Building With AI

All resources

How I Built My First Construction Site Web App Without Being a Programmer

Published 24 August 2026

I am not a professional software developer.

When I started building Site Control Occupancy, I did not begin with knowledge of databases, authentication systems, cloud infrastructure or web application security.

I began with a construction-site problem.

I wanted a simple way to understand how many people were in different underground areas and how people were moving between them.

Instead of starting by learning programming from the beginning, I started discussing the problem with AI.

That eventually turned into a working web application.

It Started With the Problem, Not the Code

The original concept was straightforward.

Place QR codes at access points between areas.

When someone moves, they scan the QR code with their smartphone. The system records the movement and updates the occupancy of each area.

An administrator can then see the current situation from a dashboard.

At this point, I understood the construction problem much better than I understood the software required to solve it.

That turned out to be important.

AI could help me with programming, but I still had to decide what the system should actually do.

Using GPT to Turn an Idea Into Requirements

One of the first things AI helped me with was breaking the idea into smaller questions.

What information should a user enter?

How should the system recognize a returning user?

What happens if someone changes phones or loses their browser information?

Who should be allowed to see phone numbers?

What happens when a company name has not been registered yet?

What should happen if an administrator deletes a company that still has users?

These are not simply coding questions.

They are product-design questions.

I used GPT as a way to discuss those decisions, challenge assumptions and translate construction-site requirements into something that could eventually be implemented as software.

Cursor Was Different

Once the requirements became more concrete, Cursor became the tool that worked directly with the codebase.

This distinction was useful for me.

I could use GPT to discuss:

  • what the system should do;
  • possible security problems;
  • database concepts I did not understand;
  • alternative designs;
  • and what instructions should be given to the coding environment.

Then Cursor could inspect the actual project, modify files, run tests and report what had changed.

I was still making the decisions, but I did not have to manually write every line of code.

Suddenly I Had to Learn About Databases

Building the first screen was only the beginning.

The application needed somewhere to store users, companies, areas and movement records.

That introduced me to PostgreSQL and Supabase.

I gradually learned that a database was not simply a spreadsheet on the internet.

There were tables, relationships, permissions and policies.

For example, the system contains personal information that should not simply be readable by anyone who knows an API address.

That led to another concept I had never needed to understand before: Row Level Security.

Authentication Became More Important Than the Interface

As the application became more realistic, the difficult questions changed.

Making a button look better was no longer the main issue.

I had to think about who could access administrative information.

The system eventually developed different administrative roles, including Viewer, Admin and Super Admin.

Administrative authentication was strengthened with multi-factor authentication, and access to sensitive data was restricted according to role.

I also had to think about the normal site user.

Requiring every worker to create a traditional username and password account would make a simple QR workflow much more complicated.

That led to a different approach for recognizing returning users while still considering what should happen when that browser identification is lost.

These were problems I had never expected to encounter when I first thought, "I want to count people using QR codes."

Building Something Is Different From Deploying It

Another major lesson was that a program working on my computer does not mean it is ready to be used.

The application needed to be hosted.

The database needed to run somewhere.

The public website needed HTTPS.

Environment variables and secret keys had to be handled correctly.

I ended up learning the different roles of services such as Vercel and Supabase because I actually needed them.

Instead of studying cloud architecture first and hoping I would eventually use it, I encountered each concept because the application had a concrete requirement.

For me, that made the learning process much easier to understand.

Security Changed the Project

The biggest change came when I started treating the application as something that could actually be used rather than just a prototype.

If real people use a system, security and privacy cannot be an afterthought.

I began testing questions such as:

Can an anonymous visitor retrieve user information?

Can a lower-privileged administrator access information that should be restricted?

What happens if an authentication token is exposed?

Does account recovery reveal information about another person?

Can administrative functions be used without the required authentication level?

The application went through multiple rounds of security improvements as these questions appeared.

Eventually, the cloud service and security design also went through an internal review before operational use.

That process taught me something important:

AI can make it dramatically easier to build software, but it does not remove the responsibility to understand what the software is doing.

Privacy Was Another Part of Software Development

Before this project, I would probably have thought of a Privacy Policy as a document added near the end of a website project.

Once personal information became part of the system, I realized it was connected directly to technical design.

What information do we collect?

Why do we need it?

Who can access it?

How long should it remain?

What happens when the project stops using the system?

Those questions affect both the Privacy Policy and the database design.

Thinking about privacy forced me to understand the application more clearly.

AI Did Not Build the Product by Itself

It would be misleading to describe the experience as simply asking AI to "make an app."

There were many iterations.

Sometimes an idea that sounded good created another problem.

A security improvement could affect usability. A database change could affect account recovery. A seemingly simple company-selection feature could affect existing users and historical records.

AI could propose solutions and write code, but someone still had to decide what behaviour was correct.

In my case, the advantage I had was not programming knowledge.

It was understanding the problem I wanted to solve.

What I Learned as a Non-Programmer

The biggest lesson from building Site Control Occupancy is not that programming is no longer necessary.

Professional software engineering knowledge still matters enormously.

What has changed is the starting point.

Previously, someone with an operational idea might have needed a software developer before even testing whether that idea made sense.

AI tools can reduce that initial barrier dramatically.

A person who understands a real-world problem can now describe it, build a prototype, test assumptions and gradually learn the technical concepts required to improve it.

That does not make the process effortless.

It makes the process accessible.

The Most Valuable Part Was Learning What I Didn't Know

When I started, I did not know that I would end up discussing database permissions, MFA, cloud regions, recovery mechanisms, audit logs, privacy retention or security reviews.

Each appeared because the project moved one step closer to being real.

That is probably the most valuable thing I gained from the process.

The application itself solves a relatively focused problem: recording movements and helping visualize occupancy between site areas.

But building it gave me a practical introduction to an entire world of software concepts that I previously had little reason to explore.

And it started with a very simple question:

Could I solve this construction-site problem with a QR code?