File Upload & Scanning Pipeline  ·  View 01 of 21  ·  Context and scope

System Context

One upload plane for twelve product tenants, and the four consumers that are deliberately outside it.

Editable source SVG draw.io All views
Product tenants (callers) Desktop sync client folder sync, bulk lane Chat product Docs & wiki product People and public submitters Workspace member Tenant security admin Platform security analyst Forms & intake product Platform dependencies Workforce & customer IdP Microsoft Entra ID Signature & intel feed vendor, pulled Scan engine vendors licensed images Key management Key Vault / Managed HSM File Upload & Scanning Pipeline Accept · scan · quarantine · serve Event consumers (out of scope) Preview & thumbnail service DLP classification Security SIEM Notification service attaches reviews break-glass public intake attachments page files authn signatures engine images tenant keys available verdicts detections state System Context — File Upload & Scanning Pipeline External / third party Person or role Security / platform synchronous v 1.0 · stack Microsoft Azure · scope attachment plane for 12 product tenants

In scope

  • Upload initiation, credentialing and admission — every rejection that can happen before a byte moves
  • Resumable chunked transfer up to 50 GB, content identity, and deduplicated verdict reuse
  • Scan orchestration across multiple engines, the quarantine state machine, and the authorised download path

Out of scope

  • Preview and thumbnail generation — a subscriber to the available event, not a stage of the pipeline
  • DLP classification and content indexing — they consume verdicts; they do not gate them
  • The product surfaces that render attachments, and long-term archival policy

Why the public-intake caller sits with the people

  • An external submitter to a form is not a tenant's backend; it is an unauthenticated stranger with a credential good for one blob path
  • That path carries the strictest ceiling and the narrowest type allow-list in the platform, and no scope declared backend-only
  • Drawing it beside the members rather than beside the product backends is the honest placement, because the trust level is the same

Stated assumptions

  • 40 million monthly active members across 12 product tenants
  • 60 million objects a day, mean 2.4 MB, p99 240 MB, maximum 50 GB
  • Engines are licensed vendor images, pulled, not built here