Corporate groups
Employee portals, internal CMS and workforce tools for corporate groups, built on Microsoft Entra ID single sign-on and delivered with the security evidence your review will ask for.

What usually goes wrong
- Everyone already has a Microsoft account. If the intranet asks for a second password, nobody will use it.
- Internal news goes out as a mass email and a PDF, and HR cannot publish anything without opening a ticket with an agency.
- The staff directory only exists inside Microsoft 365, so finding a colleague in another brand means asking around.
- Every proposal we like dies in the security review, and we lose a quarter starting again.
- We are several brands with several email domains, and every tool treats us as either one company or as strangers.
- We are locked into an intranet product: the roadmap belongs to the vendor, and our content is hard to get out.
What we build
- Employee portals with Microsoft Entra ID single sign-on and role based access, including an administrator preview of each role
- A corporate directory synced from Microsoft Graph with a resumable delta sync, proven at tens of thousands of records
- An internal CMS in two languages for news, announcements and benefits, edited by communications and HR without a developer
- A notification system with typed events, per-user preferences, mandatory notices and an in-app notification centre
- Digital employee cards with signed Apple Wallet and Google Wallet passes, branded QR and vCard download
- Native iOS and Android apps from the same codebase, signing in over a deep link, released by git tag and updated over the air
- Security hardening and compliance pages: HTTP headers, content security policy, row level security review, cookie consent with an audit trail and GDPR rights forms
What changes in this sector
In a corporate group the decision is almost never one person's. Internal communications wants the portal, IT owns identity, security reviews the architecture and procurement wants a closed number. So the work starts with an audit and a written scope, not with a design concept.
Three things separate this from a normal web project. Identity already exists: every employee has a Microsoft account, and asking for a second username and password is enough on its own to kill adoption. The organisation is plural: several brands, several email domains and several legal entities under one roof, and a person can belong to more than one. And nothing reaches production without passing a security review, so headers, content security policy, row level security, consent and audit trails belong to the build, not to a later phase.
What we build
Polargate builds the signed-in layer of a corporate group. An employee portal with Microsoft Entra ID single sign-on and a directory kept in step with Microsoft Graph, so joiners, leavers and role changes come from your tenant instead of a second list. Role based access with a permission catalog, so HR, management and editors see different portals and an administrator can preview each role. An internal CMS in two languages, so communications and HR publish news, announcements and benefits without a developer. Notifications with typed events, per-user preferences and mandatory notices. Digital employee cards with signed Apple Wallet and Google Wallet passes. Native iOS and Android apps from the same codebase, signing in over a deep link, updated over the air. And on the public side, the compliance pages a group needs: ethics and anticorruption policies in two languages, a working GDPR rights form, cookie consent with an audit trail.
What it costs
The Discovery Sprint is fixed price, from 4,900 EUR, and half of it is credited against the build if it starts within 60 days. A first phase of a portal is fixed price too, from 12,000 EUR, and usually lands between 12,000 and 25,000 EUR depending on the number of modules and integrations. It can be paid in six to ten monthly instalments. After launch, a CARE retainer from 850 EUR per month covers senior maintenance and evolution, with every ticket and the hours it consumed visible in the ServiceDesk. These are from figures: the exact number comes out of Discovery, in writing, before anyone writes code.
How we prove it
The reference is a corporate web platform for a European travel group with several consumer brands and more than 10,000 employees. The audit came first. It found access control defects, missing HTTP security headers, a row level security model that was re-evaluating permissions for every single row, and the data and the sign-in living in two disconnected places. All of it was closed before the new work started, and the detail stays between us and the client.
The portal now runs on a single backend with Microsoft sign-in on web, iOS and Android, released by git tag. The directory carries about 45,600 records; its Graph sync used to stop at exactly 10,000 users and was rebuilt to resume. Security headers score A, SSL Labs reports A+, and the Supabase security advisors, the row level security performance warnings and the duplicate policies all sit at zero. HR publishes announcements and benefits without opening a ticket.
The group is not named here. This work sits under an agreement, so it is described without the client's name; Polargate names a client only where the work is already public. Under an NDA, Pedro Ciordia walks your security and IT teams through the architecture directly.
Questions, answered
Can an employee portal use our existing Microsoft 365 accounts?
How much does an employee portal cost?
Will this pass our security review?
Can it connect to the systems we already run?
Do employees get an app, or only a website?
What happens if we stop working with you?
Start the engine
Tell us what you are building in a few short questions. A senior engineer answers in writing within 48 business hours, with a first take on scope, timeline and price.
