5. Delivery5.7 Architecture
SOQ System Architecture
Three applications, two shared services, learner journey state machine, and deployment topology.
Logical architecture
Learner journey state machine
Every transition emits a domain event consumed by SWDA hub, notifications, and reporting.
Application responsibilities
| Application | Owns |
|---|---|
| Course Website | Catalogue, public registration UX, applicant auth |
| Admin Workspace | Programmes, runs, admissions, enrolment, CRM ops, finance ops, reporting |
| Student Portal | Learning, schedule, check-in, self-service, payments view |
| Trainer Portal | Roster, delivery, attendance capture, marking, fee claims |
| SWDA Hub | API auth, mapping, submission, retry, reconciliation dashboard |
| Xero Service | Contact/invoice/payment/credit note sync |
Tenancy and roles
Single SOQ tenant with organisation-scoped data (corporate sponsors). RBAC per Section 10.1. Row-level security on student PII and financial records.
Deployment (MVP)
| Requirement |
|---|
| Singapore region hosting |
| Separate worker pool for SWDA submissions (rate limits, idempotency) |
| Integration hub isolated credentials vault |
| Blue/green API deploys; drain active exam/registration sessions before cutover |