Architecture
Two deployables and a handful of shared packages, managed with Turborepo and pnpm workspaces.
- apps/web — Next.js 16 on Vercel. Server components for the product screens, route handlers for the BFF proxy and the AI endpoints, Better Auth for sessions.
- apps/api — NestJS on Railway with a managed PostgreSQL. Every request runs as the
app_runtimedatabase role with the tenant bound through a per-request interceptor, so row-level security — not application code — is what keeps organisations apart. - packages/db — Drizzle ORM schema, migrations and the RLS policies, with isolation tests that run against a real Postgres in CI.
- packages/api, ui, eslint-config, typescript-config — shared contracts, the component library and toolchain presets.
Identity
The web app mints short-lived JWTs; the API verifies them through a JWKS endpoint and maps the subject to a database role and tenant. The UI never holds an API token — a BFF proxy forwards calls as the signed-in user. Auth events (sign-in, failures, resets) are audited at the enforcement point.
Olga
Olga is a streaming chat panel available on every dashboard screen, built on the Vercel AI SDK with Anthropic models. Her tools are read-only and scoped by the caller’s RBAC permissions, so she can answer “what slipped this week?” from scorecards, priorities and issues without seeing anything the user could not. Writes — a priority broken into tasks, an issue drafted from a conversation — are proposed, shown, and only committed after the user approves. Conversations are persisted, and a superadmin review surface shows transcripts with provenance for every tool call.
What I would do next
Phase 2 of the PRD: proactive nudges from Olga (a seat with no accountabilities, a measurable missed three weeks running), and the meeting agenda that assembles itself from the week’s data.
