Regulated banking · In production
Document
Archiving
A REST API for regulated document archiving, designed and built under NF461 constraints.
Delivered at Euro-Information for Crédit Mutuel Group, within a banking ecosystem serving around nine million customers.
Employer system · Schematics redrawn, paths illustrative
- Client
- Euro-Information · Crédit Mutuel Group
- Surface
- REST API · deposit and retrieval
- Standard
- NF461 · electronic archiving
- Stack
- C# · ASP.NET Core · SQL Server
Built within a 9M-customer banking ecosystem.
9,000,000Customer base of the banking group
Electronic archiving in regulated banking has to satisfy NF461 conformity while remaining consumable by the applications around it. Those two constraints decided the shape of the API.
From constraint to contract.
- 01Conformity
- The standard was analysed before the API was designed, so conformity shaped the contract rather than being checked against it afterwards.
- 02Integration
- Applications across the group archive through one REST service, so each consumer integrates against a documented contract rather than directly against the archive.
- 03Non-alteration
- The published API surface focused on deposit and retrieval rather than general CRUD operations.
The path a document takes.
DepositRetrieval reverses it
- Consuming applicationsGroup systems
- Archiving REST APINF461 constraints
- Electronic archiveUnder NF461 constraints
- One entry point
- Consuming applications access the archive through the REST contract, and what the standard constrains stays behind it.
- One contract to hold
- The consumers are other teams' applications. A stable contract matters when multiple applications integrate through the same service.
What I owned.
I designed the API surface and built it. Certification, infrastructure and the applications calling it were other people's work.
- Design
- API contract · endpoints · error semantics
- Build
- C# · ASP.NET Core · SQL Server
- Constraint
- NF461 requirements translated into application behaviour
- Outside my scope
- Certification · infrastructure · consuming applications
Walk me through it.
Employer system, so the repository and the data stay closed. The design decisions don't — ask and I'll take you through them.