The story
- 01 · Problem
Agencies keep clients, tasks, reports and invoices in separate tools, and cannot follow a client from the ad to the lead to the sale. NVMAX had the same problem with several agency brands behind one team, so one system had to serve many agencies, each under its own name.
- What had to change
- Born from a real operating model, not a market hypothesis: partner agencies selling under their own brand while one team does the work. Key decisions: the database first (external APIs only in scheduled syncs), code computes and AI interprets, AI reads a frozen snapshot, and a capability stays switched off until it is cleared.
- 02 · System
One platform with three jobs. WIN: prospects, automated audits, public audit pages and proposals. RUN: clients, projects, tasks, calendar, files and billing. GROW: health scores, rules, findings and recommendations re-measured after 30 days, and monthly white-label reports. Every client business gets its own portal and booking portal on its own domain.
- Connected
- Google Ads API, GA4, Search Console, Business Profile, Places, PageSpeed Insights, Google Calendar, Meta Graph API, a WordPress plugin, DataForSEO, Stripe, IMAP/SMTP.
- Automated
- A rule engine grouped in families, health scores, a 30-day outcome engine, a weekly journal written by AI agents, Ask AI with read-only tools, and an AI-search visibility probe. Changes to a business’s accounts are proposed with evidence and approved by a person.
- 03 · Implementation
A NestJS and PostgreSQL backend in 45 modules, a React front end, a WordPress plugin, scheduled jobs for sync, reports and site monitoring, and a single AI gateway: a deterministic engine computes, AI only interprets a snapshot. Built between February and September 2026, with the key decisions recorded as architecture decision records.
- 04 · Result
In pilot: NVMAX runs on it as the pilot agency and GuidedTours as the pilot business. The chain from ad to lead to payment was proven end to end with test data. Access for other agencies is by application.
Technical detail
- Architecture in detail
- Multi-tenant: the tenant comes only from the sign-in token and is enforced in the application; per-business domains with a portal and a booking portal; 86 entities and 97 migrations; credentials encrypted with AES-256-GCM; a global audit log; CSP, HSTS and an SSRF allowlist; nightly backups and error monitoring.
- Layers
- Business Architecture Software Data AI Integration Infrastructure Security
- Stack
- NestJS TypeORM React 19 PostgreSQL Redis nginx Cloudflare PHP (WordPress plugin)