Enterprise software · Internal developer platforms

A citizen-developer platform with zero manual console access

A self-service CI/CD platform that lets internal business teams ship their own apps through a single governed pipeline — zero manual cloud-console access, four delivery phases, foundation phase accepted in five weeks.

A regulated enterprise wanted the people who run its internal business teams — recruiting, finance, operations — to ship their own small internal apps, dashboards, calculators, directories, without waiting on a shared engineering backlog. The catch: every app had to run inside one audited compliance boundary, with zero manual cloud-console access, from day one.

What we built

We delivered a governed, self-service platform in four phases matched to the client's statement of work. A Terraform-defined landing zone puts every internal project inside one audited compliance boundary with customer-managed encryption and narrow, per-environment IAM personas — no standing Editor or Owner roles anywhere. The golden path runs a git push through a build, a vulnerability-scan gate, an Artifact Registry push and a Cloud Run deploy behind Identity-Aware Proxy, with a human approval gate before production. Six pilot apps launched through three reusable pipeline templates, lowest-sensitivity first, highest-sensitivity last.

Architecture

Identity runs on Workload Identity Federation for CI/CD — no long-lived service-account keys anywhere — paired with Identity-Aware Proxy and Google Workspace Groups for authorization, so access grants and revokes happen in one place. Security Command Center, per-environment KMS encryption and VPC Service Controls sit at the edge, under one hard sequencing rule: a private build worker pool has to exist before the network perimeter flips from monitoring to enforced, because enforcing it first would break the pipeline meant to deploy the fix.

A compliance-boundary folder can look right without being right — its controls only apply to projects created inside it from day one. A project moved in later is monitored going forward, not retroactively covered. We built that into how every later project gets created, not just how it gets reviewed.

What made it work

  • Risk-ordered rollout. The lowest-sensitivity pilot app proved the golden path first; the highest-sensitivity app went last, once the pattern had already held under real use.
  • A named bottleneck, flagged in writing. Every phase gates on one compliance sign-off. We called that out as a delivery risk in the project plan and asked for a named backup approver.

Current stage

The foundation phase is complete and accepted: the landing zone, the CI/CD golden path and the self-service portal are live, validated end to end, and closed out in the engagement's own acceptance record. A follow-on hardening review — closing gaps in approval separation, encryption coverage and audit logging — is scoped as a proposed 14-week phase, not yet a signed engagement. A parallel enterprise-search pilot is running for 25 licensed users across two business functions; a wider rollout beyond the pilot has not been scoped.

All case studies

Talk to us

Tell us what system the answer lives in and who needs it. We'll reply with a view on whether it's a two-week assessment, a five-week pilot, or something else.

akash@insightnext.tech

InsightNext on LinkedIn