Cost Allocation & Showback Platform  ·  View 17 of 22  ·  6 · Operations

Deployment Architecture

One region serves, one region holds the record. The recovery region rebuilds what can be recomputed.

Editable source SVG draw.io All views
Azure West Europe — primary Zone 1 AKS node pool serving Azure SQL primary statements, RPO 0 Zone 2 AKS node pool serving Sync replica zone-redundant Zone 3 — batch Spark pools spot, interruptible Fact store cluster 1.2 bn rows/mo Region-wide Raw landing zone ZRS, immutable blobs Key Vault CMK Event Hubs usage telemetry Azure North Europe — recovery Record of truth Geo-replica statements, audit Raw zone GRS copy rebuild source Cold serving AKS, scaled to zero RTO 4 h Fact store, rebuilt RTO 24 h Provider billing exports 3 clouds Cluster metrics ERP general ledger geo-replication GRS Deployment — One Region Serves, One Region Holds the Record Application we own Data store Security / platform Queue / topic External / third party event / async batch The recovery region holds what cannot be recomputed and rebuilds what can - the recovery fact store is rebuilt from the replicated raw zone. That asymmetry is why RTO is 4 hours for serving and 24 for the full fact store. v 1.0 · owner Platform Architecture · date 2026-09

The asymmetry

  • The recovery region geo-replicates statements, disputes, ownership, policy and audit — none of which can be recomputed
  • It keeps a GRS copy of the raw zone, from which the whole fact store is rebuildable
  • It does not keep a warm fact store, because doing so would double the largest cost in the platform

Targets

  • RTO 4 h for the reporting plane, 1 h on close days; RTO 24 h for full re-derivation of allocated facts
  • RPO 0 for statements, disputes, ownership and policy; RPO 24 h for conformed facts
  • Zone-redundant serving and synchronous replication inside the primary region

Cost discipline

  • The platform shall cost ≤ 0.5% of the spend it measures, and publishes its own cost as a line in its own report