Skip to content

Case study · Workforce operations and CRM

Zulivio: Workforce operations and CRM

Employees, attendance, work assignments and a sales pipeline on the company's own server.

My role
Lead developer.
Licence
AGPL-3.0
Links
Product siteSource on GitHub
Zulivio work assignments showing tasks across the workforce

Context

Zulivio is a self-hosted workforce-operations platform: employee records, attendance, work assignments, a live master dashboard and a sales CRM pipeline.

Problem

Growing teams track people, attendance and work in spreadsheets plus a per-seat CRM, so the data drifts between tools and the employee list lives in someone else's cloud.

Users

Administrators and managers, employees clocking shifts and breaks, and sales staff working a pipeline.

Operational workflow

Employees are created, edited, reset and removed under role-based control. Attendance moves through a shift and break state machine, and work assignments move through a guarded status flow so an assignment cannot jump to an invalid state.

Engineering challenge

Attendance is a good place to use an explicit state machine. A person cannot end a break they did not start, and the system should refuse that instead of recording nonsense.

Architecture

Zulivio is a pnpm and Turborepo monorepo. A NestJS backend exposes a REST API; a Next.js frontend communicates through a same-origin server-side proxy, so the browser uses a first-party session cookie and the backend stays behind the web service. PostgreSQL holds the relational records, with Prisma providing typed queries.

Shared TypeScript contracts live in a package imported by both sides. This matters when a field changes: the frontend and backend fail type-checking together instead of silently diverging.

Data model decisions

Employees, assignments, attendance sessions, leads and opportunities are related records, not separate spreadsheets. The attendance state machine has explicit states for logged out, working and on break; guarded transitions prevent an impossible work history from being recorded. Assignments have their own status-transition guard.

Backend

NestJS guards and decorators express the role hierarchy. API routes cover the employee lifecycle, work assignments, attendance, reports, a knowledge base and a sales pipeline. The repository also documents an MCP tool surface for controlled operations such as reading attendance state and starting or ending a session.

Frontend

The authenticated workspace is separate from login and setup routes. TanStack Query manages server-owned state and invalidates relevant queries after a mutation, which keeps a dashboard, employee list and assignment view in agreement without maintaining a second handwritten cache.

Security

Passwords use Argon2id. Sessions are opaque server-side tokens rather than irrevocable JWTs, so resetting or removing an employee can revoke their access. The same-origin proxy avoids a third-party cookie dependency, while route guards make role checks on the server, not only in the interface.

Infrastructure

One-click installer on the company's own server, with CSV and Google Sheets import and export for moving data in and out.

Reliability considerations

The install script checks for Docker, generates a database password if needed, starts the stack and waits for the backend's health check. Re-running it after an update rebuilds and restarts the services without touching existing data. Imports and exports provide a way to move records into or out of the system.

Difficult tradeoffs

Zulivio is an intentionally bounded workforce-operations slice of a larger roadmap. The repository separates what exists today from future multi-department plans. That is useful for a buyer and for development: a roadmap is not a feature list.

What I personally worked on

Lead developer.

Lessons learned

Workflow state is more than a status column. Expressing attendance and assignment transitions as rules makes invalid actions fail at the boundary, and gives tests something precise to assert.

Technologies

  • NestJS
  • Next.js
  • TypeScript
  • PostgreSQL
  • Prisma
  • TanStack Query
  • Docker

Screenshots

Captured from running instances.

Zulivio: frequently asked questions

What is Zulivio?
Zulivio is a self-hosted workforce-operations platform with employee records, attendance, work assignments, a master dashboard and a sales CRM pipeline.
How does attendance work?
Attendance is an explicit state machine with logged-out, working and on-break states. Invalid transitions, such as ending a break that was never started, are refused.
How are employee passwords and sessions protected?
Passwords use Argon2id and sessions are opaque server-side tokens, so resetting or removing an employee revokes access immediately.
Can data be exported?
Yes. Records can be imported and exported as CSV or Google Sheets.
Is it open source?
Yes, under the AGPL-3.0 licence on GitHub.

Read the full article: how Zulivio works →

Zulivio employee lifecycle managementZulivio attendance shift and break trackingZulivio work assignment trackingZulivio data hub with CSV and Google Sheets import and export

Expertise this project shows

Related articles

Official project links

Have something in mind?

Let’s build something useful.

Tell me about the idea, product, or workflow you’re working through.

Tap to say hello