Multi-Tenant Server-Side Governance
Tenant isolation is enforced at schema level with organizations reached through custom subdomains, and business rules run server-side only so interface manipulation cannot bypass them.

A security management platform modernization replacing a decade-old guard management monolith, orchestrating workforce readiness, real-time dispatch, verifiable patrol evidence, payroll, and client billing for security and facility operations across the USA and Canada.

The business is a US-based security services operation needing its decade-old legacy guard management software rebuilt as a unified multi-tenant SaaS platform. Built for security companies, facility services, and field operations, it orchestrates workforce readiness, real-time dispatch, incident management, payroll, and billing in one environment. In guard services the patrol log is the product: a company that cannot prove a patrol happened cannot bill for it or defend a liability claim. Ditstek replaced fragmented tooling with connected security operations on a microservices architecture scaling past one thousand sites.
The client relied on an outdated, decade-old system that caused severe performance issues, operational inefficiencies, and limited scalability, hindering their ability to support modern workflows, real-time communications, and a scalable SaaS model.
Business rules lived in database views and triggers tightly coupled to underlying tables, so the schema could not be refactored without breaking the logic entirely.
A file system holding between three and three and a half million scattered images produced storage capacity breaches, database timeouts, and repeated application crashes under normal load.
A full rewrite risks a decade of patrol logs, and those logs are the legal evidence that service was delivered, making their loss costlier than the software.
Disconnected human resources, scheduling, and payroll tools created data silos that broke the chain from workforce deployment through field execution, exception management, client reporting, and billing.
The architecture struggled under volumes reaching four thousand service calls per night, while map rendering limits capped visualization at twenty points, preventing dense officer tracking.
Labor law demanded precise tracking of regular, overtime, double time, and unpaid breaks, while GPS variability and offline conditions repeatedly broke geofencing validation and attendance records.
This security operations transformation replaced the monolith with a multi-tenant architecture enforcing tenant isolation at schema level, moved millions of legacy documents into cloud object storage, and rebuilt field operations to work offline-first.
NestJS and gRPC provide the service contracts and compile-time error checking a high-stakes security platform needs, where a failed dispatch carries consequences beyond the software.
Tenant data isolation is enforced through foreign keys and cascading deletes, so multiple organizations run on shared infrastructure via custom subdomains without separate maintained deployments.
All business rules, tenant boundaries, and role-based access controls moved strictly to the server side, blocking cross-tenant access so interface manipulation cannot bypass operational governance rules.
Over three and a half million legacy images and documents were transferred into centralized object storage, with a unified uploader and purpose-built media table replacing the file system.
Officers log incidents and capture coordinates without connectivity, with recent records cached locally and synced idempotently on reconnection so nothing duplicates when the device returns.
The engine ingests schedule data automatically, deducts unpaid breaks, calculates regular, overtime, double time, and holiday pay, and locks payroll until every single shift is verified.
This IoT-enabled operations transformation spans dispatch, verifiable patrol evidence, offline field operations, workforce scheduling, human resources, fleet management, training, client transparency, and automated payroll across a multi-tenant architecture serving many separate client organizations.
Tenant isolation is enforced at schema level with organizations reached through custom subdomains, and business rules run server-side only so interface manipulation cannot bypass them.
A centralized command center with computer-aided dispatch auto-fills details for repeat callers, supports primary and backup multi-officer assignments, and logs officers in or out remotely.
Field officers scan NFC, QR, and GPS-validated checkpoints, with duration-to-complete rules enforced, missed versus late scans tracked, and multi-photo uploads plus signature capture fully supported.
Officers work entirely without connectivity while the application caches recent records locally, then syncs idempotently on reconnection, preventing the duplicate entries that offline queues usually produce.
Boundaries are drawn as custom polygons rather than radii, giving precise location validation for clock-ins and report creation across irregularly shaped sites where circles fail.
A rules-based engine ingests schedules, deducts unpaid breaks, calculates every pay category against labor law requirements, and feeds accounting software directly with service types fully mapped.
Dynamic day, week, and month calendar views with drag-and-drop shift management and open shift bidding, detecting conflicts automatically, enforcing overtime rules, and supporting week-based repetition.
End clients receive secure read-only access to their own site data, tracking live service requests, viewing approved incident reports, downloading invoices, and monitoring patrol logs.
An integration provides prompt-based advisory support for officer reporting, suggesting incident classifications and drafting routine narratives, while the officer always retains full editorial control at all times.
The platform now holds over 2.5 million patrol log entries, which is the historical auditability the business depends on to bill clients and defend liability claims.
Total organizational overtime dropped from 6.05 percent to 2.97 percent of hours worked, because the payroll engine catches missed breaks and scheduling overlaps fragmented systems allowed.
Homepage endpoint response times fell from between 600 and 800 milliseconds down to under 300 milliseconds, with conversation page loads dropping from 60 seconds to three.
The in-house memory and job system cleared a 400-item backlog in seven hours following a concurrency increase, showing the architecture absorbs load rather than failing.
Full unit test coverage on the onboarding and reporting modules gives the platform a stable, predictable foundation for the continued development the operation depends on.
A unified multi-tenant platform scaling to over one thousand sites and four thousand officers replaced the fragmented third-party tooling that the business had previously stitched together.