What we deploy

An operating environment, not a subscription list.

Nine capabilities are in every deployment. The applications are chosen in the Blueprint. What you get at handover is one environment your team can run, with named access and a morning view of everything.

This page is what a deployment contains. How the layer works is how work moves through it: the routes, the records and who holds what.

The shape of it

Edge, managed infrastructure, applications, automation, and what the team sees.

The same architecture whether we lay it over the systems you keep or stand up a complete environment. The drawing below is the literal shape, not an illustration.

A deployed operating environment, top to bottomEdge protection at the top; ScalePass-managed infrastructure with identity, credential custody, monitoring and backups; the application layer with five always-present capabilities and six selectable components; an automation and audit layer; and at the bottom what the team sees: a morning management view, exception alerts with an owner, and approval points held by named people.EDGEEdge protection, DNS and controlled website deploymentSCALEPASS-MANAGED INFRASTRUCTUREIdentity and accessOne login, roles, least privilegeCredential custodySegregated, never in profilesMonitoring and backupsEncrypted, off-host, testedClient-isolated workspacesOwn domains, data boundariesAPPLICATIONSRecordsClients, cases, registers, queuesWorkOwners, deadlines, evidenceFilesControlled documentsChannelsTeam, alerts, escalationWikiPolicies and proceduresCHOSEN PER BLUEPRINTCRMSelectedSupportSelectedSigningSelectedFinanceSelectedCampaignsSelectedGovernanceSelectedAUTOMATION AND AUDIT TRAILSControlled workflows, signed events, scheduled reporting, exception handlingPredictable movement only. A person at every decision point.WHAT THE TEAM SEES08:30 management viewOwners, status, overdue, exceptionsAlerts with severity and ownerPrivate escalation, evidence linkApproval pointsHeld by named people, never automatedOptional: an AI operations assistant inside explicit permissions, and a managed device for the chief executive.

Always present

Nine capabilities, whatever the applications.

The standard element is the operating architecture, not a fixed bundle of tools. These nine are in every deployment, so you know what you are getting before a single application is chosen.

Identity and access
One login per person, groups and roles, and least-privilege access to every application.
Credential custody
Secrets held in a segregated store, never in documents, chats or device profiles.
Authoritative records
The structured operational core: clients, cases, work items, registers and queues, in one place.
Work and ownership
Tasks with named owners, deadlines and completion evidence, linked to the records they change.
Controlled documents
Business files held with access rules, versions and a place for evidence to live.
Communication and escalation
A team channel layer with private escalation routes and alerts that carry a severity and an owner.
Automation and audit trails
Controlled workflows between applications, signed events, scheduled reporting and exception handling.
Monitoring, backups and recovery
Monitoring, encrypted off-host backups and tested recovery, kept running as a managed layer.
Operating documentation
A team wiki holding policies, procedures and the onboarding system, written as the environment is built.

Chosen per Blueprint

The applications follow your workflows, not the other way round.

Familiar tools where they earn their place, named so you can judge them. Hosting, edge, email transport, credential custody and device management are ours to run and are described by what they do.

Selected only where your workflows need them

CRM
Twenty
Customer communications and support
Chatwoot
Agreements and signatures
Documenso
Finance operations
Invoice Ninja
Approved campaigns
Listmonk, with managed transactional-email delivery behind it
Recorded governance decisions
Loomio
AI operations assistant
An optional managed capability with explicit permission limits

The optional assistant

An AI operations assistant, inside explicit permissions.

Where a client wants it, an assistant works across the team channel, email and its own interface. Day to day it can:

  • Publish daily task and exception summaries
  • Surface deadlines, missing ownership and blockers
  • Maintain approved operational records
  • Route alerts and reminders
  • Draft internal material
  • Support controlled customer and team communications
  • Help administer approved workflows

It cannot approve customers, make regulatory judgements, sign contracts, move funds, change access arbitrarily or replace accountable humans.

In your hand

The whole environment on one managed device.

A managed device prepared with the approved applications and secure access points, so the chief executive carries the whole environment with them.

The managed deviceA handset showing a managed launcher with an approved application catalogue: Records, Work, Files, Channel, Wiki, CRM, Support, Sign, Finance. Beside it, the controls: Device-owner management with a managed launcher and an approved application catalogue; Unknown-source installation, debugging and USB file transfer blocked; Factory reset, safe boot and user modification restricted; Named user accounts with least-privilege access; Monitoring plus encrypted infrastructure backups.MANAGED LAUNCHERRecordsWorkFilesChannelWikiCRMSupportSignFinanceNothing else can be installedONE NAMED ACCOUNTManaged launcher, approved catalogue onlyUnknown installs, debugging and USB blockedReset, safe boot and user changes restrictedNamed account, least privilegeMonitored, with encrypted backupsThe controls in full, and how access is set up, are beneath.
  • Device-owner management with a managed launcher and an approved application catalogue
  • Unknown-source installation, debugging and USB file transfer blocked
  • Factory reset, safe boot and user modification restricted
  • Named user accounts with least-privilege access
  • Monitoring plus encrypted infrastructure backups

Why not just

Hire someone, buy a platform, or get an agency in?

Each is a reasonable answer to part of the problem. None of them leaves you with a documented environment your own team can run.

Three common alternatives and what each leaves undone
The alternativeWhat it gives youWhat it leaves undone
Hire an operations managerJudgement, and someone to chase.The chasing stays manual, and the knowledge leaves when they do. We build the layer they would run.
Buy one platformA good system for one job.Your other systems still do not talk to it, and the handoffs stay in inboxes. We connect the platforms you keep.
An agency or a freelancerAutomations, quickly.Rarely a record of who owns what, what was built or what happens when it fails. We document as we build and hand it over.

How the environment is built, phase by phase, is on How it works. How each layer is priced is on Pricing.

Start

Find out which of the nine you are missing.

Describe how work moves today. The free audit tells you, in writing, which capabilities are absent and which to build first.