Case study · Workforce operations and CRM
Zulivio: Workforce operations and CRM
Employees, attendance, work assignments and a sales pipeline on the company's own server.
- My role
- Lead developer.
- Licence
- AGPL-3.0

Context
Zulivio is a self-hosted workforce-operations platform: employee records, attendance, work assignments, a live master dashboard and a sales CRM pipeline.
Problem
Growing teams track people, attendance and work in spreadsheets plus a per-seat CRM, so the data drifts between tools and the employee list lives in someone else's cloud.
Users
Administrators and managers, employees clocking shifts and breaks, and sales staff working a pipeline.
Operational workflow
Employees are created, edited, reset and removed under role-based control. Attendance moves through a shift and break state machine, and work assignments move through a guarded status flow so an assignment cannot jump to an invalid state.
Engineering challenge
Attendance is a good place to use an explicit state machine. A person cannot end a break they did not start, and the system should refuse that instead of recording nonsense.
Architecture
Zulivio is a pnpm and Turborepo monorepo. A NestJS backend exposes a REST API; a Next.js frontend communicates through a same-origin server-side proxy, so the browser uses a first-party session cookie and the backend stays behind the web service. PostgreSQL holds the relational records, with Prisma providing typed queries.
Shared TypeScript contracts live in a package imported by both sides. This matters when a field changes: the frontend and backend fail type-checking together instead of silently diverging.
Data model decisions
Employees, assignments, attendance sessions, leads and opportunities are related records, not separate spreadsheets. The attendance state machine has explicit states for logged out, working and on break; guarded transitions prevent an impossible work history from being recorded. Assignments have their own status-transition guard.
Backend
NestJS guards and decorators express the role hierarchy. API routes cover the employee lifecycle, work assignments, attendance, reports, a knowledge base and a sales pipeline. The repository also documents an MCP tool surface for controlled operations such as reading attendance state and starting or ending a session.
Frontend
The authenticated workspace is separate from login and setup routes. TanStack Query manages server-owned state and invalidates relevant queries after a mutation, which keeps a dashboard, employee list and assignment view in agreement without maintaining a second handwritten cache.
Security
Passwords use Argon2id. Sessions are opaque server-side tokens rather than irrevocable JWTs, so resetting or removing an employee can revoke their access. The same-origin proxy avoids a third-party cookie dependency, while route guards make role checks on the server, not only in the interface.
Infrastructure
One-click installer on the company's own server, with CSV and Google Sheets import and export for moving data in and out.
Reliability considerations
The install script checks for Docker, generates a database password if needed, starts the stack and waits for the backend's health check. Re-running it after an update rebuilds and restarts the services without touching existing data. Imports and exports provide a way to move records into or out of the system.
Difficult tradeoffs
Zulivio is an intentionally bounded workforce-operations slice of a larger roadmap. The repository separates what exists today from future multi-department plans. That is useful for a buyer and for development: a roadmap is not a feature list.
What I personally worked on
Lead developer.
Lessons learned
Workflow state is more than a status column. Expressing attendance and assignment transitions as rules makes invalid actions fail at the boundary, and gives tests something precise to assert.
Technologies
- NestJS
- Next.js
- TypeScript
- PostgreSQL
- Prisma
- TanStack Query
- Docker
Screenshots
Captured from running instances.
Zulivio: frequently asked questions
- What is Zulivio?
- Zulivio is a self-hosted workforce-operations platform with employee records, attendance, work assignments, a master dashboard and a sales CRM pipeline.
- How does attendance work?
- Attendance is an explicit state machine with logged-out, working and on-break states. Invalid transitions, such as ending a break that was never started, are refused.
- How are employee passwords and sessions protected?
- Passwords use Argon2id and sessions are opaque server-side tokens, so resetting or removing an employee revokes access immediately.
- Can data be exported?
- Yes. Records can be imported and exported as CSV or Google Sheets.
- Is it open source?
- Yes, under the AGPL-3.0 licence on GitHub.




Expertise this project shows
Related articles
- Self-hosted employee attendance, work assignment and CRM software: how Zulivio models workflow
- Best CRM for a small business: how to choose, and HubSpot and Salesforce alternatives
- ERP vs CRM: what each one does and which you need first
- Attendance and workforce management software: what a small company needs
- An audit trail and an application log answer different questions
- Model approvals as state transitions, not a chain of buttons