Case study · Builders & Creatives

AWS architecture for a multi-tenant property management platform with AI workflows

Software for property management companies, landlords, tenants and caretakers. One web app, a hosted LLM inside the AWS account, and AI agents that take over the routine work.

Industry
Real estate, property management
My role
Architecture, full-stack development, AI workflows
Focus
Multi-tenancy, LLM integration, AWS
Results
AI workflows
Routine requests handled by AI

Tenant requests are triaged, answered and routed by agents. A person approves anything that matters.

Security
Strict isolation between organisations

Every user sees exactly their data, enforced in the token, the API, the database and storage.

Privacy
The LLM stays in the AWS account

Models run on Bedrock with guardrails. Property data is not shared with third parties.

The story

Property management runs on messages: a broken heater, a question about the service charge statement, a lease document someone needs by Friday. Managers, landlords, tenants and caretakers all need the same information, but each should only see their part of it.

I designed the platform as a multi-tenant SaaS on AWS. A Nuxt web app and a Python API run in Docker on EC2 inside a private VPC, behind CloudFront and a load balancer. Cognito issues tokens with a role and an organisation ID, and that ID follows every request down to PostgreSQL row-level security and per-organisation S3 prefixes.

On top sits the AI layer. The API puts requests on an SQS queue, a Lambda agent calls Bedrock and works through a set of tools: look up the unit, search the documents, read the photos, draft the ticket. Step Functions run the longer workflows, including the approval step where a property manager confirms before anything is sent.

Everything is observable in CloudWatch, from API latency to every prompt, tool call and token cost, and the whole stack is shipped through GitHub Actions.

System architecture: Web app, API and AI agents in one AWS account
System architecture.
AI workflow: A damage report, from message to scheduled repair
The damage report workflow. The same pattern handles questions about statements, documents and appointments.

Multi-tenancy

Each property management company is its own organisation. Within it, five roles see different slices of the same data, and the AI assistant only ever sees what the current user is allowed to see.

Access is enforced in four layers rather than trusted to one, so a bug in the app alone cannot leak another organisation's data.

Access model: Five roles, one set of rules, four layers of enforcement
Roles and permissions per organisation.

Technology

Application
Nuxt, Vue
Nuxt, Vue
Nuxt, Vue
web app for all roles
Python, FastAPI
Python, FastAPI
Python, FastAPI
API, business logic, AI tools
PostgreSQL on Amazon RDS
PostgreSQL on Amazon RDS
PostgreSQL on Amazon RDS
multi-tenant data, row-level security
Amazon EC2
Amazon EC2
app servers
Amazon S3
Amazon S3
documents and photos
AI
Amazon Bedrock
Amazon Bedrock
hosted LLM, knowledge base, guardrails
AWS Lambda
AWS Lambda
AI agent with tools
AWS Step Functions
AWS Step Functions
multi-step AI workflows
Amazon SQS, Amazon SNS
Amazon SQS, Amazon SNS
Amazon SQS, Amazon SNS
job queue, notifications
Security and networking
Amazon Cognito
Amazon Cognito
users, roles, organisation claim
AWS IAM
AWS IAM
least-privilege roles
Amazon VPC
Amazon VPC
private subnets, security groups
CloudFront, Route 53, WAF
CloudFront, Route 53, WAF
CloudFront, Route 53, WAF
CloudFront, Route 53, WAF
edge, DNS, protection
Load Balancer
Load Balancer
TLS, routing
Secrets Manager, KMS
Secrets Manager, KMS
Secrets Manager, KMS
credentials, encryption
Delivery and operations
Docker, Amazon ECR
Docker, Amazon ECR
Docker, Amazon ECR
containers, image registry
GitHub Actions
GitHub Actions
CI/CD
Amazon CloudWatch
Amazon CloudWatch
logs, metrics, traces, alarms
Core stack

Working on something similar?

Tell me what you run today and where it hurts. I will come back with how I would build it, and what I would leave alone.

Discuss your project