Blueprints

Reference architectures every submitted design is held against — 13 published by the architecture office, 1 derived from designs that were already reviewed. 12 are for Google Cloud; 2 say what good looks like on an estate the group did not choose.

Internal GenAI assistant with retrieval v1.0 was derived from 3 reviewed assistants on 8 Sept 2026The three shared one skeleton and the same three failing OWASP controls. The pattern was kept; the failures were written into the blueprint as requirements instead of copied.
14 of 14 blueprints · cited in 95 reviews to date
14 components · 17 flows
Customer-facing web application on Cloud Runv2.3
Web applicationProvided

Public web application and API on Cloud Run behind one external HTTPS load balancer with Cloud Armor, customer identity from Identity Platform, administration behind Identity-Aware Proxy, and Cloud SQL and Cloud Storage held privately inside a VPC Service Controls perimeter.

10 required controls · cited 14 timesupdated 12 Aug 2026
18 components · 21 flows
Hybrid integration with the on-premises ERPv2.0
API and integrationProvided

Google Cloud workloads reach SAP S/4HANA in Mannheim only by publishing to a Pub/Sub buffer that one dispatcher drains through a single internal load balancer and two Cloud Interconnect attachments with mutual TLS, so an outage at either end delays work instead of losing it.

10 required controls · cited 11 timesupdated 14 Sept 2026
11 components · 14 flows
Internal API behind Apigeev1.7
API and integrationProvided

Partner and internal consumers call Cloud Run services only through Apigee with mutual TLS and OAuth 2.0, while Cloud SQL and Memorystore stay on private IPs inside the API VPC.

8 required controls · cited 9 timesupdated 30 Jun 2026
15 components · 16 flows
Scheduled file-based integrationv1.2
Data pipelineProvided

Registered senders drop files over Private Service Connect into a landing bucket, Cloud Scheduler runs a Cloud Run job that verifies each file against its manifest before loading Cloud SQL and BigQuery, rejected files go to a quarantine bucket and a Pub/Sub dead-letter topic, and a late or malformed file pages the Integration Platform rota.

7 required controls · cited 9 timesupdated 2 Sept 2026
15 components · 16 flows
Public content and media deliveryv1.1
Content deliveryProvided

Product documentation, datasheets and signed firmware are served from a Cloud Storage origin through Cloud CDN behind one external HTTPS load balancer with Cloud Armor, restricted artefacts are reached only through a fifteen-minute signed URL issued by a Cloud Run service, and a Cloud Build pipeline publishes immutable content-hashed objects and invalidates just the paths it changed.

8 required controls · cited 7 timesupdated 27 Aug 2026
14 components · 17 flows
Containerised workload on GKE Autopilotv1.2
ContainersProvided

A private Autopilot cluster published through one external HTTPS load balancer with Cloud Armor, admitting only images the Northwind pipeline signed, with pods federated to their own service accounts and Cloud SQL held on private IP inside a VPC Service Controls perimeter.

10 required controls · cited 6 timesupdated 2 Sept 2026
12 components · 13 flows
Event-driven data pipelinev1.4
Data pipelineProvided

On-premises producers publish to Pub/Sub over Cloud Interconnect, Dataflow validates and enriches the stream into BigQuery and a Cloud Storage archive inside a VPC Service Controls perimeter, and Looker consumers reach the warehouse only through Identity-Aware Proxy.

7 required controls · cited 6 timesupdated 21 Jul 2026
16 components · 17 flows
Customer identity and accessv1.0
IdentityProvided

Identity Platform holds the customer directory with authenticator or passkey enrolment, a Cloud Run service issues and validates tokens behind one external HTTPS load balancer with per-endpoint Cloud Armor rate limits, Firestore holds profiles inside a VPC Service Controls perimeter, and a nightly job carries out deletion, dormancy and token expiry.

10 required controls · cited 5 timesupdated 8 Sept 2026
20 components · 25 flows
Agentic workflow with tool callingv1.2
GenAI assistantProvided

An employee-facing agent on Cloud Run behind Identity-Aware Proxy that plans with Vertex AI function calling but acts only through a tool broker, which is the sole holder of credentials, checks each call against the requester's entitlements, refuses any write without a second person's approval and appends every attempt to a BigQuery action log.

16 required controls · cited 4 timesupdated 11 Sept 2026
8 components · 8 flows
Batch analytics workspacev1.1
Analytics and reportingProvided

Analysts reach Vertex AI Workbench notebooks through Identity-Aware Proxy and query BigQuery and Cloud Storage held inside a VPC Service Controls perimeter with customer-managed keys.

6 required controls · cited 4 timesupdated 2 Jul 2026
14 components · 16 flows
Internal GenAI assistant with retrievalv1.0
GenAI assistantDerivedfrom 3 reviews

Employee-facing assistant on Cloud Run behind Identity-Aware Proxy that answers from enterprise documents through Vertex AI Vector Search with per-user entitlement filtering, screens every prompt and response with Model Armor, and keeps the model, index and conversation store inside a VPC Service Controls perimeter.

17 required controls · cited 3 timesupdated 8 Sept 2026
19 components · 23 flows
Document intake with Document AIv1.0
Document processingProvided

Supplier invoices and warranty claims land in a perimeter-held bucket under customer-managed keys, are extracted by Document AI with the payment-detail fields disabled, and reach the on-premises ERP only after a named reviewer has confirmed every field.

13 required controls · cited 2 timesupdated 11 Sept 2026
15 components · 20 flows
Web application on Azure App Servicev1.4
Web applicationAzureProvided

The shape a web application takes when a named Microsoft dependency puts it on Azure: Application Gateway with the WAF in Prevention mode as the only public address, a zone-redundant App Service with public access disabled and route-all virtual network integration, Entra ID and a user-assigned managed identity instead of connection strings, and Azure SQL Database, Key Vault and Storage reached over Private Link with diagnostic settings shipped to the central workspace.

10 required controls · cited 6 timesupdated 27 Aug 2026
15 components · 21 flows
Acquired workload on AWSv1.1
Acquired estateAWSProvided

What an inherited three-tier AWS workload must be brought to while it waits for its migration date: Route 53, CloudFront and an Application Load Balancer behind AWS WAF with ACM certificates, EC2 and RDS in private subnets with no public addresses, and the group controls laid over the top — an organisation trail to the log archive account, IAM Identity Center federated to Entra ID with no local users, no public S3, and backups held under a separate account's key.

10 required controls · cited 9 timesupdated 2 Sept 2026