oclona-summary

Oclona – Multi-Tenant HR SaaS (Technical Overview)

Oclona is a multi-tenant HR SaaS platform designed to bring workforce operations into a unified, role-aware system with strict tenant-level data isolation.

It is built using a React-based frontend and Supabase (Postgres, Auth, Row Level Security, Storage and Edge Functions).

The system emphasizes backend-enforced security, controlled onboarding flows, workflow-driven operations and predictable multi-tenant behavior without relying on client-side trust.

This repository provides a technical overview of the product’s architecture, engineering decisions, security model and key workflows.



Table of Contents

  1. Problem Space
  2. System Overview
  3. Architecture Overview
  4. Core Engineering Challenges
  5. Key Design Decisions
  6. Important Flows
  7. Security & Data Isolation
  8. Email & Communication Infrastructure
  9. Trade-offs & Limitations
  10. Future Improvements
  11. Project History

Problem Space

Multi-tenant systems introduce challenges around data isolation, authorization, workflows and lifecycle management:

Oclona is structured to address these constraints through clear application boundaries, database-enforced authorization and predictable product workflows.


System Overview


📊 Architecture Overview


Core Engineering Challenges

Tenant Isolation Without Client Trust

Users must never access data outside their authorized tenant scope.

Impact:

A tenant isolation failure would compromise the core SaaS security boundary.

Approach:


Invite-Based Onboarding

Users should be able to join a tenant through a controlled invitation flow.

Impact:

A weak invitation system could allow unauthorized tenant access or incorrect tenant association.

Approach:


Initial Tenant Setup

The first user must establish both the tenant and initial owner context.

Approach:


Data-Heavy UI Complexity

HR workflows require tables and interfaces that handle filtering, sorting, pagination, forms and state changes consistently.

Approach:


Secure Privileged Operations

Certain operations require elevated server-side capabilities, such as transactional email delivery.

Approach:


🔑 Key Design Decisions

Why Supabase?


Why RLS Over Client/API-Level Authorization?


Why Invite-Based Onboarding?


Why React SPA?


Important Flows

Multi-Tenant Onboarding

Owner Signup → Email Verification → Company Setup → Invite Member → Accept Invite → Member Signup → Tenant Linking → Access System

Why this matters:

The flow establishes tenant membership through controlled onboarding rather than trusting client-provided tenant identifiers.


Team Management


Employee Onboarding


Leave Management


🔐 Security & Data Isolation

The security model separates:

Authentication → Authorization → Data Integrity → Database Automation


Email & Communication Infrastructure

Oclona separates business communication from transactional email delivery to improve maintainability, deliverability and domain reputation management.

Domain Structure

Business Communication

Custom domain-based business mailboxes are managed through Zoho Mail for operational and customer communication.

Example identities:

Transactional Email Architecture

Transactional emails are delivered using Resend and Supabase Edge Functions through a dedicated email subdomain.

Current use cases include:

Example identities:

Email Security & Deliverability

The infrastructure uses standard email authentication mechanisms:

These help support authenticated delivery, spoofing protection, inbox placement and long-term domain reputation.

Operational Monitoring

Email and deployment workflows are monitored through:


Trade-offs & Limitations


🚀 Future Improvements


Project History


Case Study

For the full product walkthrough, screenshots, architecture diagrams, engineering decisions and detailed workflows:

View the Oclona Case Study


Notes

This repository is a technical overview and demonstration of Oclona, a production-oriented HR SaaS product.

The primary application implementation repository is private. This repository intentionally focuses on architecture, engineering decisions, product workflows, trade-offs and selected technical context rather than exposing the complete production codebase.

Documentation may evolve as the product changes. For current product behavior, refer to the deployed application and implementation.


Author

Shahnawaz Khan, Senior Frontend Engineer
Focused on building scalable SaaS products and reliable product experiences.


License

This repository is provided for demonstration and evaluation purposes only.

Reuse, redistribution, or commercial use is not permitted.