UAE School Games platform
A nationwide school-sports league needed one system for the public, for hundreds of school coaches, for the back-office team and for marshals at the venue. I took it from an AI-generated prototype to production in six weeks.
The problem
Registrations, eligibility rules, event rosters and results lived across spreadsheets and messages. Coaches could not see their own squads, the back office re-keyed data, and event day ran on paper.
The starting point was a prototype generated by another AI tool: impressive on screen, but on SQLite, with a single 10,800-line route file and no real security model.
What shipped
A bilingual public site (English and Arabic, fully right-to-left) with sport pages, rules, age tables, calendar, news, galleries and downloads.
A coach portal where schools register athletes and enter them into sports, age groups and disciplines, with eligibility and regional caps enforced on the server.
An admin console covering the sports engine, events and calendar, athletes and registrations, results upload → preview → publish, relationship management, reports, users and permissions, and an audit log.
An offline-first marshal check-in app. Taps queue on the device when the venue loses signal and sync themselves when it returns, without double-counting.
How I ran it
I owned scope, architecture and the quality bar. Every product question became a numbered decision (more than 260 of them), and every round of feedback from the client became a written plan.
Implementation ran in parallel lanes of Claude Code agents, each in its own git worktree with narrow file ownership. Nothing merged without typecheck, lint and the test suite passing. Nothing reached production without first being verified on staging. Database migrations had their own gate: a pull request touching a migration could not merge to production until that migration had been applied.
The result: 22 feedback rounds, 137 workstreams and 355 merged pull requests, from 18 August to 1 October 2026.
Under the hood
React 18, TypeScript and Vite on the client. Express 5 as a single Vercel serverless function. PostgreSQL on Supabase through Drizzle ORM, with 61 tables, 34 versioned migrations and Row-Level Security on every table.
Hand-built authentication: scrypt password hashing, database sessions and secure cookies. Seven roles and a role × module permission matrix that super admins can edit. Login rate limits, a global read-only guard for client accounts, private storage with signed URLs for identity documents, and deletion cascades that leave a single anonymised audit row.
Screens
Captured from the running product on a fully synthetic dataset. No real athlete, coach or school appears.










