Case study 02
A community platform, delivered early
A private community platform for a network of US Navy SEALs - 34+ data models and real-time messaging - delivered three months inside its original scope.

Outcome
Scoped 8 months. Shipped in 5.
- Scope
- 8 months
- Delivery
- 5 months
- Data models
- 34+
Context
A private community platform for a network of US Navy SEALs, serving and retired: personalized feeds, groups, direct messaging, professional opportunities, and content discovery - an admin dashboard and a mobile application consuming the same API. Scoped at eight months; shipped in five.
The problem
High read/write throughput across personalized feeds, group content, real-time messaging, and engagement tracking - with feed personalization that couldn't afford expensive joins across millions of relationship records, and strict role separation between admin-dashboard and mobile-app access to one shared API.
The outcome
For the business: the platform launched three months inside its scoped timeline, real-time messaging and all. For the system: scalable feed personalization, horizontally scalable WebSockets, and a clean separation between synchronous API work and asynchronous background processing.
The approach
A modular NestJS backend spanning 11+ domain modules over MySQL with 34+ models - social entities, groups, messaging, professional features, moderation - with a Next.js admin dashboard in front.
A dual-feed architecture: a personalized feed filtered by followed users and joined groups, and a global discovery feed with visibility-based filtering. Pagination uses JWT-encoded cursors - I chose stateless cursors over offset pagination because offsets degrade exactly where feeds matter most: deep in an active timeline.
Real time that can scale sideways: Socket.io behind a Redis adapter, room-based broadcasting for direct and group messages, JWT-authenticated socket connections.
Side effects out of the request path: Bull with Redis runs 11 specialized processors - post-creation side effects, email dispatch, badge assignment, tag reconciliation, notification delivery - in worker processes separated from the API.
Passwordless magic-link authentication with access/refresh token rotation, and scope-based authorization enforced by custom decorators - the admin dashboard and the mobile app share an API without sharing permissions.
Built with