Management consultancies: client portal using Next.js | Ample

INFRASTRUCTURE

What it needs

Before you start

Exactly what was tested

How to do it

  1. Model the management consultancies domain

    Create the tables client_entities, engagements, workstreams, deliverables, document_access. Client organizations live in client_entities; keep the sensitive classes (client strategy documents, financial models, interview notes) out of this schema.

  2. Workflow step 1

    Model client entities and engagement periods; every document belongs to one engagement

  3. Workflow step 2

    Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client)

  4. Workflow step 3

    Store documents in the private bucket and stream them through the app

  5. Workflow step 4

    Deploy and verify the negative authorization tests and an authorized download

   ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. Verify

    Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the management consultancies workflow.

   ample logs <deployment_id> --kind build

Tested examples

How to know it worked

Know the limits

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

Verification evidence

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f. Binding state at export: current. Required scopes: servers:write, databases:read, buckets:read.

Typed next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.