Skip to content
➜DEPLOYED
➜cd products/gealo
cd ../products
➜SYSTEM_BRIEFING--target=gealo
DEPLOYED ·gealo.app

gealo// operations console

multi-tenant from the first migration. live at gealo.app.

  • ➜
ENTER_CONSOLE platform.gealo.app// uptime measured per tenant
➜STRUCTURAL_SIGNALS--shape=stable
➜SYSTEM_SIGNALS
  • CAPABILITY
    10

    Capability pillars

    workspaces · tasks · chat · meetings · hr · docs · github · ai · billing · sso

  • BACKEND
    30+

    Feature modules

    controllers, services, guards. tenant-scoped on every read.

  • STACK
    4

    Architectural tiers

    edge · application · services · data plane

  • INVARIANT
    tenant_id

    On every read

    no cross-tenant joins. ever.

➜SNAPSHOT--format=summary

What it is

A console for the work people actually do. Projects (workspaces) hold tasks, chat, meetings, files, and integrations. Tenants hold billing, membership, policies, and the people. The spine of the system (tenancy, permissions, entitlements, audit) is the part that gets the most attention.

What stays private

Gealo is deployed at gealo.app. These pages cover architecture patterns, capability surface, and design philosophy. They do not expose schemas, exact endpoints, rate limits, JWT TTLs, package versions, or admin UI. Operational specifics live behind the auth wall, where they belong.

➜CAPABILITY_MATRIX--pillars=10 --preview

// preview · click any pillar to open the full browser Ten capability domains live in the console today. The full interactive browser is at /modules.

➜STACK_TOPOLOGY--tiers=4 --live
data flowing

Tier_01 // edge

// where the tenant is resolved

Browser

Operations console + auth shells. Tenant resolved from host.

Tier_02 // application

// thin controllers · guards enforce tenancy

Nuxt 3 // SSR

Marketing, auth shells, console pages. Tenant context per request.

Socket.IO // realtime

Tenant + project rooms. Presence, typing, notifications.

NestJS // API

Controllers thin, services do the work. Guards enforce tenancy + entitlements.

Tier_03 // services

// business logic · 30+ modules

Auth + RBAC

JWT, refresh rotation, optional 2FA, tenant role guards.

Entitlements

Plans grant a baseline, policies tighten, add-ons expand. Resolved in one service.

Workspace services

Tasks, chat, meetings, HR, docs, integrations, AI, billing.

Background jobs

Tenant-aware queues. Retention, accrual, storage recalc.

Tier_04 // data plane

// every key, query, and prefix is tenant-scoped

PostgreSQL

Primary OLTP. Real migrations in prod. Tenant-scoped queries.

MongoDB

Chat messages and flex-schema documents.

Redis

Cache (tenant-prefixed keys), rate buckets, pub/sub fabric.

S3-compatible

File plane. Presigned URLs after permission checks. Tenant/project key paths.

➜ invariant: tenant_id on every read[no cross-tenant joins]
➜ACTIVITY_TAIL--scope=illustrative

Real-time fabric carries chat, presence, task changes, webhooks, and audit. Below is a cycling tail of the kind of events the console routes every second, with fictional tenants and identifiers so nothing leaks.

➜SYSTEM_TAIL
  • ➜authtenant resolved from host
  • ➜ssosaml assertion verified
  • ➜tasksubtask created and assigned
  • ➜chatmention resolved to task entity
  • ➜rtcpresence broadcast to project room
// illustrative tail. tenants are fictional. event shapes are real. [paused on hover]
➜PRODUCT_PRINCIPLES--count=4
  • [01]

    Tenancy first

    Every surface, query, cache key, queue, and socket room is tenant-scoped. The data model makes cross-tenant joins inconvenient to write.

  • [02]

    Entitlements as law

    Plans grant, policies tighten, add-ons expand. One service computes the effective answer. The frontend never hardcodes a cap.

  • [03]

    Real-time, but scoped

    Socket.IO rooms keyed by tenant and project. No global broadcasts. Presence, typing, notifications all flow through the same fabric.

  • [04]

    Density over decoration

    The console is the surface people work in. Real counts, real permissions, real state. Spacing varies for rhythm instead of uniformity.

➜DEEP_DIVES--routes=4

// four focused routes Pick the one closest to what you actually want to know. Each route is dense, self-contained, and links back to the hub.

➜enter_the_product

The product lives at gealo.app

These pages cover how it is built. The product itself is deployed and operational. Open the console to see what the tenancy, entitlements, real-time fabric, and design system actually look like in motion.