For owners

The room where the business is decided

Structa gives the owner one screen of their own: which rooms are open, who holds a key, what the papers say, what it costs. Nothing on it waits for our permission. It is also where you leave — the whole business in one file, a closure you can undo, and permanent deletion on a clock you can stop.

Owner-only. A manager who opens this address is sent back to their own workspace — there is no read-only view of it.
Self-serve

What you change without asking anybody

There is no plan call, no ticket and no account manager between you and any control below. They live on one screen, and what you save is written to your business — never queued for us to approve.

Which modules are on

18 modules, each one a switch. An employee sees a module only if your business has it on AND their role carries it — that intersection is the whole permission model. Switch one off and the database stops showing its rows, even to you; nothing is deleted, and switching it back on brings the history with it.

Who does what

You write the roles. Each is a name, a colour, a set of modules and whether it can manage. Two powers can be granted without making somebody a manager — seeing the shipment queue and claiming a shipment — so a warehouse hire need not also get the roster and the money screens. A role also sets the headline and the default tiles its people land on; anyone can then rearrange their own dashboard, and their own arrangement wins.

The name and the address

The business name your team sees, and the address they sign in at. Changing the address breaks the old link — anyone using it needs the new one — so the screen says so before you save, not after.

How the day and the money are counted

Currency, timezone, the hour the business day rolls over, a service charge and a tax rate. A venue open past midnight sets the rollover at four, and a one-thirty tab then counts toward last night in revenue, day close and history alike.

How it looks to a guest

Your logo and your brand colour, and a print-ready business-card studio. The look of the mail your AI sends is edited here too, with a live preview beside it — that one appears once the AI Receptionist is on.

AI Receptionist

The plan and the bill

Your plan, your credit balance, the packs that top it up, every invoice Structa has charged you with its PDF, and what will be charged next. The receipts come straight from Stripe, in the currency each was charged in rather than relabelled with yours.

What is wired to the outside

Shipping and marketplace connections with their last sync, the phone lines your business owns, booking reminders, review requests, online booking, client fields and consent text, the payments connection, API keys and outbound webhooks. Each appears only when its module is on.

DeliveryAI ReceptionistBookingsPayments & POSOpen API

The record of what happened

An append-only journal: what the AI assistant did, payments voided and reversed, manager-PIN attempts and which accounts are in cooldown, and the money and connection changes behind them. Read-only, for an owner or a manager, and the database enforces that too.

None of it is a support request. The one thing this screen cannot reach is somebody else’s business — every control on it is scoped to yours by the database, not by the interface.

The documents

The papers with dates on them

Licenses, permits, insurance, leases, incorporation papers, vendor contracts — the documents a business is shut down for not having, kept where they can be found instead of in somebody’s email.

01

What needs attention sits on top

Anything expiring within sixty days, or already expired, is pulled above the list and never hidden by a filter or a category. Under a fortnight it turns amber; past the date, red.

02

A new file is a new version

Upload the renewed license against the same document and it becomes version two. The old one stays readable, with its size, its type and the date it arrived.

03

Nine categories, not a folder tree

Incorporation and EIN, license or permit, insurance, lease, vendor contract, policy, tax, certificate, other. Filter by one; archived papers have their own view.

04

Nothing is deleted, only archived

There is no delete button, and no delete policy in the database for anyone to reach around it. Archiving hides a paper from the list; restoring brings it back.

05

The upload does not trust the browser

Bytes go through a server route holding the service role: a type allowlist, a size cap, an extension that has to agree with the type, and a look at the first actual bytes — so a renamed program is refused rather than stored under a lying name. PDF, PNG, JPEG, WebP, HEIC, Word, Excel, plain text and CSV, up to 4 MB.

06

Every download is written down

A download is a link good for sixty seconds, and asking for it puts a line in the journal. That is also why the files are not inside the JSON export — they come out one at a time, each one recorded.

The limits of this room

  • It is yours alone. The database already carries a managers-can-read level and the policy that enforces it; no screen turns it on, so today the vault is owner-only.
  • It does not email you. The attention list is on this screen — nothing lands in your inbox when a license is three weeks out.
  • 4 MB a file, because the platform refuses a larger request body before our code runs at all. The storage bucket is sized higher for a future upload path that skips that limit.
  • It is not a file drive. It was built for papers with deadlines, and deliberately not for payroll archives or anything medical.
Handing it over

You can give the business to somebody else

A business has exactly one owner, and ownership is a flag on a person — never a role you can hand to two. Moving it is one control in Team & roles, and it is the only path there is.

It has to be somebody who already works here

You pick from your own active employees. Not an email address, not an invitation to a stranger.

You type their name

Type-to-confirm, like every irreversible control in here. The warning names what you are giving up before you can type it.

Both rows move together

One statement in the database promotes them and demotes you, taken under a lock on your own row. There is never an instant with two owners or none, and two fast clicks cannot both pass.

You become a regular employee

Your account and your role stay. Billing, the plan, the setup screens and this control do not. Only the new owner can hand it back.

Your browser reloads into the smaller access the moment it succeeds — no open tab keeps a power the database has already taken away.

Keys

Who can sign in, and from which device

One list: every account that can reach this business. It sits beside the form that creates them, because a screen that can hire and cannot let go is half a screen — and that other half used to live in a module an owner was free to switch off.

Block a sign-in

Immediate, reversible, and says nothing about the job. It is the control for a suspension or a dispute — the door shuts now and the question of the job waits until Monday.

End an employment

Access stops at once AND a dated line is written into that person’s own employment record — which they keep, and which no employer can edit or take back. You type their full name first.

Delete the account

Offered only on an account that is already blocked, and refused outright once an employment record exists. You block first and decide about the record later.

Set a password or a PIN

The recovery path for staff who sign in with a username instead of an email address: no mail can reach them, so the owner sets it and tells them.

Revoke a badge

For a lost phone. Their QR and their Apple Wallet pass stop working at the next scan, nothing else about the account changes, and they add a new pass themselves.

Your own row has no buttons

The owner’s account cannot block or delete itself. The server refuses it, so the screen does not offer controls that would always fail.

The devices

  • A shared tablet becomes a sign-in station when you activate it. The token is minted once and dropped straight into that device; the server keeps only its hash, and the plaintext is never shown.
  • A PIN alone never signs anybody in. It works only on a device you trusted — that pairing is the whole security model of the card screen.
  • Revoke a device and its card screen dies at once, including the token on the machine you are revoking from.
  • End somebody’s employment and the devices THEY activated are listed for you, matched by id rather than by name. They are not revoked for you: the token lives on the shop’s tablet, not with the person, and the front desk should not go dark because the manager who once set it up was let go.
The door

Leaving, and every step of it is yours

You can start because you can leave. Take everything, close the business, and — if you really mean it — have it erased. None of that needs an email to support, and none of it puts you in a conversation about staying.

First: take everything

One button in Business details. It walks every table your account can read and hands you a single JSON file named for your business and today’s date. Amounts are integer cents. It works the same from the billing-locked screen and from a closed business, because losing access must never mean losing the data.

What is in the file

  • The books: the double-entry ledger, its accounts, journal entries and lines, closed-period locks, and transactions.
  • The customers: clients and the custom fields you defined, memberships and plans, loyalty, recorded consents, visit notes and gift cards.
  • The floor: bookings, services, classes and their attendees, the waitlist, orders and order items, tables, menu items and recipes, inventory with its barcodes, alias codes and every stock movement.
  • The people: profiles, roles, shifts, published schedules, time off, punches and wages.
  • The money: payments and payment events, gift-card balances, and the exceptions where a guest paid too much.
  • The record: the audit journal, what the AI did and what it spent, PIN attempts, announcements with who read them, the house rules the assistant answers from, API keys without their hashes, and every outbound webhook with the outcome of each delivery.
  • The papers: document titles, categories, issue and expiry dates, and the full version history.

What is not, and why

  • File bytes. Documents and mail attachments export as rows — name, type, size, whether we still hold it — not as files. Each one is downloaded from the vault on its own, because each download is audited.
  • Credentials, of any kind. PIN hashes, API key secrets, webhook signing secrets, shipping-account logins, push tokens, live invitations and client-portal sessions all stay in the database. A downloaded archive must never become a way in.
  • Your staff’s private conversations. Team chat, and each person’s own chats with the assistant, belong to them. The announcement board IS exported — an announcement is the business’s own record.
  • A worker’s employment history. That record is theirs and travels with them between employers; one employer’s archive must never contain their work for another.
  • The credit ledger. Your balance is on the Billing tab, but the rows behind it are service-side only — so the file names the table and says so, rather than reading a refusal as an empty list.
  • A switched-off module’s rows. The database hides them from everyone, you included. The file says so per table instead of showing an empty array — switch the module back on and export again.
  1. 01

    Close it yourself

    In Business details, type the business name. The workspace locks for you and your whole team at once, and any paid plan is cancelled at the end of the period you have already paid for — not the instant you press the button. Nothing is deleted.

  2. 02

    Change your mind

    The closed screen offers reopening first and plainest, because it is what most people who land there actually want. Everything comes back as it was, every module with it — and a plan called off inside its paid period simply carries on.

  3. 03

    Then, if you mean it, ask for deletion

    Only from that closed screen, and only after closing — the server refuses it otherwise. Scheduling the erasure of a business we are still charging would destroy the row that tells us to stop.

  4. 04

    30 days, with the date in your inbox

    Nothing is deleted when you ask. A date is written, and we email your address that date and how to call it off. On the screen the countdown moves to the top and “Keep my data” becomes the main button — with the export still offered underneath it, and a reminder to switch a module back on before you use it.

  5. 05

    Then it is destroyed by a job, with nobody in the room

    Any live subscription is cancelled first, and if the billing system cannot be reached that business is skipped rather than destroyed — we will not erase the records of somebody we might still be charging. Then one transaction over the rows, the brand files in storage, and last the sign-in accounts; a run killed halfway is picked up by the next one. That is what the 30 days are for: the moment of destruction has no human in it, so the window is the only place a mistake can still be caught.

What survives, and it is short

  • Billing and tax records we are required to keep.
  • Any correspondence you had with our support.
  • A short row recording that a business of this name existed and was erased.
  • Your address on the do-not-email list, if you asked us to stop writing to you.
  • A staff login made with a real email address stays with the person it belongs to. Logins we created for username-only staff are deleted with the business.
In writing

The same promises, in the documents

  • The Data Processing Agreement says who is who: for your clients’ and your employees’ data you are the controller and Structa is the processor. It names every subprocessor, and its deletion clause repeats the same wait this page describes.
  • The Security page describes the wall the rest of it rests on: every record belongs to exactly one business, and PostgreSQL row-level security scopes reads and writes to the signed-in person’s business — the interface is not what keeps two businesses apart.
  • Inside the product, the Console shows which version of the Terms this business accepted, on what date and by whom — with the Terms, the Privacy Policy, the DPA, the Security page and the voice terms all linked from there, in your own language where a translation exists.
The limits

What this screen will not do

A buyer who finds a limit on their own stops believing the rest of the page. So here they are, and each one is a rule in the code rather than a matter of taste.

  • One owner per business. Ownership is a flag, not a role — you cannot appoint a second owner, only transfer to one.
  • It is owner-only. A manager is sent back to their workspace; there is no read-only Console for a bookkeeper or a silent partner.
  • The document vault is owner-only too. The managers-can-read level is written in the database, and no screen switches it on yet.
  • The vault reminds you on the screen, never by email.
  • The export is a download, not a feed. There is no scheduled export and no bucket to point at; the Open API and outbound webhooks are the live path.
  • The export is all or nothing. You cannot take one module, or one date range, out of it.
  • Closing is not deleting. It ends the plan and locks the workspace; deletion is a separate request, made afterwards.
  • Deletion cannot be hurried. 30 days is the shortest it happens in, for everybody, and asking a second time moves the date in neither direction.
  • Changing your sign-in address breaks the old one. Anyone who bookmarked it needs the new link.
  • Turning a module off does not free you of what it recorded — the rows are hidden, not destroyed, until the business itself is erased.

What’s actually true today

  • The owner has one screen of their own, and a manager cannot open it.
  • Turning a module off hides its data from everyone, you included. It never deletes it.
  • An employee sees a module only if the business has it on and their role carries it.
  • You can hand the business to an employee yourself — both rows move in one statement.
  • Blocking a sign-in takes effect immediately; ending an employment writes a line in the worker’s own record that you cannot edit.
  • A trusted tablet is revoked from this screen, and its card screen stops working at once.
  • A complete export is one button, and it works from a locked screen and from a closed business.
  • Closing the business is self-serve, cancels any paid plan, deletes nothing, and can be undone.
  • Permanent deletion waits 30 days, is emailed to you with the exact date, and can be stopped from the screen showing the countdown.
  • When that date arrives the data is gone, and we cannot bring it back.
Straight answers

Questions owners ask

Do I have to call somebody to turn a module on?

No. Every module is a switch on your own screen, and the change is saved to your business the moment you press save. Nobody at Structa approves it, and there is no upgrade call.

What happens to my data if I turn a module off?

It stops being readable — the rule is in the database, so it applies to you as well as to your staff, and to an export taken while the module is off. Nothing is deleted. Turn it back on and the history is there.

Can my accountant or my partner have a look without being an owner?

Not at this screen. Give them an account with a role that carries the modules they need — Accounting and Reports for a bookkeeper — and a role that can manage also reads the journal in the workspace. But the owner’s screen has exactly one occupant.

What exactly is in the export?

One JSON file with every table your account can read: the ledger, clients and memberships, bookings and orders, inventory and its movements, staff, shifts and punches, payments, the audit journal, and your document metadata with its version history. Not in it: file bytes, any credential, your staff’s private conversations, and any module that is currently switched off.

If I close the business, do you delete my data?

No, and that split is deliberate. Closing cancels any paid plan and locks the workspace for everyone; everything stays exactly where it was, and you can reopen it. Deleting is a second, separate thing you ask for afterwards.

Can I still get my data out after I have closed?

Yes. The export button is on the closed screen, and on the billing-locked screen before it. It is offered again underneath the deletion countdown, with a reminder to switch any module back on first, because an off module’s rows will not be in the file.

What if I ask for deletion by mistake?

Nothing is deleted when you ask. We write a date 30 days out, email it to the owner’s address with the way to call it off, and put the countdown at the top of the screen with “Keep my data” as the main button. Press it and the date is cleared.

Can I take the business with me to somebody else?

You can hand it to a colleague inside Structa, and you can take a complete copy of the data out at any time, in a format anything can read. The one thing we cannot do is move your account into another company’s software for you.