Multi-Tenant CRM/PSA SaaSInternal Product

AKechi CRM

AKechi CRM brings the whole customer lifecycle onto one secure, modular stack — leads, projects, billing, support, and AI. 22 independently deployable NestJS + Prisma microservices behind a single API gateway, and four Next.js frontends (portal, admin, customer, marketing) built so teams can ship customer value in minutes, not months.

AKechi CRM project visual

22

Microservices

152

Data Models

4

Frontend Apps

30+

Docs Shipped

01

Business Challenge

Most teams run across scattered CRM and PSA point tools with data split between them. The platform must feel simple to five-person startups yet safe to enterprises, and deep engineering — microservices, multi-tenancy, RBAC, audit — risks intimidating non-technical buyers if it is not backed by a genuinely deny-by-default security posture underneath.

02

Akechi Approach

Architected as 22 database-per-service microservices (152 models) behind a single API gateway, with a unified permission dialect and server-side deny-by-default authorization enforced in every service, in-cluster network policies for defense-in-depth, and a full observability stack (structured logs, Prometheus, OTel tracing) shipped before the feature work that depends on it.

03

Measured Outcome

Docs 01–30 shipped: the security gate, RBAC administration, observability, deploy pipeline, and E2E/perf baselines all closed out Phases 1–2, and Phase 6's first module-depth pass (doc 30 — Work Management Suite) is complete across all eight of its workstreams, with Phase 3 (SSO & SCIM) under way next.

Technical Architecture

A disciplined stack, built around the work.

The reference page feels premium because every technology has a purpose. This portfolio template does the same: grouped systems, clear roles, and compact proof.

CRM, Projects & Billing Together

Leads, contacts, companies, activities with a pipeline; project and work management with Kanban, WBS and time logging; billing built in with plans, subscriptions, invoices. No integrations to babysit, no data silos.

Unified CRMWork managementNative billingTime tracking

Microservices Foundation

22 independent, database-per-service microservices behind a single API gateway. Multi-tenant from day one, every query scoped by a stamped tenant header, on infra that targets Azure AKS with a documented free-tier fallback path.

Independent scalingDatabase-per-serviceTenant-scoped queriesAzure + fallback infra

Enterprise Security

Server-side deny-by-default authorization on every route, in-cluster network policies as defense-in-depth, full audit trail on every mutation, and a permission catalog so no permission string ever lives in component logic.

Deny-by-default authzNetwork policiesAudit trailPermission catalog

Technology Stack

Next.jsNestJSPrismaPostgreSQLRedisAPI GatewayRBAC & SSO/SCIMAzure AKSTerraform

Akechi Capabilities

What we delivered, organized like an enterprise solution.

Each capability is scoped, named, and tied to the project outcome so the page reads as proof of execution, not a loose gallery.

Unified Lifecycle

CRM, projects, billing, and support all in one platform, aggregated into a single cross-module approvals inbox. No integrations means no data silos and no context-switching.

Unified PlatformApprovals InboxWorkflowsCross-Module Automation

Observability & Ops

Pino structured logging, Prometheus metrics, and OTel tracing on every service and the gateway, with real health aggregation and a free-tier Grafana/Loki/Jaeger stack for local and fallback environments.

PrometheusOTel TracingStructured LogsHealth Aggregation

Accessible by Default

CI-gated Storybook axe scans, real WCAG contrast checks, and keyboard/touch-accessible drag-and-drop everywhere native HTML5 DnD used to be the only path.

A11y CIKeyboard DnDContrast GatePlaywright E2E

Solution Proof

Problem, response, result without visual noise.

This mirrors the clarity of the reference page while keeping the Akechi data and brand voice intact.

Platform Cohesion

Problem

Replacing five tools without building a tangled monolith risks the all-in-one trap.

Akechi Response

22 microservices each own their own database and deploy independently behind one gateway, communicating through contract events.

Result

One seamless product for users. Independence and resilience for engineering.

Enterprise Trust

Problem

Shared SaaS platforms must guarantee data isolation, granular access control, and complete accountability.

Akechi Response

Deny-by-default authorization, tenant-scoped queries, and an audit trail on every mutation were built as Phase 1 of the roadmap, not retrofitted later.

Result

Every one of the 22 services enforces the same permission dialect server-side.

Depth Over Breadth

Problem

Shipping 30 breadth documents can still leave individual modules shallow if depth work never gets scheduled.

Akechi Response

A binding numbered-document workflow requires 100% completion — acceptance criteria and testing checklist — before the next document opens, with a dedicated module-depth phase after breadth closes.

Result

Work Management Suite (doc 30) shipped complete across all eight of its workstreams as the first depth pass.

Delivery Framework

A controlled path from discovery to adoption.

The phase model keeps the page dense and scannable while showing clients how Akechi manages risk.

Phase 01

Security Gate

Unify the permission dialect, ship the authz guard package, and enforce server-side deny-by-default authorization across all 22 services.

Phase 02

Platform Hardening

Add RBAC administration, tenant security policies, full observability, CI/CD with automatic rollback, and an E2E + load-test baseline.

Phase 03

Identity & Access

Layer in SSO and SCIM provisioning on top of the hardened authorization core.

Phase 06

Module Depth

Revisit shipped modules one at a time for real depth — Work Management Suite first, complete across all eight workstreams.

AI & Automation Highlights

Smart systems, measured by operational impact.

This section gives the Azure-style technical confidence without changing the Akechi palette or overloading the page with decoration.

Route Coverage Gate

CI fails if any controller route is missing a permission key or an explicit @Public() marker.

Zero unguarded routes

Cross-Module Approvals Inbox

Timesheets, deal governance, WBS plans and project requests aggregate into one inbox with optimistic approve/reject.

4 modules, 1 inbox

Automatic Rollback Pipeline

Build-once deploys move through staging smoke tests to a manual-approval production gate, rolling back automatically on smoke failure.

Zero manual rollback steps

Ready for a similar build?

Want to Launch a SaaS Platform of Your Own?

If you have a product vision that needs serious engineering and a website that can sell it, Akechi Webcraft can design and build both — quickly, and the right way.

Schedule Consultation
Let's talk

Ready to build
something great?

Share your challenge. We'll respond with a practical next step — no pitch decks, no fluff.

Start a conversation

Send us a message

Independent? Enter your own name.

Timeline (optional)

At least 20 characters — 20 to go.

We use your details only to respond to this enquiry. See our privacy policy.