Skip to content
AM
Case Study·Client project·Full Stack Engineer — Backend Architecture & Admin Client

MonkMaze

Lead Generation & Business Automation Platform

Full-stack lead capture and business automation platform featuring multi-step lead capture, an admin dashboard system, meeting and invoice management, and analytics and blog tools.

github.com/AmirMaqbool0/MonkMaze_Backend
MonkMaze admin dashboard showing lead pipeline and analytics

01Context & Problem

The client needed a platform to replace fragmented workflows for acquiring and handling leads. The requirements included multi-step lead capture, an admin dashboard system, meeting and invoice management, and analytics and blog tools built with Next.js, Express.js, and MongoDB.

02Engineering Ownership

What I Built

  • ▸Built the multi-step lead capture flow and REST APIs using Express.js and Node.js.
  • ▸Engineered the admin dashboard system in Next.js and React with role-based access control.
  • ▸Implemented backend data models and routes for meeting and invoice management with MongoDB and Mongoose.
  • ▸Developed analytics and blog tools within the admin dashboard interface.

What I Did Not Build

  • ▸Worked from designs provided by the client rather than producing the visual design myself.

03Stack & Rationale

Next.js & React

Provided server rendering and component structure for the admin dashboard system.

Express.js & Node.js

Asynchronous REST APIs handling lead capture, meeting, and invoice endpoints.

MongoDB & Mongoose

Document schema modeling for leads, invoices, meetings, and blog content.

TailwindCSS

Utility-first styling for consistent spacing and layout across the admin interface.

04System Architecture

Component topology, data flows, and authorization boundaries:

Next.js ClientLead Capture & AdminTailwindCSS · FormsHTTPS / RESTExpress.js API LayerJWT Auth & RBAC GuardLead Pipeline ServiceInvoicing & ExportMongoose TCPMongoDB ClusterLeads · Pipeline · RolesDocument Queries

05Authentication & Authorization

Authentication issues a JWT on login, which auth middleware verifies on every protected route. Authorisation is enforced by role-based access control middleware that separates standard user access from admin access. If I were rebuilding this now I would move token storage to HTTP-only cookies and add automated tests around the auth middleware.

06Hard Technical Challenges & Solutions

Role Separation Across API Routes

Problem: Standard user accounts and administrators required different levels of access to invoices and meeting management records.

Solution: Role checks were enforced in Express.js middleware rather than in the client UI, ensuring unauthorized requests fail at the API boundary.

Multi-Step Lead Data Validation

Problem: Multi-step lead capture forms submitted data in stages, risking incomplete records reaching the database.

Solution: REST API route handlers validated incoming data payloads at each step before committing records through Mongoose models.

07What I Would Do Differently Now

Engineering Retrospective & Critical Critique

If I were building this platform today, I would implement automated testing across the REST API routes and add CI/CD with GitHub Actions to run tests on every pull request. I would also containerize the Node.js backend using Docker for consistent development and deployment environments.