
Technology
One shared backend. Every client speaks the same API.
A monorepo of typed services behind a single gateway. AI understands intent and orchestrates the platform’s own tools; suppliers sit behind ports so a mock swaps for a live integration with no change to business logic.
Versioned
typed contracts (Zod)
Scoped
per-tenant data access
Graceful
mock ↔ live adapters
Observable
health, audit, metrics
Clients
Shared services
Business modules
Data
In detail
What the diagram leaves out.
Typed contracts, versioned
Requests and responses are Zod schemas shared by the services and every client, so a breaking change fails at build time rather than in a customer’s browser. The same schema validates at the edge and documents the API.
The agent calls tools, it does not guess
The AI layer has no pricing logic of its own. It reads intent, calls the platform’s search, pricing and quotation APIs, and reports what comes back — including when the answer is nothing. No number on a quotation originates in the model.
Suppliers behind ports
Flights, hotels, maps, weather, mail and payments each sit behind an interface with a mock adapter and a live one. Turning a supplier on is a configuration change, and a supplier outage degrades one feature instead of the platform.
Security we can point at
Argon2 password hashing, short-lived access tokens with rotating refresh tokens, role- and permission-based guards on every route, rate limiting, and an audit log of administrative writes. Money is stored as integer minor units, never floats.
Per-tenant scoping
Every query that touches agency data is scoped by tenant in the service layer, and platform-level permissions are separate from an agency owner’s. Row-level security policies exist on the core identity tables, but the services do not yet connect through the restricted database role that enforces them — so we say scoped, not isolated.
Operable in production
Health endpoints on every service, structured logs, an audit trail, and analytics built from the same data the product runs on — so the numbers on a dashboard and the numbers in an invoice cannot disagree.
Where it runs
Sized for today, ready for the next step.
We would rather run a small estate well than claim a large one. The architecture is the part that scales; the hosting follows the traffic.
- Today
- Docker Compose on a single host behind Caddy, with automatic HTTPS and one service per container.
- Next
- Kubernetes manifests already in the repository, for when a single host stops being enough.
- Data
- PostgreSQL with a schema per bounded context (identity, billing, cab), and Redis for caching search results.
- Deploys
- A monorepo build with Turborepo; each service ships as its own image and can be rebuilt on its own.
