# Structural deployment types

## Self-hosted Tonic Structural instance

You can [deploy a self-hosted, on-premises instance of Tonic Structural](https://docs.tonic.ai/app/admin/on-premise-deployment).

For a self-hosted instance, Structural provides administrator tools that allow you to [monitor Structural services](https://docs.tonic.ai/app/admin/tonic-monitoring-logging/tonic-admin-service-list) and [manage Structural users](https://docs.tonic.ai/app/admin/tonic-user-access).

You can [configure Structural environment settings](https://docs.tonic.ai/app/admin/environment-variables-setting) to customize your instance.

On a self-hosted instance, based on your [license plan](https://docs.tonic.ai/app/readme-1/tonic-license-plans), you have access to the full set of supported data connectors.

## Structural Cloud

Structural Cloud is our secure hosted environment. On Structural Cloud, Tonic.ai handles monitoring Structural services and updating Structural.

For [single sign-on (SSO)](https://docs.tonic.ai/app/admin/tonic-user-access/single-sign-on), Structural Cloud only supports Okta.

Structural Cloud does not include:

* [Custom permission sets](https://docs.tonic.ai/app/admin/tonic-user-access/permissions/custom-permission-sets-configuration)
* [Environment setting configuration](https://docs.tonic.ai/app/admin/environment-variables-setting), except for specific settings that can be set for a Cloud organization from the **Organization Settings** tab on **Structural Settings**. Other than that, Structural Cloud uses a single configuration.
* [Structural data encryption](https://docs.tonic.ai/app/generation/generators-assign-config/generators-data-encryption-config)
* Access to the following data connectors:
  * [Amazon Redshift](https://docs.tonic.ai/app/setting-up-your-database/amazon-redshift)
  * [Db2 for LUW](https://docs.tonic.ai/app/setting-up-your-database/db2-luw)
  * [Spark SDK](https://docs.tonic.ai/app/setting-up-your-database/spark-sdk)

Each Structural Cloud user belongs to a Structural Cloud organization, which is determined either by the user's email domain or by a workspace invitation. Structural Cloud users do not have any access to workspaces or users from other organizations.

Each free trial user is in a separate organization, along with any users that they invite to have access to a free trial workspace.

For information about Structural Cloud organizations, go to [structural-organizations](https://docs.tonic.ai/app/admin/tonic-user-access/structural-organizations "mention").&#x20;

The Account Admin permission set allows a Structural Cloud user to manage organization users and workspaces. For information about granting access to the Account Admin permission set, go to [granting-account-admin-access-for-a-structural-cloud-organization](https://docs.tonic.ai/app/admin/tonic-user-access/permissions/granting-account-admin-access-for-a-structural-cloud-organization "mention").
