✏️ Edit Mode ON — click text to edit · use + to add items · ✕ to remove

Project Board — Ground Zero

411 Capital is starting from zero. Everything is currently manual. This board maps every phase of the build: what is done, what is missing, what gets automated, and what stays human.

✅ Phase 1 Complete 🔮 Phase 2 Next 5 Phases Total 26 Automatable Tasks 11 Missing Docs 51 Workshop Questions
Phase 1 — Pre-Workshop Complete
Process map drafted — end-to-end loan lifecycle mapped
Done
Manual vs Auto split defined — every task assigned a layer
Done
Brain vs Workers model outlined — decision logic separated from execution
Done
Data sources catalogued — providers, pros, cons, recommendations researched
Done
Missing docs identified — 11 critical gaps surfaced for collection
Done
Workshop agenda built — 51 questions across 7 topic blocks
Done
Stakeholders aligned — 411 Capital principals briefed on goals
Done
Workshop scheduled — 90-minute session on the calendar
Done
Review current onboarding document
Done
Review AI document from Erik
Done
Review process document from Eric
Done
Extract info and questions
Done
Create color mapping for each section
Done
Review and audit each section
Done
Code the 411 Capital home base
Done
Push URL live
Done
Brainstorm upstreams
Done
Map analog blueprint
Done
Add light and dark mode
Done
2
Phase 2 — Discovery Workshop 🔮 Next Up
Run 90-min discovery workshop using the 51-question framework
Critical
Collect pre-workshop docs: rate sheet, deal files, loan programs, Do Not Lend list
Missing
Map each loan program (FlexTerm, ARV Pro, Flex I/O, Fast50) to eligibility rules
Missing
Document the rate and fee matrix — what factors move rate up or down
Missing
Define hard decline criteria — what is an automatic no
Missing
Confirm borrower background check vendor (Middesk, Persona, DataVerify)
TBD
Confirm property valuation data partner (ATTOM, HouseCanary, CoreLogic)
TBD
Get Do Not Lend List in digital/structured format for API lookup
Missing
3
Phase 3 — Build System 🏗️
Design smart intake form with conditional logic — replaces static PDF
Auto
Build deal scoring engine — 5 weighted categories, 0–100 output
Auto
Code LTV auto-calculator — flag if over 75%
Auto
Build Do Not Lend List live lookup — name, address, entity cross-ref
Auto
Integrate property valuation API — pull AVM, comp data, ARV estimate
Auto
Integrate borrower background check API — KYC/KYB, entity verification
Auto
Build rate matrix auto-calculator — base rate + adjustments = final rate
Auto
Build decision routing engine — Green/Yellow/Orange/Red with reason codes
Auto
Build term sheet auto-generator — PDF template from scoring data
Auto
Set up CRM pipeline — intake, review, approved, closed stages
Setup
Wire Zapier/Make.com flows: form to scorer to CRM to notifications
Auto
Build Qualia data push — intake data pre-populates title order on approval
Auto
4
Phase 4 — Test and Validate 🔬
Run 5 historical deals through scoring engine — compare vs actual decisions
Manual
Tune scoring weights based on historical deal test results
Manual
Test Do Not Lend List lookup with known flagged names
Manual
Stress test edge cases: first-time borrower, foreign national, ARV deal, max LTV
Manual
Get 411 Capital sign-off on scoring output for first 10 live submissions
Manual
5
Phase 5 — Launch and Iterate 🚀
Soft launch: first 20 real applications through the system, supervised
Supervised
Track score vs final decision accuracy — target 90%+ alignment
Auto
Gradually reduce manual review for Green-scored deals as trust builds
Manual
Monthly model review: refresh weights, update data sources, add decline patterns
Monthly

Process Map — End to End

Full loan lifecycle from borrower contact to post-close. Color shows what is automated (teal border), manual (orange border), missing/not built (red dashed), or partial (gold border).

■ Automated ■ Manual ■ Not Built ■ Partial
Stage 1 — Borrower Intake
Borrower Contacts
Phone, email, referral. No structured capture.
Manual
Smart Intake Form
PDF replaced by digital form with conditional logic.
Not Built
LTV Auto-Check
Loan ÷ Value. Flag if over 75% instantly.
Not Built
Do Not Lend Check
Name, entity, property, agent cross-ref.
Not Built
CRM Entry
Auto-create deal record in pipeline.
Not Built
Stage 2 — Deal Analysis and Scoring
Property Data Pull
AVM, comps, ARV, title history via API.
Not Built
Borrower Background
KYC / KYB / entity check / prior deals.
Not Built
Scoring Engine
0-100 weighted score across 5 categories.
Not Built
Decision Router
Green / Yellow / Orange / Red + reason codes.
Not Built
Underwriter Review
Human review for Yellow and Orange deals only.
Always Manual
Stage 3 — Approval and Term Sheet
Rate Matrix Calc
Base rate + risk adjustments = final rate.
Not Built
Term Sheet Generator
Auto-populate template from score data.
Not Built
Lender Review
411 Capital reviews and approves term sheet.
Always Manual
DocuSign Send
Executed term sheet via e-signature.
Not Built
Stage 4 — Closing
Qualia Order
Exists but data re-entered manually from loan app.
Partial
Title Commitment
Titlewave order, manual Schedule B-I review.
Manual
Lien Search
Manual order via Qualia Marketplace.
Manual
CD Balance
Manual fee entry and balance check in Qualia.
Manual
Closing Day
Physical signing, notary, wires. Always manual.
Always Manual
Stage 5 — Post-Close and Monitoring
Simplifile Recording
Done but no automated trigger.
Manual
Draw Schedule Mgmt
No rehab draw process documented.
Not Built
Payment Monitoring
No automated late payment alert system.
Not Built
Servicing Dashboard
Portfolio view, maturity dates, status per loan.
Not Built

Manual vs. Automation Layers

Every task mapped to its layer. Some will always need a human. Others should never need one. Goal: push every repetitive decision to automation and protect human time for real judgment calls.

👤 Manual Layer — Human Required
⚠️
Yellow/Orange deal review
Score 40–79 always gets a human underwriter. Never auto-approve borderline deals.
🔴
Red flag overrides
Partial Do Not Lend matches require human judgment, not the algorithm.
📋
Term sheet final approval
411 Capital principal always reviews before any term sheet is sent to a borrower.
🏠
ARV validation when disputed
If borrower ARV and API AVM differ by over 15%, human reconciles with BPO or appraisal.
📄
Title commitment Schedule B-I review
Requires legal judgment. Lien clearance, MERS payoffs, code enforcement — always attorney.
✍️
Closing day signing and notarization
Physical presence, ID verification, notary — cannot be automated in most states.
💰
Wire disbursement authorization
All outgoing wires need manual authorization — no exceptions.
🔨
Rehab draw inspection approval
Construction milestone payments require physical or photo inspection sign-off.
📅
Loan extension decisions
Extension terms must be negotiated and approved by the lender, not auto-granted.
⚖️
Default and workout decisions
Late payments, foreclosure triggers — require legal and lender judgment.
📝
Do Not Lend List updates
Only a designated 411 Capital principal adds or removes entries from the list.
⚡ Automation Layer — Never Needs a Human
📥
Intake form capture
Form submitted, data validated, CRM record created. Trigger: form submit webhook.
📐
LTV calculation
Loan Amount ÷ Property Value. Instant. Auto-flag if above 75%.
🚫
Do Not Lend exact match check
Exact match triggers auto-decline with reason code. No human needed.
🏠
Property data enrichment
API pull: AVM, tax history, deed records, comps, flood zone. Auto-attaches to deal.
🏢
Entity / business verification
Middesk: Secretary of State check, beneficial ownership, IRS match. Runs on submit.
🧮
Deal score calculation
5 category scores weighted and totaled. Full breakdown stored in CRM automatically.
🚦
Green-score deal fast-track
Score 80+ with clean DNL and LTV in limits auto-advances to term sheet queue.
📊
Rate calculation
Base rate + LTV adjustment + experience adjustment = proposed final rate.
📃
Term sheet draft generation
Template populated from score data. Staged for lender review, not sent automatically.
💌
Borrower status notifications
Auto-email at each stage: received, under review, decision, term sheet, docs needed.
📁
Document naming and filing
Auto-name with 411 convention (Address, DocType, Version, Date) and file to Dropbox.
Deadline and SLA reminders
Auto-calendar: loan maturity, draw milestones, payment due dates, extension deadlines.
📈
Decline tracking and reason logging
Every declined deal auto-logged with reason code. Used to improve scoring monthly.
🔄
Qualia data push
On approval, structured intake data pushed to Qualia. Zero re-entry for closing team.
Manual Review Escalation — Starts Heavy, Gets Lighter as Trust Builds
🟢 Green
Score 80–100
  • Phase 1 (first 20 deals): Full manual review even for green scores — build model trust
  • Phase 2: Spot-check 1 in 5 green deals only
  • Phase 3: Auto-advance. Human only sees the term sheet for final sign-off
🟡 Yellow
Score 60–79
  • Always manual review — underwriter assigned within 24 hours
  • System surfaces weak categories with explanations for the reviewer
  • Underwriter can override score upward with documented reason
  • Conditional approval option: term sheet with additional requirements
🟠 Orange
Score 40–59
  • Escalate to senior underwriter or 411 Capital principal — never junior review
  • Borrower must provide additional documentation before review proceeds
  • 48-hour SLA. If not reviewed, auto-expires and borrower is notified
🔴 Red
Score 0–39
  • Auto-decline. No human review needed unless lender manually overrides
  • Reason codes auto-populated. Decline email sent automatically
  • Deal logged and archived. Data used to refine scoring weights monthly

Brain · Automations · Human Actions

Three distinct layers power the system. The Brain is the encoded decision logic extracted from the principals. The Automations are the workers that execute without human involvement. The Human Actions are the steps that always require a real person — judgment calls, legal sign-offs, and relationship moments the system cannot replace.

🧠 Brain — Decision Logic ⚡ Automations — Workers 👤 Human Actions — Required
🧠

The Brain

Decision logic that must be extracted from the principals and encoded into the system before any automation can work. This is the rulebook everything else runs on.

📏
LTV limits per loan program (75% hard cap)
🚦
Deal scoring weights and category thresholds
📋
Loan program routing rules per deal type
💲
Rate matrix — base rate and adjustment logic
🚫
Do Not Lend List and the reasons behind each entry
Hard decline criteria — automatic no regardless of score
👤
Borrower experience benchmarks (0, 1-3, 4-10, 10+ deals)
🏘️
Market grading and area risk ratings by zone
🔨
Rehab budget credibility standards and SOW requirements
🚪
Exit strategy validity criteria per loan type

Automations

These workers run 24/7 without human involvement. They read the Brain's rules and execute. Once built, no one touches them unless the rules change.

⚡ Auto Intake Worker

Captures borrower form data on submit
Validates all required fields
Auto-creates CRM deal record
Sends confirmation email to borrower
Triggers all downstream workers

⚡ Auto Compliance Check Worker

Queries Do Not Lend List — exact match
OFAC watchlist screening
Calls entity verification API (Middesk)
Identity verification (Persona KYC)
Returns clean / flag / block result

⚡ Auto Property Data Worker

Pulls AVM from ATTOM or HouseCanary
Fetches comparable sales (last 90 days)
Retrieves tax and deed history
Checks flood zone and zoning status
Calculates LTV and ARV spread automatically

⚡ Auto Scoring Worker

Receives data from all prior workers
Reads Brain scoring weights from config table
Calculates 0–100 total deal score
Generates score breakdown by category
Assigns Green / Yellow / Orange / Red tier

⚡ Auto Pricing Worker

Reads Brain rate matrix config
Applies LTV risk adjustment
Applies borrower experience adjustment
Calculates origination points
Outputs: rate, points, term, and fees

⚡ Auto Documents Worker

Populates term sheet template from score data
Names and files all documents (411 naming convention)
Routes to Dropbox with correct folder label
Pushes structured data to Qualia on approval
Sends DocuSign signature request

⚡ Auto Notifications Worker

Borrower status emails at every stage
Internal alerts for manual review needed
Due date and SLA reminders
Payment follow-up sequences
CRM deal stage update posts

⚡ Auto Learning Worker

Logs every deal decision and outcome
Tracks score vs actual result over time
Flags model drift each month
Surfaces patterns in decline data
Generates monthly model performance report
👤

Human Actions

These steps require a real person every single time. Judgment calls, legal sign-offs, relationship moments, and financial authorizations the system cannot and should not replace.

⚖️
Yellow and Orange Deal Review
Score 40–79 requires an underwriter. Never auto-approve a borderline deal. Human reads the score breakdown and makes the call.
🔴
Partial Do Not Lend Match Override
If the name check returns a partial match — not exact — a principal decides, not the algorithm. Too much legal risk to automate gray areas.
Term Sheet Final Approval
A 411 Capital principal reviews and approves every term sheet before it is sent to a borrower. The system drafts it — a human sends it.
🏠
ARV Dispute Resolution
When borrower ARV and the API AVM differ by more than 15%, a human reconciles with a BPO or appraisal. No algorithm resolves a valuation dispute.
📄
Title Commitment Review (Schedule B-I)
Legal judgment required. Lien clearance, MERS payoffs, code enforcement items — always an attorney. This cannot be automated.
✍️
Closing Day — Signing and Notarization
Physical presence, government ID verification, notary seal. Cannot be automated in most states for real estate secured transactions.
💸
Wire Disbursement Authorization
Every outgoing wire requires named human authorization. Two-person rule on wires above a set threshold. No exceptions — wire fraud is the top risk in real estate lending.
🔨
Rehab Draw Inspection Approval
Construction milestone payments need physical or photo inspection sign-off. A worker can trigger the request — a human approves the release.
📅
Loan Extension Negotiation
Extension terms must be reviewed and approved by a principal. The system can flag a maturity date approaching — only a human can grant an extension.
⚠️
Default and Workout Decisions
Late payment escalation, foreclosure triggers, deed-in-lieu negotiations — all require legal and lender judgment. System alerts, human acts.
📝
Do Not Lend List Updates
Only a designated 411 Capital principal adds or removes entries. Every addition needs a documented reason code. System shows the list — human controls it.
🧠
Monthly Scoring Model Review
The Learning Worker surfaces the data — a principal reviews it and decides if scoring weights need adjustment. Model governance is always a human decision.

Data Sources — Options, Pros, Cons

Every data category needed to run the system. For each one: recommended partner, alternatives, and the questions to confirm in the workshop.

AVM Property Valuation and ARV Data
ProviderBest ForProsConsCost
HouseCanary ⭐
Recommended
Hard money lenders, fix-flip ARVAI-powered AVM, ARV scoring built-in, rental forecasts, lender-grade accuracyPremium pricing. Overkill for very small portfolios.~$0.50–$2 per report
ATTOM Data ⭐
Recommended
Comprehensive: tax, deed, ownership158M+ properties, tax history, deed, foreclosure data, neighborhood analyticsAVM less refined for fix-flip vs HouseCanaryFrom ~$199/mo
CoreLogicEnterprise mortgage lendersIndustry gold standard. 99.9% coverage. 50 years of data.Enterprise pricing only. Not startup-friendly.$1,000s/mo min
Zillow API ⚠️Consumer appsFree/low cost. Familiar to borrowers.Restricted commercial use per TOS. Not for lending decisions.Free with restrictions
Estated APIStartups, MVP stageDev-friendly REST API, affordable, free trialLess depth than ATTOM or CoreLogicPay-per-call
Workshop QuestionsDo you currently use any tool to pull property comps or validate borrower ARV? Are you willing to pay per-property for automated AVM data? What is your acceptable margin of error on an auto-generated ARV before requiring a BPO?
KYC/KYB Borrower Identity and Background Checks
ProviderBest ForProsConsCost
Middesk ⭐
Recommended — Entities
Business entity verification (LLC, corp)Direct pipelines to all 50 Secretaries of State plus IRS. Beneficial ownership. 300+ lender clients.Business only — not personal KYC. Pair with Persona.Per-verification
Persona ⭐
Recommended — Individuals
Individual borrower KYCFull KYC: government ID scan, selfie liveness, OFAC/AML watchlist. Borrower-friendly UX.Primarily personal KYC. Pair with Middesk for entities.Usage-based, free dev
DataVerifyMortgage-specific fraud detectionNMLS verification, occupancy fraud, undisclosed debt detectionOver-engineered for private lending MVP stageSubscription + per-report
SocureHigh-volume digital identityIndustry-leading fraud detection accuracy. Real-time AI scoring.Enterprise pricing. Better for high-volume fintechs.Enterprise contract
Workshop QuestionsWhat percentage of loans go to LLCs vs individuals? Do you currently run any identity check other than reviewing the application? What would a clean borrower check result look like inside the system?
Credit Credit Score and Financial History
ProviderBest ForProsConsNotes
CoreLogic Credco ⭐
Recommended
Mortgage-grade tri-merge credit reportPulls from all 3 bureaus in one report. Industry standard for mortgage lenders.Requires NMLS licensing or lender credentialing.Confirm if 411 Capital already has access via attorney relationships.
PlaidBank account / income verificationBorrower connects bank, 2 years of transactions plus income verification. Used by Freddie Mac AIM.Not a credit score product. Supplementary only.Good for validating stated employment income.
Workshop QuestionsAt what point do you pull credit — intake, pre-approval, or closing? Do you do a soft pull first? What FICO is your minimum and does it vary by loan program? Is credit a hard cutoff or a pricing factor?
Title Title, Lien Search and Public Records
ProviderStatusAutomation OpportunityPriority
Qualia + Titlewave ⭐Fully operational but data re-entered manuallyBuild intake-to-Qualia API push to eliminate re-entry. Biggest closing-side time save.High Priority
Camson Crown / SkylineAlready used via Qualia MarketplaceAuto-trigger lien search order on deal approval — currently initiated manuallyMedium
SimplifileAlready used for post-close recordingAuto-trigger recording package creation on closing completionMedium
Workshop QuestionsHow long from loan approval to Qualia order today? Who enters data into Qualia — one person or multiple? Is Qualia API access available or would a webhook approach work for the data push?
CRM CRM and Deal Pipeline Management
ToolRoleProsConsWhen to Use
Airtable ⭐
Start Here
Scoring engine + deal databaseFormula fields for scoring, Zapier integration, visual views, no-code friendly, affordableNot a full CRM. Migrate to HubSpot as volume grows.Build and test scoring logic first. MVP stage.
HubSpotCRM with pipeline + email + automationsFree tier generous. Email templates, deal tracking, notifications, reporting. Scales well.Can get complex. Better once volume is established.Borrower communications and deal stage tracking.
Zapier / Make.com ⭐
Required
Automation glue between all toolsConnects intake, Airtable, HubSpot, Dropbox, DocuSign, Qualia without codeComplex zaps can be fragile. Make.com steeper learning curve.Zapier for simple flows. Make.com for complex branching.
Workshop QuestionsDo you currently use any CRM or tracking spreadsheet for active deals? How do you know which deal is at which stage today? Who needs system access — just the lender or also the closing team?

Missing Documents and Data

11 critical gaps identified. Red cards must be collected before the workshop or in the workshop itself — the system cannot be built without them. Yellow cards can come after.

🔴 6 Workshop-Critical 🟡 5 Post-Workshop

Rate and Fee Matrix

No document shows how interest rate or origination points are calculated. System cannot auto-generate a term sheet without this.

Base interest rate (current) LTV adjustment per tier Borrower experience adjustment Property type risk add-ons Extension fee structure Prepayment penalty terms

Loan Program Eligibility Rules

4 products exist but no documented decision tree for which deal goes into which program.

Property type eligibility per program LTV cap per program Borrower entity vs individual rules Min/max loan size per program Refi vs purchase rules per program

Hard Decline Criteria

No documented list of automatic no's. Without this the scoring engine cannot generate a reliable Red-tier decision.

LTV over [X]% = instant decline Active bankruptcy = decline Property type exclusions Prior fraud or foreclosure rules Minimum deal size cutoff

Do Not Lend List (Digital Format)

Referenced in AI notes but not shared. Must be in structured format (CSV or database) for API cross-reference to function.

Full name column Entity name column Property address column Reason code / category Date added and added by

Validated Scoring Weights

Draft weights proposed but never validated by the client. Need their sign-off before scoring can be trusted.

Collateral / LTV weight % Exit strategy weight % Borrower experience weight % Rehab budget weight % Market condition weight %

ARV Validation Process

Application collects ARV but no documented method exists for how 411 Capital validates or challenges a borrower's stated number.

Accept borrower ARV at face value? Require independent BPO? What variance % triggers a challenge? Who orders the BPO and when?

Borrower Experience Benchmarks

Real Estate Owned section used as experience proxy but no scoring rubric exists for 0, 1-3, 4-10, or 10+ completed deals.

0 deals = score points? 1-3 deals = score points? 4-10 deals = score points? 10+ deals = score points? Does deal type matter (flip vs rental)?

Background Check Vendor Decision

Notes reference background check companies but no specific vendor is named. Must choose KYC and KYB partners before build begins.

KYC vendor (Persona or equivalent) KYB vendor (Middesk or equivalent) AML / OFAC watchlist check vendor Budget for per-check costs

Property Data Vendor Decision

Zillow is obvious but restricted for commercial use. Must select an AVM partner before the property worker can be built.

Primary AVM source (HouseCanary / ATTOM) Budget per property lookup Acceptable AVM accuracy tolerance Need rental data also?

Rehab Budget Credibility Rules

Renovation deals require a Scope of Work but no standard for what makes an SOW credible is documented anywhere.

Required line items in SOW Contractor qualification requirements Contingency reserve minimum % Cost-per-sqft sanity check thresholds

Post-Close Monitoring Protocol

Once a loan is funded there is no documented monitoring process. Draw schedules, inspections, and payment escalation are all undefined.

Draw request process and documents required Inspection frequency for renovation loans Payment grace period before escalation Default trigger timeline Extension conditions and fees

Workshop Agenda — 51 Questions

7 blocks across 110 minutes. One workshop to extract everything needed to build the system. Expand each block to see all questions.

110 min total 51 questions 7 blocks
1
Business Philosophy and Identity — 15 min
Understand lending identity, risk appetite, and what makes a deal a yes in their gut
Q1How long have you been operating and what types of deals make up your core book of business today?
Q2What is your target borrower — experienced flippers, first-timers, commercial operators, or all?
Q3Which asset types do you lend on? What do you refuse regardless of deal economics?
Q4What geographic markets do you lend in? Any hard no-go zones?
Q5What is your average, minimum, and maximum loan size?
Q6When you look at a deal in the first 60 seconds, what tells you it is a yes before doing any real digging?
Q7What is the fastest you have turned a deal, and what made that possible?
2
Onboarding and Intake Process — 20 min
Map the current borrower intake step-by-step so it can be replicated and automated
Q8Walk me through what happens from the moment a borrower first contacts you — what is step one?
Q9What is your minimum viable package — what do you need before taking a deal seriously?
Q10Walk me through every field on your current application form and tell me why each one matters.
Q11What documents do you require at intake vs what comes later in the process?
Q12Where do deals fall apart most in intake — what is the number one thing people submit that wastes your time?
Q13Do you do any pre-qualification before a full application? What does that look like?
Q14How do you currently organize and track incoming deals — CRM, spreadsheet, email folder?
3
Deal Analysis and Underwriting — 25 min
Extract every criterion used to evaluate a deal — this becomes the scoring engine
Q15What is your maximum LTV on an as-is basis? Does this change by property type or loan program?
Q16How do you determine ARV — your BPO, a third-party appraisal, or borrower-provided comps?
Q17What LTV cap do you apply against ARV for fix-and-flip deals specifically?
Q18What is your LTC cap for total project costs (purchase plus rehab)?
Q19What property conditions are automatic disqualifiers — fire damage, mold, structural issues?
Q20How do you think about property location — hard zone map or case-by-case judgment?
Q21Do you pull credit? What is your floor score and at what point in the process?
Q22What does an experienced borrower look like to you — how many deals, what type, how recent?
Q23Do you require a personal guarantee on all deals or only certain loan types?
Q24What is your stance on first-time borrowers — hard no, or possible with extra cushion?
Q25What borrower history triggers an immediate decline — foreclosures, active bankruptcy, fraud?
Q26What minimum profit margin do you want to see on a flip deal for it to be viable?
Q27What is your minimum net equity buffer below LTV that makes you comfortable?
Q28Do you have a minimum ARV or minimum deal size?
Q29How do you handle a borrower whose rehab budget seems unrealistic — adjust it or decline?
Q30How do you validate an exit strategy — comps, borrower's plan, or both?
Q31What is your maximum loan term? Do you offer extensions, and what are the conditions?
Q32If a borrower misses their projected exit date, what triggers your escalation process?
4
Pricing and Rate Logic — 15 min
Extract the rate matrix so the system can auto-generate a proposed term sheet
Q33What factors drive your interest rate up or down from your base rate — LTV, experience, property type, market, loan size?
Q34How do you determine points at origination — standard rate or negotiated per deal?
Q35Do you charge extension fees? What are the conditions and amounts?
Q36Are there prepayment penalties and when do they apply?
Q37If you described your rate matrix as a simple table — rows as risk factor, columns as rate adjustment — what would it look like?
5
Decision and Approval Flow — 15 min
Map who decides what and when, and what triggers escalation vs auto-approval
Q38Who is involved in a deal decision — one person, committee, or tiered by deal size?
Q39Are there deal parameters where you would trust an automatic yes with no human review?
Q40What triggers a manual review vs a fast pass?
Q41What is your current average time from application to term sheet? What slows it down most?
Q42After issuing a term sheet, what are the most common reasons a deal dies before closing?
6
Post-Close and Loan Monitoring — 10 min
Capture servicing and monitoring requirements for the full system scope
Q43How do you monitor loans in-flight — draw schedules, inspections, borrower check-ins?
Q44What is your process for handling a borrower who misses a payment?
Q45How do you track construction progress — inspection reports, photos, and how often?
Q46What reporting do you require from borrowers during the loan term?
7
Automation Vision and Vendor Decisions — 10 min
Align on what done looks like and confirm data vendor choices before build begins
Q47If you imagine the perfect deal scoring system, what does it output — a score, a decision, a draft term sheet, or all three?
Q48What data fields are non-negotiable inputs for any scoring model to be useful to you?
Q49Where do you most want to save time — intake, analysis, or documentation?
Q50Are there data sources you pull manually today that you want the system to pull automatically?
Q51What does a successful deal look like 12 months post-close — what metrics matter most to you as the lender?

Risk, Compliance and Project Challenges

A full assessment of how complex this build is, what can go wrong, what the law requires, and what must be protected. Ground zero start. Every risk is rated by severity.

🔴 Critical 🟠 High 🟡 Medium 🟢 Manageable
Project Difficulty Rating
7/10
Overall Difficulty
Significant but very achievable with right sequencing
9/10
Knowledge Extraction
Hardest part — the brain is in people's heads, not on paper
6/10
Technical Build
Integrations are mature. No-code stack reduces technical risk.
7/10
Compliance Load
Business lending = lighter than consumer. Still needs structure.
4/10
Data Security Complexity
Existing vendors handle most of it. SOC 2 partners recommended.
3–6 mo
Realistic Timeline
MVP in 3 months. Full system in 6 with testing and tuning.
Critical Project Risks — What Can Kill This Build
Critical Knowledge Never Fully Extracted

The entire system depends on getting 411 Capital's decision logic out of the principals' heads and into structured rules. If the workshop is rushed, skipped, or answers are vague, the scoring engine will be built on guesswork. A model built on wrong weights will produce wrong scores — and the lender will lose trust in the system before it is even tested.

Protection: Do not build Phase 3 until all 11 critical decision inputs are confirmed and signed off on paper by the client. One incomplete workshop = one unusable system.
Critical Scope Creep During Build

Hard money lending looks simple on the surface but expands fast once you get into it. Rehab draw schedules, construction inspection protocols, default waterfall processes, extension negotiations — each one is a full sub-system. Without a hard boundary, this project can grow 3x beyond the MVP without delivering a working product first.

Protection: Define MVP clearly before build starts. MVP = intake form + LTV check + Do Not Lend lookup + scoring engine + term sheet draft. Everything else is Phase 2.
High Client Doesn't Adopt the System

The most common failure in automation projects is not technical — it is that the humans who were supposed to use the tool go back to their old habits. If the system adds steps without immediately reducing time, the team will bypass it. If the scoring output conflicts with gut feel on early deals, trust collapses quickly.

Protection: Run the first 10 real deals in parallel — score them with the system AND review manually. Compare outputs. Show the client where the system agreed with their instincts and refine where it didn't. Build trust before removing manual review.
High No Historical Deal Data to Validate Scoring

The scoring weights are theoretical until tested against real past decisions. If 411 Capital cannot share historical deal data (even anonymized) — approved, declined, and defaulted loans — there is no baseline to validate the model against. The weights will be educated guesses until enough live deals accumulate.

Protection: Request 20–50 historical deal files before the workshop. Minimum viable: 5 approvals, 3 declines, 2 defaults. Run them blind through the model and compare output vs actual decision. Adjust weights based on mismatches.
Medium Integration Breaks as Vendors Update APIs

Third-party APIs — Middesk, ATTOM, HouseCanary, Qualia — update their endpoints, change response schemas, or deprecate fields. A Zapier automation built today can silently fail if a field name changes upstream. The system can appear to be working while scoring on stale or empty data.

Protection: Add webhook health checks to every integration. Log every API call and flag nulls. Set monthly API review in the build calendar. Use Make.com over Zapier for complex flows — better error handling.
Medium Do Not Lend List Is a Legal and Operational Liability

If the Do Not Lend List is used to systematically block certain borrowers and there is no structured process for adding, removing, or auditing entries, it becomes a discrimination risk. A borrower could argue they were blocked based on protected characteristics if entries are not consistently documented with legitimate business reasons.

Protection: Every entry must have: name/entity, reason code from a pre-approved list, date added, and who added it. Periodic audit every 90 days. Attorney review of the list before the system goes live.
Critical Compliance and Legal Requirements
Critical ECOA — Adverse Action Notices Are Mandatory

The Equal Credit Opportunity Act requires any creditor — including private and hard money lenders lending to businesses — to provide a written statement of specific reasons when taking adverse action on a credit application. The CFPB confirmed in 2022 that this applies to automated scoring models too. If the system declines a deal and cannot explain exactly why in plain language, the lender is in violation. "Black box" scores are explicitly non-compliant under ECOA and Regulation B.

Required Build: Every decline must generate a written adverse action notice with specific reason codes drawn from a pre-approved list. The scoring engine must be interpretable — each category score must carry a plain-language reason. Store all adverse action notices with timestamps for audit.
Critical FCRA — Credit Report Handling

If 411 Capital pulls a credit report as part of underwriting, the Fair Credit Reporting Act governs how that information is used, stored, and communicated. Borrowers are entitled to know if an adverse action was taken based on credit report data and must receive a notice pointing them to the reporting agency. Credit data cannot be stored indefinitely or used for purposes beyond the original loan decision.

Required Build: FCRA-compliant adverse action language in every decline that involved a credit pull. Partner with a credit vendor (CoreLogic Credco) that provides compliant disclosure templates. Set data retention and deletion policies for credit reports.
Critical GLBA — Borrower Data Privacy and Safeguards Rule

The Gramm-Leach-Bliley Act applies to all financial institutions including private lenders. It requires a written information security plan, employee training, vendor oversight, and annual risk assessments. Under the 2023 updated Safeguards Rule, lenders must encrypt customer data both in transit and at rest, implement multi-factor authentication, and appoint a qualified individual to oversee the security program. A single breach without a documented safeguards plan means the lender is personally liable.

Required Build: Written Information Security Plan (WISP) before system goes live. Encrypt all borrower PII at rest and in transit. MFA on all system access points. Only use SOC 2 certified vendors. Annual GLBA review.
High State Licensing — Varies by Loan Type and State

Hard money lending license requirements vary significantly by state. Business-purpose loans secured by commercial property or 5+ unit residential are generally exempt from NMLS requirements. However, business-purpose loans on 1–4 unit residential property are a gray area — California, Nevada, Oregon and 15+ other states have tightened requirements since 2025. The key distinction: consumer purpose = always licensed; business purpose on 1–4 family = state-dependent.

Action Item for Workshop: Confirm what states 411 Capital lends in and what property types. Flag any residential 1–4 family business-purpose loans immediately for attorney review before automating that deal type. Do not build automation for loan types where licensing is unconfirmed.
High Fair Lending — Scoring Algorithm Bias Risk

Any automated scoring model in lending carries the risk of disparate impact — producing outcomes that disproportionately harm a protected class even without discriminatory intent. If the model uses neighborhood or zip code data, property location scoring, or any variable that correlates strongly with race, ethnicity, or national origin, the lender is exposed to Fair Housing Act and ECOA challenges. This is not theoretical — regulators are actively investigating algorithmic lending bias.

Protection: Avoid using zip code or neighborhood as a direct scoring factor — use market liquidity data (days on market, comp volume) instead. Conduct a bias audit on the model annually. Keep detailed logs of all scoring decisions. Do not score borrowers on demographic proxies.
Medium AML / BSA Compliance — Know Your Customer

The Bank Secrecy Act requires financial institutions including private lenders to have anti-money-laundering programs, conduct customer due diligence, and file Suspicious Activity Reports for transactions that appear unusual. With automated KYC and KYB tools doing identity checks, the system must log every verification and flag anomalies for human review. Automated OFAC watchlist screening is mandatory.

Required Build: OFAC watchlist check on every borrower (Persona handles this). Log all KYC/KYB verifications with timestamps. Create an SAR protocol for flagged deals. Designate a BSA officer at 411 Capital — this is a named individual responsibility.
Medium Data Retention and Right to Deletion

Borrower application data — SSNs, bank statements, entity documents, credit reports — cannot be held indefinitely. GLBA, FCRA, and state privacy laws (California CCPA, Virginia VCDPA) each have specific retention windows and deletion rights. An automated system that never purges data creates a compounding liability as the database grows.

Required Build: Data retention schedule: credit reports deleted after loan decision + 25 months (FCRA). Application data archived after 7 years (common audit standard). Declined applicant data purged after 36 months. Automated deletion jobs built into the system from day one.
High Data Protection — What Must Be Secured

The system handles Category 1 sensitive financial data — the most regulated and highest-value target for breaches. Every layer must be designed with security as a first principle, not bolted on after.

High PII Data in the Intake Form

The intake form collects full legal name, SSN or EIN, date of birth, address, financial statements, and bank information. This is the highest-risk data collection point. If the form is built on a platform that does not have SOC 2 Type II certification, the lender accepts full liability for any breach of that data during transmission or storage.

Required: Only use SOC 2 Type II certified intake platforms (Typeform, Jotform Hipaa tier, or custom built on AWS/GCP). TLS 1.2+ encryption in transit. No storage of SSNs in plain text anywhere in the pipeline — tokenize on capture. Persona handles ID documents; never store them in Airtable or Google Sheets.
High Third-Party Vendor Security Chain

Every API partner — Middesk, ATTOM, HouseCanary, Qualia, DocuSign, Zapier — has access to some portion of borrower data. GLBA requires the lender to conduct vendor due diligence and have written contracts with each vendor confirming their security standards. If a vendor is breached and the lender cannot demonstrate they vetted and monitored that vendor, the lender shares legal liability.

Required: Vendor security questionnaire or SOC 2 report on file for every API partner before go-live. Written data processing agreements with each vendor. Annual vendor review. Use Persona and Middesk specifically because both have SOC 2 certification and are designed for financial services.
High Wire Fraud and Social Engineering Risk

Hard money lending involves large wire disbursements at closing. Automated systems that send approval notifications and term sheets create new social engineering attack surfaces — a fraudster who intercepts a notification email can attempt to redirect wires by impersonating the lender or borrower. Wire fraud in real estate is one of the fastest-growing categories of financial crime.

Required: Never include wire instructions in automated emails. All wiring instructions delivered only by phone verbal confirmation + secure portal — never email. Multi-factor authentication on all system logins. Closing team trained specifically on business email compromise recognition. Wire amounts over a threshold require two-person authorization.
Medium CRM as a Data Liability

If HubSpot or Airtable holds full borrower files including SSNs, credit data, and bank statements, those platforms become regulated data stores. A misconfigured sharing permission, an accidentally public Airtable base, or an exported spreadsheet sent to the wrong email address creates a reportable breach. Many CRM-related breaches happen through exactly these mundane mistakes, not sophisticated attacks.

Required: Never store raw SSNs, credit reports, or bank statements in CRM or Airtable. Store tokenized references only — the actual documents live in a dedicated secure file store (Dropbox Business with viewer restrictions or Google Drive with DLP policies enabled). Role-based access: closing team sees closing docs; underwriters see underwriting data; no single user has full record access unless they are a named principal.
Medium Document Version Control and Audit Trail

In lending, an audit trail is not optional — it is how the lender defends every decision in a regulatory examination or legal dispute. The system must record who reviewed a deal, when, what version of the score they saw, what changed, and who approved the final term sheet. If the audit trail is incomplete, the lender cannot reconstruct a decision — which is a regulatory violation under GLBA and ECOA record-keeping requirements.

Required Build: Immutable event log for every deal: form submitted, score calculated, review opened, decision made, term sheet sent, signed, funded. Timestamp and user ID on every event. No overwrite — all changes create new versions. Store audit logs separately from operational data and back up daily.
Medium Access Control and Offboarding

As the team grows — additional underwriters, a closing coordinator, a loan officer — access permissions compound. A former employee with retained access to a Zapier account, an Airtable base, or a Dropbox folder is a significant uncontrolled risk. Most small financial services firms never formalize offboarding checklists, meaning ex-employees often retain system access indefinitely.

Required: Role-based access from day one — no admin access for anyone who does not need it. Offboarding checklist: every system access revoked within 24 hours of departure. Annual access audit — list every user, every system, every permission level. Single sign-on (SSO) via Google Workspace to make revocation instant across all connected tools.
High Technical Challenges — Build Complexity
High Scoring Engine Is a Living System, Not a Static Formula

The biggest technical challenge is that the scoring model is not a one-time build — it is a system that must be updated as market conditions change, as new deal patterns emerge, and as the lender gains confidence in specific risk categories. A scoring model built in Airtable formulas will be brittle and hard to update. A model built in a no-code automation tool like Make.com will be slow. The right architecture separates the weights from the logic so that updating weights does not require rebuilding workflows.

Recommendation: Store scoring weights as a configuration table in Airtable (one row per category, one column per weight). The calculation engine reads from that table. To change a weight, update one cell — the whole system recalculates automatically. This makes the model tunable without touching code.
High Data Quality from Multiple API Sources

The property data worker pulls from ATTOM or HouseCanary, the borrower check worker pulls from Middesk and Persona, and the credit worker may pull from a separate bureau. Each API returns data in a different format, with different field names, different confidence scores, and different rates of null values for rural or uncommon properties. A scoring engine that receives a null from one API and treats it as zero will score a deal incorrectly.

Required Build: Data normalization layer before scoring. Every API response mapped to a canonical internal schema. Null handling rules: if AVM returns null, flag for manual entry before scoring proceeds — do not score with missing data. Confidence score from HouseCanary below 70% triggers manual review regardless of AVM value.
High Qualia Integration — No Public API Guarantee

Qualia is used for closing management and already handles title ordering. The plan is to push intake data to Qualia automatically on deal approval to eliminate re-entry. However, Qualia's API access and webhook capabilities vary by account tier and are not publicly documented in full. Depending on the account, the integration may require Qualia professional services or may only support limited data push via their Marketplace tools.

Action Item: Contact Qualia directly before building this integration. Confirm API access level on the 411 Capital account. If direct API is not available, consider a semi-automated solution using Zapier's Qualia connector. Worst case: a structured pre-filled form that closes the data entry gap even without full automation.
Medium Zapier / Make.com Automation Fragility at Scale

No-code automation tools like Zapier and Make.com are excellent for MVP builds but have known failure modes at scale: rate limiting, execution timeouts on long-running workflows, poor error visibility when a step silently fails, and data loss if a zap errors mid-run with partial writes. A workflow that sends a borrower through five steps and fails on step three may leave incomplete data in the CRM with no alert.

Mitigation: Use Make.com for complex multi-step flows — it has better error handling and retry logic. Build error notification into every flow: if any step fails, send an alert to a designated internal Slack channel or email. Monthly review of all active automations to confirm they are running as expected. As volume grows beyond 100 applications per month, evaluate migrating critical flows to a proper backend service.
Medium Document Generation — PDF Fidelity

Auto-generating term sheets and adverse action notices as PDFs requires a templating layer that reliably populates variable fields without formatting errors. Merged fields that overflow cells, dollar amounts that lose formatting, or dates that render incorrectly can create term sheets that look unprofessional or — worse — contain legally ambiguous amounts. DocuSign's templating and tools like Documint or Anvil handle this but require careful template design.

Recommendation: Use Documint or Anvil for PDF generation — both have robust field validation and preview modes. Build the template with a dedicated designer, not a raw merge tool. Test every template with edge-case data: very long names, high dollar amounts, multiple properties. Version control all templates.
Manageable No-Code Stack Limits Future Scalability

An Airtable + Zapier + HubSpot stack is an excellent MVP. At high volume — say 500 applications per month — Airtable row limits, Zapier task caps, and HubSpot plan tiers become constraining. This is not a current problem but it is a planned obsolescence that should be acknowledged from day one so the architecture is designed to be migrated to without rebuilding from scratch.

Plan Ahead: Design data schemas in Airtable that would translate directly to a PostgreSQL database. Document every Zapier flow with enough detail that it can be rebuilt as code later. At 200 applications per month, evaluate whether to upgrade within the no-code stack or begin a parallel backend build. This is a year-two problem, not a year-one problem.
High Scoring Engine Specific Risks
High Weight Miscalibration — Approving Deals That Should Have Been Declined

The most dangerous failure mode is a false positive — the system scores a deal green, the lender approves it without human review, and the deal defaults. On a $500,000 hard money loan, one uncaught bad deal can erase months of revenue. The risk is highest in the early months when the model has no performance history to validate against.

Required Protocol: No deal is auto-approved without human sign-off for the first 6 months regardless of score. After that, only Green deals with scores above 85 get fast-tracked — and those are still reviewed for term sheet accuracy by a principal before sending. Set this policy in writing before go-live.
High Single-Score Masking — One Great Category Hiding One Terrible One

A weighted average score can hide a catastrophic weakness. If a borrower has perfect experience (40/40 on that category) but zero exit strategy viability (0/20 on that category), the aggregate score might still reach 75 — which looks like a conditional approval. But a deal with no viable exit is a loss regardless of how experienced the borrower is. Aggregate scores can obscure category-level red flags.

Required Build: Category floor rules — if any single scoring category falls below a minimum threshold (e.g., exit strategy below 5/20, or LTV above hard cap) the deal is automatically capped at Red regardless of aggregate score. The scoring engine must support both a total score AND category-level knock-out rules.
Medium Model Drift — Market Changes Invalidating Historical Weights

A scoring model calibrated in a rising market may systematically over-approve deals in a flat or declining market. Exit strategy weights built on 2021–2023 fix-flip data may be too optimistic for 2025 conditions. A model that is never re-trained will become progressively less accurate as market conditions shift.

Required Build: Monthly model performance review — compare score distribution of funded deals against actual outcomes (sold, refinanced, defaulted, extended). If Green-scored deals start defaulting at elevated rates, flag immediately for weight recalibration. The Learning Worker tracks this automatically; the lender reviews the report monthly.
Manageable First-Time Borrower Scoring Bias

The experience category systematically penalizes first-time borrowers. This is intentional — experience reduces risk — but if the weights are too heavy on experience, the system will decline all new-to-market borrowers regardless of deal quality. This could mean missing genuinely good deals from capable first-timers with strong properties and exit plans.

Mitigation: Cap the experience deduction at a maximum of 15 points below a baseline rather than going to zero. Compensating factors: if LTV is very conservative (under 60%) and exit strategy is clearly documented, experience weight can be partially offset. Build this as an override rule in the scoring config table.
Auto Non-Negotiable Build Requirements Before Go-Live

These are not optional. Every item below must be in place before the system handles a real borrower application.

Written adverse action notice template with specific reason codes reviewed by attorney
Legal
Written Information Security Plan (WISP) drafted and signed off by 411 Capital principal
Legal
SOC 2 confirmation on file for every API vendor (Persona, Middesk, ATTOM or HouseCanary)
Security
Do Not Lend List structured in digital format, audited by attorney, with reason codes
Legal
Category floor rules configured in scoring engine — single bad category cannot be masked by aggregate score
Build
Immutable audit log capturing every deal event with timestamp and user ID
Build
Wire fraud warning added to all approval communications — no wiring instructions sent via email ever
Security
OFAC watchlist check active on every application before any scoring step runs
Compliance
MFA enabled on every system account — no exceptions, no shared logins
Security
First 20 live deals run in parallel manual + automated review before removing human oversight from Green-tier
Process
State licensing confirmed for all active lending states — attorney sign-off on business-purpose residential loan treatment
Legal
Data retention schedule documented — credit reports, applications, funded loans, declined deals each have defined deletion timelines
Compliance