▲ 10 r/nocode

what is the best way to build a custom client portal for an agency?

We are currently managing about 15 agency clients using a mix of Google Drive links, Notion pages, and Slack channels. It looks messy and clients keep losing track of deliverables and invoices.

I want to build a clean, secure client portal where clients log in to see their specific project status, upload files, and view deliverables. What's the easiest platform to build this on without writing custom code?

reddit.com
u/Distinct_Highway873 — 1 day ago
▲ 3 r/nocode

Best all in one website platform for small businesses?

i'm trying to avoid stitching together five different services just to run a business website.
website, forms, analytics, blog, seo, domain... i'd rather keep everything under one roof if possible.

does anyone actually use an all-in-one platform and feel like it was the right decision?

reddit.com
u/Distinct_Highway873 — 1 day ago
▲ 1 r/Retool

How to build a clean admin panel to manage web app data and user accounts?

We have a custom backend system, but our non-technical team members need a friendly web-based admin panel to view user signups, edit user roles, approve content submissions, and issue refunds. What is the fastest tool for generating clean admin dashboards?

reddit.com
u/Distinct_Highway873 — 3 days ago
▲ 3 r/WixHelp+1 crossposts

Wix vs GoDaddy vs Squarespace: which is best for a new site?

If the goal is low friction setup, Wix looks like the strongest pick. It feels more beginner friendly than Godaddy and more practical than Squarespace if you want the domain side to be simple.

reddit.com
u/DigiNoon — 2 days ago

what is the best way to build a gated membership portal with recurring subscription payments?

I want to launch a private research community where paid members get access to weekly industry reports, a searchable resource library, and an exclusive discussion board. What is the easiest way to build a gated membership web app with Stripe recurring billing?

reddit.com
u/Distinct_Highway873 — 4 days ago

Can you recommend companies that are leading the way in innovative delivery partnerships?

We’re looking into different delivery partners as our e-commerce operations scale, and I’m interested in companies that are doing more than just traditional package transportation.

A lot of providers can move packages from point A to point B, but we’re looking for partners that are improving the overall delivery experience through things like better tracking, flexible delivery options, technology integrations, and a smoother customer experience. For those working in e-commerce or supply chain, which delivery companies do you think are actually innovating right now?

reddit.com
u/Distinct_Highway873 — 16 days ago

What's the best ai driven prospecting and lead research tool you ever used

We were testing a new ai driven prospecting tool to build a list for outbound, and someone on my team decided to trust the enrichment way too much. It pulled company names, titles, and emails, and we pushed it straight into a sequence without checking anything. when people started replying we realized the tool had mixed up our target accounts with a bunch of totally wrong contacts some of them not even buyers. On top, one of the sequences was sent with a line that referenced a fake trigger event the ai hallucinated from the company site. So now a bunch of people have seen a message that basically says we researched them and clearly did not. We also had one contact reply asking why we were pitching a service to his wife at a different company with almost the same name.

I want to disappear. How to recover now from this

reddit.com
u/Distinct_Highway873 — 25 days ago

Developer first startups is there any revenue intelligence platform that is worth it

I’ve been running a dev-first B2B SaaS, but the second a user hits our pipeline, everything turns into vibes and spreadsheets.

We track product events like crazy, ship fast, and live in user DMs. But hacking a solution together with Stripe exports, Airtable, and HubSpot tags stopped working once we hit 20 active trials. Now I’m completely blind.

Everyone keeps pitching enterprise bloatware like Gong or Clari, but we’re just two devs and a part-time AE. Anyone found a revenue tool that actually fits this scale?

reddit.com
u/Distinct_Highway873 — 28 days ago

do you know any good parcel delivery solutions for ecommerce brands??

hey so, a quick question

we’re kinda reworking our shipping setup rn and looking into different parcel delivery solutions that work in real ecommerce ops , main issue is we don’t wanna overcomplicate the warehouse side (pick/pack etc is already pretty set), but we need more flexibility on delivery speeds plus better visibility for customers, right now it feels like most setups are either super rigid or just not great when you scale up order volume. i would love to hear what ppl are using rn

reddit.com
u/Distinct_Highway873 — 29 days ago

security tools keep sending noisy tickets to developers with no context. how do you fix that?

eng lead pulled me aside after standup on Monday. showed me a Jira ticket that had been sitting unactioned for 3 weeks. CVE id, CVSS 9.1, component name, link to scanner. that's it. his dev had no idea if the service was internet-facing, no idea if there was a known exploit, no idea if it was even still running. he'd pinged security twice and got back "it's critical, please prioritize." the dev closed it as won't fix just to get it off his board.
that's where we are.

our devs are getting tickets out of multiple scanners and not one of them explains why the finding matters. we're a security team covering a couple hundred engineers, so "just go look at each one" was never going to scale.

a typical ticket lands in Jira with a CVE id, a severity score, a component name, and a link back to the scanner. it doesn't say whether the affected service is internet-facing. it doesn't say whether the box is a compliance-scoped production asset or a dev sandbox nobody's touched in eight months. some of that the scanner could tell you.the scanner is already flagging it as KEV or giving it a very high EPSS score. but the integration that opens the Jira ticket strips it down to the CVE and the number. just "critical, fix this" with none of the context that explains why.

the result is most tickets get ignored until someone escalates. the ones that do get picked up take twice as long because the dev is running triage that should have happened before the ticket existed. eng leads are pushing back now. the security backlog is a black hole to them and they can't tell what's urgent from what's just a scanner doing its thing. tbh they're not wrong.

what we need is the context attached before the ticket gets created. exposure, asset criticality, whether anything is being actively exploited. bolting it on manually doesn't scale. i'm not sure if that's a workflow problem or a tooling problem at this point.

for teams that have this working: what changed. did you find something that fixed it, or is everyone just doing manual triage on the dev side and living with the noise?

reddit.com
u/Distinct_Highway873 — 30 days ago

Why did my package switch to a different last mile delivery service?

I ordered a few pantry and home items from a brand I hadn’t used before. Everything showed normal tracking at first, but then it suddenly updated showing a different last mile delivery service handling the final step instead of the usual USPS/UPS type update I was expecting. At first I wasn’t sure what that meant, but the delivery itself was smooth. The driver arrived within the estimated window, sent a quick message before arrival, and followed the delivery instructions I left. The only thing that surprised me was how quickly tracking went from minimal updates to “out for delivery” on the same day.

Is this kind of handoff during last mile delivery becoming more common now?

reddit.com
u/Distinct_Highway873 — 1 month ago

best gtm tools that integrate with claude code, what is there

i am pushing hard on my first saas for the last month and i've started leaning on claude code for almost everything because it is just way more accurate. i have a small web app that is still pre-revenue, and i am dealing with 143 visitors so far, 19 signups, and a couple of founder communities. to ship faster, i use claude code to draft features, clean up my backend, and help write copy.

but the part i'm completely stuck on is the gtm tooling that should sit around it. some of my friends say distribution is harder than building and i'm starting to see that. i can ship features faster than i can even decide what tools i should be wiring together. because i'm building a developer-focused tool, general marketing trackers and broad intent tools don't give me the actual technical fit data i need.

i want a setup where i can feed accurate developer intent and engineering footprints straight back into my workflows so i can track leads properly and run outbound without manually spending hours researching every sign-up. what are people using to track technical b2b buyers when shipping this fast?

reddit.com
u/Distinct_Highway873 — 1 month ago

How do you improve post-purchase experience when ecommerce delivery is hurting NPS?

Apparently our entire customer experience strategy begins and ends with whether a stranger can read an address label. Our pre purchase funnel is fine. Our product reviews are good. But our post purchase experience is destroying our NPS and it is entirely an ecommerce delivery problem. People love the stuff when it arrives. The issue is the part where it gets lost in the same three ways:

Driver marks it delivered, customer sends us a picture of their very empty porch.
Package is on vehicle for delivery for three days straight like it is doing a road trip.
Last mile delivery helpdesk gaslights us all.

We use the usual suspects plus a few of the newer last mile delivery companies. Ironically, the only deliveries customers consistently praise lately are when the shipment goes through Veho. I literally had a customer email just to say whoever that Veho driver was, give them a raise like I am in charge of their payroll. Everyone internally is yelling about NPS dashboards and customer obsession while our ecommerce delivery partners are out there playing package bingo.

Has anyone successfully shifted more volume to last mile delivery providers that do not wreck the post purchase experience without blowing up costs or SLAs?

reddit.com
u/Distinct_Highway873 — 1 month ago

is anyone using a next day delivery platform for ecommerce??

hey so i kinda have a random question. has anyone here ever used a next day delivery thing in their setup?? we’ve been looking at ways to make shipping a bit more flexible without messing up the warehouse flow. like rn everything just goes through the same pick/pack process but the delivery side is rigid with speeds and stuff.

does it literally arrive the next day or is it just to sound good??

reddit.com
u/Distinct_Highway873 — 1 month ago

What does cloud infrastructure automation look like for you beyond a couple of Terraform pipelines and some bash glue?

When people say they've automated cloud infra, they often mean they've tamed provisioning. There is Terraform or another IaC tool, some shared modules, and CI pipelines that apply changes through a known path. That is a big step up from clicking around in a console, but it does not automatically solve what happens once systems are running.

The hard part is everything after "resources created." Handling changes with confidence, reacting to alerts the same way each time, tidying up unused bits, and keeping drift in check are all much harder to standardize. That is usually where ad‑hoc scripts and manual runbooks creep back in: one‑off fix scripts, steps people run from their laptops, and procedures that only live in a wiki page.

Teams that push further talk about change flows where most modifications follow a known pattern, about runbooks that actually get used because they are wired into tooling, and about automation that suggests or carries out common responses rather than asking a person to reinvent them each incident. Getting there often means giving up some flexibility and sticking to patterns more strictly than many engineers like.

If you would say your cloud infra automation genuinely goes beyond "Terraform plus some scripts," what does that do for you on a normal week that you didn't have before, and what habits or design choices did you have to change to trust it in production?

reddit.com
u/Distinct_Highway873 — 1 month ago

the PR-time scan model assumes the developer already reviewed the code. That assumption breaks with agent-written PRs

we made a decision six weeks ago to stop treating CI as the primary security gate for agent-generated code. The math stopped working: PR raised, scanner runs, findings land in a backlog, developer already on the next feature. With hand-written code that lag was annoying but survivable, because the developer had at least mentally reviewed the code as they wrote it, the PR-time scan was the second check. With Copilot and Claude generating 200-line PRs in two minutes, there is no first check. The scan is now the first pass over code no human has read carefully, and the backlog grows faster than anyone clears it.

So we've been trying to move real security checks into the IDE. Where we've hit walls:

  1. Semgrep via editor extension, custom rules on save.* Near-instant feedback on pattern matches. Great when it works. The problem is rule maintenance - our rules encode internal patterns (auth middleware usage, required sanitization functions, mandatory logging decorators) and drift every time a framework version bumps. Nobody owns keeping them current. The rules that would help most are the ones stalest.

  2. Lightweight SAST on file save via local container. Latency 8–12 seconds depending on file size. Developers tolerated it about a week before turning it off. Empirically our threshold is 3–4 seconds. Above that it gets disabled and never re-enabled.

Maintenance we can probably grind on. Latency is the harder wall, because it's a property of the analysis itself and no amount of team process fixes it. Faster scanners give up depth; deeper scanners give up the IDE window.

What I'd like to know from anyone who's actually running in-IDE security during heavy agent-assisted development: what have you gotten under the 3–4 second bar without dropping to trivial pattern matching? Incremental analysis on just the changed region? Pre-computed indexes? Offloading to a warm backgroun

reddit.com
u/Distinct_Highway873 — 1 month ago

same vulnerability showing up 5 times across different tools, how do you deduplicate findings

posting this because i'm tired of arguing with my own ticket queue

last sprint we patched what we thought was one critical and the backlog barely moved. turned out the same CVE was open in five places under five different finding ids, and closing one did nothing to the other four. it was a bug in an internet-facing service, so it got picked up just about everywhere it could be. the Tenable scan saw it on the host. Snyk saw it in the dependency. Wiz saw it on the cloud workload. DAST found the behavior, Snyk found the package, and the pentest report had already called it out. Same problem three different ways. and an old pentest report from last year had already flagged it. one vuln, and five separate tickets nobody fully owns.

what kills me is the dedup isn't even hard in theory, it's that nothing shares a key. matching on CVE id alone is wrong, the same CVE on two separate assets is two real problems, not a duplicate. so you need CVE id plus a stable asset identity, and that second half is where it dies. Tenable sees it as a host issue, Wiz sees it as a cloud resource, and Snyk sees it as a package. there's no identifier that survives across all of them, so you can't write one clean join. you end up hand-maintaining a per-tool translation map and it rots the second someone spins up new infra.

the downstream effect is our open-findings count is fiction. leadership sees a number, that number is inflated by however many duplicates we never merged, and calls get made off it anyway. ngl i've stopped trusting our own dashboards.

so before i go build yet another internal correlation script i'll be maintaining forever: has anyone gotten real cross-tool dedup working, and did it come from inside one of the tools or from something sitting above all of them.

reddit.com
u/Distinct_Highway873 — 1 month ago

Need b2b teams here which agentic gtm tools are actually worth using?

i've been in b2b for a minute now and im so sick of our setup. our crm is supposed to be the "source of truth" but let’s be real nobody updates it in real time. marketing automation is spitting out these random lead scores that the sales reps completely ignore, and i spend half my week stuck in spreadsheets trying to stitch data together just so leadership has something to look at for the weekly board meeting. meanwhile, management is breathing down our necks asking why we don't have some AI magic layer that watches product usage, site behavior, and tech stacks to automatically tell reps hey call these 8 accounts right now because they did X.

everything we do is either completely manual or some black-box algorithmic scoring that nobody on the team actually trusts. i just want something that acts like a reliable junior operator in the background handling the grunt work of mapping out actual intent.

reddit.com
u/Distinct_Highway873 — 1 month ago
▲ 6 r/grc

what metrics do you actually show the board for vulnerability management

our security team presents to the board next quarter and i've been tasked with the vuln management section. first time doing this at board level and i'm trying to figure out what lands versus what gets us a bunch of questions we can't answer cleanly.

right now we lean on mean time to remediate and SLA compliance by severity, plus total open vulns. none of those tell a clean story on their own. total open vulns goes up every time we onboard a new scanner or expand coverage, so it looks like we're getting worse when we're just seeing more. MTTR looks fine, but that's partly because crits with no patch never close, so they drop out of the average entirely, and the number reflects the vulns we could fix quickly, not the ones stuck with no fix. SLA compliance makes leadership feel good but tells you nothing about what's at risk.

i've seen people talk about exposure window and exploitability weighting, but we’ve looked at weighting exposure and exploitability more heavily but i'm not sure how to explain that to a board. you say "we prioritize by CVSS and EPSS" and half the room nods like they understood that.

whatever we show, someone asks how we compare to industry benchmarks. i never have a clean answer because benchmarks for this swing wildly by sector and company size, and that's before you account for what you're even scanning.

the only thing that's ever landed cleanly with our execs is exposure on internet-facing assets, how many known-exploitable vulns are sitting on something reachable from outside and how long they've been there. that maps to "what could hurt us" in language a board follows.

everything else we put up turns into a debate about methodology and we lose the room.

has anyone figured out how to make vuln management metrics meaningful at the board level without dumbing it down to uselessness or drowning them in numbers they have no context for. what do you show, and what questions does it usually kick off?

reddit.com
u/Distinct_Highway873 — 1 month ago

How do COOs evaluate last mile delivery performance in logistics operations?

I thought last mile delivery management was mostly about getting a few good rates and watching on time delivery. It is not that at all!!

Every region has its own little disaster. One market has late handoffs, the other has weird tracking gaps, another gets crushed on customer complaints even when the last mile logistics provider says everything was fine. We have orders moving through Veho in one area and the rest of the network on different parcel delivery service partners, and the reporting never lines up cleanly enough to feel confident about anything. What keeps messing with me is that the same last mile delivery service can look amazing in one place and borderline useless in another. So when leadership asks what the last mile delivery performance is, I do not have a clean answer. I have five messy answers.

I’ve got a list of questions I’m hoping to get some answers to:

For you people that do this at bigger ecommerce delivery brands, how are you setting the rules?

Do you manage by region, by last mile delivery provider, by service level, or by whatever breaks customer support the least?

How are you getting COOs to care about the stuff that does not show up in a pretty dashboard until it is a problem in last mile logistics? I’d appreciate real and honest answers, as this issue can’t keep occurring 😡

reddit.com
u/Distinct_Highway873 — 1 month ago