django.md

Management consultancies: client portal using Django

Summary

A client portal blueprint for management consultancies built with Django on Ample. Domain schema: client_entities (name, industry, primary_contact_role): client organizations; engagements (client_entity_id, scope_title, phase, period_start, period_end): engagement periods and phases; workstreams (engagement_id, name, owner, status, due_at): tracked workstreams; deliverables (engagement_id, title, version, object_key, released_at): versioned deliverables shared with the client; document_access (document_id, principal_reference, role, granted_at): who may read which document. Public information: service offerings and case studies (anonymized), consultant profiles, engagement model. Kept out of scope until handling is reviewed: client strategy documents, financial models, interview notes. Client strategy material is confidential; authorization is modeled per engagement and no compliance claim is made. Technical basis verified on Django: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Model the management consultancies domain. Create the tables client_entities, engagements, workstreams, deliverables, document_access. Client organizations live in client_entities; keep the sensitive classes (client strategy documents, financial models, interview notes) out of this schema.
  2. Workflow step 1. Model client entities and engagement periods; every document belongs to one engagement
  3. Workflow step 2. Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client)
  4. Workflow step 3. Store documents in the private bucket and stream them through the app
  5. Workflow step 4. Deploy and verify the negative authorization tests and an authorized download
  6. Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
   ample deploy . --name <app-name> --public --start "python3 run.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. Verify. Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the management consultancies workflow.
   ample logs <deployment_id> --kind build

Tested examples

Success checks

Limitations

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

Verification evidence