Syed Yahya

Projects

Event Workforce Platform

Web App · Automation · AI · Data

The problem

Staffing hundreds of temporary event workers means applications, onboarding, contracts, scheduling, attendance and payroll all have to work as one connected flow across many locations.

What I built

Founder and sole builder: requirements, design, development, UAT iteration with the client and release management.

Features

  • Mobile-first public application with WhatsApp OTP verification
  • Recruiter review and select/reject/waitlist workflow, with automatic onboarding invites
  • Onboarding with encrypted sensitive fields and server-generated digital contracts (signed upload, ops verification; corrections as signed variation notices)
  • Virtualized operations scheduling board with warn-only conflict handling
  • Geofenced, photo-verified clock-in/out with late detection and auto clock-out
  • Timesheets with daily verification, frozen rate snapshots and audited reopen
  • Payslip PDFs, worker portal access and payroll export
  • Google Drive project archive export with checksum verification and fail-closed storage cleanup
  • WhatsApp Cloud API notifications, installable worker portal with push reminders
  • Capability-based RBAC (40 capabilities), mandatory staff MFA, full audit trail

Integrations

  • WhatsApp Cloud API (Meta)
  • Google Drive and Sheets APIs
  • Resend (email)
  • Supabase Postgres, Auth and private Storage
  • Leaflet/OpenStreetMap geocoding
  • Web Push

Decisions I made

  • Configuration-driven rather than hard-coded to one event, so the platform can be reused for future projects
  • Money stored as integer cents; Asia/Singapore time handled server-side
  • Kept NRIC, bank and address out of the public application; collected only at onboarding, encrypted, with NRIC masked for most staff
  • Warn-only shift conflicts (humans decide) but hard-reject unscheduled clock-ins
  • GPS issues informational only after stakeholder feedback, to avoid extra ops workload
  • Fail-closed storage cleanup: only delete files verified in Drive via fresh size+checksum check
  • Change-request discipline: every change is an issue, branch, PR with tests, then staging, then production

Outcome

End-to-end flow from public mobile application to payslip in one configuration-driven platform.

Stack

Next.js · TypeScript · Tailwind CSS · shadcn/ui · Prisma · Supabase · Vercel · React-PDF · Zod · Vitest · Playwright

Built under my studio, Built by SAB.