Secure bulk APIs for a state government screening programme
Secure bulk APIs and automation behind background checks for people working with children, in disability services and in aged care.
- Client
- Department of Human Services, South Australia
- Role
- Technical Lead, onsite in Sydney
- Through
- Cloudwerx
- Industry
- Government
How it fits together
External agencies
Search and register people in bulk
MuleSoft
Integration layer
Person Search and ROI API
Custom Apex REST, OAuth 2.0 JWT, partial success
Screening records and reference numbers
Exact-match identity, collision-free numbering
Oracle billing sync
Scheduled, retry-safe, batches of 25
Orange marks the parts I built.
Context
The Screening Transformation Program runs background screening for people who want to work with children, in disability services or in aged care. External agencies need to check screening records, and the platform needs to exchange information with several other agencies for each type of check.
The problems
- Agencies needed to search many people in one request, and one bad record could not be allowed to fail the whole batch.
- Matching the right person mattered more than anything else. A wrong match on this kind of data is not acceptable.
- Every applicant needed a unique reference number, even when many applications arrived at the same moment.
- Each check type talked to a different set of agencies, and every new combination was costing configuration effort.
- A monthly finance process was manual.
What I designed and built
- B2B Person Search and Registration-of-Interest API
- A custom Apex REST service consumed through MuleSoft, split across six classes with one job each: entry point, data transfer objects, search, registration, logging and utilities.
- Two-tier validation with partial success
- Organisation and officer checks run once for the request; each person is then validated on their own. The response reports success or a documented error code per item.
- Exact-match identity logic
- Matching across normalised reference numbers, date of birth and full name, with a variant that returns only the latest outcome when someone has renewed.
- OAuth 2.0 JWT Bearer flow, end to end
- RSA 2048 key pair, signed tokens, a dedicated integration user and token caching for all traffic between MuleSoft and Salesforce.
- Metadata-driven third-party check framework
- Routes three check types to the right combination of four external agencies. New combinations are added by configuration.
- Concurrent-safe reference number engine
- No collisions, and a full audit trail from person to identifier to outcome.
- User permission assignment framework
- Grants the right access whenever a user is created or changes role, for 100+ internal users.
- Finance billing engine
- Scheduled sync to Oracle with a triage workspace, safe retries and batches of 25.
How I worked
I wrote the solution design specifications that the integration engineers, testers and the client worked from, which let three teams build in parallel. I owned user acceptance testing onsite, and kept the offshore developers aligned with a written handover every day.
Outcome
Launched with a low defect count. I was promoted to Associate Team Lead during the programme.
Skills used
- Apex REST
- OAuth 2.0 JWT
- MuleSoft
- Custom Metadata
- Platform Events
- LWC
- Oracle ERP
- Solution design
- UAT
Next case study
A live AI agent, and the data pipeline behind it