ServicesAboutWorkBackgroundContactGet in touch →
● Independent practice·Since 2013·SE Massachusetts
v.2026

The systems
nobody else wants to touch.

.NET monoliths with a decade of business logic. Legacy QuickBooks integrations. Multi‑role enterprise apps. I take the assignments other consultants quote a year out — and finish them.

// Recent clients
Pease & Curren/BIZ Diagnostic/Narragansett Boat Club/+ more
§ 02 — Practice

Four ways to hire me.

Most engagements are some combination of these. The first conversation is to figure out which combination — and whether I'm the right person for what you need.

01 / Primary offer

Fractional CTO for businesses with real software inside them.

Two days a week. Long engagements. The same person, every Tuesday and Thursday, for as long as you need me.

Senior technology leadership without the full‑time cost. I work alongside your team to set direction, make hard architectural decisions, and give your stakeholders a trusted technical voice — on a schedule that fits your budget.

Most fractional engagements run 12–24 months. Long enough to ship the thing, short enough to leave you self‑sufficient when it's done.

  • Architecture decisions
  • Vendor & build reviews
  • Hiring & team structure
  • Board & investor reporting
  • Roadmap & trade‑offs
  • Hands‑on code when it helps
02 / Audit

Architecture review

An independent audit of your current systems. I identify where complexity has accumulated, where risk is hiding, and the specific changes that will have the most impact — with a practical remediation plan, not a list of problems.

03 / Build

Custom software

Custom .NET applications, database design, API development, and enterprise integrations built to last. Full‑stack from requirements to delivery — with documentation your team can actually use.

04 / Advisory

IT consulting

Practical guidance on the technology decisions businesses face every day — vendor selection, infrastructure planning, security posture, and day‑to‑day reliability — without overcomplicating the stack.

§ 03 — About
Allen Waldrop
SE MASS18+ YRS

I write the spec, then I write the code.

Most consultants do one or the other. Doing both is why my clients keep me around for years instead of months — and why I can quote a job in a meeting and ship it without the plan falling apart the moment it hits code.

Two decades of hands‑on work building, maintaining, and untangling complex systems for businesses of all sizes. The full stack — custom .NET applications, database architecture, enterprise integrations, API development, and everything in between.

For thirteen of those years I did this alongside a full‑time role as senior software engineer and solutions architect at a regulated manufacturer — owning the internal API surface, leading the team, and keeping plant‑floor systems running. The practice never was a side project, and neither was the day job.

What clients value most isn't just the technical work. It's having someone who can walk into a problem, understand the business impact, communicate clearly with technical and non‑technical stakeholders alike — and get it solved without drama.

The best technology decision isn't always the most sophisticated one. Sometimes the right answer is simple, maintainable, and just works.

Experience
18+ yrs software · 13 yrs practice
Stack
.NET / C# / SQL / API
Base
SE Massachusetts
Status
Accepting · Q3 2026
§ 04 — Selected work

Six systems, in detail.

Three built for clients, three built in‑house at manufacturing scale. Every one ran for years. Every one replaced something that was quietly costing money to keep alive — or built what couldn't be bought off the shelf.

// Client work — AW ConsultingContracted engagements, all still active
CASE 01
ASP.NET / .NETEnterprise integrationFinancial platform
2019 — Present

Pease & Curren — precious metals refining platform.

27,600 lines of C# replaced three siloed systems and eliminated multi‑year manual commission reconciliation.

A precious metals refining operation needed to unify the full processing lifecycle — customer shipment intake, lab assay, refinery processing, financial settlement, and accounting sync. Three external systems (Satuit CRM, QuickBooks Desktop, manual tracking) operated in complete silos. Commission calculations required manual multi‑year historical lookbacks. Settlements were hand‑reconciled.

Read the full breakdown

The hard part

QuickBooks Desktop integration via the legacy COM‑based QBXML API — one of the more difficult integrations in the Windows ecosystem. Plus an orchestrated nightly sync sequencing CRM → QuickBooks → internal DB with email alerting on failure.

The clever part

A 6‑phase commission calculation engine handling multi‑year historical lookback, customer tenure classification, tiered bonus structures, and gross profit thresholds via staging tables. Exact decimal precision throughout — the kind precious‑metals settlement can't round away.

The outcome

Manual reconciliation across three systems eliminated entirely. Commission reporting that previously required Excel work across years of history now runs on demand. Seven user roles gained centralized, role‑appropriate visibility.

// architecture · simplified85 pages
SATUIT CRMQBXMLDAYSHEETSCRON SYNCASSAYSETTLEREFINECOMMISSIONS
// 7 roles · 3 integrations · ~27,600 LoC
CASE 02
SaaS platformWhite‑label arch.ASP.NET / .NET
2021 — Present

BIZ Diagnostic — multi‑brand business‑health SaaS.

Eight scored dimensions, twelve modules, one codebase serving hundreds of advisory firm brands.

Professional advisory firms needed to scale structured business diagnostics without scaling headcount. Delivering assessments to thousands of clients, scoring them objectively, and routing each one to the right subject‑matter expert was entirely manual.

Read the full breakdown

The hard part

A modular assessment engine with two tiers — a 20‑minute diagnostic and a 2‑hour deep‑dive — each scoring 8 business areas, weighted on three axes: Vision 25%, Plan 45%, Desire 30%.

The clever part

The hostname is the tenant key. Each branded URL resolves to its own dataset, its own assessment tier, its own logo and compliance text — down to per‑brand wording on individual questions. Isolation is enforced, not filtered: land on a brand you don't belong to and your session is cleared, you're redirected to your own, and you're logged out. The API inherits the same boundary — its token resolves to exactly one brand.

The outcome

Diagnostics delivered to thousands of end‑clients without proportional staff growth. Manual expert referral workflows replaced by algorithmic routing. Server‑side PDF and Excel reporting, scheduled jobs, and role‑based access across a dozen modules — all on one codebase.

// scoring matrix · CIQ8 × 12
VISPLANDESROPSFINMKTSLSTEAMm1m2m3m4m5m6m7m8m9m10m11m12
// vision .25 · plan .45 · desire .30
CASE 03
ASP.NET / .NETWebhooks (HMAC)Club operations
2022 — Present

NBCLogBook — Narragansett Boat Club operations.

A self‑service member portal for a 24‑boat fleet, with WooCommerce membership webhooks driving access in real time.

A rowing club had no centralized system for managing its shared fleet. Members couldn't reserve boats. Staff had no real‑time visibility. Membership status lived in a separate WooCommerce store with no automated sync. No structured way to log crew, track guests, or record damage incidents.

Read the full breakdown

The hard part

WooCommerce membership webhooks — validated with HMAC‑SHA256 — automatically activate and deactivate member accounts in real time across the full membership lifecycle: creation, renewal, transfer, cancellation.

The clever part

Multi‑step boat reservations with crew assignment, real‑time checkout/check‑in, guest registration, damage reporting, personal activity history. Admin: boat inventory, time slot config, blackout dates, bulk Excel import/export. Transactional email runs through Mailgun, with SMTP fallback.

The outcome

Members gained self‑service. Membership access enforced automatically. Staff gained full operational visibility — every reservation, guest, and damage report in one auditable place.

// webhook · HMAC‑SHA25624+ pages
WOOCOMMERCEHMAC VERIFYMEMBER DBRESERVEMAILGUN
// member · admin · email audit log
// In-house, at scale — Gold Medal BakeryThirteen years as senior engineer & solutions architect
CASE 04
.NET CLI engineWPF (MVVM)SAP + FedEx
Gold Medal Bakery

APO — automated program ordering at plant scale.

One SQL schema, three applications, and an ordering engine that stayed accurate without ever getting a real‑time count.

A bakery's program ordering ran on scan data, sales velocity, and guesswork about how long freight actually took. There were no real‑time product counts to order against, and lead times were assumptions rather than measurements. Ordering accuracy depended on whoever was paying attention that week.

Read the full breakdown

The hard part

Building ordering logic that degrades gracefully instead of failing loudly. With no real‑time counts available, the engine had to hold accuracy from SAP scan data and sales velocity alone — and stay stable when the inputs were late, partial, or contradictory.

The clever part

Lead times stopped being assumptions. I wrote the FedEx integration that pulls actual pickup and delivery dates into SAP, then computed average transit days from that real history and fed it back into the engine's planning. The system learned how long freight took by watching freight.

The outcome

Three components over one schema: a .NET CLI ordering engine, a WPF/MVVM tool for entering correct inventory, and WebForms reporting with Excel export. Operations, planning, and reporting finally worked from the same numbers.

// three components · one schema1 DB
SAP SCAN DATAFEDEX TRANSITAPO · CLI ENGINEINVENTORY · WPFREPORTS · ASPXONE SQL SCHEMA
// cli engine · wpf mvvm · webforms reporting
CASE 05
ASP.NET Web APIBadge authenticationAir‑gapped clients
Gold Medal Bakery

GMBAuth — the layer everything else had to go through.

Plant‑floor machines with no route to the internet, authenticating real people by badge against the HR system.

Machines on the production floor needed to know who was standing in front of them. They had no internet access, no domain login worth using, and no way to reach the HR system that actually knew who worked there. Every application that wanted an identity was solving this separately, or not at all.

Read the full breakdown

The hard part

An internal‑only ASP.NET Web API gateway that turns a badge scan into a verified identity, bridging the physical badge system and the Dayforce HR platform — for clients that can't reach either one directly. Air‑gapped by design, not by accident.

The clever part

Solving it once, in one place, with an interface other systems could adopt without caring how badges or HR records worked. It stopped being an authentication service and became the authentication layer.

The outcome

Across thirteen years I wrote every internal API system at the company but one — and that one authenticates through this gateway. When stakeholders later proposed expanding a separate portal into the delivery vehicle for everything, I argued against folding unrelated concerns into a single system. Being the integration point is worth more than being the monolith.

// auth gateway · internalALL BUT 1
LINE TERMINALSCALE / KIOSKPLANT FLOORGMBAUTHBADGE SYSDAYFORCEINTERNAL SYSTEMS// NO INTERNET
// badge → identity · every internal system
CASE 06
SSIST‑SQL tuningProduction rescue
Gold Medal Bakery

ESP — the order generator nobody was left to support.

Found the bug, owned the regression my own fix caused, and finished five times faster than it had ever run.

The automatic order generator for the rack & tray business was built by an outside group, converted to SSIS, and then orphaned. The people who wrote it were gone and the vendor could no longer support it. It was crashing in production and nobody owned it. I was brought in as the engineer who would go into the packages and find out why.

Read the full breakdown

The hard part

A customer group had been reused, leaving two rows — one inactive, one active. A subquery buried deep inside one package never checked the active flag, so a scalar subquery returned two values and took the whole run down. Finding that meant reading somebody else's SSIS internals and the T‑SQL embedded in them.

The honest part

My fix was correct and made things much worse — a twenty‑minute run became two hours. Correct and unusable is still broken. That was mine to fix too, so I went back in with a targeted tuning pass rather than reverting to a run that crashed.

The outcome

Two well‑chosen indexes brought it to two to five minutes depending on customer group — faster than it had ever run, including before the bug. Support‑and‑tuning work on someone else's packages, which is most of what inheriting a system actually looks like.

// runtime · same job~5× faster
INHERITED — 20 MINAFTER MY FIX — 2 HRSAFTER TUNING — 2–5 MIN// one subquery fix · two indexes// bars to scale · 120 min max
// 20m → 2h → 2-5m

// Screenshots and live demos available on request.

§ 05 — Track record

The practice runs alongside a full career.

Not instead of one. Most of what I know about systems under real operational load came from being accountable for them full‑time, in a regulated manufacturing environment, for thirteen years.

  1. 2013 — 2026Fall River, MA

    Senior Software Engineer / Solutions Architect

    Gold Medal Bakery
    • Owned the internal API surface — authored every internal API system but one across thirteen years, including the badge authentication gateway that the remaining system authenticates through.
    • Built full‑stack line‑of‑business applications over shared SQL Server infrastructure: ASP.NET WebForms apps for timeclock, shipping manifests, third‑party receiving, promo management, costing and budget planning, plus WinForms and WPF desktop tools for visitor credentials, real‑time shipping‑performance displays, and market‑basket dashboards.
    • Integrated the systems the business actually ran on — SAP BAPI, EDI intake routing, Shopify webhooks with an hourly GraphQL fulfillment sync, FedEx Track, QuickBooks, and Dayforce — and drove barcode scanners on the plant floor through vendor device SDKs.
    • Led and mentored the engineering team, established coding and T‑SQL standards, and translated requirements across Accounting, Logistics, and HR.
  2. 2008 — 2013Providence, RI

    Web Software Engineer

    Oomph (formerly C. Murray Consulting)
    • Built and upgraded custom ASP.NET (C#) and PHP applications, including re‑architecting a legacy Access 2003 system into a full ASP.NET business‑tracking application.
    • Integrated QuickBooks, Satuit, and DYMO label printers via the DYMO Label Framework SDK, and did the SOAP web‑service work of that era.
    • Wrote multithreaded C# tooling for large‑scale content migrations out of WordPress, Drupal, and CitySoft CE.
  3. 2007 — 2008Providence, RI

    Web Software Engineer

    Verizon
    • Built a live ticket‑auditing system in C#, ASP.NET 2.0, and MS SQL, and deployed the RI FSC website with AJAX and a custom GDI image‑scaling library.

// B.S. Computer Information Science (Networking), Johnson & Wales University, 2006
// A.S. Computer Information Technology, 2004 · A+ Certified

§ 06 — Contact

What's the one thing in your stack that's been bothering you for six months?

// Response
Within 24 hours, usually same day. I read every inquiry — there's no triage layer between us.
// Location
Southeastern Massachusetts. Remote engagements anywhere; on‑site within a 90‑minute drive.
// Honesty
If I'm not the right fit, I'll tell you in the first call and recommend someone who is.