Internal Developer Platform  ·  View 01 of 21  ·  Context and scope

System Context

Who asks the platform for things, and which systems it must drive to answer.

Editable source SVG draw.io All views
Source and supply chain GitHub Enterprise Container Registry People Product Engineer Tech Lead Platform Engineer Security Engineer Azure estate Landing Zone AKS Fleet Managed Data Services Internal Developer Platform Paved road · guardrails Governance and money Microsoft Entra ID Cost Management Risk and Audit scaffolds · deploys owns components ships the road authors policy subscriptions runs workloads provisioned intent signed images entitlements spend evidence Internal Developer Platform — System Context External / third party Person or role Security / platform synchronous two-way batch The platform is a tenant of the landing zone, not its owner: it provisions inside subscriptions the landing zone hands it. v 1.0 · owner Platform Architecture · date 2026-09

Decisions

  • The platform is a tenant of the landing zone, not its owner: it provisions inside subscriptions handed to it, under an Azure Policy floor it does not set.
  • GitHub is the only bidirectional edge on the diagram, because the team's repository holds intent and the platform must both write to it and read from it.
  • Entra ID is the sole source of identity and entitlement; the platform maintains no user or access list of its own.

Assumptions

  • 900 engineers, 140 teams, 1,400 deployable components, 5,200 deploys per week (stated assumptions throughout the set).
  • An existing landing zone with management groups and a subscription vending process already in place.
  • A current baseline of 19 working days from request to first production deploy, which is the number the platform is built to destroy.

Out of scope

  • Product code, product architecture and product on-call. The platform paves the road; teams drive on it.
  • Network topology, subscription vending and the organisation's policy floor — the landing zone owns all three.
  • Being an approval workflow. A request the platform accepts and then queues for a human has already failed.