Security services
Case study
In progress: a device-pass backend for a security company
An EMM supplies the data; the backend owns every pass decision; a React admin consumes the API.
Headline result
Every pass decision in one backendwith signed barcodesA security services company
- Client
- A security services company
- Industry
- Security services
- Platform
- Samsung Knox Manage (EMM) · Frappe Framework
- Scope
- 6 modules
1ProblemPass decisions were scattered between the EMM and spreadsheets; registrations that did not match a known device had nowhere to go.
2What we builtA data model for devices, installed apps, SIMs, activity, unmatched registrations and settings.
3OutcomeEvery pass decision in one backend. With signed barcodes
The route · this project
The method behind every case →- ArchitectureEMM supplies data only; the backend owns all pass decisions; React admin on the REST API
- Data modelDevices, installed apps, SIMs, activity, unmatched registrations, settings
- Pass lifecyclePending Activation, Active, Temporary, Inactive, Expired
- BarcodesHMAC-SHA256 signed
01 · The client
A security services company
A security services company managing device passes for a fleet of mobile devices enrolled in Samsung Knox Manage.
- Industry
- Security services
- Engagement
- Frappe backend + React admin on an EMM feed
02 · The challenge
What wasn’t working
01Pass decisions were scattered between the EMM and spreadsheets
02Registrations that did not match a known device had nowhere to go.
03 · What we implemented
The solution
A data model for devices, installed apps, SIMs, activity, unmatched registrations and settings.
EMM (Samsung Knox Manage) supplies data only; Frappe owns every pass decision; a React admin consumes the Frappe REST API. HMAC-SHA256 signed barcodes.
Modules
- Devices
- Installed apps
- SIMs
- Activity log
- Unmatched registrations
- Settings
- A pass state machine owned by the backend, never by the EMM.
- HMAC-signed barcodes for verification.
- A React admin interface on the backend's REST API.
How work flows now
- 1Pending Activation
- 2Active
- 3Temporary
- 4Inactive
- 5Expired
04 · The results
What changed for the business
One backendEvery pass decision taken by the backend, never by the EMM
Signed barcodesEach pass barcode HMAC-SHA256 signed for verification

