AI-First Enterprise LMSInternal Product

Akechi LMS

Akechi Lms is a multi-tenant, AI-first Enterprise Learning Management System serving schools, universities, coaching institutes, and corporate L&D under one white-labelled backend, built to scale to millions of learners across thousands of tenants.

Akechi LMS project visual

31

Backend Modules

E0–E28

Epics Shipped

60

DB Migrations

Thousands of Tenants

Target Scale

01

Business Challenge

Schools, universities, coaching institutes, and corporate L&D teams each need a full LMS — courses, assessments, live classes, grading, finance, placements, HR — but every existing option forces a choice between a rigid single-tenant product or a fragile pile of point tools stitched together per customer.

02

Akechi Approach

Built as one NestJS modular-monolith backend and one Next.js 15 frontend around a trust layer shipped first: tenant isolation, identity, deny-by-default authorization, and audit — with every one of 31 vertical-slice modules built on top of it rather than bolted alongside it.

03

Measured Outcome

Twenty-nine epics (E0–E28) have shipped against 60 Prisma migrations, with white-label branding per tenant, Postgres RLS enforcing isolation as the backstop behind every tenant-scoped query, and a Definition of Done that will not let a module ship without its permission keys, audit event, and accessibility pass.

Technical Architecture

A disciplined stack, built around the work.

The reference page feels premium because every technology has a purpose. This portfolio template does the same: grouped systems, clear roles, and compact proof.

Trust Layer Foundation

Tenancy, identity, deny-by-default authorization, and audit are built first and shared by every module, not reimplemented per feature.

Tenant-scoped queriesPermission catalogPostgres RLS backstopDomain event audit trail

Modular Monolith Backend

31 vertical-slice NestJS modules — course, assess, live, grade, finance, crm, placement, hr, ai — each owning its own controller, service, repository, and domain layer.

NestJS 11Prisma 6BullMQ jobsSocket.IO realtime

Role-Based Frontend

One Next.js 15 app renders every role's dashboard after a single login, with Zod contracts shared end-to-end between forms and the API.

Next.js 15 App RouterReact QueryZustandnext-intl

Technology Stack

NestJS 11Next.js 15Prisma 6PostgreSQL 16RedisBullMQSocket.IOZodAzure

Akechi Capabilities

What we delivered, organized like an enterprise solution.

Each capability is scoped, named, and tied to the project outcome so the page reads as proof of execution, not a loose gallery.

Multi-Tenant White-Labelling

Schools, universities, coaching institutes, and corporate L&D each get branded tenant experiences on shared infrastructure, isolated at the database and query layer.

Multi-TenantWhite-LabelPostgres RLS

Deny-by-Default Authorization

Every route carries an explicit permission key or is explicitly public; a permission catalog and route-coverage check keep the guard honest in CI.

RBACPermission CatalogCI Enforced

Full Learning Lifecycle

Courses, live classes, assessments, gradebook, attendance, certificates, finance, placements, and HR all ship as first-class modules, not add-ons.

AssessmentLive ClassesGradebookFinance

AI-First by Design

An AI module and generation-usage tracking are built into the core schema from the first migration, not retrofitted after launch.

AI GenerationsUsage MeteringSearch

Solution Proof

Problem, response, result without visual noise.

This mirrors the clarity of the reference page while keeping the Akechi data and brand voice intact.

Fragmented Point Tools

Problem

Institutes typically stitch together a course host, a video tool, a spreadsheet gradebook, and a separate CRM, with no shared identity or audit trail.

Akechi Response

Akechi Lms unifies courses, assessment, live classes, grading, finance, CRM, and placements behind one authenticated session and one permission model.

Result

31 modules share one trust layer instead of 31 separate access-control implementations.

Tenant Isolation at Scale

Problem

A single misfiltered query in a multi-tenant system can leak one institute's learner data into another's dashboard.

Akechi Response

Every tenant-owned query filters on tenantId from the authenticated context, backed by Postgres RLS as the enforced last line of defense.

Result

Tenant isolation is a database-enforced invariant, not just an application-layer convention.

Auditable by Construction

Problem

Regulators, universities, and enterprise L&D buyers all expect a real audit trail, not logs bolted on after an incident.

Akechi Response

Every mutation emits a domain event that lands in audit_logs and fans out to notifications, enforced by the module template itself.

Result

Every state change across all 31 modules is traceable from day one, not from whenever logging was added.

Delivery Framework

A controlled path from discovery to adoption.

The phase model keeps the page dense and scannable while showing clients how Akechi manages risk.

E0–E9

Trust Layer

Ship tenancy, identity, deny-by-default authorization, and the audit event pipeline every later module depends on.

E10–E18

Core Learning

Build courses, media, enrolments, batches, notifications, and the assessment and live-class engines.

E19–E24

Operations

Add gradebook weighting, attendance, finance, CRM/admissions, and placement tracking on the same trust layer.

E25–E28

Scale Features

Layer in HR, custom fields, approvals, integrity checks, and the module marketplace.

Ongoing

Deepen & Harden

Most epics have shipped; work now deepens existing modules against the tracker's honest completeness percentage rather than starting new ones.

AI & Automation Highlights

Smart systems, measured by operational impact.

This section gives the Azure-style technical confidence without changing the Akechi palette or overloading the page with decoration.

Outbox-Driven Notifications

A BullMQ worker drains the domain-event outbox into email, digests, retention jobs, and exports without blocking the request path.

1 worker, 5+ job types

Route Coverage Gate

pnpm authz:check fails CI if any controller route is missing a permission key or an explicit @Public() marker.

Zero unguarded routes

GDPR Erasure Job

Soft-deleted, user-authored content is only hard-deleted through a scheduled erasure job, never an ad hoc query.

Auditable data retention

Ready for a similar build?

Building a multi-tenant platform that needs real tenancy, not a shared schema with a WHERE clause?

Akechi Webcraft can design and build platforms where tenant isolation, authorization, and audit are load-bearing from the first migration, not retrofitted before launch.

Schedule Consultation
Let's talk

Ready to build
something great?

Share your challenge. We'll respond with a practical next step — no pitch decks, no fluff.

Start a conversation

Send us a message

Independent? Enter your own name.

Timeline (optional)

At least 20 characters — 20 to go.

We use your details only to respond to this enquiry. See our privacy policy.