Recipe Costing and Confidentiality: How Multi-Unit Groups Protect Proprietary Formulas in a Cloud System

What Keeping a Recipe Confidential in the Cloud Actually Requires
Keeping a proprietary recipe confidential in a cloud costing system comes down to controlling two things: which staff roles can open a recipe and read its exact ingredient quantities, and which outlets a recipe is visible in at all. Scope both by role and by location, and a group can cost its signature dishes for margin without ever exposing the formula across the whole business.
That distinction matters because the fear is real and specific. One multi-outlet casual dining group paused its recipe costing rollout entirely, uncomfortable entering the exact quantities behind its signature dishes into any cloud system in case the formulas leaked. Margin visibility went on hold pending a leadership decision. The recipes never moved, so the group kept costing on paper and guessing at food cost.
The mistake in that decision is treating confidentiality as all-or-nothing: either the recipe goes in the system and everyone can see it, or it stays locked in a chef's head and nobody can cost it. Recipe costing and confidentiality are not opposites. The right controls let you have both, and this guide walks through the failure modes that make groups think otherwise and the mechanisms that resolve each one.

Why "The Cloud Sees Everything" Is the Fear That Stalls Rollouts
The objection underneath most stalled rollouts is an assumption, not a fact: that putting a recipe into a shared system makes it visible to every user in the group by default. If that were true, a signature formula entered for costing would be readable by staff at outlets that never serve the dish, by managers who only need the cost number, and potentially by anyone who later leaves for a competitor. For a proprietary formula that is the whole competitive edge, that is an unacceptable trade, so the recipe stays out and the costing never happens.
The cost of that freeze is quiet but continuous. Take a single signature dish selling at $18.00 with a target food cost of 30 percent, or $5.40 a plate. Left uncosted, its real food cost drifts to 34 percent, or $6.12, without anyone seeing it. That is $0.72 of unseen drift per plate. At 90 plates a week across a 12-outlet group, one dish quietly gives back about $40,000 a year, and the group never knows because the recipe it was afraid to expose is the one it also cannot measure.

The way out is to reject the premise. Visibility in a well-designed cloud costing system is not a single group-wide switch; it is decided per user and per outlet. Once that is true, entering a recipe stops being an act of disclosure and becomes an act of measurement.
Deciding Who Can See Recipe Costs: Admin Gatekeeper or Every Chef?
The second thing that stalls groups is having no clear model for who should be allowed to see recipe costs and quantities at all. The instinct is a binary: appoint one trusted administrator as a gatekeeper who enters and guards every recipe, or train chefs directly and let them manage their own. Both extremes fail. A single gatekeeper becomes a bottleneck and a single point of failure; open access to every chef recreates the leak fear you started with.
Role-based access control replaces that binary with a matrix. Instead of one decision for the whole group, you decide separately what each role can do: who can view a recipe cost, who can see the exact ingredient quantities behind it, and who can edit the recipe. Supy exposes more than 200 customisable permissions for exactly this, so viewing a cost and reading a formula are different rights granted to different people. A branch manager can see that a dish runs at 31 percent food cost without ever seeing the quantities that make it; an executive chef can edit the formula for their own recipes; group finance can read costs across every outlet but never open a single ingredient list.

Framed this way, the "gatekeeper versus chefs" question dissolves. You are not choosing a custodian; you are assigning rights per role. The IT and data-integrity concern that granular access control is what keeps a shared system safe is answered directly, because who can create items, change settings, and view reports is each a separate, auditable permission rather than one broad login.
Scoping Recipes by Location So a Formula Never Leaves Its Kitchen
Role controls decide who can see a recipe; location scoping decides where a recipe exists at all. This is the second gate, and it is the one that most directly answers the leak fear. In Supy, recipe visibility is controlled by location: a recipe can be assigned to the specific outlets that serve it, so a proprietary formula stays visible only to the branches that need it and never appears across the group by default. Every action runs through two independent checks, a role permission and a per-location setting, so a user only reaches a recipe when both their role and their outlet clear it.
In practice that means a house sauce base developed by the central kitchen is visible only there, a signature dish is scoped to the two outlets that plate it, and a manager at a third outlet cannot see either, because the recipe simply is not part of their location. The formula never has to travel group-wide to be costed. It is entered once, scoped tightly, and measured where it lives. Because every change is captured in a tamper-proof audit log tied to a named user and timestamp, a group can also prove after the fact exactly who opened or edited a recipe, which is often what turns a nervous leadership team into a confident one.

The Margin Visibility You Lose Every Month the Recipes Stay on Paper
Once confidentiality is handled by role and location, the upside the group put on hold becomes available, and it is larger than most operators expect. A cloud-costed recipe carries a target food cost percentage with over-threshold alerts, so a dish that drifts past its 30 percent target flags itself instead of hiding in a month-end report. Costs break down by ingredient and by outlet, so the same signature dish running at 28 percent in one branch and 34 percent in another becomes a visible, fixable gap rather than a blended average that looks fine.
That is the trade the leak fear was quietly making: to protect a formula from a leak that proper access controls prevent anyway, the group gave up the branch-by-branch margin visibility that recipe costing exists to deliver. Keeping recipes on paper does not make them more confidential; it just makes them unmeasured. The confidentiality problem and the margin problem have the same solution, which is to put the recipe in a system that scopes it correctly rather than one that assumes everyone should see everything.

If your group has recipe costing on hold, run a quick self-diagnostic before your next planning cycle. First, name the specific fear: is it that a competitor could obtain the formula, or simply that too many internal users would see it? Almost always it is the second, and role plus location scoping resolves it. Second, list the roles that actually need each right separately, view cost, view quantities, and edit, rather than granting one broad login. Third, pick two or three signature recipes, scope them to only the outlets that serve them, and cost them for one month. If the food cost gap you find on even one dish is bigger than the leak risk you were protecting against, you have your leadership decision. For a deeper look at how this fits the wider costing picture, see our guide to recipe costing software and why spreadsheet recipe costing falls behind software as a group scales. You can also see how role and location controls work inside Supy recipe costing and across the platform's permissions and access controls.


.jpg)

