SaaS
Subscription software, where the tenancy model, the billing ledger and the cost of serving one account are engineering decisions before they are pricing ones.
The context
A subscription product is sold once and run every day after that. Every account shares one codebase, one deployment and one on-call rotation, so a decision made for the first customer is inherited by all the rest. Margin is decided below the feature list: tenant isolation, a billing ledger that reconciles, and a release that reaches every tenant at once.
What makes it hard
The tenancy model is chosen once
Shared schema, schema per tenant and database per tenant differ in migration cost, blast radius, and whether one customer can be restored or moved alone. The choice is cheap in the first month and a rewrite in the third year.
Billing as a ledger, not a field
Trials, mid-cycle upgrades, proration, dunning and refunds are state transitions, and each one has to reconcile with an invoice already cleared under ZATCA e-invoicing. A payment processor holds the charge, not the record.
One release, every tenant at once
No maintenance window is convenient for every account, so schema changes ship backward-compatible first and behind a flag. A migration that locks the largest tenant’s table locks the product.
Cost per tenant, invisible by default
Gross margin is decided by per-tenant compute, storage growth, egress and model tokens — none of which appear on a bill aggregated by service. Usage has to be traced to a tenant before a price can be defended.
How we help
- The tenancy model, the billing state machine and the data residency question are settled in the first architecture review, before an account makes them expensive.
- Billing is written as an event ledger, so an invoice and the subscription state can be reconciled against the same record.
- Releases ship behind flags, and migrations are written to be applied and reversed while every tenant is live.
- Cost is attributed per tenant from the first release, so a pricing decision is argued from consumption rather than from an estimate.
- The handover includes the runbook for restoring one tenant without touching the rest.
- ZATCA e-invoicing on every charge, credit and refund
- Personal Data Protection Law limits on data leaving the Kingdom
- Mada and riyal settlement beside international card rails
- Cloud Computing Regulatory Framework rules when a tenant is a government entity
- SSO, SCIM and audit logs as procurement requirements
- Arabic and RTL inside the product, not only the marketing site
Related services
Tell us what you are building.
Send the outline and we will come back with an honest read on scope, sequence and what it takes to run it in production.
