Software, AI &platformsAI agentsMVPsteamsbuilt to hold up.
Z-Axiss designs and engineers enterprise platforms, AI systems and apps for government, healthcare, mobility, education and commerce — the software organisations actually run on, every working day.
Domain expertise that shortens the learning curve.
We learn the rules of your business before we design around them — enforcement, clinical, academic or commercial.
8+Years building software, since 2018
35+Clients served
35+Projects delivered
25People on the team
What we do
Full-stack capability, under one roof.
We work as the product engineering team for organisations that need software to do a real job. That means owning the problem, not just the ticket queue.
AI agents & applied AI
AI put to work inside the systems you already run: agents that handle real workflows, LLM features in existing products, and document intelligence — on governed, auditable foundations.
Full delivery of a platform, from the domain model through to the interface people use all day. We take responsibility for how the system behaves, not just whether it compiles.
Domain modellingArchitectureBackend & APIsWeb & mobile appsAutomated testing
Developers, testers and project managers who join your team and work to your process — integrated rather than at arm's length. Scale up and down without a hiring cycle.
Getting a first version in front of real users quickly, using our MVP development framework — then refining it against what those users actually do, not opinion.
AI agents that plan, act and hand off — inside your systems.
We build production AI agents on whichever framework fits the job — Google ADK, LangGraph, the OpenAI Agents SDK, or plain code against your own stack. Multi-agent workflows, tools that act in your systems and human approval where it matters, alongside LLM features and document intelligence that plug into your existing platforms — with observability that shows what each model decided, why, and at what cost.
Uses NLP to extract tags and keywords from examination questions, so educators can organise and analyse assessment content at scale. It learns from feedback.
Staff attendance, leave and asset tracking for schools, colleges and training providers — location-verified clock-ins, ledger-backed leave and a full audit trail.
Client work stays the client's. We built these platforms under contract; the organisations that commissioned them own and run them.
Daily attendanceCompany-wide · today
112Checked in
6Late
9On leave
Employee A · 09:02Checked in
Employee B · 09:41Late
Our product
Employee Management Portal — software we own.
Attendance, leave, assets and internal communication in one self-hosted system. Every hour, every absence and every asset accounted for. You deploy it on your infrastructure; we keep developing it.
It depends on scope and integrations. A focused MVP usually takes a few months; enterprise platforms take longer. After the first call you get a clear roadmap with milestones, not a vague estimate.
Yes. We integrate AI agents, LLM features and document intelligence into platforms you already run, with monitoring so you can see what the AI decided and why.
Fixed-scope projects, monthly retainers, and dedicated engineers who join your team. We also work white-label for agencies and software companies.
You do. Client work is built under contract and owned by the client. NDAs and IP assignment are standard.
Yes. Most of what we have built is still running, and we stay involved with support, monitoring, fixes and new features.
Yes. We refresh design, performance and architecture on existing platforms without disrupting day-to-day operations.
Send a message or book an appointment. We'll discuss your goals and come back with an approach, a team shape and a realistic timeline.
Ready to turn your idea into a product?
Free 30-minute call. Leave with an approach, a team shape and a realistic timeline.
We provide software engineering, AI and consultancy to enterprises, SMEs and technology challengers. Since 2018 we have helped businesses across multiple industries design, develop and deliver products faster and more cost-effectively.
We design AI agents, LLM features and document intelligence that plug into your existing platforms and workflows — built on governed, auditable foundations, so you can see what each model decided and why.
AI agents, on the framework that fits. Multi-agent workflows that take on real operational work — triage, support, data entry, reconciliation — built on Google ADK, LangGraph, the OpenAI Agents SDK or your own stack.
LLM integration. Search, summarisation and assistants added to products you already run.
Document intelligence. Large language models and AI parsers that mine company documents for retrieval.
AI observability. Monitoring of cost, quality and decisions, with human review where it matters.
Private deployment. Models hosted in your own environment when data cannot leave it.
Business-oriented solutions that meet market standards and your own requirements. In practice, we take responsibility for how the system behaves in the hands of the people who use it every day.
Domain modelling. We learn the rules — enforcement, clinical, academic, commercial — before designing around them.
Architecture that fits. Modular monolith or microservices, chosen for the problem rather than the trend.
Backend and integrations. APIs, data pipelines and connections into the systems you already run.
Web and mobile. One core, delivered through whichever channels your users need.
Tested business rules. Automated suites around the logic that matters, run on every change.
03 — Team augmentation
Engineers who join the team, not the org chart.
Strengthen your workforce with people who integrate into your projects — keeping delivery on track and within budget without the overhead of building a department.
Developers, testers, PMs
The roles you are short of, not a fixed bundle.
Inside your process
Our engineers work to your ceremonies, standards and definition of done.
Agile delivery
Short cycles, visible progress, and change absorbed without renegotiating everything.
Scale both ways
Add capacity for a push, release it afterwards, without a hiring cycle.
04 — Ideation & MVP
From concept to something real users can break.
We guide you through shaping the concept, then build a functional MVP to test with real users — reducing risk before a full-scale launch. Our MVP framework has taken clients to market substantially faster than a conventional build.
01
Shape
Brainstorming and conceptualising, ending in a prioritised feature set rather than a wish list.
02
Build
A functional MVP — narrow, but genuinely usable by the people you are building for.
03
Learn
Feedback gathered from real usage, so the next iteration is informed by evidence.
04
Scale
Hardening what proved out, and dropping what did not, before full launch.
2weeks
AI readiness sprint
We map where AI can take work off your team, prototype the strongest case, and hand you a costed plan.
We research and test with the people who will use the system, so the result is engaging and intuitive rather than merely functional.
UI/UX design
User research and usability testing feeding designs that build habit, not friction.
Research & testing
Wireframes & prototypes
Design systems
Digital transformation
We assess your current systems and build a roadmap that aligns technology with business goals, rather than replacing tools for their own sake.
Systems assessment
Technology roadmap
Web & e-commerce
Customised website design and development, and e-commerce with customer-centric management behind it.
Custom websites
E-commerce platforms
06 — Cloud & DevOps
Shipping should be boring.
We automate workflows, shorten time to market and raise the reliability of what you already run. DevOps comes alongside our development and cloud work, because deployment decisions belong with the people making architecture decisions.
CI/CD
Pipelines that make a release routine instead of an event.
Environments
Containerised deployment that behaves the same everywhere it runs.
Monitoring
Operational readiness, so problems surface before users report them.
Cloud
Enterprise cloud capability through our partnership with Trillo, a Google Cloud Partner.
Technologies
Every stack your roadmap needs.
Current expertise across web, mobile, AI, data and cloud — ready to plug into your roadmap.
How we engage
Three ways to start.
Discovery
Scope a problem
You have a business problem and no fixed solution yet. We shape it into an architecture, a plan and a cost.
Digital products for organisations across industries.
Every project below was designed and engineered by Z-Axiss for a client, and is owned and operated by that client. Grouped by the industry it serves, because the domain is what shapes the system.
Industries we serve
Where our work goes.
Real experience in industries where compliance, scale and daily reliability all have to work together.
Every case study on this page is client work. We designed and built those platforms under contract, and the organisations that commissioned them own and run them. Entries marked as a product or capability are the exception — those are software Z-Axiss owns, or a capability we offer rather than a delivered client project.
Working on something in your sector?
We have taken systems live in enforcement, healthcare, education and commercial marketing. Tell us the problem and we'll tell you honestly whether we're the right team.
Every hour, every absence, every asset — accounted for.
Attendance, leave, assets and internal communication in one self-hosted system, built and supported by Z-Axiss and configured to how your organisation actually works.
On site, verifiedWithin graceNo short hours1 exception to review
A defensible record rather than a punch time. Every override keeps the original calculation on file.
Overview
One system for the work that surrounds the work.
Most companies run attendance in one tool, leave in another, equipment in a spreadsheet and announcements in a chat thread nobody can search. Nothing reconciles, so every payroll cycle turns into an investigation.
The portal puts all of it in one place, with three purpose-built views so people only see the part that is theirs — deployed on your own infrastructure, with no per-seat licence.
9Modules covering the full employee day
3Role portals, plus an API role
7Built-in report types, exportable
MultiCompany support, one login
Three portals
Everyone sees their part of it, and nothing else.
For employees
Clock in, request, check, done
Clock in and out, see today's shift and hours
Live leave balances and request history
Explain a late arrival before anyone asks
See assigned equipment and confirm receipt
For managers
Their team, decided today
Who is in, late, absent or on leave — right now
Approve leave, excuse lateness, review absences
Team calendar before approving overlaps
Team-only reports and balances
For administrators
The rules, and the receipts
Shifts, leave types, quotas, fiscal years, locations
Accounts, roles, invitations and access
Company-wide attendance, leave and asset data
Corrections and exports with a full log
The modules
Everything the working day actually touches.
Modules that share one set of people, one policy layer and one audit trail — so a clock-in, a leave balance and a laptop handover all reconcile against each other.
Platform & deployment
Built to run on your infrastructure, on your terms.
A complete application you own and deploy — not a seat-based subscription with your workforce data in someone else's account.
RUN
Deployment
Containerised, started with a single command, on your servers or a managed host.
DB
Data ownership
A PostgreSQL database you control, with schema upgrades applied on release.
API
Open API
A documented REST API with a dedicated integration role for payroll, HRIS or BI.
INT
Integrations
Google Calendar, Google Chat, email delivery and CSV import for historic data.
SEC
Security
Token authentication, hashed passwords and per-company isolation at the query layer.
QA
Quality
An automated suite covering business rules, permissions and isolation on every change.
UX
Experience
Responsive throughout — phones for clocking in, desktops for administration.
FIT
Adaptable
Modules, fields and rules extended to fit how you already work.
How we deliver it
You are not buying a download.
Z-Axiss implements the portal end to end, and stays with it afterwards.
01
Discovery & policy mapping
Your shifts, leave types, entitlements and approval chains mapped onto the configuration first.
02
Deployment & migration
Installed on your infrastructure or ours, with historic records imported at go-live.
03
Customisation
Extra modules, fields, reports and integrations from the team that built it.
04
Training & support
Role-based onboarding plus ongoing maintenance and upgrades.
Request a demo
See the portal running on your own scenarios.
Tell us about your organisation and we'll walk you through the modules that matter to you — with your shift and leave rules in mind.
A working session, not a slide deck.
Configured against your shifts and leave policy.
Deployment and migration questions answered directly.
A software company built on doing the difficult parts properly.
Z-Axiss is a software product engineering company in Islamabad. Since 2018 we have grown from a small team into a delivery partner for organisations that need systems to hold up under real operational load.
The company
Software that has to work on the day it matters.
We have established ourselves as one of Pakistan's leading software firms through sustained commitment rather than rapid marketing.
We specialise in enterprise platforms, AI systems, custom web and mobile applications, e-commerce with customer-centric management systems, and enterprise resource planning. Our reputation comes from professionalism and a steady commitment to quality.
As demand for digital operations grows, so does the need for prompt and effective solutions. We guide clients through the whole journey, not just the build.
2018Founded
35+Clients served
35+Projects delivered
25People on the team
Our partnerships
Enterprise capability, a team that cares about the details.
As a partner of Trillo — a recognised Google Cloud Partner — and DreamAI, we pair enterprise cloud and AI capability with a team small enough to care about the details.
Frameworks that cut cost and timeOur engineers build on platforms that reduce development cost and time dramatically — up to 90% against a conventional build.
MVP-first deliveryWe use that speed to take clients from concept to market through our MVP framework.
Delivered into the USPlatforms in operational use by municipal authorities and private operators.
How we work
Why clients choose us.
We don't just build software; we craft solutions tailored to the business behind them — whether you're a start-up launching a first product or an enterprise extending its digital capability.
Professional
A team that treats commitments, timelines and quality as the same conversation.
Passionate
Engineers who push boundaries and stay curious about the domains they build for.
Creative
A collaborative environment where design and engineering shape the product together.
Reliable
Delivery you can plan around, with progress visible rather than reported.
Supportive
We stay with the system after launch — most of what we've built is still running.
Global outlook
Work delivered for clients in the United States and beyond, from our base in Islamabad.
Principle
Domain-first
We learn the rules of your business before we design around them.
Principle
Built to be audited
Systems that record how a decision was reached, not just what it was.
Principle
Integrated teams
Engineers inside your process and cadence, not reporting from a distance.
Principle
Long-run ownership
We build for the years after launch, not the demo.
Security & standards
Built to be audited, from day one.
Compliance is a design constraint we build around, not a layer added before launch. Systems record how a decision was reached — that is what survives a challenge.
AUDIT
Full audit trails
Every decision, change and approval recorded with who, when and why.
PHI
Healthcare data
Access controls, encryption and secure records handling for clinical workflows.
GDPR
Privacy by design
Consent, lawful processing, retention and deletion built into the data model.
OWASP
Secure engineering
Security reviews against common web and mobile vulnerabilities before release.
WCAG
Accessibility
Interfaces that work for people using assistive technologies.
AI
Governed AI
Model decisions logged, monitored and explainable, with human review where it matters.
CI/CD
Controlled releases
Automated tests and pipelines so every change is traceable and reversible.
SLA
Operational readiness
Monitoring and support so systems keep running long after launch.
Meet the people behind the systems.
Engineers, designers and delivery leads working from Islamabad.
Engineers, designers and delivery leads working from Islamabad on platforms used across the United States and beyond.
Working here
We hire engineers who want to own something.
Our teams work close to the domain — enforcement rules, clinical workflows, assessment logic — because that is where the interesting engineering problems actually live. If that appeals, we'd like to hear from you.
Close to the domainYou'll learn the rules behind the software, not just the ticket.
Design and engineering togetherDesigners and engineers shape the product side by side.
Work that stays in useMost of what we build is still running years later.
AI in productionReal work on agents, LLM features and observability.
Your offshore engineering team, under your brand.
For agencies, consultancies and software companies that need senior delivery capacity. We work inside your process, and your client relationship stays yours.
A recognised Google Cloud Partner and the company behind Trillo AOS, an agent orchestration platform. Together we deliver enterprise cloud and agentic AI projects, with Z-Axiss engineers working inside the platform.
Google Cloud PartnerAgent orchestrationEnterprise delivery
D
AI & machine learning partner
DreamAI
An AI and machine learning software company building systems on cloud platforms and on-premises for enterprises across many industries.
AI & ML systemsCloud & on-premisesEnterprise AI
Partners, not just vendors. Through Trillo — a recognised Google Cloud Partner — and DreamAI, our clients get enterprise cloud and AI capability with a Z-Axiss delivery team that stays close to the work.
Writing from the people who build the work — architecture decisions, domain modelling, interface design and what we've learned shipping into environments where the output gets challenged.
Tell us what you are building.
We're the innovation delivery partners you can trust. Send us the problem and a member of the team will come back to you directly.
The short version of how we work with you and your information.
Terms & conditions
01
Acceptance of terms
By using our services you agree to be bound by these terms. If you do not agree, please do not use our services.
02
Services provided
We offer IT services including consultation, project management and technical support. Specific details are described across this site.
03
Appointment booking
When you book an appointment you agree to provide accurate and complete information about your project, including tech stack, scope and timeline.
04
Changes to terms
We may modify these terms at any time. Changes take effect on posting, and continued use of our services constitutes acceptance.
Privacy policy
Privacy policy to be added. Add your full privacy policy here before launch — what data the site collects, how enquiries are stored, how long they're kept and how people can ask for deletion.
New · Agents on any framework
Agentic AI that does the work, not just the talking.
We design, build and run AI agents that plan, use your tools, hand off to each other and ask a human when it matters. We choose the framework to fit your stack and your constraints — Google ADK, LangGraph, the OpenAI Agents SDK, or none at all — and engineer the result like the rest of our software: tested, observable and built to be audited.
Work that currently lives in inboxes, spreadsheets and swivel-chair tasks.
An agent is worth building when a process has clear rules, a lot of volume and a real cost when it's slow or wrong. These are the places we start.
Operations & back office
Reconcile records, chase missing data, update systems and flag exceptions for a person to decide.
Customer & case support
Triage requests, draft answers from your knowledge base and route the hard ones with full context.
Document processing
Read contracts, forms and reports, extract what matters and file it where it belongs.
Sales & CRM operations
Enrich leads, prepare account briefs and keep the pipeline clean without manual data entry.
IT & DevOps
Investigate alerts, gather logs, suggest fixes and open tickets with the evidence attached.
Compliance review
Check records against policy, explain every finding and leave the decision with a reviewer.
How we build
Production agents, on the framework that fits you.
We are not tied to one vendor's toolkit. We have the most production mileage on Google's ADK, and we build just as readily on LangGraph, the OpenAI Agents SDK or Microsoft's Agent Framework — or straight against model APIs when a framework would only add weight. The framework is a choice made in discovery; the engineering below is what stays constant whichever way it goes.
01 · Workflow runtime
Deterministic where it must be, flexible where it can be.
We compose agent logic as execution graphs — routing, fan-out and fan-in, loops, retries and nested workflows — so the steps that must happen in order always do, and the model only decides where judgement is actually needed.
Graph workflowsRoutingRetriesState management
02 · Multi-agent delegation
Specialists, not one agent that does everything.
An orchestrator hands structured tasks to specialist agents and gets controlled output back. Agents can also talk across systems and vendors over the open Agent2Agent (A2A) protocol.
Task APIAgent hierarchiesA2A protocol
03 · Tools & integrations
Agents that act inside your systems.
Agents get tools built from your own functions, OpenAPI specs and existing services — your CRM, ERP, databases, email and document stores — with permissions scoped to exactly what each agent needs.
Sensitive actions pause for explicit confirmation, with the agent's reasoning and evidence in front of the reviewer. Approvals, rejections and edits are all recorded.
Tool confirmationApproval queuesEscalation
05 · Evaluation
Tested like software, before and after launch.
We build evaluation sets from your real cases and run them on every change, so a prompt tweak or model upgrade can't quietly break a workflow that was working.
Eval datasetsRegression testsQuality scoring
06 · Deployment
Runs where your data is allowed to be.
Agents are containerised and deployed wherever the data is allowed to live — Google Cloud Run or Vertex AI Agent Engine, AWS, Azure, or your own infrastructure. Every framework we work with is model-agnostic, so the deployment target and the model provider stay separate decisions.
Cloud RunVertex AI Agent EngineAWS & AzureSelf-hostedModel-agnostic
Frameworks we build onGoogle ADKLangGraphOpenAI Agents SDKMicrosoft Agent FrameworkMCPNo framework
Built inPythonTypeScriptJavaGoKotlin
Built to be audited
Every step an agent takes, on the record.
An agent you can't inspect is an agent you can't trust with real work. We instrument every run so you can see what happened, why, and what it cost.
Full traces. Every model call, tool call, handoff and decision, in order.
Cost & latency tracking. Per agent, per workflow and per customer.
Quality monitoring. Drift and failure alerts before users notice.
Governance. Scoped permissions, approval rules and a durable audit log.
Agent observability · run #4821
StatusCompleted
Duration18.4 s
Model calls6
Tool calls9
orchestrator.plan
research.search
data.query_sql
human.approve
action.update_crm
Agent response · rendered interface
Agent
InvoiceINV-2291
MismatchQty 40 vs 36
Approve creditEscalate
Adaptive agent interfaces
Agents that answer with a screen, not a wall of text.
Instead of chat replies, our agents can return structured interface specs — tables, forms, approvals — that your app renders with its own trusted components. The model describes the UI; it never ships code that runs in your users' browsers.
Safe by design. JSON specs rendered by your own components, with no runtime execution of AI-generated code.
On-brand. Agent output looks like the rest of your product.
From idea to running agent
How an agent project runs.
01
Discover
We pick the workflow with the clearest value and map its rules, systems and risks.
02
Prototype
A working agent on your real data, with the human checkpoints agreed up front.
03
Evaluate
Tested against real cases until it meets the quality bar you set.
04
Deploy & operate
Launched with monitoring, cost tracking and ongoing improvement.
FAQ
Agentic AI, answered.
A chatbot answers questions. An agent works toward a goal: it plans steps, calls tools in your systems, checks results and hands off or escalates when needed.
Whichever suits the work. We pick based on your existing stack, where your data has to live, how much orchestration the workflow genuinely needs, and who will maintain it after we hand over. We have the most production mileage on Google's ADK, and we work the same way with LangGraph, the OpenAI Agents SDK and Microsoft's Agent Framework. Some workflows are better served by plain code against a model API, and we will say so.
No. You own the source, the agent definitions and the evaluation sets outright. We keep orchestration logic separate from any one SDK and put models behind an interface you can swap, so changing framework or provider later is a migration rather than a rewrite.
Any of the major providers — Gemini, GPT, Claude — or open-weight models you host yourself. We choose per task, balancing quality, speed, cost and where your data is allowed to go, and we re-test when a better option appears.
Yes. Agents connect through APIs, databases and existing services, with each agent given only the permissions it needs.
Sensitive actions require human approval, every run is traced and logged, and you can see exactly what an agent did and why.
Yes. We deploy on Google Cloud, or in your own environment when data can't leave it.
Find the first workflow worth giving to an agent.
A 2-week AI readiness sprint: we map the opportunities, prototype the strongest one and hand you a costed plan.
There is a version of this industry where the goal is to get to launch.
Hit the date, take the photograph, move the team onto the next thing.
We have never worked that way, and the reason is simple: almost
everything we have built is still running.
The bill arrives later
A civil enforcement platform issues notices that get appealed months
after the fact. A telehealth system holds records a clinician will
open years after the consultation. A leave ledger has to reconcile in
the fourth fiscal year as cleanly as it did in the first. None of
those obligations exist on launch day. All of them are decided by
choices made long before it.
That is why we spend what looks like a disproportionate amount of time
on the parts of a system nobody demos — the audit trail, the
correction workflow, the migration path for historic data. Those are
not features you sell. They are the difference between a platform that
ages well and one that quietly becomes a liability.
Software that cannot explain itself becomes a liability the moment somebody asks it to.
Ownership changes the incentives
We hand over source, documentation and the automated test suite. Our
clients own what we build outright, and our own products are deployed
on their infrastructure rather than rented back to them by the seat.
That is partly principle and partly practical — a team that knows the
client can walk away builds differently from one that assumes they
cannot.
It also keeps us honest about complexity. When you know somebody else
will maintain the system, you stop being clever for its own sake.
Small team, long horizon
We are a subsidiary of Trillo, a recognised Google Cloud Partner, which
gives us enterprise cloud capability behind a team small enough to
care about the details. Our engineers sit close to the domain —
enforcement rules, clinical workflows, assessment logic — because that
is where the decisions that matter actually get made.
If you are choosing a partner, the question worth asking is not how
fast they can ship the first version. It is what the system looks like
in year three, and who will still understand it.
Most requirements describe what a system should do. In civil
enforcement, that is not enough. The system also has to be able to
explain, months later, why it did it — to somebody who disagrees.
The appeal is part of the workflow
When we worked on the Vehicle Management System, the thing that
reshaped my approach was realising that a notice is not the end of a
process. It is the start of one. Notices get appealed. Officers get
challenged. A record that says violation: yes is worthless if
it cannot also say which rule was applied, what the input was, and
who reviewed it.
So we stopped writing acceptance criteria that ended at the outcome.
Every rule got a second criterion: given this decision, can a
reviewer reconstruct how it was reached from the record alone?
Rules belong to the client, not the codebase
Parking conditions differ by site. Grace periods differ by shift.
Leave entitlements differ by grade. The instinct is to encode the
first version you are told about, and the consequence is a change
request every time policy moves.
The better question during discovery is not "what is the rule?" but
"who changes this rule, and how often?" If the answer is anyone other
than an engineer, it belongs in configuration. That one question has
saved more delivery time than any process I have introduced.
Ask who changes the rule, not just what the rule is. The answer tells you where it belongs.
Override, never overwrite
Every operational system needs a way for a human to disagree with it —
to excuse a late arrival, reverse an automatic absence, correct a
record entered in error. The failure mode is letting that override
erase the original.
Keep both. The system's calculation, the human's decision, the reason
and the reviewer. It costs almost nothing at write time and it is the
only thing that makes a difficult conversation fair — and provable.
Demo interfaces are built for a five-minute story with clean data.
Operator interfaces are built for somebody working a queue all day,
with data that is messy, incomplete and occasionally contradictory.
They are not the same product.
Density is a feature
The generous whitespace that makes a marketing screenshot look calm
becomes a liability when a case worker needs to compare twelve rows.
On enforcement and attendance screens we deliberately raise density:
more rows in view, tighter type, status carried by a coloured token
rather than a full-width banner.
The test is not whether it looks pleasant in a screenshot. It is
whether somebody can scan forty records and spot the two that need
attention without scrolling.
Build the empty, loading and error states first
In Angular work especially, it is tempting to build the happy path and
treat everything else as polish. We do it the other way round now. If
a screen cannot answer "what does this look like with no data, slow
data, or a failed request?", it is not finished.
Operators lose trust in a system the first time it shows them a blank
panel with no explanation. Trust is very expensive to win back.
An operator will forgive an ugly screen. They will not forgive one that lies about what it knows.
Keep the keyboard in mind
Anyone processing volume will stop reaching for the mouse within a
week. Tab order, focus management after a modal closes, submitting
without hunting for a button — these are not accessibility
afterthoughts, they are throughput features. They also happen to make
the product genuinely accessible, which is the right outcome arrived
at from a practical direction.
None of this is exotic engineering. It is mostly the discipline of
building for the hundredth hour rather than the first five minutes.
Adding a model to a product is now the easy part. The hard part is the
interface around it — because the moment software starts making
suggestions, users need to know how much to trust them.
Review, not transcription
On ExamPro, the system extracts tags and keywords from examination
questions. The temptation is to present that as finished work.
We designed it as a review task instead: the tags arrive as
proposals, the educator confirms or corrects them, and those
corrections feed back into the engine.
The framing matters more than the accuracy figure. A user who
understands they are reviewing will catch the mistakes. A user who
believes the work is done will not look.
Show the work, not just the answer
Wherever a suggestion can be traced to something concrete — the phrase
in the question that produced a tag, the record a summary came from —
surface it. Users calibrate their trust from evidence, and a system
that shows its reasoning gets more useful corrections back.
Present a model's output as a proposal and users check it. Present it as a result and they stop looking.
Latency is a design problem
Model calls are slow and variable in a way that ordinary API calls are
not. A spinner that sits for eight seconds reads as broken. Streaming
partial output, showing what stage the work is at, and keeping the
rest of the interface usable while it runs are all front-end
decisions, not infrastructure ones.
And the feature must degrade honestly. If the engine is unavailable,
say so and let the user proceed manually. Silently returning nothing
is how a promising feature gets switched off by the people it was
built for.
The telehealth platform we built serves five distinct roles. Each one
arrives with a different job, a different vocabulary and a different
tolerance for complexity. The design problem is not building five
interfaces. It is building one system that can present five honest
views of itself.
Start from the job, not the data model
A provider and a patient can look at the same consultation record and
need almost nothing in common from it. The provider needs history,
prescribing and documentation. The patient needs to know what was
decided and what happens next.
When you design outward from the shared data model, everyone gets a
slightly wrong screen. When you design inward from each role's actual
task, the shared model does its job quietly underneath — which is
where it belongs.
Scope is a design decision before it is a permission
Role-based access is usually treated as a security control bolted on
at the end. It is more useful as a design constraint at the start. A
manager who only ever sees their own team does not need a filter for
everyone else. Removing that filter makes the screen simpler and the
permission model easier to reason about at the same time.
The five things this person needs, not the forty they do not — that is the whole brief.
The seams are where products fail
Most of the pain in multi-role systems lives at the handovers: the
prescription passing to a pharmacy, the lab order returning a result,
the leave request reaching an approver. Those transitions deserve more
design attention than any single screen, because that is where users
currently fall back on phone calls and email.
If a handover inside your product is slower than a WhatsApp message,
people will use WhatsApp — and your system stops being the record.
The quickest way to model a leave balance is a column holding the
remaining days. It works immediately, and it fails the first time
somebody disagrees with the number.
The column cannot explain itself
When a balance lives in a single field, every change overwrites the
evidence of the previous one. An employee asks why they have
eleven days instead of twelve and nobody can answer without digging
through logs — assuming the logs captured it at all.
In the Employee Management Portal we model it the other way round.
Entitlements are credited per fiscal year, and every approval,
cancellation, adjustment and unpaid deduction is written to a ledger
as its own entry. The balance is the sum of those entries. It is never
typed by anyone.
What that buys you
Disputes stop being arguments and become queries. Corrections stop
being edits and become compensating entries with a reason attached.
And historic data can be imported at go-live as opening entries
rather than as invented starting numbers.
The same shape applies well beyond leave: asset custody, enforcement
case state, anything where "how did we get here?" is a question
somebody will eventually ask.
If your system stores an outcome without storing how it was reached, somebody will have to reconstruct it under pressure.
The costs, honestly
Derived balances mean more rows and more care around reads. You will
want an index strategy, and eventually a snapshot for performance —
but a snapshot you can always rebuild from the entries, never a
snapshot that becomes the truth.
That is the discipline: the ledger is authoritative, everything else
is a cache. Hold that line and the system stays explainable for as
long as it runs.