I was working on a site, the same site as my
"I hate me users" post,
and then I left the organization that I had been building it for. I
was building it for free, on my own time, because it was fun, and I
really love the people it was helping. When I started it was about 60
people using the site, it is now hovering at probably 600 (internal
tool btw). I am personally super proud of this, it's no SF startup,
but it is very very useful to the people who use it, and one day,
inshallah, I will talk about it more freely. now it's very important
to note that I left this project in the hands of a very non-technical
person, we will call him Mr. A.
fiveplay
About 2 weeks ago I get a text from Mr. A, and he says he has a
problem that he would like me to fix, he is supposed to have a super
admin role, but the state of his profile is broken and so he can't
monitor all the things he needs, although the rest of the site is
functioning fine (yay). I texted him back the same day, "yeah twin I
got u". fast forward to TODAY, someone else texts me and says "yo,
Mr. A is pressed, shit's broken, and he wants to switch the whole
thing over to an excel sheet" AY FUCK NO, I spent HOURS AND HOURS
working on this site, cause it made my people's lives easier, and I
know they will not appreciate an excel sheet, they have tried and
failed, and switched to PAPER at one point. so I locked in, and
decided to fix it.
the meat
Here is the main technical problem. I only have access to the github
repo. no cloudflare login, no supabase login, none of that, my only
ways of interacting with the site are pushing code to the codebase,
and visiting the production site. but. when something is pushed or
merged to main, it kicks off cloudflare and supabase to push those
changes to prod. I'm in
ูู ุฉ
Not my proudest moment, lowkey just security through obscurity. I
don't even have an account on the site, so I made a little very
obscure endpoint, which I could curl to give me the account data for
Mr. A, as well as some other manager-y profiles so I could compare
and contrast.
and there it was. his role was set to admin instead of super admin.
that's it, that's the whole thing.
so I built a second obscure endpoint, that when called could ONLY
change Mr A's profile data, and only to the data I needed it to be
(relax about broad permissions, I didn't have em). I shipped it,
called it, prayed, checked my og endpoint and saw the data was fixed,
jumped for joy, and texted Mr. A that he should be chillin now.
I then promptly removed my little scary endpoints, pushed to prod
again, and verified my curls didn't work anymore. and then I jumped
for joy once again.
Mr. A texted back and said "badass brother" which I appreciated
because it means my people can use my site for at least another day.
It's also surprisingly fitting, because he doesn't know I had to
backdoor the whole thing to change what amounted to 2 variables in a
database that he has direct access to.
I Was Locked Out Of My Own Legacy. ๐ Here's What It Taught Me About Ownership, Impact, And Why Spreadsheets Are Never The Answer.
Setting the stage ๐ฌ
A few years ago I made a decision that most people told me was "not a good use of my time."
I built a platform. For free. On nights and weekends. For an organization I deeply believed in.
No equity. No salary. No LinkedIn announcement post (until now ๐ ).
Just me, a laptop, and a genuine belief that the people doing this work deserved better tooling than what they had.
We started with 60 users.
Today? We're hovering around 600. ๐
That's a 900% increase in adoption. Organic. Zero marketing spend. Zero growth hacking. Just relentless focus on the end user.
Is it a unicorn? No. Did I raise a Series A? Also no. ๐
But here's what I've learned: impact isn't measured in valuation. It's measured in the hours you give back to people who never asked for them.
Eventually I transitioned off the project and handed the keys to an incredible leader I'll call Mr. A. Non-technical. Deeply mission-driven. The kind of person who makes you want to do better work.
That handoff felt like the end of the story.
It wasn't. ๐
The moment everything changed โก
Two weeks ago, I received a message from Mr. A.
His super-admin permissions weren't resolving correctly. He couldn't access the visibility layer he needed to steward the platform.
Everything else? Running beautifully. (Shoutout to boring, resilient architecture. ๐)
I responded same-day. I said I'd handle it.
Then life happened. As it does. ๐คท
Fast forward to this week. A different stakeholder reaches out.
The message, paraphrased:
"Mr. A is frustrated. The tool is blocking him. He's considering migrating the entire workflow to a spreadsheet."
I want you to sit with that for a second.
A spreadsheet. ๐
600 people. One source of truth. Migrated back into a grid of cells with no validation, no permissions model, no audit trail, and no single owner.
Here's the part that stopped me cold: this team had already tried spreadsheets. It failed. They went back to PAPER.
Read that again.
Paper. In 2026. ๐
So I did what I think we all need to do more often in our careers.
I stopped scrolling. I closed the laptop lid on everything else.
And I locked in. ๐
The technical reality check ๐ป
Now here's where it gets interesting from an engineering perspective.
I no longer had access to the infrastructure.
โ No Cloudflare credentials
โ No Supabase credentials
โ No admin account
โ No dashboard, no console, no observability layer
My entire attack surface, and I use that word deliberately, was:
โ Push access to the GitHub repository
โ A browser pointed at production
But here's the thing about modern CI/CD. ๐
When code merges to main, the pipeline fires. Cloudflare rebuilds. Supabase migrates. Production updates.
I couldn't log in.
But I could deploy.
And in 2026, deploy access is access.
A note to my network ๐ฃ
Let's pause the story, because there's a lesson here that I'd be doing you a disservice not to surface.
I had zero credentials and full write access to production.
That was convenient for me. It is catastrophic for your threat model.
If a former volunteer can reach your database through a git push, so can a compromised dependency. So can a leaked token. So can a contributor you've never met.
This isn't my full-time job. ๐ค
It is yours.
Audit your pipelines. Enforce branch protections. Require review. Rotate the keys of everyone who leaves, on the day they leave.
Supply chain security is not a Q4 initiative. It's table stakes. ๐
Ok. Back to the story. ๐
The summit ๐๏ธ
Full transparency, because I believe in leading with vulnerability: this was not my most elegant work.
What I shipped was, in the most technical sense, security through obscurity.
I deployed a single unlisted read-only endpoint. I curled it. It returned Mr. A's profile record, plus a handful of comparable manager profiles so I could diff the schema.
And there it was.
His role was set to admin instead of super_admin.
That's it. That's the whole incident. ๐คฏ
Weeks of friction. A near-migration to Excel. 600 users on the line.
Two variables.
So I shipped a second endpoint. Scoped to exactly one record, writing exactly one value. Nothing broader. Nothing reusable. (For the security folks already typing in the comments: I didn't have broad permissions to grant myself. That wasn't discipline, that was constraint. Sometimes those look the same. ๐)
I called it. I prayed. ๐คฒ
I re-ran my read endpoint.
Fixed. โ
Then I did the part that matters more than the fix: I ripped both endpoints out, redeployed, and verified my own curls returned 404.
Because shipping is not the finish line. Cleanup is. ๐งน
Mr. A texted me back. Two words:
"badass brother" ๐
I'll be honest, that landed harder than any performance review I've ever received.
It also made me laugh. Because he has no idea I had to smuggle a backdoor through a deployment pipeline to change two variables in a database he already has direct access to.
Sometimes the most senior thing you can do is quietly solve a problem nobody will ever fully understand. ๐ก
3 takeaways:
1๏ธโฃ Users don't want your architecture. They want their Tuesday back.
2๏ธโฃ Constraints are not blockers. They're a design brief.
3๏ธโฃ If someone is threatening to move your product to a spreadsheet, you have already lost the trust battle. Fix it before they open Excel.
What's the scrappiest thing you've ever done to keep something alive for your users? Drop it in the comments ๐ I read every single one.
โป๏ธ Repost if you believe internal tools deserve the same craft as customer-facing ones.