← BLACKSWAN OS
Enterprise Architecture · Service Catalogue
Internal Readiness · Simulated
Centre Status

Enterprise Architecture & Service Catalogue Centre

Source of truth for production architecture, services, APIs, environments, dependencies, data flows, ownership, support boundaries, and resilience mapping inside BLACKSWAN Capital Markets OS. Every service carries an accountable owner, a criticality tier, a support contract, and an evidence-pack reference. Conservative posture: internal enterprise architecture readiness workflow only — not security certification, not regulatory approval, not audit opinion.

Services catalogued
17
8 Production Ready · 5 Production Candidate · 3 Staging · 1 Conditional
APIs & integrations
10
6 OIDC-target · 3 webhook · 1 outbound vendor
Environments mapped
7
Local · Staging · Preview · Prod Candidate · Prod · DR · Pilot
Open exceptions
9
Tracked in exception register · architecture board review pending
Service state legend
Draft Designed Build Staging Production Candidate Production Ready Conditional Production Degraded Deprecated Retired Archived
Twelve architecture domains

Enterprise Architecture & Service Catalogue domains

Service Catalogue
17 services catalogued

Every production-bound service catalogued with owner, environment, criticality, dependencies, SLA, support tier, evidence reference.

API Catalogue
10 catalogued · 1 pending owner

Each API/integration recorded with method, data class, auth method, dependency, evidence output. No undocumented surface.

Environment Map
7 environments mapped

Local · Staging · Deployed Preview · Production Candidate · Production · DR/BCP · Sandbox/Pilot. Data class allowed per environment.

Data Flow Map
Linked to Data Governance

Source systems → services → evidence packs → exports → stakeholder rooms → regulator/board bundles, classified at every hop.

Dependency Graph
Critical map current

Upstream/downstream dependency graph for resilience planning, change-impact, vendor concentration, blast-radius analysis.

Ownership / RACI
17/17 services

Accountable · technical · compliance · risk · security · operations · support · escalation contact per service.

Support Boundaries
1 service tier pending

Support tier, hours, incident category, escalation SLA, runbook reference, rollback/recovery path per service.

Criticality & Impact Tolerances
Tiers + RTO/RPO assigned

Tier-1 (critical) → Tier-3 (assistive). RTO / RPO / max outage / impact tolerance per tier.

Integration Inventory
Linked to Vendor Risk

External vendor integrations cross-mapped to Vendor Risk Centre inventory and DPA / SCC posture.

Change / Release Linkage
Wired to Release Control

Every change references services affected, test evidence, approval state, release window, rollback plan, post-release watch.

Resilience Mapping
DR test scheduled 2026-06-12

Critical-path map, dual-region readiness, vendor concentration, DR/BCP runbook, last DR drill, exception list.

Architecture Evidence Pack
Pack assembled

Service catalogue · API catalogue · environment map · data flow · dependency graph · RACI · ADRs · exception register · audit trail.

Service catalogue

Production-bound services · owner · environment · criticality · SLA

Service Owner Environment Criticality Upstream Downstream SLA / SLO Support tier Evidence ref Blocker Next action State
Auth & Access Service Identity Lead · CISO Staging (Entra prod target) Tier-1 Microsoft Entra (target) All centres & APIs 99.95 % · RTO 15m / RPO 0 T1 24×7 EA-EV-SVC-001 Entra tenant cutover pending Complete tenant registration Production Candidate
Evidence Pack Registry Head of Evidence Production Tier-1 Auth · KMS · DB Exports · Rooms · Centres 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-002 None Quarterly dependency review Production Ready
Evidence Export Service Head of Evidence · SRE Lead Production Tier-1 Registry · KMS Regulator binders · Stakeholder Rooms 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-003 None Continue export-integrity SLO watch Production Ready
Stakeholder Rooms Service Head of Stakeholder Rooms Production Tier-1 Auth · Registry · KMS Recipients · audit log 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-004 None Per-room access review on share Production Ready
Data-Room MNPI Access Service CISO · Data Governance Lead Production Tier-1 (restricted) Auth · KMS · Data classification Counterparty DD packs 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-005 MNPI binding scope under privacy review Close privacy review Conditional Production
Command Centre Shell Programme Manager Production Tier-2 Auth · all 14 centres Operators · board view 99.5 % · RTO 1h / RPO 15m T2 business + on-call EA-EV-SVC-006 None None Production Ready
Launch Readiness Service Programme Manager Production Tier-2 Evidence Registry · Approval workflow Go/No-Go board 99.5 % · RTO 1h / RPO 15m T2 EA-EV-SVC-007 None Continue weekly readiness review Production Ready
Approval & Sign-Off Service Programme Manager · CISO Production Tier-1 Auth · Evidence Registry Release Control · Board 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-008 None None Production Ready
Release Control & Rollback Service SRE Lead · Programme Manager Production Tier-1 Approval workflow · Monitoring All production services 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-009 None Quarterly rollback drill Production Ready
Monitoring & Incident Service SRE Lead · CISO Production Tier-1 SIEM · service signals Paging · Reg. Escalation · Board 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-010 None Quarterly IR drill Production Ready
Regulatory Escalation Service Head of Regulatory · External Counsel Production Candidate Tier-1 Monitoring · Evidence Registry Regulator binders · Board paging 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-011 Counsel sign-off on rule pack Lock template · go live Production Candidate
Commercial Onboarding Service Head of Commercial · CFO Production Candidate Tier-2 Auth · KYC partner · CRM Billing · Stakeholder Rooms 99.5 % · RTO 1h / RPO 15m T2 EA-EV-SVC-012 KYC contract sign-off pending Counsel sign-off & go live Production Candidate
Financial Controls Service CFO · External Auditor (pending) Production Candidate Tier-2 Onboarding · Billing Audit binder · Board reporting 99.5 % · RTO 1h / RPO 15m T2 EA-EV-SVC-013 External-auditor validation pending Close auditor review Production Candidate
Data Governance Service Data Governance Lead · CISO Production Tier-1 Auth · KMS · classification engine All data-handling services 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-014 None Quarterly DSR readiness drill Production Ready
Vendor Risk Service Head of Procurement · Risk Committee Staging Tier-3 Vendor inventory · contract metadata Risk committee · Board 99.0 % · RTO 4h / RPO 1h T3 business hours EA-EV-SVC-015 Counsel review of vendor classification Promote to production candidate Staging
Model Governance Service CISO · Head of Regulatory Staging Tier-2 Model inventory · audit log Approval workflow · Board narrative 99.5 % · RTO 1h / RPO 15m T2 EA-EV-SVC-016 Counsel sign-off on rule pack Promote to production candidate Staging
Security Operations Service CISO · SRE Lead Staging (Entra prod target) Tier-1 Auth · SIEM · WAF All centres 99.9 % · RTO 30m / RPO 5m T1 24×7 EA-EV-SVC-017 Entra cutover + DLP test pending Complete cutover & DLP test Staging
API & integration catalogue

Internal APIs · external integrations · auth · data class

API / Integration Method / Type Owner Data class Auth method Status Dependency Evidence output
Auth API REST · POST /api/auth/login · /logout Identity Lead Internal · MFA factors Entra OIDC (target) · staging factors Production Candidate Microsoft Entra Auth event log
Evidence Pack API REST · GET /api/evidence/{pack} Head of Evidence Restricted · MNPI scope tagged OIDC + ABAC Production Ready Auth · Registry · KMS Access ledger event
Export Manifest API REST · POST /api/exports Head of Evidence · SRE Lead Restricted · pack-level DEK OIDC + ABAC Production Ready Pack Registry · KMS Export manifest evidence
Stakeholder Room API REST · POST /api/rooms · GET Head of Stakeholder Rooms Restricted OIDC + room-link signing Production Ready Auth · Registry Room access ledger
Notification API Webhook + Email · POST /api/notify SRE Lead Internal HMAC + OIDC Production Ready Email connector Notification delivery log
GitHub repo integration Webhook · push / PR / release SRE Lead Internal HMAC · short-lived token Production Ready GitHub (vendor) Release manifest
Email / notification connector SMTP + provider API SRE Lead Internal · per-recipient address API key (KMS-stored) Production Ready Email vendor Delivery receipts
Identity provider (Entra OIDC) OIDC · authorisation code + PKCE Identity Lead Authentication only OIDC discovery Production Candidate Microsoft Entra Sign-in log (Entra)
Monitoring / logging endpoint OTel · push to SIEM SRE Lead · CISO Internal (logs) mTLS Production Ready SIEM vendor SIEM index
Billing / payment integration REST + webhook CFO · SRE Lead Internal · PCI-out-of-scope API key + HMAC Production Candidate Payment processor Invoice + audit-flag
Environment map

Seven environments · purpose · data class · auth · restrictions

Environment Purpose Data class allowed Auth posture Restrictions Owner Readiness
Local / Staging Developer iteration · staging readiness rehearsal Internal · synthetic only Staging factors (simulated) No production data · no MNPI · no personal data SRE Lead Staging
Deployed Preview (per PR) Per-PR review & stakeholder walk-through Internal · synthetic only Staging factors · IP allow-list Auto-expire 7 d · no MNPI · no personal data SRE Lead Staging
Production Candidate Pre-cutover validation against production posture Internal + scoped restricted Entra OIDC (target) Counsel + CISO sign-off; restricted-class limited to dry-run Programme Manager · CISO Production Candidate
Production Live operations · regulator-facing All classes per ABAC Entra OIDC enforced Change-control + dual sign-off SRE Lead · CISO · Programme Manager Awaiting Entra cutover
DR / BCP target Active-passive standby · regional failover Same as production · isolated keys Entra OIDC Drill quarterly · RTO 30m / RPO 5m for Tier-1 SRE Lead Designed · drill 2026-06-12
Sandbox / Client Pilot Counterparty pilot · isolated tenant Pilot-scoped data only Entra OIDC + per-tenant scope Counsel review per pilot · no shared data with prod Head of Commercial · CISO Designed
Regulator / Board demo Read-only demonstration for regulator or board Curated synthetic + redacted internal Entra OIDC + observer role Counsel pre-approval · audit-logged · auto-revoke Head of Regulatory · Programme Manager Designed
Data flow & lineage map

Source systems → services → evidence packs → exports → rooms → bundles

Source system Service(s) consuming Data class Downstream evidence pack(s) Downstream artefact(s) Audit event family Retention class
Auth event log Auth Service · Security Ops Service Internal · personal (sign-in metadata) Security Evidence Pack Regulator binder · SIEM index SEC-AUTH-* 7 y
Evidence pack metadata Registry · Export · Rooms · Centres Restricted · MNPI scope tagged 21 evidence packs Exports · Room shares · Board binder EV-* 10 y
Audit log events All centres Internal Architecture · Security · Governance packs Regulator binder · audit binder AUDIT-* 10 y
Stakeholder Room access ledger Rooms Service · Security Ops · Data Governance Personal · MNPI binding Stakeholder Rooms Evidence Pack DSR / privacy review · regulator binder ROOM-* 7 y
Export manifests Export Service · Regulator binders Restricted Evidence Export Pack Regulator response binders EXP-* 10 y
Billing event stream Billing · Financial Controls Internal · audit-track Financial Controls Pack Audit binder · revenue evidence FIN-* 10 y
Incident timeline Monitoring/Incident · Reg. Escalation · Stakeholder Rooms Internal · MNPI on regulator-impact Incident Evidence Pack Regulator notification · board paging INC-* 10 y
Vendor inventory + contracts Vendor Risk · Security Ops · Procurement Internal Vendor Risk Pack Risk committee · board VEN-* 10 y
Model / tool outputs Model Governance · all consuming centres Internal · context-dependent Model Risk Evidence Pack Board narrative · exam binder MR-* 10 y
Dependency graph · critical service map

Cross-centre dependencies for resilience & change impact

Ownership / RACI matrix

Accountable · Technical · Compliance · Risk · Security · Operations · Support

Service Accountable Technical Compliance Risk Security Operations Support contact Escalation path
Auth & Access Service CISO Identity Lead Head of Regulatory Risk Committee CISO SRE Lead secops-oncall@ SRE → CISO → COO
Evidence Pack Registry Head of Evidence SRE Lead Data Governance Lead Risk Committee CISO SRE Lead evidence-oncall@ Evidence → SRE → CISO
Evidence Export Service Head of Evidence SRE Lead Data Governance Lead Risk Committee CISO SRE Lead export-oncall@ Evidence → SRE → CISO
Stakeholder Rooms Service Head of Stakeholder Rooms SRE Lead Data Governance Lead Risk Committee CISO SRE Lead rooms-oncall@ Rooms → CISO → COO
Data-Room MNPI Service CISO Data Governance Lead External Counsel Risk Committee CISO SRE Lead mnpi-oncall@ CISO → External Counsel → Board
Command Centre Shell Programme Manager SRE Lead Head of Regulatory Risk Committee CISO SRE Lead shell-oncall@ Programme → SRE → COO
Launch Readiness Service Programme Manager SRE Lead Head of Regulatory Risk Committee CISO SRE Lead readiness-oncall@ Programme → COO
Approval & Sign-Off Service Programme Manager SRE Lead External Counsel Risk Committee CISO SRE Lead approvals-oncall@ Programme → COO → Board
Release Control Service SRE Lead SRE Lead Head of Regulatory Risk Committee CISO SRE Lead release-oncall@ SRE → CISO → COO
Monitoring & Incident Service SRE Lead SRE Lead Head of Regulatory Risk Committee CISO SRE Lead incident-oncall@ SRE → CISO → CEO
Regulatory Escalation Service Head of Regulatory SRE Lead External Counsel Risk Committee CISO SRE Lead reg-escalation@ Regulatory → Counsel → CEO
Commercial Onboarding Service Head of Commercial SRE Lead External Counsel Risk Committee CISO SRE Lead onboarding-oncall@ Commercial → CFO
Financial Controls Service CFO SRE Lead External Auditor (pending) Risk Committee CISO SRE Lead finance-oncall@ CFO → Board
Data Governance Service Data Governance Lead SRE Lead Head of Regulatory Risk Committee CISO SRE Lead dg-oncall@ DG → CISO → COO
Vendor Risk Service Head of Procurement SRE Lead External Counsel Risk Committee CISO SRE Lead vendor-risk@ Procurement → Risk Committee
Model Governance Service CISO Head of Evidence Head of Regulatory Risk Committee CISO SRE Lead mg-oncall@ CISO → Risk Committee
Security Operations Service CISO SRE Lead Head of Regulatory Risk Committee CISO SRE Lead secops-oncall@ CISO → COO → CEO
Support boundary & runbook

Tier · hours · incident category · escalation SLA · runbook · rollback

Service Support tier Hours / coverage Incident category Escalation SLA Runbook ref Rollback / recovery path Evidence output
Auth · Evidence Registry · Export · Rooms · MNPI · Approval · Release · Monitoring · Reg. Escalation · Data Governance · Security Ops Tier-1 24×7 Sev-1/2/3 Sev-1 page ≤ 5 m · Sev-2 ≤ 15 m RB-T1-MASTER Rollback to last green release; isolate, restore from snapshot, re-issue keys Incident timeline + post-mortem
Shell · Launch Readiness · Commercial · Financial · Model Governance Tier-2 Business hours + on-call Sev-2/3 Sev-2 ≤ 30 m · Sev-3 ≤ 4 h RB-T2-MASTER Feature flag · re-deploy last green · degrade gracefully Incident timeline + change diff
Vendor Risk Service Tier-3 Business hours Sev-3 Sev-3 ≤ 1 business day RB-T3-MASTER Re-deploy last green · revert inventory snapshot Change diff
Incident response (cross-service) Tier-1 24×7 Any severity Per severity RB-IR-MASTER Containment · revocation · regulator-notify trigger · post-mortem Incident binder · regulator notification log
Release rollback Tier-1 24×7 Sev-1 + release window Page ≤ 5 m RB-RC-ROLLBACK Snapshot pin · feature flag · DB migration reverse Release-control evidence
DR / regional failover Tier-1 Drill quarterly · 24×7 invoke Sev-1 regional RTO 30 m RB-DR-FAILOVER Active-passive failover · re-issue keys · re-publish endpoints DR drill report + RTO evidence
Data incident (privacy) Tier-1 24×7 Sev-1/2 data CISO + DG Lead ≤ 30 m RB-DG-INCIDENT Containment · DSR queue · retention hold · regulator notify timeline DSR readiness + regulator notice
Architecture decision records

Decision · context · alternatives · rationale · affected services

ADR ID Decision Context Alternatives Rationale Owner Date Affected services Evidence hash Review cadence
ADR-001 Adopt Microsoft Entra OIDC for production auth Enterprise IdP target; SMCR / FCA alignment In-house auth · third-party IdP · social login Lowest internal risk · best fit for FCA SMCR · widely accepted by counterparties CISO · Identity Lead 2026-02-12 Auth · all consuming services sha256:adr1…ff01 Annual + on auth-API change
ADR-002 Standalone static artifacts per Centre with hardened launcher Mitigate SPA-route hijacking risk; explicit file resolution React-router only · all-server-rendered · standalone artifacts Hardens production paths; .html cannot be hijacked by SPA fallback; per-Centre isolation SRE Lead · Programme Manager 2026-03-05 All 15 Centres sha256:adr2…ff02 Quarterly
ADR-003 Per-pack DEK + KEK rotation for evidence packs Restricted/MNPI evidence requires strong tenancy & key boundary Single key · per-pack DEK · per-event DEK Per-pack DEK balances key-mgmt cost with blast-radius Head of Evidence · CISO 2026-03-22 Evidence Registry · Export · Rooms · MNPI sha256:adr3…ff03 Quarterly
ADR-004 Zero-trust posture (8 pillars) as production baseline Sensitive data + regulator scrutiny + remote operators Perimeter-only · zero-trust · hybrid Zero-trust is the only posture that survives counterparty + regulator scrutiny CISO 2026-04-02 Security Ops · all Tier-1 services sha256:adr4…ff04 Semi-annual
ADR-005 All AI/model outputs require human-in-the-loop review Regulator scrutiny on AI · counsel posture · board paging risk Fully automated · advisory only · always-human-in-loop Eliminates automated regulatory/legal/audit decisioning risk CISO · Head of Regulatory 2026-04-18 Model Governance · Board Narrative · Exam Response sha256:adr5…ff05 Quarterly
ADR-006 Identify dual-source candidates for every Tier-1 vendor dependency UK FCA OpRes / EU DORA concentration scrutiny Single-vendor · dual-source · multi-cloud Dual-source plan is the minimum prudent posture for OpRes Head of Procurement · Risk Committee 2026-04-25 Vendor Risk · Resilience map sha256:adr6…ff06 Quarterly
ADR-007 Evidence export carries explicit limitation footer in every file Counsel review of exported evidence No footer · footer in cover only · footer in every file Per-file footer survives forwarding and out-of-context use Head of Evidence · External Counsel 2026-05-02 Evidence Export · Stakeholder Rooms · Regulator binders sha256:adr7…ff07 Quarterly
ADR-008 Active-passive DR with RTO 30 m / RPO 5 m for Tier-1 UK FCA important business service tolerance Active-active · active-passive · cold-standby Active-passive meets RTO/RPO target at staged cost SRE Lead · CISO 2026-05-09 All Tier-1 services sha256:adr8…ff08 Annual + on RTO/RPO change
Change-control & release linkage

Proposed changes · affected services · test evidence · approval · release window

Change ID Proposed change Affected services Test evidence Approval state Release window Rollback plan Post-release monitoring
CHG-001 Microsoft Entra OIDC cutover (staging → production candidate) Auth Service · all consuming services Integration test report · MFA enforcement test Pending Sign-off 2026-06-08 02:00–05:00 UTC Revert to staging factors · re-issue tokens · disable Entra app Auth SLO · sign-in failure rate · Entra log diff
CHG-002 Revenue recognition classifier validation v0.6.1 Financial Controls · Model Governance 200-event test set · CFO baseline External Auditor Pending 2026-06-15 (window TBC) Lock previous baseline · audit-flag affected events Match-rate watch · auditor-flag exception rate
CHG-003 Enable WAF custom rule pack in shadow → enforce Security Operations · all edge routes Shadow-mode 7d baseline · CISO sign-off Pending CISO Sign-off 2026-05-30 22:00–24:00 UTC Disable custom rule pack · revert to OWASP only WAF custom-rule hit rate · false-positive rate
CHG-004 SIEM DLP egress rule production-test Security Operations · Data Governance Staging egress test · ABAC denies confirmed Pending 2026-05-30 06:00–08:00 UTC Disable rule · revert to monitoring-only mode DLP block rate · false positive rate
CHG-005 Quarterly DR drill (active-passive failover) All Tier-1 services Previous drill report · backup verification Scheduled 2026-06-12 23:00–02:00 UTC n/a (drill); restore from snapshot if regression RTO/RPO actuals · regression report
CHG-006 Reclassify 2 vendors to "material" outsourcing Vendor Risk Service · Regulatory Escalation Counsel review · risk-committee notes Counsel Pending Effective 2026-06-01 Revert classification · notify Risk Committee Vendor inventory diff · Reg. Escalation log
Architecture exception register

Open exceptions · compensating control · target close

Exception Affected artefact / service Severity Owner Compensating control Resolution path Target close State
Undocumented API surface Internal admin debug endpoint Medium SRE Lead Internal-only IP allow-list · MFA Document & review with CISO · or retire endpoint 2026-05-26 In Progress
Missing technical owner Billing webhook receiver Low CFO · SRE Lead SRE on-call covers; alert routes to billing-oncall Name a billing technical lead in RACI 2026-05-22 In Progress
Unsupported environment requested Engineer-owned ad-hoc preview env Low SRE Lead Auto-expire 7 d · synthetic data only Decline non-Preview envs by policy; document in onboarding 2026-05-24 In Progress
Stale dependency on monitoring vendor v1 endpoint Monitoring & Incident Service Low SRE Lead v2 endpoint pinned · v1 fallback only Migrate to v2 only; remove v1 fallback 2026-06-15 In Progress
Data-flow gap — vendor concentration scorer outputs Vendor Risk Service ↔ Resilience map Medium Head of Procurement · SRE Lead Output captured in Vendor Risk Centre pack Add explicit flow into Resilience map 2026-05-30 In Progress
Missing runbook — sandbox pilot tear-down Sandbox / Client Pilot env Low Head of Commercial · SRE Lead Manual tear-down per pilot · checklist Write RB-PILOT-TEARDOWN runbook 2026-05-28 In Progress
Unclear support tier — Vendor Risk Service Vendor Risk Service Low Head of Procurement Defaulted to Tier-3 business hours Confirm Tier-3 with Risk Committee + reflect in service catalogue 2026-05-24 In Progress
Unresolved resilience dependency — email vendor concentration Notification API · Email connector Medium SRE Lead · Head of Procurement Email vendor risk score Medium · contingency to alternate provider Add dual-provider readiness; document failover steps 2026-06-08 In Progress
Production-readiness blocker — Entra cutover dependency chain Auth · Security Ops · Model Governance · Vendor Risk High CISO · Programme Manager Staging factors enforced; dependent services held at staging Complete Entra cutover (CHG-001) and re-promote dependent services 2026-06-15 In Progress
Audit trail & evidence preservation

Audit log of architecture & service-catalogue events

Timestamp (UTC) Actor Artefact / service Action Evidence hash Limitation recorded Next step
2026-05-08 09:30 Programme Manager · SRE Lead Service catalogue EA-CATALOGUE — 17 services published sha256:ea11…aa01 "Internal architecture readiness only." Quarterly catalogue review
2026-05-09 11:05 SRE Lead · Identity Lead API catalogue EA-API — 10 APIs catalogued sha256:ea22…aa02 "Internal." Pending owner closure for billing webhook
2026-05-10 08:40 SRE Lead · CISO Environment map EA-ENV — 7 environments mapped sha256:ea33…aa03 "Internal." Confirm Pilot policy with Head of Commercial
2026-05-11 14:12 Data Governance Lead · Head of Evidence Data flow map EA-DFL — 9 source flows linked sha256:ea44…aa04 "Internal." Close Vendor Risk → Resilience flow gap
2026-05-12 10:22 Programme Manager RACI matrix EA-RACI — 17 services covered sha256:ea55…aa05 "Internal." Name billing technical lead
2026-02-12 17:00 CISO · Identity Lead ADR-001 (Entra OIDC) ADR-001 published sha256:adr1…ff01 "Internal." Annual review
2026-03-05 09:14 SRE Lead · Programme Manager ADR-002 (standalone artifacts) ADR-002 published sha256:adr2…ff02 "Internal." Quarterly review
2026-05-13 16:48 SRE Lead · CISO Resilience mapping EA-RES — DR drill scheduled 2026-06-12 sha256:ea66…aa06 "Internal." Run drill; publish report
2026-05-14 09:05 CISO · Identity Lead CHG-001 (Entra cutover) Change record opened sha256:chg1…bb01 "Internal." Sign-off + run window
2026-05-15 12:42 Architecture Board Exception register EA-EXC-REGISTER — 9 open exceptions logged sha256:ea77…aa07 "Internal readiness only." Weekly review
2026-05-16 08:00 Programme Manager · SRE Lead · CISO Service catalogue attestation EA-ATTESTATION — monthly attestation sha256:ea88…aa08 "Internal; not regulatory approval." Re-attest monthly
Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated architecture data. All service identifiers, owners, SLA targets, evidence hashes, ADR dates, and audit events shown here are seed values for an internal architecture readiness workflow. They are not a live CMDB, not a live service registry, and not a live audit log.
  • Internal enterprise architecture readiness workflow only. This Centre captures BLACKSWAN's internal architecture posture. It is not security certification, not a SOC 2 / ISO 27001 attestation, not a regulator-issued approval, and not an audit opinion.
  • Not legal advice. ADRs and resilience mapping reference jurisdiction expectations (UK FCA, EU DORA, MAS, ADGM) as drafted by internal owners. Submissions to any regulator are reviewed and signed by external counsel and the accountable SMF / senior person.
  • Not authorization for external launch. "Production Ready" state means the internal architecture board considers the service ready for production posture against staging readiness criteria. External-facing deployment, Entra cutover, counsel sign-off, and regulator engagement are separately tracked.
  • Conservative production posture. "Production Candidate" services are explicitly held until their dependency chain (Entra · DLP · counsel sign-off · external auditor) closes. Dependency states are visible in the service catalogue and exception register.