How all 60 source sections (plus front matter, diagrams and conclusion) were incorporated, revised, deferred or rejected — and the provenance of every one of the 133 components.
The source document is a 60-section practice guide: broad, thematic, and deliberately organization-neutral. It describes what disciplines exist, not which components an enterprise should build. Reverse-engineering therefore worked at the theme level: each section was inventoried, mapped to architecture views, and either incorporated (theme carried into concrete components/controls), revised (carried with a documented correction), deferred (no requirement identified), or rejected (not usable as architecture input).
S20 means section 20 motivates the component's
existence — it does not mean the source specified that component. Nearly every concrete design element (field values, controls,
protocols, failure semantics, runbooks) is this package's proposal layered on the source's themes: assumptions A-01/A-02 apply globally.
The 41 embedded diagrams were rejected as authoritative input per the brief — every view here renders from the canonical data model instead.| Ref | Source section | Disposition | Mapped to | Note |
|---|---|---|---|---|
| S1 | Modern Enterprise Architecture: Introduction & Vision | incorporated | executive-overview | Vision framing carried into objectives and principles. |
| S2 | Digital Transformation & Business Modernization | incorporated | business-architecture, roadmap | Outcome-first stance became PR-01 and roadmap sequencing. |
| S3 | Enterprise Architecture Principles | incorporated | governance-finops | Source's principle themes formalized into the 12 testable principles (PR-01..12). |
| S4 | Current State Enterprise Assessment | incorporated | roadmap, runbook P1 | Drives Phase 1 discovery; also the basis for the illustrative baseline (A-01). |
| S5 | North Star & Future State Architecture | incorporated | roadmap | Target-state definition + transition-state discipline. |
| S6 | Business Architecture | incorporated | business-architecture | Capability/value-stream anchoring of all technology nodes. |
| S7 | Business Capability Mapping | incorporated | business-architecture | Capability set + heat-map treatment (maturity values are placeholders). |
| S8 | Value Streams & Business Processes | incorporated | business-architecture | Four generic value streams modeled. |
| S9 | Product, Platform & Portfolio Architecture | incorporated | portfolio-product-platform | Product/platform/portfolio distinction + reuse relationships. |
| S10 | Enterprise Roadmaps & Transformation Planning | incorporated | roadmap | Wave structure with exit criteria and quick wins. |
| S11 | IT Portfolio Management & Technology Investment | incorporated | portfolio-product-platform | Investment-alignment fields on portfolio view. |
| S12 | Application Portfolio Management (APM) | incorporated | portfolio-product-platform, runbook P1 | APM inventory + dispositions in init-discovery. |
| S13 | Solution Architecture | revised | architecture-decisions | Not a separate view: absorbed into the metamodel + ADR discipline so solution designs inherit the canonical model. |
| S14 | Application Architecture | incorporated | application-domain | Domain services, BFF, modularity; transactional boundaries via svc-order. |
| S15 | Integration Architecture | incorporated | integration-api | Full integration taxonomy modeled with failure semantics the source omits. |
| S16 | API-First Enterprise & API Management | incorporated | integration-api | Gateway + APIM + portal + lifecycle (ADR-06). |
| S17 | B2B Integration, Partner Ecosystems | incorporated | integration-api | EDI/AS2/MFT + partner onboarding runbook + reconciliation controls. |
| S18 | SaaS Architecture & Vendor Ecosystems | incorporated | application-domain | SoR discipline (CT-05); SaaS integrated via governed paths only. |
| S19 | Data Architecture, Information Strategy & Governance | incorporated | data-analytics | Catalog/classification-driven governance; MDM; quality. |
| S20 | Event-Driven Architecture & Enterprise Messaging | incorporated | integration-api | Streams-vs-queues semantics (ADR-07) + DLQ/replay discipline the source implies but doesn't specify. |
| S21 | Cloud-Native Architecture | incorporated | cloud-infrastructure, platform-engineering | Cloud-native principles realized through the platform layer. |
| S22 | Hybrid Cloud, Multi-Cloud & Cloud 2.0 | revised | cloud-infrastructure | Hybrid carried as TRANSITION posture (ADR-01); multi-cloud gated by justification (ADR-03); 'Cloud 2.0' marketing term not carried into the model. |
| S23 | Infrastructure Architecture & Cloud Foundations | incorporated | cloud-infrastructure | Landing zones, segmentation, connectivity. |
| S24 | Platform Engineering & Internal Developer Platforms | incorporated | platform-engineering | Platform-as-product + golden paths + IDP. |
| S25 | Enterprise Security Architecture & Zero Trust | incorporated | security-zero-trust | Expanded into the concrete control catalog (source stays at principle level). |
| S26 | Enterprise Modernization Assessment Framework | incorporated | runbook P1-P2 | Assessment dimensions embedded in discovery + wave prioritization. |
| S27 | Modernization Strategies (7Rs) | revised | architecture-decisions, runbook P2 | Source's 7R list (S27) and 5R list (S54) are inconsistent; standardized here on 8 dispositions (adds 'relocate', separates replace/repurchase) - flagged as a revision. |
| S28 | Legacy Transformation (Mainframes, ERP, CRM, COTS & SOA) | incorporated | application-domain | ACL + facade + incremental strangling; ERP kept as SoR. |
| S29 | Enterprise Architecture Patterns & Design Principles | incorporated | architecture-decisions | Pattern guidance folded into principles + ADR options. |
| S30 | Cloud & Distributed System Patterns | incorporated | operations-sre, resilience-dr | Pattern set carried into NFR/scalability requirements with adoption criteria. |
| S31 | Microservices Architecture & Service Mesh | revised | application-domain | Microservices are criteria-gated (ADR-05); service mesh demoted to open decision OD-06 rather than assumed. |
| S32 | Containers, Kubernetes & Cloud Orchestration | incorporated | cloud-infrastructure | K8s adopted WITH justification criteria (ADR-04) per prompt's anti-fashion rule. |
| S33 | Infrastructure as Code, Automation & GitOps | incorporated | devsecops, platform-engineering | IaC-only provisioning; GitOps reconciliation; drift-as-incident. |
| S34 | DevSecOps, CI/CD & Continuous Delivery | incorporated | devsecops | Extended with SBOM/signing/provenance which the source does not mention. |
| S35 | Software Quality Engineering, Testing & Release Management | incorporated | devsecops, runbook P4/P8 | Quality gates in pipelines; release + operational-readiness procedures. |
| S36 | Technology Operations (ITOps), CloudOps & Platform Operations | incorporated | observability-sre, runbook P9 | Day-2 process catalog in runbook Phase 9. |
| S37 | Observability, Monitoring, Logging, Tracing & AIOps | incorporated | observability-sre | OTel-first (ADR-11); AIOps optional + hygiene-gated + human-approved. |
| S38 | Reliability, Scalability, Performance, HA & DR | incorporated | resilience-dr | Tiered recovery + immutable backup + cyber vault; numbers withheld pending BIA. |
| S39 | FinOps, Cloud Financial Management & Cost Optimization | incorporated | governance-finops | Tag-enforced allocation, showback-first (ADR-16), AI cost metering. |
| S40 | Data Modernization (Mesh, Fabric, Lakehouse & Streaming) | revised | data-analytics | Mesh/fabric/lakehouse disambiguated per prompt: lakehouse=estate, mesh=operating model, fabric=tooling claim treated cautiously (ADR-08). |
| S41 | AI Architecture & Enterprise AI Platforms | incorporated | ai-agentic | Expanded into gateway/registry/eval/vector components the source doesn't name. |
| S42 | Agentic AI & Autonomous Enterprises | incorporated | ai-agentic | Source's autonomy vision bounded by tool registry + HITL + kill switch (ADR-14). |
| S43 | Digital Experience, Web, Mobile & Omni-Channel | incorporated | business-architecture, application-domain | Channel set + BFF pattern. |
| S44 | Enterprise Application Ecosystems | incorporated | portfolio-product-platform | Ecosystem relationships modeled as canonical graph. |
| S45 | Architecture Governance & Review Boards | incorporated | governance-finops | ARB + decision rights + exception-with-expiry mechanics. |
| S46 | Enterprise Technology Governance | incorporated | governance-finops | Per-domain governance bodies + policy-as-code enforcement. |
| S47 | Architecture Characteristics & Quality Attributes | incorporated | docs/risk-assumption-register (NFRs) | Quality attributes became the NFR register with placeholders + measurement methods. |
| S48 | Measuring Architecture Success (KPIs, OKRs & Maturity) | incorporated | roadmap, runbook P9 | Exit criteria + Phase-9 metric set. |
| S49 | Common Architecture Anti-Patterns | incorporated | roadmap (baseline), quality tests | Anti-patterns shaped the illustrative baseline AND the package's own quality gates. |
| S50 | Innovation, Emerging Tech, Edge & Future Platforms | deferred | roadmap wave-3 | No concrete requirement identified; edge = OD-05; radar cadence carries the theme. |
| S51 | Application Rationalization & Technical Debt Reduction | incorporated | portfolio-product-platform | Departmental-sprawl node + rationalization dispositions. |
| S52 | Domain-Driven Modernization | incorporated | application-domain | Bounded contexts as extraction seams (ADR-05). |
| S53 | API Modernization & Integration Transformation | incorporated | integration-api | Facade-first legacy API enablement (init-legacy-facade). |
| S54 | Cloud Migration & Application Transformation Strategy | revised | roadmap | 5R variant reconciled with S27 into the single 8R set (see S27 note). |
| S55 | Enterprise Digital Platform Modernization | incorporated | platform-engineering, portfolio | Platform-first delivery model. |
| S56 | Legacy Application Decomposition & Incremental Modernization | incorporated | application-domain, roadmap | The strangler waves ARE this section, made concrete. |
| S57 | Enterprise Integration Modernization | incorporated | integration-api | ESB-drain-by-flow-class plan. |
| S58 | Data Migration & Data Platform Modernization | incorporated | data-analytics | Lakehouse migration with parallel-run + variance evidence. |
| S59 | Modern Application Delivery Models & Product-Centric Architecture | incorporated | portfolio-product-platform | Product-centric ownership on every node (owner fields; platform-as-product). |
| S60 | Enterprise Transformation Roadmaps & Continuous Modernization | incorporated | roadmap | Continuous-modernization cadence in wave 3 / Phase 9. |
| S-intro | Front matter & topic list | incorporated | traceability | TOC lists ~50 topics vs 60 body sections with title drift (e.g. 'Business Verticals Based Architecture' has no body section) - recorded as a source inconsistency. |
| S-images | 41 embedded diagrams | rejected | - | Decorative/unlabeled diagrams not tied to a model; per the brief they are NOT reused as authoritative architecture. All diagrams here derive from the canonical data model instead. |
| S-conclusion | Conclusion | incorporated | executive-overview | Continuous-journey framing carried into Phase 9 cadence. |
| # | Inconsistency | Where | Resolution in this package |
|---|---|---|---|
| 1 | The "7Rs" list gives seven dispositions in S27 (retain, rehost, replatform, refactor, repurchase, replace, retire) but a five-item variant in S54 (rehost, replatform, refactor, rebuild, replace); 'relocate' never appears; 'replace' vs 'repurchase' overlap is unexplained. | S27 vs S54 | Standardized on eight dispositions (adds relocate; replace and repurchase kept distinct) — recorded as a revision, used in P1 disposition register. |
| 2 | The front-matter topic list (~50 items) does not match the 60 body sections; e.g. "Business Verticals Based Architecture" appears in the list but has no body section. | Front matter | Body sections treated as authoritative; vertical-specific architecture is explicitly out of scope pending org input (industry unknown — OQ-03). |
| 3 | 41 diagrams are embedded without captions tying them to a model or notation; several appear beside unrelated sections. | Throughout | Rejected as architecture input (per brief). All visuals in this package derive from one canonical model with a single legend. |
| 4 | "Cloud 2.0" is used as a maturity label without definition. | S22 | Not carried into the model; the underlying ideas (platform-integrated AI/automation/FinOps operating model) are represented as concrete components instead. |
| 5 | Duplicated coverage: modernization strategy appears in S27/S51/S54/S56/S60; integration in S15/S16/S17/S20/S53/S57; data in S19/S40/S58. No cross-references reconcile them. | Multiple | Each cluster merged into one canonical treatment (dispositions register; integration view + catalog; data view + ADR-08) with all source refs retained on the nodes. |
| 6 | Agentic AI (S42) promises autonomy without any control model; security section (S25) never mentions AI-specific threats. | S42/S25 | Gap filled by proposal: gateway, guardrails, tool registry, HITL, kill switch, eval/red-team controls (C-AI-01…06) — labeled as extensions, not source content. |
| 7 | The source names no volumes, SLAs, RTO/RPOs, regulations, vendors-as-requirements, or organization facts anywhere. | Global | All such values are placeholders bound at P0–P2; registers A-*/OQ-* track them; nothing is presented as fact (A-05/A-10/A-11). |
Every node's provenance. "Baseline element" = part of the illustrative current state constructed from the source's challenge narrative (A-01); "design proposal" = target/transition component motivated by the cited sections (A-02).
| ID | Component | Layer | Source refs | Provenance class |
|---|---|---|---|---|
ai-agent-orch | Agent Orchestrator & Planner | ai | S42 | source-themed design proposal |
ai-embed | Embedding & Chunking Pipeline | ai | S41, S42 | source-themed design proposal |
ai-feature-store | Feature Store | ai | S41 | source-themed design proposal |
ai-gateway | AI Gateway & Model Access Control | ai | S41, S42 | source-themed design proposal |
ai-guardrails | AI Safety Guardrails & Content Filtering | ai | S41, S42 | source-themed design proposal |
ai-hitl | Human-in-the-Loop Approval Service | ai | S42 | source-themed design proposal |
ai-mlplat | ML Platform (training, registry, evaluation) | ai | S41 | source-themed design proposal |
ai-models-hosted | Hosted Foundation Model Services | ai | S41 | source-themed design proposal |
ai-models-self | Self-Managed Model Serving | ai | S41 | source-themed design proposal |
ai-observe | AI Observability & Cost Controls | ai | S41, S37 | source-themed design proposal |
ai-prompt | Prompt Registry & Lifecycle | ai | S41, S42 | source-themed design proposal |
ai-rag | RAG Retrieval Service (authorization-aware) | ai | S41, S42 | source-themed design proposal |
ai-tools | Agent Tool Registry & Execution Sandbox | ai | S42 | source-themed design proposal |
ai-vector | Vector Store & Index | ai | S41, S42 | source-themed design proposal |
acl-legacy | Legacy Anti-Corruption Layer | application | S28, S56 | source-themed design proposal |
app-bff-customer | Experience API - Customer BFF | application | S14, S16, S43 | source-themed design proposal |
app-bff-partner | Experience API - Partner BFF | application | S16, S17 | source-themed design proposal |
app-legacy-core | Legacy Core Business System (Monolith) | application | S27, S28, S56 | source-described baseline element |
app-legacy-dept | Departmental Apps & EUC Portfolio | application | S12, S51 | source-described baseline element |
db-operational | Operational Databases (per-service) | application | S14, S30 | source-themed design proposal |
ext-partners | Trading Partners (EDI / API) | application | S17 | source-themed design proposal |
ext-payment | Payment Service Provider | application | S17 | source-themed design proposal |
saas-collab | Collaboration & Productivity Suite | application | S18 | source-themed design proposal |
saas-crm | CRM (Customer Relationship SoR) | application | S18 | source-themed design proposal |
saas-erp | ERP (Finance & Procurement SoR) | application | S18, S28 | source-themed design proposal |
saas-hris | HRIS (Workforce SoR) | application | S18 | source-themed design proposal |
saas-itsm | ITSM & CMDB | application | S18, S36 | source-themed design proposal |
svc-billing | Billing & Invoicing Service | application | S14, S18 | source-themed design proposal |
svc-catalog | Product & Catalog Service | application | S14, S52 | source-themed design proposal |
svc-customer | Customer Profile Service | application | S14, S52 | source-themed design proposal |
svc-document | Document & Content Service | application | S14 | source-themed design proposal |
svc-fulfillment | Fulfillment Orchestration Service | application | S14, S20 | source-themed design proposal |
svc-notify | Notification Service | application | S14, S20 | source-themed design proposal |
svc-order | Order Management Service | application | S14, S52, S56 | source-themed design proposal |
svc-workflow | Workflow & Case Management | application | S8, S43 | source-themed design proposal |
cap-customer-engagement | Customer & Channel Engagement | business | S7, S43 | source-themed design proposal |
cap-finance | Finance & Procurement | business | S18, S28 | source-themed design proposal |
cap-insight | Enterprise Insight & Decisioning | business | S19, S40, S41 | source-themed design proposal |
cap-order-fulfillment | Order & Service Fulfillment | business | S7, S8 | source-themed design proposal |
cap-partner-supply | Partner & Supply Collaboration | business | S17 | source-themed design proposal |
cap-product-service | Product & Service Management | business | S7, S9 | source-themed design proposal |
cap-technology | Technology & Platform Services | business | S9, S24 | source-themed design proposal |
cap-workforce | Workforce & Talent | business | S18 | source-themed design proposal |
obj-agility | Faster, Safer Change Delivery | business | S1, S2, S10 | source-themed design proposal |
obj-cost | Technology Cost Transparency & Efficiency | business | S39, S11 | source-themed design proposal |
obj-experience | Unified Customer & Partner Experience | business | S43 | source-themed design proposal |
obj-intelligence | Data- & AI-Enabled Decisions | business | S19, S41 | source-themed design proposal |
obj-resilience | Operational Resilience & Continuity | business | S38 | source-themed design proposal |
obj-trust | Security, Privacy & Compliance Readiness | business | S25, S46 | source-themed design proposal |
per-customer | Customer | business | S6 | source-themed design proposal |
per-developer | Developer / Engineer | business | S6 | source-themed design proposal |
per-employee | Employee / Agent | business | S6 | source-themed design proposal |
per-executive | Executive / Portfolio Leader | business | S6 | source-themed design proposal |
per-partner | Trading Partner | business | S6 | source-themed design proposal |
per-sre | SRE / Operations Engineer | business | S6 | source-themed design proposal |
vs-acquire-onboard | Prospect-to-Customer | business | S8 | source-themed design proposal |
vs-order-to-cash | Order-to-Cash | business | S8 | source-themed design proposal |
vs-procure-to-pay | Procure-to-Pay | business | S17 | source-themed design proposal |
vs-request-to-resolve | Request-to-Resolution | business | S8 | source-themed design proposal |
data-bi | BI & Analytics Service | data | S19 | source-themed design proposal |
data-catalog | Data Catalog, Lineage & Metadata | data | S19, S40 | source-themed design proposal |
data-cdc | Batch & CDC Ingestion | data | S19, S58 | source-themed design proposal |
data-lakehouse | Lakehouse (raw / validated / curated / serving) | data | S40, S58 | source-themed design proposal |
data-legacy-dw | Legacy Reporting Database | data | S58, S51 | source-described baseline element |
data-mdm | Master & Reference Data Management | data | S19 | source-themed design proposal |
data-quality | Data Quality & Observability | data | S19, S58 | source-themed design proposal |
data-stream-proc | Stream Processing | data | S20, S40 | source-themed design proposal |
data-warehouse | SQL Serving Warehouse | data | S40 | source-themed design proposal |
dp-customer360 | Customer 360 Data Product | data | S40, S19 | source-themed design proposal |
dp-orders | Orders & Fulfillment Data Product | data | S40 | source-themed design proposal |
ch-contact-center | Contact Center & Service Channel | experience | S43 | source-themed design proposal |
ch-employee-workspace | Employee Workspace | experience | S43, S51 | source-themed design proposal |
ch-mobile | Customer Mobile App | experience | S43 | source-themed design proposal |
ch-partner-portal | Partner Portal | experience | S17, S43 | source-themed design proposal |
ch-web | Customer Web Portal | experience | S43 | source-themed design proposal |
fin-tooling | Cost Management & Allocation Tooling | governance | S39 | source-themed design proposal |
gov-ai | AI Governance Council | governance | S41, S42 | source-themed design proposal |
gov-api | API & Integration Governance | governance | S16, S46 | source-themed design proposal |
gov-arb | Architecture Review Board | governance | S45 | source-themed design proposal |
gov-data | Data Governance Council | governance | S19 | source-themed design proposal |
gov-ea-repo | Architecture Repository & Standards | governance | S45, S46 | source-themed design proposal |
gov-finops | FinOps Practice & Review | governance | S39 | source-themed design proposal |
gov-platform | Cloud & Platform Governance | governance | S46 | source-themed design proposal |
gov-reliability | Service Reliability Review | governance | S37, S38 | source-themed design proposal |
gov-secrisk | Security & Risk Review | governance | S45, S25 | source-themed design proposal |
gov-steering | Executive Technology Steering Committee | governance | S45 | source-themed design proposal |
int-apigw | API Gateway (Edge) | integration | S16, S53 | source-themed design proposal |
int-apim | API Management & Developer Portal | integration | S16 | source-themed design proposal |
int-b2b | B2B Gateway (EDI / AS2) | integration | S17 | source-themed design proposal |
int-esb | Legacy ESB / Point-to-Point Middleware | integration | S28, S49, S57 | source-described baseline element |
int-events | Event Streaming Backbone | integration | S20, S57 | source-themed design proposal |
int-ipaas | iPaaS & Integration Orchestration | integration | S15, S57 | source-themed design proposal |
int-mft | Managed File Transfer | integration | S17 | source-themed design proposal |
int-queue | Message Queue Broker | integration | S20 | source-themed design proposal |
int-schema | Schema & Contract Registry | integration | S16, S20 | source-themed design proposal |
ops-aiops | AIOps & Event Correlation | operations | S37 | source-themed design proposal |
ops-backup | Backup & Immutable Backup Platform | operations | S38 | source-themed design proposal |
ops-cyber-vault | Cyber Recovery Vault | operations | S38 | source-themed design proposal |
ops-dem | Synthetic Monitoring, RUM & DEM | operations | S37 | source-themed design proposal |
ops-dr | DR Orchestration & Recovery Runbooks | operations | S38 | source-themed design proposal |
ops-incident | Incident Management & On-Call Paging | operations | S36, S37 | source-themed design proposal |
ops-observability | Observability Platform (metrics / logs / traces) | operations | S37 | source-themed design proposal |
ops-otel | Telemetry Pipeline (OpenTelemetry) | operations | S37 | source-themed design proposal |
cf-connect | Hybrid Connectivity | platform | S22, S23 | source-themed design proposal |
cf-dns-edge | DNS, Traffic Management & CDN | platform | S22, S30 | source-themed design proposal |
cf-k8s | Container Platform (managed Kubernetes) | platform | S32 | source-themed design proposal |
cf-landing | Cloud Landing Zones & Account Structure | platform | S22, S23 | source-themed design proposal |
cf-network | Network Hub & Segmentation | platform | S22, S23 | source-themed design proposal |
cf-paas | Managed PaaS & Serverless Runtimes | platform | S21, S30 | source-themed design proposal |
cf-vm | VM Estate (rehost landing) | platform | S27, S54 | source-themed design proposal |
edge-sites | Edge Locations | platform | S50 | source-themed design proposal |
onprem-dc | On-Premises Data Center | platform | S23, S28 | source-described baseline element |
pe-artifacts | Artifact & Container Registry | platform | S34 | source-themed design proposal |
pe-cicd | CI/CD Pipelines | platform | S34 | source-themed design proposal |
pe-golden | Golden Path Templates | platform | S24 | source-themed design proposal |
pe-iac | IaC & Environment Provisioning (GitOps) | platform | S33 | source-themed design proposal |
pe-idp | Internal Developer Portal & Service Catalog | platform | S24 | source-themed design proposal |
pe-policy | Policy-as-Code Engine | platform | S33, S46 | source-themed design proposal |
pe-scm | Source Control & Code Review | platform | S33, S34 | source-themed design proposal |
sec-ciam | Customer & Partner Identity (CIAM) | security | S25, S17 | source-themed design proposal |
sec-edge | WAF, DDoS & Bot Protection | security | S25, S30 | source-themed design proposal |
sec-endpoint | EDR / XDR | security | S25 | source-themed design proposal |
sec-idp-workforce | Workforce Identity Provider | security | S25 | source-themed design proposal |
sec-iga | Identity Governance & Administration | security | S25 | source-themed design proposal |
sec-kms | KMS / HSM, PKI & Certificate Lifecycle | security | S25 | source-themed design proposal |
sec-pam | Privileged Access Management | security | S25 | source-themed design proposal |
sec-pdp | Zero-Trust Policy Decision Point | security | S25 | source-themed design proposal |
sec-posture | CNAPP (CSPM / CWPP) & Vulnerability Management | security | S25, S34 | source-themed design proposal |
sec-secrets | Secrets Management | security | S25, S33 | source-themed design proposal |
sec-siem | SIEM & Security Analytics | security | S25, S37 | source-themed design proposal |
sec-soar | SOAR & Response Automation | security | S25, S37 | source-themed design proposal |
sec-sse | SSE (SWG / CASB / DLP) | security | S25 | source-themed design proposal |
sec-workload-id | Workload Identity & Service Identity (mTLS) | security | S25, S31 | source-themed design proposal |
The brief's required content per view, restated as each view's coverage checklist (also visible in-app under “About this view”), with the honesty notes that qualify the coverage.
| View | Required content (checklist) | Honesty notes |
|---|---|---|
| Executive Enterprise Overview |
| Representative nodes only at this altitude; drill into domain views for completeness. Cross-cutting layers (security, observability, governance, FinOps) appear as capability bands. |
| Business Capability & Value-Stream Architecture |
| Heat-map values (business_purpose field) are placeholders pending org scoring. Capability maturity requires Phase-1 workshops. |
| Product, Platform & Portfolio Architecture |
| Disposition field (reuse/new/replace-retire) drives the portfolio color-coding. Funding model = placeholder pending P0; product-vs-project distinction per S9/S59. |
| Application & Domain Architecture |
| Extraction criteria for module->service decisions live in ADR-05. svc-order owns the order transactional boundary; saga compensation in svc-fulfillment. |
| Integration, API, B2B, Messaging & Event Architecture |
| Every edge carries protocol/auth/failure metadata - click any relationship. Queue-vs-stream selection tree in the integration catalog doc. |
| Data, Analytics, Lakehouse & Governance Architecture |
| Mesh = operating model, lakehouse = estate, fabric = tooling claim (ADR-08). Zone promotion requires quality gates. Classification tags drive masking + access. |
| Enterprise AI, ML, GenAI, RAG & Agentic Architecture |
| Agents hold 'transition' status deliberately: production autonomy is gated by gov-ai (phase-6 exit criteria). No component calls model providers directly. |
| Cloud, Hybrid, Multi-Region, Infrastructure & Edge |
| Multi-AZ is the baseline; multi-REGION is open decision OD-01 - deliberately not drawn until priced against the BIA. Multi-cloud requires ADR-03 justification. Workload placement criteria in ADR-04. |
| Platform Engineering & Internal Developer Platform |
| Platform SLOs + adoption metrics are the team's KPIs (R-08 mitigation). Golden paths make compliance the default, not a gate. |
| DevSecOps & Software Supply Chain |
| Admission verification is the enforcement point (strongest layer): unsigned/unattested images do not schedule. Emergency-release path RB-14 rehearsed. |
| Enterprise Security & Zero Trust |
| Every control maps to assets in controls.json - the Controls tab shows the mapping. Regulatory/privacy overlays are configurable (A-11); trust-zone crossings are the boundary set. |
| Observability, SRE, Operations & AIOps |
| AIOps is optional + hygiene-gated: correlation on noisy telemetry automates confusion. Telemetry retention/redaction is a cost AND privacy control. |
| High Availability, DR, Cyber-Recovery & Continuity |
| ALL RTO/RPO values are tier-band placeholders pending BIA (A-05/A-07). Scenario coverage: AZ loss (multi-AZ), region loss (OD-01 - open), dependency loss (degradation matrices), cyberattack (vault), operator error (PITR + GitOps revert). |
| Architecture Governance, Portfolio & FinOps |
| Governance bodies connect to what they govern - the edges ARE the operating model. Exception expiry is automated, not aspirational (PR-12). |
| Current -> Transition -> Target & Roadmap |
| Use Compare mode (toolbar) to diff states. The current state is an ILLUSTRATIVE baseline (A-01) - Phase 1 discovery replaces it with evidence. |
Controls cite the source sections that motivate them; enforcement detail is proposal. Every control maps to concrete assets
(full mapping in the app's security view and data/controls.json).
| ID | Control | Source refs | Applies to (first assets) |
|---|---|---|---|
| C-ID-01 | Workforce SSO with phishing-resistant MFA | S25 | sec-idp-workforce, ch-employee-workspace, pe-idp, ops-observability, saas-collab, saas-itsm … |
| C-ID-02 | Customer & partner identity via CIAM | S25 | sec-ciam, ch-web, ch-mobile, ch-partner-portal |
| C-ID-03 | Privileged access is JIT, vaulted and recorded | S25 | sec-pam, cf-landing, onprem-dc, cf-k8s, db-operational |
| C-ID-04 | Workload identity replaces static service credentials | S25 | sec-workload-id, cf-k8s, svc-order, svc-billing, ai-tools, pe-cicd |
| C-ID-05 | Joiner-mover-leaver automation with access reviews | S25 | sec-iga, saas-hris, sec-idp-workforce |
| C-NET-01 | Edge protection on all internet ingress | S25 | sec-edge, ch-web, ch-mobile, ch-partner-portal, int-apigw |
| C-NET-02 | Deny-by-default segmentation with private endpoints | S25 | cf-network, cf-k8s, db-operational, data-lakehouse, ai-vector |
| C-NET-03 | Hybrid connectivity redundancy | S22, S23 | cf-connect, onprem-dc |
| C-APP-01 | OAuth2/OIDC discipline on every API | S16, S25 | int-apigw, app-bff-customer, app-bff-partner, svc-order, svc-billing, ai-gateway |
| C-APP-02 | Schema validation and input handling at boundaries | S25 | app-bff-customer, app-bff-partner, svc-order, svc-customer, int-apigw |
| C-APP-03 | Rate limiting, quotas and abuse monitoring | S25 | int-apigw, app-bff-partner, ai-gateway |
| C-APP-04 | mTLS / service identity on sensitive internal paths | S25 | sec-workload-id, svc-billing, svc-customer, ai-rag, db-operational |
| C-APP-05 | Secure session and token handling on channels | S25 | ch-web, ch-mobile, ch-partner-portal, sec-ciam |
| C-DP-01 | Classification drives policy | S19 | data-catalog, data-lakehouse, dp-customer360, dp-orders, ai-vector, svc-document |
| C-DP-02 | Encryption at rest with owned keys | S25 | sec-kms, db-operational, data-lakehouse, ai-vector, ops-backup |
| C-DP-03 | Masking / tokenization outside production need-to-know | S25 | data-lakehouse, dp-customer360, ai-embed, db-operational |
| C-DP-04 | Retention, deletion and legal hold per record class | S25 | svc-document, data-lakehouse, ops-backup, saas-collab |
| C-DP-05 | Data residency overlay (configurable) | S25 | cf-landing, data-lakehouse, ai-models-hosted |
| C-CLD-01 | Landing-zone guardrails as code | S22, S33, S46 | cf-landing, pe-policy |
| C-CLD-02 | IaC-only provisioning with drift detection | S33 | pe-iac, cf-landing, cf-k8s |
| C-CLD-03 | Hardened baselines, patching and admission control | S25 | cf-k8s, cf-vm, pe-artifacts |
| C-CLD-04 | Continuous posture and workload protection | S25 | sec-posture, cf-landing, cf-k8s |
| C-SC-01 | Security scanning gates in CI | S34 | pe-cicd, pe-scm |
| C-SC-02 | SBOM, signing and provenance verification | S25 | pe-cicd, pe-artifacts, cf-k8s |
| C-SC-03 | Branch protection and deploy separation of duties | S25 | pe-scm, pe-cicd |
| C-SC-04 | Vulnerability lifecycle with expiring exceptions | S34, S25 | sec-posture, pe-cicd, saas-itsm |
| C-INT-01 | Contract and schema governance | S16, S20 | int-schema, int-apim, int-events |
| C-INT-02 | DLQ, replay and poison-message handling | S20 | int-events, int-queue, svc-fulfillment, svc-notify, int-b2b |
| C-INT-03 | Idempotent consumers and deduplication | S25 | svc-fulfillment, svc-notify, svc-document, data-stream-proc |
| C-INT-04 | Governed file transfer integrity | S17 | int-mft, int-b2b, ext-partners |
| C-INT-05 | Reconciliation on financial and partner flows | S17 | svc-billing, saas-erp, ext-payment, int-b2b |
| C-AI-01 | All model access through the AI gateway | S41, S42 | ai-gateway, ai-models-hosted, ai-models-self, ai-rag, ai-agent-orch |
| C-AI-02 | Prompt-injection defense and output validation | S42 | ai-guardrails, ai-gateway, ai-agent-orch |
| C-AI-03 | Authorization-aware retrieval with provenance | S41, S42 | ai-rag, ai-vector, ai-embed, data-catalog |
| C-AI-04 | Agent tools are allowlisted, scoped and sandboxed | S42 | ai-tools, ai-agent-orch, int-apigw |
| C-AI-05 | Human approval and kill switch for high-impact actions | S42 | ai-hitl, ai-agent-orch, ai-gateway |
| C-AI-06 | AI evaluation, drift and cost monitoring | S41, S37, S39 | ai-observe, ai-mlplat, ai-gateway, fin-tooling |
| C-OPS-01 | Standard telemetry with correlation ids | S37 | ops-otel, ops-observability, cf-k8s, int-apigw, svc-order |
| C-OPS-02 | Synthetic and real-user monitoring of key journeys | S37 | ops-dem, ch-web, ch-partner-portal |
| C-OPS-03 | SIEM onboarding is part of go-live | S25 | sec-siem, cf-landing, int-apigw, ai-gateway |
| C-OPS-04 | Automated response with human gates | S25 | sec-soar, sec-siem, sec-idp-workforce |
| C-RES-01 | Backups with immutability and tested restores | S38 | ops-backup, db-operational, data-lakehouse, app-legacy-core |
| C-RES-02 | Isolated cyber-recovery vault | S38 | ops-cyber-vault, ops-backup |
| C-RES-03 | Tiered DR runbooks, rehearsed | S38 | ops-dr, svc-order, db-operational, int-events |
| C-RES-04 | Multi-AZ by default for critical tiers | S38, S30 | cf-k8s, db-operational, int-events, data-lakehouse |
| C-GOV-01 | Decisions and exceptions are recorded and expiring | S45 | gov-arb, gov-ea-repo |
| C-GOV-02 | Tagging, allocation, budgets and anomaly detection | S39 | fin-tooling, cf-landing, pe-policy |
| C-GOV-03 | Control evidence retention | S25 | saas-itsm, gov-ea-repo, sec-siem |
| C-PRV-01 | Privacy overlay: consent, minimization, DSR readiness | S19 | svc-customer, dp-customer360, ai-embed, svc-document |