intelligence threshold4Multi-format certificates, curriculum vintage detection, roster matching
Regulation as moat5Labor Code + BSIS dual accountability
No physical labor5Remote document/ops (site visits optional upsell, not core)
Sam Altman test5Extraction/normalization improve with frontier models
Outcome pricing5Per pack / per month desk
Gross margin potential450%+ after automation; watch PII/security handling cost
Buyer urgency5Law already effective; $750 + BSIS risk
Competitive whitespace4Consultants & association tools exist; continuous DFY desk underserved
Novelty vs manifest5No prior PPO SB 513 training-file blueprint
AI capability fit5OCR + structured extraction is a core model strength
Active demand evidence4Industry checklists, audit services, association tooling
Budget/competitor proof5Sundahl $1k+, CALSAGA dues, Kearnan audits
Waitlist/lead-magnet potential5Free Friction Scan of 10 files
Narrow MVP wedge5One pack: SB 513 field completeness for active roster sample
Distribution clarity4CALSAGA, LinkedIn QM/owner lists, BSIS licensee directories
Licensing feasibility4Ops documentation vendor; clear no-UPL / no-BSIS-practice boundary
Operational repeatability5Checklist + templates + exception queues
Speed to first revenue5Manual first 3 customers with Drive + checklist

Total ~87/100. Six-gate sum ~28/30 (see Go/no-go).

Target buyer

ICP: California Private Patrol Operator (PPO) companies with roughly 15–250 security guards, 1–5 branch offices, owner-operated or thin admin (office manager / HR generalist / Qualified Manager doubling as ops). Beachhead: Southern California + Bay Area PPOs that still use paper/PDF certificate folders or generic HRIS without BSIS-aware fields.

Economic buyer: PPO owner / Qualified Manager / Director of Operations. Trigger events: SB 513 effective date, impending BSIS inspection, former-employee personnel-file request, insurance carrier loss-control ask, CALSAGA conference scare talk, failed internal audit of three sample files.

Jobs-to-be-Done

  • When BSIS or a former guard asks for training records, produce a complete file in <30 days without scrambling.
  • When onboarding a new guard, file a field-complete certificate set before the officer hits a post.
  • When CE season hits, prove the 2-hour AUF refresher + remaining hours are documented and serialized.
  • When counsel/insurer asks about negligent-hiring exposure, show an auditable training vault.

Painful problem

PPOs already must maintain registrant training records under BPC §7583.6 and issue CCR §643-compliant certificates. SB 513 now makes those same records personnel-file objects with mandatory fields, 3-year post-termination retention, and a hard 30-day production clock. The work is tedious, multi-format, and high-stakes—yet too narrow for big HRIS vendors and too continuous for a $1,700 one-day audit visit that only samples three files.

The outcome we sell

Deliverable: A QM-approved Training-File Completeness Pack containing (1) roster coverage map, (2) per-file SB 513 / CCR §643 / curriculum-vintage scorecard, (3) remediation tickets with exact missing fields, (4) retention & 30-day request SOP, (5) evidence vault of normalized certificate metadata + source hashes. Optional: monthly Roster File Desk for new hires + CE renewals.

Customer experience: “Our training files are request-ready and inspection-ready.” Not “we bought another dashboard.”

First one-feature MVP wedge

ElementDefinition
ICPCA PPO, 15–120 guards, PDF/paper-heavy training files
TriggerSB 513 now in effect / upcoming BSIS inspection / first former-employee request
PainCannot prove field-complete training personnel files at scale
One-feature MVPActive-roster Completeness Pack for up to 40 guards (or first 40 sampled)
InputRoster CSV + certificate PDFs/photos + training facility IDs
OutputScorecard + remediation tickets + request SOP + vault index
Human chokepointOps reviewer QA + customer QM approval of remediation plan
Success metric≥90% of sampled files reach “field-complete or ticketed with owner” in ≤10 business days
What users ask nextMonthly desk, ex-employee archive backfill, firearms/baton permit overlay, multi-branch rollup

Evidence summary

  • Verified SB 513 amends LC §1198.5; effective Jan 1, 2026; training records require specified fields; 3-year post-termination retention; 30-day production.
  • Verified BPC §7583.6 requires PPOs to maintain training completion records for the duration of registrant employment, available to BSIS.
  • Verified CCR §643 certificate elements (hours, entity, instructor, serial number, DCA compliance statement).
  • Verified BSIS Apr 2026 staff report: 3,077 PPOs; 351,170 guards; PPO complaints 42% of recent complaint volume.
  • Verified Sundahl BSIS audit prep from $1,000 base (+ travel), reviewing only three employee files.
  • Verified CALSAGA membership includes training database for serialized certificates; PPO dues $250 + per-officer fee.
  • Inferred Many SMB PPOs still outside CALSAGA database discipline or hold legacy incomplete PDFs.
  • Unverified Exact statewide % of PPOs currently SB 513 field-complete—treat as unknown; use Friction Scan to measure.

Claim table

ClaimLabelConfidence
SB 513 effective Jan 1, 2026 expands personnel records to education/training records with required fieldsVerifiedHigh
$750 civil penalty available for late personnel-file productionVerifiedHigh
PPOs must maintain registrant training records for employment duration (BPC 7583.6)VerifiedHigh
CCR 643 requires serialized certificates with instructor, hours, compliance statementVerifiedHigh
3,077 active PPO licenses / 351,170 guards (BSIS Feb 25, 2026)VerifiedHigh
Sundahl audit prep ~$1,000+ for 3-file site visitVerifiedHigh
CALSAGA members get training DB for serialized certs; dues prove budgetVerifiedHigh
Beachhead TAM ~$3–10M DFY service spendInferredMed
50%+ gross margin by day 90 with AI extractionInferredMed
% of PPOs currently non-compliant on SB 513 fieldsUnverifiedLow

Source-claim matrix

ClaimLabelSourceTypeDateConf.Section
SB 513 amends LC 1198.5; training records + required elementsVerifiedleginfo SB 513Primary statute2025–26HRegulatory
Field list + 30-day access + 3-year retention commentaryVerifiedLittler SB 513Law firm2025/26HEvidence
$750 penalty / injunctive relief / feesVerifiedAALRR SB 513Law firm2025/26HPain
Security-industry SB 513 checklist & certificate elementsVerifiedKearnan SB 513Industry consulting2026HDemand
BPC 7583.6 PPO recordkeepingVerifiedBPC 7583.6Primary statuteCurrentHLicensing
CCR 643 certificate requirementsVerifiedBSIS Order of Adoption / §643RegulationPost-AB229HRegulatory
PTA/AUF training manual & BPC citesVerifiedBSIS POA manualAgencyCurrentHMVP
3,077 PPOs; 351,170 guards; complaint mixVerifiedBSIS Staff Report Apr 2026Agency2026-04HMarket
Sundahl audit prep $1,000+/3 filesVerifiedSundahl BSIS Audit PrepVendor pricing2025/26HBudget
CALSAGA training DB + duesVerifiedCALSAGA Member BenefitsAssociationCurrentHBudget
Training certs are primary BSIS audit itemVerifiedCALSAGA PPO ToolboxAssociation2024HConversations
CA private security revenue ~$1.2BInferredGitnux CA security statsSecondary2026MMarket

Market and demand evidence

BSIS reports 3,077 active PPO licenses and 351,170 security guard registrations as of February 25, 2026, plus 5,320 PPO Qualified Managers. PPO-related complaints were ~42% of BSIS complaints from Jul 1, 2025–Feb 25, 2026—signaling ongoing regulatory friction. Industry secondary estimates put California private security revenue near $1.2B (directional). SB 513 creates a statewide employer obligation; PPOs feel it acutely because training certificates are already BSIS-critical artifacts.

Active buyer conversations

  • Kearnan’s public SB 513 checklist tells PPOs to “audit every active employee’s personnel file” and designate a records custodian—language that maps 1:1 to a DFY pack.
  • CALSAGA PPO Toolbox warns members that training certificates are among the first items checked in a BSIS audit and that missing certificates often require re-training.
  • Sundahl markets pre-inspection file reviews because “it’s usually better for a contractor on your side to find violations.”
  • Littler / AALRR / CalChamber employer alerts create general HR urgency that security-industry operators translate into certificate panic.

Competitive landscape

PlayerWhat they sellGap
CALSAGA Training DatabaseMember tool to generate serialized certificatesDoesn’t remediate historical mess; membership-gated; not DFY ops
Sundahl & AssociatesEpisodic BSIS audit prep site visit (~$1k+ / 3 files)Sample-based, not continuous completeness; travel-heavy
Kearnan ConsultingCompliance consulting / program reviewAdvisory, not AI-native throughput desk
Generic HRIS / DropboxStorageNo BSIS/SB 513 field logic
GuardFile ClearDFY completeness pack + optional monthly desk

Competitor and budget validation

Budget already exists in three buckets: (1) office-admin labor hours for certificate chasing, (2) CALSAGA dues ($250 + per-officer fees) for training tooling, (3) episodic consultants ($1,000–$1,700+ for a thin 3-file prep). GuardFile redirects that spend into a packaged outcome covering the full sampled roster with AI leverage. Win condition is not “no competitors”—it is better unit economics and completeness coverage than sample audits + self-serve databases.

Pricing evidence and proposed pricing

OfferPriceUnit
Friction Scan (lead magnet)$0Up to 10 certificates → gap scorecard
Founding Completeness Pack$1,499Up to 40 active guards (first 20 customers)
Standard Completeness Pack$2,499–$4,999Tiered by roster size / branches
Ex-Employee Archive Backfill$999–$2,999Per 50 former employees (3-year window)
Roster File Desk$399–$999/moNew hires + CE file ops + quarterly re-score
Inspection Sprint$1,99910-business-day rush before known BSIS visit

Never hourly. Optional pass-through for third-party re-training fees if customer elects re-certification—not contingency pricing.

Regulatory and compliance considerations

  • Labor Code §1198.5 / SB 513: training records as personnel records; required elements; access rights; retention.
  • BPC §7583.6 & related private security act: PPO must maintain training verification records for registrants; BSIS inspection rights.
  • CCR §643: certificate content, serial numbering, trainer retention of exams/certificates.
  • PTA/AUF curriculum shift (AB 229 / AB 2515): new Guard Card applicants need updated combined training—not legacy WMD-only.
  • Privacy: personnel files contain PII; need BA-style data handling, least-privilege vault, deletion schedules.

Licensing boundary

ActivityWho
Extract, classify, score certificate fields; draft remediation tickets; maintain vault indexAI + trained ops
Approve remediation plan; decide re-train vs. obtain missing cert; respond to employee requests; represent company to BSISCustomer QM / employer
Issue BSIS certificates / teach PTA/AUF / act as training facilityLicensed TF / authorized PPO trainer—not GuardFile unless separately licensed
Legal opinions on Labor Code exposure, negligent hiring, use-of-force liabilityCustomer counsel—never GuardFile

Must not claim: “BSIS-approved,” “guarantees clean inspection,” “legal compliance opinion,” or practice as a PPO/TF. Position as administrative documentation & completeness operations vendor under customer authorization. Written disclaimer on every pack.

AI-native advantage

AI changes the economics by reading heterogeneous certificate PDFs/photos, normalizing fields against SB 513 + CCR §643 schemas, detecting curriculum vintage (WMD vs PTA/AUF), matching roster identities, and generating remediation tickets at a cost far below human file clerks. Humans stay at judgment chokepoints (ambiguous names, missing pages, re-train decisions). Better models → cheaper completeness, not a new customer-facing chatbot.

Internal AI engine architecture (10 layers)

  1. Intake: secure upload of roster + certificates; chain-of-custody hash.
  2. Normalization: OCR, deskew, dedupe, page classification.
  3. Retrieval/knowledge: SB 513 field schema, CCR §643 rules, PTA/AUF vintage markers, customer prior gold files.
  4. AI workbench: field extraction, competency text synthesis from course titles, gap classification.
  5. Deterministic rules: required-field presence, serial format, single-cert PTA/AUF rule, retention clock math, 30-day request SLA timers.
  6. Human chokepoint: ops QA on low-confidence extractions; QM approval of remediation.
  7. QA: second-pass sampling, schema validators, red-team missing-page checks.
  8. Delivery: pack PDF + ticket CSV + vault index + SOP.
  9. Learning loop: correction → prompt/rules/gold examples.
  10. Model-portability: provider-agnostic extraction interface; rules layer survives model swaps.

AI-vs-human operations pipeline

AI
OCR + extract certificate fields; detect WMD vs PTA/AUF; map to roster
Rules
Score SB 513 / CCR 643 completeness; flag retention & request SLA risks
Human ops
Review low-confidence files; write remediation tickets; assemble pack
QM (customer)
Approve plan; authorize re-train / records request responses
QA
Sample 10% of “complete” files; verify vault hashes
Delivery
Issue Completeness Pack; schedule Desk cadence if subscribed

Dynasty translation layer

  • Buyer: PPO owner/QM paying to avoid $750 penalties, BSIS pain, and lawsuit discovery gaps.
  • Service: DFY completeness + optional managed monthly file ops.
  • Workflow: intake → extract → score → ticket → QM approve → vault → renew.
  • Tooling: Drive/S3 vault, extraction models, checklist DB, CRM; later light customer portal.
  • Sales: “We’ll tell you which of your 40 files fail SB 513/BSIS fields in 72 hours—then fix the ops.”
  • Delivery: Manual for first 3; automations after pilot 5–10.
  • Expansion: PSE employers, training facilities, multi-state guard firms with CA beachheads, firearms/baton permit overlays.

Anti-duplication analysis

Checked restored manifest (407 runs) + root *-blueprint.html filenames. No prior slug for PPO SB 513 training-file completeness. Adjacent but distinct: FCRA adverse-action engine (employment screening letters), I-9 engines, tip-pool packs, CancelPath (fitness cancel pathways), WDOFile (pest WDO Connect). GuardFile’s buyer (PPO/QM), workflow (certificate field completeness), and outcome (request-/inspection-ready training personnel files) do not match those entries.

Anti-commoditization analysis

If future general models let QMs self-extract certificates, GuardFile still wins on (1) maintained rule packs for SB 513 + CCR 643 + curriculum vintage, (2) exception queues and QA sampling, (3) retention/request SLA operations, (4) multi-branch evidence vaults, (5) trust interface that keeps the QM as the customer-facing accountable party. Commodity OCR ≠ inspection-ready ops product.

Service delivery workflow

  1. Kickoff + authorization + data-processing terms.
  2. Roster ingest + certificate bulk upload.
  3. AI extraction + rules scoring.
  4. Ops QA + ticket drafting.
  5. QM review call (30–45 min).
  6. Remediation execution support (templates, re-train tracking)—customer remains trainer/employer.
  7. Pack delivery + vault.
  8. Optional Desk: weekly new-hire batch + monthly CE sweep.

Operations as product

SOPs for intake completeness, required evidence lists (roster fields, certificate types), automated completeness checks, exception queues (illegible scan / name mismatch / missing serial), reviewer assignment, confidence scoring, audit trails, versioned scorecards, gold-standard certificate examples, red-team missing-page tests, customer-ready pack templates, root-cause tags (trainer omission vs. storage failure), postmortem loop after any failed BSIS finding on a covered file.

No-holes quality engine

  • Schema validators for every SB 513 field.
  • CCR §643 element checklist including serial + instructor + compliance statement.
  • PTA/AUF single-certificate rule check.
  • Retention clock computed from termination date when provided.
  • Dual control: extractor ≠ final pack signer (ops lead).
  • Customer QM sign-off recorded before “complete” status.

What the human expert actually does

TaskLicense?Min/unit launchMin/unit day 90Automation pathQuality riskCannot automateAudit trail
Intake completeness checkNo155Checklist botMissing pagesJudging corrupt uploadsIntake log
Low-confidence extraction reviewNo83Better OCR/modelsWrong hoursAmbiguous handwritingReview notes
Remediation ticket writingNo62Ticket templatesVague ticketsPrioritizing re-train vs retrieveTicket IDs
Pack QA sampleNo20/pack10/packAuto-sampleFalse completeSpotting systemic trainer failureQA sheet
QM advisory callNo (not legal advice)4025Async loom + checklistScope creep to legalTrust / escalation decisionsCall notes
Customer QM approvalPPO QM (customer)3015n/aRubber-stampingEmployer accountabilitySigned approval

Minimum viable offer

GuardFile Completeness Pack — Founding $1,499: Friction Scan of 10 files free → paid pack for up to 40 active guards within 10 business days → scorecard + tickets + SOP + vault. Upsell Desk at $499/mo after pack acceptance.

Fulfillment process (first 3 customers)

  1. Shared Drive folder + NDA/DPA + authorization letter.
  2. Manual checklist in Sheets; Claude/GPT extraction assist on each PDF.
  3. Human-built scorecard PDF.
  4. Zoom QM review.
  5. Deliver pack; capture corrections into SOP v0.1.
  6. Automate extraction batching only after pilot #5.

Tools and systems

Day one: Google Workspace / encrypted S3, spreadsheet roster DB, PDF OCR (model API), Notion/Linear tickets, Stripe invoicing, Calendly, DocuSign for QM approval. Later: light portal, webhook from customer HRIS, automatic CE calendars. No custom platform before revenue.

Human-in-the-loop quality control

Confidence <0.85 → mandatory human review. 100% review on firearms/baton quals in MVP. Random 10% re-score of “green” files. Any customer dispute opens postmortem within 48 hours. Never auto-send packs without ops lead sign-off.

Nonlinear scaling and unit economics

MetricLaunchDay 90Year 1 target
ASP Completeness Pack$1,499–$2,499$2,499$2,999 blended
COGS / pack (inference + ops minutes + QA + tools)~$700 (53% GM)~$450 (70% GM)~$350 (75%+ on pack)
Desk COGS / mo~$220 on $499~$150~$120
Automation %35%60%80%
Throughput / ops FTE / day8–12 files25–40 files60+ files
Rework rate<15%<8%<5%
Revenue / FTE~$12k/mo~$25k/mo~$40k+/mo
CAC payback≤2 packs or ≤3 Desk months
Scan→paid≥8%≥12%≥15%
Pack→Desk≥35%≥45%≥50%
Gross margin target≥50%≥60%≥65% blended

COGS breakdown: model inference, secure hosting, ops review minutes, QA sample, support, sales follow-up, compliance documentation. No filing fees. PII security tooling included in hosting line.

Distribution proof table

ChannelWhy ICP reachableFirst angleConv. assumptionProof sourceMeasurementFollow-up
CALSAGA / Security UniversityPPO associationSB 513 file clinic5–10 scans / eventMember benefits / toolboxScans, pack closesEmail sequence
LinkedIn outbound to QM/ownersTitles visible10-file Friction Scan offer3–6% reply; 20%→scanBSIS licensee volumeReply→scan→paidPersonalized gap memo
BSIS complaint/inspection fear contentSearch + AEO“SB 513 checklist for PPOs”2% landing→scanKearnan/Littler demandOrganic scansRetarget
Referral from trainers / TFsThey see bad certsRev-share on packs1 pack / partner / moTF ecosystemPartner-sourced revenueQuarterly
Insurance / broker introsLoss controlNegligent-hiring file readinessLong cycleIndustry practiceIntro→scanJoint webinar

Sales and outreach plan

Three layers: (1) founder-led education on SB 513 × BSIS certificate failure modes; (2) warm conversion of Friction Scan users with a written gap memo; (3) targeted outbound to PPOs with 20–150 guards offering a free 10-file scan and a scoped founding pack—not a generic demo.

Founder-led content plan

Teach: required SB 513 fields; why 2-year BSIS habits fail the 3-year retention rule; serial-number failures; PTA/AUF single-certificate rule; how to answer a former-employee request in 30 days; sample redacted scorecards; cost of re-training vs. retrieving certificates.

First 30 days of content

10 educational posts: (1) SB 513 in plain English for PPOs; (2) field checklist; (3) retention 2 vs 3 years; (4) serial numbers; (5) instructor name omissions; (6) WMD vs PTA/AUF; (7) 30-day request playbook; (8) what BSIS actually opens first; (9) multi-branch file chaos; (10) Desk vs. one-time pack.

3 diagnostic teardowns: redacted failing certificate; roster with missing CE AUF hours; ex-employee request timeline fail.

2 lead magnets: SB 513 PPO field checklist PDF; 10-file Friction Scan.

1 webinar: “Make your training files request-ready in 10 business days.”

1 outbound template: “I reviewed how SB 513 treats Powers-to-Arrest certificates as personnel records—happy to score 10 of your files this week at no cost.”

Lead magnet and waitlist plan

Lead magnet: Free Friction Scan—upload ≤10 certificates + roster snippet → 1-page gap scorecard within 3 business days. Waitlist CTA: “Get SB 513 File-Ready — join founding cohort (cap 20).” Captures pain signal (missing fields count). Sales-ready when ≥3 critical gaps or inspection date <30 days. Waitlist ≠ PMF; paid pack conversion is the gate.

Warm GTM plan

Convert scan users with a 15-minute review; offer founding pack; ask CALSAGA contacts and friendly TFs for intros; run a private Slack/email office hours for the first 20.

Targeted outbound plan

Build list from public PPO directories / web presence; personalize around branch count + likely admin thinness; lead with diagnosis offer, not SaaS pitch. Cap outbound to 40 new contacts/week during pilot to protect fulfillment.

Answer-engine / search visibility plan

Publish quotable pages: “Does SB 513 apply to security guard training certificates?” “What fields must a PPO training record include?” “How long must California employers keep training records after termination?” Structure FAQs for AI overviews; cite primary statutes.

Pilot design and early-demand-trap mitigation

  • Pilot cap: 10 Completeness Packs (founding cohort 20 soft-cap for scans, 10 paid).
  • Incentive: founding price $1,499 + free first month Desk if started within 14 days.
  • Feedback: structured form per pack + weekly ops retro.
  • Product feedback vs custom work: schema gaps = product; one-off legal memos = refuse / refer counsel.
  • Do not hire temporary clerks to hide broken intake—fix intake requirements instead.

Early-access feedback flywheel

Every correction becomes: rule update, prompt example, gold certificate, QA check, or SOP line. Tag root causes. Publish internal changelog. Customer-visible: monthly “rules hardened” note for Desk subscribers.

Build-before-scale checkpoints

  • After 5 packs: harden intake checklist, evidence requirements, confidence thresholds.
  • After 10 packs: harden SOPs, exception queues, reviewer checklists, delivery templates.
  • After 20 packs: pause new logos until COGS, rework, escalation, and cycle time are measured and GM ≥55% on trailing 10.

7-day / 30-day / 90-day launch plans

7-day: landing page, checklist magnet, scan workflow, 3 design-partner outreaches, disclaimer + DPA templates.

30-day: 40 scans, 8 paid packs, 3 Desk conversions, first CALSAGA/community touch, content cadence live.

90-day: 25 packs cumulative, 12 Desk subs, SOP v1.0, automation ≥60%, measured unit economics, decide geographic second beachhead (NorCal densify vs. PSE expansion).

Metrics and KPIs

  • Scan→paid ≥8%; pack cycle time ≤10 business days; field-complete rate; rework %; Desk NRR; GM %; PII incidents = 0; escalation-to-counsel rate; CSAT on QM calls.

Risks and mitigations

Top risks: UPL creep; PII breach; customers expecting BSIS guarantee; CALSAGA/tooling commoditization; underestimating firearms-permit complexity; sales cycle stalls without inspection trigger. Mitigations baked into licensing boundary, security controls, scoped MVP, and inspection-sprint urgency offers.

Exhaustive risk register

1. Unauthorized practice of law / overclaiming “compliance”
L/I: M/H · Mitigation: Disclaimers; no legal opinions; counsel escalation path; QM remains decision-maker.
2. PII / personnel-file data breach
L/I: L/H · Mitigation: Encrypted vault, least privilege, retention limits, incident plan, vendor DPA.
3. Customer treats pack as BSIS inspection guarantee
L/I: M/H · Mitigation: Explicit non-guarantee language; scope = documentation completeness ops.
4. CALSAGA database + self-serve AI commoditizes wedge
L/I: M/M · Mitigation: Sell continuous Desk + remediation ops + multi-branch vault, not cert printing.
5. Illegible / incomplete source docs inflate COGS
L/I: H/M · Mitigation: Intake quality gates; surcharges for re-scan; pause automation on bad batches.
6. Name mismatches across roster vs certificates
L/I: H/M · Mitigation: Human chokepoint; fuzzy match with mandatory confirm.
7. Firearms/baton permit complexity expands scope
L/I: M/M · Mitigation: MVP excludes deep permit lifecycle; offer later SKU.
8. Slow sales without inspection trigger
L/I: M/M · Mitigation: SB 513 effective-date urgency + former-employee request content + founding pricing.
9. Early demand trap (custom legal memos)
L/I: M/H · Mitigation: Hard scope; refuse custom legal work; pilot cap.
10. Trainer/TF channel conflict
L/I: L/M · Mitigation: Partner, don’t displace training revenue; refer re-trains to TFs.
11. Model hallucination of certificate fields
L/I: M/H · Mitigation: Confidence thresholds; human QA; never invent serial numbers.
12. Retention of records beyond authorization
L/I: L/H · Mitigation: Contractual retention schedule; auto-delete; customer-owned vault option.

What could kill this

  • Scan→paid <4% after 100 scans.
  • COGS >60% ASP after hardening through 20 packs.
  • Material unauthorized-practice or data incident.
  • BSIS or major association ships a trusted free DFY concierge that closes the ops gap.
  • Customers only want one-hour advisory calls (model collapses to consulting).

Go/no-go reasoning

Six gates (1–5): Low trust 4 · Low task judgment 4 · High intelligence 5 · Regulation moat 5 · No physical labor 5 · Sam Altman 5 → 28/30.

Clears evidence threshold: clear buyer, painful specific problem, spend/labor proof, active demand, competitor/budget validation, credible win vs. sample audits, narrow MVP, path to first sale without platform, no fatal blocker, 50%+ GM path, distribution path. Prefer this over Notice195 (PEO crowding) and WashRenew (CancelPath near-dup).

Final recommendation

GO — Blueprint. Launch GuardFile Clear as a CA PPO SB 513 / BSIS Training-File Completeness Desk with a free Friction Scan wedge, founding Completeness Packs, and a monthly Roster File Desk. Keep licensing boundaries tight; measure scan→paid and COGS before scaling past 20 packs.

Source list