Customer 360 Enterprise Data Platform — Denodo on Azure  ·  View 25 of 39  ·  Runtime

When a Source Goes Down

The degradation path, drawn across all four parties, from healthy through to recovery.

Editable source SVG draw.io All views
Healthy Detect Degrade Inform Recover Source ServiceNow responding Latency past 3 s Errors above 25% Vendor incident open Probe succeeds Denodo Full 360 assembled Timeout at 3 s Circuit opens Partial result built Per-domain status set Half-open retry Consumer Every panel populated No visible change Support panel greyed Cases unavailable, 09:14 Panel repopulates Operator Source SLO green Alert on error budget Runbook opened Status page updated Post-incident review When a Source Goes Down — Partial, Labelled, and Never Silent This is the answer to the agent journey's worst moment. An empty panel and an unreachable source must never look the same, so the contract carries a status per domain rather than one status per response. v 1.0 · owner Data & AI Global Practice · date 2026-09

The design rule

  • An empty panel and an unreachable source must never look the same. Everything else on this page follows from that one sentence.
  • The circuit opens on error rate rather than on a single timeout, so a slow query does not remove a working source from the 360.
  • Graceful degradation is per domain. Losing ServiceNow costs the support panel and nothing else; the profile, orders and value panels are unaffected.

Numbers

  • Source timeout 3 s; circuit opens above 25% errors in a 60-second window; half-open retry after 30 seconds.
  • The consumer sees a timestamped notice, so an agent can tell a customer how current the information they do have is.

Assumptions

  • Every source has a health probe that is independent of the query path; a source that only looks healthy because queries are succeeding cannot be trusted during an incident.
  • Vendor status pages are not on the critical path of detection.