Product / Knowledge Base / 11. Solution Architecture (Reference)

11. Solution Architecture (Reference)

User & Administration Guide — Version 1.0.0.4

Guide summary

The following diagrams summarize how Risk & Compliance Hub fits into Microsoft 365. For full technical detail, see docs/Risk-Compliance-Hub-Technical-Architecture.docx in the solution package.

On this page

The following diagrams summarize how Risk & Compliance Hub fits into Microsoft 365. For full technical detail, see docs/Risk-Compliance-Hub-Technical-Architecture.docx in the solution package.

Solution architecture overview
Figure 16 — Solution architecture overview
Deployment targets — SharePoint pages, Teams tabs, and native list forms
Figure 17 — Deployment targets — SharePoint pages, Teams tabs, and native list forms
Application modules: Risk, Compliance, and Administration
Figure 18 — Application modules: Risk, Compliance, and Administration
Platform and technology stack
Figure 19 — Platform and technology stack
Compliance module architecture
Figure 20 — Compliance module architecture
Security, permissions, and licensing boundary
Figure 21 — Security, permissions, and licensing boundary
Component architecture
Figure 22 — Component architecture

Additional App Functionality

Power Automate Companion Architecture

Power Automate flows are optional companion automation. They are not embedded in the SharePoint Framework package. The app stores workflow settings and email templates in SharePoint AppSettings, and customer-managed flows can read those settings to send notifications, overdue alerts, scheduled reports, and workflow-rule messages.

  • Deploy flows separately in the customer tenant when shared mailbox delivery or scheduled automation is required.
  • Keep each flow's Site URL variable aligned with the SharePoint site that hosts the app.
  • Disable app-based Graph email delivery when Power Automate owns the same notification events.

Audit, Security, and Data Boundaries

Operational data is stored in SharePoint lists in the customer tenant. The app audit log records app-level changes for transparency, while Microsoft 365 remains the system of record for tenant-wide identity, permissions, retention, and compliance audit controls.