Symptoms:

  • Diagrams list servers, IPs, and VNets, but no actionable steps for Azure RBAC, PIM, or Entra group creation.
  • The access-setup team can’t translate static topology into identity and role assignments.
  • Design deliverables stop at infrastructure layers, leaving identity, security, and automation implicit.

๐Ÿงฉ The Missing Bridge: Implementation Mapping  (WHAT → HOW)

DEFINITION: What’s really missing: A translational layer between the “physical design” (WHAT) and the “implementation procedure” (HOW).

 

What’s really missing: The Missing Link: bridging the WHAT and the HOW since time immemorial (or at least since the last design review). The quest: Somewhere between the "physical design" (WHAT) and the "implementation procedure" (HOW) lies a semi-mythical construct known to project managers as "the missing spec". It speaks all languages, but none fluently.

Static Topology 2 Dynamic Procedure

The WSxx structure runs cleanly from governance to go-live and beyond. 

WS01–WS05 are about making sure the ground is solid;

WS06–WS09 are where the data and reporting magic happens;

WS10–WS12 are delivery, testing, and handover. 

The Implementation Translation Layer (ITL) sits in WS01 — bridging the “what” of design and the “how” of implementation so no one is left guessing.

Programme Work Streams (WS00โ€“WS12)

Script-free accordion: opening one WS closes the others. WS00 starts open.

DescriptionSets the programme up properly โ€” ownership, cadence, RAID, reporting, and a common language across teams.
Key DeliverablesPID โ€ข Governance Framework โ€ข RAID Log โ€ข RACI Matrix โ€ข Delivery Calendar
Candidate Roles & Skills Programme Manager โ€” planning, steering, risk PMO Lead โ€” cadence, reporting, tooling Change Analyst โ€” comms, impact mapping
Student HookLike organising a huge school project so everyone knows their job and no one forgets homework.
ScenarioBefore any migration, PMO sets up templates, channels, and weekly stand-ups so every WS works the same way.
DescriptionBuilds the Azure foundations โ€” environments, permissions, Entra groups, certs, connectivity. Produces the Implementation Translation Layer (ITL).
Key DeliverablesEnvironment Build Checklist โ€ข ITL (WHATโ†’HOW) โ€ข Access Matrix โ€ข Certificate Register
Candidate Roles & Skills Solution Architect โ€” landing zones, standards Azure Engineer โ€” RBAC, subscriptions, policy IDAM Specialist โ€” Entra, PIM, Conditional Access
Student HookMaking sure everyoneโ€™s got the right keys to the right rooms โ€” not everyone gets the master key.
ScenarioDev/SIT/UAT built with group-based access; ITL says exactly how to request, approve, and assign roles.
DescriptionConnectivity between tenants, routing, DNS, ExpressRoute, private endpoints, and firewalls.
Key DeliverablesNetwork Design Pack โ€ข Firewall & Routing Config โ€ข Connectivity Test Plan
Candidate Roles & Skills Network Engineer โ€” IP, subnets, BGP Security Engineer โ€” firewall rules, IDS Infra Architect โ€” topology, resilience
Student HookWiring up all the computers so messages know where to go.
ScenarioFirewall rules allow Dynamics (Serco) to reach SQL pool (Capita) for controlled test loads.
DescriptionTarget apps (Dynamics, SharePoint, Power Platform) are patched, licensed, configured, and ready to integrate.
Key DeliverablesApplication Readiness Report โ€ข Endpoint Register โ€ข Integration Access Plan
Candidate Roles & Skills App Owner โ€” configs, licensing Technical Lead โ€” plugins, connectors Release Manager โ€” gates, approvals
Student HookMaking sure the toys work before the game starts.
ScenarioPower Platform connectors validated; known plug-ins smoke-tested in UAT.
DescriptionDefines secure data exchange โ€” APIs, Logic Apps, KingswaySoft pipelines โ€” with CI/CD and secrets.
Key DeliverablesIntegration Design Document โ€ข API Catalogue โ€ข Connection & Secret Register
Candidate Roles & Skills Integration Architect โ€” patterns, contracts API Developer โ€” REST, OAuth2 DevOps Engineer โ€” pipelines, IaC
Student HookBuilding pipes that let different machines talk without shouting.
ScenarioLogic App posts nightly updates from Dynamics to Synapse; secrets stored in Key Vault.
DescriptionEnforces BBC InfoSec and UK GDPR: Entra, Conditional Access, PIM, audit, key rotations.
Key DeliverablesSecurity Architecture โ€ข IDAM Build Book โ€ข Compliance Statement โ€ข RBAC Mapping
Candidate Roles & Skills Security Architect โ€” policy, controls Compliance Officer โ€” GDPR, DPIA IDAM Engineer โ€” PIM, CA, audits
Student HookSetting the rules so no one sneaks into the sweet shop.
ScenarioMFA required for admins; PIM used for just-in-time elevation; logs sent to SIEM.
DescriptionMoves data cleanly and provably: extract, transform, load, reconcile, evidence.
Key DeliverablesData Migration Strategy โ€ข Entity Mapping โ€ข Reconciliation Logs โ€ข Migration Runbook
Candidate Roles & Skills Data Architect โ€” design, lineage ETL Developer โ€” SSIS, Python, SQL Test Analyst โ€” data QA, counts
Student HookLike moving toys from one box to another without losing any pieces.
ScenarioLegacy SQL โ†’ staging โ†’ Dataverse; counts checked at each hop; exceptions logged and fixed.
DescriptionMasks/pseudonymises production data for safe non-prod testing while keeping realism.
Key DeliverablesConcealment Rules Catalogue โ€ข Algorithm Register โ€ข KingswaySoft Pipeline Spec
Candidate Roles & Skills Data Engineer โ€” hashing, tokenisation Data Privacy Officer โ€” policy, risk Security Architect โ€” key mgmt, KMS
Student HookChanging real names into made-up ones so testers can play safely.
ScenarioNames and postcodes swapped with deterministic fakes; audit shows what changed (not who).
DescriptionRebuilds reporting: Synapse, models, Power BI; validates meaning and performance.
Key DeliverablesBI Design Pack โ€ข Dataset Catalogue โ€ข Visual Validation Log
Candidate Roles & Skills BI Architect โ€” modelling, governance Data Modeller โ€” star, SCD Power BI Dev โ€” DAX, visuals
Student HookDrawing pictures that tell the story of whatโ€™s happening.
ScenarioLegacy KPIs rebuilt in Power BI; refresh via pipelines; numbers reconcile to finance baseline.
DescriptionMigrates and republishes SSRS RDLs; updates data sources; aligns permissions.
Key DeliverablesRDL Inventory โ€ข Publishing Runbook โ€ข Verification Checklist
Candidate Roles & Skills Report Developer โ€” RDL, datasets DBA โ€” connections, performance Release Manager โ€” scheduling
Student HookCopying old drawings onto new paper without smudging them.
ScenarioFinance RDLs re-pointed to Synapse SQL; shared data sources; folder-level RBAC applied.
DescriptionBuilds the playbook for go-live: sequence, timing, checkpoints, rollback. Proves it end-to-end.
Key DeliverablesCutover Plan โ€ข Dress Rehearsal Report โ€ข Issue Log
Candidate Roles & Skills Cutover Manager โ€” choreography Release Lead โ€” gates, comms Tech Leads โ€” scripts, rollback
Student HookPractising the big show before opening night.
ScenarioFull trial run with checkpoints and a timed rollback drill; lessons logged into the plan.
DescriptionRuns SIT, UAT, NF testing; proves systems and data behave; defects tracked and closed.
Key DeliverablesTest Plan โ€ข Test Scripts โ€ข Defect Log โ€ข QA Sign-off
Candidate Roles & Skills Test Manager โ€” strategy, cycles Data QA Analyst โ€” reconciliations Business Tester โ€” acceptance
Student HookChecking your homework before handing it in.
ScenarioUAT verifies contacts in Dynamics, reconciles row counts and key KPIs to legacy.
DescriptionStabilises after go-live, resolves issues, hands over to BAU with documentation and KT.
Key DeliverablesHypercare Plan โ€ข Transition Checklist โ€ข Knowledge Transfer Pack
Candidate Roles & Skills Service Transition Lead โ€” ITIL, KT Support Engineer โ€” monitoring, fixes Knowledge Manager โ€” runbooks
Student HookMaking sure the new toy keeps working after Christmas morning.
ScenarioRunbooks handed to BAU; job runs monitored; user tickets triaged and closed within SLOs.