Intelligence & Services → Identity & Profile Service

Profile API

The single, versioned API surface every internal service and external destination uses to read (never directly query) customer profile data.

High-Level Design

One API surface, so every consumer gets the same governed view of the profile.

Data Source
Data Sources
Every touchpoint and business system
→
Ingestion
Ingestion Layer
SDKs, connectors, protocols
→
Processing
Transformation & Processing
Populates the profile the API serves
→
Foundation
Unified Data Foundation
Governance & Security enforces field-level access
→
Intelligence
Profile API
.NET Core Analytics/AI API behind Azure API Management
→
Activation
Every Consumer
Support tools, activation destinations, other microservices

💼 Business Context

  • Prevents every consuming team from writing its own SQL against the profile table, which would create N different, drifting interpretations of 'the customer'
  • Gives Governance & Security a single enforcement point for field-level access instead of N direct-query paths to audit
  • Owned by Data Engineering / Platform Engineering

🔌 Technical Overview

The Profile API is a .NET Core service — packaged as a Docker container and deployed on AKS — fronted by Azure API Management, which applies rate limiting, authentication, and request logging consistently with the Ingestion Layer's gateway pattern. It exposes REST and gRPC endpoints backed by the Unified Customer Profile and Identity Graph, enforcing the same RBAC/ABAC and column-masking policies defined in Governance & Security so a caller's permitted fields are consistent whether they call the API from a support tool or an activation service.

Endpoints

GET /profile/{customer_key} GET /identity/resolve GET /relationships/{customer_key} POST /profile/batch

💾 Profile API Request

GET /v1/profile/cust_004821
Authorization: Bearer 

200 OK
{ "customer_key": "cust_004821", "lifecycle_stage": "active", "ltv_band": "gold" }
-- fields the caller is not entitled to are omitted, not nulled

🔗 Integration Points

  • Azure API Management — gateway: auth, rate limiting, request logging
  • Unified Customer Profile, Identity Graph, Relationships — the underlying data this API serves
  • Access Control (RBAC/ABAC) — enforced per request, per field
  • Application Insights — per-request tracing and dependency tracking across every call

🧰 Services Consumed

  • Owning microservice — Cxos.Profile.Api (see the Full Application Service Map)
  • Database — Azure Cosmos DB (Core API + Gremlin API) + Azure Cache for Redis

⚠️ Non-Functional Considerations

  • Scale: stateless service scales horizontally on AKS behind API Management; read-heavy traffic is absorbed by the Redis cache layer beneath it
  • Latency: p99 under 100ms for single-customer reads; batch endpoint is used for bulk activation exports rather than looping single calls
  • Reliability: circuit breakers and retry policies (Polly) protect callers if the underlying PostgreSQL store is under load
  • Security/Privacy: every response is entitlement-filtered per caller identity — omitting fields the caller lacks access to, not just masking them

🎯 Enterprise Example

The Real-time Activation service calls the Profile API to check consent and preferred channel before sending a promotional email, and the same API — with different caller entitlements — powers a support agent's console, guaranteeing both see a consistent, correctly-governed view of the customer.

← Back to Identity & Profile Service