Harsh Wardhan
Identity: System ThinkingFlagshipOpen Source

Vertex CampusOS

Multi-Tenant University Operations & Student Governance Platform

Engineering Challenge

“How do you build a campus operating system that replaces scattered WhatsApp groups and manual spreadsheets?”

Products•Active Development•Lead Developer & Architect•2026
Modules12Integrated
RBACMulti-RoleRLS Isolated
AttendanceAutomatedClass Rosters
OD WorkflowDigitalApprovals
Vertex CampusOS
01 Context

Overview & Motivation

Campus administration in universities often relies on fragmented tools—WhatsApp groups for announcements, physical paper for On-Duty (OD) approvals, and offline spreadsheets for attendance tracking. Vertex CampusOS unifies these disjointed operational streams into a multi-role operating platform built on Next.js and Supabase.

Why I Built It

During my time at university, tracking club event signups and managing attendance approvals required physical signatures and endless group messages. I wanted to build a single system where every campus workflow had a clear, verifiable digital path.

02 System Design

Platform Architecture

StudentsRegistrations, attendance tracking, event discoveries
Frontend UIResponsive React layouts, reactive state flows
API LayerWorkflow boundaries and secure data contracts
ServicesAuth boundaries, club roles, attendance verifications
DatabaseStructured relational tables and operational source of truth

Built on a decoupled model separating the responsive client layer, authentication boundary, and relational persistence. Employs fine-grained RLS at the database layer.

03 System Components

Platform Modules

Student Directory

Centralized enrollment records, profile verification, and registration status.

Club Governance

Event creation, registration tracking, and budget allocation workflows.

Attendance System

Automated class rosters with faculty verification controls.

Digital OD Approvals

Multi-stage approval state machine for On-Duty leave requests.

04 Technical Rigor

Engineering Decisions & Tradeoffs

Decision #01 • RLS Multi-Tenancy vs API Authorization
Problem:

Managing club and student permission logic inside API routes led to duplicate checks and authorization leak risks.

Decision:

Configured PostgreSQL Row-Level Security (RLS) policies bound to user auth roles, ensuring queries automatically filter data at the database layer.

Tradeoff:

Policy evaluation adds slight overhead to complex queries, requiring indexed policy keys.

Outcome:

Guaranteed zero multi-tenant data leakage between student clubs and department admins.

Decision #02 • Reactive Dashboard State Sync
Problem:

Club leads and students frequently experienced out-of-sync registration counts when managing high-traffic event signups.

Decision:

Integrated Supabase real-time websocket listener channels into local React state hooks.

Tradeoff:

Increased active WebSocket connection count during event windows.

Outcome:

Achieved sub-100ms dashboard updates across active administrative panels.

05 Security & Isolation

Challenges & Security Notes

Multi-Tenant Data Isolation

Employs PostgreSQL RLS policies ensuring students access only their own records, club leaders view only their club rosters, and admins retain system audit capability.

Role-Based Access Control Surface Area

Issue: Admins, club leaders, and students required vastly different user interfaces without code duplication.

Decision/Solution: Architected modular layout containers fed by a unified capabilities contract rather than rendering separate app routes.

Chronology

Development Timeline

Jan 2026

Architecture & Schema Design

Modeled database tables and RLS policy rules.

Feb 2026

Core Attendance & Club Modules

Built student event registration and class roster engines.

Mar 2026

Digital OD Approval Pipeline

Shipped multi-tier state machine for faculty approvals.

Apr 2026

Production Showcase Release

Deployed flagship platform with live demo environment.

Future Direction

What's Next

Integration with automated push notifications for approval states
Exportable PDF attendance reports for department heads
Offline mobile client with local sync
Retrospective Summary

Key Takeaways

Takeaway #01

Pushing authorization to database RLS policies prevents entire classes of client-side security leaks.

Takeaway #02

Designing around real organizational workflows requires understanding user permission matrices before writing code.

Takeaway #03

Real-time WebSocket streams drastically simplify state management for multi-user dashboards.

Continue Exploring

Related Engineering Projects