ENGINEERING TOPIC HUB

APIs, SaaS & System Architecture

This hub covers the boundaries that keep SaaS products understandable and safe: tenant context, authorization, API contracts, durable workflows, database isolation and explicit failure semantics.

QUESTIONS THIS HUB ANSWERS
01

Where is tenant isolation enforced?

02

How are retries made safe across services and jobs?

03

When is a modular monolith better than distributed services?

DECISION FRAMEWORK

Define the boundary, then choose the technology.

Protect the boundary

Derive tenant and authorization scope from trusted identity, never from an untrusted payload.

Make retries explicit

Idempotency keys, outboxes and durable inboxes are business correctness mechanisms.

Distribute only for a reason

Separate services when ownership, scaling or failure isolation justifies the coordination cost.

CURATED GUIDES

Continue with practical guides.

All articles →
Saudi commerce · Webhook operations

Salla webhook rotation: change endpoints without losing events

A production cutover plan for moving Salla webhooks between endpoints while preserving events, security, rollback and per-store subscription state.

Read the guide
AI infrastructure · Vector search

Qdrant multitenancy: isolate retrieval, scoring and storage

A production design for tenant-safe Qdrant retrieval: enforce scope in trusted code, separate sparse scoring populations and promote heavy tenants deliberately.

Read the guide
AI security · Anthropic CVP

Anthropic CVP: reduced cyber blocks need stronger architecture

Anthropic expanded CVP into three tiers. The real deployment work is identity, authorization, isolation, egress control, retention and revocation.

Read the guide
AI · Decision infrastructure

OpenAI Decisions API: build a decision system, not a magic threshold

OpenAI's Decisions API turns text and images into probabilities, choices and scores. The hard part is the policy around the answer.

Read the guide
AI infrastructure · Anthropic API

Anthropic Models API `line`: stop parsing model IDs

Anthropic added a model-family field to the Models API. Here is how to use it for discovery without confusing family, capability and release policy.

Read the guide
AI · Content provenance

OpenAI textGrain: what text watermarking can—and cannot—prove

OpenAI made text watermarking opt-in for select API models. This guide explains textGrain, detection limits and a safe provenance architecture.

Read the guide
Architecture · Distributed consistency

Transactional Outbox: fix dual writes without pretending they are atomic

A production guide to committing state and events together, then publishing through polling or CDC with ordering, idempotency and observable recovery.

Read the guide
AI · Speech generation

Gemini 3.8 TTS in production: voices, streaming and consent

A production guide to Gemini 3.8 Flash TTS and Flash-Lite covering model routing, streaming audio, reusable voices, consent, caching and evaluation.

Read the guide
AI agents · Runtime architecture

GPT-6 agent loops: async tools, steering and safe recovery

A production guide to GPT-6 async tool calling and mid-turn steering with pending-work registries, WebSocket recovery, approvals, budgets and observability.

Read the guide
AI infrastructure · API latency

OpenAI Ultrafast mode: engineer latency, not just token speed

A production guide to routing GPT-6 Astra Ultrafast requests with WebSockets, latency budgets, rate limits, residency checks, fallbacks and cost controls.

Read the guide
DevOps · Docker BuildKit

Secure Docker builds: fast caches without leaked secrets

A production guide to BuildKit layer, mount and registry caches; secret isolation; multi-stage runtime images; and verifiable SBOM and provenance.

Read the guide
E-commerce engineering · Shopify

Shopify bundles: design the cart transform contract

A production guide to fixed and customized Shopify bundles: composition, pricing, inventory, Cart Transform operations, failure policy and reconciliation.

Read the guide