Customer 360 Enterprise Data Platform — Denodo on Azure  ·  View 15 of 39  ·  Data

Storage Zones

Who owns each byte, what would have to be restored, and what could simply be rebuilt.

Editable source SVG draw.io All views
Systems of record — the platform never writes here Salesforce CRM profile, segment SAP S/4HANA orders, invoices Oracle Billing payments ServiceNow CSM cases Marketing Cloud campaigns Azure lakehouse — rebuildable from source in 14 hours Bronze Event landing 30 days CDC change log 30 days Silver customer_activity 13 months order_history 7 years Gold customer_value daily snapshot segment_and_churn daily snapshot Platform-owned state — the only data this platform masters ECID Crosswalk backed up, PITR 7 d Survivorship Rules Git, versioned DQ Exceptions 90 days Denodo Metadata views, policies Disposable acceleration — losing all of it costs latency, not data Cache tables TTL 15 min to 24 h Summaries rebuilt nightly MPP result cache in memory CDC nightly invalidates Storage Zones — Who Owns Each Byte, and What Could Be Rebuilt External / third party Data store event / async batch Only the third box needs a backup strategy. Everything above it is authoritative elsewhere, and everything below it is rebuildable on demand. v 1.0 · owner Data & AI Global Practice · date 2026-09

The backup argument

  • Only the third box needs a backup strategy. Everything above it is authoritative in a system we do not own, and everything below it is rebuildable on demand.
  • That makes the crosswalk, the survivorship rules, the quality exceptions and the Denodo metadata the platform's entire recovery surface — four small stores, not a data lake.

Numbers

  • Crosswalk: point-in-time restore, 7 days retained, RPO 5 minutes through geo-replication.
  • Lakehouse: rebuildable end to end from source in about 14 hours; not backed up, replicated for availability only.
  • Cache and summaries: never backed up. Losing all of them costs latency for one refresh cycle.

Risks

  • A 14-hour lakehouse rebuild is acceptable for analytics and not for the 360. The federated path must keep working while it runs, which is what the never-cache rule on the crosswalk protects.