Customer 360 Enterprise Data Platform — Denodo on Azure

Solution Architecture v1.0 · Data & AI Global Practice · 2026-09 · 39 views · Denodo Platform, Microsoft Azure and open source

One governed, semantic, secured view of a customer, assembled at query time from Salesforce, SAP S/4HANA, Oracle Billing, ServiceNow, Marketing Cloud, an Azure lakehouse and a digital event stream. Denodo is the enterprise logical data layer; the requirement's illustrative stack named Snowflake, AWS S3, Apigee, Okta, Reltio and Informatica, and this set answers it on Azure and open source instead — Databricks with Delta Lake on ADLS Gen2 for the lakehouse, Azure Event Hubs on the Kafka protocol for streaming, Azure API Management for the gateway, Microsoft Entra ID for identity, Zingg on Spark plus a PostgreSQL crosswalk in place of a commercial MDM, Soda Core for quality rules, Denodo's Presto-based Embedded MPP for lake acceleration, Microsoft Purview federating the Denodo catalogue, and Azure Monitor with Prometheus, Grafana and Sentinel for observability.

39 views 39 HTML views39 SVG39 draw.io Updated 2026-09-06
Architecture views

39 views, each in three formats.

Open a view to read it in full. Every SVG carries its diagram source inside it, so it opens in diagrams.net fully editable with no import step; the draw.io files are the same diagrams as plain source.

  1. 01
    System Context

    Who uses the Customer 360, what it reads, and what it deliberately does not touch.

  2. 02
    High-Level Architecture

    The shape of the platform in one picture: federate by default, materialise by exception.

  3. 03
    The Governing Principle

    Which responsibilities Denodo takes, and which it must be prevented from taking.

  4. 04
    Actors and Their Core Journeys

    Who the platform is for, in their own words, and what each of them gets to do with it.

  5. 05
    Journey — Answering an Inbound Call

    What happens to an agent in the first forty seconds, and the moment where the platform lets them down.

  6. 06
    Journey — Building a Customer Report

    How a report author finds, understands and is blocked by a dataset that was certified all along.

  7. 07
    Journey — Resolving a Duplicate Customer

    The one journey where the failure is a wrong answer rather than a slow one.

  8. 08
    Layered Architecture

    What depends on what, and why no consumer can reach a source structure directly.

  9. 09
    Container Architecture

    The deployable units, the technology in each, and what talks to what.

  10. 10
    The Denodo View Hierarchy

    The four modelling layers, the naming standard, and where each kind of logic is allowed to live.

  11. 11
    Integration Surface

    Every way the platform touches another system, with protocol, cadence and who owns it.

  12. 12
    Source Connectivity

    For each class of source: the connector, how it authenticates, what it can be asked to do, and what follows from that.

  13. 13
    Identity Resolution

    How five source identifiers become one enterprise customer, and why none of it happens in a view.

  14. 14
    Data Flow

    What is copied, what is only read, and the cadence on every arrow.

  15. 15
    Storage Zones

    Who owns each byte, what would have to be restored, and what could simply be rebuilt.

  16. 16
    The Customer 360 Logical Model

    The entities a consumer sees, the one key they all join on, and where the source keys survive.

  17. 17
    The Freshness Contract

    Which attribute groups are federated, cached or materialised — and the rule that decides, rather than the author.

  18. 18
    Caching and Acceleration

    What can answer a query, how each store is kept fresh, and where the platform refuses to help.

  19. 19
    Data Quality

    How a defect is detected, what it does to the record, and who is expected to fix it.

  20. 20
    A Customer360 Query, End to End

    What actually happens between a report refreshing and rows arriving, across five systems.

  21. 21
    Query Optimisation

    The stages between a statement and a plan, and which of them do the real work.

  22. 22
    A Data Service Call

    One REST call from the agent desktop, including the part where a source does not answer.

  23. 23
    Real-Time Digital Activity

    The one genuinely streaming path, and why Denodo does not read the stream.

  24. 24
    The AI Assistant

    How a grounded answer is produced, and why the model needed no security design of its own.

  25. 25
    When a Source Goes Down

    The degradation path, drawn across all four parties, from healthy through to recovery.

  26. 26
    Subject Access and Erasure

    Finding every copy of one person across six systems, and who is allowed to delete them.

  27. 27
    A Merge Propagates

    From a steward's approval to every consumer agreeing, and what happens if the notification is missed.

  28. 28
    Deployment

    What runs where, what survives a zone, and what a region failure actually costs.

  29. 29
    Workload Isolation

    Three classes with different latency contracts, and the one resource they still share.

  30. 30
    Environments and Delivery

    How a view change reaches production, and the three gates that stop a bad one.

  31. 31
    Observability

    Every signal from emission to the person or control that acts on it.

  32. 32
    The Operating Loop

    How the platform decides what to materialise next, and why that is a governed change.

  33. 33
    Cost Model

    What drives spend, what it scales with, and the four levers that actually move it.

  34. 34
    Trust Zones

    Where the boundaries are, what crosses each one, and where an attacker actually arrives.

  35. 35
    Identity and Access

    From a sign-in to a filtered, masked result set — and the one trade-off in the chain.

  36. 36
    Authorisation Model

    One policy set per role, and every channel inheriting it without restating it.

  37. 37
    Sensitive Data

    Five classes of sensitive data, classified once and enforced everywhere above it.

  38. 38
    Governance and Lineage

    From a business definition to a column-level trace, and the loop that keeps ownership honest.

  39. 39
    Failure Modes

    Every named way this breaks, what absorbs it, and the one class with no technical answer.

The package

Everything as it was delivered.

These files are served exactly as they were produced — the diagram pages keep their own house style because that is the artifact, not a rendering of it.