A content hub that keeps 40 franchise sites on-brand without a bottleneck
A headless CMS where corporate manages shared brand content centrally while each of 40 franchise locations publishes its own class schedule and local promotions without touching code.
Who, what, and how long
- Industry
- Healthcare & Dental Practices
- Duration
- 9 weeks
- Cooperation model
- Fixed price
Client name withheld under NDA. Engagement details are shown to the extent our agreement permits.
Two kinds of content
Brand content and location content modeled as distinct related types, never one mixed pool.
Brand content and location content are separate types with a defined relationship, never one pool with a flag on it. A location page composes centrally owned brand blocks with its own hours, staff and offers, so a national campaign lands everywhere without a franchisee having to paste it, and a franchisee editing their own page can't alter the campaign.
- Brand and location modeled as distinct related types
- Location pages compose central blocks with their own content
- National campaigns land without franchisee action
The content library: 84 brand sections that go to all forty sites beside 1,120 location entries that go to exactly one, nine content types owned by type instead of by a flag, and how one club page composes central blocks with its own.
Four roles against nine content types, with location managers publishing classes and hours while offers are signed off regionally, a tampered club URL returning null from the API, and the two rules the pilot settled.
Scoped editors
Each location's staff can reach only their own content, and the API enforces it.
Editor scope is derived from the location a user belongs to and enforced in the API, not in the interface. A franchisee can't reach another site's content by editing a URL, because the query never returns it. Roles are granular enough that a manager can update hours while only a regional lead can change an offer, which is what made devolving editing acceptable to head office.
- Scope enforced in the API, not by hiding interface
- URL tampering returns nothing, never another site's content
- Granular roles: hours devolved, offers held regionally
Central brand control
A campaign section versioned centrally and scheduled onto all forty clubs across four regions, 80 pages to regenerate and no location entry touched, with a legal footer correction made once for every site.
Corporate pages stay centrally owned and versioned across all forty sites.
Corporate pages are owned centrally and versioned, so the legal footer, the brand story and the compliance copy are the same forty times over and can be corrected once. Publishing a brand change regenerates only the affected pages across all forty sites, which keeps a wording fix a two-minute operation instead of a scheduled deploy.
- Corporate pages centrally owned and versioned
- One correction propagates across all forty sites
- Incremental regeneration: a wording fix takes minutes
What we were brought in to do
Forty franchise locations each needed to publish their own class schedules and local promotions, but every change went through a single corporate webmaster, so simple updates took days.
Forty franchised locations, each running its own class timetable and local promotions, all published by one corporate webmaster. A location wanting to move a Tuesday class emailed the request and waited. The engagement was commissioned when a franchisee started running a parallel unofficial page on a social platform because the official one couldn't keep up with their schedule.
Content Platform Engineering
Where the old way broke
Corporate brand pages and location-specific content lived in the same undifferentiated CMS with one set of editor permissions, so a location manager couldn't update a class time without going through the same queue as a brand-wide campaign change.
Brand pages and location pages sat in the same CMS with one set of editor permissions, so there was no way to let a location manager change a class time without also letting them change the brand's compliance copy. The safe answer had been to let nobody edit, which put a corporate webmaster in the path of forty locations' routine timetable changes.
We modeled brand content and location content as distinct, related types, gave each location's staff scoped editor access to only their own content, and kept corporate brand pages centrally controlled, all delivered through one API to a shared site template.
What we built together
- 01
Separated brand-level and location-level content into distinct, related types
Brand content and location content are distinct related types, never one pool with a flag, which is what makes a scoped permission expressible at all.
- 02
Built scoped editor roles so location staff can only touch their own content
Enforcing scope in the API, not just the interface, was the point corporate needed convincing of, since a franchisee doesn't have to be devious to edit a URL.
- 03
Kept corporate brand pages centrally controlled and versioned
Corporate pages stay centrally owned and versioned, so the legal footer and compliance copy are the same forty times and correctable once.
- 04
Delivered everything through one API to a shared, brand-consistent template
Two locations piloted the scoped role first, which is why hours devolved to managers while offers stayed at regional level.
Phase by phase
Phase 1: Separate
Brand from local
Separated brand-level and location-level content into distinct, related types with an explicit relationship.
- Content model
- Relationship map
Phase 2: Scope access
Forty editors, forty scopes
Built scoped editor roles so location staff could only touch their own schedules and promotions.
- Role definitions
- Permission tests
Phase 3: Centralise
Brand pages, versioned
Kept corporate brand pages centrally controlled and versioned so a change rolls out consistently.
- Version control
- Rollout mechanism
Phase 4: Deliver
One template, forty sites
Delivered everything through one API into a shared brand-consistent template.
- Delivery API
- Shared template
- Location onboarding guide
A week of activity: 412 publishes at a median of four minutes against the old three days, split by day between clubs and head office, the queue of twelve local offers and six scheduled brand sections, and recent publishes with their save-to-live time.
Operational results after launch
Days → minutes
Time to publish a local update
40 of 40
Locations self-publishing
−85%
Corporate webmaster queue
Time to publish a local update compares the previous email-and-wait cycle with the current self-serve one. Forty of forty self-publishing is a count of locations that published at least once unaided in the first quarter. The webmaster queue reduction is that role's own ticket count, before and after.
Client name withheld under NDA. Figures are approximate, drawn from the engagement’s own reporting.
About our collaboration
A cross-functional team of 4 worked on a fixed price basis over 9 weeks, covering Content modeling, Editor roles, Headless CMS build. We ran daily standups with their own lead in the room, and a demo at the end of every sprint. Scope changed twice during the engagement, and both times the change was priced and agreed before work started.
Nine weeks, fixed price, with the content split (brand versus location) settled with corporate marketing in week one, because everything else follows from it. Two locations piloted the scoped editor role before the other thirty-eight, and the granularity changed as a result: hours devolved to managers, offers held at regional level.
What we'd carry into the next one
- 01
The bottleneck was corporate reviewing local content it had no reason to review.
Corporate had been reviewing class times it had no basis to have an opinion about. The queue existed because permissions couldn't tell the two kinds of change apart.
- 02
Scoped permissions turned forty potential brand violations into forty independent editors.
Scoping made devolution safe. Nobody had been given access because access had been all-or-nothing, not because the franchisees couldn't be trusted.
- 03
One template is what keeps forty sites on-brand. The CMS alone wouldn't have.
The template is what holds the brand, not the CMS: forty editors with the same content model and no shared template would still produce forty different sites.
One club page, five sections, two owners
The club publishes its timetable. It can’t touch the price.
Take the Cedar Falls manager’s seat. Pick a section of her page and try to change it: local sections go live on her site alone, the offer waits for her regional manager, and brand sections are refused by the API. Switch tabs, or use the arrow keys once one is focused.
- Draft savedby Renée Alvarez0:00
- Scope checked in the APIentry club = cedar-falls ✓0:01
- Page regenerated/clubs/cedar-falls only · 1 page0:20
- Live on the club siteNo other club touched0:25
Nothing sent yet
Step times are illustrative, not measured, and exclude the time a person spends writing. The recorded figure is the median publish across the 40 clubs in a week: four minutes, against 3 days before.
From a club manager’s save to the one page it belongs on
Forty clubs write into one content model through one API, and the shared template is what keeps forty sites on brand. Who may write what is decided in the API, before anything is stored.
- 01 · EditHub editorHead office edits brand sections; each club's staff edit their own schedule and promotions, without touching code.
- 02 · ScopeGraphQL API + role checkScope comes from the location a user belongs to and is enforced in the API. A tampered URL returns nothing.
- 03 · ModelBrand & location typesDistinct related types, never one pool with a flag. A club page composes central blocks with its own entries.
- 04 · StateVersioned brand entriesCorporate pages are owned centrally and versioned, so a footer or compliance line is corrected once for all forty.
- 05 · DeliverOne template, 40 sitesNext.js with incremental regeneration: a change rebuilds only the affected pages, so a wording fix takes minutes.
Forty editors, one brand, no way into another club’s page
Scope is enforced, not trusted
Editor scope is derived from the location a user belongs to and enforced in the API, not by hiding parts of the interface. Editing a URL to reach another club returns nothing, because the query never returns it.
Compliance copy has one owner
Corporate pages, the legal footer and the brand story are owned centrally and versioned. A club editing its own page can't alter them, and a correction is made once for all forty sites.
Rollouts leave clubs' work alone
Brand and location content are separate related types, so a national campaign lands on every site without a franchisee pasting it, and without touching the schedules and offers each club wrote.
Running many locations that should publish their own pages without breaking the brand? Scope your build in 3 minutes.
Scope your buildNearby engagements
Web PlatformsThe ransomware attack that became a four-hour non-event
A ransomware attack encrypted the primary patient records server. Drilled offsite backups and a written runbook turned what could have been a scramble into a full restore inside the recovery time objective.
Healthcare & Dental Practices · Ongoing retainer
E-commerceA cart that won't check out until the prescription is real
An online pharmacy where a prescription is a first-class record with its own lifecycle, and prescription-only items simply can't leave the cart without one.
Healthcare & Dental Practices · 20 weeks
Web PlatformsThe right blood type isn't enough: it has to be someone who can get there
A donor register that matches each request on blood-group compatibility and on whether the donor can actually reach the hospital. One platform serves a web admin and a mobile client from the same records.
Healthcare & Dental Practices · 16 weeks
Let's talk
Running a large platform, shaping a first MVP, or getting a product ready for a funding round? Tell us where you are. We'll shape the process around it, and stay with you after launch.














