Skip to main content

DMT — IoT Platform, Task & Document Module

A multi-tenant platform for monitoring and controlling IoT gateways and devices, built by a team at Rivon AI. I worked on the backend of the task and document management module: service records with sub-tasks, an approval workflow for changes, notifications and an audit trail.

  • Rivon AI
  • Backend Engineer
  • Task & Document Module
  • Team Project

The Platform

Organisations with many connected devices need to see live state, automate reactions to conditions, keep each customer’s data separate, and track maintenance work to completion. The platform combines device monitoring, a rule-based automation engine, hierarchical permissions, and a service-records system for inspection work.

The backend is FastAPI with Google Cloud services for background work. The frontend is a Next.js app.

My Module: Tasks and Documents

  • Service records — A record is the main task. Its items are sub-tasks, each with status, deadline, image, comments and its own status history. Statuses are new, in-process, completed, canceled and temporary-stopped.
  • Approval workflow — Changing a status, responsible person or deadline does not apply immediately. The API stores a pending change and sends a short code by SMS to the responsible person. Posting the code applies the change, appends history, notifies contacts and writes an audit entry. A batch type approves several changes together.
  • Change detection and notifications — A diff of the record flags what changed, including added or removed sub-tasks, and notifies stakeholders by email through Pub/Sub and by SMS through Cloud Tasks, so delivery is retried outside the request.
  • Audit log — Create, update, status change, approval, delete, email and SMS events are recorded per record and can be filtered.
  • Analytics — Per-user action metrics and monthly status summaries, such as records created, tasks finished and deadlines delayed.

Design Notes

Notifications and retries run on queues and topics rather than inside the API request, which keeps the API thin. Data is scoped by organisation, and endpoints are protected by permission scopes with read-own and read-all variants. The wider platform, including automation and device handling, was built by the team and I describe only the module I worked on.

Technology Stack

BackendPython, FastAPI, SQLAlchemy, Pydantic, PostgreSQL with JSONB
CloudGoogle Cloud Pub/Sub, Cloud Tasks, Cloud Scheduler, Cloud Functions, Cloud SQL
AuthFirebase ID tokens, organisation-scoped permission scopes
MessagingEmail through Pub/Sub, SMS through Cloud Tasks
FrontendNext.js, MUI, Redux