Selected professional practice

Work that crosses the org chart.

The strongest engineering work rarely belongs to one product. These sanitised cases show how I approach identity, infrastructure, application delivery and operational ownership when they meet.

01 / DataBalk

Cloud Service Engineer

Cloud engineering with guardrails.

Selected patterns from Microsoft cloud operations, identity, application integrations and deployment design. Customer names, tenant details and live topology are intentionally omitted.

01

Azure governance · PowerShell · ARM · Microsoft Graph

Cloud inventory without a secret-value path

Designed bounded, multi-tenant inventory tooling for Key Vault metadata, access models, role assignments and scan coverage. Strict host allowlists, request budgets and an explicit metadata-only boundary kept the tool useful without creating another route to sensitive values.

Coverage is evidence too: an inaccessible subscription remains visibly incomplete instead of being reported as an empty result.
02

Microsoft Entra · PIM · Least privilege

Privileged access with an operator still in control

Built a guarded role-activation helper around exact tenant matching, bounded duration, justification, interactive confirmation, WhatIf support and authoritative readback.

Administrative convenience should reduce repetition, not remove the moment where an operator understands and approves elevated access.
03

Entra applications · Service principals · Consent

Identity configuration as comparable evidence

Created deterministic exports of application registrations, enterprise applications, permissions and consent to support cross-environment investigation and alignment while deliberately removing credentials and public-key material.

Configuration comparisons become dependable when collection is exact, repeatable and separate from secret material.
04

Business Central · Azure DevOps · Preflight design

Find the deployment boundary before changing it

Mapped the boundary across vaults, access, diagnostics, pipelines and service connections with a read-only preflight before a broader deployment-identity change was considered.

The preflight contained no mutation path. When the surrounding architecture did not support a safe assumption, the migration direction stayed parked.
05

OIDC federation · Azure RBAC · Cloudflare One

Secretless delivery and simpler network paths

Worked on workload-identity federation for deployment and on routed Cloudflare connectivity for managed desktops—favouring short-lived identity and direct supported paths over stored secrets, proxy layers or guessed topology.

A simpler architecture is valuable only when its identity, network and verification boundaries are explicit.

02 / Visnovo

DevOps Engineer

Visnovo

Build it, operate it, prove the result.

Development and customer delivery sit alongside responsibility for hosting, mail and infrastructure. I continue to work with Visnovo following its takeover of Obsite, alongside a small amount of independent freelance work. The examples below stay at architecture level to protect operational detail.

01

Python · DNSSEC · DANE/TLSA · Cloudflare · Plesk

Certificate state reconciled across systems

Engineered an active reconciliation platform that compares mail-service certificate state with DNS and provider state, then applies bounded additive changes through separate privilege layers.

Rollover is additive first. Manually owned records are never silently claimed, ambiguous DNSSEC state fails closed and cleanup waits through two TTL windows.
02

Linux · systemd · Plesk · Roundcube

Managed hosting that repairs drift safely

Combined customer-facing hosting customisation with operational guards that snapshot, hash, repair through supported tooling and verify convergence when generated configuration drifts.

Branding remains decorative and inherits vendor-managed assets; it does not modify authentication or create a fragile fork of the upstream interface.
03

Registrar · DNS · Mail · Hosting · Account ownership

Service handover as a systems problem

Separated domain registration, DNS, web hosting, mail, DNSSEC/DANE and account access into explicit handover tracks with allowed, denied and incomplete acceptance states.

A nameserver change is not a complete handover—and becomes dangerous when security records and non-DNS services are treated as incidental.

03 / Obsite

Founder · 2019–2024

Technical ownership became business ownership.

Obsite was where infrastructure, web delivery and direct client accountability became one role. Visnovo later took over the agency; the work continued through Visnovo while a small independent freelance practice remained alongside it.

01

Founded and operated a technical digital agency from 2019 to 2024 before its takeover by Visnovo.

02

Owned Linux and Proxmox infrastructure alongside customer web and email hosting.

03

Combined development, optimisation and SEO with direct client advice and partner delivery.

04

Continued working with Visnovo after the takeover while retaining a small independent freelance practice.