page:blueprints:b2b saas:client portal:laravel

B2B SaaS: Client Portal using Laravel

Summary

A client portal blueprint for B2B SaaS built with Laravel on Ample. Domain schema:

Public information: product documentation by version, pricing and plan comparison, status and changelog.
Kept out of scope until handling is reviewed: customer data inside workspaces, usage and billing records, support attachments. Customer workspace data is tenant-scoped; isolation is application-enforced and no security certification is claimed.

Technical basis verified on Laravel: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute: Verified apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Workload

Client portal

Workflow Steps

  1. Model the B2B SaaS domain: Create the tables customer_workspaces, workspace_members, doc_versions, customer_assets, document_access. Customer tenants live in customer_workspaces; keep the sensitive classes out of this schema.
  2. Model client entities and engagement periods; every document belongs to one engagement.
  3. Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client).
  4. Store documents in the private bucket and stream them through the app.
  5. Deploy: Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
    • Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  6. Verify: Run the pattern self-test(s) and your own acceptance checks for the B2B SaaS workflow.
    • Command: ample logs --kind build

Technical Input Schema

Examples

Success Checks

  1. App responds on its public URL (expect: ample canary laravel patterns).
  2. Private-document-library self-test from the example (expect: see the pattern fixture checks).

Limitations

Cost Estimate