Consent & Privacy Service  ·  View 02 of 22  ·  Context and scope

High-Level Architecture

Five stages, and the seam between Decide and Act that the rest of the set exists to explain.

Editable source SVG draw.io All views
Declare Purpose registry Aurora Global Two-person approval Capture Consent SDK web, iOS, Android Capture service Fargate Consent ledger DynamoDB, append-only Decide Current-state projection rebuildable Decision API p99 10 ms In-process cache last-known-good Act Withdrawal stream EventBridge Case orchestrator Step Functions Suppression list consulted on ingest Prove Verification prober sampled absence Evidence store S3 Object Lock policy bundle streams withdrawal Consent & Privacy Service — High-Level Architecture Security / platform Decision point Application we own Data store Interface / broker Queue / topic batch synchronous event / async The seam the set is about sits between Decide and Act: the platform knows the permission, other systems hold the data. v 1.0 · owner Security & Identity Architecture

Decisions

  • Declare precedes Capture: an unregistered purpose cannot be consented to, and there is no default purpose.
  • Capture commits to the ledger before acknowledging, and acknowledges without waiting for projection, propagation or anything downstream.
  • Prove is a stage, not a by-product. Verification probing and the evidence store are first-class because an attestation from a target system is a claim, not a fact.

The seam

  • Left of Act, the platform is authoritative and fast. Right of it, every outcome belongs to somebody else's system and arrives as an attestation or a silence.
  • That is why erasure is a four-state protocol and withdrawal has a published propagation ceiling rather than a latency target.

Assumptions

  • Decision p99 ≤ 10 ms on local cache hit, ≤ 40 ms on remote evaluation in-region; capture acknowledged at p99 ≤ 200 ms.
  • 120,000 decisions/second steady state, 400,000/second for a 120 s burst.