Stockholm, SwedenAzure architecture / Platform engineering

I build dependable systems for complicated work.

Platform engineer and Azure architect in Stockholm. At Dental IT and through Bragi AB, I work across enterprise cloud migrations, secure integrations, product development, and the operational reality around them.

Portrait of Gustaf Ekfeldt
Gustaf EkfeldtPlatform engineer and product founder
Build
Products from operational problems
Design
Secure platforms and boundaries
Connect
Systems, teams, and vendors
Resolve
Incidents with no obvious owner

Selected work

Products, platforms, and the problems between them.

The common thread is not a technology. It is taking a consequential mess, finding the useful boundary, and staying responsible until the result works in real life.

Owned product / Bragi AB

Dwelly

Renovation communication that knows every apartment.

Dwelly brings notices, timelines, status updates, documents, and e-signing into one place for projects where residents stay on-site during the work.

Resident communication / Project status / Documents / E-signing

Owned product / Bragi AB

Trapphuset

The board portal that puts the board in control.

Built for Swedish housing associations that want maintenance planning, signed meeting protocols, contracts, resident communication, and issue reporting without being locked into a traditional management contract.

Property operations / Governance / Resident portal / Workflow automation

Independent product / Privacy

Static

A privacy tool that answers surveillance with counter-intelligence.

Static blocks extension enumeration, browser fingerprinting, and session replay. Its opt-in Noise mode learns what a site probes and returns a stable, plausible decoy persona - entirely inside the browser.

Chrome + Firefox / 20+ API vectors / Zero backend / MIT licensed

Incident investigation

The 9 GB check-in.

A distributed dental group was losing access to its web-based clinical system during the same three windows every day. Because every clinic shared the network, one source could disrupt work everywhere.

60+ clinics

1,000+ managed endpoints

9 GB per repeated download

Signal

Everyone saw the outage. Nobody could see the source.

The traffic appeared to implicate the clinical platform because both paths terminated in AWS. Full packet capture was not viable at this scale; the firewall appliance exhausted its available memory within seconds.

Method

Build the observability the investigation needs.

I created a separate Azure log pipeline, compared destination traffic with private-link telemetry, narrowed the activity to one network scope, then introduced DNS logging and verified the endpoint with Wireshark.

Root cause

A remote-management task downloaded the same 9 GB package at every check-in.

Removing the affected user tasks ended the saturation across the network. I reported the behavior to the vendor, and it was changed in a subsequent product update.

Enterprise Azure migration

One platform transition across 30 locations and 700 users.

For Dentalum, I led a NIS2-driven migration spanning identity, mail, SharePoint, networking, virtual desktops, and the automation around onboarding and offboarding.

Identity
Mail migration, Entra ID, and dynamic security groups for each clinic.
Network
A shared Azure VNet with deliberately separated clinic subnets.
Access
Azure Virtual Desktop and virtual machines for controlled remote work.
Automation
Azure Functions connecting business systems to staff lifecycle workflows.

The chapter before Bragi

Molarisoft taught me that software needs the right conditions around it.

Inside Dental IT, I helped develop Molarisoft with a colleague as an internal venture within the Planmeca and Plandent group. We built budgets, architecture, product demonstrations, and three concepts: Elyxir, Molna, and Medtrics.

We presented to senior group leadership and brought Elyxir to a three-month pilot with service teams in Finland and Sweden. During customer review, I presented the architecture and authorization model, narrowed permissions after feedback, and carried pilot access through approval and successful sign-in. The proposed ownership model did not align, and the experience clarified the kind of company I wanted to build. A few months later, I founded Bragi AB.

Elyxir architecture

Enterprise AI without a public backend.

Separate delivery paths, guarded ingress, isolated Azure environments, private service access, and identity-based authorization.

Simplified Elyxir cloud architectureGitHub deploys separate development and live applications through independent workflows. Cloudflare protects each public edge. Both Azure environments use private service access and connect to Microsoft Entra ID and Graph.SOURCEDELIVERYPUBLIC EDGEAZURE ENVIRONMENTSIDENTITYGitHubApplication codeDEV workflowIndependent deliveryLIVE workflowIndependent deliveryCloudflareWAF / rate limitsCloudflareWAF / rate limitsDEVVNet-integrated appPRIVATE AI / SEARCH / DATAManaged identity + RBACLIVEVNet-integrated appPRIVATE AI / SEARCH / DATAManaged identity + RBACEntra IDGraph / SharePoint
  1. SourceGitHub application code
  2. DeliverySeparate DEV and LIVE workflows
  3. EdgeCloudflare WAF and rate limits
  4. AzureIsolated apps and private services
  5. IdentityEntra ID, Graph, and SharePoint
Public-safe system view. Mutable infrastructure details and literal resource wiring are intentionally omitted.
Inspect the technical decisions
  • Independent GitHub Actions workflows for development and live environments.
  • Cloudflare WAF, geographic restrictions, and rate limiting at the public edge.
  • VNet-integrated applications with separate application and private-resource network segments.
  • Private endpoints and private DNS for AI, search, data, storage, and secret management.
  • Managed identity and RBAC instead of embedded service credentials.
  • No public access to backend data and AI resources.
  • Microsoft Graph integration for Entra ID and SharePoint.
  • Worked directly with Microsoft's ISV + Digital Native CoE on AI Search, data architecture, private networking, identity, and token optimization, followed by an offline review of the updated network design.

Enterprise context

Organizations supported through my work at Dental IT.

Shown as project context, not endorsement.

Profile

The role changes. The responsibility does not.

I work best where infrastructure, software, operations, and people meet. That usually means the problem is difficult to hand off cleanly - so I stay close enough to understand the whole system.

  1. Incoming

    Irori

    Platform Engineer

    The next chapter: bringing the same systems view into a dedicated platform-engineering role.

  2. 2025 - now

    Bragi AB

    Developer & Founder

    Founded a product company to own both the software and the conditions around it, building Dwelly, Trapphuset, BRF Tavla, ATEM, and client platforms.

  3. 2021 - now

    Dental IT

    From first line to architecture.

    I joined close to day-to-day support, moved into the internal Escalated tier, and now lead architecture, migration, and platform decisions.

    1. StartedFirst line

      Users, incidents, and the operational context behind the technology.

    2. ProgressedEscalated

      Complex cases crossing systems, sites, suppliers, and obvious ownership.

    3. NowAzure Solutions Architect

      Architecture, identity, cloud migrations, integrations, and technical leadership.

  4. 2017 - 2021

    Swoother

    IT Consultant

    Started in consulting, working close to users and taking responsibility for the systems behind their day-to-day work.

Selected Bragi work

Different products. The same ownership of the result.

ATEM controlled protocol boundary website

Product and integration / Bragi AB

ATEM

A self-hosted, Entra-authenticated boundary that exposes nine deliberately selected Autotask tools to remote AI clients.
The Lounge networking platform

Client platform / Bragi AB

The Lounge

Built and maintain a closed B2B networking platform, with ongoing product development and support.

Owned product / Bragi AB

BRF Tavla

A deliberately narrow digital noticeboard for Swedish housing associations. Boards publish once; residents read through a stable link or QR code without an app, account, or another oversized portal.

Stockholm / Open to good conversations

Have a difficult system worth understanding?