The Booth · data and access

Passports, unsigned agreements and other people's money.

That is what a management company keeps. This page says plainly where all of it sits, who can reach it, and what happens when somebody leaves.

Where the data lives

One installation, belonging to your company.

The database, the uploaded files and the log sit together in one place that is yours. There is no shared pool, no other company's records alongside yours, and nothing copied out to a third party service.

You can have that installation on hosting we run for you, on your own domain, or entirely on your own server. In every case the same rule holds: your roster is yours, and a readable export can be taken at any time.

Uploaded files are kept in a folder that is closed to the web. No document, recording or video has a web address of its own. Every file is served by a page that checks who you are, and checks the restricted tick, before it sends a single byte.

The practical implication is the ordinary one. The workspace is only as private as the device it is left signed in on. Lock your laptop.

  • One company per installationNo shared database, no cross company reporting, no pooled artist list.
  • Files behind a checkA copied file address gets a refusal, not the file.
  • Passwords stored hashedNobody, including an admin, can read yours. An admin can only replace it.
  • Every action loggedWho did it and when, readable by admins on the Today page.
  • Export whenever you askRecords and files, in a readable format, without a negotiation.
Roles

Four of them, and what each is for.

An admin sets a role and can change it at any time. Where a role cannot see something it is not shown at all, because a locked padlock still tells people something.

RoleTypicallySeesMoneyContracts and restricted files
AdminThe principal, or an operations managerEverything, plus the team page and the activity logYesYes
Artist managerThe person running the artist day to dayThe full record, key terms, versions, signatures, open points, media, documents, diary and figuresYesYes
CommercialBookings and partnershipsArtists and leads, media, documents, the diary with fees, the finance pages, send-in linksYesNo
ResearchA scout, an intern, a freelancerArtists and leads, media, documents, the diary, notes and open pointsNoNo
Restricted files

Narrowed to two roles

Marked on upload by an admin or an artist manager. The file then does not appear in anybody else's list at all, only a line saying how many documents are hidden from their role. Use it for identity documents, tax papers and anything the whole team has no reason to open.

Locking yourself out

Two protections, and one habit

Nobody can change their own role and nobody can disable their own account. Beyond that, keep two admins. One person with the only admin account and a lost password is a bad afternoon.

Signing in, and leaving

Said plainly, including the part that is missing.

Signing in

Password only, today

An admin creates an account and hands over a starting password privately. Passwords must be at least ten characters and repeated wrong attempts stop the sign in page accepting tries. There is no second factor on The Booth as it stands, so a password needs to be long and used nowhere else. Where a company needs one, it is quoted with the installation.

When somebody leaves

Disable, do not delete

The account stops working immediately and nothing that person created is lost. Their notes, uploads and open points stay where they are, still carrying their name. If they held a send-in link for an artist, replace it and the old address stops at once.

  • Archiving an artist keeps everything and hides them from the default list
  • Deleting an artist is admin only, removes every file uploaded against them, and cannot be undone
  • The scheduled task address that keeps the diary feeds current carries a key, and belongs in the server panel and nowhere else
The one open page

A send-in link is deliberately open.

The producer sending a mix at midnight should not need an account. It accepts files for exactly one artist and does nothing else. It cannot read the roster, the contracts, the figures, or anything already on that artist's record.

  • A ceiling of forty files an hour on each link
  • Replaced in one press, switched off in one press
  • Every arrival logged with the name and note the sender typed
Reading an artist's diary Where an artist runs The Desk, The Booth reads their bookings through a read only feed protected by a key set at both ends, and never writes back. An artist's diary is their business data. Reading it into your management system sits inside a normal management agreement, but the artist should be told before the first sync rather than after. We say the same to every company we install for.
Before a demonstration

Send your lawyer's questions over in writing.

We would rather answer a data processing question by mail than in a meeting, and it saves the half hour for the software.