hayman.dev LTD logo
Case Study • Lumina by AMBA UK

Every benefit, behind one sign-in

Lumina gave employees a single point of access to all their benefits and financial information - with SAML v2 single sign-on connecting them to external providers, securely.

  • Partner Project
  • SAML v2 SSO
  • Azure SaaS
  • Pen-tested
  • Live 2021–2024

0

Months - prototype to board approval

0 yrs

Live and supported, 2021 contract to 2024

0+

Pen tests a year after launch

0%

Infrastructure as code - Bicep & Azure APIs

The Brief

Benefits and finances, finally in one place

AMBA UK is a leader in employee benefits technology. They wanted a single point where employees could access all their benefits and financial information - from one location, with one single sign-in.

Wellness programmes, ethical shopping, financial details - everything currently scattered across separate logins, unified behind a single door. AMBA brought designs prepared by their in-house team.

Our partner Mohunky led the client relationship, and Ralph Media shaped the experience. We built everything that makes it work.

The partnership

Three teams, one platform

  • M

    Mohunky

    Client liaison, project management and ongoing support.

  • R

    Ralph Media

    UX/UI design - turning a benefits catalogue into an intuitive flow.

  • H

    Hayman.dev

    The build - platform, SAML v2 SSO and Azure infrastructure.

How we built it

From a two-month prototype to a pen-test-ready platform

A build sequenced for ROI, secured for scrutiny - step by step.

  1. 01

    Two months

    The prototype

    We built the key elements of the project and showcased their ROI to the shareholders. The response was overwhelming - the full system was contracted in late 2021.

  2. 02

    Agreed with stakeholders

    Milestones, ROI first

    We identified challenges early and agreed milestones for every feature - collating the quickest-ROI capabilities up front, with a raft of updates to follow.

  3. 03

    From first release

    Pen-test ready

    We knew the platform would be pen tested. With decades of pen-tested applications behind us, we drove technical excellence from day one - the first release covered the annual pen test and the monthly tests after it.

  4. 04

    IdP or SP

    SAML v2, both ways

    The parallel challenge: a SAML v2 framework that works as Identity Provider or Service Provider - connecting external websites to the dashboard, with security audits at every step.

What we engineered

Enterprise plumbing, invisible to the employee

From the SAML v2 framework to the Azure infrastructure it runs on - here's the engineering behind one smooth sign-in.

passkey

SAML v2 SSO

A framework that acts as Identity Provider or Service Provider - one login opens every connected benefit.

cloud

Azure SaaS & PaaS

PaaS-delivered services and a full SaaS platform - the whole product runs on Azure.

code_blocks

Infrastructure as Code

New client services deployed via Bicep and raw Azure APIs - domains, SSL certificates, databases, web apps and API endpoints.

payments

Azure bill monitoring

Spend visibility built in - cloud costs tracked and reported through the Azure API.

verified_user

Pen-test-ready releases

Technical excellence from the first release - the platform sailed its annual pen test, and the monthly tests that followed.

database

Enterprise stack

C#, .NET Core, TypeScript and SQL Server - foundations built for years of operation.

The security layer

One sign-in. Every provider. Zero shortcuts.

The parallel challenge to the build was identity. We created a SAML v2 compliant framework that works as an IdP (Identity Provider) or SP (Service Provider) - so once an employee signs into the Lumina dashboard, they connect to external websites securely.

Extensive integration and security audits made sure no user data could be compromised - on either side of the assertion.

SAML v2 IdP SP Audited
The flow
person

Employee signs in once

Credentials checked against the Lumina dashboard

passkey

SAML v2 assertion issued

Signed, encrypted and audited end to end

shopping_bag

Provider A

Benefits portal

local_mall

Provider B

Ethical shopping

account_balance

Provider C

Financial info

IdP

Lumina issues the identity to connected providers.

SP

Lumina consumes provider identities when needed.

Audited

Integration and security reviews on both sides of the flow.

The Outcome

From unanimous board approval to a 2024 merger

The finished platform delivered a polished, all-in-one experience. Feedback was fantastic - employees particularly appreciated the SSO, and companies saw higher engagement with their benefits and increased satisfaction.

Our partnership ran from the late-2021 contract until 2024, when the company merged with another provider - a full build, ongoing support and years of pen-test-ready operation.

What the numbers said

Engagement up. Friction gone.

trending_up

Higher engagement

Employees actually used their benefits - because they could finally find them.

sentiment_satisfied

Increased satisfaction

One sign-in made every benefit effortless to reach - no more forgotten logins.

verified_user

Pen-tested, every year

Annual and monthly audits passed - user data protected throughout.

One login can change everything

Let's engineer your single sign-on

SAML v2, Azure infrastructure, infrastructure as code - whatever your platform needs, we'll build it to survive scrutiny.

No hard sell • A real engineer on the first call