Skip to content
advancedPhase 97 · Production-Ready

SaaS Project Management Platform

Build a multi-tenant SaaS with RBAC, API keys, usage limits, audit logging, billing integration, and tenant isolation.

6h 40m
0 problems
Topic Progress0%

Project Overview

SaaS Project Management Platform

Build a multi-tenant SaaS similar to Jira or Linear.

Multi-Tenancy

  • Multiple organizations on one deployment
  • Complete data isolation
  • Tenant-specific configurations
  • Usage limits per plan

RBAC

Role Permissions
Owner Full access, billing
Admin Manage members, projects
Member Create/edit tasks
Viewer Read-only

Architecture — What Goes Where and Why

Project Architecture

Before writing any code, let's understand what files we need and where they go. Think of this like a blueprint for a house — you don't start building without a plan.

The File Tree

Every project needs a folder structure. Here is ours:

├── server.js
├── database.js
├── middleware/tenant.js
├── routes/workspaces.js
├── routes/projects.js
├── routes/tasks.js
├── public/index.html

What Each File Does

Let me explain each file like you're 5 years old:

server.js — Express server

Multi-tenant API with workspace isolation.

database.js — PostgreSQL connection

Tables for workspaces, projects, tasks, users with tenant_id.

middleware/tenant.js — Tenant isolation

Ensures all queries are scoped to the current workspace.

routes/workspaces.js — Workspace management

Create workspaces, invite members, manage roles.

routes/projects.js — Project management

CRUD projects within a workspace.

routes/tasks.js — Task management

CRUD tasks with assignments and due dates.

public/index.html — SaaS dashboard

Workspace selector, project boards, task lists.

Why This Structure?

You might wonder: why use folders at all? Why not put everything in one place?

Because as projects grow, you might have:

  • Multiple CSS files
  • Many JavaScript files
  • Images, fonts, and other assets

If they're all in one folder, it's chaos. Folders keep things organized.

// BAD — everything in one folder
index.html
styles.css
main.css
dark.css
app.js
utils.js
helper.js

// GOOD — organized in folders
index.html
css/
  styles.css
  main.css
js/
  app.js
  utils.js

The Golden Rule

When you start a project, ALWAYS:

  1. Create the folder structure FIRST
  2. Then fill in the files one by one
  3. Never write everything in one giant file

This is how professional developers work. Always.

Step 1 — Project Setup (Creating the Empty House)

Setting Up the Project

We are going to create an empty project from scratch. This is the exact process professional developers use every single day.

Open Your Terminal

Your terminal (also called "command line" or "console") is where you type commands to talk to your computer.

  • Mac: Open "Terminal" app
  • Windows: Open "PowerShell" or "Command Prompt"
  • VS Code: Press Ctrl+` (backtick) to open the built-in terminal

Step-by-Step Commands

Type each of these commands, one at a time, pressing Enter after each:

mkdir saas-pm && cd saas-pm && git init && npm init -y && npm install express pg bcryptjs jsonwebtoken && mkdir middleware routes public public/css public/js

What Just Happened?

Let me explain each command like you're 5:

mkdir [folder] — "Make a new box." This creates a folder on your computer.

cd [folder] — "Go inside the box." Now when you type commands, they happen inside this folder.

git init — "Start keeping a diary." Git will now track every change you make. If you break something, you can go back in time.

npm init -y — "Create an ID card for this project." It creates package.json with default settings. The -y means "yes to all questions."

touch [file] — "Create an empty file." Think of it as a blank piece of paper.

Verify It Worked

Type this command to see your files:

ls -la

The .gitignore File

Open .gitignore and add this:

node_modules/
.DS_Store
*.log
.env

Why? Because node_modules can be HUGE — thousands of files. We don't want to save all of them in Git. We can always recreate them with npm install.

Your First Git Commit

Now save everything to Git:

git add .
git commit -m "Initial project setup"

Congratulations! You just set up a project like a real developer.

Step 2 — Building the Core (Step by Step)

Building the Application

Now let's build the application step by step. Follow each step in order.

Build Steps

  1. Create PostgreSQL tables with tenant_id for multi-tenancy
  2. Build tenant isolation middleware
  3. Build workspace CRUD and member management
  4. Build project management within workspaces
  5. Build task management with assignments
  6. Build frontend with workspace selector
  7. Add role-based access (admin, member, viewer)
  8. Implement invitation system
  9. Test tenant isolation (User A cannot see User B data)
  10. Commit and deploy

How Each Step Works

Step 1 — Create the entry point

Every application starts with an entry file. This is the file that runs first when someone opens your app.

Think of it like the front door of a house. Everything starts when you walk through it.

Step 2 — Set up the structure

Before writing features, we set up the basic layout. This is like putting up the walls before painting them.

Step 3 — Add the main functionality

Now we add what makes the app actually DO something. This is the "brain" of the application.

Step 4 — Connect everything

We wire the pieces together. The HTML connects to CSS. The JavaScript connects to HTML. Everything talks to each other.

Step 5 — Test and fix

We try everything, find bugs, and fix them. Real developers spend 30% of their time testing.

Save and Test

After each step, save your files and refresh the browser. If something breaks, check the browser console (F12 → Console tab).

Commit after each major step:

git add .
git commit -m "Describe what you just built"

Pro Tip

Build in small steps. Don't write 100 lines and then test. Write 10 lines, test, fix, then write 10 more. This catches errors early when they're easy to fix.

Multi-Tenancy Design

Tenant Isolation

Shared Database Strategy

// Middleware enforces tenant isolation
tenantIsolation = async (req, res, next) => {
  req.organizationId = req.user.organization;
  next();
};
app.use('/api', auth, tenantIsolation);

// Every query includes organization filter
const tasks = await Task.find({ organization: req.organizationId });

Usage Limits

async function checkLimits(orgId, resource) {
  const org = await Organization.findById(orgId);
  const limits = { free: 5, pro: 50, enterprise: Infinity };
  if (org.usage[resource] >= limits[org.plan][resource]) {
    throw new Error(\`Usage limit reached for \${resource}\`);
  }
}

API Keys and Audit Logs

API Key Management

import crypto from 'crypto';
function generateApiKey() {
  const key = \`pk_\${crypto.randomBytes(32).toString('hex')}\`;
  const hashed = crypto.createHash('sha256').update(key).digest('hex');
  return { key, prefix: key.slice(0, 11), hashed };
}

Audit Log

const auditLogSchema = new mongoose.Schema({
  organization: ObjectId, user: ObjectId, action: String,
  resource: String, resourceId: ObjectId, details: Mixed, ip: String
}, { timestamps: true });

function audit(action) {
  return async (req, res, next) => {
    const originalJson = res.json.bind(res);
    res.json = (body) => {
      AuditLog.create({ organization: req.organizationId, user: req.user._id, action, resource: req.baseUrl });
      return originalJson(body);
    };
    next();
  };
}

Common Mistakes (What Goes Wrong)

Mistakes Everyone Makes

Every developer makes these mistakes. Knowing them ahead of time saves hours of debugging.

Mistake 1: Forgetting to Connect Files

<!-- WRONG — CSS is not linked, page looks ugly -->
<link rel="stylesheet" href="style.css">

<!-- RIGHT — file path matches actual location -->
<link rel="stylesheet" href="css/styles.css">

How to check: Right-click the page → Inspect → Network tab → look for red (failed) resources.

Mistake 2: JavaScript Before HTML

<!-- WRONG — JavaScript runs before HTML exists -->
<script src="app.js"></script>
<body>...</body>

<!-- RIGHT — JavaScript runs after HTML loads -->
<body>...</body>
<script src="app.js"></script>

Mistake 3: Not Using preventDefault()

// WRONG — page reloads when you submit
form.addEventListener('submit', () => {
  // This code runs, but then the page reloads!
});

// RIGHT — preventDefault stops the reload
form.addEventListener('submit', (e) => {
  e.preventDefault(); // Now the page doesn't reload
});

Mistake 4: Modifying State Without Re-rendering

// WRONG — changes data but screen stays the same
todos.push(newTodo);

// RIGHT — always update the screen after changing data
todos.push(newTodo);
render(); // Now the screen shows the new todo

Mistake 5: Not Handling Empty Input

// WRONG — adds empty tasks
addTodo(""); // Adds a blank todo

// RIGHT — check for empty input
if (text.trim()) {
  addTodo(text);
}

Mistake 6: Ignoring Errors

How to check for errors:

  1. Press F12 in your browser
  2. Click "Console" tab
  3. Look for red text
  4. Click on it to see what went wrong

If you see red text, DON'T IGNORE IT. That's the computer telling you something is broken.

Debugging Checklist

When something doesn't work:

  1. Check the console — F12 → Console (red text = error)
  2. Check the Network — F12 → Network (red lines = failed requests)
  3. Check file paths — Are CSS/JS files in the right folder?
  4. Check spelling — Typos in IDs, class names, function names
  5. Check the basics — Is the server running? Is the URL correct?

The 5-Minute Rule

If you've been stuck for 5 minutes:

  1. Stop
  2. Re-read the error message
  3. Search the error on Google/Stack Overflow
  4. If still stuck, ask for help

Don't waste hours on something that might be a simple typo.

Testing Everything Works

Testing Your App

A real developer NEVER assumes code works. They TEST it.

Why Test?

  • Users will find every bug you missed
  • Bugs found later cost 10x more to fix
  • Testing gives you confidence to make changes

Manual Testing Checklist

Go through this checklist for EVERY feature:

□ Page loads without errors (check browser console — F12)
□ All buttons work when clicked
□ All forms submit correctly
□ Input validation works (empty, special characters)
□ Data saves and loads correctly
□ Responsive on mobile (resize browser)
□ No console errors
□ All links work
□ Loading states appear during API calls
□ Error messages show when things fail

How to Check for Errors

Press F12 in your browser. Click the "Console" tab.

  • Empty = Good! No errors.
  • Red text = Bad. Click it to see what went wrong.

Edge Cases to Test

Real users do weird things. Test these:

  1. Empty input — What happens if you submit nothing?
  2. Very long input — Paste a 1000-character string
  3. Special characters — Type < > & " ' / 4. Rapid clicking — Click a button 10 times fast
  4. No internet — Turn off WiFi and try
  5. Refresh mid-action — Reload while something is happening

Browser Testing Tools

Tool How to Open What It Shows
Console F12 → Console JavaScript errors and logs
Network F12 → Network API requests and responses
Elements F12 → Elements Live HTML and CSS
Device Mode Ctrl+Shift+M Mobile screen simulation

Git Commit

After testing, commit your work:

git add .
git commit -m "Complete [project name] with testing"

What You Just Learned

Summary — Skills You Now Have

Technical Skills

  1. Project Structure — You know how to organize files in folders
  2. Git — You can initialize, add, commit, and push
  3. Version Control — You can track changes and go back in time
  4. HTML/CSS/JavaScript — You can build interactive web pages
  5. DOM Manipulation — You can change what's on screen with code
  6. Event Handling — You can respond to clicks, inputs, and other actions
  7. State Management — You can track and update application data
  8. Debugging — You can find and fix errors using browser tools
  9. Testing — You can verify your app works correctly

Thinking Skills

  1. Architecture — You planned the project BEFORE writing code
  2. Problem Solving — You broke a big problem into small steps
  3. Debugging — You systematically found and fixed errors
  4. Documentation — You wrote notes for future you (and other developers)

The Pattern

Every frontend application follows this pattern:

State (data) → Render (draw) → Event (respond) → Update State → Render again

React, Vue, Angular, Svelte — they ALL do this. You just learned the fundamental pattern that powers the entire web.

What's Next?

Look at the next project in the roadmap. Each new project builds on what you learned here. The skills compound — every project makes you a better developer.

Remember: every expert was once a beginner who didn't give up.

Quick Reference

Quick Reference

File Overview

  • server.js: Express server
  • database.js: PostgreSQL connection
  • middleware/tenant.js: Tenant isolation
  • routes/workspaces.js: Workspace management
  • routes/projects.js: Project management
  • routes/tasks.js: Task management
  • public/index.html: SaaS dashboard

Setup Commands

mkdir saas-pm && cd saas-pm && git init && npm init -y && npm install express pg bcryptjs jsonwebtoken && mkdir middleware routes public public/css public/js

Common Patterns

// Select an element
const el = document.getElementById('myId');

// Add event listener
el.addEventListener('click', (e) => {
  e.preventDefault();
});

// Update the DOM
el.innerHTML = '<p>New content</p>';
el.textContent = 'Text only';

Debugging

F12 → Console     → Check for errors
F12 → Network     → Check API requests
F12 → Elements    → Inspect HTML/CSS
Ctrl+Shift+M      → Mobile view

Git Commands

git init                  # Start a repo
git add .                 # Stage all changes
git commit -m "message"   # Save changes
git push                  # Upload to GitHub

Quiz

1. What is multi-tenancy?

Question 1 options

Flashcards

Question

What is RBAC?

Answer

Role-Based Access Control — permissions based on roles rather than individual users

Question

What is tenant isolation?

Answer

Ensuring one customer cannot access another customer data at the query level

Revision Notes

Key Takeaways

  • 1.Multi-tenancy requires isolation at every query
  • 2.RBAC provides scalable permissions
  • 3.API keys should be hashed
  • 4.Audit logs track changes

Interview Tips

  • Explain tenant isolation strategies
  • Design RBAC system
  • Discuss API key security

Cheat Sheet

SaaS Platform

Tenant Isolation

const tasks = await Task.find({ organization: req.organizationId });

Audit Log

AuditLog.create({ organization, user, action, resource });