A transparent, auditable draw from application to allotment letter.
EstateFlow Balloting runs the ballot the way applicants, auditors and management expect it to be run. Applications come in with CNIC de-duplication and verified booking payments, are pooled by category and phase, and are drawn by a seeded random process that can be shown on screen and replayed. Results publish to the web, WhatsApp and SMS; winners get allotment letters and a plot on the map; unsuccessful applicants are refunded in one batch.
- features
- 12features
- modules
- 12modules
- screens
- 5screens
- webhooks
- 8webhooks
- Draw 001
- GV3-1187 → Plot 52-B
- Draw 002
- GV3-0342 → Plot 118-C
- Draw 003
- GV3-1920 → Plot 07-E
- Draw 004
- GV3-0771 → Plot 201-F
- Remaining
- 146 of 150 plots
A draw nobody can verify, results nobody receives
- Applications on paper; duplicates by CNIC discovered after the draw
- The draw runs on a laptop nobody can audit
- Winners find out days later; the office phone does not stop
- Refunds for unsuccessful applicants take months
How each part of Balloting actually works
12 features from the product documentation. Select one to read what it does, the mechanism behind it, the data it holds, the state before and after, and what it connects to.
Application intake
Online form, dealer portal entry and bulk import from bank-collected forms. Each application carries CNIC, category, phase, booking receipt and dealer reference.
Online form, dealer-portal entry and bulk import of bank-collected forms create applications with CNIC, category, phase, booking receipt and dealer reference.
Applicant, CNIC, category, phase, receipt, dealer, timestamp.
Website, Dealer portal, Finance.
Paper forms in boxes.
A structured applicant list.
Eligibility & CNIC de-duplication
One application per CNIC per category rule, booking-amount verification against bank receipts, and flagging of incomplete or duplicate submissions before the draw.
One-application-per-CNIC-per-category rule; booking-amount verification against bank receipts; incomplete or duplicate submissions flagged before the draw.
CNIC, receipt match, flags.
Finance, Sealing.
Duplicates found after the draw.
A clean eligible list.
Category & phase pools
5 Marla, 10 Marla, 1 Kanal, commercial and any custom categories, each with its own pool, quota and reserved plots (for example overseas or employee quotas).
Each category has its own pool, quota and reserved plots (e.g., overseas, employees); pools are drawn in a configured sequence.
Category, pool, quota, reserved plots.
Draw, Maps.
One undifferentiated list.
Fair pools with quotas enforced.
Seeded random draw
The draw uses a published seed and a cryptographic random generator. The sequence is deterministic from the seed, so the outcome can be replayed and verified by an auditor.
The eligible list is frozen and hashed. A published seed drives a cryptographic random generator; the sequence is deterministic from the seed and can be replayed and verified.
List hash, seed, draw order.
Audit, Live screen.
An unverifiable draw.
A draw an auditor can replay.
Live draw screen
A projector-ready screen shows applicant and plot as each is drawn, with running counts per category, for a hall or a livestream.
A projector-ready screen shows applicant and plot as each is drawn with running counts per category; the run is recorded.
Draw events, counts, recording.
Draw, Results.
A laptop nobody can see.
A public, recorded ceremony.
Plot assignment on the map
Winners are matched to actual plot numbers from the live inventory, either by random plot draw or by sequence; the plot turns Booked on EstateFlow Maps immediately.
Winners are matched to actual plot numbers from live inventory by random plot draw or sequence; the plot turns Booked on Maps immediately.
Winner, plot ID, status.
Maps, ERP inventory.
Plot allocation weeks later.
Plot known at the draw.
Results on WhatsApp, SMS & web
Every applicant is notified with their result within minutes. A public results page is searchable by application number or CNIC.
Results broadcast on WhatsApp and SMS; a public results page is searchable by application number or masked CNIC.
Result, delivery status.
WhatsApp API, SMS, Website.
Days of phone calls.
Every applicant informed within minutes.
Allotment letters
Letters generate from a template with applicant, plot, category and payment plan, ready to print or deliver on WhatsApp.
Letters generate from a template with applicant, plot, category and payment plan; printed or delivered on WhatsApp.
Template, merge fields, letter.
Documents.
Typed one by one.
Instant, consistent letters.
Plan hand-off to QistFlow
Successful applications become files with the category’s payment plan and schedule, starting from the ballot date.
Successful applications become files with the category’s plan and a schedule starting from the ballot date.
File, plan, schedule.
QistFlow.
Re-entry into the ledger.
Files ready for collection.
Refunds for unsuccessful applicants
A single refund batch computes amounts per policy, routes approval and produces the bank payout file.
A refund batch computes amounts per policy, routes approval and produces the bank payout file; status tracked per applicant.
Refund amount, approval, bank file, status.
Accounts, Approvals.
Months of refunds.
One approved batch.
Audit log & sealed results
Applicant list, seed, draw order and results are hashed and stored. Any change after sealing is impossible without a visible trail.
Applicant list, seed, draw order and results are hashed and stored; any change after sealing is impossible without a visible trail.
Hashes, seal time, audit log.
Audit, Auditor access.
Results could be edited.
Tamper-evident results.
Ballot dashboard
Applications per category, verification status, oversubscription ratio, results delivered and refunds processed.
Applications per category, verification status, oversubscription ratio, results delivered and refunds processed on one screen.
Counts, ratios, statuses.
Insights.
Manual tallies.
Live ballot control.
12 modules, switched on per role. Admins configure rules; everyone else sees only what applies to them.
- Application Intake
- Eligibility & CNIC Check
- Payment Verification
- Category & Quota Pools
- Seeded Random Draw
- Live Draw Screen
- Plot Assignment
- Results Publishing
- Allotment Letters
- Refund Batches
- Audit & Sealing
- Ballot Dashboard
One file, start to finish.
A realistic sequence from the documentation, with the state before and after each step. Names and numbers are illustrative.
Applicants check status and results on the Buyer App; dealers submit and track applications from the portal.
- 01
Announce
Phase 3 opens for 620 plots in four categories. The application form goes live on the website and dealer portal with a closing date.
- 02
Collect
2,140 applications arrive with booking receipts. Bank-collected paper forms are bulk-imported by application number.
- 03
Verify
CNIC duplicates (31) and unverified payments (58) are flagged and resolved. 2,051 applications are eligible.
- 04
Seal the list
The eligible list is frozen and hashed. The seed is generated and printed in a sealed envelope for the hall.
- 05
Draw
On ballot day, the seed is entered on stage. Winners and plot numbers appear on screen category by category; the run is recorded.
- 06
Publish
Within ten minutes, results reach every applicant on WhatsApp and SMS and the public results page is live.
- 07
Allot and refund
Winners receive allotment letters, files open in QistFlow, plots turn Booked on the map. 1,431 unsuccessful applicants are refunded in one batch.
Balloting, screen by screen
Click the sidebar to move between the overview, lists, records, boards and the settings that drive the rules. Sample data on real layouts.
Ballot control room
Green Valley · Phase 3 · Ballot day, 14:20- 5 Marla96047%
- 10 Marla61530%
- 1 Kanal28414%
- Commercial1929%
| Seq | Application | Applicant | CNIC (masked) | Plot | Delivered |
|---|---|---|---|---|---|
| 001 | GV3-1187 | Rabia Anwar | 35202-•••••-1 | 52-B | WhatsApp · SMS |
| 002 | GV3-0342 | Usman Ghani | 61101-•••••-7 | 118-C | WhatsApp · SMS |
| 003 | GV3-1920 | Hina Baig | 42201-•••••-4 | 07-E | WhatsApp · SMS |
| 004 | GV3-0771 | Kamran Shah | 37405-•••••-9 | 201-F | SMS · WhatsApp pending |
Applications · Phase 3
2,140 received · 2,051 eligible · 89 flagged| App # | Applicant | CNIC | Category | Dealer | Receipt | Verification | Status |
|---|---|---|---|---|---|---|---|
| GV3-1187 | Rabia Anwar | 35202-•••••-1 | 10 Marla | Direct | HBL 44120 | Matched | Eligible |
| GV3-0342 | Usman Ghani | 61101-•••••-7 | 10 Marla | Al-Noor | MCB 10933 | Matched | Eligible |
| GV3-0771 | Kamran Shah | 37405-•••••-9 | 10 Marla | Skyline | HBL 44201 | Matched | Eligible |
| GV3-1502 | M. Aslam | 35201-•••••-3 | 5 Marla | Direct | — | No receipt | Flagged |
| GV3-1503 | M. Aslam | 35201-•••••-3 | 5 Marla | City Mkt | UBL 8812 | Duplicate CNIC | Flagged |
| GV3-0090 | Hina Baig | 42201-•••••-4 | 1 Kanal | Direct | HBL 43990 | Matched | Eligible |
Draw · 10 Marla pool
615 applications · 150 plots · seed 7f3a…c91e · sealed 14 Sep 09:00- 14 Sep 09:00Eligible list sealed and hashed · 2,051 applications
- 14:00Seed envelope opened on stage · entered by auditor
- 14:02Draw 001 · GV3-1187 → Plot 52-B · WhatsApp + SMS delivered
- 14:02Draw 002 · GV3-0342 → Plot 118-C
- 14:03Draw 003 · GV3-1920 → Plot 07-E
- 14:03Draw 004 · GV3-0771 → Plot 201-F · SMS delivered · WhatsApp pending
- Screen
- Hall projector · livestream
- Next pool
- 1 Kanal · 284 apps · 60 plots
- Results page
- estateflow.live/gv/phase-3
Results & allotment
Winners 620 · unsuccessful 1,431 · letters 620| App # | Applicant | Category | Result | Plot | Letter | File | Refund |
|---|---|---|---|---|---|---|---|
| GV3-1187 | Rabia Anwar | 10 Marla | Successful | 52-B | Sent | GV3-2001 | — |
| GV3-0342 | Usman Ghani | 10 Marla | Successful | 118-C | Sent | GV3-2002 | — |
| GV3-0090 | Hina Baig | 1 Kanal | Successful | 07-E | Sent | GV3-2003 | — |
| GV3-0555 | A. Karim | 5 Marla | Unsuccessful | — | — | — | Batch RF-09 · approved |
| GV3-0902 | S. Bibi | 5 Marla | Unsuccessful | — | — | — | Paid 18 Sep |
Ballot configuration
Phase 3 · 620 plots- 5 Marla
- 320 plots · 960 apps · 20 reserved overseas
- 10 Marla
- 150 plots · 615 apps · 15 overseas · 5 employee
- 1 Kanal
- 60 plots · 284 apps
- Commercial
- 90 plots · 192 apps
- One per CNIC per category
- Enforced
- Booking amount
- Verified against bank receipts
- Cut-off
- 12 Sep 17:00
- Randomness
- Seeded CSPRNG · deterministic replay
- Plot assignment
- Random plot from pool
- Results
- WhatsApp + SMS + public page
- Refunds
- Full booking amount · batch within 15 days
Scheduled to email or exported to Excel and PDF. Every report drills down to the record.
- Applications per category and per day
- Verification status and flags
- Oversubscription ratio per pool
- Draw log with sequence and plot
- Results delivery status
- Refund batch status
Who uses it, and what each role sees
Access is scoped by role, team and field. A dealer never sees another dealer’s file; an agent never exports the database.
Applicant
Application status, result, allotment letter or refund status
Dealer
Applications submitted through the dealer and their results
Ballot admin
Intake, verification, pools, sealing and the draw
Auditor
Sealed hashes, seed, draw log and replay tool
Finance
Payment verification and refund batches
| Module | View | Create / edit | Approve | Export | Configure | Delete |
|---|---|---|---|---|---|---|
| Application Intake | AllOwnTeamAllAll | —OwnTeam—All | ————All | ————All | ————All | ————All |
| Eligibility & CNIC Check | AllOwnTeamAllAll | —OwnTeam—All | ————All | ————All | ————All | ————All |
| Payment Verification | AllOwnTeamAllAll | —OwnTeam—All | ————All | ————All | ————All | ————All |
| Category & Quota Pools | AllOwnTeamAllAll | —OwnTeam—All | ————All | ————All | ————All | ————All |
| Seeded Random Draw | AllOwnTeamAllAll | —OwnTeam—All | ————All | ————All | ————All | ————All |
| Live Draw Screen | AllOwnTeamAllAll | —OwnTeam—All | ————All | ————All | ————All | ————All |
Own = only records assigned to me · Team = my team’s records · All = the whole organisation. Field-level rules can further hide price, owner or CNIC per role.
Toggle to see how each control changes the posture score. Defaults shown are our recommended configuration.
Every action writes an entry with actor, entity, before and after value and time. Entries cannot be edited or deleted, only exported. Try it: perform an action.
- 12:04:11S. KhanBooked plot 14-C · Balloting
- 12:03:48SystemLock acquired · unit 14-C
- 11:58:02A. ButtApproved discount 5% · AP-2291
- 11:41:30H. MalikExported leads (team, 84 rows)
- 11:20:15AdminChanged role: F. Noor → Field agent
- 10:15:07SystemBlocked transfer · GV2-0930 (defaulter)
What happens without anyone clicking
Rules run the routine work. Flo, the AI assistant, handles the parts that need language or judgement, and every AI action is logged.
Automations
- CNIC de-duplication at intake
- Payment matching to bank receipts
- List sealing and hashing
- Results broadcast on WhatsApp and SMS
- Allotment letter generation
- File creation in QistFlow for winners
Flo in Balloting
- Duplicate and anomaly detection across applications
- Demand forecasting per category for the next launch
Outbound WhatsApp uses approved templates. Low-confidence cases escalate to a person.
Connects to anything, not just the list
Every connector in the catalogue, the full REST API and a webhook for every state change. If it has an API, EstateFlow talks to it.
Every connector below is available to Balloting. Those most used with it are highlighted; anything not listed connects through the REST API, webhooks or Zapier / Make / n8n.
- Zameen
- Bayut
- Graana
- OLX Property
- Meta Lead Ads (Facebook, Instagram)
- Google Ads lead forms
- TikTok lead forms
- Website forms
- Landing-page builders
- Chat widget
- QR / offline import (CSV, Excel)
- WhatsApp Business API (Meta Cloud API or any BSP)
- SMS gateways (Telenor, Jazz, Zong, Ufone, Twilio)
- Email (SMTP, Gmail, Outlook, SendGrid)
- VoIP / cloud PBX (SIP, Asterisk, Twilio Voice)
- Call tracking numbers
- Push notifications (FCM, APNs)
- Payment gateways (PayFast, Safepay, JazzCash, Easypaisa, Stripe)
- Bank transfer / IBFT references
- Pay links
- Bank statement import (CSV, MT940)
- Bank feeds (Enterprise)
- POS terminals
- QGIS projects (.qgz)
- PostGIS
- GeoServer (WMS / WFS)
- Shapefile, GeoJSON, KML, DXF / CAD import
- Mapbox, Leaflet, OpenLayers clients
- ArcGIS / Esri (Enterprise)
- Satellite imagery providers
- GPS from field devices
- QuickBooks
- Xero
- Sage
- Odoo
- Tally
- SAP / Oracle / Dynamics (Enterprise)
- FBR e-invoicing
- Excel / CSV export for any ledger
- CNIC OCR
- NADRA verification partners
- DocuSign
- Adobe Sign
- PandaDoc
- Google Drive
- OneDrive / SharePoint
- Dropbox
- S3-compatible storage
- Biometric devices (ZKTeco, Hikvision)
- Bank payroll files
- Google Workspace / Microsoft 365 directories
- SSO: SAML, OIDC, Azure AD (Enterprise)
- Boom barriers & RFID
- ANPR cameras
- Smart meters (electricity, water, generator)
- IoT sensors (MQTT)
- Sales-centre kiosks & touch tables
- Digital signage
- Power BI
- Tableau
- Looker Studio
- Metabase
- Zapier
- Make
- n8n
- Google Sheets
- Slack / Teams alerts
- Everything in the UI is available through the REST API: read, create, update, and the same approvals and locks apply.
- Every state change emits a webhook within seconds, with a signed payload and automatic retries.
- Per-organisation API keys with scopes per module; OAuth 2.0 for partner apps; rate limits published per plan.
- JSON over HTTPS, cursor pagination, filtering and sorting on every list endpoint, bulk endpoints for imports.
- Sandbox organisation for testing; OpenAPI 3.1 specification and Postman collection; changelog with versioned endpoints (/v1).
- /v1/ballots
- /v1/applications
- /v1/pools
- /v1/verification
- /v1/draws
- /v1/results
- /v1/allotment-letters
- /v1/refund-batches
Each resource supports list, get, create, update and (where allowed) delete, with the same permissions and approvals as the UI.
/v1/ballots/{id}/applicationsSubmit an application from a bank or dealer system
/v1/ballots/{id}/results?cnic=35202-•••••-1Public result lookup
/v1/ballots/{id}/auditList hash, seed, draw log for an auditor
curl https://api.estateflow.live/v1/ballots/{id}/applications \
-H "Authorization: Bearer ef_live_•••" \
-H "Content-Type: application/json" - application.received
- application.flagged
- ballot.sealed
- draw.started
- draw.result
- results.published
- letter.generated
- refund.batch_created
Every state change in every product emits an event. Subscribe per event type, per project or for the whole organisation. Signed with HMAC-SHA256, retried with backoff for 24 hours, replayable from the dashboard.
POST https://your-server.example/estateflow
X-EstateFlow-Signature: sha256=3c9a…12ff
Content-Type: application/json
{
"id": "evt_01J8Z6M9QK",
"type": "booking.created",
"occurred_at": "2026-09-06T07:04:12Z",
"organisation": "green-valley",
"data": {
"booking_id": "BK-2026-0417",
"unit": { "id": "14-C", "project": "phase-2", "block": "C", "size": "10 Marla" },
"customer": { "id": "c_88112", "name": "Ahsan Raza" },
"plan": "36m-cat-b",
"net_price": 4441250,
"agent": "u_0142",
"dealer": "d_al-noor"
}
} Connected EstateFlow products
- MapsThe society map, alive: every plot coloured by real status.
- QistFlowThe plot-file payment engine: schedules, reminders, recovery, transfers.
- Documents & ContractsAgreements, deeds and receipts that generate themselves, signed with a trail.
- ERPOne inventory, one booking process, one set of numbers.
- CRMEvery lead answered in seconds, tracked to booking.
Balloting runs standalone or with the rest of the suite on the same database. Quotes are per organisation, based on users, plots and files.
- Demo on your own data
- Data migration from spreadsheets or your current system
- Onboarding and WhatsApp template approval
About Balloting
01 How can applicants trust the draw was random?
The eligible list is sealed and hashed before the ballot. A published seed drives a cryptographic random generator, so the same seed and list always reproduce the same result. An auditor can replay it.
02 Can we reserve plots for quotas such as overseas Pakistanis or employees?
Yes. Each category can hold reserved plots and a separate pool, and the draw runs pools in the sequence you define.
03 What happens to unsuccessful applicants?
They are notified with their result and refunded in a batch. Refund amounts follow your policy, approvals are routed, and the bank file is produced from the batch.
See Balloting on your own data.
A 45-minute demo on your own data. We load a sample of your inventory and files before the call, so you see your plots, your plans and your numbers, not a sample scheme.
- One block of your scheme digitised on the live map
- A booking → schedule → WhatsApp reminder, end to end
- A file transfer with the lock and dues check
- A rollout order and a written quote within two days