More information

What it covers, and what it doesn't.

CastCrypt runs a haunt season end to end: availability, casting, the schedule, the door, and the hours everyone worked. Below is the detail, with every feature grouped by where it lands in your season, how your cast's data is kept separate and secure, and what the product runs on.

Before the doors open

Getting your people in

Roster, availability, and the audition day that fills it.

One availability submission, every department

Staff say once which nights and time windows they'll work, and rank their departments and positions. Every manager staffs from that same pool, so the moment someone is assigned they drop off everyone else's open list. You choose which availability options exist, so a haunt that treats "only free after 8" as simply unavailable can switch those off.

Roster import

Load the spreadsheet you already keep. Downloadable templates per dataset, field-by-field validation, and a dry-run preview showing exactly what will change before anything is written. Export back out the same way.

Self-signup by invite link

Send one time-limited, revocable link and let your cast create their own accounts, restricted to the departments you choose. No account admin per person.

Audition days

Events, groups, and candidates who type their own details at a lobby tablet. A scoring rubric you define, and blind scoring by default: a panellist sees the rest of the panel only once their own card is locked, so the room doesn't anchor on whoever scores first. Hire and decline decisions send templated emails.

Skills, training and approvals

Track who is approved for which position, which training is required, and who has completed it. Incomplete required training blocks an assignment before it lands.

Building the night

Casting and scheduling

The part that takes a week by hand.

Smart cast

Fills every open character across every scene in one click; auto-fill covers crew and front-of-house posts. It only considers performers approved for the part who told you they were free, and never double-books anyone.

Your regulars keep their parts

Whoever has played a character most of the season plays them again tonight. If they're unavailable the next most established performer steps in, so the show keeps its familiar faces.

It learns as the season runs

Every time you move someone out of a role, release them, or record a no-show, that pairing counts for less. Shifts worked through to the end count for more. The first pass gets closer to your own board every week you use it.

Costume and physical fitment

Mask endurance, eyewear, contacts, height range, shirt, waist and shoe sizing are checked against what the role actually requires. Someone the costume won't fit is not the answer, however reliable they are.

Conflicts caught before they happen

Double-bookings, missing approvals, minimum ages, consecutive-night limits and training gaps are blocked at the point of assignment. Anything you override is recorded with your reason, so the exception stays visible.

Seasons you can reuse

Duplicate an entire season, including shows, staffing requirements and call times, with every date shifted to a new start.

On show night

Running the door and the floor

The ten minutes before doors, and the four hours after.

Kiosk check-in

A full-screen, locked-down tablet at the door. Staff scan a per-employee QR badge with the camera, use a hardware barcode scanner, or type a code. Leaving kiosk mode needs a manager password.

Live cast board

A control-room screen showing who is on shift, where they're working, and who hasn't arrived yet.

Print-ready cast sheets

Cast, post, makeup and check-in sheets straight from the schedule, with the columns you choose.

Announcements

Broadcast to everyone or to one department, set an end date, mark what needs acknowledging, and see who has actually read it.

After the night

Hours, and what the season tells you

Numbers you can hand to a bookkeeper.

Hours worked, correct across midnight

Timed from real clock-in and clock-out stamps. Hours count towards the night the shift belonged to, not the moment the badge was scanned, so a shift that opens at 23:00 and closes at 05:00 stays on its own night and Halloween doesn't land in November. Exportable for payroll.

Attendance and reliability

Who showed, who was late, who called out and who never arrived. Reliability is calculated from that record rather than from anyone's impression.

Insights

Attendance, hours, response rates, cross-department utilisation, staffing fill against what each show actually needed, and recognition and feedback. All exportable to CSV.

Around the season

Running your workspace

Configuration that doesn't need us.

Roles and permissions you control

A capability matrix rather than fixed roles. Sensitive things like emergency contacts and restricted notes are separate permissions you grant deliberately.

Your own catalog

Departments, positions, skills, training courses, venues, seasons and shows are all yours to edit. Positions carry their own costume and physical requirements.

Costume and prop inventory

Masks, costumes, props and accessories, the condition of each, and who currently has it checked out. The assignee picker knows who it will fit.

Modules you can turn on or off

Casting, costumes, auditions, media and training can each be switched on or off to suit how your haunt runs. Anything switched off is hidden completely rather than left as a dead menu item, and you can turn it back on whenever you need it.

Employee portal

Built for a phone: shifts, call times, acknowledgments, their own hours and attendance, documents, announcements, release requests and profile.

Security & your data

You are putting your cast's details into this.

So here is exactly how they are handled. Each of these is enforced by the software itself, not left to procedure.

Your workspace is yours alone

Every client runs on their own web address with their own branding, users and data. Separation isn't a filter someone has to remember to apply. The database layer stamps and checks your workspace on every single read and write, so a missed filter cannot expose another client's information, and we run an automated check that verifies this holds.

Passwords and sign-in

Passwords are stored only as a one-way hash, so nobody at CastCrypt can read them and we cannot tell you what yours is. Sign-in uses a signed, http-only session cookie that scripts in the browser cannot read. Password reset links are single-use and time-limited, and only a hash of the link is kept, so the database never holds a working reset token.

People see only what you allow

Permissions are set per role and editable per workspace, so a department manager sees their own department and a supervisor sees show night. Emergency contacts and restricted notes are their own permissions rather than being bundled with general access.

Door tablets are contained

A check-in kiosk runs on its own device token with an expiry, separate from anybody's user account. Leaving kiosk mode requires a manager password. If a tablet goes missing you revoke that one device, with no password changes and no effect on any staff account.

Every management action is recorded

Assignments, overrides, permission changes, deletions and sign-ins are written to an audit log you can read. If someone asks why a person came off a show, the answer is in the record rather than in anyone's memory.

Where your data lives

Managed PostgreSQL on Supabase, running on AWS in Oregon (us-west-2), with the application served from the same region. All traffic is over HTTPS. CastCrypt staff accounts are a completely separate login system from your workspace accounts.

Technology

What it runs on

Nothing exotic, on purpose. Mainstream, well-supported components mean your season isn't resting on something obscure, and anyone you ask can tell you what these are.

Application
Next.js 15 and React 19, written in TypeScript
Database
PostgreSQL, managed by Supabase, accessed through Prisma
Hosting
Vercel, in the same region as the database
Email
Resend or Amazon SES for resets, invitations and shift reminders
Scheduled work
A nightly job that reminds everyone working tomorrow
Quality
526 automated tests and full type checking on every change
In development

Not built yet

A few things are still in progress. Ask where any of them stand and we'll tell you where they are.

Photo and document uploads

Cast headshots and paperwork can be recorded against a person today, but file storage itself is still being wired up. If uploads matter to you, ask, because it's close.

Text-message reminders

Email reminders are live. SMS needs carrier registration before it can be switched on.

Venue management screens

Venues are set up for you during onboarding; editing them yourself is coming.

Want to see it against your own season?

Tell us how many people you run and how your nights are shaped, and we'll walk you through it, or move a roster you already keep in a spreadsheet.