Lagerbestand

Recipe Costing and Confidentiality: How Multi-Unit Groups Protect Proprietary Formulas in a Cloud System

What Keeping a Recipe Confidential in the Cloud Actually Requires

Keeping a proprietary recipe confidential in a cloud costing system comes down to controlling two things: which staff roles can open a recipe and read its exact ingredient quantities, and which outlets a recipe is visible in at all. Scope both by role and by location, and a group can cost its signature dishes for margin without ever exposing the formula across the whole business.

That distinction matters because the fear is real and specific. One multi-outlet casual dining group paused its recipe costing rollout entirely, uncomfortable entering the exact quantities behind its signature dishes into any cloud system in case the formulas leaked. Margin visibility went on hold pending a leadership decision. The recipes never moved, so the group kept costing on paper and guessing at food cost.

The mistake in that decision is treating confidentiality as all-or-nothing: either the recipe goes in the system and everyone can see it, or it stays locked in a chef's head and nobody can cost it. Recipe costing and confidentiality are not opposites. The right controls let you have both, and this guide walks through the failure modes that make groups think otherwise and the mechanisms that resolve each one.

Two independent access gates, a role check and a location check, decide who can view a recipe


Why "The Cloud Sees Everything" Is the Fear That Stalls Rollouts

The objection underneath most stalled rollouts is an assumption, not a fact: that putting a recipe into a shared system makes it visible to every user in the group by default. If that were true, a signature formula entered for costing would be readable by staff at outlets that never serve the dish, by managers who only need the cost number, and potentially by anyone who later leaves for a competitor. For a proprietary formula that is the whole competitive edge, that is an unacceptable trade, so the recipe stays out and the costing never happens.

The cost of that freeze is quiet but continuous. Take a single signature dish selling at $18.00 with a target food cost of 30 percent, or $5.40 a plate. Left uncosted, its real food cost drifts to 34 percent, or $6.12, without anyone seeing it. That is $0.72 of unseen drift per plate. At 90 plates a week across a 12-outlet group, one dish quietly gives back about $40,000 a year, and the group never knows because the recipe it was afraid to expose is the one it also cannot measure.

About 40,000 dollars a year in unseen food cost drift on one uncosted signature dish across a 12-outlet group


The way out is to reject the premise. Visibility in a well-designed cloud costing system is not a single group-wide switch; it is decided per user and per outlet. Once that is true, entering a recipe stops being an act of disclosure and becomes an act of measurement.

Deciding Who Can See Recipe Costs: Admin Gatekeeper or Every Chef?

The second thing that stalls groups is having no clear model for who should be allowed to see recipe costs and quantities at all. The instinct is a binary: appoint one trusted administrator as a gatekeeper who enters and guards every recipe, or train chefs directly and let them manage their own. Both extremes fail. A single gatekeeper becomes a bottleneck and a single point of failure; open access to every chef recreates the leak fear you started with.

Role-based access control replaces that binary with a matrix. Instead of one decision for the whole group, you decide separately what each role can do: who can view a recipe cost, who can see the exact ingredient quantities behind it, and who can edit the recipe. Supy exposes more than 200 customisable permissions for exactly this, so viewing a cost and reading a formula are different rights granted to different people. A branch manager can see that a dish runs at 31 percent food cost without ever seeing the quantities that make it; an executive chef can edit the formula for their own recipes; group finance can read costs across every outlet but never open a single ingredient list.

Permission matrix showing recipe cost, ingredient quantities, and edit rights granted separately per staff role


Framed this way, the "gatekeeper versus chefs" question dissolves. You are not choosing a custodian; you are assigning rights per role. The IT and data-integrity concern that granular access control is what keeps a shared system safe is answered directly, because who can create items, change settings, and view reports is each a separate, auditable permission rather than one broad login.

Scoping Recipes by Location So a Formula Never Leaves Its Kitchen

Role controls decide who can see a recipe; location scoping decides where a recipe exists at all. This is the second gate, and it is the one that most directly answers the leak fear. In Supy, recipe visibility is controlled by location: a recipe can be assigned to the specific outlets that serve it, so a proprietary formula stays visible only to the branches that need it and never appears across the group by default. Every action runs through two independent checks, a role permission and a per-location setting, so a user only reaches a recipe when both their role and their outlet clear it.

In practice that means a house sauce base developed by the central kitchen is visible only there, a signature dish is scoped to the two outlets that plate it, and a manager at a third outlet cannot see either, because the recipe simply is not part of their location. The formula never has to travel group-wide to be costed. It is entered once, scoped tightly, and measured where it lives. Because every change is captured in a tamper-proof audit log tied to a named user and timestamp, a group can also prove after the fact exactly who opened or edited a recipe, which is often what turns a nervous leadership team into a confident one.

Recipe visibility grid showing each recipe visible only in its serving outlets and none group-wide by default


The Margin Visibility You Lose Every Month the Recipes Stay on Paper

Once confidentiality is handled by role and location, the upside the group put on hold becomes available, and it is larger than most operators expect. A cloud-costed recipe carries a target food cost percentage with over-threshold alerts, so a dish that drifts past its 30 percent target flags itself instead of hiding in a month-end report. Costs break down by ingredient and by outlet, so the same signature dish running at 28 percent in one branch and 34 percent in another becomes a visible, fixable gap rather than a blended average that looks fine.

That is the trade the leak fear was quietly making: to protect a formula from a leak that proper access controls prevent anyway, the group gave up the branch-by-branch margin visibility that recipe costing exists to deliver. Keeping recipes on paper does not make them more confidential; it just makes them unmeasured. The confidentiality problem and the margin problem have the same solution, which is to put the recipe in a system that scopes it correctly rather than one that assumes everyone should see everything.

Food cost percentage by branch against a 30 percent target, showing which branches drift over


If your group has recipe costing on hold, run a quick self-diagnostic before your next planning cycle. First, name the specific fear: is it that a competitor could obtain the formula, or simply that too many internal users would see it? Almost always it is the second, and role plus location scoping resolves it. Second, list the roles that actually need each right separately, view cost, view quantities, and edit, rather than granting one broad login. Third, pick two or three signature recipes, scope them to only the outlets that serve them, and cost them for one month. If the food cost gap you find on even one dish is bigger than the leak risk you were protecting against, you have your leadership decision. For a deeper look at how this fits the wider costing picture, see our guide to recipe costing software and why spreadsheet recipe costing falls behind software as a group scales. You can also see how role and location controls work inside Supy recipe costing and across the platform's permissions and access controls.

Book a Demo with Supy for confidential recipe costing

Ready to optimize your restaurant operations?

Blog

Our operational insights

No items found.

Your questions 
answered

Everything you need to know about Supy — from setup to integrations, pricing, and daily use. If it’s not covered here, just ask.

Was bedeutet es, ein Rezept in einem Cloud-Kalkulationssystem vertraulich zu halten?
+

Ein Rezept in einem Cloud-Kalkulationssystem vertraulich zu halten bedeutet, dass zwei unabhängige Kontrollen darüber entscheiden, wer Zugang dazu hat. Eine rollenbasierte Berechtigung legt fest, welche Benutzer die Kosten eines Rezepts einsehen, die genauen Zutatenmengen lesen oder das Rezept bearbeiten dürfen, und eine standortspezifische Einstellung entscheidet, in welchen Restaurants ein Rezept überhaupt sichtbar ist. Eine proprietäre Formel kann einmal eingegeben, auf die Filialen beschränkt werden, die sie nutzen, und nur von den Rollen gelesen werden, die Sie genehmigen. Vertraulichkeit hört auf, ein Alles-oder-nichts-Prinzip zu sein: Das Rezept ist für die Marge messbar, ohne jedem Benutzer in der Gruppe zugänglich zu sein.

Wie schützt die rollenbasierte Zugriffskontrolle ein proprietäres Rezept?
+

Die rollenbasierte Zugriffskontrolle schützt ein proprietäres Rezept, indem ein einzelner Login in separate, granulare Rechte aufgeteilt wird. Die Anzeige des Wareneinsatzes eines Gerichts, das Einsehen der genauen Zutatenmengen dahinter und das Bearbeiten des Rezepts werden zu drei verschiedenen Berechtigungen, die drei verschiedenen Rollen erteilt werden. Supy bietet hierfür mehr als 200 anpassbare Berechtigungen, sodass die Konzernfinanzabteilung Kosten überall lesen kann, ohne eine einzige Formel zu öffnen, während nur ein Küchenchef die Mengen seiner eigenen Rezepte einsehen und bearbeiten kann. Da jede Aktion einem namentlich bekannten Benutzer in einem manipulationssicheren Prüfprotokoll zugeordnet ist, kann eine Gruppe auch genau nachweisen, wer auf was zugegriffen hat.

Warum zögern Unternehmensgruppen bei der Rezeptkalkulation aus Vertraulichkeitsgründen?
+

Der Grund für die Verzögerung liegt in der Angst, dass das Eingeben von Mengenangaben zu Signature-Rezepten in ein gemeinsames Cloud-System proprietäre Formeln für alle sichtbar macht, die sich einloggen können. Die Unternehmensleitung geht davon aus, dass die Sichtbarkeit ein einziger gruppenweiter Schalter ist, weshalb Rezepte auf Papier gehalten und die Margenübersicht auf Eis gelegt werden, anstatt ein Datenleck zu riskieren. Diese Annahme ist in der Regel falsch: Die Sichtbarkeit wird in einem richtig konfigurierten System pro Rolle und pro Standort festgelegt, nicht global. Die tatsächlichen Kosten der Verzögerung sind ein unsichtbarer Wareneinsatz-Drift, der bei einem einzigen Signature-Gericht in einer 12-Outlet-Gruppe pro Jahr bis zu ca. 40.000 USD betragen kann.

Können verschiedene Mitarbeiter die Kosten eines Rezepts einsehen, ohne die Zutatenmengen zu sehen?
+

Ja. Die Einsicht in die Kosten eines Rezepts und die Einsicht in seine Zutatenmengen sind separate Berechtigungen, sodass eine Gruppe eine davon ohne die andere gewähren kann. Ein Filialleiter kann sehen, dass ein Gericht bei 31 Prozent Wareneinsatz liegt, und die Konzernfinanzabteilung kann Kosten über alle Restaurants hinweg vergleichen – ohne dass einer von beiden jemals die Zutatenliste öffnet, die die Formel zum Betriebsgeheimnis macht. Nur die Rollen, die Sie ausdrücklich genehmigen – in der Regel der Küchenchef, dem ein Rezept gehört –, können die Mengen lesen oder bearbeiten. Diese Trennung ermöglicht es einer Gruppe, vollständige Kalkulations- und Margenanalysen durchzuführen, während die Formel selbst auf die wenigen Personen beschränkt bleibt, die sie wirklich benötigen.

Wie verhindert die Standortbeschränkung, dass ein Rezept in der gesamten Gruppe geteilt wird?
+

Die Standortbeschränkung verhindert ein Datenleck, indem sie kontrolliert, wo ein Rezept existiert – nicht nur, wer es öffnen kann. Jedes Rezept wird den spezifischen Restaurants zugewiesen, die es servieren, sodass ein exklusives Gericht, das auf zwei Filialen beschränkt ist, nie in einer dritten erscheint, und eine Soßenbasis der Zentralküche nur der Zentralküche sichtbar bleibt. Jede Aktion durchläuft zwei Prüfungen – eine Rollenberechtigung und eine standortspezifische Einstellung –, sodass ein Benutzer nur dann auf ein Rezept zugreifen kann, wenn sowohl seine Rolle als auch sein Restaurant freigegeben sind. Die Formel muss nie gruppenübergreifend geteilt werden, um kalkuliert zu werden, was das Risiko beseitigt, vor dem sich Betreiber am meisten fürchten.

Wer sollte Rezepte eingeben und verwalten dürfen: ein Administrator oder die Köche?
+

Keines der beiden Extreme funktioniert gut. Ein einzelner Administrator als Gatekeeper wird zum Engpass und zu einem einzigen Fehlerpunkt, während ein offener Zugang für alle Köche die Angst vor Datenlecks erneut aufleben lässt. Das bessere Modell besteht darin, Rechte nach Rolle zu vergeben, anstatt einen einzigen Verantwortlichen zu bestimmen. Küchenchefs verwalten und bearbeiten ihre eigenen Rezepte, Manager sehen die für ihr Restaurant relevanten Kosten, und die Finanzabteilung liest die Kosten der gesamten Gruppe – jeder Bereich wird durch eine separate Berechtigung geregelt. So wird die Arbeit verteilt, ohne die Zugriffsrechte auszuweiten, und da das Recht, Einträge zu erstellen oder Einstellungen zu ändern, selbst ein kontrolliertes Recht ist, werden die Bedenken zur Datenintegrität, die IT-Teams äußern, gleichzeitig beantwortet.

Welche Margenübersicht gewinnt eine Gruppe, sobald Rezepte sicher kalkuliert sind?
+

Sobald Rezepte sicher kalkuliert sind, erhält eine Gruppe einen filialbezogenen Einblick in die Marge, den sie auf Papier nicht erzielen kann. Jedes Rezept enthält einen Ziel-Wareneinsatz in Prozent mit Warnmeldungen bei Überschreitung, sodass ein Gericht, das seinen 30-Prozent-Zielwert überschreitet, sich selbst markiert, anstatt als Monatsende-Überraschung aufzutauchen. Die Kosten werden nach Zutat und nach Standort aufgeschlüsselt, sodass ein gemittelter Wert, der gesund wirkt, in eine sichtbare Abweichung umgewandelt wird, zum Beispiel läuft dasselbe Gericht in einer Filiale bei 28 Prozent und in einer anderen bei 34 Prozent. Dieser filialbezogene Überblick ist genau die Margenkontrolle, auf die Gruppen aufgrund der Angst vor der Rezeptvertraulichkeit verzichtet haben.

Bereit, Ihre Abläufe zu transformieren?

Schließen Sie sich mehr als 3.500 Restaurantbetreibern an, die mit Supy Kosten senken, Abläufe optimieren und klügere Entscheidungen treffen.