Internal operations · Two separate systems · Deployed
Bridge
Bridge is the public name of two independent employer-owned applications: one for Achour Holding and one for Aligned Tech. They share an engineering principle, not a database, deployment, or reskinned product.
Two implementations with different ownership
- Achour Holding · Deployed and adoptedBridge
I architected and implemented this system end to end. It is used by the development department and subsidiaries to follow projects, exchange controlled operational context, and inspect approved progress through role-scoped interfaces.
- Aligned Tech · Production useBridge
I developed this separate implementation with Tayseer Laz and the internal team. It is the company’s main CEO operations dashboard and supports leadership, sales, AI-development teams, other internal teams, and client workflows.
The implementations live in independent repositories and have different data models, integrations, users, access rules, and release histories. Both are called Bridge because both solve the organizational gap between work occurring in specialist tools and people needing a trustworthy operating view.
Technical case study: a controlled read model over operational systems
The shared design decision is to preserve upstream authority. Bridge records stable links, normalizes the fields a workflow needs, attaches provenance, applies organization scope, and makes disagreement or failed synchronization visible instead of pretending every source behaves like one database.
The common data path
- 01 · LinkBind records deliberately
An external project, task, file location, or conversation becomes usable only after it is associated with the correct internal organization and project.
- 02 · NormalizeKeep identity and source
Bridge maps the subset needed for operations while retaining external identifiers, source timestamps, link state, or audit context.
- 03 · ScopeResolve access before data
The authenticated organization and role determine which read model can be queried. Missing scope is an error, not permission to widen the result.
- 04 · DeriveBuild explainable status
Progress, attention, and reporting views are calculated from linked tasks, milestones, dates, and states that a person can inspect.
- 05 · ReconcileExpose disagreement and retry safely
Synchronization logs, last-seen state, bounded retries, and manual review distinguish “unchanged” from “could not verify.”
Bridge at Achour Holding: fail-closed scope carried into AI retrieval
The Achour Holding implementation resolves scope from the authenticated session before reading a project. A development-department administrator can receive a holding-wide scope; a subsidiary account can receive only its assigned company. A missing company, inactive account, unknown role, malformed “view as” request, or unauthenticated request is denied. The company is not accepted from a convenient request parameter and then trusted.
The department's “view as subsidiary” operation is implemented as scope narrowing. It cannot be used by a subsidiary, cannot move a subsidiary to another company, and does not grant write authority while impersonating the client view. Tests also make real and nonexistent cross-company targets indistinguishable to a subsidiary so the access check does not become a company-discovery side channel.
The read-only ChatGPT/MCP path applies a separate boundary. It is disabled unless explicitly configured, uses credentials that do not authenticate the human application, and exposes bounded read tools backed by a read model with no write statements. Ambiguous record identifiers are refused rather than guessed, oversized activity responses require a narrower request, and returned context excludes credential material and private file identifiers.
- Selected: one central scope resolver that fails closed
- Reason: every route receives the same answer for administrator, subsidiary, inactive, missing, and unknown identities. Tradeoff: a bad assignment blocks access until corrected; the system never repairs ambiguity by broadening visibility.
- Selected: a separate, read-only AI door
- Reason: conversational retrieval can inspect approved operational context without inheriting a browser session or mutation authority. Tradeoff: actions still return to the application and a responsible person.
Bridge at Achour Holding: deployment failure is part of the design
A release is not accepted merely because the build completed. The deployment path verifies the candidate service internally and through its public health contract. If startup or health verification fails, it restores the previous application source and serving image, then checks that the rollback itself is healthy.
The rollback path was deliberately exercised with changes that passed the application tests but failed at runtime. Database state is not automatically rolled back, which is an important limitation: schema and data changes still require backward-compatible planning or a separate recovery procedure.
Bridge at Aligned Tech: synchronization with retained provenance
The Aligned Tech implementation links an internal project to an external project or milestone and retains the external identifiers on the local project and task records. During reconciliation, the connector downloads the relevant source snapshot, filters it to the explicit link, maps source states into the smaller local state model, and matches existing rows by stable external task identity.
The project update runs in a transaction. Existing linked tasks are updated, unseen linked tasks are created, and linked local rows no longer present in the authoritative snapshot are removed. Deadline changes receive a source label, synchronization attempts create directional status records, and the project stores when it was last reconciled. Webhook updates reduce delay; manual and scheduled reconciliation remain available for events that were missed or could not be processed.
The principal tradeoff is that a useful local read model is intentionally less expressive than the source system. Unknown source states fall back to a safe local state, while external IDs and synchronization records preserve enough provenance to investigate the mapping. The automated tests I found directly cover status normalization; the repository does not support publishing an exhaustive synchronization-success metric.
Evidence and failure boundaries
- Achour access tests
Tenant-isolation cases cover absent sessions, cross-company reads, administrator narrowing, inactive organizations, write denial, and indistinguishable forbidden targets.
- Achour AI tests
Configuration, credential separation, read-only tool registration, result bounds, ambiguous identifiers, OAuth behavior, and absence of sensitive values are exercised automatically.
- Achour deployment tests
Repository history records both a pre-deploy health-gate failure and a runtime failure that restored and revalidated the previous release.
- Aligned synchronization evidence
Code and history show stable external identifiers, transactional import and reconciliation, source-labelled deadline changes, synchronization logs, webhook handling, manual reset, and status-mapping tests.
Both Bridge implementations are employer-owned. This account intentionally omits source code, dashboard images, prompts, organization records, subsidiary or client data, credentials, private infrastructure, and confidential operating metrics. It does not claim that synchronized views are instantaneous or that incomplete upstream records become accurate automatically.
Ownership and status
Bridge at Achour Holding: I owned the architecture and implementation end to end, including organization scope, project and content workflows, integrations, the read-only AI access path, tests, deployment, and adoption support. It is deployed and adopted by the development department and subsidiaries.
Bridge at Aligned Tech: delivery was shared with Tayseer Laz and the internal team. My repository history includes operational dashboards, external-system synchronization, reporting and AI-assisted workflows, access boundaries, production hardening, and deployment work. It is the company’s main CEO operations dashboard and is used across internal and client workflows.