Case study 06 / 26
DataAttendance
Attendance, scheduling, leave and a first-class public API — a workforce platform with a business portal, kiosk mode, an offline-capable mobile app and OAuth for integrators.
- Status
- In development
- Domain
- web · cloud · security
- Source of claims
- Private repository README (reviewed). Source and deployment are not public.
The shared workforce layer for a family of business products and a standalone product in its own right: employee identity, organisation structure, attendance policies, scheduling, kiosks, leave, tasks and documents, exposed through a contract-first API with keys, OAuth 2.0, signed webhooks and a sandbox.
01/The problem
Attendance data decides pay, so it has to be trustworthy at the edges: clock-ins from phones that go offline, kiosks on a shop floor, shifts that cross daylight-saving changes — and every correction must leave a trail an auditor can verify.
02/The system
The shared workforce layer for a family of business products and a standalone product in its own right: employee identity, organisation structure, attendance policies, scheduling, kiosks, leave, tasks and documents, exposed through a contract-first API with keys, OAuth 2.0, signed webhooks and a sandbox.
03/Scope
- 01A pure attendance engine package: state machine, policies, DST-safe shift windows, and geofence, IP, Wi-Fi and device verification with offline rules.
- 02Business portal for people, attendance, policies, scheduling, kiosks, leave, tasks, documents and reports, plus a kiosk app.
- 03Employee mobile app (Expo) with an offline clock-in queue and biometric unlock.
- 04Public API with keys, OAuth 2.0, signed webhooks with retries and SSRF guards, a sandbox and a generated developer portal.
- 05Two-step verification, billing and plan limits, and an assistant bounded by the caller's permissions.
04/Engineering
Contract first
Zod schemas and an endpoint registry generate validation, routing and the OpenAPI spec, and a typed client is generated from the same contract.
A tamper-evident audit trail
Audit entries are hash-chained and the database enforces append-only tables with triggers; tests detect tampering.
05/Interface
Interface screenshots of this commercial product are not public. The visual above is an abstract representation of its modules — not the product itself.
06/Tech stack
- NestJS
- Next.js
- Expo / React Native
- TypeScript
- Prisma
- PostgreSQL 16
- Redis
- Zod
- Playwright
- OAuth 2.0 (PKCE)
07/Result
Verified outcomes
- 95 package and unit tests, 148 API integration tests against real PostgreSQL and Redis, and 17 Playwright journeys.
- Integration tests cover tenant isolation on every endpoint, IDOR, privilege escalation, concurrent clock-ins, idempotent retries and OAuth refresh reuse.
Known limitations
- Production launch gates (hosted runtime, credentials) have not been verified.
08/Links
Private commercial codebase — no public links.
Next case study
Data Accommodation →