Identity-Governed Event-Driven Architecture for High-Volume Regulated Workflows

Authors

  • Aravind Yedmala Independent Researcher, USA

DOI:

https://doi.org/10.70917/ijcisim-2026-5857

Keywords:

Access-controlled event topics, event-driven architecture, event lineage, message broker security, regulated enterprise workflows, workload identity

Abstract

Event-driven modernization is frequently assessed in terms of throughput, scalability, and resilience, while identity governance and business-level authorization within the messaging layer receive less design attention. This article argues that an event-driven platform serving regulated workflows should treat topics, schemas, producers, and consumers as governed resources that answer the same questions an application programming interface (API) already answers: which subject or workload is acting, under which identity, whether the action is authorized, and how the decision will be recorded. It develops a reference model built around access-controlled event topics, schema governance, workload identity for producers and consumers, layered policy enforcement from the broker to the application, delivery and consistency guarantees, and audit lineage capable of reconstructing a workflow across multiple asynchronous hops. Against a simpler baseline in which authorization stops at broker-level topic permission, the model's distinguishing claim is that five separate authorization decisions arise in an asynchronous workflow and that collapsing them into one broker-level check is what produces the accountability gap this article addresses. The article contributes a five-layer authorization model in which each layer answers a distinct trust question, an explicit separation of immediate delegated processing from delayed asynchronous processing in token handling, a threat-and-control summary for event-driven platforms, a distinction between operational telemetry and formal audit evidence together with the failure modes that degrade the latter, a discrete-event simulation of a partition-key strategy's effect on ordering violations and audit-reconciliation gaps under the illustrative workload profile, and a readiness checklist for regulated migration. Sources comprise peer-reviewed studies of broker performance and partitioning, publish-subscribe confidentiality, microservice authorization and audit logging, stream-processing correctness, and microservice data management, alongside the NIST Cybersecurity Framework 2.0, NIST guidance on microservices and cloud-native application security, and primary event and token specifications. The model itself has not been deployed in a production regulated environment; the simulation reported in Section VII is a discrete-event approximation intended to illustrate the mechanism, not a benchmark of a fielded system, and the comparative statements elsewhere in the article remain qualitative. It is intended to enable, not to demonstrate, end-to-end accountability across asynchronous stages, and it requires practical validation in each deployment context.

Downloads

Download data is not yet available.

Downloads

Published

2026-09-04

How to Cite

Aravind Yedmala. (2026). Identity-Governed Event-Driven Architecture for High-Volume Regulated Workflows. International Journal of Computer Information Systems and Industrial Management Applications, 18(23s), 2002–2021. https://doi.org/10.70917/ijcisim-2026-5857

Issue

Section

Original Articles