Skip to content
Service

Role-based access & auth systems

Authentication and authorisation designed as a system rather than a pile of if-statements: roles, permissions, resource ownership and tenant isolation modelled once and enforced at the data layer, so a missing UI check cannot become a data leak. Includes SSO, MFA, session policy and an audit trail.

Scope this projectBook a 30-min call2–6 weeksQuoted per project

What you get

The outcomes we hold ourselves to on this work. If we cannot commit to them for your project, we say so during scoping rather than after the invoice.

  • Permissions enforced server-side, not just hidden in the UI
  • Multi-tenant isolation that survives a mistyped query
  • An audit log that answers 'who saw this, and when'
  • SSO and MFA without a bespoke login flow per client

Deliverables

Everything on this list is handed over and documented. Anything outside it is quoted before it is built.

  • Role, permission and resource-ownership model
  • Server-side enforcement at the query layer
  • SSO (OAuth2 / OIDC / SAML) and MFA
  • Session, token and refresh policy
  • Admin UI for roles and user management
  • Audit logging and access reports

Typical timeline

Most engagements of this type run 2–6 weeks end to end. Step four absorbs the difference between the short and long end of that range.

  1. Discovery call

    30 minutes, free

    We walk through what you are building, who it is for, and what has to be true for the project to count as a success. You leave with a rough scope, a rough number and an honest read on whether we are the right team.

    You receive: Written scope summary within 24 hours

  2. Proposal & fixed scope

    2–3 days

    A written proposal: milestones, deliverables, timeline, price and explicit exclusions. No hourly surprises — you approve a scope, and changes to it are quoted before any work starts.

    You receive: Proposal, contract and milestone schedule

  3. Architecture & design

    Week 1

    Data model, API contracts and infrastructure plan on paper before code. UI work starts in Figma so you approve screens rather than reviewing half-built pages.

    You receive: Architecture doc, ER diagram, approved designs

  4. Build in weekly sprints

    Bulk of the project

    Working software every week on a staging URL you can click through. A short written update each Friday: what shipped, what is next, anything blocking. You are never guessing where the project stands.

    You receive: Staging environment, weekly demo and written update

  5. Test, harden & launch

    Final 1–2 weeks

    Automated tests in CI, load and failure-path testing, security review, performance budgets, then a rehearsed deploy with a rollback plan. Launch day is uneventful by design.

    You receive: Test suite, CI pipeline, production deployment

  6. Handover & support

    Ongoing

    Documentation, a recorded walkthrough and a 30-day warranty on everything we shipped. If you want us to keep operating it, a maintenance retainer picks up from there.

    You receive: Docs, walkthrough video, 30-day warranty

Questions we get asked

Build auth or buy it?
Buy the identity provider, build the authorisation. Password resets, MFA and SSO are solved problems not worth your money; the rules about who may see which record are specific to your product and belong in your codebase.
Can you retrofit this onto a live product?
Yes, and it is common. We map the current checks, model the intended permissions, then migrate route by route behind a flag so nothing breaks for existing users mid-flight.

Need role-based access & auth systems?

Tell us what you are working with — existing code, a blank repo, or a deadline you are worried about. This one is quoted per project: you get a written scope and a fixed number within 24 hours.

Replies within 4 business hours · No obligation · You keep the scope document