Role-based access & auth systems
Authentication and authorisation designed as a system rather than a pile of if-statements: roles, permissions, resource ownership and tenant isolation modelled once and enforced at the data layer, so a missing UI check cannot become a data leak. Includes SSO, MFA, session policy and an audit trail.
What you get
The outcomes we hold ourselves to on this work. If we cannot commit to them for your project, we say so during scoping rather than after the invoice.
- Permissions enforced server-side, not just hidden in the UI
- Multi-tenant isolation that survives a mistyped query
- An audit log that answers 'who saw this, and when'
- SSO and MFA without a bespoke login flow per client
Deliverables
Everything on this list is handed over and documented. Anything outside it is quoted before it is built.
- Role, permission and resource-ownership model
- Server-side enforcement at the query layer
- SSO (OAuth2 / OIDC / SAML) and MFA
- Session, token and refresh policy
- Admin UI for roles and user management
- Audit logging and access reports
Typical timeline
Most engagements of this type run 2–6 weeks end to end. Step four absorbs the difference between the short and long end of that range.
Discovery call
30 minutes, freeWe walk through what you are building, who it is for, and what has to be true for the project to count as a success. You leave with a rough scope, a rough number and an honest read on whether we are the right team.
You receive: Written scope summary within 24 hours
Proposal & fixed scope
2–3 daysA written proposal: milestones, deliverables, timeline, price and explicit exclusions. No hourly surprises — you approve a scope, and changes to it are quoted before any work starts.
You receive: Proposal, contract and milestone schedule
Architecture & design
Week 1Data model, API contracts and infrastructure plan on paper before code. UI work starts in Figma so you approve screens rather than reviewing half-built pages.
You receive: Architecture doc, ER diagram, approved designs
Build in weekly sprints
Bulk of the projectWorking software every week on a staging URL you can click through. A short written update each Friday: what shipped, what is next, anything blocking. You are never guessing where the project stands.
You receive: Staging environment, weekly demo and written update
Test, harden & launch
Final 1–2 weeksAutomated tests in CI, load and failure-path testing, security review, performance budgets, then a rehearsed deploy with a rollback plan. Launch day is uneventful by design.
You receive: Test suite, CI pipeline, production deployment
Handover & support
OngoingDocumentation, a recorded walkthrough and a 30-day warranty on everything we shipped. If you want us to keep operating it, a maintenance retainer picks up from there.
You receive: Docs, walkthrough video, 30-day warranty
Questions we get asked
- Build auth or buy it?
- Buy the identity provider, build the authorisation. Password resets, MFA and SSO are solved problems not worth your money; the rules about who may see which record are specific to your product and belong in your codebase.
- Can you retrofit this onto a live product?
- Yes, and it is common. We map the current checks, model the intended permissions, then migrate route by route behind a flag so nothing breaks for existing users mid-flight.
Where this has shipped
Case studies with the numbers we measured, including the ones that did not move.

AK Car Rental
A car rental booking platform — accounts, a vehicle catalogue, and a booking form that captures type, locations and dates in a single pass.
Client projectRead case study

MHB AC Repair & Services
A service business site built around one job: turn a visitor into a booked call-out, on a phone, in under a minute.
Client projectRead case study

Fashion Storefront
A clothing storefront with category browsing, a cart that survives navigation, and a best-sellers carousel on the landing page.
Client projectRead case study
Usually paired with this
Most projects combine two or three of these. We scope them as one engagement rather than separate invoices.
End-to-end web applications
Full product builds — from empty repo to live, monitored deployment.
4–12 weeksFrom $96
Android & iOS applications
Cross-platform mobile apps that ship to both stores from one codebase.
6–16 weeksQuoted per project
RAG systems & knowledge assistants
Retrieval pipelines that answer from your data, with citations.
3–10 weeksFrom $108
Need role-based access & auth systems?
Tell us what you are working with — existing code, a blank repo, or a deadline you are worried about. This one is quoted per project: you get a written scope and a fixed number within 24 hours.
Replies within 4 business hours · No obligation · You keep the scope document