The registers that keep this architecture honest: risks with owners and mitigations, labeled assumptions, hard constraints, open questions, dependencies, and the NFR register with measurement methods.
| ID | Risk | Impact / likelihood | Mitigation (controls / initiatives) | Owner |
|---|---|---|---|---|
| R-01 | Strangler stall Extraction waves lose funding/momentum; dual-run (cloud + legacy + ESB) becomes permanent, doubling run cost. | high-impact unassessed (placeholder - score at P0) | Wave exit criteria include decommission evidence; steering reviews drawdown curve; init-legacy-retire is a first-class initiative. | Executive steering |
| R-02 | Legacy knowledge loss The people who understand monolith semantics leave before extraction completes. | high-impact unassessed (placeholder - score at P0) | P1 documentation sprint; ACL contract tests encode behavior; pairing rotations. | Legacy platform team |
| R-03 | Messaging semantics misuse Teams put work on streams or facts on queues; DLQs unowned; replay untested. | medium-impact unassessed (placeholder - score at P0) | ADR-07 decision tree; golden-path templates; DLQ drills as consumer onboarding gate (C-INT-02). | Integration platform |
| R-04 | Data-quality debt propagates Ungoverned sources feed products and AI; trust collapses on first bad executive number. | high-impact unassessed (placeholder - score at P0) | Quality gates on zone promotion; certification before consumption; catalog-first onboarding (RB-09). | Data governance council |
| R-05 | AI retrieval leakage RAG surfaces content the caller isn't entitled to see - a data breach through the assistant. | high-impact unassessed (placeholder - score at P0) | Authorization-aware retrieval (C-AI-03); entitlement-bypass tests as release gate; only cataloged sources embeddable. | AI platform + security |
| R-06 | Agent overreach An agent with broad permissions performs unintended production actions. | high-impact unassessed (placeholder - score at P0) | Tool allowlists + transaction limits + HITL + kill switch (C-AI-04/05, RB-12); autonomy levels graduated by gov-ai. | AI governance council |
| R-07 | Cloud cost overrun Untagged sprawl, idle capacity, unwatched AI token burn. | medium-impact unassessed (placeholder - score at P0) | Tag-or-no-deploy policy; budgets + anomaly alerts; monthly FinOps review; gateway token metering (ADR-16). | FinOps practice |
| R-08 | Platform team bottleneck IDP becomes a ticket queue; teams route around it; shadow platforms return. | medium-impact unassessed (placeholder - score at P0) | Platform-as-product operating model with SLOs + adoption metrics; self-service golden paths; gov-platform arbitration. | Platform engineering |
| R-09 | Unexamined lock-in Provider coupling grows silently beyond the consciously accepted level. | medium-impact unassessed (placeholder - score at P0) | Annual lock-in/exit review (ADR-02); open table formats at the data layer; gateway abstraction at the AI layer. | Enterprise architecture |
| R-10 | Detection gaps New platforms ship without SIEM onboarding; incidents are invisible. | high-impact unassessed (placeholder - score at P0) | SIEM onboarding in every go-live checklist (C-OPS-03); coverage map reviewed by gov-secrisk. | Security operations |
| R-11 | Ransomware reaches backups Attacker with admin credentials encrypts/deletes primary backups. | high-impact unassessed (placeholder - score at P0) | Immutability windows + isolated cyber vault with separate credentials (C-RES-01/02); vault recovery drills. | SRE + security |
| R-12 | B2B modernization under-adoption Partners stay on legacy exchange paths; the B2B gateway serves a fraction of traffic. | medium-impact unassessed (placeholder - score at P0) | Onboarding runbook with lead-time target; per-partner migration plan in init-b2b; partner portal incentives. | Partner operations |
| R-13 | Skills gap K8s + data + AI platform skills are scarce; hiring lags the roadmap. | medium-impact unassessed (placeholder - score at P0) | A-04 validation at P0; training budget; managed services preferred; PaaS escape valve (ADR-04). | CTO organization |
| R-14 | Governance theater Boards meet without decision rights or SLAs; teams bypass; exceptions never expire. | medium-impact unassessed (placeholder - score at P0) | Charters with decision rights + review SLAs; policy-as-code enforcement; exception expiry automation (PR-12). | Executive steering |
| R-15 | Compliance scope surprise Payment/privacy obligations turn out broader than assumed (A-09/OQ-03). | high-impact unassessed (placeholder - score at P0) | Early org-input checkpoints at P0/P1; configurable overlays ready (C-DP-05, C-PRV-01); no scope-narrowing design bets before review. | Risk & compliance |
| ID | Assumption | Statement |
|---|---|---|
| A-01 | Illustrative baseline | The source document defines no real organization. The 'current state' here is an illustrative baseline constructed ONLY from challenges the source describes (S4, S27-S28, S49, S51, S56-S58): legacy monolith, ESB point-to-point sprawl, overnight-batch reporting, SaaS integrated ad hoc, departmental app sprawl. Phase 1 discovery replaces it with evidence. |
| A-02 | Target content is proposal | Target-state components and controls are design proposals / industry-practice extensions consistent with source themes - the source mandates almost none of them specifically. Each node's source_traceability field distinguishes source-derived themes from proposals. |
| A-03 | Single primary cloud pending ratification | One primary cloud provider is assumed (ADR-02); the provider identity itself is an organization selection, not made here. |
| A-04 | Platform team capacity | A platform team capable of operating managed Kubernetes is assumed (drives ADR-04). If untrue, the PaaS-first variant in ADR-04 applies. |
| A-05 | All recovery/availability values are placeholders | No BIA exists. Every availability_target/rto/rpo value is a tier-band placeholder, never a commitment. |
| A-06 | Residency unknown | Data residency/sovereignty obligations are unknown (OQ-02); residency is modeled as a configurable control overlay (C-DP-05). |
| A-07 | Provisional service tiers | Criticality/tier assignments are provisional judgments pending BIA. |
| A-08 | Vendors are illustrations | Representative products in the integration catalog are illustrative options with selection criteria - none are selections or endorsements. |
| A-09 | Payment scope unreviewed | Payment flows assume provider-side tokenization; actual compliance scope requires organization-specific assessment. No compliance claim is made anywhere in this package. |
| A-10 | Volumes unknown | Load, growth and storage volumes are unknown (OQ-04); capacity records carry placeholders plus the test method that will replace them. |
| A-11 | No certification claims | Regulatory/compliance frameworks are modeled as configurable overlays; nothing here asserts certification or compliance. |
| A-12 | Ownership placeholders | All owner fields are role placeholders to be bound to named people/teams at Phase 0. |
| ID | Constraint | Statement |
|---|---|---|
| CT-01 | Static delivery | This package is standards-based HTML/CSS/JS with no build step and no CDN dependencies (offline-capable by design; supply-chain surface minimized). |
| CT-02 | Single canonical model | All views render from data/architecture.json + views.json; no view may contradict the canonical model. |
| CT-03 | WCAG 2.2 AA target | Accessibility target for all HTML deliverables; table alternatives exist for every graph. |
| CT-04 | Legacy continuity | The legacy core must keep operating until strangler waves complete - business continuity outranks migration speed. |
| CT-05 | SoR discipline retained | ERP/CRM/HRIS remain SaaS systems of record; modernization re-platforms the integration around them, not the systems themselves. |
| CT-06 | Governed integration only | Cross-domain access happens via APIs/events/governed pipelines - never direct database access across ownership boundaries. |
| ID | Question |
|---|---|
| OQ-01 | Region strategy & DR region pair (feeds OD-01). |
| OQ-02 | Data residency / sovereignty obligations by jurisdiction. |
| OQ-03 | Applicable regulatory overlays (privacy, sector-specific). |
| OQ-04 | Volumes: traffic, orders, partners, data growth, peaks (capacity baselines). |
| OQ-05 | Platform team size/skills reality (validates A-04). |
| OQ-06 | SaaS data backup scope per vendor shared-responsibility review. |
| OQ-07 | Payment scope: card-present? stored credentials? provider model? (validates A-09). |
| OQ-08 | Workflow/case realization preference (feeds OD-03). |
| OQ-09 | AI use-case inventory with risk classes (feeds gov-ai intake). |
| OQ-10 | Existing contracts/licenses constraining product options. |
| OQ-11 | Current identity estate (greenfield CIAM or consolidation?). |
| OQ-12 | Any concrete edge-computing use case with NFRs (feeds OD-05). |
Sequencing constraints between roadmap initiatives (full detail incl. exit criteria and rollback stances in the roadmap view).
| Initiative | Wave | Depends on | Retires risk |
|---|---|---|---|
| Governance & decision fabric | wave-0 | — | R-14 |
| Discovery, APM inventory & BIA | wave-0 | init-governance | R-02 |
| Cloud landing zones & network foundation | wave-0 | init-governance | R-07 |
| Identity foundation (workforce + CIAM + PAM + JML) | wave-0 | init-governance | R-10 |
| Observability & incident baseline | wave-0 | init-landing | R-10 |
| FinOps baseline (tagging, allocation, budgets) | wave-0 | init-landing | R-07 |
| Platform engineering MVP (golden paths) | wave-0 | init-landing, init-identity | R-08 |
| API management & edge gateway | wave-1 | init-platform-mvp | R-03 |
| Event backbone & queues | wave-1 | init-platform-mvp | R-03 |
| Legacy facade & anti-corruption layer | wave-1 | init-api-platform | R-01 |
| B2B & partner exchange modernization | wave-1 | init-event-backbone | R-12 |
| Lakehouse, catalog & first data products | wave-1 | init-landing, init-event-backbone | R-04 |
| Strangler wave 1: customer & order extraction | wave-1 | init-legacy-facade, init-platform-mvp | R-01 |
| Strangler wave 2: fulfillment, billing & ESB drain | wave-2 | init-strangler-1, init-b2b | R-01 |
| Resilience & cyber-recovery proof | wave-2 | init-data-platform, init-strangler-1 | R-11 |
| AI foundation: gateway, RAG, evals, cost | wave-2 | init-data-platform, init-identity | R-05 |
| Governed agentic automation (first use case) | wave-3 | init-ai-foundation | R-06 |
| Legacy decommission with evidence | wave-3 | init-strangler-2, init-data-platform | R-01 |
| Continuous optimization & radar cadence | wave-3 | init-resilience, init-finops | R-07 |
Requirement stances with the measurement method that will replace each placeholder. No numeric target below is a commitment until bound at P1–P2 with organization data.
| Category | Requirement stance | Measurement / verification method |
|---|---|---|
| Availability | Service tiers T1–T4 define expectations; numeric targets are assigned per service ONLY after the BIA prices downtime (P1). Multi-AZ is the T1/T2 baseline (C-RES-04); multi-region is decision OD-01. | BIA report → tier assignment per service in the model; availability measured from synthetic + SLO data, reported monthly. |
| Performance | Latency/throughput/concurrency/payload/batch-window targets are placeholders per component (capacity records) until OQ-04 volumes exist. Interactive paths carry an indicative sub-second p95 placeholder explicitly marked as unvalidated. | Load tests against agreed profiles in a performance environment; RUM/synthetic percentiles in production; targets versioned in NFR register. |
| Scalability | Horizontal-first (stateless services, HPA), queue-based load leveling for bursty work, partitioning for streams/data, read replicas where read-heavy, PaaS/serverless for spiky low-duty workloads. Scaling triggers are defined per component at onboarding (RB-05/RB-18). | Scale tests to 2× expected peak placeholder; autoscale drill; capacity review cadence. |
| Security | Identity-first zero trust (C-ID-*), deny-by-default networks (C-NET-*), OAuth2/OIDC discipline (C-APP-01), encryption everywhere (C-DP-02), supply-chain gates (C-SC-*), AI-specific controls (C-AI-*). Full catalog: security model doc. | Control tests with evidence per controls.json; red-team/pen-test scope per change class; posture scan trends. |
| Resilience | Dependency failure = designed behavior: timeouts, circuit breakers, bounded retries with jitter, bulkheads, DLQs, graceful degradation matrices per consumer; recovery via tested backup/restore, tiered DR, cyber vault (C-RES-*). | Chaos/failure drills per tier cadence; DR rehearsal timings vs objectives; degradation matrix accuracy reviewed at PIR. |
| Operability | A service is done when observable (OTel + SLO + owner), on-call-staffed, runbook'd, capacity-planned, restore-tested. Platform SLOs cover the paths teams depend on. | ORR checklist (P8); orphan-alert audits; runbook drill records. |
| Maintainability | Modular boundaries (ADR-05), golden-path consistency, contract-first interfaces, automated tests as release gates, tech-debt register reviewed quarterly with capacity actually allocated. | DORA metrics; debt burn-down; standards-conformance scans. |
| Portability | Valued where cheap and real: open table formats (data), OTel (telemetry), OCI/K8s (compute), gateway abstraction (AI providers). NOT pursued via lowest-common-denominator abstraction layers (ADR-03). Lock-in is accepted consciously and reviewed annually. | Annual lock-in/exit review per ADR-02; exit-cost estimate refresh. |
| Compliance | No certification or regulatory compliance is claimed anywhere (A-11). Privacy, records, residency and sector overlays are modeled as configurable control sets (C-DP-05, C-PRV-01, C-DP-04) that activate once OQ-02/03 answers arrive. | Overlay activation records; control evidence retention (C-GOV-03); external audit only after org scoping. |
| Accessibility | This package itself targets WCAG 2.2 AA: keyboard-complete, visible focus, contrast-checked tokens, reduced-motion support, table alternatives for every graph, no color-only meaning. | Keyboard walkthrough; automated a11y scan; screen-reader spot checks (validation section of README). |
| Cost | Every product allocated (tags enforced at deploy), budgeted, anomaly-monitored; unit economics per product; AI token budgets per consumer; optimization cadence (rightsizing, commitments, storage lifecycle, egress review) monthly via FinOps review. | Allocation coverage %; budget variance; anomaly MTTR; unit-cost trend per product. |