Skip to content
→ All work

Case study 06 / 26

DataAttendance

Attendance, scheduling, leave and a first-class public API — a workforce platform with a business portal, kiosk mode, an offline-capable mobile app and OAuth for integrators.

Status
In development
Domain
web · cloud · security
Source of claims
Private repository README (reviewed). Source and deployment are not public.

The shared workforce layer for a family of business products and a standalone product in its own right: employee identity, organisation structure, attendance policies, scheduling, kiosks, leave, tasks and documents, exposed through a contract-first API with keys, OAuth 2.0, signed webhooks and a sandbox.

01/The problem

Attendance data decides pay, so it has to be trustworthy at the edges: clock-ins from phones that go offline, kiosks on a shop floor, shifts that cross daylight-saving changes — and every correction must leave a trail an auditor can verify.

02/The system

The shared workforce layer for a family of business products and a standalone product in its own right: employee identity, organisation structure, attendance policies, scheduling, kiosks, leave, tasks and documents, exposed through a contract-first API with keys, OAuth 2.0, signed webhooks and a sandbox.

03/Scope

  1. 01A pure attendance engine package: state machine, policies, DST-safe shift windows, and geofence, IP, Wi-Fi and device verification with offline rules.
  2. 02Business portal for people, attendance, policies, scheduling, kiosks, leave, tasks, documents and reports, plus a kiosk app.
  3. 03Employee mobile app (Expo) with an offline clock-in queue and biometric unlock.
  4. 04Public API with keys, OAuth 2.0, signed webhooks with retries and SSRF guards, a sandbox and a generated developer portal.
  5. 05Two-step verification, billing and plan limits, and an assistant bounded by the caller's permissions.

04/Engineering

Contract first

Zod schemas and an endpoint registry generate validation, routing and the OpenAPI spec, and a typed client is generated from the same contract.

A tamper-evident audit trail

Audit entries are hash-chained and the database enforces append-only tables with triggers; tests detect tampering.

05/Interface

Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.

06/Tech stack

  • NestJS
  • Next.js
  • Expo / React Native
  • TypeScript
  • Prisma
  • PostgreSQL 16
  • Redis
  • Zod
  • Playwright
  • OAuth 2.0 (PKCE)

07/Result

Verified outcomes

  • 95 package and unit tests, 148 API integration tests against real PostgreSQL and Redis, and 17 Playwright journeys.
  • Integration tests cover tenant isolation on every endpoint, IDOR, privilege escalation, concurrent clock-ins, idempotent retries and OAuth refresh reuse.

Known limitations

  • Production launch gates (hosted runtime, credentials) have not been verified.

08/Links

Private commercial codebase — no public links.

Next case study

Data Accommodation →