
☁️ SaaS & Cloud · Class UML
An object model for users, organisations, roles and permissions in a B2B SaaS app, with role-based access control.
Drawing diagram…
Class diagram for SaaS RBAC: Organisation has Memberships; each Membership links a User to the Organisation with one Role; Role has many Permissions (e.g. project.create, billing.manage) and can be a system role or a custom role for one organisation; Invitation lets admins invite users by email; Membership has a can(permission) method used by access checks.
classDiagram
class User {
+String id
+String email
+String name
}
class Organisation {
+String id
+String name
+String plan
+invite(email, role) Invitation
}
class Membership {
+String status
+can(permission) bool
}
class Role {
+String name
+bool isSystem
}
class Permission {
+String key
}
class Invitation {
+String email
+DateTime expiresAt
+accept(user) Membership
}
Organisation "1" --> "*" Membership
User "1" --> "*" Membership
Membership --> Role
Role "1" --> "*" Permission
Organisation "1" --> "*" Role : custom roles
Organisation "1" --> "*" InvitationHow a microservices app runs on Kubernetes in the cloud: ingress, namespaces, services with multiple replicas, managed databases and monitoring.
A typical CI/CD pipeline from a pull request to production: build, tests, security scans, staging deploy, approval and a canary release.
The authorization code flow with PKCE used by most modern web and mobile apps to log users in through an identity provider.
A B2B SaaS product serving many customer organisations from one platform: tenant-aware services, per-tenant data isolation, billing and admin.
The classic three-tier web app on AWS: CloudFront and a load balancer, an autoscaling app tier in private subnets, and a Multi-AZ database.
Services that talk through events instead of direct calls: an order service publishes events that inventory, payments, notifications and analytics react to.