Service Engineering Platform

Telops · Group IT · Architecture Overview · 2025

Service Engineering Platform

A GitOps-driven ITSM framework that turns IT into a self-service product marketplace: versioned, automated, and built for scale across a multi-subsidiary enterprise.

This deck is the whole system — where everything fits. Zoom in from here: Content covers how we manage catalog content; Product Pilot is the back-office app we are building.

What Service Engineering owns

Service Engineering owns the catalog engine, serves consumers through an API, and keeps operational systems current.

01 · Marketplace model

IT as a Self-Service Marketplace

Group IT operates as a platform, not a single IT department. Multiple providers publish products and business areas shop, subscribe, and manage their own consumption. Service Engineering powers the marketplace infrastructure.

Group IT

Core enterprise products

  • Core infrastructure products
  • Microsoft 365 and Azure services
  • Security and compliance tooling
  • Standard laptop and device packages
  • Enterprise application licenses
Business Area IT Depts

Subsidiary-specific services

  • Subsidiary-specific apps and tools
  • Local hardware bundles
  • Business-area software licenses
  • Specialised access packages
Group Shared Services

Cross-group offerings

  • Finance and ERP system access
  • HR platform subscriptions
  • Shared infrastructure services
  • Cross-group integrations
The marketplace platform

IT Hub Portal and SEP platform services

The customer storefront lets users browse and search the product catalog, order products and bundles, manage subscriptions and renewals, view service status and SLAs, and access knowledge base guides in a multi-language, multi-entity experience.

Billing and chargebacks Audit and compliance SLA enforcement Fulfilment automation Translations i18n Change control
Consumers

Who buys and manages consumption

  • Employees order products, apps, access, hardware, and subscriptions.
  • IT managers and approvers approve team orders and review usage and costs.
  • Product owners publish products, manage SLAs and pricing, monitor service health, and keep knowledge content current.
Platform role of Service Engineering: We do not just offer products. We build and operate the marketplace infrastructure: Back Office tooling for providers, the release pipeline, APIs for the storefront, and the billing, audit, SLA, and fulfilment machinery the marketplace depends on.

02 · Product catalog and services

The IT Product Catalog

The product catalog is the central commercial layer of the marketplace. It defines every orderable IT product, how it is structured, priced, and delivered. Products replace the legacy concept of IT services and become the primary vehicle for self-service consumption.

CategoryExamplesDelivery
Software and LicensesMicrosoft 365, Adobe CC, Slack, Jira, SAP modules, custom appsIAM provisioning, license assignment
Infrastructure and CloudAzure landing zones, resource groups, VPN access, storage quotasAzure automation, access group
Hardware PackagesLaptop bundles, monitor sets, phones, accessoriesIntune enrolment, physical dispatch
Workspace and AccessOffice access badge, lab entry, secure zones, meeting room bookingAD security group, physical access system
Bundles and OnboardingNew employee package, contractor starter kit, team productivity bundleChild product orders, automated fulfilment
Support ServicesExtended helpdesk SLA, dedicated support tier, VIP responseJSM SLA policy, assignment group
Product anatomy

Microsoft 365 Business

SKU: M365-BUS-001. Variants include Standard and Power User, with regional license differences. Options include Teams Phone and Copilot. Provisioning SLA is 4h, support is business hours, and ownership sits with Group IT Cloud Team at EUR 18 per user per month.

Customer KB linkedInternal KB linkedIAM: Entra group M365-BUSLeanIX: APP-0042
Product catalog

Customer-facing commerce layer

Defines what people can order. Products are structured as SKUs, variants, and bundles, managed in Back Office, and published to the IT Hub Portal.

Service catalog

ITSM fulfilment machinery

Defines request forms, routing rules, SLA policies, and assignment groups behind each product. It is managed in JSM and configured through the GitOps pipeline.

Self-service principle: The catalog is not just a list. Customers discover, configure, order, track, and renew through the IT Hub Portal without opening a JSM ticket directly. The product definition drives the full journey from storefront to fulfilment.

03 · System overview

Ecosystem Components

ITSM Core · Atlassian

JSM

Jira Service Management

Core ITSM engine for service requests, incidents, change management, and SLA enforcement. Receives orders from the IT Hub Portal.

Jira Assets

CMDB

Stores products, subscriptions, applications, hardware, locations, and assignment groups. Written by the GitOps pipeline.

Staff KB

Confluence Internal KB

IT playbooks, runbooks, incident guides, and internal process documentation for staff-facing use in JSM.

Customer KB

Confluence Customer KB

Public help articles and product guides served through APIs to the IT Hub Portal with multi-language support.

Identity, Access and Device Management · Microsoft

IAM

Azure AD / Entra ID

Central identity authority for user accounts, groups, SSO, MFA, application access, and physical access links.

Device SoT

Microsoft Intune

MDM/MAM source of truth for endpoint hardware, assigned users, installed apps, and compliance state.

Microsoft

Azure

Hosts CI/CD pipeline runners and tracks Azure landing zones and resource groups as infrastructure records.

Enterprise Catalog, Data and Monitoring

Enterprise architecture

LeanIX

Enterprise application inventory with owners, metadata, business-area usage, and links into the product catalog.

Analytics

IT Service Data and Metrics

SLA compliance, ticket volumes, subscription counts, hardware utilisation, and service health from JSM, CMDB, and Intune.

Monitoring

JSM Ops

Alerting, on-call coverage, and maintenance windows. Powers the public status page automatically.

Config SoT

GitHub

Version control for ITSM configuration, product definitions, SLA rules, and routing configuration.

Customer and Operator Interfaces

Applications Team

IT Hub Portal

Customer-facing self-service storefront for catalog browsing, ordering, App Store, knowledge base, and service status.

In Development

Back Office (SEP)

Product management UI for IT staff and product owners. Edits products, SLAs, pricing, coverage, KB links, translations, and monitoring.

04 · Architecture diagram

System Architecture

A layered platform behind a service marketplace. The app layer captures intent, the platform layer turns configuration and content into governed releases, those releases land in systems of record, and everything feeds insight and billing.

OrderFulfilmentSupportBilling

A marketplace for IT and business services: employees order, vendors fulfil, and Group IT provides the platform, tooling, tracking, and support model.

App layer · UI and workflows

Axpo Hub, Back Office, and JSM Portal

Axpo Hub is the marketplace storefront. Back Office maintains catalog, content, SLAs, ops rules, and LeanIX imports. JSM Portal supports IT staff fulfilment, tickets, requests, and support handling.

Platform layer · Service Engineering

SEP API, Config as Code, Translation Service, Approval Service, GitOps Pipeline, Ops and Metrics

Serves catalog and content, receives updates, versions product and SLA definitions in Git, validates changes, deploys with environments, and layers better data and automation over JSM and JSM Ops.

Data layer · Systems of record

CMDB, JSM, Confluence, and Intune

CMDB stores products, subscriptions, hardware, and locations. JSM handles requests, tickets, fulfilment, and support. Confluence stores content and knowledge pages. Intune remains the device source of truth.

Insight and commercial

Databricks and ITFM Finance Portal

Shared analytics and finance reporting track pricing, usage, service metrics, support signals, and billing.

05 · Data model

CMDB · Configuration Domains

Jira Assets is divided into six configuration domains. Pipeline-managed domains are written exclusively by the GitOps pipeline. Direct JSM edits to those records are overwritten on the next run.

DomainDescriptionKey attributesSource of truth
ProductsPrimary catalog entity. What customers order. Supports groups, variants, and options.SKU, variant, option, owner, SLA, price, description, coverage, groupBack Office to GitHub to Pipeline
SubscriptionsMaps users and business areas to products. Activation triggers IAM provisioning.User, product ref, terms, expiry, status, IAM group refJSM Requests and IAM sync
ApplicationsSoftware application records behind products, versioned with checkpoints and linked to LeanIX.App name, version, checkpoints, LeanIX link, Back Office link, ownerLeanIX import and Back Office
HardwarePhysical and virtual assets. Intune is source of truth for endpoint device records.Category, asset tag, location, assignee, landing zone, Intune ID, complianceIntune sync, Azure, manual infra
LocationsOffices, rooms, and IT-relevant spaces for routing and physical access correlation.Site, floor, room, region, access groupManual
Assignment GroupsGroups of IT staff responsible for incidents and request types.Group name, members, scope, escalation path, coverage hoursBack Office to Pipeline

06 · Identity and access

Users and Identity as a Platform Layer

Azure AD / Entra ID is not just authentication. It links subscriptions, hardware configurations, physical access, and entitlements across the IT estate.

Subscriptions to IAM

Entitlement provisioning

Subscription activation in CMDB triggers Azure AD changes such as application access group membership or license assignment. Expiry and cancellation remove access automatically.

Hardware to IAM and Intune

Device and configuration profiles

Hardware records are enriched by Intune device model, serial, OS, installed apps, compliance, and assigned user data.

Physical access to IAM

Badges and door access

Physical access rights are managed as Azure AD security groups and surfaced in CMDB alongside logical subscriptions.

Identity as onboarding orchestrator

Day-1 automation

A new employee bundle coordinates Azure AD account creation, Intune device enrolment, subscription activation, license assignment, and physical access provisioning.

Design principle: Entra ID is the single source of user identity truth. SEP reads from and writes to AD. It does not maintain a parallel user directory.

07 · GitOps pipeline and environments

Configuration as Code and Environment Model

GitOps Pipeline

  1. Edit in Back Office: product owners or IT managers modify products, SLAs, or routing rules and initiate an ITSM change process.
  2. Commit to GitHub: Back Office serialises changes to YAML or JSON on a branch.
  3. CI/CD Pipeline: GitHub Actions triggers Azure runners for schema validation, linting, policy checks, and staging deployment.
  4. Staging Review and Approval Gate: reviewers test the change in sandbox JSM, portal, Back Office, CMDB, and Confluence.
  5. Write to Production CMDB: the CMDB Writer applies compiled, versioned configuration to Jira Assets.
  6. Rollback: any configuration state can be restored by reverting a Git commit and re-running the pipeline.

Environment Model

Staging environment

Mirrors production

Sandbox JSM, IT Hub Portal, Back Office, CMDB, and Confluence support ITSM change review, QA, and integration testing before promotion.

Production environment

Live customer-facing environment

Production JSM, IT Hub Portal, Back Office, CMDB, and public status page are maintained through the approved GitOps pipeline.

Contract: The GitOps pipeline is the only mechanism that writes to pipeline-managed CMDB records in production. Operational incident and request work in JSM is unaffected.

08 · Technical standards

Platform Tech Standards

Defined technology standards for the Back Office application, pipeline, and SEP API layer reflect team competencies, enterprise tooling availability, and long-term maintainability goals.

Back Office application

Frontend, backend, auth, hosting

ReactTypeScriptTailwind CSSshadcn/uiPythonDjango / DRFPostgreSQLRedisAzure AD SSOOAuth 2.0 / OIDCREST + OpenAPIAzure App ServiceDocker / AKS
GitOps pipeline

Source control, config, CI/CD, writer

GitHubBranch protectionPR reviewsYAMLJSONJSON Schema validationGitHub ActionsAzure-hosted runnersLinting + policy gatesPython scriptJira Assets APIIdempotent writes
Integrations and APIs

Atlassian, Microsoft, enterprise, AI

JSM REST APIAssets APIConfluence REST APIAtlassian i18nMicrosoft Graph APIIntune MDM APIAzure AD SDKLeanIX REST APIWebhooksOpenAI / Azure OpenAIJSM Automation rules
Standard rationale: Python + Django aligns with the IT Hub Portal stack, enabling shared libraries and patterns. React + TypeScript supports a modern Back Office UI. GitHub Actions with Azure runners keeps delivery inside the Microsoft and GitHub ecosystem.

09 · Interface roles

Three Views, One Platform

Each interface serves a distinct audience and data surface. The Back Office API decouples the IT Hub Portal from JSM so the portal team can evolve independently.

IT Hub Portal

Customer self-service storefront

Browse products, place orders, manage subscriptions, access the App Store, read translated customer KB articles, and view service status.

Back Office (SEP)

Provider self-management

Manage customer-facing descriptions, pricing, SLA settings, coverage, translations, KB links, monitoring, and GitOps-triggered changes. Imports from LeanIX.

JSM Portal

IT service staff tooling

Reads CMDB for routing, SLAs, and assignment groups while handling incidents, change workflows, request fulfilment, and internal KB surfacing.

Decoupling principle: The SEP Back Office API becomes the integration point. The portal calls Back Office APIs while Back Office manages JSM and CMDB.
Knowledge base: Internal KB surfaces in JSM Portal for staff. Customer KB surfaces in IT Hub Portal through Confluence APIs. Both are linked per product in Back Office.

10 · Automation and AI

Automation and AI Layer

Automation and AI are embedded across the platform, from fulfilment orchestration to intelligent triage, reducing manual effort while improving service quality and consistency.

Fulfilment automation

JSM Automation rules

Provision subscriptions, route bundle sub-orders, and update CMDB on completion.

AI-assisted triage

Classification and routing

Suggest assignment group, SLA tier, and related KB articles before work reaches an agent.

AI summarisation

KB generation

Resolved incidents can be summarised into draft KB articles, and stale articles can be flagged.

Onboarding orchestration

Cross-system Day 1 flow

Bundle orders coordinate JSM, Azure AD, Intune, and CMDB for a faster onboarding process.

Proactive alerting

Maintenance and status

JSM Ops monitors services, maintenance windows, broadcasts, on-call rosters, and assignment groups.

Reporting

Anomaly detection

Aggregated service data can flag ticket spikes, SLA breach trajectories, and subscription or hardware mismatches.

Automation principle: The GitOps pipeline is the primary automation mechanism for configuration. Operational automation and AI triage layer on top of a correctly configured foundation.

11 · Transition roadmap

Today to Target State

Current state

Manual and tightly coupled

IT services managed ad hoc. CMDB edited manually in Jira Assets. IT Hub Portal tightly coupled to JSM. Translations per application. Status page maintained manually. Intune not linked to CMDB. Identity provisioning largely manual. Onboarding requires around 15 service requests. No config versioning or environments. Single provider: Group IT.

Manual CMDB editsJSM tight couplingNo config versioningManual onboardingManual status pageIntune not linkedSingle provider
Target state

Multi-provider and self-service

Multi-provider self-service marketplace. All ITSM config in Git as YAML or JSON. Back Office enables provider self-management. IT Hub Portal decoupled via SEP API. Bundle-based onboarding with automated fulfilment and IAM provisioning. Intune synced to CMDB. Status page auto-maintained. Centralised translations. Staging and production environments. AI-assisted triage. Full config rollback.

Multi-providerSelf-service catalogGitOps configAPI decouplingBundle automationAuto status pageCentralised i18nLeanIX linkedIntune syncIAM orchestrationAI triageStaging env
Gradual transition: SEP is introduced incrementally alongside existing processes. The IT Hub Portal migrates from JSM direct calls to SEP APIs domain by domain. The GitOps pipeline expands one CMDB domain at a time. Intune sync is introduced alongside existing hardware records. Multi-provider capability unlocks as Back Office matures.
Service Engineering Team Scope

Owns the Back Office application, SEP API layer, CMDB schema, GitOps pipeline, ITSM automation framework, identity integration patterns, Intune to CMDB sync, and marketplace infrastructure. The IT Hub Portal customer UI is maintained by the Applications group as a consumer of SEP APIs.

Back Office AppSEP API LayerGitOps Pipeline + EnvironmentsCMDB Schema and AutomationIdentity Integration PatternsMarketplace Infrastructure