Enterprise software
Systems built for scale, compliance, single sign-on, audit and long lifespans.
- Engagement
- Multi-phase programme with a named architect
- Typical timeline
- 7–8 months
- Starts with
- A workshop with the department heads and whoever signs off security.
Procurement sends a two-hundred-line security questionnaire, legal wants data residency written into the contract, and IT will not issue an account outside single sign-on. Building the software is the straightforward half; surviving the review that lets it exist is the project.
Software your procurement and security teams will approve.
What we build
Concrete artefacts, handed over and documented.
- 01
Single sign-on and directory sync against your identity provider, with group-to-role mapping documented
- 02
A permission model written as a matrix and enforced in one place, so an auditor can read it without reading code
- 03
An audit trail that cannot be edited: who saw a record, who changed it, and what the value was before
- 04
An integration contract with each surrounding system, including behaviour during their maintenance windows
- 05
Environments, release process and a rehearsed rollback path, plus the evidence pack your security review will ask for
- 06
Operating documentation and training for the team who run it once we have gone
What changes
Security and procurement review passes on first submission more often than not
Access changes when someone joins or leaves a department, without a ticket to engineering
Disputed records carry their own history, which settles most disputes in minutes
How it runs
- Weeks 1–4
01Requirements and vetoes
Interviews with the business owners, then with everyone who can stop the project: security, legal, IT and finance.
- Weeks 5–22
02Build in slices
Each slice ends as a working module in your own environment, reviewed by the department that will depend on it.
- Weeks 23–32
03Cutover
Parallel running beside the old system, staged migration, then training and a supported first month.
Chosen per project. Named here so you can see the shape of it.
- TypeScript
- Node.js
- Postgres
- Keycloak
- Docker
- Terraform
Questions we get asked
Tell us the outcome, not the tooling.
Send us the situation you are in. We will tell you which discipline it belongs to, what we would do first and what it costs, including when the answer is to wait.


