Full-stackRamco SystemsAug 2026 to Oct 2026
Self-service payroll data integration platform
Payroll customers needed their data in banks, finance tools and benefits systems, and every integration was custom work. I designed and built a platform that lets them set it up themselves.
My roleLead developer, designed and built it end to end
Running in a UAT environment after about two months, with around 200 design decisions recorded along the way.
- API gatewayScoped credential per client, mutual TLS
- IdentitySingle sign-on, invites, dynamic roles
- Integration backendWizard, scheduler, job queue, delivery
- EmailSend-only notifications
- Web appThe six-step connector wizard
Built at Ramco Systems for the Ramco Payce product. Internal names, infrastructure and code stay private, so this page describes the engineering.
The problem
Payroll customers need their HR and payroll data in other systems: banks, finance tools, benefits vendors. Each of those integrations used to be one-off custom work.
What I built
A guided six-step wizard lets a customer user build a connector: pick the data, link it, transform fields, choose the output format, then deliver encrypted files to SFTP on a schedule or let another system pull the data through an API. Product and implementation teams control which data each customer may use.
Behind it are five services I designed and wrote: a zero-trust API gateway, a reusable identity service (single sign-on with OIDC and PKCE, invitations, dynamic roles), the integration backend (wizard APIs, scheduler, job queue, transform pipeline, delivery), a send-only email service, and the React front end.
Hard parts
- Least privilege by design. The gateway gives each client application its own scoped, encrypted credential, and callers must also prove their workload identity.
- Reliable scheduling without new infrastructure. The job queue runs on PostgreSQL row locks, so there is no broker to operate.
- Repeatable releases without a CI/CD pipeline. An offline release path: multi-architecture images, transfer, import, rolling update and health check, plus restore-tested backups.
Result
Designed, built and hardened in about two months, running in UAT ahead of a cloud production rollout.
- Go
- React
- TypeScript
- PostgreSQL
- Kubernetes
- OIDC