SlideShare uma empresa Scribd logo
1 de 17
Baixar para ler offline
Date: June 2020
Prepared by: John Phenix
Chief API Architect, HSBC Commercial Bank
Automating API Governance
PUBLIC
1
1
HSBC - The World’s Leading International Bank
39million
customers
3,900 offices
65
countries & territories
Present in
Reported Revenue
$53.8bn 254PB of data
Data Centres in 21
countries
96,600+ Servers
$1.5 Trillion
Daily payments processed
235,000
people around the world
46,000 IT Professionals $2.5bn Run / $3.3bn Change (cash)
PUBLIC
2
Challenge
PUBLIC
How to make API governance an accelerator
instead of a brake?
3
Apple’s iOS Standards and Governance platform produces a consistent, market leading App experience
Why HSBC needs API Standards and Governance – an example from Apple
PUBLIC
4
HSBC’s API Standards and Governance platform will produce a consistent, market leading API developer experience
Why HSBC needs API Standards and Governance
Governance
PUBLIC
Governance
5
Tip 1: What to Govern?
PUBLIC
Security Operations Reputation
As little as possible!The minimum needed to deliver value and
manage risks
Tip 1: Focus governance on real risks rather than personal preferences
6
Comprehensive
Tip 2: What does good look like?
PUBLIC
Scalable Consistent
Evidenced
Tip 2: Good governance scales to meet delivery cadence
7
Visibility
Tip 3: Where to invest effort
PUBLIC
Tools Training
Automation
Tip 3: Shift left – make it easier to fall into success
8
Tip 4a: Pick your style - Centralised
Small team(s) of API SMEs who manually review APIs.
You can duplicate the ARB (API Review Board) in different
geographies.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
9
Tip 4b: Pick your style - Federated
API Champions from every region and major project to enforce
standards locally and escalate non-compliance.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
10
Tip 4c: Pick your style - Automated
Speed and safety at scale requires an automated approach.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
11
Tip 4c: Pick your style -– Hybrid
Focus manual reviews on exceptions and qualitative analysis.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?”
12
Tip 5: How to automate
Audit Trail
API
Engineers
Governance
Engineers
Batch
Rules Setup
CI/CD Pipeline
CAGE UI
Repository
Rules
Lead
Architects
Certification
Dashboard
CAGE
PUBLIC
13
Peer Reviews
Tip 5: How to automate
PUBLIC
Building APIs Right Building the Right APIs
Training
Tip 5: Automate as much as you can, but you still need people
14
5 Governance Tips
Q1: What to govern
Q2: What does good look like
Q3: Where to invest effort
Q4: How to pick your style
Q5: How to automate
PUBLIC
Tip 1: Focus governance on real risks rather than personal preferences
Tip 2: Good governance scales to meet delivery cadence
Tip 3: Shift left – make it easier to fall into success
Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?”
Tip 5: Automate as much as possible, but you still need people
15
Example Rules
Security:
• Sensitive info in query parameters
• Standard headers
• Security policies
Operations:
• Naming standard
• Published to API Repository
• Versioning
• Check for duplicate APIs
• Health endpoint
Style:
• camelCase, PascalCase and snake-case
• Always return 2xx, 4xx and 5xx
• Misuse of HTTP verbs
• Plural nouns for resource collections
• Example request and response schemas
PUBLIC
16 PUBLIC

Mais conteúdo relacionado

Mais procurados

Mais procurados (20)

apidays LIVE LONDON - Differentiating your Developer Program: Is Speed "A" Di...
apidays LIVE LONDON - Differentiating your Developer Program: Is Speed "A" Di...apidays LIVE LONDON - Differentiating your Developer Program: Is Speed "A" Di...
apidays LIVE LONDON - Differentiating your Developer Program: Is Speed "A" Di...
 
[WSO2 Integration Summit Singapore 2019] Building the Next Generation Digital...
[WSO2 Integration Summit Singapore 2019] Building the Next Generation Digital...[WSO2 Integration Summit Singapore 2019] Building the Next Generation Digital...
[WSO2 Integration Summit Singapore 2019] Building the Next Generation Digital...
 
apidays LIVE Paris 2021 - APIs and Data products: How do they impact your bus...
apidays LIVE Paris 2021 - APIs and Data products: How do they impact your bus...apidays LIVE Paris 2021 - APIs and Data products: How do they impact your bus...
apidays LIVE Paris 2021 - APIs and Data products: How do they impact your bus...
 
apidays LIVE New York 2021 - API narrative: A true story of APIs and I by Div...
apidays LIVE New York 2021 - API narrative: A true story of APIs and I by Div...apidays LIVE New York 2021 - API narrative: A true story of APIs and I by Div...
apidays LIVE New York 2021 - API narrative: A true story of APIs and I by Div...
 
[WSO2 Summit APAC 2020] Enabling Digital Transformation and Ecosystem Collabo...
[WSO2 Summit APAC 2020] Enabling Digital Transformation and Ecosystem Collabo...[WSO2 Summit APAC 2020] Enabling Digital Transformation and Ecosystem Collabo...
[WSO2 Summit APAC 2020] Enabling Digital Transformation and Ecosystem Collabo...
 
APIdays Singapore 2019 - API Economy Journey Map, Alan Glickenhouse, API Busi...
APIdays Singapore 2019 - API Economy Journey Map, Alan Glickenhouse, API Busi...APIdays Singapore 2019 - API Economy Journey Map, Alan Glickenhouse, API Busi...
APIdays Singapore 2019 - API Economy Journey Map, Alan Glickenhouse, API Busi...
 
apidays LIVE LONDON - How to spot a Zombie Developer Portal by Allan Knabe
apidays LIVE LONDON - How to spot a Zombie Developer Portal by Allan Knabeapidays LIVE LONDON - How to spot a Zombie Developer Portal by Allan Knabe
apidays LIVE LONDON - How to spot a Zombie Developer Portal by Allan Knabe
 
apidays LIVE London 2021 - From Open Banking to Embedded Finance by Simon Tor...
apidays LIVE London 2021 - From Open Banking to Embedded Finance by Simon Tor...apidays LIVE London 2021 - From Open Banking to Embedded Finance by Simon Tor...
apidays LIVE London 2021 - From Open Banking to Embedded Finance by Simon Tor...
 
Open Bank Project Presentation Tel Aviv CA 4th April 2017
Open Bank Project Presentation Tel Aviv CA 4th April 2017 Open Bank Project Presentation Tel Aviv CA 4th April 2017
Open Bank Project Presentation Tel Aviv CA 4th April 2017
 
apidays LIVE New York 2021 - API as a product: who, what, where, when, why, a...
apidays LIVE New York 2021 - API as a product: who, what, where, when, why, a...apidays LIVE New York 2021 - API as a product: who, what, where, when, why, a...
apidays LIVE New York 2021 - API as a product: who, what, where, when, why, a...
 
apidays LIVE Hong Kong 2021 - Headless API Management by Snehal Chakraborty, ...
apidays LIVE Hong Kong 2021 - Headless API Management by Snehal Chakraborty, ...apidays LIVE Hong Kong 2021 - Headless API Management by Snehal Chakraborty, ...
apidays LIVE Hong Kong 2021 - Headless API Management by Snehal Chakraborty, ...
 
API Trends
API TrendsAPI Trends
API Trends
 
apidays LIVE LONDON - Can banks benefit from FinTech partnerships that delive...
apidays LIVE LONDON - Can banks benefit from FinTech partnerships that delive...apidays LIVE LONDON - Can banks benefit from FinTech partnerships that delive...
apidays LIVE LONDON - Can banks benefit from FinTech partnerships that delive...
 
apidays LIVE Australia 2020 - API Product for Business Ecosystems by Amancio ...
apidays LIVE Australia 2020 - API Product for Business Ecosystems by Amancio ...apidays LIVE Australia 2020 - API Product for Business Ecosystems by Amancio ...
apidays LIVE Australia 2020 - API Product for Business Ecosystems by Amancio ...
 
apidays LIVE Paris 2021 - What does the future of communication APIs look lik...
apidays LIVE Paris 2021 - What does the future of communication APIs look lik...apidays LIVE Paris 2021 - What does the future of communication APIs look lik...
apidays LIVE Paris 2021 - What does the future of communication APIs look lik...
 
apidays LIVE London 2021 - Best practices when monetizing APIs by Derric Gill...
apidays LIVE London 2021 - Best practices when monetizing APIs by Derric Gill...apidays LIVE London 2021 - Best practices when monetizing APIs by Derric Gill...
apidays LIVE London 2021 - Best practices when monetizing APIs by Derric Gill...
 
apidays LIVE Paris 2021 - How to create a profitable API business with direct...
apidays LIVE Paris 2021 - How to create a profitable API business with direct...apidays LIVE Paris 2021 - How to create a profitable API business with direct...
apidays LIVE Paris 2021 - How to create a profitable API business with direct...
 
apidays LIVE London 2021 - Driving API adoption in Insurance by Allan Knabe (...
apidays LIVE London 2021 - Driving API adoption in Insurance by Allan Knabe (...apidays LIVE London 2021 - Driving API adoption in Insurance by Allan Knabe (...
apidays LIVE London 2021 - Driving API adoption in Insurance by Allan Knabe (...
 
The API SlideShare for Bankers and Fintech Executives
The API SlideShare for Bankers and Fintech ExecutivesThe API SlideShare for Bankers and Fintech Executives
The API SlideShare for Bankers and Fintech Executives
 
API & the 3 Pillars of Digital Transformation - apidays LIVE Paris 2020
API & the 3 Pillars of Digital Transformation - apidays LIVE Paris 2020API & the 3 Pillars of Digital Transformation - apidays LIVE Paris 2020
API & the 3 Pillars of Digital Transformation - apidays LIVE Paris 2020
 

Semelhante a INTERFACE by apidays - Automating API Governance by John Phenix

The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...
The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...
The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...
Nordic APIs
 

Semelhante a INTERFACE by apidays - Automating API Governance by John Phenix (20)

API Monetization
API MonetizationAPI Monetization
API Monetization
 
API Products: Who, What, Where, When, Why, and How?
API Products: Who, What, Where, When, Why, and How?API Products: Who, What, Where, When, Why, and How?
API Products: Who, What, Where, When, Why, and How?
 
apidays New York 2023 - Embedded Business Models in Retail, Bernd Schulze & B...
apidays New York 2023 - Embedded Business Models in Retail, Bernd Schulze & B...apidays New York 2023 - Embedded Business Models in Retail, Bernd Schulze & B...
apidays New York 2023 - Embedded Business Models in Retail, Bernd Schulze & B...
 
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
 
Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...
Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...
Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...
 
apidays LIVE Paris 2021 - API data sharing legal practices in the Private Sec...
apidays LIVE Paris 2021 - API data sharing legal practices in the Private Sec...apidays LIVE Paris 2021 - API data sharing legal practices in the Private Sec...
apidays LIVE Paris 2021 - API data sharing legal practices in the Private Sec...
 
apidays LIVE Paris 2021 - Digital API Ecosystems, Marketplaces and Platforms ...
apidays LIVE Paris 2021 - Digital API Ecosystems, Marketplaces and Platforms ...apidays LIVE Paris 2021 - Digital API Ecosystems, Marketplaces and Platforms ...
apidays LIVE Paris 2021 - Digital API Ecosystems, Marketplaces and Platforms ...
 
The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...
The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...
The Federated Future: Pioneering Next-Gen Solutions in API Management - Marku...
 
2022 apidays LIVE Helsinki & North_How good are your APIs? Really?
2022 apidays LIVE Helsinki & North_How good are your APIs? Really?2022 apidays LIVE Helsinki & North_How good are your APIs? Really?
2022 apidays LIVE Helsinki & North_How good are your APIs? Really?
 
RubiX ID - API management - Pim Gaemers
RubiX ID - API management - Pim GaemersRubiX ID - API management - Pim Gaemers
RubiX ID - API management - Pim Gaemers
 
Entering the Platform Age: How to create genuine value for internal and exter...
Entering the Platform Age: How to create genuine value for internal and exter...Entering the Platform Age: How to create genuine value for internal and exter...
Entering the Platform Age: How to create genuine value for internal and exter...
 
Open Bank Project API Days API Strat Berlin 2015
Open Bank Project API Days API Strat Berlin 2015Open Bank Project API Days API Strat Berlin 2015
Open Bank Project API Days API Strat Berlin 2015
 
The Global Influence of Open Banking, API Security, and an Open Data Perspective
The Global Influence of Open Banking, API Security, and an Open Data PerspectiveThe Global Influence of Open Banking, API Security, and an Open Data Perspective
The Global Influence of Open Banking, API Security, and an Open Data Perspective
 
apidays LIVE LONDON - API platform strategy and operating models by Kiran Nadgir
apidays LIVE LONDON - API platform strategy and operating models by Kiran Nadgirapidays LIVE LONDON - API platform strategy and operating models by Kiran Nadgir
apidays LIVE LONDON - API platform strategy and operating models by Kiran Nadgir
 
2018 digital marketing trends - Dave Chaffey
2018 digital marketing trends - Dave Chaffey2018 digital marketing trends - Dave Chaffey
2018 digital marketing trends - Dave Chaffey
 
API Economy: 2016 Horizonwatch Trend Brief
API Economy:  2016 Horizonwatch Trend BriefAPI Economy:  2016 Horizonwatch Trend Brief
API Economy: 2016 Horizonwatch Trend Brief
 
API-as-a-product: The Key to a Successful API Program
API-as-a-product: The Key to a Successful API ProgramAPI-as-a-product: The Key to a Successful API Program
API-as-a-product: The Key to a Successful API Program
 
API Management Part 1 - An Introduction to Azure API Management
API Management Part 1 - An Introduction to Azure API ManagementAPI Management Part 1 - An Introduction to Azure API Management
API Management Part 1 - An Introduction to Azure API Management
 
From Zero to Sixty: Driving a DocOps Based Approach to APIs at Ford Motor Com...
From Zero to Sixty: Driving a DocOps Based Approach to APIs at Ford Motor Com...From Zero to Sixty: Driving a DocOps Based Approach to APIs at Ford Motor Com...
From Zero to Sixty: Driving a DocOps Based Approach to APIs at Ford Motor Com...
 
[WSO2 Summit Americas 2020] Having the Best Technology Isn’t Everything
[WSO2 Summit Americas 2020] Having the Best Technology Isn’t Everything[WSO2 Summit Americas 2020] Having the Best Technology Isn’t Everything
[WSO2 Summit Americas 2020] Having the Best Technology Isn’t Everything
 

Mais de apidays

Mais de apidays (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
Apidays New York 2024 - The secrets to Graph success, by Leah Hurwich Adler, ...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
Apidays New York 2024 - API Discovery - From Crawl to Run by Rob Dickinson, G...
 
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
Apidays Singapore 2024 - Building with the Planet in Mind by Sandeep Joshi, M...
 
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
Apidays Singapore 2024 - Connecting Cross Border Commerce with Payments by Gu...
 
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
Apidays Singapore 2024 - Privacy Enhancing Technologies for AI by Mark Choo, ...
 
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
Apidays Singapore 2024 - Blending AI and IoT for Smarter Health by Matthew Ch...
 
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
Apidays Singapore 2024 - OpenTelemetry for API Monitoring by Danielle Kayumbi...
 
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
Apidays Singapore 2024 - Connecting Product and Engineering Teams with Testin...
 
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
Apidays Singapore 2024 - The Growing Carbon Footprint of Digitalization and H...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
Apidays Singapore 2024 - API Monitoring x SRE by Ryan Ashneil and Eugene Wong...
 
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
Apidays Singapore 2024 - A nuanced approach on AI costs and benefits for the ...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
Apidays Singapore 2024 - How APIs drive business at BNP Paribas by Quy-Doan D...
 

Último

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Último (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 

INTERFACE by apidays - Automating API Governance by John Phenix

  • 1. Date: June 2020 Prepared by: John Phenix Chief API Architect, HSBC Commercial Bank Automating API Governance PUBLIC
  • 2. 1 1 HSBC - The World’s Leading International Bank 39million customers 3,900 offices 65 countries & territories Present in Reported Revenue $53.8bn 254PB of data Data Centres in 21 countries 96,600+ Servers $1.5 Trillion Daily payments processed 235,000 people around the world 46,000 IT Professionals $2.5bn Run / $3.3bn Change (cash) PUBLIC
  • 3. 2 Challenge PUBLIC How to make API governance an accelerator instead of a brake?
  • 4. 3 Apple’s iOS Standards and Governance platform produces a consistent, market leading App experience Why HSBC needs API Standards and Governance – an example from Apple PUBLIC
  • 5. 4 HSBC’s API Standards and Governance platform will produce a consistent, market leading API developer experience Why HSBC needs API Standards and Governance Governance PUBLIC Governance
  • 6. 5 Tip 1: What to Govern? PUBLIC Security Operations Reputation As little as possible!The minimum needed to deliver value and manage risks Tip 1: Focus governance on real risks rather than personal preferences
  • 7. 6 Comprehensive Tip 2: What does good look like? PUBLIC Scalable Consistent Evidenced Tip 2: Good governance scales to meet delivery cadence
  • 8. 7 Visibility Tip 3: Where to invest effort PUBLIC Tools Training Automation Tip 3: Shift left – make it easier to fall into success
  • 9. 8 Tip 4a: Pick your style - Centralised Small team(s) of API SMEs who manually review APIs. You can duplicate the ARB (API Review Board) in different geographies. Scalable Consistent Comprehensive Evidenced PUBLIC
  • 10. 9 Tip 4b: Pick your style - Federated API Champions from every region and major project to enforce standards locally and escalate non-compliance. Scalable Consistent Comprehensive Evidenced PUBLIC
  • 11. 10 Tip 4c: Pick your style - Automated Speed and safety at scale requires an automated approach. Scalable Consistent Comprehensive Evidenced PUBLIC
  • 12. 11 Tip 4c: Pick your style -– Hybrid Focus manual reviews on exceptions and qualitative analysis. Scalable Consistent Comprehensive Evidenced PUBLIC Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?”
  • 13. 12 Tip 5: How to automate Audit Trail API Engineers Governance Engineers Batch Rules Setup CI/CD Pipeline CAGE UI Repository Rules Lead Architects Certification Dashboard CAGE PUBLIC
  • 14. 13 Peer Reviews Tip 5: How to automate PUBLIC Building APIs Right Building the Right APIs Training Tip 5: Automate as much as you can, but you still need people
  • 15. 14 5 Governance Tips Q1: What to govern Q2: What does good look like Q3: Where to invest effort Q4: How to pick your style Q5: How to automate PUBLIC Tip 1: Focus governance on real risks rather than personal preferences Tip 2: Good governance scales to meet delivery cadence Tip 3: Shift left – make it easier to fall into success Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?” Tip 5: Automate as much as possible, but you still need people
  • 16. 15 Example Rules Security: • Sensitive info in query parameters • Standard headers • Security policies Operations: • Naming standard • Published to API Repository • Versioning • Check for duplicate APIs • Health endpoint Style: • camelCase, PascalCase and snake-case • Always return 2xx, 4xx and 5xx • Misuse of HTTP verbs • Plural nouns for resource collections • Example request and response schemas PUBLIC