Checklist
From Lovable to enterprise production
Lovable and Supabase make it possible to build a working internal app in days. Running it safely for hundreds of employees with real company data is a different job. This is the checklist we work through.
1. Single sign-on with Entra ID
Replace email/password accounts with SSO through Microsoft Entra ID (SAML or OIDC). Map Entra groups to application roles, stored in a separate roles table — never on the user profile — and remove access automatically when people leave.
2. Row-level security review
Every table needs RLS enabled and policies that match the real access model. Check for tables without policies, policies that trust client-supplied values, overly broad read access, and admin checks done in the browser.
3. Secrets
No private keys in the frontend or the repository. Move API keys to server-side secrets, rotate anything that was ever exposed, and give each environment its own credentials.
4. Environments
Separate development, test and production — with separate databases and data. Production data is never used for experiments; test data is synthetic or anonymized.
5. CI/CD
Code in your own Git repository, pull-request review, automated tests, database migrations versioned and applied through the pipeline, dependency and secret scanning, and a repeatable deploy with rollback.
6. Observability
Structured logs, error tracking, uptime monitoring and alerts that reach an owner. For AI features, add tracing of prompts and tool calls with PII redaction, plus cost and quality metrics.
7. Data residency and compliance
Decide where data is stored and processed — typically an EU region — and document sub-processors, retention and a data processing agreement. Classify the data the app touches and check GDPR and EU AI Act obligations.
8. Ownership and support
Name an accountable product owner and a technical owner, write a runbook, and agree on support hours and incident handling. A production system is a product, not a demo.