SMS / Push (Twilio, FCM)
Time-sensitive, high-attention channels for delivery updates, security alerts, and in-session re-engagement — used more sparingly than email due to higher intrusiveness.
High-Level Design
SMS/Push follows the same trigger path as email, with stricter consent and frequency rules.
💼 Business Context
- Highest-attention channel for genuinely time-sensitive messages — delivery updates, security alerts, session re-engagement — but overuse burns customer trust faster than any other channel
- Explicit opt-in consent for SMS is typically a distinct legal requirement from general marketing consent
- Owned by Marketing Technology / Platform Engineering
🔌 Technical Overview
The Activation API routes SMS sends through Twilio and mobile push through Firebase Cloud Messaging (FCM), using device tokens and phone numbers stored on the Unified Customer Profile. Because these channels are more intrusive, the same .NET Core service (Docker container on Azure Container Apps) enforces a frequency cap — tracked as workflow state in the Operational Services' Workflow Engine — separately from the channel-level consent check every send already requires.
Channels
💾 SMS/Push Send Record
{
"customer_key": "cust_004821",
"channel": "push",
"provider": "fcm",
"trigger": "session_reengagement",
"frequency_cap_state": "1_of_3_this_week"
}
🔗 Integration Points
- Twilio — SMS delivery provider
- Firebase Cloud Messaging — mobile push delivery provider
- Unified Customer Profile — device tokens, phone numbers, and channel-specific consent
- Workflow Engine (Operational Services) — enforces per-customer frequency caps across sends
🧰 Services Consumed
- Owning microservice —
Cxos.Activation.Api(see the Full Application Service Map) - Database — Azure Cosmos DB (dispatch log) + Azure Cache for Redis (frequency caps)
⚠️ Non-Functional Considerations
- Scale: lower volume than email by design, given frequency capping — sized for bursty but bounded traffic
- Latency: push notifications typically deliver in under 10 seconds; SMS within the 5-minute activation SLA
- Reliability: a failed push falls back to no-op rather than substituting SMS automatically, since channel substitution without consent would itself be a compliance issue
- Security/Privacy: SMS opt-in is tracked as a distinct consent flag from general marketing consent and enforced independently
🎯 Enterprise Example
A flight delay triggers a push notification to the airline app within seconds of the operational system reporting it — the kind of time-sensitive alert email couldn't deliver fast enough to be useful, while the frequency cap prevents the same customer from also being pushed a same-day promotional offer.