JR
Approach

A studio, not an agency.

We work the way good product teams work. Spec before code. Schema before screens. Observability and audit on day one, not retrofitted in month six.

Delivery framework

Three phases, three gates, one spine.

Every engagement runs this shape. Phases move left to right and only advance through a gate — a named artifact you have seen and agreed to. The spine underneath is not a phase; it is work that happens in all of them. Two weeks, four to twelve, one — then sixty days of warranty.

SOD-JR · DELIVERY FRAMEWORK REV 1.0 GATE 1 GATE 2 GATE 3 SPEC SIGNED PROD READY RUNBOOK ACCEPTED 01 · DISCOVERY 2 WEEKS Decide what done means Spec and schema sketch Threat model Success metrics OUT · WRITTEN SPEC 02 · BUILD 4–12 WEEKS Ship in two-week loops Sprint, demo, correct Roadmap visible throughout You see Friday’s build OUT · RUNNING SYSTEM 03 · HANDOVER 1 WEEK Give it away properly Runbook and walkthrough On-call rotation handed over Your team runs it OUT · OWNERSHIP 04 · WARRANTY 60 DAYS Reachable, not resident Defects on us Questions answered No lock-in by design OUT · CLEAN EXIT CONTINUOUS · NOT A PHASE · PRESENT FROM DAY ONE Audit trail Every mutation, with context Observability Logs, traces, error budgets Security & RBAC Authorisation in the database Docs & tests Written as we go, not after IN · SPREADSHEETS, HANDOFFS, TRUST OUT · A SYSTEM YOUR TEAM RUNS WITHOUT US
Gate 1 · Spec signed

No code starts until the spec, schema sketch, threat model and success metrics are written down and you have agreed to them. If discovery says the project shouldn’t happen, that is a valid outcome and you keep the document.

Gate 2 · Production ready

Migrations reversible and running in CI, authorisation enforced at the database, audit and observability live, tests green. A build that only works on a laptop has not passed this gate.

Gate 3 · Runbook accepted

Your engineers have run the system without us in the room — deploy, rollback, restore, and the three things most likely to page someone at 2am. Handover ends when they can, not when we say so.

Patterns we believe in
  • Event sourcing in audit-heavy domains. Every mutation is an event with full context — IP, user agent, session, before / after.
  • RLS over middleware. Authorisation lives in the database where it can’t be bypassed. The app is a UI on top, not a gatekeeper.
  • Type-safe APIs. If the schema is right, half the bugs never exist.
  • Schema-as-truth. Migrations live in code, run in CI, are reversible. There is no “production drift” on our watch.
  • Idempotency by default. Replaying a webhook should not double-charge anyone.
  • Observability from day one. Logs, traces, error budgets — not bolted on when production breaks.
What we don’t do
  • White-label your work or pretend we built nothing.
  • Hand you a Figma and disappear. Anything we design we also ship.
  • Sell you AI you don’t need. The default is “do you actually need a model here?”
  • Lock you into us. Documentation, runbooks and tests on handover — or you have us by the throat, which is fine, but not how we build.

Start with a scoping audit.

Two weeks. We come back with a spec, schema sketch, threat model and success metrics. Applies against the full engagement if you continue.

Book a scoping audit