Building a SaaS product in 2026 comes down to five early decisions: tenancy model, billing provider, permissions, usage metering and observability. For most B2B products, start with a shared Postgres schema, a tenant_id on every row and row-level security; bill web customers through Stripe Billing (0.7% of billing volume plus card fees) or Paddle as merchant of record (5% + 50¢); and use RevenueCat for app-store subscriptions. A focused MVP takes 12 to 16 weeks.
NIST defines software as a service as the capability for a customer to use a provider's applications running on cloud infrastructure. In practice that means one codebase serving many customers, each of whom expects their data to be isolated, their bill to be right and their admins to control who sees what. Those expectations are architecture, and they are expensive to retrofit. This guide covers each decision in the order you should make it.
The baseline architecture
A typical SaaS stack in 2026 has a web front end in React or Next.js; an API in Node.js with NestJS, Python with Django or FastAPI, Go, or Ruby on Rails; PostgreSQL as the system of record; Redis for caching and queues; a background job runner; object storage for files; and a managed auth provider or a well-tested library. Any of those back ends works, and we build on all of them, hosted on AWS, GCP, Azure or Vercel; choose the one your team can hire for and debug at 2 a.m. What separates a SaaS from a web app is the layer that runs through all of them: tenant context, billing state, permissions and per-tenant telemetry.
Tenancy models compared
AWS's SaaS guidance names three isolation models: pool, where tenants share resources; silo, where each tenant gets dedicated resources; and bridge, a mix of the two. In database terms they map to the three options below.
| Model | Isolation | Cost per tenant | Migration pain | Best for |
|---|---|---|---|---|
| Shared schema (pool): one set of tables, tenant_id on every row | Logical; enforced by row-level security and application checks | Lowest; one database to run | Lowest; each migration runs once for everyone | Most B2B and B2C SaaS, especially before scale |
| Schema per tenant (bridge): one database, one schema per customer | Stronger; separate tables on a shared server | Moderate; connection and catalogue overhead grows with tenants | High; every migration runs once per schema and can fail halfway | Tens to low hundreds of tenants needing custom fields or per-tenant restores |
| Database per tenant (silo) | Strongest; separate database, optionally a separate region or keys | Highest; per-tenant infrastructure and monitoring | Highest; fleet-wide migrations need orchestration and rollback plans | Regulated or enterprise customers with contractual isolation or residency needs |
Start pooled unless a signed customer requires otherwise, and design so a large tenant can later move to its own database. In Postgres, enable row-level security with a policy on tenant_id, add FORCE ROW LEVEL SECURITY so the table owner cannot bypass it, and set the tenant for each transaction rather than each connection, so a pooled connection never carries one customer's context into another customer's request.
Billing: Stripe Billing vs Paddle vs RevenueCat
Billing depends on where you sell. On the web you decide whether to be the merchant of record yourself or pay someone else to be it. In mobile apps, Apple and Google are the merchant for digital subscriptions, and the question becomes how to manage entitlements across both stores.
| Provider | Model | Published price | Sales tax and VAT | Best for |
|---|---|---|---|---|
| Stripe Billing | You are the merchant; Stripe runs subscriptions, invoices, dunning and usage meters | 0.7% of billing volume, plus 2.9% + 30¢ per US card payment | Your responsibility, with Stripe tooling available | Web B2B SaaS, sales-led deals and usage-based pricing |
| Stripe Managed Payments | Stripe acts as merchant of record | 3.5% per transaction on top of standard processing | Handled, in more than 80 countries | Digital products that want a merchant of record without leaving Stripe |
| Paddle | Merchant of record | 5% + 50¢ per checkout transaction | Handled | Small teams selling globally without tax operations |
| RevenueCat | Entitlements layer over App Store and Google Play billing | Free up to $2,500 monthly tracked revenue, then 1% of tracked revenue | Handled by Apple and Google as merchants | Mobile subscriptions across iOS and Android |
Store fees sit underneath RevenueCat. Apple's standard commission is 30%, or 15% for Small Business Program members with up to $1 million in prior-year proceeds and for subscriptions after a subscriber's first paid year. Google Play's fee on subscriptions in the US, UK and EEA has been 10% since 30 June 2026, plus a 5% billing fee when you use Google Play Billing. In the US, apps may link out to web checkout under the Epic v. Apple injunction, but the commission Apple may charge on those purchases is still in litigation after the Supreme Court agreed on 30 June 2026 to review the contempt ruling. SlimAI, the AI calorie app we built, sells subscriptions through RevenueCat, which keeps entitlement logic in one place across both stores.
Permissions: role-based access from day one
Role-based access control (RBAC) decides who can do what inside a tenant. Retrofitting it after the first enterprise customer asks is one of the most expensive changes a SaaS team makes, because every endpoint has to be revisited. A small model built early lasts a long time.
- A memberships table linking user, tenant and role, so one person can belong to several tenants with different roles.
- Permissions as named strings, such as invoices.read or members.invite, checked on the server for every request, never only in the UI.
- Default roles of owner, admin, member and billing, with custom roles added later as data rather than code.
- An audit log of sign-ins, permission changes and data exports, which enterprise buyers ask for in security reviews.
- Single sign-on through SAML or OIDC and SCIM provisioning, planned as a later tier rather than built on day one.
Usage metering
If any part of your price depends on usage, such as API calls, documents processed or AI tokens, metering is a ledger, not a log line. Record each usage event with a unique ID so retries cannot double-count, aggregate per tenant in your own database, and send totals to your billing provider. Stripe now requires a billing meter behind every metered price; its legacy usage records API was removed in API version 2025-03-31.basil. Show customers the same numbers you bill them for. For AI features, meter inference per tenant from the start, because cost scales with use rather than seats. SlimAI does this with a daily credit allowance for free users that is held in the user's cloud record, so reinstalling the app does not reset it.
Anything that moves money deserves the same discipline. From 2021 to 2023 one of our senior engineers worked on Xendit's merchant payments app, shipping payment links, QR payments and disbursements for merchants in Indonesia and the Philippines. The habits carry straight over to SaaS billing: unique IDs on every event, retries that cannot charge twice, and reconciliation you run, not assume.
Onboarding
Self-serve onboarding is where tenancy, billing and permissions meet. One signup should create the tenant, an owner membership and a trial or free plan in a single transaction, so there is never a user without a tenant or a tenant without a plan. Then measure activation: pick the one event that shows a customer got value, such as a first report generated or a first teammate invited, and track how long it takes. Sample data, an invite flow and empty states that explain the next step usually move that number more than a product tour does.
Observability
- Structured logs with tenant_id, user_id and a request ID on every line, so one customer's problem can be traced end to end.
- Distributed traces across the API, background jobs and third-party calls, with OpenTelemetry keeping you vendor-neutral.
- Per-tenant metrics for requests, errors, latency and cost, so you can see when one customer's usage threatens everyone else's.
- Alerts on billing webhooks and failed jobs, because a silent webhook failure is a revenue bug.
- Error tracking with releases tagged, so a regression points at the deploy that caused it.
Data lifecycle: backups, export and deletion
Enterprise and privacy reviews ask the same three questions. Can you restore one customer without restoring everyone? Can a customer export their data? Can you delete it completely when they leave? In a pooled database, build per-tenant export and deletion as jobs that walk every table with a tenant_id, including files in object storage and copies in analytics and search indexes. Test a restore before the first customer asks, and write down how long backups are kept, so your contracts and your infrastructure say the same thing.
Timeline in weeks
| Weeks | Workstream | Output |
|---|---|---|
| 1–2 | Discovery and architecture | Scope, data model, tenancy and billing decisions written down |
| 2–4 | Foundations | Auth, tenants, memberships, RBAC skeleton, CI and environments |
| 3–9 | Core workflow | The two or three features customers will pay for |
| 6–10 | Billing and metering | Plans, trials, checkout, webhooks, usage meters and invoices |
| 8–12 | Onboarding and admin | Signup flow, invites, empty states, internal admin tools and emails |
| 10–14 | Observability and security | Logs, traces, alerts, audit log, dependency and access review |
| 12–16 | Beta and launch | Real tenants, data migration scripts, fixes and launch |
On cost, Clutch's software development pricing guide, updated 21 September 2026, says most projects on its platform cost $10,000 to $49,000, and that the average reviewed project cost $132,480 over about 13 months. DesignRevision's 2026 guide puts an agency-built SaaS MVP at $50,000 to $250,000 over three to six months, and a freelancer build at $20,000 to $60,000. Techparser quotes fixed scope after a call and sends an estimate within two business days, and the client owns the code and IP.
Frequently asked questions
- What is SaaS development?
- SaaS development is building software that customers use over the internet on a subscription, running on infrastructure the provider manages, which is how NIST defines software as a service. Beyond the product features, it covers multi-tenancy, subscription billing, role-based permissions, usage metering, onboarding and the monitoring needed to run one codebase for many customers.
- How much does it cost to build a SaaS?
- Published figures vary with scope and team. Clutch's September 2026 guide says most software projects on its platform cost $10,000 to $49,000, with an average reviewed project of $132,480. DesignRevision's 2026 guide puts an agency-built SaaS MVP at $50,000 to $250,000 and a freelancer build at $20,000 to $60,000. Billing and hosting fees continue after launch.
- How long does it take to build a SaaS MVP?
- A focused B2B SaaS MVP typically takes 12 to 16 weeks: discovery and architecture, foundations such as auth and tenancy, the core workflow, billing and metering, onboarding, observability and a beta. DesignRevision's 2026 guide gives three to six months for agency builds. Scope, integrations and compliance needs move the timeline more than the tech stack does.
- Single-tenant or multi-tenant?
- Start multi-tenant with a shared schema, a tenant_id on every row and row-level security, because one deployment and one migration path keep cost and effort low. Move specific customers to single-tenant databases when a contract requires isolation, data residency or dedicated keys. Designing tenant context in from day one makes that later move a migration, not a rewrite.
About the author
Zoraiz Ejaz
Co-founder, Techparser
Zoraiz Ejaz is a co-founder of Techparser and leads its engineering and product practice. He has spent close to a decade designing, building and scaling mobile, web and AI products for startups and enterprise teams across health, fintech, payments, social and education, from first architecture and release pipelines through to launch and years of production support. He writes about how to scope, cost and ship software that lasts.


