BuildOrbit
All Projects

Yuki CRM

buildorbit.studio
Yuki CRM passwordless sign-in screen with the Fresh Daylight workspace design

Secure Drive-style employee workspace for private files, controlled sharing, large transfers, and auditable operations.

A private internal CRM foundation centered on secure file work. Employees can organise folders, upload large files directly to S3, manage versions, share internally or externally, create upload-only requests, search, recover deleted items, and operate through a light Fresh Daylight interface.

ERP & SaaSSecure File WorkspacePrivate pilotWeb
Delivery footprint

The scale of what shipped.

Quick numbers to show the size, complexity, or scope of the system behind this case study.

2
Workspace Views
3
Delivery Paths
1
Append-only Audit
0
Public S3 Reads
Case Study

How the project moved from constraint to launch.

A concise read of the challenge, the system we designed, and what changed once the product reached production.

01

The Challenge

The team needed a familiar file workspace without giving up private-by-default access, precise permissions, large-transfer reliability, revocation, malware controls, auditability, and operational evidence required for an internal CRM foundation.

02

Our Approach

We built a modular Next.js workspace backed by Neon Postgres, Prisma, private S3 storage, and CloudFront delivery. The browser uses direct multipart transfers with grouped progress, while the application enforces OTP identity, permission inheritance, signed delivery, external share policy, upload requests, lifecycle controls, append-only audits, quotas, and scheduled maintenance.

03

The Result

Completed the Phase 1 product and governance code paths, including the Fresh Daylight redesign and Drive-style folder transfers. Final production acceptance remains deliberately gated by live restore, large-transfer, malware, and infrastructure rehearsals.

Product Screens

Across the platform.

Passwordless Sign-in

Workspace List

Workspace Grid

Workspace Controls

Secure Sharing

File Requests

Key Features

What actually shipped.

Selected capabilities and system details that mattered in the final product, not a padded feature checklist.

Private-by-default hierarchical folder workspace

Direct and multipart S3 uploads with grouped progress and cancellation

Folder imports that preserve relative paths and empty directories

Internal permissions, external shares, and upload-only requests

File versions, recycle bin, search, stars, and storage quotas

Email OTP authentication with domain and invitation controls

Malware quarantine boundary and short-lived signed delivery

Append-only audit export, archive jobs, monitoring, and runbooks

Tech Stack

Built with reliable production tooling.

The stack was chosen to fit the product constraints, not to chase trends. These are the technologies behind the shipped system.

Next.jsReactTypeScriptNeon PostgresPrismaAWS S3CloudFrontPostmarkSentryAWS CDKPlaywrightVitest

Building something with this level of complexity?

If you're planning a secure file workspace with real delivery constraints, we can help you scope it, make the technical calls early, and ship it properly.

Direct technical conversations before scope gets expensive.
Full-stack product delivery from interface to backend to launch.
Clear tradeoffs and execution plans instead of vague agency promises.