Martin Pohl

Apple MDM · Identity & SSO · Builder with AI agents · Prague

01

What did you build, and what happened when it met the world?

I'm an Apple MDM and identity consultant (since 2018) who also runs Profispráva SVJ, a small property manager for homeowners' associations in Prague. Over the last weeks I built, mostly by directing AI agents, two iOS apps on top of it. ProfiSprávceSVJ is an owner portal with documents, payments and push notifications, and SVJ Monitor is a paid app that lets any apartment owner watch their own building's manager. Both are in TestFlight but not yet in the App Store, so there are no users or revenue to report yet. Apple rejected the first review because reviewers couldn't log in, and getting through Apple's process has been harder than writing the code. Alongside that I shipped Tokeny, a dashboard for OpenRouter AI spend.

02

Show us

  • martinpohl.cz is my portfolio: consulting, own projects and the blog.
  • profispravcesvj.cz is the property management company the apps are built on.
  • SVJ Monitor is the landing page and PWA for the paid owner app.
  • Tokeny is a live dashboard for OpenRouter AI spend.

The iOS apps are still in TestFlight, so you can't download them yet. You'd see an owner signing in with Apple, a passkey or an email code, then browsing their building's documents, payments and announcements, with push notifications from the manager.

03

The hardest problem you've solved

At Livesport, as Senior System Engineer, I built the company's Apple for Business stack from scratch. The Macs and iPhones had no central management, Windows machines sat beside them, and everything ran on Google Workspace. I chose Mosyle as the MDM, set up Apple Business Manager and zero-touch enrollment, and moved macOS and iOS security onto MDM policies. My key decision was not to bring in a classic AD/Azure AD domain just for Windows. Instead I managed Windows through Google Credential Provider (GCPW) with Enhanced desktop security, so Google Workspace stayed the single identity for every platform. That kept the stack simpler and cheaper to run than two parallel identity systems.

04

How do you actually use AI in your work today?

I run my one-person business with a team of AI agents. Each has its own job: building iOS apps, handling SVJ email, legal questions, social posts and property search. I direct them, review every pull request and click the Apple and DNS steps they can't do themselves. Because of that setup, these are in production: the profispravcesvj.cz site and owner portal on Supabase and Vercel, the SVJ Monitor PWA, my portfolio martinpohl.cz, and Tokeny, a dashboard that tracks what I spend on AI models through OpenRouter. With the model in the loop I rebuilt the whole app release pipeline: agents write the code, run EAS builds and push to TestFlight. What broke the first time was the part nobody automates. Apple rejected our first build because reviewers couldn't get past Sign in with Apple, the agents couldn't get through Apple's 2FA consoles, and one production deploy failed silently while an older build kept serving. My lesson is that the model writes code fast, but releases, identity and anything behind a human login still need me in the loop.

05

Why Groupon, why now, and what would you own in your first ninety days?

Groupon runs a big part of its engineering and operations from Prague, and it's in the middle of a turnaround, where a small team that moves fast matters more than headcount. That's how I already work: I spent the last year shipping products alone with AI agents, and before that I built Livesport's Apple for Business stack from scratch. Now is the moment because AI is changing how internal IT gets done, and I'd rather do that inside a company of Groupon's size than only for my own projects.

In my first ninety days I'd want to own the Apple and endpoint fleet together with identity and SSO: an audit of MDM, enrollment and access, then making the calls on zero-touch onboarding and offboarding, so new people get a ready laptop and accounts on day one without tickets. I'd take device and access requests off the IT and security team's plate and automate the repetitive parts with AI agents, with clear logs and a human approving anything risky.