Live portfolio trace / Lusaka, Zambia

Samuel Kaoma

I build systems where being wrong is expensive.

Software Engineer at AVEC Technologies. Settlement cores, forensic evidence engines, and multi-tenant platforms — across Go, Java, Python, and TypeScript.

Interactive Simulation

Live Stream Anomaly Engine

Total Ingested20
Anomalies0
Raw Data StreamThreshold CheckStatistical TestAnomaly ScoringFlagged Result
Raw Data StreamTap a node to inspect

Ingests raw time-series measurements from remote water-level sensors and survey paradata endpoints.

Active MetricsReading: 35.5 m Status: nominal
// Ingest data packet stream
stream.on("data", (packet) => {
  ingestBuffer.push(packet.value);
});
Delay2.0s
Live
System Log TerminalPipeline connection: secure
Awaiting sensor ingestion metrics stream...

Traversing the archive

One signal, many systems.

Follow the route as the active packet inspects each project surface: settlement, forensic evidence, regulatory compliance, clinical operations, infrastructure monitoring, agritech, and research pipelines.

Signalnominal01 / 13
  1. A national payment-system settlement core built around the Bangladesh Bank failure mode: above a value threshold, funds move only when t independent authorisers have each signed that specific transfer — so a compromised endpoint yields one signature and settles nothing.

    Implemented the core as a single-writer deterministic state machine — no wall-clock reads, no floating-point money, no order-dependent map iteration — making event-sourced replay byte-reproducible; all three prohibitions are enforced by architecture tests rather than convention.

    Delivered an ISO 20022 participant gateway over mTLS with idempotency and signature verification, a multi-tenant React bank portal with in-browser Merkle inclusion and consistency proofs, and a C#/WPF operator console with two-person emergency suspension.

    Backed 79 delivered features with a measured 1,059 core tests and 74 portal tests — zero failures, zero skips — plus 280 mutation probes. Each probe edits one production line and requires the suite to fail; surviving probes exposed an entirely untested browser session layer and a gridlock-resolution path that bypassed the settlement check.

    Java 21C# / .NET 8ReactTypeScriptC (PKCS#11)PostgreSQLISO 20022
  2. A case-linkage engine that reports how much the available evidence shifts the odds that two incidents share an actor — as a calibrated likelihood ratio that always carries its prior, and with no vocabulary for asserting identity.

    Implemented the full speaker-evidence stack from first principles — GMM-UBM by EM, i-vector total-variability extraction, LDA/WCCN, and two-covariance PLDA with the exact closed-form log-likelihood ratio — against NumPy and SciPy alone, with no deep-learning framework required. A borrowed pre-trained extractor sits behind an optional dependency and an architecture boundary, benchmarked against the reference stack rather than replacing it.

    Built the DSP front end (MFCC/LFCC, VAD, LPC formant estimation, YIN pitch tracking, jitter/shimmer/HNR), an analysis-by-synthesis CELP narrowband channel model, and an LFCC/GMM spoofing countermeasure with an explicit out-of-domain indicator.

    Encoded three guarantees in the type system: absence carries its reason instead of collapsing to LR = 1, a likelihood ratio cannot exist without an explicit justified prior, and uncalibrated scores are unreportable. A build-time check fails if the vocabulary of identification appears in any emittable string.

    PythonNumPySciPyHypothesisFastAPI
  3. A two-product platform on one identity and permission system: a training and admissions pipeline, and a full commercial CRM running leads to deals to quotations to contracts to payments — with document versioning, contract signing, an aged debtor book, and value-based approval controls.

    Extended it through the buy side — sourcing, purchase orders, goods receipt, landed-cost allocation and per-deal margin — over a stock ledger with transaction-scoped, self-rolling-back database tests.

    Secured sessions with JWT access tokens plus rotating refresh tokens in httpOnly cookies, pluggable S3-compatible storage, and per-route permission enforcement documented route by route.

    Diagnosed a silent-CI class of failure and reproduced it on demand: without DATABASE_URL, 69 of 145 tests skip while all seven packages still report ok and the command exits 0 — precisely the approvals, stock-ledger, landed-cost and payables tests. CI sets the variable, so CI has always run the full suite; it is local runs that quietly do not.

    GoEchoGORMPostgreSQLReact 19TypeScriptVite
  4. A compliance engine that turns Zambian building regulation into executable rules and returns a citation-carrying, byte-reproducible verdict — then generates layouts against those same rules and re-judges every candidate before offering it.

    Made provenance a type invariant: a GroundedValue cannot be constructed without a ValueOrigin, so no verdict can rest on an unscaled or unsourced measurement, and a customary boundary cannot support a violation asserted inside its own positional error.

    Compiled applicable rules plus a household brief into CP-SAT constraints that each carry the rule that produced them, then re-judged every generated layout with the compliance engine — which caught the solver placing buildings on the very setback they were generated to satisfy.

    Designed the orchestration grounding layer so a language model cannot originate a number: tools return registered value references, the facade refuses raw numeric arguments, and a validator rejects any draft containing a numeral the session never obtained.

    PythonGoogle OR-Tools CP-SATShapelypytest
  5. A tenant-scoped hospital operations platform covering patient records, visit queues with triage priority, clinical diagnosis capture, ICD-10 and CPT coding lookups, WHO benchmarking, pharmacy stock, and invoicing.

    Built the pharmacy and revenue side: stock receipt and adjustment ledgers, dispensation history, low-stock and expiry alerting, FDA drug lookup, drug-interaction checking, and invoice finalisation into a billing cycle.

    Built the tenant onboarding lifecycle on top of a colleague's ControlHub provisioning plane — document submission with timeline tracking, activation emails, admin setup links, and the admin review flow — over middleware-enforced tenant scoping. It is the only module in the codebase carrying its own tests.

    Layered RBAC with per-user permission overrides and audit logging on every state change, with a React 19 operator front end over the Go/Echo service layer.

    GoEchoPostgreSQLJWTReact 19TypeScriptVite
  6. Flagship build
    SmartFarmer SKACE product interface

    The heaviest build in the archive — a multi-tenant platform that turns everyday Zambian farm activity into evidence a lender can trust: GPS-verified attendance, cadastre-verified location, and satellite-verified crop growth, folded into a cryptographically signed farm track record and transparent credit score.

    4Services, one repo
    RLSTenant isolation
    SignedLender track record

    Built as four cooperating services in one repo — a Go/Echo API, a React + Vite dashboard, an Expo mobile app for field workers, and a Python/XGBoost yield-prediction service.

    Verifies farm claims against independent, hard-to-fake sources: Sentinel-2 NDVI (Copernicus), the ZNSDI cadastral geoportal, and GPS geofencing — surfaced as a signed, QR-verifiable lender report.

    Enforces tenant isolation at two layers — request-scoped middleware plus PostgreSQL Row-Level Security that fails closed — with Go, Vitest, and Python test suites all passing.

    GoEchoPostgreSQLReactExpoPythonXGBoost
    Open case study
  7. Flagship build
    Z-SIMP Operational Demo Platform product interface

    A modular monitoring platform for sensor-driven water and infrastructure oversight with dual-mode ingestion (real public telemetry plus a synthetic disaster simulator), anomaly detection, incident workflows, and province-aware operational visibility.

    DualLive + sim data modes
    IQRInterpretable detection
    InfluxDBTime-series store

    Combined rolling IQR baselines, domain rules, and IsolationForest as a supporting detector.

    Built secure dashboards, public status surfaces, incident command actions, and audit-aware response flows.

    Designed for operational scale with FastAPI services, persistence layers, and notification simulation.

    FastAPIReactVitePostgreSQLInfluxDBScikit-learnTailwind CSS
    Open case study
  8. A rental platform for appliance inventory, requests, payments, customer access, and admin review with a clean split between public browsing and protected operational workflows.

    Implemented admin and customer portals with credentials-based authentication.

    Designed inventory, request, payment-proof, and reminder flows around a Prisma data model.

    Production build passed during the audit.

    Next.jsReactPrismaPostgreSQLNextAuthTailwind CSS
    Open case study
  9. Flagship build
    Survey & ODK Paradata Platform product interface

    A research-grade feature extraction and anomaly-detection platform for mobile survey paradata, paired with an analytics dashboard for exploration, statistics, and honest evaluation against ground truth.

    40Engineered features
    IQRRobust anomaly detection
    76.1%F1 vs ground truth

    Engineered a four-layer validation pipeline across parsing, feature extraction, validation, and anomaly scoring.

    Backed the work with a meaningful pytest suite including end-to-end threshold assertions.

    Current test run surfaced one real failure where `ODK403` was classified as normal, which is the kind of signal a real audit should expose.

    PythonFastAPIPandasNumPyReactVite
    Open case study
  10. Accounting workflows covering balances, expenses, invoices, recurring items, reports, and transaction visibility.

    Built authenticated dashboard surfaces around financial operations and reporting.

    Used Drizzle, Postgres, PDF tooling, and a component-driven UI system.

    Current build is blocked locally by a missing `styled-jsx` dependency, despite the codebase itself being substantial.

    Next.jsDrizzle ORMPostgreSQLReactRecharts
  11. A relationship wellness product focused on communication, mood broadcasting, check-ins, and relationship health signals.

    Blended emotional product design with dashboards, shared timelines, and couple workflows.

    Prepared the architecture for Supabase auth, realtime features, and analytics.

    Current local build is blocked because the `next` command is unavailable in that project environment.

    Next.jsSupabaseReactTailwind CSS
  12. A document intelligence and management concept for institutional operations, archives, and administrative insight, with a richer frontend than backend implementation today.

    Positioned as a centralized system for secure digital archives, analytics, and approval workflows.

    Frontend production build passed during the audit.

    Pairs a strong branded frontend with a backend that is still close to the starter scaffold.

    Next.jsNestJSFramer MotionTypeScript
  13. A hybrid codebase that currently combines transport marketplace flows with collaboration-oriented APIs, making it one of the more interesting product-transition stories in the archive.

    The implemented home experience points to a Zambia-focused transport marketplace rather than only a workspace tool.

    API routes still include tasks, spaces, analytics, and collaboration modules alongside marketplace flows.

    Production build passed, but the narrative must stay honest about the repo drift.

    Next.jsReactSupabaseTypeScriptTailwind CSS

trace.complete

Systems thinking, carried through the whole build.

Current Focus

Universal SaaS For
Institutional Teams.

Building a universal multi-tenant SaaS platform for Zambian parastatal bodies, government agencies, and higher-learning institutions — middleware-driven tenant scoping, role-and-permission RBAC with per-user overrides, audit logging, and workflow automation.

Current roleSoftware Engineer at AVEC Technologies
EducationBachelor of Science in Computer Science

Built the clinical, pharmacy, billing, and onboarding modules of IntelliHealth, a multi-tenant hospital platform on a Go/Echo/PostgreSQL service layer with a React 19 operator front end, working alongside a colleague who owned the tenant-provisioning plane.

Own end-to-end delivery: domain modelling, API contracts, schema migrations, front-end implementation, and production deployment for low-bandwidth institutional users.

Experience

March 1, 2026 - Present

Software Engineer

AVEC Technologies

Building a universal multi-tenant SaaS platform for Zambian parastatal bodies, government agencies, and higher-learning institutions — middleware-driven tenant scoping, role-and-permission RBAC with per-user overrides, audit logging, and workflow automation.

November 2025 - February 2026

ICT Intern - e-Government Division

Smart Zambia Institute (Office of the President)

Completed an ICT internship with direct exposure to enterprise government infrastructure, systems development, networking, planning workflows, ICT support, and confidential operational handling.

Core Tools & Context

Java 21

Zero-dependency settlement domain and single-writer deterministic core for the SKACE settlement platform.

Go & Echo

Production API for the Arcus commercial suite and the IntelliHealth multi-tenant clinical platform.

FastAPI

High-throughput ingestion layer for Z-SIMP sensor feeds and ODK anomaly scoring.

PostgreSQL

Primary datastore with Row Level Security for SmartFarmer and an append-only ledger for settlement.

NumPy & SciPy

GMM-UBM, i-vector, and PLDA implemented from first principles in VIFLAP — no deep-learning framework.

Mutation probes

128 probes across SKACE that edit one production line and require the test suite to fail.

Cisco Linux ProgramCisco IT EssentialsCCNA

Resume & Credentials

Experience, education,
and credentials in one place.

Browse the resume online for a clear view of experience, project range, and technical background. A downloadable PDF is available when needed.

Current Focus

Software Engineer

AVEC Technologies

March 1, 2026 - Present

Built the clinical, pharmacy, billing, and onboarding modules of IntelliHealth, a multi-tenant hospital platform on a Go/Echo/PostgreSQL service layer with a React 19 operator front end, working alongside a colleague who owned the tenant-provisioning plane.

Own end-to-end delivery: domain modelling, API contracts, schema migrations, front-end implementation, and production deployment for low-bandwidth institutional users.

Education

Bachelor of Science in Computer Science

University of Zambia

Expected Graduation: 2026

Relevant coursework: Data Structures and Algorithms, Database Systems, Operating Systems, Computer Networks, Software Engineering, Numerical Analysis, and Discrete Structures.

Registry & Audit Log

The Audited Codebase
Registry

A transparent index of all system codebases audited for this archive. Every project is inspected for architecture structure, data models, and quality controls.

13 of 13 systems

System & FocusArchitecture & DataQuality Signals & Audit NotesAction

SKACE Settlement Platform

Finance / Sovereign Payment InfrastructureFinance

"The most technically demanding system in the archive, and the one whose verification story is strongest. It is explicitly not deployed and not production-ready; known gaps are tracked in HANDOFF.md rather than hidden."

Architecture

Polyglot: a zero-dependency Java 21 settlement domain, an application layer of commands and event-sourced replay, infrastructure for ISO 20022 / mTLS / PKCS#11 / PostgreSQL, three separate gateway composition roots, a C# WPF operator console, a React portal, and a C PKCS#11 shim that holds no business logic.

FE:React + TypeScript bank portal showing position and queue, with in-browser Merkle inclusion and consistency proof verification against a signed tree head. A separate C#/.NET 8 WPF console handles queue management, business-day control, and two-operator suspension.
BE:A single-writer deterministic settlement core: (State, Event) to (State, Effects). Concurrency lives only at the edges — parsing, validation, I/O — never at the point of posting. Two listeners with no code path from a bank to an operator command.
Data/Auth:One shared append-only ledger with tenant-filtered projections; a TenantView is the permission, with no parameter for someone else's data. mTLS throughout, PKCS#11 signing, and t-of-n distinct authoriser signatures above the value threshold.
Maturity: 79 of 79 planned features passing; not deployed, and honest about it
Measured 2026-09-02: 1,059 core tests and 74 portal tests, 0 failures, 0 errors, 0 skipped
280 mutation probes across 12 scripts, covering 79 features that all pass
Mutation probes edit one production line and require the suite to fail
A cached `./gradlew build` returns BUILD SUCCESSFUL in 18s having run no test at all — the forced re-run on the same commit found a real intermittent TLS failure the cache had hidden
The C#/.NET console suite is excluded from every figure above: the machine has the .NET 8 runtime but no SDK, so it cannot be built or run
Probes caught an entirely untested browser session layer, a TLS 1.3 context still enabling TLS 1.2, and gridlock resolution bypassing the settlement check
Seven invariants — conservation, liquidity, immutability, finality, authorisation, sequence, determinism — each traced to design decisions
Standing prohibitions enforced at the database role and by architecture tests, not by convention
Four ISO 20022 schemas are faithful synthetics under the real namespaces because the official ones are licensed
Audit Only

VIFLAP

Research Engineering / Forensic StatisticsResearch

"The rarest signal in the archive: a system engineered so that overclaiming is structurally impossible, and one that reports its own negative results rather than the best cell."

Architecture

Five layers with dependencies pointing inward only — domain (standard library only), analysis (numpy/scipy, no I/O), evaluation, application against ports, infrastructure adapters, and interfaces. The rule is enforced by parsing the import graph in tests, not documented in a README.

FE:HTTP API and command line only. There is deliberately no live path: nothing accepts a stream, a socket, or a partial buffer.
BE:Every model is trained from data — GMM-UBM by EM, i-vector total variability, LDA/WCCN, two-covariance PLDA with the exact closed-form LR, an analysis-by-synthesis CELP channel model, an LFCC/GMM spoofing countermeasure, conjugate models for non-acoustic evidence, and four fusion strategies with dependence modelling.
Data/Auth:Hash-chained, append-only, fsync-before-acknowledge audit; refused and empty queries are recorded; the prior is logged with every query; separation of duties is enforced by a Principal object that refuses to exist for incompatible authority pairs.
Maturity: Reference implementation for a doctoral proposal; one hypothesis tested end to end
Measured 2026-09-01: 832 tests collected, 832 passed, 0 failures, 0 skips — unit, property-based (Hypothesis), integration, API contract, and architecture
The two advertised build-time gates are real: an import-graph layering test, and a check that fails the build if the vocabulary of identity reaches an emittable string or identifier
Trained on 306 LibriSpeech speakers, evaluated on 102 held out from training and calibration
30-cell sweep with bias-corrected intervals reported as 0 supported, 6 falsified, 24 inconclusive — decided on the interval, never the point estimate
A conclusion that was wrong is withdrawn in place, with the wrong version and the reason preserved
A build-time check fails if the vocabulary of identification appears in any emittable string — a field named match_score fails the build
Audit Only

Arcus Investments Platform

Finance / Production B2B SaaSFinance

"The clearest evidence of production ownership in the archive — deployed, operated, documented for non-engineers, and with its own failure modes written down rather than discovered by the next person."

Architecture

Two products in one codebase sharing a single identity and permission system, split across two git repositories — a Go/Echo/GORM backend and a React 19 + Vite SPA — deploying independently from main on CI green.

FE:React 19, TypeScript, React Router, Radix primitives for unstyled behaviour, and Framer Motion, with plain CSS rather than a component kit. Public marketing site, enrollment forms, product catalogue, events manager, and a deliberately unlinked staff sign-in.
BE:Go and Echo over PostgreSQL: admissions and training pipeline, commercial CRM from leads through payments, buy-side sourcing and purchase orders with landed-cost allocation, an aged debtor book, document versioning, contract signing, and value-based approval controls.
Data/Auth:JWT access tokens plus rotating refresh tokens in an httpOnly cookie, pluggable storage (local disk to S3-compatible), Resend or SMTP email, and per-route permission enforcement documented route by route.
Maturity: Built, CI-gated, and deployed to Railway (the demo instance is not currently provisioned)
Measured 2026-09-01: 145 top-level tests; go build and go vet both clean on Go 1.26.1
Frontend carries no test suite at all — its verification is a typecheck plus a build
DB-backed tests run in a transaction that is rolled back, so a run leaves the database as it found it
Reproduced the silent-CI failure mode on demand: without DATABASE_URL, 69 of 145 tests skip while all seven packages print ok and the command exits 0 — precisely the approvals, stock-ledger, landed-cost and payables tests
Lint gate at 0 errors with a known 8-warning baseline, none of them no-explicit-any
Five maintained documents: architecture, security, API, operations, and a non-technical user manual
Audit Only

SKACE Architect

Research Engineering / Regulatory SystemsResearch

"A system whose most impressive property is what it refuses to do. The corpus honesty — publishing the placeholder ratio getting worse rather than hiding it — is the kind of signal that survives technical scrutiny."

Architecture

Foundation (units, grounded values, a geometry kernel that is the only place Shapely is imported), domain (regulation, design, site, compliance) depending on nothing but foundation, application services, and infrastructure adapters implementing domain ports.

FE:A command line: skace validate, skace check, skace curate, and skace stats — with human-readable verdicts that name the rule that emptied a buildable envelope and the reason a finding was downgraded.
BE:A closed PredicateKind enum with all seven evaluators implemented; a CP-SAT layout solver whose constraints each carry the rule that produced them; and a curation console that refuses publication for an unknown source, fewer than two test cases, a failing test case, or an author signing off their own work.
Data/Auth:A versioned Zambian rules corpus with schema, jurisdictions, sources, provisions, and manifests. Verdicts are byte-reproducible via Decimal quantization, content-addressed value refs, canonical JSON, and immutable ruleset binding.
Maturity: Elaboration iteration E2–E3; compliance spine complete
Measured 2026-09-01: 327 tests, 0 failures, in 121s — domain invariants, engine behaviour, architecture conformance, per-evaluator behaviour, curation refusals, grounding enforcement, and every rule's own declared test cases
An architecture test fails the build if anything under skace.domain ever reaches a language model — written before the orchestration layer existed
The grounding layer makes it impossible for a model to originate a number; tools that would let one waive a finding do not exist at any tier
The README states plainly that 11 of 14 seed rules carry UNVERIFIED_PLACEHOLDER values and must not be relied on
skace validate prints the placeholder count on every run
Audit Only

IntelliHealth

Healthtech / Multi-tenant SaaSHealthtech

"The strongest example of ordinary commercial delivery in the archive: a real domain, real tenants, and a deliberate template distillation rather than a copy with features removed."

Architecture

Go/Echo modular monolith: db connection manager and migrations, models, middleware (JWT, tenant, RBAC, audit, CORS), and feature modules each split into handler, service, and DTOs.

FE:React 19 + TypeScript + Vite operator interface with Tailwind CSS, Radix UI, Framer Motion, React Router v7, and protected routes by account type.
BE:Clinical (patients, visit queues with triage priority, diagnosis capture), coding (ICD-10, CPT, WHO benchmarking), billing (line items, invoice finalisation), inventory and pharmacy (stock receipt and adjustment ledgers, dispensation history, low-stock and expiry alerts, FDA lookup, drug-interaction checks), onboarding, and a ControlHub tenant-provisioning plane.
Data/Auth:PostgreSQL with middleware-driven tenant scoping (WHERE clauses applied automatically) and a single-tenant fallback mode; JWT auth; RBAC with roles, permissions, and per-user overrides tracked with reasoning; audit middleware on every state change; statement timeouts to prevent query runaway.
Maturity: Shipped at AVEC Technologies on a hardened Go template
Multi-tenancy is infrastructure, not a per-query convention
Permission overrides are recorded with their justification
Three explicit architectural patterns (new module, thin wrapper, infrastructure) documented to prevent pattern drift
Measured 2026-09-01: go build and go vet both clean; the whole backend carries 5 test functions in 1 file (modules/onboarding), all passing; the frontend has no test suite at all
A team build, unlike the rest of this archive: git history shows 8 backend commits, 6 by Samuel (pharmacy inventory, onboarding lifecycle, clinical triage desk, billing checkout, automated invoicing) and 2 by a colleague (the initial template and the ControlHub provisioning implementation)
By far the thinnest verification story here — it is presented as delivery work, not as an engineering-rigour exhibit
Audit Only

Z-SIMP Operational Demo Platform

GovTech / InfrastructureGovTech

"This reads like a serious systems demo rather than a simple dashboard mockup. It is one of the clearest proofs of system-design depth in the archive."

Architecture

Split FastAPI backend, React/Vite frontend, and infra folder with Docker Compose plus Nginx.

FE:Operational command UI with panels for alerts, approvals, audits, coverage, public portal, response checklists, and live sensor monitoring.
BE:Python services for auth, detector logic, incident engine, event bus, notifications, simulator, and persistence adapters.
Data/Auth:PostgreSQL plus InfluxDB persistence, simulated sensor ingest, JWT login, and province-aware responsibility chains.
Maturity: Most technically expansive system in the archive
Strong top-level README with implementation detail
Infra assets present under /infra
Large component surface on the frontend
Frontend production build passed during this audit
Measured 2026-09-02: 44 backend tests, 44 passed, 0 failures, in 95s — test_api (11), test_auth (13), test_detector (9), test_live_feed (5), test_settings (6)
The detector threshold is a real constant, not a claim: ml_min_train_points defaults to 200, so IsolationForest cannot activate before that and never overrides the interpretable IQR baseline
DATA_MODE is validated against a closed set and raises on anything else, which is what makes the live-versus-simulation provenance banner trustworthy rather than decorative
Case Study

SmartFarmer SKACE

Agritech / Trust SystemsAgritech

"Architecturally the strongest system in the archive — polyglot, security-minded, and integration-heavy — but still best presented as a production-minded MVP rather than a finished enterprise deployment."

Architecture

Four cooperating services in one repository: a Go/Echo API, a React + Vite web dashboard, an Expo React Native mobile app, and a Python/XGBoost ML service. (A dormant Next.js app remains at the repo root from an earlier iteration and is not the active product.)

FE:React 19 + Vite owner and manager dashboard (farm records, lender track record, satellite health) plus an Expo mobile app for field workers (GPS attendance, tasks, AI crop scanner).
BE:Go/Echo API with JWT auth, route-level RBAC, tenant middleware, cryptographic signing of the track record, and integrations for satellite NDVI, cadastre, weather, and AI advisory.
Data/Auth:PostgreSQL with Row-Level Security enforcing tenant isolation at the database, layered under request-scoped tenant middleware so cross-tenant access fails closed.
Maturity: Production-minded MVP
Four-service architecture (Go, React, Expo, Python) in one coherent monorepo
Two-layer tenant isolation: tenant middleware plus PostgreSQL Row-Level Security
Verification against independent sources: Sentinel-2 NDVI, ZNSDI cadastre, GPS geofencing
Cryptographically signed, QR-verifiable lender track record with tamper detection
Automated tests pass across backend (Go), web (Vitest), and ML (Python unittest)
Detailed, honest README plus a technical report and audits under /docs
Case Study

SKACE Rent

Workflow SaaSSaaS

"This is one of the cleaner business-workflow projects in the archive. The operational flow from request to payment proof to active rental is easy to explain to recruiters."

Architecture

Full-stack Next.js app with public catalog, admin area, customer portal, App Router APIs, Prisma services, and operational business rules.

FE:Public browsing experience plus admin pages for appliances, payments, and requests, alongside a customer portal for rental tracking and proof upload.
BE:Route handlers for auth, uploads, rental requests, admin review, files, and reminder cron workflows, backed by service functions in src/lib/server.
Data/Auth:PostgreSQL via Prisma, NextAuth credentials, Blob-backed uploads, reminder scheduling, and seed support.
Maturity: Strong production foundation
Detailed README with environment, routes, and deployment notes
Service layer and data formatting utilities are present
Cron/reminder workflows are modeled explicitly
Production build passed during this audit
No automated tests were detected
Case Study

Survey & ODK Paradata Platform

Research EngineeringResearch

"This project is especially strong for technical interviews because it proves rigor, not just interface polish."

Architecture

Split Python research pipeline and React/Vite dashboard, tied together around paradata ingestion, feature extraction, anomaly detection, and dataset exploration.

FE:Dashboard sections for overview, anomalies, feature exploration, notebook access, and data inspection.
BE:Pipeline controller coordinates SurveyCTO and ODK parsers, feature extractors, statistical validation, and anomaly detection.
Data/Auth:CSV-based dataset ingestion and generated feature outputs, with FastAPI listed in requirements for service exposure.
Maturity: Most rigorous testing story in the archive
Large pytest suite including end-to-end threshold assertions
Research-grade README with precise data expectations
Separate visualization, parser, validation, and pipeline modules
Best evidence of formal regression-style quality controls in the archive
Current end-to-end pytest run failed one detection assertion because `ODK403` was classified as normal
Audit Only

Sunricort Accounting

Internal Finance SoftwareFinance

"The code is much more serious than the project documentation suggests. This is a strong portfolio item once its narrative is surfaced properly."

Architecture

Full-stack Next.js application using dashboard route groups, server actions, Drizzle ORM, and Better Auth.

FE:Authenticated dashboard pages for accounts, contacts, expenses, invoices, recurring items, reports, settings, and transactions.
BE:Server actions in lib/actions drive each functional area, with auth/session checks and data aggregation performed server-side.
Data/Auth:PostgreSQL schema via Drizzle with enums and tables for accounts, contacts, transactions, invoices, recurring items, and expenses.
Maturity: Substantive codebase hidden behind weak documentation
Well-structured domain action files
Detailed schema and financial aggregation logic are present
README is currently almost empty
Current build is blocked locally by a missing `styled-jsx` dependency
No automated tests were detected
Audit Only

SKACE Relationships

Consumer ProductConsumer

"This shows strong product imagination and solid data/privacy modeling, but some of the AI-oriented features are still closer to scaffolding than deep implementation."

Architecture

Full-stack Next.js monolith with auth, onboarding, dashboard, pair flows, settings, API routes, and Supabase integration.

FE:Landing page, sign-up/login flows, onboarding, solo and couple dashboard tabs, pair interface, and settings.
BE:App Router APIs for couples, messages, moods, vents, and relationship insights.
Data/Auth:Supabase auth and PostgreSQL schema with Row Level Security across profiles, couples, moods, vents, messages, timeline events, games, check-ins, and insights.
Maturity: Feature-rich concept with meaningful data modeling
SQL setup script is detailed and security-aware
API routes map directly to the modeled relationship features
Current local build is blocked because the `next` command is unavailable in the project environment
Some insight behavior falls back to default/generated values
No automated tests were detected
Audit Only

SKACE UNI SAAS / UNILUS DIMS

Institutional SoftwareOther

"This should be framed honestly as an institutional product concept with a more developed frontend experience than backend implementation."

Architecture

Split Next.js frontend and NestJS backend, but the two sides are not equally mature.

FE:Dashboard surfaces for executive analytics, approval pipelines, RFID simulation, and an AI-oriented document intelligence vault.
BE:Nest backend is still close to the starter scaffold and currently exposes only a basic controller/service rather than domain-specific institutional modules.
Data/Auth:Frontend simulates workflow-rich surfaces; backend data layer is not yet built out into a real document-management system.
Maturity: Frontend-forward concept with backend still early
Frontend component set suggests a clear institutional product direction
Frontend production build passed during this audit
Backend Jest suite passed during this audit, but only the default starter test exists
Good example of concept maturity exceeding backend implementation maturity
Audit Only

SKACE Move

Hybrid / Product TransitionOther

"This is exactly the kind of project where a deep audit matters. Without the audit it would be easy to describe it incorrectly."

Architecture

Next.js application whose current code mixes collaborative workspace APIs with transport-marketplace and mobility modules.

FE:The root experience renders a transport marketplace, while the repo documentation still describes a collaborative task platform.
BE:API surface includes tasks, spaces, analytics, members, and collaborations, but also transport-specific marketplace endpoints for bookings, dispatch, live trips, notifications, and wallets.
Data/Auth:Supabase helpers are present, and transport datasets are modeled explicitly in lib/transport-data.ts.
Maturity: Interesting codebase with documentation drift
Current implementation and README no longer fully align
Interesting hybrid of collaboration and transport concepts
Production build passed during this audit
No automated tests were detected
Needs narrative clarification before being presented publicly
Audit Only
contact — samuel-kaoma@portfolio: ~

$ whoami

Samuel Kaoma — Software Engineer

$ status --availability

Open to software engineering roles, platform work, and product teams.

$ contact --list

$