Defaults by stage

Business Bootstrap steps are not all day-one work. Use the stage that matches headcount, product mail, and compliance pressure; skip self-host chat, design hosts, and org infra until the pain is real.

GitHub org identity (profile, site, docs hub) can run in the same week as solo defaults. That is the Fast org bootstrap path (Cursor skill bootstrap-org) — not a reason to skip email/vault later.

Solo / pre-product

  • Email — Cloudflare Routing inbound; ZeptoMail or defer human SMTP; Resend when first app mail ships.

  • Vault — Bitwarden cloud (or personal Vaultwarden).

  • Design — Penpot or skip until brand work starts.

  • Scheduling — Cal.com hosted, or Cal.diy only if you already self-host.

  • Chat — Skip dedicated infra; Discord / Slack free is enough if you need a room at all. No Mattermost yet.

  • Infra — Optional personal infra; else DNS by hand until painful.

  • Funding — Skip unless you already publish libraries others depend on or you run on donations; a GitHub Sponsors profile is cheap if you do. If you do ask, put balance + floor on your own page (donation ask ideas).

  • Studio (vibe coding) — Stand up Cursor (or peer) skills / agent rules / MCP now if you ship with an AI studio. Not a BB capability area — see Vibe coding bootstrap · Bootstrap Cursor skills.

  • Forge identity — If the GitHub (or peer) org still looks vacant, run Fast org bootstrap before the deeper IT rows.

Product shipping

  • Email — Resend on updates. (or similar); Customer.io when journeys needed; ZeptoMail for human @domain.

  • Vault — Bitwarden org + CLI custom fields.

  • Design — Penpot (or Figma if partners require it).

  • Scheduling — Cal.com unless residency forces Cal.diy.

  • Chat — Hosted Slack / Mattermost Cloud / Discord. Self-host Mattermost only if residency already forces a VPS fleet.

  • Infra — Org infra Pulumi repo; encode Resend/Zepto/DMARC DNS; optional cal. / vault. / Penpot hosts. Member-only static docs: Cloudflare Access (GitHub org as IdP).

  • Funding — If you maintain public OSS, add Sponsors and/or an Open Collective before the first “how do we pay you?” email. See OSS funding landscape. Donation-supported products: show the fund on-site.

  • Studio (vibe coding) — Keep the studio durable (skills out of always-on rules; connectors for CI mail / forge). Same links as solo; wire secrets via vault + secrets distribution hub.

Small team (collaborators)

  • Email — Per-user ZeptoMail keys; never shared master SMTP; escalate DMARC after alignment.

  • Vault — Shared Bitwarden collections; no shared master passwords.

  • Design — Design library ownership documented.

  • Scheduling — Cal.com team features when round-robin / branding matter.

  • Chat — Revisit self-hosted Mattermost when seat cost or integration control hurts; use a real VPS (Hetzner/DO/Vultr-class), not shared hosting. Wire Linear via webhooks or n8n; agents via Composio + Mattermost REST/PATs. See Mattermost self-host.

  • Infra — Central infra + Antora docs; secrets in ESC/vault; optional chat. / mm. host; Access on member hostnames (invite to GitHub org — not Cloudflare dashboard users).

  • Funding — Prefer a collective / fiscal host when money must be shared or invoiced; chase grants only for public-good scoped work.

Many seats / compliance

  • Email — Consider Google Workspace for inboxes; keep Resend/CIO for product.

  • Vault — Official Bitwarden (cloud or self-host) for SSO/attestations — not Vaultwarden alone.

  • Design / scheduling — Penpot or partner-required Figma; Cal.com org features.

  • Chat — Mattermost Cloud or hardened self-host with SSO, object-storage offload (R2/B2), CDN, DB volume isolation, and restore drills.

  • Infra — Hybrid IaC; policy as code; marketing subdomain isolation mandatory.

  • Funding — Treat fiscal-host KYC, grant reporting, and trademark ownership like other vendor risk.

Summary matrix

Stage Email Vault · design · scheduling · chat Infra · funding · studio

Solo / pre-product

Routing + defer or ZeptoMail; Resend when app mail ships

Bitwarden cloud; Penpot optional; Cal.com/Cal.diy; no Mattermost

Hand DNS until painful; Sponsors only if you already publish deps; AI studio if you vibe-code

Product shipping

Resend + ZeptoMail lanes; CIO when journeys needed

Bitwarden org; Penpot/Figma; Cal.com; hosted chat

Org Pulumi infra; Sponsors / Open Collective if you maintain OSS; keep studio durable (skills / MCP)

Small team

Per-user SMTP keys; DMARC escalate

Shared vault collections; team Cal.com; Mattermost self-host when cost/residency bites

Central infra + docs; collective/fiscal host when money is shared

Many seats / compliance

Workspace inboxes + product ESPs

Official Bitwarden; Cal.com org; Mattermost Cloud or hardened self-host + object storage

Hybrid IaC; funding compliance (KYC, grant reports, trademarks)