CI/CD Platform  ·  View 01 of 22  ·  Context and scope

System Context

Who triggers a build, what the platform reads without writing, and where the evidence goes.

Editable source SVG draw.io All views
Accountable for release Release owner Security engineering People who push and review Application engineer Code reviewer Outside contributor Platform engineer Systems of record Source control Package registries Container registry Identity provider CI/CD Platform commit to production Targets and consumers Runtime platforms Audit and compliance Cloud control planes pushes commits approves merge opens fork PR owns capacity events, definitions dependencies publishes images authenticates approves promotion sets gate policy deploys to evidence feed provisions capacity CI/CD Platform — System Context Person or role External / third party synchronous batch Test authoring, the runtime platform and the registries are outside the boundary. The platform reads source control and never writes to it. v 1.0 · owner Platform Engineering · date 2026-09

Decisions

  • Source control is read-only to the platform. Definitions are fetched at the commit under test; nothing is pushed back except a check status.
  • The outside contributor is a first-class actor in the context, not an exception handled later. Their code runs on the same substrate under a different credential posture.
  • Package and container registries sit outside the boundary and are reached through the platform's own mirror, so an upstream outage degrades latency rather than stopping all builds.

Deliberately out of scope

  • Test authoring and test frameworks — the platform runs tests, it does not define them.
  • The runtime platform that receives a deployment; the platform moves a digest pointer and reports the outcome.
  • Incident management, and developer laptops including any local build cache on them.

Assumptions

  • 4,200 engineers in 610 teams across 38,000 repositories; a tenant is a team.
  • ~300 fork pull requests per quarter from outside the company.
  • Every figure in this set is a stated assumption unless tied to a named provider SLA.