Crew & Pay
One employment record, through the working relationship
People records, organisation, leave, payroll and statutory fields share a tenant-scoped foundation instead of becoming separate spreadsheets.
Deck · selected work
Carbon is the reference implementation for Deck and remains a client tenant, not a special branch of the product. The same tenant boundary and module contracts are built for every client that follows.
The public tenant subdomain, host-derived tenant context and row-level isolation are real. The case study explains the architecture that makes Carbon tenant one without making it the only tenant the system can serve.
Read the Carbon case studyInside Deck
These are implemented product areas in the repository today. Their boundaries are deliberate: a handled failure in one module should not cascade into another.
Crew & Pay
People records, organisation, leave, payroll and statutory fields share a tenant-scoped foundation instead of becoming separate spreadsheets.
Careers
Public roles, applications, verification, a stage board and the handoff into Crew are implemented as one route family.
Flow
Guest, reservation, feedback and sales surfaces live in a separate module boundary from employment data.
Docs & Seal
Access-checked files, recipient records and sealing keep documents in the same tenant without making them broadly visible.
Start with the work that breaks, the records it touches and the people who have to use the fix.