The problem
Mines, plants and the businesses that serve them run on a patchwork of systems: an asset register in one tool, inspections on paper or in a spreadsheet, permits in another system, contracts in a document store and billing checked by hand. Each new capability meant another product, another login and another place where the data stopped agreeing with itself.
Asterion set out to give these operations one platform: one sign-in, one tenancy model and one shared view of assets, contracts and people, with AI where it saves real work.
What we built
- Industrial operations: an asset registry with health scoring and remaining-useful-life estimates, reliability engineering, shutdown and turnaround planning, field inspection with an offline-first mobile app, safety and permit-to-work with competency-gated approvals, ESG and carbon reporting, and workforce competency and fatigue.
- Contracts and assurance: contract intelligence (clause extraction, risk scoring, obligation tracking, tracked-changes redlines), contractor invoice assurance, and turnaround schedule assurance with Monte Carlo risk simulation.
- Revenue and trading intelligence: billing and spend assurance across healthcare, mining, utilities and manufacturing, and commodity trading intelligence.
- Communications: voice, chat, WhatsApp and Teams agents, and AI outbound calling with a POPIA compliance pack.
- Platform services: tenant and user administration, a common data layer that keeps parties, assets and obligations consistent across modules, and an orchestration layer. It spots cross-module clashes, such as a shutdown task against an open permit or a fatigued crew, and queues them for a person to approve.
Architecture
- One FastAPI service per module (Python 3.12, SQLAlchemy 2, Pydantic v2, Alembic).
- React, TypeScript and Vite apps, a module portal, and an offline-first field app shipped as a signed Android app.
- PostgreSQL with a database per module and row-level security enforced per tenant.
- Keycloak single sign-on across the platform, with per-tenant module licensing.
- A Redis event backbone, so an incident in one module can trigger a workflow or a message in another.
- Claude-powered pipelines and assistants on a shared agent runtime. Anything that acts outside the platform waits for a person to press Execute.
- A deliberately simple runtime (Docker Compose behind nginx) with push-to-deploy and a smoke-test gate that checks the module frontends against their real APIs.
Result
Healthcare: a private hospital group runs revenue assurance on its own finance exports. Ten monthly batches of debtors' ageing and fixed-fee billing reconcile to the cent, and every fixed-fee case is checked against 6,457 rows of funder-contract tariffs across 22 agreements. Stop-loss exposure is reported both gross and net, because line items decide which is recoverable.
Mining and chemicals: an acid plant's shutdown quality assurance, previously run on Excel and paper, was rebuilt in the platform. The previous year's audit (26 equipment dossiers, 677 plan tasks and 24 scope changes) was imported and reproduces its surveillance figures exactly, and 74 scanned evidence pages were transcribed by AI for review.
Petrochemicals: a company's contracts team was onboarded onto the contract-intelligence products, with a shared workspace and individual ones.