The operating picture for the Private Office.
For Principals, Private Offices, and Family Office teams who run residences, not the portfolio. Britemet Estate brings the full operating scope of a Private Office into one discreet system: residences, people, vendors, visitors and access, travel, Principal intelligence, documents and SOPs, incidents, approvals, Thread tasks, Status Net, onboarding and handover, reporting, continuity, and encrypted messaging on web, iPhone, and Android. Seventeen role types each get the view they need, and nothing they do not.
Questions? Estate FAQ · User types
Click through a sample Private Office.
Product-style walkthrough of the Estate ops console and field shell. Switch between Chief of Staff and Executive Protection to see how the same Ashford office looks for leadership vs gate and post. Sample data only, not a live client tenant. Nothing you click is saved.
One system. The right view for every seat in the Private Office.
Britemet Estate is built around seventeen distinct roles across five groups. Capabilities are enforced server-side on every request. A persona frames the console; it never grants access. Each operator sees what their role, estate scope, and clearance allow, and nothing they do not.
The people the office serves
- Principal: Full operating visibility with final-approver authority. Approvals, Principal intelligence, travel, user access, and direct secure contact, every figure scoped and attributed.
- Family Member: Read-only family visibility over residences, travel, household documents, and secure messages. No directory or governance controls.
Who runs the office day
- Family Office Director: Principal Office visibility kept current: approvals, intelligence, continuity, user access, and SME membership support.
- Chief of Staff: The operating picture: residences, open issues, Thread tasks, approvals, vendors, incidents, users and access, Principal intelligence, and secure channels (PA · EA · Chef · EP · Estates).
- Executive Assistant: Office and correspondence on the move: the Principal’s travel, visitors, documents, tasks, and day logistics.
- Personal Assistant: The day in front of the Principal: movement, visitors, preferences, soft blocks, and a direct encrypted line to the office.
Roles that see all estates by default: Principal, Family Member, Family Office Director, Executive Assistant, Chief of Staff, and Director of Security. Everyone else is limited to estates they are granted.
Residences, service, and the house day
- Estate Manager: Property workflows residence by residence: registry, visitors, vendors, staff, maintenance, and local issues.
- Director of Residences: Multi-residence coordination: notes, routines, staffing, seasonal opens, and onboarding paths across properties.
- House Manager: Daily household execution: staff roster, vendors, visitors, and the service calendar for that house.
- Executive Housekeeper: Service standards, the housekeeping team, rooms and care programs, and SOPs on the floor.
- Housekeeper: The day at the residence: expected visitors, rooms in service, and standards awaiting acknowledgment.
- Executive Chef: Menus, service windows, dietary notes, and a secure line to the office, messaging-first by design.
- Estate Staff: Assignments, expected visitors, and the standards that apply to grounds, maintenance, or similar work.
Gate, post, and scoped outsiders
- Director of Security: Risk posture across Status Net, visitors, incidents, protection, and controlled files, with risk-flag authority and quarantine release. May manage user access and legal hold.
- Executive Protection: Gate and post: verify by name and ID, check in and out, post welfare and movement on the Status Net, read the incident board and security SOPs. Approving or adding a visitor stays with management.
- Contractor: Scoped external access: your site visits, work windows, and required document acknowledgments. No office messaging or governance.
- Vendor Contact: Scoped vendor visibility: scheduled service visits and shared documentation for your firm.
Three gates. Deny-all by default.
Effective access is the intersection of role capabilities, estate scope, and clearance. Navigation and actions are driven by what the server returns, not by hardcoded role lists in the client.
What you may do
Seventeen roles map to a fixed capability set (view estates, manage visitors, decide approvals, release quarantine, post status, and more). The API enforces every capability on every request.
Where you may act
Org-wide leadership sees every residence. Estate Managers, house staff, and field roles are limited to ACTIVE estate grants. No grant means no rows. Deny-all is the safe default.
How sensitive the data is
Clearance bands (Standard → Elevated → Restricted → Principal eyes only) gate what may be decrypted inside a domain. An EP agent can verify a visitor without seeing vetting narrative or Principal intelligence.
Platform support staff are outside the tenant role model. Break-glass sessions require dual approval, time bounds, and attributed audit, never a permanent platform-admin seat inside the client database.
A controlled alternative to inboxes, spreadsheets, and memory.
Most Private Offices already run capital with discipline. The work around the Principal (residences, people, access, exceptions) often still lives in places that were never built for private operations.
Protocols live in people’s heads
Preferences, escalations, access rules, and vendor context disappear when a key operator leaves, or when someone is offline at the wrong moment.
Inboxes and spreadsheets
Email threads, shared drives, and side chats become the system of record for access, incidents, and approvals, with no clear ownership trail.
Security and continuity by memory
Visitor access, contractor activity, travel risk, and emergency procedures need structure, attribution, and continuity, not another informal channel.
Leadership sees issues late
Family Office and Principal Office leaders often learn about household issues only after they become expensive, sensitive, or political.
Approvals without provenance
Access changes, exceptions, document handling, and high-sensitivity actions need a clear decision record you can defend, not a buried reply chain.
Expertise on demand
Chiefs of Staff need trusted specialists for security, continuity, HR and legal coordination, vendor governance, and estate operations, not ad-hoc calls.
Everything a Private Office actually runs.
Web ops console for the desk; field shell on iPhone and Android. Navigation is capability-gated so a housekeeper never sees an Approvals link that would only fail, and the server still enforces regardless.
Residences and operating knowledge
- Residence registry: properties, rooms, systems, assets, vendors, schedules, and maintenance history
- Household manual: SOPs, routines, service standards, escalations, and continuity notes
- Insurance context, operating standards, property documents, and household records
- Multi-residence coordination for notes, routines, contractors, risks, and exceptions
People, vendors, and users & access
- Staff, advisors, vendors, contractors, and guests with responsibilities, training records, and emergency contacts
- Vendor history, service requirements, access notes, renewals, documents, and work status
- Users & Access for top roles (Principal, Family Office Director, Chief of Staff, Director of Security): tenant directory, MFA state, live sessions, and revoke/restore. Attributed, no hard delete.
- Role-based capabilities, estate grants, and clearance so each seat stays least-privilege
Thread: operational task and activity feed
- Push and track work across the office: open, in progress, needs review, and done
- Facets for Office, House, Security, Estates, PA, EA, Chef, EP, and general work
- Managers push and assign; operators complete their own items, hierarchy-scoped by the API.
- Distinct from Messages: Thread is the task board, not chat
Status Net: welfare, movement, sitreps
- Attributed, server-timestamped, append-only posts that replace consumer-chat “status nets”
- Static watches for hourly welfare checks. A missed check is itself the alert.
- Movement watches for departure, on location, arrival, Principal secure, holding, and route change
- One-tap posts for officers; watch owners open and stand down details. Overdue items float to the top
Visitor registration and gate workflows
- Expected visitors, hosts, purpose, and property-specific windows in one controlled flow
- Identity and vetting context encrypted at the field, with role-scoped visibility
- Approve, deny, risk-flag (Director of Security), check-in, and on-site status with attributable decisions
- Gate verification for Executive Protection: name and ID without office-wide approvals or full vetting narrative
Security, incidents, and approvals
- Executive Protection protocols, risk notes, emergency contacts, continuity plans, and response history
- Incident records with attachments, follow-up owners, after-action notes, and risk context
- Decision chains for access changes, sensitive requests, exceptions, and leadership review
- Attributed activity, approval controls, encrypted sensitive fields, and least-privilege access
Travel plans, manifests, and security advance
- Travel plans and itineraries coordinated across residences, staff, and protection
- Manifests and party context for who is moving, with appropriate role visibility
- Routes, timing, carriers, and accommodation context kept out of informal threads
- Security advance notes and operational detail for Executive Protection and trusted operators
Principal preferences and Principal intelligence
- A named module for Principal preferences, household standards, and recurring instructions
- Service expectations, travel preferences, and private operating notes under strict access
- Principal intelligence kept as governed records, not informal side channels
- Clearance-aware visibility so only authorized roles see the highest-sensitivity context
Documents, controlled files, and SOP knowledge
- Controlled document library for property, vendor, security, and household records
- SOP knowledge base with acknowledgments so procedures outlast any single operator
- File upload with malware/DLP scan, quarantine, and authenticated proxy download. No durable public links.
- Quarantine release reserved for roles with release authority (e.g. Chief of Staff, Director of Security)
Continuity, onboarding, and reporting
- Structured onboarding paths when new staff, roles, or residences come online
- Handover records so knowledge does not leave with a departing operator
- Operating picture: open incidents, pending approvals, flagged visitors, document acknowledgments
- Export-ready records and continuity controls that preserve protocols and history over time
Encrypted messaging on web, iPhone, and Android
- Secure threads for the Private Office with membership and role gates
- Department channels (Office · House · Family) and role facets (PA · EA · Chef · EP · Estates)
- Encrypted in transit and at rest; sensitive fields never stored as cleartext in the database
- Native iPhone and Android apps for coordination in the field, not only at a desk, without putting operational detail into personal SMS or consumer chat.
Subject-matter expertise on demand
- Structured access for Principal, Family Office Director, and Chief of Staff, not an anonymous ticket queue.
- Specialists in estate operations, residential security and emergency management, HR and legal coordination, and vendor governance
- Membership-style guidance during setup and steady state for the people who run the office
- Named point of contact for the Private Office when sensitive matters need careful handling
A delivery model shaped around the Private Office.
Choose the operating model, onboarding support, and specialist guidance that fit the estate’s scope and governance requirements.
From a single residence to a Principal Office.
- Residence, multi-residence estate, and Principal Office operating models
- Self-guided or white-glove onboarding, with operating-record migration
- Custom branding, private training, and custom-domain options
- Client-separated AWS or cloud environments with isolated data boundaries
Subject-matter expertise when the office needs it.
- Structured access to specialists in estate operations, residential security, and emergency management
- HR and legal coordination support for staff, vendors, and sensitive household matters
- Vendor governance, reporting, audits, and client-specific operating standards
- A named point of contact for the Private Office, not an anonymous ticket queue
- Membership-style guidance for Chiefs of Staff and estate leadership during setup and steady state
The database enforces the rules the app cannot skip.
Estate inherits the Britemet private-operations platform model: non-negotiable controls live in the data layer and infrastructure, not only in application conventions. Sensitive household and office data is treated as the design center.
Per-client environments
Each client can be provisioned with strong separation: dedicated data boundaries (including per-client databases and scoped AWS environments) so one office’s records stay apart from every other client.
Segregated runtime roles
The application connects as a least-privileged role. Privileged paths (audit writing, maintenance, export, file proxy, control-plane break-glass) are split so ordinary app credentials cannot forge dual-control evidence, self-certify a file as clean, or mark erasure complete.
Envelope encryption at the field
Highly sensitive fields are encrypted before storage with AES-256-GCM envelope keys. Ciphertext is cryptographically bound to tenant, table, row, and field so data cannot be relocated across boundaries. Search uses blind indexes where exact match is required, without storing cleartext for lookup.
Encrypted mobile messaging
Private Office threads for staff and leadership run through Estate with encryption in transit and at rest, membership controls, and mobile apps on iPhone and Android so coordination does not default to personal SMS or consumer chat.
TLS and managed keys
External traffic is HTTPS/TLS. Databases and object storage use encryption at rest with managed KMS keys, least-privilege key access, and private networking for service-to-service paths. Object buckets deny public access and unencrypted uploads.
Attributed, append-only evidence
Business mutations are force-audited into an append-only mutation log. Semantic audit events are hash-chained and tamper-evident. Completeness guards are designed so a change cannot occur without a durable record, even when a code path forgets to log something.
Break-glass and four-eyes
Privileged overrides and support break-glass sessions require dual approval, distinct actors for approve versus execute, time bounds, and single-use consumption. Approval evidence is control-plane written, not forgeable by the normal application role.
Scan, quarantine, proxy download
Files pass malware and DLP scanning before release. Infected or blocked verdicts cannot be silently downgraded. Downloads go through an authenticated proxy that re-checks grant, scan state, and quarantine at stream time, not durable public links.
Legal hold and crypto-shred
Active legal holds block mutation and deletion of covered records. Erasure uses crypto-shred of data keys, freeze after shred, and tracked purge of registered derived copies, so deletion is a controlled, auditable process rather than a soft flag alone.
History leadership can trust
Protocols, incidents, approvals, and operating records remain available to approved leadership through staff and vendor change, with tenant-consistency checks so child rows cannot cross client boundaries.
Role, estate scope, and clearance
Effective access is the intersection of role capabilities, estate scope, and clearance. A user only sees the residences and sensitivity bands they are granted, so Principal intelligence and operational detail stay in the right hands.
Immutable export for diligence
Audit export batches are designed as contiguous, self-verifying packages for long-term evidence preservation (including WORM-style object lock where configured), so leadership can prove history rather than reconstruct it from inboxes.
Language on this page describes technical controls in the platform foundation. It is not a claim about third-party audit outcomes. For diligence detail, request an Estate briefing or see the public Security overview.
The operating picture for the Private Office.
One system of record. Least privilege by design. Continuity by default. Britemet Estate is offered by arrangement, with onboarding tailored to the office.