Feedback from plant managers, IT directors and backend teams who run the portals we deliver for heavy industry corporations across Malaysia and the region.
Clarifications on how we frame deliverables, security boundaries, and support terms for corporate intranet and backend portal engagements.
We treat an intranet as an internal web platform with authenticated access, role-based permissions, and structured content for employees. Deliverables include information architecture, user roles, document workflows, search, and integration points with existing identity providers. We do not include public-facing marketing sites or e-commerce storefronts in this category.
A backend portal is an internal tool that connects operational data, approval chains, and reporting for heavy industry teams. Typical examples are maintenance request systems, equipment log dashboards, and supplier document exchange. We scope these as separate modules with their own data models, API contracts, and audit trails rather than as generic content pages.
We design around zero-trust principles: every request is authenticated, every access decision is logged, and sessions expire on a defined schedule. Identity federation with your existing Active Directory or SSO provider is assumed. We do not store plaintext credentials, and we document the encryption layer used for data at rest and in transit.
Our standard scope includes a development environment, a staging environment that mirrors production configuration, and the production deployment itself. We define data migration steps between these environments and agree on a rollback plan before cutover. Additional sandbox instances for training or testing are quoted separately.
We do not provide ongoing content writing, translation of interface text into additional languages, or 24/7 on-call monitoring unless explicitly added. Hardware procurement, network infrastructure changes, and third-party license fees are also outside the base scope. Any of these can be arranged as a separate work package with its own timeline.
Change requests are logged with a clear description, impact assessment, and priority level. We confirm the effect on the delivery schedule before starting work. Minor text edits and configuration changes are applied within the agreed maintenance window; structural changes to data models or user flows are treated as new scope.