Event-Driven Notification Platform · View 02 of 26 · 1 · Context and scope
High-Level Architecture
The shape of the platform in one picture, for the reader who will see only one.
Copy
PNG
PDF
⋯
Editable source
SVG
draw.io
All views
Produce
Produce
Business applications
no PII in payload
Business applications...
Campaign Manager
bulk audiences
Campaign Manager...
Ingest
Ingest
Envoy Gateway
mTLS · JWT · quota
Envoy Gateway...
Event Ingest API
Go · ack p95 80 ms
Event Ingest API...
Schema Registry
Avro · backward only
Schema Registry...
Distribute
Distribute
Apache Kafka
3 priority tiers · RF 3
Apache Kafka...
Event Archive
Iceberg · 400 d
Event Archive...
Decide
Decide
Rules Engine
Flink · CEL conditions
Rules Engine...
Preference Service
consent · quiet hours
Preference Service...
Orchestrator
Temporal workflows
Orchestrator...
Compose
Compose
Template Service
versioned · localised
Template Service...
Render Service
Handlebars · MJML
Render Service...
Rate Limiter
Redis token bucket
Rate Limiter...
Deliver
Deliver
Channel Workers
6 channels · Go
Channel Workers...
Providers
2 per channel
Providers...
Delivery Store
ClickHouse · 90 d
Delivery Store...
5 min micro-batch
5 min micro-batch
receipts
receipts
High-Level Architecture
High-Level Architecture
External / third party
External / third party
Interface / broker
Interface / broker
Application we own
Application we own
Security / platform
Security / platform
Queue / topic
Queue / topic
Data store
Data store
batch
batch
event / async
event / async
Retry, channel fallback, scheduling and every failure path are deliberately omitted here — acts 4 and 6 carry them.
Retry, channel fallback, scheduling and every failure path are deliberately omitted here — acts 4 and 6 carry them.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Decisions
Ingestion acknowledges after a durable Kafka write, not after a decision — producers are never blocked by rule evaluation
Rules are evaluated once, centrally, in a stateful stream job; channel workers make no routing decisions
Every channel is a consumer of its own topic, so one slow provider cannot back up another
Targets
Event ingestion acknowledged p95 under 80 ms, p99 under 100 ms
Event to notification queued p95 under 800 ms
Event to provider accepted p95 under 2 s for transactional traffic
99.95% availability on ingestion, 99.9% on the platform as a whole
Deliberately omitted
Retry, channel fallback and dead-lettering — views 17 and 26
Scheduling, digests and quiet hours — view 16
Everything about tenancy and isolation — view 08
◀ System Context
All views
Layered Architecture ▶