Open Source Toolbox
Reference stack for enterprise delivery. MANPRA Workforce remains non-dependent: components can be swapped without changing core product architecture.
How we use it
Toolbox components guide architecture decisions, but tenant data paths and product behavior stay owned by MANPRA Workforce services.
Enterprise deployment posture
Hosting options: Vercel, AWS, Azure (based on tenant requirements).
CDN strategy: edge caching for marketing, no-cache for tenant APIs.
Observability: metrics, traces, and audit logs monitored continuously.
Security posture: least privilege, evidence-first review trails.
Compliance: country-aware defaults with export-ready controls.
Auth / SSO
- Keycloak — enterprise IAM and federation
- Authentik — self-hosted SSO workflows
- Zitadel — identity orchestration
Billing
- Stripe — current billing provider baseline
- Kill Bill — long-term billing engine option
- Lago — usage-based billing control plane
Analytics
- PostHog — product analytics and funnels
- Plausible — lightweight traffic analytics
Support
- Chatwoot — customer support inbox
- Zammad — ticketing and SLA workflows
IAM / RBAC
- Ory Keto — authorization graph concepts
- Casbin — policy evaluation patterns
Audit / Logs
- OpenSearch — indexed audit exploration
- Loki + Grafana — centralized logs and dashboards
Workflow
- n8n — automation and event pipelines
Docs
- Docusaurus — long-form docs publishing