Upay KPI Workspace
A production internal platform that turns multi-role KPI operations into one controlled, auditable workflow, from monthly target setup and submissions through review, correction, and reporting.
Engineering evidence
- My contribution
- End-to-end engineering ownership · Discovery, architecture, implementation, hardening, and rollout
- Outcome
- Deployed to production for internal KPI operations
- Decision record 01
- Kept authorisation and workflow transitions server-side, and ran PostgreSQL in CI as in production, so concurrency and integrity are tested against the real database engine.
Architecture
Described at pattern level only: the system is confidential, so no internal data, endpoints, infrastructure, or business rules are shown.
01
Web client
- Next.js + TypeScript
- Role-specific views
- Excel import preview / export
02
API
- Django REST Framework
- Per-action capability checks
- Guarded workflow transitions
03
Domain & audit
- Transactional state changes
- Append-only audit history
- Bounded file handling
04
Data & ops
- PostgreSQL (CI and production)
- Redis
- Docker, health checks, backups
Technical highlights
- 01
Modelled a multi-stage monthly operating lifecycle as guarded state transitions instead of loosely connected forms and manual handoffs.
- 02
Enforced capability-based authorisation and record-level confidentiality on the server, with regression tests for access, elevation, and cross-user data boundaries.
- 03
Built the production path around versioned containers, PostgreSQL-aligned CI, health checks, backup and rollback procedures, audit integrity, and bounded file handling.
Abstract
Upay KPI Workspace covers the complete lifecycle of KPI operations across several departments. My work spans workflow discovery, product boundaries, full-stack architecture, authorisation, transactional domain logic, testing, deployment, and operational readiness. Because the system is confidential, this case study describes only engineering patterns and outcomes; it publishes no internal data, infrastructure addresses, proprietary rules, source repository, or production access path.
Stack
- Next.js
- TypeScript
- Django REST Framework
- PostgreSQL
- Redis
- Docker