Skip to content

← Back to the Labs

L3:vendor-management-portal · Software Wing · Hero

Vendor Management Portal

Purchase orders, invoices, tax checks and approvals, shipped solo in about six weeks.

Role
Sole engineer and operator: designed, directed, reviewed and shipped with AI coding agents
Period
Aug 2026 to Oct 2026

Results

  • ~6 weeks

    From first commit to a deployed portal, as the only engineer

    Repository history, 21 Aug to 4 Oct 2026

    Verified
  • 21 domains

    Backend domains, with 110 database migrations and 51 specs

    Counted from the repository; the product has no AI features

    Verified
  • 4.4 KB → 2.1 KB

    Session cookie size after fixing a production sign-in failure

    Measured during the production fix, recorded in the repository

    Verified

Problem

A business unit in the group needed a vendor portal built around purchase orders: vendor onboarding, delivery documents, invoices, verification across several tax types, and parallel accounting and tax approvals, with an SAP integration that could not take the portal down. Direction arrived weekly from the product owner, including a user-approved process revision that reshaped the workflow.

What I did

  • Wrote 51 numbered specs and delivered them spec-first: AI coding agents implemented, and I reviewed every pull request behind gated CI.
  • Modelled 21 backend domains in FastAPI and PostgreSQL with 110 Alembic migrations, then re-centred the workflow on purchase orders after a user-approved process revision.
  • Put SAP behind a provider port with retries, rate limits and a circuit breaker, so a slow ERP cannot cascade into the portal; today the port serves seeded procurement data.
  • Secured sign-in with Entra ID single sign-on plus local Argon2id accounts, with roles re-checked on every request; deployed with Bicep, VNet integration and Key Vault references.
  • Traced production failures to root cause: a build step that broke app startup, a sign-in teardown race and a session cookie too large for browsers.

Architecture

  1. HumanVendorsOnboarding, documents, invoices
  2. HumanInternal approversProcurement, accounting, tax
  3. ClientNext.js portalUI and BFF, sealed session
  4. ServiceFastAPI backend21 domains, roles checked per request
  5. DataPostgreSQLFlexible Server, 110 migrations
  6. DataBlob StorageDocuments, direct browser upload
  7. ExternalEntra IDStaff single sign-on
  8. ExternalSAP ERPProvider port, seeded data today

Data flow

  • Vendors to Next.js portal (HTTPS)
  • Internal approvers to Next.js portal (HTTPS)
  • Next.js portal to FastAPI backend (REST)
  • Next.js portal to Blob Storage (direct upload)
  • FastAPI backend to PostgreSQL (SQL)
  • FastAPI backend to Blob Storage (documents)
  • FastAPI backend to Entra ID (OIDC)
  • FastAPI backend to SAP ERP (circuit breaker)

Stack

  • Python
  • FastAPI
  • PostgreSQL
  • Alembic
  • Next.js
  • TypeScript
  • Azure App Service
  • Azure Key Vault
  • Microsoft Entra ID
  • Bicep
  • GitHub Actions
  • SAP integration

L2 · On the journeyTechnical Consultant, Software & AI · Metrodata (PT Mitra Integrasi Informatika)