| Raw landing zone |
ADLS Gen2 with immutable blob policy and lifecycle tiering |
Azure |
S3 with Object Lock, or GCS with bucket retention |
Write-once semantics enforced by the platform rather than by convention, and tiering to archive without changing the path |
ADR-02 |
| Cost fact store |
Azure Data Explorer, partitioned by period and provider |
Azure |
Synapse dedicated pools, BigQuery, Snowflake, or Delta on Databricks SQL |
Columnar scan over a 13-month window with materialised roll-ups, and cheap partition drop for retention |
ADR-03 |
| Allocation engine |
Azure Databricks, partition-parallel, on spot node pools |
Azure |
Synapse Spark, EMR, Dataproc, or a warehouse-native SQL pipeline |
Deterministic partitioned execution with checkpointing, which is what makes a pure re-run affordable on interruptible capacity |
ADR-15 |
| Ingestion orchestration |
Azure Data Factory with per-provider pipelines |
Azure |
Airflow, Step Functions, or Cloud Composer |
Declarative per-source scheduling with landing manifests and a clear cutoff-and-escalate semantic |
ADR-11 |
| Ownership, policy and statements |
Azure SQL Database, zone-redundant, geo-replicated |
Azure |
PostgreSQL Flexible Server, Aurora, or Cloud SQL |
Temporal tables for effective dating, synchronous commit for RPO 0, and transactional publication of a frozen statement |
ADR-05 |
| Policy registry |
Git repository as the source, versions pinned in Azure SQL |
Open source + Azure |
A policy table with an approval workflow, or OPA bundles |
Review, history and rollback come free; the pinned version id is what the allocation run actually reads |
ADR-01 |
| Usage telemetry transport |
Event Hubs with downsampling on ingest |
Azure |
Kafka, Kinesis, or Pub/Sub |
2.6 bn samples a month at bounded retention, with a consumer that can fall behind without losing the window |
ADR-09 |
| Serving tier |
AKS across availability zones, autoscaled |
Azure |
App Service, Cloud Run, or ECS |
Serving isolated from batch so no interactive request ever queues behind an allocation run |
ADR-15 |
| Identity |
Entra ID with workload identity and enforced MFA |
Azure |
Okta with OIDC, or any IdP issuing group claims |
Short-lived machine credentials with no static keys, and group claims that name the person rather than their scope |
ADR-16 |
| Key management |
Key Vault with customer-managed keys and rotation |
Azure |
KMS, Cloud KMS, or HashiCorp Vault |
Rotation without re-ingestion, which matters when the raw zone is immutable and 37 months deep |
ADR-16 |
| Provider billing access |
Per-provider export-read-only credentials in Key Vault |
Multi-cloud |
Any least-privilege billing reader role |
Credentials that read the bill cannot reach the workloads, which is what makes estate-wide access acceptable |
ADR-16 |
| Billing schema |
FOCUS-conformed cost record, provider fields retained |
FinOps Foundation |
A bespoke internal schema |
One vocabulary across three clouds, with the provider-native columns kept so nothing is lost in translation |
ADR-02 |
| Dashboards and marts |
Pre-aggregated roll-ups served to Power BI and the platform UI |
Azure |
Looker, QuickSight, or Superset |
Bounded query cost per team, with full-grain reads reserved for drill-through |
ADR-03 |
| Observability |
Azure Monitor, alerting on correctness rather than availability |
Azure |
Prometheus and Grafana, or any SLO tooling |
For a measurement platform, being wrong is worse than being late, and the alert policy has to say so |
ADR-11 |