Customer 360 Enterprise Data Platform — Denodo on Azure

Architecture Views

39 views, in reading order. Every view ships three ways: an HTML page, an SVG that re-opens in diagrams.net fully editable, and draw.io source.

Denodo is the enterprise logical data layer: one governed, semantic, secured view of a customer assembled at query time from Salesforce, SAP, Oracle, ServiceNow, Marketing Cloud, an Azure lakehouse and a digital event stream. Read the set in order — the boundary and the governing principle first, then who it is for and what they get to do, and only then the structure that has to justify itself against them. One decision carries the whole design: Denodo owns access, never truth. Identity is mastered outside it, history lives in the lakehouse, streaming stays in Event Hubs, and every source system keeps writing its own records. That boundary is why the identity crosswalk is the one join the platform is forbidden to cache, why the freshness contract in view 17 is architecture rather than tuning, and why the AI assistant in view 24 needed no security design of its own.

Context and scope

What sits inside the boundary, what the platform only reads, and the principle that decides everything after it.

People and journeys

Who the 360 is for, and the three journeys whose worst moments the rest of the set has to answer.
04 People who take value from it Customer Service Agent 1,800 seats Goal — Know who I am talking to before they finish saying their name, and tell whether their open case is really still open. Core journeys Answer an inbound call 9,400 calls a day Check an order or invoice Raise a complaint Relationship Manager 420 seats Goal — Walk into a meeting knowing what this account bought, what broke, and what we last promised them. Core journeys Prepare for an account meeting Review my book weekly BI Developer 90 authors Goal — Build a customer report on one certified dataset instead of joining five systems whose table names I do not know. Core journeys Find a certified dataset Build a Power BI report Data Scientist 35 users Goal — Pull a governed cohort into a notebook with the personal fields already masked, without raising a ticket first. Core journeys Pull a masked cohort Publish a score back People who run and govern it Data Steward Customer Data Team Goal — Prove where every attribute on the 360 came from, and merge two records without anyone losing history. Core journeys Resolve a duplicate customer Certify a dataset Answer a lineage question Platform SRE follow the sun Goal — Find out that a source has gone slow before the contact centre tells me. Core journeys Triage a slow query Handle a source outage Privacy Officer DPO office Goal — Answer a subject access request inside the statutory window without a manual trawl through six systems. Core journeys Fulfil a DSAR Approve a masking exception Systems that consume it Agent Desktop App 60 rps at peak Goal — Get the whole customer panel in one call, in under two seconds, or a clear reason why not. Core journeys Load the customer panel Customer AI Assistant Azure OpenAI Goal — Answer in the caller's words using only what the agent asking is allowed to see. Core journeys Answer a grounded question Partner Portal 4 partners Goal — Read the subset of the 360 our contract allows, and nothing beyond it. Core journeys Fetch an entitled subset Machines that act unasked ECID Resolution Job nightly, 02:00 UTC Goal — Reconcile every new source identifier to one enterprise customer before the business day starts. Core journeys Resolve new identifiers Publish crosswalk deltas Cache Refresh Scheduler Denodo Scheduler Goal — Keep each cached view inside its declared freshness window without stampeding the source. Core journeys Refresh on schedule Invalidate on ECID change Model Scoring Job daily, Databricks Goal — Land lifetime value, churn and segment scores where the semantic layer can join them by morning. Core journeys Score and publish Who the Customer 360 Is For, and What Each of Them Gets to Do Person or role Journey / task External / third party Security / platform v 1.0 · owner Data & AI Global Practice · date 2026-09 Actors and Their Core Journeys Who the platform is for, in their own words, and what each of them gets to do with it. HTML page SVG draw.io

Structure

The layering rule, the deployable units, every interface, and how five source identifiers become one customer.
09 Azure — Customer 360 landing zone Edge and delivery Front Door and WAF TLS 1.3 Denodo Load Balancer JDBC and ODBC API Management quota, keys, JWT Denodo query tier — AKS node pools VDP Interactive 3 pods, BI and desktop VDP Data Services 2 pods, REST VDP Analytical 2 pods, science Embedded MPP Presto, 6 workers Denodo control tier Solution Manager licence, promotion Design Studio modelling Data Catalog search, certification Scheduler cache refresh State Cache Database PostgreSQL Flexible Metadata Database VDP catalogue ECID Crosswalk PostgreSQL Query Log Log Analytics Azure data platform Databricks SQL serverless warehouse Delta Lakehouse ADLS Gen2 Event Hubs Kafka protocol Unity Catalog lake grants Platform services Microsoft Entra ID Key Vault source credentials Azure Monitor metrics and logs Microsoft Purview enterprise catalogue Salesforce SAP S/4HANA Oracle Billing ServiceNow Marketing Cloud REST JDBC cache read offload Parquet scan OAuth REST refresh Container Architecture — The Deployable Units and What They Talk To Interface / broker Application we own Data store Queue / topic Security / platform External / third party synchronous batch Three VDP pools, not one cluster: a data scientist scanning three years of orders cannot take latency from the contact centre. Source credentials are drawn on view 35, not here. v 1.0 · owner Data & AI Global Practice · date 2026-09 Container Architecture The deployable units, the technology in each, and what talks to what. HTML page SVG draw.io

Data

What is copied and what is only read, who owns each byte, the model consumers see, and the freshness contract that decides between them.

Runtime

A query, an API call, a stream, an AI answer, a source outage, a subject access request and a merge — each followed end to end.

Operations

Where it runs, how it survives a zone and a region, how a view reaches production, what is watched, and what it costs.

Assurance

Trust boundaries, identity, the single policy set every channel inherits, sensitive data, governance, and every failure mode named.
Open svg/<view>.svg or drawio/<view>.drawio in draw.io Desktop or at app.diagrams.net to edit. The SVG carries the diagram inside it, so it is both the picture and the source. This folder is self-contained — copy it whole and every link still resolves.