Keeping one customer out of another's data
On a shared platform this is the failure nobody recovers from quietly. I build the separation into the storage layer, so it does not depend on every future query remembering to filter correctly.
Hermawan Safrin
Backend Developer (PHP) · Baubau, Indonesia
Six years writing PHP. Most of that time has gone into systems handling payroll, bookings and customer records, where a wrong figure or a row shown to the wrong account stops being a small bug and starts being a compliance conversation. That is the work I am good at, and the work I enjoy.
Currently an independent contractor for an Australian company, working remotely from Indonesia.
I am a backend developer based in Baubau, Indonesia, and I have spent the last six years writing PHP for products that other businesses run their operations on. Payroll that has to pay the right amount. Bookings that cannot be double sold. Records that belong to one company and must never appear in front of another. When the data is that consequential, the interesting problems stop being about features and start being about correctness, isolation and access.
On a shared platform this is the failure nobody recovers from quietly. I build the separation into the storage layer, so it does not depend on every future query remembering to filter correctly.
Most systems start with two roles and outgrow them fast. I design permission models detailed enough to be useful and plain enough that a customer's own admin can change them without filing a ticket.
Queries are fine at launch and painful three years later. I find where the time is really going and cut it, while the results stay exactly the same.
Strict analysis and real tests, added to code that already ships. The goal is simple: mistakes get caught before deployment rather than by a customer.
Every provider models the same idea slightly differently. I turn that mess into one predictable shape, so nothing downstream has to know which provider it came from.
Credentials sitting in config files. Dependencies kept out of habit. I get them out rather than bumping a version number and calling it fixed.
Baubau, Indonesia, on GMT+8. That gives me a full overlap with Australia and Singapore, most of the working day with the rest of South East Asia, and a workable morning overlap with Europe. I already work this way day to day for a client in Australia, so the timezone is a solved problem rather than an experiment.
Mostly existing ones, and that is usually where I am most useful. Joining a codebase that already carries real customers, learning why it looks the way it does, and improving it without a rewrite is a specific skill. Greenfield work is enjoyable, but rescuing something people already depend on is harder and matters more.
Contract and independent work, remote. I am comfortable being the backend owner on a small team, or the person brought in for a specific problem: a permission model that no longer fits, a report nobody can wait for any more, a codebase that needs a safety net before the next big change.
Send me an email describing the problem, not the job spec. I will tell you honestly whether it is something I would be good at, and if it is not, I will say so. Nothing about that first exchange commits either of us to anything.
Yes, and I already do. The practical answer is that I write things down. Decisions, trade-offs and the reasoning behind a change go somewhere the rest of the team can read them later, so progress does not stall waiting for our hours to overlap.
Backend is where I am strongest and where I want to spend my time. That said, I have shipped internal interfaces when a feature needed one end to end, and I am comfortable working closely with frontend engineers rather than throwing an API over the wall.
English for all written and spoken work, and Indonesian natively. Most of my professional communication has been in English with teams outside Indonesia.
Always happy to talk backend architecture, or about working together. My work history is on LinkedIn.
Usually replies within a day · Remote · GMT+8