
A bigger server runs out eventually.
A single application server can only be made faster by being made larger, and there is a largest one. After that the only move is a rewrite, usually at the worst possible moment.
A stateless application holds no session on the machine serving it, so any request can go to any instance and instances can be added and removed while it runs. Capacity becomes a number somebody changes rather than a migration somebody schedules.
The work is in the separation: sessions, uploads and background jobs each move somewhere that is designed to hold them. Done at the start it is a design decision. Done in year three it is the rewrite.
A backup nobody has restored is a belief.
One deployment, many customers.
The boundary is in the data layer
Every query is scoped to a tenant by the layer underneath the application, where the calling code cannot reach past it. A missing filter in a new feature returns nothing rather than somebody else’s records.
One deployment to operate
Every customer runs the same version. There is no matrix of per-customer builds to reproduce a bug against, and a security fix reaches everybody at once.
Capacity follows demand
Instances are added when load rises and removed when it falls. The bill tracks usage rather than the busiest hour of the quarter.
We run the infrastructure
Scaling, backups, patching and monitoring are ours. The client’s team works on the product, which is the reason they commissioned a platform rather than a server.
Platforms already running on this architecture.
Email and calendar software, healthcare management systems, customer relationship management, and project management tools, each serving its own set of organizations from one deployment.
The domain differs every time. The shape underneath does not, which is why a platform in a field we have not worked in before is not a research project.
Someone has to be awake at three.
A platform is not finished when it works. It is finished when somebody can be responsible for it at three in the morning, and that is a different set of decisions.
Monitoring watches what a customer would notice rather than what a server reports: whether a sign-in succeeds, whether a job queue is draining, whether the slowest tenant is slow. An alert that fires on processor load is an alert nobody reads by the second week.
Backups are restored on a schedule. A backup nobody has restored is a belief, and an incident is the wrong moment to find out which one you have.
Deployments are automated, reversible and dull. Every customer runs the same version, so there is no matrix of builds to reproduce a defect against and a security fix reaches everybody in one release. Anything that changes the shape of stored data goes out ahead of the code that needs it, which is what keeps a rollback available for as long as it might be wanted.
Capacity follows demand within the hour, which matters for cost as much as for load: the bill tracks what was used rather than the busiest hour of the quarter. All of that is ours to run, so the client’s team can work on the product, which is the reason they commissioned a platform rather than a server.

Contact