The week was not saved on the screens. It was saved on the parts nobody demos.
What was needed
A logistics team needed an internal portal. Track fleet workflows, manage vendor permissions, approve dispatches. Nothing exotic, and nothing that any off the shelf product fits properly, because the workflow is the company's own.
Built the usual way, that is months of backend engineering and then a security review. Teams tend to budget for the first part and get surprised by the second.
Why the review is the expensive half
A dispatch portal is an access control problem wearing the costume of a dashboard. A driver should see their own runs. A warehouse manager should see the depot. A vendor should see the jobs they were given and nothing else. Someone has to approve a dispatch, and later someone has to be able to prove who approved it.
Written by hand, every one of those rules is a place to get it slightly wrong, and a reviewer has to check all of them.
What was built
The engineering team vibecoded the dashboard in under a week. The roles were the point: drivers and warehouse managers see different things, and every dispatch action is written to an audit trail.
None of that access control was hand written. It comes with the backend the application sits on, so it was working the first time the application ran, rather than being added once someone asked for it.
Why it went quickly
- Roles and permissions were configured, not coded, so there was no custom auth layer to write or review
- Dispatch actions were logged because logging is part of the backend, not because someone remembered to add it
- The security review had less to look at, since the controls being reviewed were the platform's rather than this application's
What it does not mean
The application did not write itself. Someone still had to decide what a driver should see, what a vendor should not, and which dispatches need approval before they go out. Those are business decisions and no platform makes them for you.
What changed is where the week went. The team spent it on those decisions instead of on rebuilding a permissions model that already exists in every application of this kind.
What to take from it
The interesting number is not that the dashboard took under a week. It is that the audit trail and the access rules took none of it.