Built for teams
Run a studio.Operate a platform.
Every admin action is written to a log nobody can edit. Every AI job runs in its own isolated tier, so a model crash never slows down an upload. Every request traces end to end. This is the infrastructure underneath the workflow.
01
Fleet overview
The whole studio, on one screen.
Total users, new signups, pending approvals, storage used, and a live processing-health row — failed photos, failed videos, failed uploads — computed straight from the database on every request, not a stale cache. Invite-based onboarding keeps the directory clean: an invite link expires in two days, and nobody appears in the user list until they accept it.

02
Audit log
Write-once. Never edited. Never deleted.
Every administrative action — approve, suspend, delete, impersonate, force logout — is recorded with who did it, when, and from what IP address. The application itself has no path to edit or erase an entry: a tamper-evident record for teams that need to prove what happened, not just remember it.

03
Jobs & queues
AI never starves the uploads.
Every background queue — uploads, video processing, AI analysis, face matching, batch edits, depth maps — is visible live, with retry, drain and pause controls per queue. AI work runs in its own isolated tier with its own memory limit, and a load governor pauses it automatically under pressure, so a heavy AI backlog never slows down the thing that actually matters: getting a shoot into the library.

04
Observability
One trace, from upload to pixel.
Every API call and background job emits an OpenTelemetry trace and a correlated, structured log line — a single trace can span the HTTP request, the resumable upload, the AI analysis and the thumbnail generation that followed it. Prometheus metrics, a status board with infrastructure health, and single sign-on into the observability stack come standard, not bolted on for one customer.

05
Access & integrations
One identity, everywhere admin happens.
Admins sign into the platform’s own CMS with the same Hotshoe account — no second password, no separate user directory to keep in sync. SMTP, rate limits and per-user upload caps are configured from the same Integrations tab, with safe defaults and a deployment checklist that live-tests DNS, email and the streaming gateway before you rely on them.

Trust the platformthe way you trust your own server room.
Talk to us about team seats, SSO and dedicated deployments.
