page:blueprints:digital agencies:client portal:django

Digital agencies: client portal using Django

Summary

A client portal blueprint for digital agencies built with Django on Ample. Domain schema:

Public information: services and case studies, team, contact. Kept out of scope until handling is reviewed: unreleased creative and campaign plans, client analytics exports, brand credentials. Unreleased creative is confidential; brand platform credentials never belong in these flows.

Technical basis verified on Django: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary.

Prerequisites

Workflow Steps

  1. Model the digital agencies domain: Create the tables client_entities, engagements, approval_rounds, deliverables, document_access. Client brands live in client_entities; keep the sensitive classes (unreleased creative and campaign plans, client analytics exports, brand credentials) out of this schema.
  2. Workflow step 1: Model client entities and engagement periods; every document belongs to one engagement.
  3. Workflow step 2: Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client).
  4. Workflow step 3: Store documents in the private bucket and stream them through the app.
  5. Workflow step 4: Deploy and verify the negative authorization tests and an authorized download.
  6. Deploy: Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
  7. Verify: Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the digital agencies workflow.

Cost Estimate

Components

Limitations

Next Actions