Inspect the actual code CORE builds

We are publishing complete, real applications built by CORE as open-source repositories. Clone them, run them locally, review the code, evaluate the security. Judge the quality yourself.

Real code · Not a marketing demo

Why we're doing this

Every AI product on the market claims to generate great code. Very few will let you inspect what "great" actually means. We're publishing three complete, working systems built by CORE — end-to-end — so any engineer, CTO, or technical evaluator can form their own opinion without a sales call, a login, or a signed NDA.

Why we make these free forever.

Three reasons.

First, these are the three hardest-to-get-right patterns in enterprise software: multi-tenant authorization, workflow engines, and data ingestion with role-scoped reporting. Every enterprise SaaS product needs some version of all three. Nobody should have to build them from scratch anymore.

Second, they're the honest engineering credibility signal enterprise buyers ask for. When you evaluate an AI software delivery platform, the fair question is: show me what it actually builds. These three repositories are the answer. Read the code. Read the commits. Read the issues. Nothing tells you what CORE produces faster than that.

Third, free forever. There is no commercial upsell path. There is no rug-pull scheduled. If you build on them, you own that decision permanently.

🔐

Multi-Tenant RBAC Admin Console

core-rbac-console

The business case

Every enterprise SaaS product lives or dies on one thing: can it isolate one customer's data from another customer's, and can it prove it.

Get this right and enterprise deals close. Get it subtly wrong — one privilege-escalation bug, one missing audit entry, one leaky tenant boundary — and you're explaining a breach to your customer's CISO. Or worse, to their regulator.

This project is a complete, production-ready admin console for multi-tenant applications. Organization hierarchies, teams, role-based permissions down to individual resources, user provisioning and deprovisioning workflows, and a cryptographically-verifiable audit log of every privileged action.

Adopt it as the authorization backbone for your own SaaS product, use it as the reference implementation your team benchmarks against, or lift specific patterns — the tenant isolation model, the audit log design, the RBAC policy engine — into your existing codebase.

Who this helps

Founders and CTOs building multi-tenant SaaS products, engineering leads responsible for compliance-grade authorization, platform teams standardizing RBAC across an internal product portfolio, security architects reviewing tenancy isolation patterns.

Where you can use this

  • Multi-tenant SaaS products — the entire authorization backbone, ready to use
  • Internal enterprise platforms — where teams inside a company need isolated workspaces with granular permissions
  • Regulated industries (financial services, healthcare, government) — where SOC 2, HIPAA, or FedRAMP audit trails need cryptographic tamper-evidence
  • Marketplace platforms — vendor / customer / admin isolation with per-transaction permission scoping
  • API gateways and platform APIs — as a reference model for how to implement fine-grained authorization at scale
  • Consulting engagements — as a benchmark implementation to point client engineering teams at
  • Security training — as a worked example of what "secure by design" multi-tenancy looks like in .NET

Industries where this pattern is under active adoption: financial services (broker platforms, treasury tools), healthcare (patient portals, clinical trial systems), professional services (client portal platforms), and any B2B SaaS scaling from single-tenant proof-of-concept to multi-tenant production.

Show technical detail ▾

A .NET 8 / Blazor admin console implementing production-grade multi-tenant authorization with these architectural properties:

Tenant isolation model: row-level security enforced at the database layer (not just at the application layer), with tenant context flowing through every request via an authenticated claim. Cross-tenant access is architecturally impossible, not just discouraged. Includes a test suite that actively attempts to breach isolation and asserts every attempt fails.
RBAC engine: hierarchical roles (organization → team → resource), attribute-based permission evaluation, deny-by-default policy semantics. Permissions can scope down to individual records, not just resource types. Includes a policy simulator for previewing "what can user X do?" before granting a role.
User lifecycle: invitation flow with signed tokens, provisioning webhook interface (adapt to any identity provider), configurable deprovisioning (soft-delete with retention, hard-delete with audit-only trace, or SCIM-triggered).
Audit log: every privileged action produces an immutable, hash-chained log entry. Tamper detection is cryptographic — each entry includes the hash of the previous, so retroactive modification is provably detectable. Configurable retention (7-year default for SOC 2). Exportable to any SIEM.
Session management: configurable idle timeout, forced re-auth on sensitive operations, concurrent session limits, active-session revocation.
No external dependencies for the core: ships with local password authentication so you can evaluate the model without wiring up SSO/OAuth. Adapters for SAML, OIDC, and Entra ID available as separate optional packages.
Install: Clone the repo, dotnet run. Runs locally in under 60 seconds. Docs: Full README, architecture decision records for every significant design choice, threat model in /docs/security.md. Contribution: Additional identity provider adapters, database backends, and threat-model expansions welcome.
.NET 8 ASP.NET Core C# Blazor Azure SQL EF Core ASP.NET Identity
🔄

Configurable Approval & Workflow Engine

core-workflow-engine

The business case

Every enterprise runs on approval workflows. Procurement requests. Expense reports. Access requests. Vendor onboarding. Policy exceptions. Change management. Contract signatures.

Most of these live inside expensive platforms — ServiceNow, Jira Service Management, custom-built tools that took a year and never quite fit. And every one of them is fundamentally the same pattern: a state machine, some approvers, an escalation rule, an audit trail.

This project is that pattern, built well, given to you free. Define your approval workflow as configuration — states, transitions, who can approve at each stage, what happens when a step misses its SLA, how the whole history is recorded. Adapt it to procurement, expense approval, access requests, or any process that follows the same shape.

The alternative is what most teams do today: hardcode if/else chains that ossify within six months, or license a platform that costs more than the process is worth. This project is the third option.

Who this helps

Operations leaders replacing spreadsheet-driven approvals, engineering teams building workflow features into existing products, IT service management teams looking for a ServiceNow alternative, compliance teams standardizing approval processes across business units.

Where you can use this

  • Procurement and purchasing systems — multi-level PO approvals, vendor onboarding, contract signature routing
  • HR operations — hiring approvals, promotion workflows, PTO with delegation logic, exit approvals
  • Finance operations — expense approvals, journal entry review, capex approvals, budget variance workflows
  • IT service management — access requests, change management, incident escalation, service catalog fulfilment
  • Compliance and governance — policy exception requests, regulatory filing sign-offs, audit finding remediation tracking
  • Legal operations — matter intake, contract review routing, conflict-check workflows, settlement approvals
  • Product and engineering — release approvals, architecture review boards, security review workflows
  • Customer operations — refund approvals, escalation routing, credit limit change requests, KYC/AML review flows

Industries where configurable workflow engines are under active demand: financial services, healthcare (clinical protocol changes, credentialing), insurance (claims triage, underwriting workflows), professional services (project intake, resource allocation), higher education (grant approvals, curriculum change workflows), and government (permit issuance, benefit adjudication).

Show technical detail ▾

A .NET 8 workflow engine that treats approval processes as first-class configurable data — not as hardcoded application logic. Core architectural properties:

State machine model: workflows are defined as directed graphs of states, transitions, and guard conditions in JSON or YAML. No recompilation to change a workflow. State transitions are transactional; concurrent transitions on the same instance are serialized via optimistic concurrency control.
Approver resolution: approvers per state can be static users, dynamic roles, computed from the workflow context (e.g. "requester's manager's manager"), or delegated. Includes a delegation-of-authority model with time-bounded delegations and automatic cascade if the primary approver is unavailable.
SLA and escalation: each state can have configurable SLA timers. On breach, the engine can auto-escalate to a defined role, reassign, or trigger a custom action. Escalation history is preserved as part of the workflow instance.
Audit history: every state transition, approval, rejection, comment, and escalation is captured as an immutable event log. The full timeline of a workflow instance is queryable and exportable — for compliance evidence, for dispute resolution, for process analytics.
Extensibility: custom actions on state entry/exit via a plugin interface (invoke webhooks, send notifications, update external systems). The engine ships with a "log-only" notification adapter so you can evaluate the state machine without wiring email/Slack — swap in real notification adapters when you're ready.
Concurrency correctness: stress-tested for race conditions on approval decisions. Includes property-based tests asserting invariants: no double-approval, no orphaned instances, deterministic terminal states.
Install: Clone the repo, dotnet run. Includes three sample workflows (procurement, expense, access request) ready to demo. Docs: Workflow authoring guide, state machine design patterns, migration guide from spreadsheet-based approvals. Contribution: Additional notification adapters, workflow templates for common enterprise processes, and analytics extensions welcome.
.NET 8 ASP.NET Core C# Azure SQL Azure Service Bus Azure Functions MassTransit Blazor
📊

Data Ingestion & Reporting Platform

core-data-reporting

The business case

Every enterprise conversation about software eventually reaches the same place: "can it handle our data, and can it give our executives a dashboard."

This is the least glamorous, most expensive, and most under-delivered layer of enterprise software. It's where projects go over budget. It's where data quality problems get discovered too late. It's where reports show conflicting numbers because two teams built two versions of the same query.

This project is a working reference implementation of that entire layer — done well. Upload structured data. Validate it against defined rules. Transform it through a configurable pipeline. Persist it with role-scoped access. Report on it via dashboards that respect the same permissions.

Adopt it as the ETL and reporting foundation for your own product, extract the parts you need (the validation engine, the role-scoped query patterns, the dashboard components), or use it as the reference architecture your engineering team benchmarks against.

Who this helps

Product teams building analytics into their applications, data engineering leads designing role-scoped reporting, finance and operations teams tired of manual data reconciliation, engineering leads who've been asked to "just add a dashboard" and want to do it correctly.

Where you can use this

  • Analytics inside SaaS products — the "insights" tab customers expect, with proper multi-tenant data isolation
  • Executive dashboards — for finance, sales operations, HR analytics, supply chain visibility — where different roles see different slices of the same underlying data
  • Compliance reporting — for regulated industries where reports need lineage back to source data (financial services, pharmaceutical trials, healthcare quality reporting)
  • Data migration projects — validated ingestion of legacy data into new systems, with error handling that produces a report rather than silently losing rows
  • Consolidation reporting — for multi-entity organizations rolling up numbers from multiple subsidiaries with different data quality standards
  • ETL for downstream systems — as the ingestion and validation layer feeding data warehouses (Snowflake, BigQuery, Redshift) or BI tools (Tableau, Power BI, Looker)
  • Internal ops tools — for teams that today live in spreadsheets: sales operations, procurement, marketing analytics, project reporting
  • Regulatory submissions — where numbers reported to regulators must be traceable back to the source records they were derived from

Industries where this pattern is under active demand: financial services (regulatory reporting, treasury analytics), healthcare (population health, quality metrics), retail and CPG (sales analytics, inventory reporting), professional services (utilization and billing analytics), manufacturing (production reporting, quality control dashboards), and any organization consolidating operational data across multiple business units.

Show technical detail ▾

A .NET 8 platform for structured data ingestion, transformation, storage, and reporting — designed to be embedded in enterprise applications or deployed standalone. Core architectural properties:

Ingestion layer: upload or programmatic import of CSV, JSON, and XLSX. Streaming parser handles files larger than memory. Every ingestion produces a unique batch ID for downstream traceability.
Validation and transformation pipeline: rule definitions in JSON — required fields, type coercion, referential integrity, custom validators via plugin interface. Failed rows are captured with the specific failing rule and offered for manual correction, not silently discarded. Transformation stages are composable and idempotent — reprocessing a batch produces the same result.
Query performance: indexes generated based on declared access patterns. For datasets over 10M rows, the platform includes a columnar-storage tier with automatic hot/cold partitioning. Query plans are logged for every user-facing report to catch performance regressions early.
Role-scoped access: integrates with the RBAC model from Project 1 (or any external RBAC provider via adapter). Data access is filtered at the query layer, not at the application layer — a user querying a table sees only rows their role permits, enforced in SQL. This is the pattern that prevents "finance sees HR data" incidents.
Reporting layer: Blazor-based dashboard components (charts, tables, filters, drill-downs) that inherit the role-scoping automatically. Scheduled reports via cron-style expressions with export to PDF, XLSX, and CSV. Emailed reports go through the same permission filter — a scheduled report sent to a user shows only what that user could see interactively.
Audit and lineage: every report execution logs the querying user, the query parameters, the row count returned, and the batch IDs the data was derived from. Full data lineage from ingestion source to displayed value.
Install: Clone the repo, dotnet run. Includes sample datasets and three pre-built dashboards to demo. Docs: Data model design guide, validation rule authoring guide, dashboard building tutorial, integration guide for embedding in existing applications. Contribution: Additional file format parsers, dashboard components, and export formats welcome.
.NET 8 ASP.NET Core C# Azure SQL Azure Data Factory Power BI Embedded Azure Blob Storage Blazor

Have a project in mind?

See CORE working through a similar example, or let's talk about building yours.

See a worked example → Book a conversation