Architecture

MI-Proc Platform Architecture

v1.3 — Updated with full database schemas, module links & complete workflows

B2B Procurement Marketplace
Multi-Tenant Whitelabel
Mi-Wallet Escrow

① CLIENTS

Web App (Buyer)Web App (Supplier)Back-OfficeWhitelabel TenantsMobile (RN)

② EDGE & SECURITY

CDN + WAF (TLS 1.3)API Gateway (JWT → Internal Token)IdP (Keycloak + Nafath)Bot/Fraud DetectionService Mesh (mTLS + SPIFFE)

③ BFF LAYER

Mi-Proc BFF (Web)Whitelabel BFFMobile BFF

④ EVENT BACKBONE (Kafka) + TEMPORAL (SAGA Engine)

Apache Kafka (RF=3, min.insync=2)Temporal Workflow EngineApicurio Schema RegistryDebezium CDC (Outbox relay)

⑤ DOMAIN MICROSERVICES (14 services, 1 DB each)

Identity & AccessOnboarding/KYBTenant ConfigCatalogueRFQQuote/BidNegotiationPurchase RequisitionOrder/FulfilmentLedger (Event-Sourced)EscrowDisputeInvoicing/ZATCARating/Reputation

⑥ SAGA ORCHESTRATORS (6 sagas on Temporal)

Onboarding SAGARFQ-to-Settlement SAGAMilestone-Release SAGADispute-Resolution SAGATenant-Provisioning SAGAWithdrawal/Payout SAGA

⑦ PLATFORM & INTEGRATION SERVICES

Payment Provider Gateway (ACL)Notification (Novu)Socket ServiceAnalyticsAudit/ComplianceAI Matching

⑧ DATABASES & EXTERNAL SYSTEMS

PostgreSQL (1 DB/service)Valkey CacheOpenSearch (Discovery)ClickHouse/PG (OLAP)MoC/Wathiq/Nafath APIZATCA APIBank/PSP (today)MI-EMI Wallet (future/SAMA)

Async by Default

All inter-service via Kafka. Sync only client→BFF & own DB reads.

One DB Per Service

No shared databases. No cross-service joins. Events flow data out.

SAGA Workflows

Durable, versioned, compensatable via Temporal. 6 SAGAs defined.

Tenant Isolation

tenant_id on every aggregate. Repo filters + Specification pattern.