Case study 11 / 11
HR technology
DeliveredClient work · NDAHR and Payroll Platform: From Build to Secure Cloud in 11 Days
On a three-person team, I owned the cloud, deployments and payroll work for an enterprise HR and payroll platform. I set up its secure AWS environment entirely as code, automated deployments with no stored passwords, and adapted the cloud plan three times in one week, delivering a secure, cloud-hosted product in about eleven days.
Person
A change is approved
System
Automatic deployment, no stored passwords
System
Private AWS network, written as code
Output
Private database and encrypted documents
On this page
The challenge
The client wanted a modern HR and payroll platform for enterprises in its region, as an alternative to large, old-fashioned HR systems. It needed local rules built in: tracking when employee documents expire, local payroll compliance files and statutory benefit calculations, public holidays and local leave rules.
The timeline was days, not months. The client reviewed the product in rounds and needed a live, secure, cloud-hosted version to test against its own scenarios from the start.
What the team delivered
A complete HR and payroll platform: eight user roles with a permissions console, employee records and profiles, organisation design, self-service portals for employees and managers, a single approvals inbox, leave and attendance, automatically generated letters and payslips, performance reviews, payroll with a multi-step approval chain, and an AI HR assistant that answers questions in plain language within each user's permissions.
What I owned
A secure cloud environment, written as code
I designed and built the whole AWS setup using Terraform, so it can be rebuilt exactly at any time:
- a private network, with the database kept away from the public internet
- an encrypted, private store for employee documents
- all passwords and keys held in a dedicated secrets service, never in the code
- a cost-conscious setup suited to the project's stage
Automated, password-free deployments
Every change is built and deployed automatically. The deployment pipeline proves who it is to AWS without any stored passwords, needs no direct login to servers, and checks that the application is healthy before a release is marked complete.
Adapting under pressure
The cloud plan changed three times in a few days, and delivery never slipped:
- The planned cloud region wasn't available on the account, so I moved the whole setup to another region.
- A managed hosting service hit networking limits, so I switched to a simpler setup that gave more control at lower cost.
- Along the way I fixed a networking capacity issue and several configuration problems.
Payroll
I brought a payroll prototype over from a different technology into the main platform, including processing, compliance files, reconciliation, salary structures, reports and an organisation chart. Then I connected it to the real payroll engine for calculations, exceptions, approvals and payslips, replacing a large amount of placeholder logic.
Launch materials
I built automated product videos: scripts log into the live system as different users and record walkthroughs, which are then assembled into finished videos. User manuals were generated the same way for handover.
Built for trust
- Access rules are enforced on the server, not just hidden in the interface.
- Salary information is hidden by role across the whole platform, including inside the AI assistant.
- Every change is recorded in an audit log, and every input is validated.
- Passwords and keys live only in AWS's secrets service.
The results
A secure, cloud-hosted HR and payroll platform with an AI assistant, built, deployed and reviewed by the client in about eleven days. The client got infrastructure it can rebuild from code, and deployments that need no stored passwords and no server access.
Under the hoodShow technical detailsHide technical details
- Cloud: AWS VPC with public and private subnets, RDS PostgreSQL, ECR, encrypted and versioned S3, Secrets Manager, EC2 with Docker behind a Caddy reverse proxy, and Terraform state stored remotely with locking.
- Deployments: GitHub Actions authenticating to AWS through OIDC, with releases run through AWS Systems Manager and health checks before completion. Infrastructure changes are planned on review and applied on approval.
- Quality: an automated end-to-end test suite of about 75 scenarios with a fully passing run during delivery, plus 35 of 35 stress and edge-case scenarios passing, including payroll edge cases.
Related work
- CS2 Technologies productLive
GWS Connect 24: Adding AI to a Live B2B Marketplace
AI added to a live wholesale marketplace: a 24/7 AI sales agent, deals sent to the CRM in one click with their activity shown back, and AI that drafts personalised outreach for a person to approve.
B2B wholesale commerce
- CS2 Technologies productLive
NextMovePath: An AI Strategy Engine for Canadian Immigration
A live platform that turns a person's Canadian immigration profile into a personalised AI strategy report. Accurate calculations provide the facts, AI plans the strategy, and the report arrives live and as a PDF.
Immigration
- A large enterprise groupDelivered
Adaptive AI-Readiness Assessment Platform
An adaptive assessment that measures employees' AI skills, grades written answers with AI under strict safeguards, and gives everyone a personal learning path, while people review anything uncertain.
Enterprise workforce and HR · NDA