A permission-aware multi-agent assistant for a multi-tenant SaaS
An AI assistant that does real work across six business apps, acting as the signed-in user and never doing anything their role doesn't allow.
- Role
- Sole engineer, Mehta Softech
- Product
- Mitoo
- When
- 2025 – present
- Stack
- NestJS, TypeScript, AWS Bedrock (Claude), PostgreSQL, pgvector
The problem
Mitoo is a multi-tenant business platform made up of six product apps. Every customer has its own data, and every user has a role with fine-grained permissions. Everyday tasks like scheduling an interview, logging a sales call or applying for leave take several screens and many clicks.
The goal: let people simply type the task ("schedule an interview for Priya tomorrow at 5 pm") and have it done, with exactly the data and permissions they already have in the product.
- product apps
- 6product apps
- specialist agents
- 28specialist agents
- actions it can take
- ~640actions it can take
- common recruiter tasks (was ~1.5 min)
- ~15 scommon recruiter tasks (was ~1.5 min)
How it fits together
- The user types a task in plain language, in the app they're already using.
01 / 05
Chat
- The user types a task in plain language, in the app they're already using.
What made it hard
- Scale. Hundreds of possible actions across six products. No single model call can choose well among all of them at once.
- Trust. In a multi-tenant system with per-role permissions, the assistant must never be able to do something the user couldn't do by hand, however the request is phrased.
- Exactness. Language models paraphrase, guess and sometimes claim success they didn't achieve. Business actions such as deleting a record or changing a status have to be exact.
- Conversation. Real tasks span several turns: "the second one", "change the date", "yes, go ahead". The assistant has to keep track without mixing up users, companies or apps.
Principles I designed around
- Specialists, not one giant prompt. Each area of the product gets its own agent that sees only what's relevant to it.
- Permissions belong to the system, not the prompt. What the model can't see, it can't be talked into using.
- The model reasons; code handles anything that must be exact. Selections, confirmations and anything destructive are deterministic.
- Act as the user. Reusing the product's own API means isolation, validation and audit trails come for free.
Outcomes
- Common recruiter workflows went from ~1.5 minutes of clicking to ~15 seconds of typing.
- One assistant works across six apps, with each user's permissions respected end to end.
- Recruiters can search candidates by describing the person they want instead of filling in filters.