Skip to content
advancedPhase 101 · Enterprise / Senior

Multi-Tenant Enterprise SaaS

Build enterprise SaaS with advanced RBAC, custom reporting, admin controls, disaster recovery, and compliance features.

6h 40m
0 problems
Topic Progress0%

Project Overview

Multi-Tenant Enterprise SaaS

Build a production-grade enterprise SaaS with complete tenant isolation.

Requirements

  • Multiple organizations with complete data isolation
  • RBAC with custom roles
  • Audit logging for compliance
  • API key management
  • Usage limits and billing concepts
  • Admin controls and dashboards
  • Reporting and analytics
  • Search across tenant data
  • Notifications system

Add

  • Caching layer (Redis)
  • Background job processing
  • Monitoring and alerting
  • Security hardening
  • CI/CD pipeline
  • Disaster recovery planning

Architecture — What Goes Where and Why

Project Architecture

Before writing any code, let's understand what files we need and where they go. Think of this like a blueprint for a house — you don't start building without a plan.

The File Tree

Every project needs a folder structure. Here is ours:

├── server.js
├── database.js
├── middleware/tenant.js
├── middleware/rbac.js
├── middleware/audit.js
├── routes/admin.js
├── routes/projects.js
├── public/index.html

What Each File Does

Let me explain each file like you're 5 years old:

server.js — Multi-tenant Express server

Handles tenant isolation, RBAC, audit logging, and all API routes.

database.js — PostgreSQL with row-level security

Tenant isolation via database policies and connection scoping.

middleware/tenant.js — Tenant resolution

Identifies tenant from subdomain or header and scopes all queries.

middleware/rbac.js — Role-based access control

Enforces permissions: admin, manager, viewer roles.

middleware/audit.js — Audit logging

Logs every action with user, timestamp, and change details.

routes/admin.js — Admin API

Tenant management, user invites, billing, settings.

routes/projects.js — Project API

Multi-tenant project CRUD with role enforcement.

public/index.html — Enterprise dashboard

Admin panel, user management, project boards, audit log viewer.

Why This Structure?

You might wonder: why use folders at all? Why not put everything in one place?

Because as projects grow, you might have:

  • Multiple CSS files
  • Many JavaScript files
  • Images, fonts, and other assets

If they're all in one folder, it's chaos. Folders keep things organized.

// BAD — everything in one folder
index.html
styles.css
main.css
dark.css
app.js
utils.js
helper.js

// GOOD — organized in folders
index.html
css/
  styles.css
  main.css
js/
  app.js
  utils.js

The Golden Rule

When you start a project, ALWAYS:

  1. Create the folder structure FIRST
  2. Then fill in the files one by one
  3. Never write everything in one giant file

This is how professional developers work. Always.

Step 1 — Project Setup (Creating the Empty House)

Setting Up the Project

We are going to create an empty project from scratch. This is the exact process professional developers use every single day.

Open Your Terminal

Your terminal (also called "command line" or "console") is where you type commands to talk to your computer.

  • Mac: Open "Terminal" app
  • Windows: Open "PowerShell" or "Command Prompt"
  • VS Code: Press Ctrl+` (backtick) to open the built-in terminal

Step-by-Step Commands

Type each of these commands, one at a time, pressing Enter after each:

mkdir enterprise-saas && cd enterprise-saas && git init && npm init -y && npm install express pg bcryptjs jsonwebtoken && mkdir middleware routes public public/css public/js

What Just Happened?

Let me explain each command like you're 5:

mkdir [folder] — "Make a new box." This creates a folder on your computer.

cd [folder] — "Go inside the box." Now when you type commands, they happen inside this folder.

git init — "Start keeping a diary." Git will now track every change you make. If you break something, you can go back in time.

npm init -y — "Create an ID card for this project." It creates package.json with default settings. The -y means "yes to all questions."

touch [file] — "Create an empty file." Think of it as a blank piece of paper.

Verify It Worked

Type this command to see your files:

ls -la

The .gitignore File

Open .gitignore and add this:

node_modules/
.DS_Store
*.log
.env

Why? Because node_modules can be HUGE — thousands of files. We don't want to save all of them in Git. We can always recreate them with npm install.

Your First Git Commit

Now save everything to Git:

git add .
git commit -m "Initial project setup"

Congratulations! You just set up a project like a real developer.

Step 2 — Building the Core (Step by Step)

Building the Application

Now let's build the application step by step. Follow each step in order.

Build Steps

  1. Create PostgreSQL tables with tenant_id and row-level security
  2. Build tenant resolution middleware (subdomain/header)
  3. Build RBAC middleware with role hierarchy
  4. Build audit logging middleware
  5. Build admin API (tenant, user, settings management)
  6. Build project API with tenant isolation
  7. Build invitation and onboarding flow
  8. Build enterprise dashboard frontend
  9. Test tenant isolation across all endpoints
  10. Test role-based access (admin vs viewer)
  11. Test audit log completeness
  12. Document architecture and deployment guide
  13. Commit and deploy

How Each Step Works

Step 1 — Create the entry point

Every application starts with an entry file. This is the file that runs first when someone opens your app.

Think of it like the front door of a house. Everything starts when you walk through it.

Step 2 — Set up the structure

Before writing features, we set up the basic layout. This is like putting up the walls before painting them.

Step 3 — Add the main functionality

Now we add what makes the app actually DO something. This is the "brain" of the application.

Step 4 — Connect everything

We wire the pieces together. The HTML connects to CSS. The JavaScript connects to HTML. Everything talks to each other.

Step 5 — Test and fix

We try everything, find bugs, and fix them. Real developers spend 30% of their time testing.

Save and Test

After each step, save your files and refresh the browser. If something breaks, check the browser console (F12 → Console tab).

Commit after each major step:

git add .
git commit -m "Describe what you just built"

Pro Tip

Build in small steps. Don't write 100 lines and then test. Write 10 lines, test, fix, then write 10 more. This catches errors early when they're easy to fix.

Advanced RBAC

Role-Based Access Control

Permission Model

const roleSchema = new mongoose.Schema({
  organization: ObjectId,
  name: String,
  permissions: [{
    resource: String,
    actions: [String]
  }]
});

const userRoleSchema = new mongoose.Schema({
  user: ObjectId,
  organization: ObjectId,
  role: ObjectId
});

Permission Middleware

function requirePermission(resource, action) {
  return async (req, res, next) => {
    const userRole = await UserRole.findOne({
      user: req.user._id,
      organization: req.organizationId
    }).populate('role');

    const permission = userRole.role.permissions.find(p => p.resource === resource);
    if (!permission || !permission.actions.includes(action)) {
      return res.status(403).json({ error: 'Insufficient permissions' });
    }
    next();
  };
}

router.delete('/projects/:id', auth, requirePermission('projects', 'delete'), deleteProject);

Custom Roles

POST /api/roles
{
  "name": "project-manager",
  "permissions": [
    { "resource": "projects", "actions": ["read", "create", "update"] },
    { "resource": "tasks", "actions": ["read", "create", "update", "delete"] },
    { "resource": "members", "actions": ["read"] }
  ]
}

Reporting and Analytics

Analytics Dashboard

Aggregation Pipeline

router.get('/analytics/overview', auth, async (req, res) => {
  const orgId = req.organizationId;

  const [projects, tasks, members] = await Promise.all([
    Project.countDocuments({ organization: orgId }),
    Task.aggregate([
      { $match: { organization: orgId } },
      { $group: { _id: '$status', count: { $sum: 1 } } }
    ]),
    UserRole.countDocuments({ organization: orgId })
  ]);

  res.json({ projects, tasksByStatus: tasks, members });
});

router.get('/analytics/velocity', auth, async (req, res) => {
  const velocity = await Task.aggregate([
    { $match: { organization: req.organizationId, status: 'done' } },
    {
      $group: {
        _id: { $dateToString: { format: '%Y-%m-%d', date: '$completedAt' } },
        completed: { $sum: 1 }
      }
    },
    { $sort: { '_id': 1 } },
    { $limit: 30 }
  ]);
  res.json(velocity);
});

Common Mistakes (What Goes Wrong)

Mistakes Everyone Makes

Every developer makes these mistakes. Knowing them ahead of time saves hours of debugging.

Mistake 1: Forgetting to Connect Files

<!-- WRONG — CSS is not linked, page looks ugly -->
<link rel="stylesheet" href="style.css">

<!-- RIGHT — file path matches actual location -->
<link rel="stylesheet" href="css/styles.css">

How to check: Right-click the page → Inspect → Network tab → look for red (failed) resources.

Mistake 2: JavaScript Before HTML

<!-- WRONG — JavaScript runs before HTML exists -->
<script src="app.js"></script>
<body>...</body>

<!-- RIGHT — JavaScript runs after HTML loads -->
<body>...</body>
<script src="app.js"></script>

Mistake 3: Not Using preventDefault()

// WRONG — page reloads when you submit
form.addEventListener('submit', () => {
  // This code runs, but then the page reloads!
});

// RIGHT — preventDefault stops the reload
form.addEventListener('submit', (e) => {
  e.preventDefault(); // Now the page doesn't reload
});

Mistake 4: Modifying State Without Re-rendering

// WRONG — changes data but screen stays the same
todos.push(newTodo);

// RIGHT — always update the screen after changing data
todos.push(newTodo);
render(); // Now the screen shows the new todo

Mistake 5: Not Handling Empty Input

// WRONG — adds empty tasks
addTodo(""); // Adds a blank todo

// RIGHT — check for empty input
if (text.trim()) {
  addTodo(text);
}

Mistake 6: Ignoring Errors

How to check for errors:

  1. Press F12 in your browser
  2. Click "Console" tab
  3. Look for red text
  4. Click on it to see what went wrong

If you see red text, DON'T IGNORE IT. That's the computer telling you something is broken.

Debugging Checklist

When something doesn't work:

  1. Check the console — F12 → Console (red text = error)
  2. Check the Network — F12 → Network (red lines = failed requests)
  3. Check file paths — Are CSS/JS files in the right folder?
  4. Check spelling — Typos in IDs, class names, function names
  5. Check the basics — Is the server running? Is the URL correct?

The 5-Minute Rule

If you've been stuck for 5 minutes:

  1. Stop
  2. Re-read the error message
  3. Search the error on Google/Stack Overflow
  4. If still stuck, ask for help

Don't waste hours on something that might be a simple typo.

Testing Everything Works

Testing Your App

A real developer NEVER assumes code works. They TEST it.

Why Test?

  • Users will find every bug you missed
  • Bugs found later cost 10x more to fix
  • Testing gives you confidence to make changes

Manual Testing Checklist

Go through this checklist for EVERY feature:

□ Page loads without errors (check browser console — F12)
□ All buttons work when clicked
□ All forms submit correctly
□ Input validation works (empty, special characters)
□ Data saves and loads correctly
□ Responsive on mobile (resize browser)
□ No console errors
□ All links work
□ Loading states appear during API calls
□ Error messages show when things fail

How to Check for Errors

Press F12 in your browser. Click the "Console" tab.

  • Empty = Good! No errors.
  • Red text = Bad. Click it to see what went wrong.

Edge Cases to Test

Real users do weird things. Test these:

  1. Empty input — What happens if you submit nothing?
  2. Very long input — Paste a 1000-character string
  3. Special characters — Type < > & " ' / 4. Rapid clicking — Click a button 10 times fast
  4. No internet — Turn off WiFi and try
  5. Refresh mid-action — Reload while something is happening

Browser Testing Tools

Tool How to Open What It Shows
Console F12 → Console JavaScript errors and logs
Network F12 → Network API requests and responses
Elements F12 → Elements Live HTML and CSS
Device Mode Ctrl+Shift+M Mobile screen simulation

Git Commit

After testing, commit your work:

git add .
git commit -m "Complete [project name] with testing"

What You Just Learned

Summary — Skills You Now Have

Technical Skills

  1. Project Structure — You know how to organize files in folders
  2. Git — You can initialize, add, commit, and push
  3. Version Control — You can track changes and go back in time
  4. HTML/CSS/JavaScript — You can build interactive web pages
  5. DOM Manipulation — You can change what's on screen with code
  6. Event Handling — You can respond to clicks, inputs, and other actions
  7. State Management — You can track and update application data
  8. Debugging — You can find and fix errors using browser tools
  9. Testing — You can verify your app works correctly

Thinking Skills

  1. Architecture — You planned the project BEFORE writing code
  2. Problem Solving — You broke a big problem into small steps
  3. Debugging — You systematically found and fixed errors
  4. Documentation — You wrote notes for future you (and other developers)

The Pattern

Every frontend application follows this pattern:

State (data) → Render (draw) → Event (respond) → Update State → Render again

React, Vue, Angular, Svelte — they ALL do this. You just learned the fundamental pattern that powers the entire web.

What's Next?

Look at the next project in the roadmap. Each new project builds on what you learned here. The skills compound — every project makes you a better developer.

Remember: every expert was once a beginner who didn't give up.

Quick Reference

Quick Reference

File Overview

  • server.js: Multi-tenant Express server
  • database.js: PostgreSQL with row-level security
  • middleware/tenant.js: Tenant resolution
  • middleware/rbac.js: Role-based access control
  • middleware/audit.js: Audit logging
  • routes/admin.js: Admin API
  • routes/projects.js: Project API
  • public/index.html: Enterprise dashboard

Setup Commands

mkdir enterprise-saas && cd enterprise-saas && git init && npm init -y && npm install express pg bcryptjs jsonwebtoken && mkdir middleware routes public public/css public/js

Common Patterns

// Select an element
const el = document.getElementById('myId');

// Add event listener
el.addEventListener('click', (e) => {
  e.preventDefault();
});

// Update the DOM
el.innerHTML = '<p>New content</p>';
el.textContent = 'Text only';

Debugging

F12 → Console     → Check for errors
F12 → Network     → Check API requests
F12 → Elements    → Inspect HTML/CSS
Ctrl+Shift+M      → Mobile view

Git Commands

git init                  # Start a repo
git add .                 # Stage all changes
git commit -m "message"   # Save changes
git push                  # Upload to GitHub

Quiz

1. Why custom roles instead of fixed roles?

Question 1 options

Flashcards

Question

What is RBAC?

Answer

Role-Based Access Control — assigning permissions through roles rather than individual users

Question

What is disaster recovery?

Answer

Plans and procedures for restoring services after a catastrophic failure or data loss

Revision Notes

Key Takeaways

  • 1.Custom roles provide flexible permission management
  • 2.Reporting requires complex aggregation pipelines
  • 3.Enterprise SaaS needs comprehensive audit trails
  • 4.Disaster recovery planning is essential

Interview Tips

  • Design the RBAC permission model
  • Explain tenant data isolation strategies
  • Discuss disaster recovery approaches

Cheat Sheet

Enterprise SaaS

Permission Check

function requirePermission(resource, action) {
  return async (req, res, next) => {
    const role = await getUserRole(req.user, req.org);
    if (!hasPermission(role, resource, action)) return res.status(403);
    next();
  };
}