Skip to content
All work

Case study 11 / 11

HR technology

DeliveredClient work · NDA

HR and Payroll Platform: From Build to Secure Cloud in 11 Days

On a three-person team, I owned the cloud, deployments and payroll work for an enterprise HR and payroll platform. I set up its secure AWS environment entirely as code, automated deployments with no stored passwords, and adapted the cloud plan three times in one week, delivering a secure, cloud-hosted product in about eleven days.

  1. Person

    A change is approved

  2. System

    Automatic deployment, no stored passwords

  3. System

    Private AWS network, written as code

  4. Output

    Private database and encrypted documents

Salary data is hidden by role everywhere, including inside the AI assistant.

The challenge

The client wanted a modern HR and payroll platform for enterprises in its region, as an alternative to large, old-fashioned HR systems. It needed local rules built in: tracking when employee documents expire, local payroll compliance files and statutory benefit calculations, public holidays and local leave rules.

The timeline was days, not months. The client reviewed the product in rounds and needed a live, secure, cloud-hosted version to test against its own scenarios from the start.

What the team delivered

A complete HR and payroll platform: eight user roles with a permissions console, employee records and profiles, organisation design, self-service portals for employees and managers, a single approvals inbox, leave and attendance, automatically generated letters and payslips, performance reviews, payroll with a multi-step approval chain, and an AI HR assistant that answers questions in plain language within each user's permissions.

What I owned

A secure cloud environment, written as code

I designed and built the whole AWS setup using Terraform, so it can be rebuilt exactly at any time:

  • a private network, with the database kept away from the public internet
  • an encrypted, private store for employee documents
  • all passwords and keys held in a dedicated secrets service, never in the code
  • a cost-conscious setup suited to the project's stage

Automated, password-free deployments

Every change is built and deployed automatically. The deployment pipeline proves who it is to AWS without any stored passwords, needs no direct login to servers, and checks that the application is healthy before a release is marked complete.

Adapting under pressure

The cloud plan changed three times in a few days, and delivery never slipped:

  1. The planned cloud region wasn't available on the account, so I moved the whole setup to another region.
  2. A managed hosting service hit networking limits, so I switched to a simpler setup that gave more control at lower cost.
  3. Along the way I fixed a networking capacity issue and several configuration problems.

Payroll

I brought a payroll prototype over from a different technology into the main platform, including processing, compliance files, reconciliation, salary structures, reports and an organisation chart. Then I connected it to the real payroll engine for calculations, exceptions, approvals and payslips, replacing a large amount of placeholder logic.

Launch materials

I built automated product videos: scripts log into the live system as different users and record walkthroughs, which are then assembled into finished videos. User manuals were generated the same way for handover.

Built for trust

  • Access rules are enforced on the server, not just hidden in the interface.
  • Salary information is hidden by role across the whole platform, including inside the AI assistant.
  • Every change is recorded in an audit log, and every input is validated.
  • Passwords and keys live only in AWS's secrets service.

The results

A secure, cloud-hosted HR and payroll platform with an AI assistant, built, deployed and reviewed by the client in about eleven days. The client got infrastructure it can rebuild from code, and deployments that need no stored passwords and no server access.

Under the hoodShow technical details
  • Cloud: AWS VPC with public and private subnets, RDS PostgreSQL, ECR, encrypted and versioned S3, Secrets Manager, EC2 with Docker behind a Caddy reverse proxy, and Terraform state stored remotely with locking.
  • Deployments: GitHub Actions authenticating to AWS through OIDC, with releases run through AWS Systems Manager and health checks before completion. Infrastructure changes are planned on review and applied on approval.
  • Quality: an automated end-to-end test suite of about 75 scenarios with a fully passing run during delivery, plus 35 of 35 stress and edge-case scenarios passing, including payroll edge cases.