A multi-tenant ledger and automated WhatsApp invoicing platform.

Scaled a single-depot invoicing bot into a secure multi-tenant SaaS. Features a Next.js 16 daybook dashboard, an Express + Baileys WhatsApp worker, and an isolated /platform operator plane on a single VPS.

Role
Sole engineer — architecture to launch
Client
Small businesses & retail depots
Timeline
August 2026 – September 2026
Stack
Next.js 16 Dashboard, WhatsApp Worker, Shared Packages, Infrastructure
Deliverables
Next.js 16 dashboard, WhatsApp worker, Platform console, REST/Webhook API
  • Automated
    WhatsApp Invoicing
  • 100%
    Data Isolation
  • 1 VPS
    multi-tenant architecture serving several shops on a single deployment

The problem

Small retail businesses in Pakistan rely on fragmented tools—manual khata books, spreadsheets, and manual WhatsApp messaging—leading to reconciliation discrepancies and untracked receivables.

The original system solved this for a single depot, but onboarding additional shops by spinning up independent servers and databases was unsustainable. However, moving to a shared database introduced a dangerous operational edge: a forgotten query filter could leak sensitive financial records between competing businesses, and customer support required sharing shop passwords.

Approach

I re-architected the system into an npm-workspaces monorepo running containerized services under Docker Compose on a single VPS:

  • Strict Data Isolation: Every tenant-scoped function in packages/domain enforces tenantId as its first positional parameter and throws if it is missing. All database collections use compound indexes prefixed with tenantId (tenantId_1_normalizedName_1, tenantId_1_invoiceNo_1).
  • Mathematical Ledger Integrity: Financial entries live in a single transactions collection using signed numbers (invoices positive, payments negative). Balances are computed via $sum, making history discrepancies impossible. Invoice numbers are minted atomically inside MongoDB replica-set transactions.
  • Platform Plane & Support Sessions: Built an isolated /platform control plane for tenant provisioning, seat capping, and maintenance. Operators debug tenant issues via time-boxed (1-hour) HMAC-SHA256 signed return tickets that mint temporary shop admin sessions, logging every mutation to an immutable audit trail.
  • Resilient WhatsApp Dispatch: An Express + Baileys worker maintains a persistent WhatsApp WebSocket. Invoices are committed as PENDING_DISPATCH before triggering an async ping, after which the worker claims rows via distributed leases with exponential backoff (1–30 mins).

Architecture

Next.js 16 Dashboard — Handles daybook entries, client/supplier ledgers, Auth.js v5 credentials auth, and the /platform console.
WhatsApp Worker Express + Baileys service maintaining a persistent WhatsApp WebSocket for read-only ledger queries and PDF dispatch.
Shared Packages Centralized Mongoose schemas (packages/db), tenant-scoped business logic (packages/domain), and PDFKit letterhead generators (packages/pdf)
Infrastructure — Single VPS running Caddy (automatic TLS), Docker Compose, and a single-node MongoDB replica set for transaction support.

Outcome

A self-hosted, multi-tenant accounting platform operating reliably on a single VPS behind a Caddy reverse proxy. Multiple businesses run with complete isolation on one database instance, allowing shop owners to track daybooks and dispatch automated PDF invoices via WhatsApp, while giving operators a secure, auditable administration plane.