PeopleOS
2026 · ~300-employee target · phased rolloutI built.One auditable system of record for HR, attendance and statutory payroll.
Go deeper
An original HR, attendance, statutory-payroll and workforce platform for a ~300-person Indonesian garment manufacturer, replacing a 291-column master workbook, a legacy Apps Script attendance app, paper leave forms and a macro-driven payroll spreadsheet with one auditable system of record. The ~300 is the company's headcount and the system's design target, not a count of people using it: the August 2026 cutover began a phased rollout that is still in progress.
Status: Cloud production since the August 2026 cutover, phased rollout in progress. Release v10.1.0 reached production on 3 Oct 2026, after its four database migrations were rehearsed on a restored copy of production; the current release, v10.4.0, followed on 9 Oct 2026. I promoted both.
What it does
At the August 2026 cutover (v9.30): 17 domain modules (identity, org, people, time, leave, payroll, approvals, performance, recruitment, reports, audit, theme, company, team, tasks, notifications, platform) over a 102-model Postgres schema. Three interface types (Admin / Manager / Employee) with Director-only role administration, effective-dated RoleAssignment history and field-level masking of identity, bank, BPJS and compensation data. Attendance is an append-only event ledger with audited void+replace edits; overtime is computed automatically from actual attendance with no request/approval workflow (confirmed as the company's real rule). Payroll runs through separately versioned rule engines in exact decimal arithmetic, snapshots every rate and threshold onto every result, and produces publish-gated HTML+PDF payslips plus a checksummed bulk-transfer file in the bank's own macro-enabled XLSM template. Also: 13 leave types, THR with automatic payroll inclusion, master-data import/export with preview → transactional apply → rollback, versioned contract PDFs, per-user liquid-glass themes, 30 reports, EN/ID localisation. The only model calls are in recruitment, where screening ranks, scores and recommends and a person decides; nothing probabilistic sits between an attendance event and a payslip. Since September 2026 every merged change ships as one immutable image through staging and smoke tests. Changes to payroll, leave, shared calculations, the database layer, access control or the recruitment AI wait at staging until I promote that exact image, and an integrity compare after every production release rolls it back if anything protected moved. A push that carries a migration releases nothing, so schema changes go in separately, ahead of the code.
- Next.js 16 (App Router, Server Actions)
- React 19
- TypeScript
- PostgreSQL
- Prisma 6
- Tailwind CSS 4
- decimal.js
- argon2id (@node-rs/argon2)

