Menu
Healthcare

Regulatory compliance scheduling platform with geographic routing and audit trail

A full-stack Rails platform that gives an equipment inspection provider a single system of record for a compliance calendar spanning thousands of individually scheduled assets — derived due dates, per-specialist workload queues, geographic radius search, generated compliance documents, and a customer self-service portal.

Client — a specialist regulatory inspection services provider
Concept visuals — not actual screenshots
01 — Challenge

The provider's business is measured on one thing: nothing at a customer site goes past its due date. Every asset runs on its own compliance cycle, spread across hundreds of physical sites and assigned to a roster of licensed specialists, and a missed date is a regulatory event for the customer rather than an administrative slip. Run on spreadsheets, that operation has no audit trail, no reliable due-date arithmetic, no way to route field visits efficiently, and a regulator-facing document that gets retyped every cycle.

02 — Approach

Modelled the register as a three-level hierarchy — customer organisation, physical site, individual asset — to match how the work is actually organised, and gave sites that run on a materials-licence audit cycle a one-to-one extension of the normal site record rather than a duplicated parallel table or a pile of nullable columns. Cycle and derived next-due date live per asset as the platform's primary axis, and every dashboard, search, report and notification reads from that same value, so there's one authoritative answer to what's due rather than several parts of the app disagreeing.

Priority is set independently at the asset, site and customer level and rolled up into a single score ordering each specialist's personal queue, so the business can express three separate kinds of importance without any of them overwriting another. Rather than calling an external geocoding service, coordinate reference data ships with the application and was bulk-imported once, so radius search over the register carries no runtime dependency, no latency and no quota — sites geocode automatically from their postal code on save.

Every customer, site and asset is versioned, so deletions and edits are recoverable in one action, and a per-record token embedded in change notification emails lets a specialist revert a change directly from the email without opening the app. A nightly job finds everything falling due at a per-customer configured lead time, groups it by assigned specialist, and emails that specialist together with the site contacts from the specialist's own address, so replies land with the person who has to attend rather than a shared inbox.

03 — Impact

The compliance calendar became a system rather than a spreadsheet, with every specialist working from their own queue instead of filtering a shared list, and field visits plannable by proximity because the register is searchable by distance as well as by name and date. The regulator-facing document is generated rather than retyped, records are defensible with a complete attributed change history, and mistakes are correctable rather than permanent — including directly from the notification that reported them. A scoped self-service portal lets the provider's own customers see what's due at their facilities without exposing anything else, and the platform absorbed several years of continuous change, including the later addition of that entire customer-facing realm onto a system originally built for internal use.

Stack
MySQLRuby on RailsMySQLDeviseCanCanCanPaperTrailGeokitAxlsx
More work
AED inspection and compliance platform for schools and hospitals→Clinical coordination platform for coverage requests, consultation and secure messaging→Social accountability platform for weight loss with peer meal rating and real-time chat→

Something holding you back?

New build, rebuild, or adding AI to what you already have — I'll take a look and give you an honest perspective.

Get in touch ↗