Enterprise Metadata Management System · View 12 of 22 · Runtime
Search and Discovery
The read path a data consumer actually experiences, and where entitlements are applied.
Copy
PNG
PDF
⋯
Editable source
SVG
draw.io
All views
Data Consumer
Data Consumer
Catalog UI
Catalog UI
API Gateway
API Gateway
Search Service
Search Service
Entitlement Filter
Entitlement Filter
Search Index
Search Index
Knowledge Graph
Knowledge Graph
1. search "net revenue"
1. search "net revenue"
2. GraphQL search
2. GraphQL search
3. verify OIDC token
3. verify OIDC token
4. query + principal
4. query + principal
5. resolve visibility
5. resolve visibility
6. domain + label filter
6. domain + label filter
7. faceted query
7. faceted query
8. ranked hits
8. ranked hits
9. related and certified
9. related and certified
10. neighbours
10. neighbours
11. boost certified assets
11. boost certified assets
12. results + facets
12. results + facets
13. profile: owner, quality
13. profile: owner, quality
14. log for popularity
14. log for popularity
Search and Discovery — Request Path
Search and Discovery — Request Path
Entitlements are applied before ranking, so a restricted asset never appears in a count, a facet or a total.
Entitlements are applied before ranking, so a restricted asset never appears in a count, a facet or a total.
v 1.0 · owner Platform Engineering · date 2026-08
v 1.0 · owner Platform Engineering · date 2026-08
Text is not SVG - cannot display
Decisions
Entitlements are resolved before ranking, not after. Filtering results afterwards leaks existence through counts, facets and totals.
Certification and quality are ranking signals, not just badges. The trusted asset should win the search, not merely look better once found.
Popularity is logged asynchronously so telemetry can never slow or fail a search.
Targets
Search p95 under 300 ms at 5 million indexed assets.
Faceting on domain, platform, owner, classification, certification and quality band.
Read cache holds hot asset profiles for 15 minutes, which also covers a search-index outage (view 22).
Assumption
Visibility is attribute-based on domain plus sensitivity label. Asset-level access-control lists were rejected as unmanageable at this scale.
◀ Lineage Construction
All views
Stewardship Workflows ▶