Profile API
The single, versioned API surface every internal service and external destination uses to read (never directly query) customer profile data.
High-Level Design
One API surface, so every consumer gets the same governed view of the profile.
💼 Business Context
- Prevents every consuming team from writing its own SQL against the profile table, which would create N different, drifting interpretations of 'the customer'
- Gives Governance & Security a single enforcement point for field-level access instead of N direct-query paths to audit
- Owned by Data Engineering / Platform Engineering
🔌 Technical Overview
The Profile API is a .NET Core service — packaged as a Docker container and deployed on AKS — fronted by Azure API Management, which applies rate limiting, authentication, and request logging consistently with the Ingestion Layer's gateway pattern. It exposes REST and gRPC endpoints backed by the Unified Customer Profile and Identity Graph, enforcing the same RBAC/ABAC and column-masking policies defined in Governance & Security so a caller's permitted fields are consistent whether they call the API from a support tool or an activation service.
Endpoints
💾 Profile API Request
GET /v1/profile/cust_004821 Authorization: Bearer200 OK { "customer_key": "cust_004821", "lifecycle_stage": "active", "ltv_band": "gold" } -- fields the caller is not entitled to are omitted, not nulled
🔗 Integration Points
- Azure API Management — gateway: auth, rate limiting, request logging
- Unified Customer Profile, Identity Graph, Relationships — the underlying data this API serves
- Access Control (RBAC/ABAC) — enforced per request, per field
- Application Insights — per-request tracing and dependency tracking across every call
🧰 Services Consumed
- Owning microservice —
Cxos.Profile.Api(see the Full Application Service Map) - Database — Azure Cosmos DB (Core API + Gremlin API) + Azure Cache for Redis
⚠️ Non-Functional Considerations
- Scale: stateless service scales horizontally on AKS behind API Management; read-heavy traffic is absorbed by the Redis cache layer beneath it
- Latency: p99 under 100ms for single-customer reads; batch endpoint is used for bulk activation exports rather than looping single calls
- Reliability: circuit breakers and retry policies (Polly) protect callers if the underlying PostgreSQL store is under load
- Security/Privacy: every response is entitlement-filtered per caller identity — omitting fields the caller lacks access to, not just masking them
🎯 Enterprise Example
The Real-time Activation service calls the Profile API to check consent and preferred channel before sending a promotional email, and the same API — with different caller entitlements — powers a support agent's console, guaranteeing both see a consistent, correctly-governed view of the customer.