Customer 360 Enterprise Data Platform — Denodo on Azure
Denodo is the enterprise logical data layer: one governed, semantic, secured view of a customer assembled at query time from Salesforce, SAP, Oracle, ServiceNow, Marketing Cloud, an Azure lakehouse and a digital event stream. Read the set in order — the boundary and the governing principle first, then who it is for and what they get to do, and only then the structure that has to justify itself against them. One decision carries the whole design: Denodo owns access, never truth. Identity is mastered outside it, history lives in the lakehouse, streaming stays in Event Hubs, and every source system keeps writing its own records. That boundary is why the identity crosswalk is the one join the platform is forbidden to cache, why the freshness contract in view 17 is architecture rather than tuning, and why the AI assistant in view 24 needed no security design of its own.
Context and scope What sits inside the boundary, what the platform only reads, and the principle that decides everything after it.
People and journeys Who the 360 is for, and the three journeys whose worst moments the rest of the set has to answer.
04
People who take value from it
Customer Service Agent
1,800 seats
Goal — Know who I am talking to before they finish
saying their name, and tell whether their open case
is really still open.
Core journeys
Answer an inbound call
9,400 calls a day
Check an order or invoice
Raise a complaint
Relationship Manager
420 seats
Goal — Walk into a meeting knowing what this account
bought, what broke, and what we last promised them.
Core journeys
Prepare for an account meeting
Review my book
weekly
BI Developer
90 authors
Goal — Build a customer report on one certified
dataset instead of joining five systems whose table
names I do not know.
Core journeys
Find a certified dataset
Build a Power BI report
Data Scientist
35 users
Goal — Pull a governed cohort into a notebook with
the personal fields already masked, without raising a
ticket first.
Core journeys
Pull a masked cohort
Publish a score back
People who run and govern it
Data Steward
Customer Data Team
Goal — Prove where every attribute on the 360 came
from, and merge two records without anyone losing
history.
Core journeys
Resolve a duplicate customer
Certify a dataset
Answer a lineage question
Platform SRE
follow the sun
Goal — Find out that a source has gone slow before
the contact centre tells me.
Core journeys
Triage a slow query
Handle a source outage
Privacy Officer
DPO office
Goal — Answer a subject access request inside the
statutory window without a manual trawl through six
systems.
Core journeys
Fulfil a DSAR
Approve a masking exception
Systems that consume it
Agent Desktop App
60 rps at peak
Goal — Get the whole customer panel in one call, in
under two seconds, or a clear reason why not.
Core journeys
Load the customer panel
Customer AI Assistant
Azure OpenAI
Goal — Answer in the caller's words using only what
the agent asking is allowed to see.
Core journeys
Answer a grounded question
Partner Portal
4 partners
Goal — Read the subset of the 360 our contract
allows, and nothing beyond it.
Core journeys
Fetch an entitled subset
Machines that act unasked
ECID Resolution Job
nightly, 02:00 UTC
Goal — Reconcile every new source identifier to one
enterprise customer before the business day starts.
Core journeys
Resolve new identifiers
Publish crosswalk deltas
Cache Refresh Scheduler
Denodo Scheduler
Goal — Keep each cached view inside its declared
freshness window without stampeding the source.
Core journeys
Refresh on schedule
Invalidate on ECID change
Model Scoring Job
daily, Databricks
Goal — Land lifetime value, churn and segment scores
where the semantic layer can join them by morning.
Core journeys
Score and publish
Who the Customer 360 Is For, and What Each of Them Gets to Do
Person or role
Journey / task
External / third party
Security / platform
v 1.0 · owner Data & AI Global Practice · date 2026-09
Actors and Their Core Journeys
Who the platform is for, in their own words, and what each of them gets to do with it.
HTML page
SVG
draw.io
Structure The layering rule, the deployable units, every interface, and how five source identifiers become one customer.
09
Azure — Customer 360 landing zone
Edge and delivery
Front Door and WAF
TLS 1.3
Denodo Load Balancer
JDBC and ODBC
API Management
quota, keys, JWT
Denodo query tier — AKS node pools
VDP Interactive
3 pods, BI and desktop
VDP Data Services
2 pods, REST
VDP Analytical
2 pods, science
Embedded MPP
Presto, 6 workers
Denodo control tier
Solution Manager
licence, promotion
Design Studio
modelling
Data Catalog
search, certification
Scheduler
cache refresh
State
Cache Database
PostgreSQL Flexible
Metadata Database
VDP catalogue
ECID Crosswalk
PostgreSQL
Query Log
Log Analytics
Azure data platform
Databricks SQL
serverless warehouse
Delta Lakehouse
ADLS Gen2
Event Hubs
Kafka protocol
Unity Catalog
lake grants
Platform services
Microsoft Entra ID
Key Vault
source credentials
Azure Monitor
metrics and logs
Microsoft Purview
enterprise catalogue
Salesforce
SAP S/4HANA
Oracle Billing
ServiceNow
Marketing Cloud
REST
JDBC
cache read
offload
Parquet scan
OAuth REST
refresh
Container Architecture — The Deployable Units and What They Talk To
Interface / broker
Application we own
Data store
Queue / topic
Security / platform
External / third party
synchronous
batch
Three VDP pools, not one cluster: a data scientist scanning three years of orders cannot take latency from the contact centre. Source credentials are drawn on view 35, not here.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Container Architecture
The deployable units, the technology in each, and what talks to what.
HTML page
SVG
draw.io
12
Connector
Authentication
What is delegated
Access strategy
SaaS CRM
Salesforce adapter
OAuth 2.0 JWT bearer
SOQL filters, limits
Federated, no cache
ERP
SAP HANA JDBC
Vault-held tech user
Joins, aggregates
Federated plus partial
Billing
Oracle JDBC
Vault-held tech user
Joins, aggregates
Partial cache, 30 min
ITSM
ServiceNow REST
OAuth 2.0
Filters only
Cached 15 min
Marketing
Marketing Cloud REST
OAuth 2.0
Filters only
Cached 1 hour
Lakehouse
Databricks JDBC
Managed identity
Full SQL pushdown
Federated on gold
Lake files
Parquet base view
Managed identity
Partition pruning
MPP acceleration
Streaming
Delta streaming table
Managed identity
Partition pruning
Federated, 60 s lag
Identity crosswalk
PostgreSQL JDBC
Managed identity
Full SQL pushdown
Never cached
Source Connectivity — Connector, Identity, Delegation and Strategy
The two SaaS rows delegate least, which is why they are the two that get cached. Delegation capability, not preference, decides the strategy column.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Source Connectivity
For each class of source: the connector, how it authenticates, what it can be asked to do, and what follows from that.
HTML page
SVG
draw.io
Data What is copied and what is only read, who owns each byte, the model consumers see, and the freshness contract that decides between them.
15
Systems of record — the platform never writes here
Salesforce CRM
profile, segment
SAP S/4HANA
orders, invoices
Oracle Billing
payments
ServiceNow CSM
cases
Marketing Cloud
campaigns
Azure lakehouse — rebuildable from source in 14 hours
Bronze
Event landing
30 days
CDC change log
30 days
Silver
customer_activity
13 months
order_history
7 years
Gold
customer_value
daily snapshot
segment_and_churn
daily snapshot
Platform-owned state — the only data this platform masters
ECID Crosswalk
backed up, PITR 7 d
Survivorship Rules
Git, versioned
DQ Exceptions
90 days
Denodo Metadata
views, policies
Disposable acceleration — losing all of it costs latency, not data
Cache tables
TTL 15 min to 24 h
Summaries
rebuilt nightly
MPP result cache
in memory
CDC
nightly
invalidates
Storage Zones — Who Owns Each Byte, and What Could Be Rebuilt
External / third party
Data store
event / async
batch
Only the third box needs a backup strategy. Everything above it is authoritative elsewhere, and everything below it is rebuildable on demand.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Storage Zones
Who owns each byte, what would have to be restored, and what could simply be rebuilt.
HTML page
SVG
draw.io
17
Freshness required
Access strategy
Where it materialises
Refresh trigger
Customer profile
Near real time
Federated
Nowhere
Not applicable
Contact details
Near real time
Federated, masked
Nowhere
Not applicable
Account status
Near real time
Federated
Nowhere
Not applicable
Orders, last 90 days
Near real time
Federated
Nowhere
Not applicable
Order history, 3 years
Daily
MPP over Delta
Silver tables
Nightly ELT
Open support cases
Under 15 minutes
Partial cache
Cache database
Scheduler, 15 min
Marketing engagement
Under 1 hour
Full cache
Cache database
Scheduler, hourly
Digital activity
Under 60 seconds
Federated on Delta
Silver streaming
Continuous
Lifetime value, scores
Daily
Federated on gold
Gold tables
Model run, 03:00
Aggregated KPIs
Daily
Denodo summary
Summary table
After model run
Identity crosswalk
Immediate
Federated only
Never
Merge event
Freshness Contract — What Is Federated, Cached or Materialised, and Why
This table is the architecture, not a tuning guide. A view author cannot choose a strategy; they declare a freshness class and the platform assigns one.
v 1.0 · owner Data & AI Global Practice · date 2026-09
The Freshness Contract
Which attribute groups are federated, cached or materialised — and the rule that decides, rather than the author.
HTML page
SVG
draw.io
Runtime A query, an API call, a stream, an AI answer, a source outage, a subject access request and a merge — each followed end to end.
20
Power BI
Denodo Load Balancer
Virtual DataPort
ECID Crosswalk
Cache Database
Salesforce
SAP S/4HANA
Embedded MPP
1. SQL on Customer360
2. route to interactive pool
3. validate token, resolve roles
4. expand views, prune branches
5. enterprise ids for this region
6. 4,812 ids
7. open cases, refreshed 4 min ago
8. case rows
9. SOQL, filtered and projected
10. delegated join and aggregate
11. profile rows
12. pre-aggregated totals
13. three-year history scan
14. aggregate over Delta
15. apply row filter and column masks
16. result set, 1.9 s
Runtime — One Customer360 Query, End to End
Five sources, two of them never touched: the branch pruner removed marketing and billing because no projected column came from them.
v 1.0 · owner Data & AI Global Practice · date 2026-09
A Customer360 Query, End to End
What actually happens between a report refreshing and rows arriving, across five systems.
HTML page
SVG
draw.io
Operations Where it runs, how it survives a zone and a region, how a view reaches production, what is watched, and what it costs.
28
Azure North Europe — primary, active
Availability zone 1
VDP Interactive
1 pod, 8 vCPU
VDP Data Services
1 pod, 8 vCPU
MPP workers
2 nodes
Availability zone 2
VDP Interactive
1 pod, 8 vCPU
VDP Data Services
1 pod, 8 vCPU
MPP workers
2 nodes
Availability zone 3
VDP Interactive
1 pod, 8 vCPU
VDP Analytical
2 pods, 16 vCPU
MPP workers
2 nodes
Zone-redundant services
PostgreSQL Flexible
ZRS, HA pair
ADLS Gen2
ZRS
Key Vault
zone redundant
Event Hubs
ZRS namespace
Azure West Europe — warm standby
Compute, scaled down
VDP pods
1 per pool, idle
Solution Manager
standby node
Replicated state
PostgreSQL replica
geo, RPO 5 min
ADLS GRS
asynchronous
Metadata replica
revision synced
Salesforce
SAP S/4HANA
ServiceNow
Traffic Manager
health-probed failover
geo-replication
GRS
failover
Deployment — Three Zones Live, One Region Warm
Application we own
Data store
Security / platform
Queue / topic
External / third party
Interface / broker
event / async
failure / alternate
Losing a zone loses a third of capacity and no session state. Losing the region costs 30 minutes to RTO, and the cache is deliberately not replicated because it is rebuildable.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Deployment
What runs where, what survives a zone, and what a region failure actually costs.
HTML page
SVG
draw.io
Assurance Trust boundaries, identity, the single policy set every channel inherits, sensitive data, governance, and every failure mode named.
34
Internet — untrusted
Browser and mobile
Credential stuffing
Scripted extraction
Perimeter — Azure edge
Front Door and WAF
TLS 1.3, OWASP set
API Management
JWT, quota, schema
DDoS Protection
Application — private virtual network
VDP pods
no public address
Data Catalog
Design Studio
named users only
Solution Manager
Data — reachable by private endpoint only
Cache database
ECID Crosswalk
ADLS Gen2
CMK encrypted
Databricks
no public workspace
Control — separate subscription, separate
administrators
Key Vault
HSM-backed keys
Microsoft Entra ID
conditional access
Microsoft Sentinel
write-once sink
Audit archive
13 months, immutable
TLS 1.3, WAF
blocked
bearer, mTLS
Private Link
managed identity
audit
Trust Zones — What Crosses Each Boundary, and What Proves It May
External / third party
Risk / gap
Interface / broker
Security / platform
Application we own
Data store
synchronous
failure / alternate
event / async
No secret is held by a consumer and none by a pod. Every credential is fetched at runtime under a managed identity, and the audit path is one-directional by design.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Trust Zones
Where the boundaries are, what crosses each one, and where an attacker actually arrives.
HTML page
SVG
draw.io
35
Relationship Manager
Power BI
Microsoft Entra ID
Denodo Load Balancer
Virtual DataPort
Key Vault
SAP S/4HANA
Microsoft Sentinel
1. opens the account report
2. OIDC authorisation code flow
3. access token with group claims
4. ODBC connection, bearer token
5. least-busy node
6. validate signature, read claims
7. roles: rm_emea, no_payment_data
8. map roles to view grants
9. fetch the SAP service credential
10. secret, 60-minute lease
11. rows for the delegated predicate
12. row filter by book, mask payment columns
13. authorised rows only
14. principal, view, row count, masks
Identity — From a Sign-In to a Filtered, Masked Result Set
The source sees the platform identity, not the user. That is a deliberate trade: pass-through authentication was rejected because SAP and Salesforce cannot express the enterprise role model, so the filter must be applied where the model exists.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Identity and Access
From a sign-in to a filtered, masked result set — and the one trade-off in the chain.
HTML page
SVG
draw.io
36
Datasets granted
Column policy
Row policy
Channels
Service Agent
Customer360, Support
Contact masked to last 4
Own contact-centre queue
Desktop REST, assistant
Relationship Manager
Customer360, Orders, Value
Full contact, no payment
Own account book
Power BI, Excel
BI Developer
Certified business views
Value masked until granted
All rows, aggregate only
Design Studio, Power BI
Data Scientist
Integration and business views
Pseudonymised keys
Sampled cohorts
JDBC from notebooks
Data Steward
Every view and the crosswalk
Unmasked, reason recorded
All rows
Studio, catalog, console
Privacy Officer
DSAR assembly view only
Unmasked, case-scoped
One subject at a time
DSAR console
Platform SRE
Metadata and logs only
No customer columns
No customer rows
Monitor, Solution Manager
AI Assistant
Whatever the caller has
Whatever the caller has
Whatever the caller has
MCP tools only
Partner Portal
Contracted subset
No personal data at all
Own contracted accounts
REST through APIM
Authorisation — One Policy Set, Inherited by Every Channel
The assistant row is the whole security argument for AI: it has no grants of its own, so nothing had to be reasoned about twice.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Authorisation Model
One policy set per role, and every channel inheriting it without restating it.
HTML page
SVG
draw.io
37
Classify
Tag
Policy
Enforce
Prove
Direct identifiers
Name, tax id
pii.direct
Deny unless granted
Full redaction
Access log per query
Contact data
Email, phone, address
pii.contact
Partial by role
Last four shown
Mask applied count
Financial
Card, IBAN, balance
pii.financial
Deny by default
Tokenised at source
Never cached
Behavioural
Clickstream, sessions
pii.behaviour
Pseudonymised
Hashed device id
Re-identification review
Derived scores
Lifetime value, churn
restricted.model
Approved purpose only
Row filter by book
Purpose recorded
Sensitive Data — Classified Once, Enforced Everywhere
Classification is declared on the integration view, not on each business view. A new business view inherits every mask the moment it is created, which is why the layering rule is a security control.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Sensitive Data
Five classes of sensitive data, classified once and enforced everywhere above it.
HTML page
SVG
draw.io
39
Source-side — expected, absorbed
Source unavailable
partial result, view 25
Source slow
timeout, circuit opens
API quota exhausted
backoff, cache serves
Schema drift
base view breaks in CI
Platform — degraded, not lost
VDP pod loss
retried, no session state
Cache database loss
cold reads, 3x latency
MPP cluster loss
falls back to the source
Region loss
RTO 30 min, RPO 5 min
Correctness — the class that actually matters
Stale cache after a merge
reconciler bounds at 1 h
Crosswalk corruption
point in time, 7 days
Wrong survivorship pick
replayable from source ids
Masking regression
policy scan blocks release
Programme — slow, and therefore easy to miss
Uncertified view in use
promotion gate blocks it
Owner leaves, asset orphaned
certification expires
Extract copied to a spreadsheet
usage telemetry only
Denodo becomes the bottleneck
the real programme risk
same root cause
concentration risk
Failure Modes — What Breaks, What Absorbs It, and What Is Left Over
Risk / gap
synchronous
failure / alternate
The last box has no technical mitigation. Every consumer depending on one logical layer is the price of the design, and it is managed by workload isolation and honest capacity planning rather than by architecture.
v 1.0 · owner Data & AI Global Practice · date 2026-09
Failure Modes
Every named way this breaks, what absorbs it, and the one class with no technical answer.
HTML page
SVG
draw.io
Open svg/<view>.svg or drawio/<view>.drawio in draw.io Desktop or at app.diagrams.net to edit. The SVG carries the diagram inside it, so it is both the picture and the source. This folder is self-contained — copy it whole and every link still resolves.