A deployment, described
Foundations in place, no infrastructure. From registration to a working environment.
A regulated financial-services company with a small founding team, preparing for controlled regulated operations. They had the concept, identity, domain, email and registration. They had no environment in which to run the work with owners, evidence and approvals.
A real deployment, described with the client's permission and anonymised. Details that could identify the client are withheld by agreement.
Where they started
Foundations in place. No operating infrastructure.
A question like "who owns this case" or "where is the evidence" had nowhere to be answered, because nothing held ownership, customer operations, evidence, approvals or reporting in one place.
- Ownership
- Work spread across conversations, documents and manual handoffs, with no unified record of who owned what.
- Customer operations
- No shared system for onboarding cases, trades, settlement or reconciliation.
- Evidence and approvals
- No place for compliance evidence to live and no recorded approval route.
- Reporting
- No management view that did not have to be assembled by hand.
How it ran
Audit, Blueprint, deployment, handover.
The four phases every engagement runs, applied to a team with nothing yet in place.
Audit
Read how the work would move once operations began, and where it would stall.
Blueprint
Decided what would be configured, what would have to be built, and who would hold which authority.
Deployment
Stood up the environment, configured the applications, built the operating layer between them, and tested it with synthetic cases and recovery drills.
Handover
Named access, written procedures, a governance model and a managed device, with the team running the day from the team channel.
What every deployment carries
Nine capabilities, and what each was here.
The same nine as on What we deploy. The applications were chosen in the Blueprint; the capabilities were not optional.
- Identity and access
- One login per person, with roles across every application.
- Credential custody
- Secrets in a segregated store, never in documents, chats or the device.
- Authoritative records
- Baserow: clients, onboarding cases, trades, settlement, reconciliation, compliance queues, personnel, governance.
- Work and ownership
- OpenProject: owners, deadlines and completion evidence, linked to the records.
- Controlled documents
- Nextcloud: access rules, versions and a place for evidence to live.
- Communication and escalation
- Mattermost: private escalation channels and alerts with a severity and an owner.
- Automation and audit trails
- n8n: workflows between the applications, signed events, scheduled reports, exception handling.
- Monitoring, backups and recovery
- Monitoring, encrypted off-host backups and tested recovery, run as a managed layer.
- Operating documentation
- Outline: policies, procedures and the onboarding system, written as the environment was built.
Chosen in the Blueprint for this team: CRM, support, signatures, finance, campaigns, recorded governance decisions and the assistant.

What could not be bought
The applications could be bought. The operating layer between them could not. That layer is what ScalePass built.
- The registers: which fields, which states, who owns each record and what counts as done.
- The routes between applications: what moves, when, with a signed event at each step and a person at every decision point.
- The daily view and the exception report, so the day starts from the record rather than from inboxes.
- The approval controls: who may authorise what, with a second person wherever a decision needs one.
- The manuals, the governance model, the onboarding system, the assistant's permissions and the managed device.

A Monday morning
Everyone opens the team channel first.
Two reports a day, one at the start and one on what is still unresolved. In between, the team works from the task board and escalates through private channels.

- 08:30
- The management view arrives in the team channel, linked to the task board: owners, status, due dates, overdue items and exceptions.
- Chief executive
- Reads approvals, exceptions and finance oversight from the view, and decides.
- Systems owner
- Watches infrastructure, access and automation health.
- Commercial lead
- Works the pipeline, proposals, campaigns and agreements.
- Customer-success lead
- Works the support inbox and onboarding coordination.
- The assistant
- Reports, reminds and routes, inside its permissions.
- 16:30
- A second report, on what is still unresolved rather than on activity.
The chief executive reads the day rather than assembling it. Nobody asks who owns a case, because the record says.
At handover
Handed over as a working environment, not a set of subscriptions.
Built so a small founding team can run on named owners, checks and evidence rather than memory, while accountability and sensitive decisions stay with people.
- Named access and defined responsibilities
- Written procedures and a governance model
- Approval boundaries, with a second person wherever a decision needs one
- Private escalation channels and two daily views
- A managed device for the chief executive
Start
Describe where your business stands today.
Foundations and no infrastructure, or systems and no flow between them. The free audit reads the picture and tells you which it is and what to build first.