Accounting firms: client portal using Next.js | Ample

INFRASTRUCTURE

What it needs

PREREQUISITES

Before you start

STEP BY STEP

How to do it

  1. 1

Model the accounting firms domain

Create the tables client_entities, engagements, document_requests, deliverables, document_access. The businesses and individuals served lives in client_entities; keep the sensitive classes (tax identifiers and financial statements, bank and payroll records, identity documents) out of this schema.

  1. 2

Workflow step 1

Model client entities and engagement periods; every document belongs to one engagement

  1. 3

Workflow step 2

Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client)

  1. 4

Workflow step 3

Store documents in the private bucket and stream them through the app

  1. 5

Workflow step 4

Deploy and verify the negative authorization tests and an authorized download

  1. 6

Deploy

Run the synchronous deploy once and read the result. Re-running with no change is a no-op.

    ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
    ```

7. 7

#### Verify

Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the accounting firms workflow.
ample logs <deployment_id> --kind build
```

EXAMPLES

Tested examples

SUCCESS CHECKS

How to know it worked

COST

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision 515b7316fc6e5a81679407ae0c811146ceb2c5c7).

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

EVIDENCE

Verification evidence

EXECUTION

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-22T00:31:22.774679+00:00 at revision e6446ceea69b. Binding state at export: current. Required scopes: servers:write, databases:read, buckets:read.

NEXT ACTIONS

Typed next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.