Skip to content
CP SHEQ Control Plane Docs

Companies and deployments

How the Control Panel's companies, roles, and deployments relate — tiers, status, custom domains, and what's structural-only versus actually enforced.

Last updated 12 September 2026 · v1

Overview

In the Control Panel, a company is the business entity being administered (for example, "Ubuntu Mining (Pty) Ltd") and a deployment is one running site under it — its own instance of the SHEQ application, with its own tier, region, and address. A company can have any number of deployments; one login can hold a role on more than one company, and the role can differ between them.

Why it matters

Two things stay deliberately separate: who can administer a company's settings and deployments in the Control Panel, and who can use the SHEQ application at a given site day-to-day. A company administrator manages deployments — creating, upgrading, deleting — but that's a Control Panel permission, not automatically a SHEQ application permission; what it does grant is a mapped role the moment they open a specific deployment through Open app (see The Control Panel).

How it works

Every company membership carries one of two roles:

  • Company administrator — can edit the company's details and logo, create and delete deployments under it, and change a deployment's tier or custom domain.
  • Company viewer — can see the company and its deployments, but every management action is blocked with a real permission error from the API, not just hidden in the interface.

A deployment has a tier (Bronze, Silver, or Gold, in that order) that caps how many employees it supports, and can be moved up or down one tier at a time. A deployment also has a status shown as a badge — active once it's up and running, or a transitional/failure state (deploying, deleting, failed) while a change is in progress or didn't complete. Deleting a deployment or a company is permanent and cannot be undone; a company can only be deleted once it has no deployments left under it.

A custom domain (in place of the standard <deployment-id>.sheqcontrolplane.com address) can be requested from Silver tier upward. Setting one goes through a real setup process on SHEQ Control Plane's side before it actually works — the Control Panel shows its progress as Pending setup, Validating certificate, Connecting, or Live, so a newly-requested domain being non-functional at first is expected, not a fault. Clearing a custom domain back to the standard address is always allowed, regardless of tier.

A deployment also carries descriptive site metadata — a location, address, description, a photo, and any custom fields an administrator wants to record. Entering an address places the site automatically on a map; this only works if the address can actually be located, in which case the map is simply not shown.

What's not built

Billing (per company vs. consolidated) is a structural choice recorded on the company today, with no invoicing or charging behind it. AD/SSO linking and scheduled backups are shown as not-yet-available in the interface rather than working features. A company's only member is whoever created it — there's no way yet to invite or remove additional people on a company, so every company today has exactly one administrator and no viewers.