Case study · Software

A portal with three types of users

ComfortMap is a public directory of care homes (a “Booking.com for care homes”) plus a portal with separate dashboards for care home staff and residents' families. It also includes the story of a real bug, found and fixed in production.

3distinct roles: care home staff, resident family, super-admin
ISRstatic public pages, regenerated hourly, indexable by Google
1critical bug found, diagnosed and fixed live in production
ComfortMap dashboard — care home profile, laptop screen
ComfortMap
01

A public directory for care homes

ComfortMap solves a discovery problem: families looking for a care home for a parent need a place to compare real options, not just a static directory with stale public data.

02

The difference from a static directory of public data

Alternatives on the market are often static directories, populated from public ministry data and never updated by the care homes themselves. ComfortMap is a real marketplace, with a dynamic profile each home edits directly — description, photos, amenities, starting price, capacity.

03

SEO-friendly public pages + role-based dashboards

Besides the public directory, the portal has three access types: care home staff, families and super-admin (platform-wide visibility).

  • 01SEO public directory county and individual profile pages, rendered with ISR — fast, indexable, minimal infrastructure cost.
  • 02Staff dashboard operational, day to day — residents, logbook, direct messaging with families.
  • 03Family portal logbook, photos, weekly reports, updated by staff, visible to the family.
04

From role-based structure to a bug fixed at the source

  • 01Public route structure (/camine, /camine/[județ], /camine/[județ]/[profil]) rendered with ISR (incremental static regeneration, hourly).
  • 02Three separate access levels — staff, family, super-admin — with Row Level Security at the database level.
  • 03Production audit for client-reported errors — identifying the real cause, not just the symptom.
  • 04Fix at the source, plus dedicated error boundaries on every area of the app.
  • 05Live verification of the complete flow for all three roles, after the fix.
05

From intermittent crashes to verified operation

A session update was failing silently because of an overly strict database-level security policy, which left some users without functional access to their account, with no clear error message — just a generic crash. We fixed the cause, not just the symptom, and verified the complete flow live for all three roles — magic-link authentication, access to the correct dashboard, persistent session, a working audit log for sensitive actions (in line with the 5-year data retention requirements).

06

What we used

Next.js with the App Router, Supabase/Postgres with Row Level Security for role-based data isolation, magic-link authentication, an audit log for sensitive actions, hosting with ISR rendering for public pages.

07

Real maintenance means fixing the cause, not the symptom

The signal that led us to the bug wasn't a clear error, but a generic crash — the kind of vague report that's tempting to treat superficially. The diagnosis showed an overly strict security policy at the database level, not an interface problem. We fixed the cause, not the symptom, and added error boundaries so that a similar error, in future, would no longer block the whole platform — only the affected area.

At the time of the audit, one area still had simulated data (a care home's contact settings) — we documented it explicitly as an open item, we didn't hide it.

FAQ

Frequently asked questions

How is this different from a static directory of care homes?

ComfortMap has a dynamic profile, edited directly by each care home (description, photos, price, amenities) — not stale static public data.

What bug did you find and how did you fix it?

A post-authentication session update was failing silently because of a database security policy; we moved the operation onto a channel with the correct permissions and added error boundaries, so that a similar error would show a clear message instead of a crash.

How is data separated between the three roles?

Through Row Level Security at the database level — every role sees only the data it has the right to access, verified at the source, not just in the interface.

The Niche Society
The Niche Society TeamAI and software engineers from Bucharest · LinkedIn
delivered 2026

Let's see what can be automated in your business.

A free 30-minute session: we'll tell you what can be automated, how long it takes and what it costs, with a fixed price after discovery.

Book a free sessionoffice@thenichesociety.ro

We reply the same business day.

+40 733 045 833