The platform is an active metadata hub, not a passive catalog: metadata flows back out to policy enforcement, quality tooling and incident management. A catalog that only absorbs becomes shelfware.
Federated ownership with central policy. Domains own their assets, terms and certification; the central function owns the canonical model, the policy catalogue and the stewardship SLA.
Four personas are first-class, not one: consumer, steward, domain owner and platform engineer each have a distinct surface. Governance and security read the same graph through the console.
Explicit non-goals
It does not execute data-quality tests — results are ingested from the engines that already run them (view 15).
It does not enforce access at query time — it publishes labels that the platforms already enforcing access consume (view 05).
It does not store data values. Only bounded profile statistics, and none at all for confidential or restricted assets (view 20).
Assumptions to confirm
200 source systems in scope at go-live, ~40 distinct connector types.
20,000 licensed users, ~2,000 daily active; single tenant, EU data residency.
Entra ID is the enterprise IdP and group source, synchronised over SCIM.