← Architecture review

Architecture review workflow

The review is a bounded sequence from one production question to one defensible decision. Each stage has a purpose, an input, and an observable output.

Phase 1Context assembly
Frame · Intake · Reconstruct
Phase 2Empirical testing
Select trajectories · Test hypotheses
Phase 3Remediation & governance
Findings · Actions · Decision
01

Frame the decision

Name the system, workflow, lifecycle stage, operating conditions, consequential actions, decision owner, and exclusions.

Input: decision requestOutput: review charter
02

Intake the evidence

Inventory existing architecture views, contracts, configurations, traces, evals, deployment material, and recovery procedures. Record versions, environments, dates, and gaps.

Input: existing artifactsOutput: evidence index + gap list
03

Reconstruct the as-built system

Compare what the team says exists with what artifacts and runtime evidence demonstrate. Map purpose, authority, agent nodes, tools, state, memory, data, boundaries, controls, operations, and ownership.

Input: As-Built workbookOutput: observed architecture + unknowns
04

Select critical trajectories

Choose a representative success path and the paths that carry production risk: consequential action, degraded dependency, interruption/recovery, unauthorized request, or real failure.

Input: system map + evidenceOutput: trajectory set
05

Test the highest-risk hypotheses

At each seam, ask what can be wrong, stale, malicious, duplicated, ambiguous, outside authority, undetected, or unrecoverable. Run only approved, bounded probes that can change the conclusion.

Input: trajectories + unknownsOutput: supported, rejected, or open hypotheses
06

Write atomic findings

Describe each demonstrated failure as condition → trigger → failure → consequence → control gap, with severity, confidence, affected boundary, evidence, and detection/recovery implications.

Input: evidence + hypothesesOutput: prioritized findings
07

Sequence remediation

Define the required capability, containment or structural change, owner, horizon, release, dependencies, acceptance evidence, and residual risk. Do not stop at “add guardrails.”

Input: findingsOutput: action register
08

Decide and hand off

Record proceed, proceed with conditions, do not proceed/expand, or insufficient evidence. Include blockers, accepted residual risks, expiry, next review trigger, and accountable owner.

Input: actions + acceptance evidenceOutput: decision record + handoff
The stopping rule: Stop collecting when the evidence is sufficient to make the named decision, or state clearly that it is not. The goal is not a complete inventory of everything; it is a defensible next decision.

Where the workbooks fit

Return to the architecture review offer →