matt-taylor.tech

Engineering

Engineering projects

A selection of the infrastructure, automation, integrations, and internal platforms I've built in production, alongside the businesses and products I operate outside work. Each card links to a deeper write-up.

Filter by topic

Work

AI-augmented IT operations platform

Internal Python and Supabase platform unifying six IT source systems into one analyzable store, with a live Claude agent running on top. Technicians make plain-language requests in private ticket notes; the agent reasons over the whole ticket, including screenshots, and escalates across a confidence cascade. Analysis is unconstrained, but every write is confirm-gated.

Python Supabase Azure Functions Microsoft Graph Claude API (incl. vision) Cowork skills
Read more →

IT Ops MCP server

A live Model Context Protocol server exposing IT's operational systems to Claude as one connector: tools across Freshservice, ScreenConnect, Meraki, Dell warranty, and Microsoft Graph. Read-heavy, with governed writes whose trust boundary sits at the identity layer, so every action is scoped and attributed to the individual technician rather than a shared account.

Python FastMCP Azure Container Apps Entra OAuth (OBO) Microsoft Graph Freshservice ScreenConnect Cisco Meraki Dell TechDirect
Read more →

IT documentation library, generated from live systems

Thirteen domains covering the estate end to end, generated from the live systems through Microsoft Graph, Meraki APIs, PowerShell over ScreenConnect, and Freshservice. The library closes the loop: exposed back through the MCP server as a read-only skill, it grounds the ticket agent's answers in documented standards and proposes corrections as human-reviewed pull requests.

Python MCP server Microsoft Graph Azure Cost Management Cisco Meraki API PowerShell ScreenConnect Freshservice API Snowflake Markdown
Read more →

Multi-site Remote Desktop Services platform

Designed, deployed, and documented a multi-site Remote Desktop Services platform serving roughly 850 users. One site splits the RDS roles across separate servers with the gateway isolated in a DMZ; a regional site runs a consolidated single-server deployment. Public access is TLS-fronted with certificates auto-renewed through Let's Encrypt and Cloudflare DNS-01.

Windows Server 2022 Remote Desktop Services RD Gateway / Broker / Web Access / Licensing Certify The Web Let's Encrypt + Cloudflare DNS-01 Group Policy PowerShell
Read more →

Microsoft 365 tenant architecture and governance

The documented architecture and governance of the Microsoft 365 estate: Entra ID identity governance, Conditional Access policy design, app registration and SaaS integration inventory, a licensing model mapped to SKUs, and workload configuration across Exchange Online, Teams, SharePoint, and Power Platform. The reference layer every identity, security, and automation decision builds on.

Microsoft Entra ID Conditional Access Privileged Identity Management Microsoft 365 Microsoft Graph
Read more →

Enterprise browser extension for a vendor portal

Edge/Chrome MV3 extension automating a monthly irreversible bulk-email process inside a partner's legacy contract portal. It runs entirely in the operator's authenticated session, so no credentials are stored or relayed and there is no backend. Dry-run and supervised-batch guardrails throughout; distributed as a signed .crx with silent auto-update, force-installed through Intune.

Chrome/Edge MV3 chrome.scripting GitHub Actions Cloudflare R2 Intune (Edge + Chrome policy)
Read more →

Intune fleet management and proactive remediations

Endpoint fleet automation across 51 offices in Microsoft Intune: scheduled proactive remediations, app packaging, batch antivirus removal, per-division serial-based device renaming, Edge bookmark policy templates, and winget and Chocolatey update orchestration.

Microsoft Intune PowerShell Proactive Remediations Win32 app packaging Autopilot
Read more →

Client Services activity report (serverless)

Monthly Microsoft 365 activity report (email, Teams, SharePoint, OneDrive) for Client Services and Reconciliation staff, migrated from an on-prem scheduled task to a serverless Azure Automation runbook. Authenticates with a system-assigned managed identity via Microsoft Graph: no server, no certificates, no stored secrets. Scoping the Mail.Send permission to one mailbox is a tracked open item.

Azure Automation PowerShell 7 Managed identity Microsoft Graph
Read more →

Client Manager distribution list automation

Keeps Exchange Online distribution lists and the Entra ID security groups behind Microsoft Fabric access in step with live CRM data, nightly, for every client. Re-architected off an on-prem scheduled task onto a single Azure Automation runbook on a system-assigned managed identity, removing a stored credential and a permissive parser.

Power Automate Azure Automation PowerShell Managed identity Microsoft Graph Exchange Online SharePoint
Read more →

Service catalog and onboarding/offboarding automation

Structured Freshservice service items handling the company's full onboarding and offboarding volume. Multi-ticket onboarding cascade plus HR Onboarding Teams App plus Power Automate flows propagating to Freshservice, the outgoing MSP, and the company CRM. Provisioning time compressed from hours to minutes.

Freshservice Power Automate Power Apps Entra ID Dynamic groups
Read more →

HRIS integration via Entra ID SCIM

SCIM-based integration consolidating three upstream HR platforms onto one centralized HRIS as the system of record for employee lifecycle events fanned out through Entra ID. User attribute standardization, SCIM connector config, UAT, vendor handoff, plus a downstream HRIS-to-CRM notification flow.

HRIS (SCIM) Microsoft Entra SCIM Entra ID Power Automate
Read more →

Employee SMS broadcast platform

Production employee broadcast platform: Microsoft Forms + Power Automate + Graph + Twilio with Teams approval routing, dynamic Entra ID audience targeting, and CTIA-compliant toll-free A2P.

Microsoft Forms Power Automate Microsoft Graph Twilio Cloudflare Worker
Read more →

Cross-platform data sync

A family of integrations keeping data flowing between systems never built to talk to each other: Entra ID into Snowflake, CRM into Exchange Online distribution lists, the HRIS into Entra over SCIM, and seven IT tools into a Supabase backbone. The Entra-to-Snowflake pipeline, a stored procedure with no external server, gets the deep dive.

Snowflake (Python runtime) Microsoft Graph SCIM Power Automate PowerShell Supabase SQL MERGE
Read more →

HPSCAT vendor data ingestion pipeline

PowerShell and Microsoft Graph pipeline replacing manual monthly reporting across a changing manufacturer roster. Re-hosted onto a domain service account with encrypted credential storage as part of a fleet-wide automation hardening pass.

PowerShell Microsoft Graph SharePoint Static-IP whitelisting Windows DPAPI
Read more →

Freshservice reporting infrastructure

Executive reporting on Freshservice built by connecting Power BI directly to the REST API rather than accepting the vendor's native reports. Published to a workspace with scheduled refresh: no intermediate warehouse, no pipeline to operate. Years in continuous service.

Freshservice API Power BI Power Query Microsoft Fabric (F64)
Read more →

M&A IT Integration Toolkit

Reusable cross-tenant PowerShell migration tooling and an operating playbook generated by a Node.js + docx document builder. Backed by a full task-level work inventory inside a reusable repo template.

PowerShell Movebot Microsoft Graph Node.js Astro Cloudflare Pages
Read more →

Security operations and incident response

Built and run the security posture: a sustained account-compromise caseload handled under a documented response procedure, a standing activity-audit discipline, and platform controls across Defender XDR, risk-based Conditional Access, PIM, and Windows LAPS. Point security tools were consolidated into the platform layer on a metrics-backed case.

Microsoft Defender XDR Entra ID P2 Conditional Access Privileged Identity Management Windows LAPS AdminDroid CISA ScubaGear
Read more →

Enterprise naming and identity standards

Seven interlocking standards covering compute, identity, network, and directory naming, designed so one attribute on the user object drives every downstream automation: dynamic group membership, licensing, Conditional Access scoping, Intune targeting, printer assignment. Versioned and governed, each documenting the format it replaced.

Entra ID dynamic groups Active Directory Intune Conditional Access Microsoft 365 groups IP address management
Read more →

Managed SD-WAN / ISP standardization (multi-region)

Region-by-region migration of per-office internet, individually contracted across several carriers with no common management layer, onto managed SD-WAN. Overlap-first dual-WAN cutovers on the Meraki MX fleet are sequenced around contract terms, with LAN re-addressing and segmentation riding each cutover.

CommandLink SD-WAN / NaaS Cisco Meraki MX (dual-WAN) AT&T Business Fiber Spectrum / Comcast / Cox Entra Conditional Access
Read more →

Multi-site network architecture refresh

Foundational multi-site network refresh across one region's office estate. Meraki MX appliances + Aruba Instant On switching + APs, installed personally on a two-week road trip.

Cisco Meraki HPE Aruba Instant On Site-to-site VPN MFP central monitoring
Read more →

Multi-region phone system consolidation on Teams Phone

Multi-year program retiring a fragmented regional telephony estate, several hosted PBX platforms inherited through acquisition, and standardizing the company on Microsoft Teams Phone with Calling Plans through a hardened, repeatable cutover playbook.

Microsoft Teams Phone Microsoft Calling Plans Teams Admin Center DID porting Auto-attendants / call queues
Read more →

Microsoft Fabric F64 migration

Migrated the BI estate off a per-seat Power BI Pro licensing model onto a single Fabric F64 capacity: dynamic Entra ID group access instead of manual provisioning, row-level security so partners see only their own data, and external sharing without buying licenses. Zero-downtime cutovers.

Microsoft Fabric (F64) Power BI Semantic models Row-level security Entra ID dynamic groups
Read more →

Snowflake platform review: cost, performance, and security

A read-only review of a Snowflake account owned by the BI team, not IT, from live ACCOUNT_USAGE introspection. Three findings the owning team acted on: reporting was half of compute spend, the Power BI warehouse was badly undersized, and the access model around service and consultant accounts needed tightening.

Snowflake ACCOUNT_USAGE Claude Cowork Browser extension Power BI / Fabric
Read more →

Three-layer observability stack

A three-layer observability stack built and run solo for a 125-user multi-site business: PRTG sensors, Telegraf-style Windows agents, and hand-written bash SNMP collectors feeding InfluxDB, with Grafana on top. Per-role telemetry profiles across hypervisor, SQL, domain controllers, network, and storage.

PRTG Network Monitor InfluxDB Grafana Influx Capacitor Bash SNMP v2c
Read more →

Full-stack technology modernization

Modernized an entire small-business technology stack as one program: server infrastructure, Active Directory from scratch, Office 365 migration, network refresh, replacement of a legacy Unix service-management system on SCO OpenServer (vendor-driven data conversion), and iPads with MDM that took field technicians off paper.

Windows Server Active Directory Office 365 Network refresh iOS / MDM SCO OpenServer
Read more →

Enterprise AI rollout, policy, and governance

Own the AI program end to end: governance, developer platform, and rollout. Authored the corporate AI Policy and a separate AI-Assisted Development Policy, backed by a developer handbook and repo template. Policies apply company-wide; licensing is phased across Copilot and Claude for Teams, with admin config version-controlled and applied by pull request.

Claude for Teams Claude Code GitHub Copilot Microsoft Copilot Studio Model Context Protocol (MCP) GitHub organization Azure Key Vault Microsoft 365 / Entra ID Microsoft Purview
Read more →

IT operating-model standardization

The defining technology program: turning nine separately operated regional estates into one operating model across identity, Dell endpoints, Meraki and Aruba office networks, Teams Phone, Freshservice, vendors, documentation, and acquisition integration. A national-scale continuation of the standardization model first built across three offices and brands.

Microsoft 365 / Entra ID Dell business endpoints Intune Cisco Meraki Aruba Instant On Microsoft Teams Phone Freshservice MTS Office
Read more →

Dependency-sequenced IT roadmap

Author and maintain a dependency-sequenced IT roadmap: nine single-topic initiative documents plus a sequencing README, each stating what it depends on and what it blocks, so leadership can see which decisions gate which projects. Grown out of an annual State of IT assessment with honest progress reconciliation.

Markdown Git Docs-as-code Dependency sequencing
Read more →

Support channel centralization on Freshservice

Heading a program to bring every support team (CRM, application, mobile app, data, and IT) onto one Freshservice ticketing platform, replacing today's mix of email, shared mailboxes, and disparate per-team tools. One front door, per-team queues, shared SLAs and reporting.

Freshservice ITIL
Read more →

Freshservice implementation

End-to-end ITSM platform rollout replacing inherited spreadsheets and ad-hoc ticketing. Thousands of tickets a year, a live asset inventory covering the company fleet, and a knowledge base spanning every IT domain.

Freshservice ITIL REST API Power BI / Fabric
Read more →

IT operations runbook library

A library of operational runbooks standardizing how the IT team runs day to day: onboarding and offboarding, password resets, computer deployment, macOS enrollment, server patching, backup and recovery, purchasing, and endpoint escalation. Written as repeatable procedures so any team member, a new hire included, can execute them consistently.

Markdown Freshservice Power Automate Intune Apple Business Manager
Read more →

Open source

Entra stale-guest lifecycle automation

github.com/matt-taylor-tech/Entra-StaleGuestsCleanup ↗

Managed-identity PowerShell runbook for staged Microsoft Entra guest cleanup. Report-only by default, with disable-before-delete controls, exclusions, privileged-role skipping, blast-radius limits, anomaly aborts, and Pester tests. Built and tested as a tenant-neutral public reference; deployment is not claimed.

PowerShell Microsoft Graph Azure Automation Managed identity Pester GitHub Actions
Read more →

Dell warranty to Freshservice sync

github.com/matt-taylor-tech/DellWarrantytoFreshserviceAssets ↗

Portable Python integration that resolves Dell TechDirect entitlements and enriches matching Freshservice assets with coverage detail. Dry-run by default, with runtime field discovery, collision guards, write caps, idempotent updates, offline tests, and no third-party dependencies. Built and tested; deployment is pending.

Python Dell TechDirect API Freshservice API OAuth 2.0 GitHub Actions
Read more →

ScreenConnect remote endpoint ops toolkit

github.com/matt-taylor-tech/sc-remote-endpoint-ops-toolkit ↗

Claude skill for running commands on and diagnosing ScreenConnect sessions through its REST API: session lookup, command execution with captured output, and read-only diagnostic playbooks. The API has no per-user scoping, so the guardrails live in the tool itself: a destructive-command denylist, confirm-first for state changes, and secret redaction on everything leaving a session.

Python ScreenConnect RESTful API Manager Claude Code / Cowork plugin Freshservice (optional)
Read more →

Subreddit Sounds

github.com/matt-taylor-tech/subreddit-sounds ↗

Turns what a music subreddit is posting into a self-refreshing Spotify playlist. Resolves Reddit, YouTube, and Bandcamp posts to Spotify tracks (genre and duration filtered), then rolls the playlist to the latest N. Python and FastAPI in one container, with a browser setup wizard and a daily scheduled job. Public repo; my most-played playlist.

Python FastAPI SQLite SQLAlchemy 2.0 APScheduler Jinja2 Docker Reddit API Spotify API
Read more →

Founder-built businesses

Volleyball Engine

volleyballengine.com ↗

The custom software that runs the league's competition and payouts. Next.js and TypeScript on Cloudflare Workers: season schedule generation, six tournament formats including a Swiss pairing algorithm with teammate-penalty scoring, real-time live scoring over Supabase subscriptions, playoff brackets, and a revenue-split calculator driving 1099 contractor payouts.

Next.js TypeScript Cloudflare Workers Supabase React Playwright Vitest
Read more →

Matt's Volleyball League

mattsvolleyball.com ↗

A recurring volleyball league I founded and run as a side business with a contractor team. The public side runs on a Teamlinkt API integration pulling live schedules, scores, and standings into an Astro site on Cloudflare and a GroupMe system driven by scheduled GitHub Actions.

Teamlinkt API Astro Cloudflare Pages Functions GitHub Actions GroupMe API Playwright Affinity Designer
Read more →

Independent Mobile App Business

Focused an initial portfolio of around 20 apps on one profitable product, unpublishing the other 19. The retained app has exceeded 50,000 lifetime app sales across iOS and Android. Now maintained with Flutter and Dart, supported by Python content tooling.

Flutter / Dart App Store Connect Google Play Console Python
Read more →

Personal

matt-taylor.tech

This site. Astro 5 + Tailwind v4, content modeled as typed TypeScript data instead of CMS pages, Pagefind for static search, dark mode with persistence, Cloudflare Pages deploy from a GitHub-connected repo. Built and maintained as portfolio and personal lab.

Astro 5 Tailwind v4 TypeScript Pagefind Cloudflare Pages
Read more →

Home lab and home automation

A datacenter pattern run at home: a two-node Hyper-V cluster on Windows Server 2025, a redundant Active Directory forest, a non-routed 10GbE storage fabric with iSCSI behind it, a 3-2-1 Veeam and Backblaze backup program, a separate Microsoft 365 E5 tenant for non-production work, and Home Assistant at whole-house scale. Documented as code.

Hyper-V Windows Server 2025 Active Directory iSCSI / 10GbE Veeam Synology HPE Aruba Home Assistant
Read more →