Core enterprise products
- Core infrastructure products
- Microsoft 365 and Azure services
- Security and compliance tooling
- Standard laptop and device packages
- Enterprise application licenses
Telops · Group IT · Architecture Overview · 2025
A GitOps-driven ITSM framework that turns IT into a self-service product marketplace: versioned, automated, and built for scale across a multi-subsidiary enterprise.
This deck is the whole system — where everything fits. Zoom in from here: Content covers how we manage catalog content; Product Pilot is the back-office app we are building.
What Service Engineering owns
Service Engineering owns the catalog engine, serves consumers through an API, and keeps operational systems current.
01 · Marketplace model
Group IT operates as a platform, not a single IT department. Multiple providers publish products and business areas shop, subscribe, and manage their own consumption. Service Engineering powers the marketplace infrastructure.
The customer storefront lets users browse and search the product catalog, order products and bundles, manage subscriptions and renewals, view service status and SLAs, and access knowledge base guides in a multi-language, multi-entity experience.
02 · Product catalog and services
The product catalog is the central commercial layer of the marketplace. It defines every orderable IT product, how it is structured, priced, and delivered. Products replace the legacy concept of IT services and become the primary vehicle for self-service consumption.
| Category | Examples | Delivery |
|---|---|---|
| Software and Licenses | Microsoft 365, Adobe CC, Slack, Jira, SAP modules, custom apps | IAM provisioning, license assignment |
| Infrastructure and Cloud | Azure landing zones, resource groups, VPN access, storage quotas | Azure automation, access group |
| Hardware Packages | Laptop bundles, monitor sets, phones, accessories | Intune enrolment, physical dispatch |
| Workspace and Access | Office access badge, lab entry, secure zones, meeting room booking | AD security group, physical access system |
| Bundles and Onboarding | New employee package, contractor starter kit, team productivity bundle | Child product orders, automated fulfilment |
| Support Services | Extended helpdesk SLA, dedicated support tier, VIP response | JSM SLA policy, assignment group |
SKU: M365-BUS-001. Variants include Standard and Power User, with regional license differences. Options include Teams Phone and Copilot. Provisioning SLA is 4h, support is business hours, and ownership sits with Group IT Cloud Team at EUR 18 per user per month.
Defines what people can order. Products are structured as SKUs, variants, and bundles, managed in Back Office, and published to the IT Hub Portal.
Defines request forms, routing rules, SLA policies, and assignment groups behind each product. It is managed in JSM and configured through the GitOps pipeline.
03 · System overview
Core ITSM engine for service requests, incidents, change management, and SLA enforcement. Receives orders from the IT Hub Portal.
Stores products, subscriptions, applications, hardware, locations, and assignment groups. Written by the GitOps pipeline.
IT playbooks, runbooks, incident guides, and internal process documentation for staff-facing use in JSM.
Public help articles and product guides served through APIs to the IT Hub Portal with multi-language support.
Central identity authority for user accounts, groups, SSO, MFA, application access, and physical access links.
MDM/MAM source of truth for endpoint hardware, assigned users, installed apps, and compliance state.
Hosts CI/CD pipeline runners and tracks Azure landing zones and resource groups as infrastructure records.
Enterprise application inventory with owners, metadata, business-area usage, and links into the product catalog.
SLA compliance, ticket volumes, subscription counts, hardware utilisation, and service health from JSM, CMDB, and Intune.
Alerting, on-call coverage, and maintenance windows. Powers the public status page automatically.
Version control for ITSM configuration, product definitions, SLA rules, and routing configuration.
Customer-facing self-service storefront for catalog browsing, ordering, App Store, knowledge base, and service status.
Product management UI for IT staff and product owners. Edits products, SLAs, pricing, coverage, KB links, translations, and monitoring.
04 · Architecture diagram
A layered platform behind a service marketplace. The app layer captures intent, the platform layer turns configuration and content into governed releases, those releases land in systems of record, and everything feeds insight and billing.
A marketplace for IT and business services: employees order, vendors fulfil, and Group IT provides the platform, tooling, tracking, and support model.
Axpo Hub is the marketplace storefront. Back Office maintains catalog, content, SLAs, ops rules, and LeanIX imports. JSM Portal supports IT staff fulfilment, tickets, requests, and support handling.
Serves catalog and content, receives updates, versions product and SLA definitions in Git, validates changes, deploys with environments, and layers better data and automation over JSM and JSM Ops.
CMDB stores products, subscriptions, hardware, and locations. JSM handles requests, tickets, fulfilment, and support. Confluence stores content and knowledge pages. Intune remains the device source of truth.
Shared analytics and finance reporting track pricing, usage, service metrics, support signals, and billing.
05 · Data model
Jira Assets is divided into six configuration domains. Pipeline-managed domains are written exclusively by the GitOps pipeline. Direct JSM edits to those records are overwritten on the next run.
| Domain | Description | Key attributes | Source of truth |
|---|---|---|---|
| Products | Primary catalog entity. What customers order. Supports groups, variants, and options. | SKU, variant, option, owner, SLA, price, description, coverage, group | Back Office to GitHub to Pipeline |
| Subscriptions | Maps users and business areas to products. Activation triggers IAM provisioning. | User, product ref, terms, expiry, status, IAM group ref | JSM Requests and IAM sync |
| Applications | Software application records behind products, versioned with checkpoints and linked to LeanIX. | App name, version, checkpoints, LeanIX link, Back Office link, owner | LeanIX import and Back Office |
| Hardware | Physical and virtual assets. Intune is source of truth for endpoint device records. | Category, asset tag, location, assignee, landing zone, Intune ID, compliance | Intune sync, Azure, manual infra |
| Locations | Offices, rooms, and IT-relevant spaces for routing and physical access correlation. | Site, floor, room, region, access group | Manual |
| Assignment Groups | Groups of IT staff responsible for incidents and request types. | Group name, members, scope, escalation path, coverage hours | Back Office to Pipeline |
06 · Identity and access
Azure AD / Entra ID is not just authentication. It links subscriptions, hardware configurations, physical access, and entitlements across the IT estate.
Subscription activation in CMDB triggers Azure AD changes such as application access group membership or license assignment. Expiry and cancellation remove access automatically.
Hardware records are enriched by Intune device model, serial, OS, installed apps, compliance, and assigned user data.
Physical access rights are managed as Azure AD security groups and surfaced in CMDB alongside logical subscriptions.
A new employee bundle coordinates Azure AD account creation, Intune device enrolment, subscription activation, license assignment, and physical access provisioning.
07 · GitOps pipeline and environments
Sandbox JSM, IT Hub Portal, Back Office, CMDB, and Confluence support ITSM change review, QA, and integration testing before promotion.
Production JSM, IT Hub Portal, Back Office, CMDB, and public status page are maintained through the approved GitOps pipeline.
08 · Technical standards
Defined technology standards for the Back Office application, pipeline, and SEP API layer reflect team competencies, enterprise tooling availability, and long-term maintainability goals.
09 · Interface roles
Each interface serves a distinct audience and data surface. The Back Office API decouples the IT Hub Portal from JSM so the portal team can evolve independently.
Browse products, place orders, manage subscriptions, access the App Store, read translated customer KB articles, and view service status.
Manage customer-facing descriptions, pricing, SLA settings, coverage, translations, KB links, monitoring, and GitOps-triggered changes. Imports from LeanIX.
Reads CMDB for routing, SLAs, and assignment groups while handling incidents, change workflows, request fulfilment, and internal KB surfacing.
10 · Automation and AI
Automation and AI are embedded across the platform, from fulfilment orchestration to intelligent triage, reducing manual effort while improving service quality and consistency.
Provision subscriptions, route bundle sub-orders, and update CMDB on completion.
Suggest assignment group, SLA tier, and related KB articles before work reaches an agent.
Resolved incidents can be summarised into draft KB articles, and stale articles can be flagged.
Bundle orders coordinate JSM, Azure AD, Intune, and CMDB for a faster onboarding process.
JSM Ops monitors services, maintenance windows, broadcasts, on-call rosters, and assignment groups.
Aggregated service data can flag ticket spikes, SLA breach trajectories, and subscription or hardware mismatches.
11 · Transition roadmap
IT services managed ad hoc. CMDB edited manually in Jira Assets. IT Hub Portal tightly coupled to JSM. Translations per application. Status page maintained manually. Intune not linked to CMDB. Identity provisioning largely manual. Onboarding requires around 15 service requests. No config versioning or environments. Single provider: Group IT.
Multi-provider self-service marketplace. All ITSM config in Git as YAML or JSON. Back Office enables provider self-management. IT Hub Portal decoupled via SEP API. Bundle-based onboarding with automated fulfilment and IAM provisioning. Intune synced to CMDB. Status page auto-maintained. Centralised translations. Staging and production environments. AI-assisted triage. Full config rollback.
Owns the Back Office application, SEP API layer, CMDB schema, GitOps pipeline, ITSM automation framework, identity integration patterns, Intune to CMDB sync, and marketplace infrastructure. The IT Hub Portal customer UI is maintained by the Applications group as a consumer of SEP APIs.