Skip to harness content
Open technical reference map

Assurance model

Layer 0, 13 production domains, and three proof levels

Layer 0 commissions the foundation before non-documentation delivery. The 13 production domains evaluate applicable production obligations. Proof levels state how strongly the result is supported.

Layer 0 — Foundation / Good Looks Like

7 capabilities and 14 controls bind requirements, quality attributes, architecture, data, engineering strategy, ownership, and risk.

product-domain

Product & Domain

Establish the product outcome, users, domain language, invariants, and scope boundaries before delivery work begins.

  • FND-PRODUCT-001Target users, desired outcomes, in-scope behavior, exclusions, and success measures are explicit and reviewable.
  • FND-DOMAIN-001Domain terminology, core entities, ownership boundaries, and business invariants are defined without conflicting meanings.
requirements-acceptance

Requirements & Acceptance

Turn the requested outcome into bounded, testable behavior and explicit acceptance conditions.

  • FND-REQ-001Functional requirements, constraints, assumptions, exclusions, and external dependencies are testable and traceable to the requested outcome.
  • FND-ACCEPTANCE-001Acceptance criteria cover critical success paths, negative paths, boundary cases, and externally blocked conditions.
quality-attributes

Quality Attributes

Commission measurable non-functional targets and the failure behavior expected from the workload.

  • FND-QUALITY-001Performance, scale, availability, security, privacy, accessibility, observability, and cost targets are explicit where applicable.
  • FND-FAILURE-001Critical failure modes, degraded behavior, recovery objectives, and unsafe outcomes are identified before implementation.
architecture-boundaries

Architecture & Boundaries

Define the reference architecture, dependency direction, and trust boundaries that keep delivery work out of spaghetti paths.

  • FND-ARCH-001The reference architecture names modules, responsibilities, dependency direction, asynchronous boundaries, and the normal delivery path.
  • FND-BOUNDARY-001Data, identity, tenant, provider, network, runtime, and human-authority boundaries are explicit with named owners.
data-transactions

Data & Transactions

Establish authoritative data ownership and transaction invariants before features depend on them.

  • FND-DATA-001Authoritative data sources, schemas, classification, retention, residency, deletion, migration, and recovery expectations are defined.
  • FND-TRANSACTION-001Transaction boundaries, consistency, idempotency, concurrency, ordering, reconciliation, and rollback rules are explicit and testable.
engineering-test-strategy

Engineering & Test Strategy

Define how changes are built, tested, reviewed, promoted, and kept maintainable.

  • FND-ENGINEERING-001Coding standards, module boundaries, branch policy, environments, dependency policy, migration policy, and delivery commands are commissioned.
  • FND-TEST-001The test and evaluation strategy assigns appropriate unit, integration, contract, end-to-end, load, security, and domain proof to owned boundaries.
decisions-ownership-risk

Decisions, Ownership & Risk

Make hard-to-reverse decisions, operational ownership, approval boundaries, and residual risk explicit.

  • FND-DECISION-001Hard-to-reverse product, architecture, data, provider, security, and operational decisions have owners, rationale, alternatives, and review triggers.
  • FND-RISK-001Known risks, Red Zone actions, approvers, escalation paths, runbooks, rollback ownership, and accepted residual risk are recorded.

Production domains

Each domain declares dependencies, capabilities, and controls. Applicability resolves to evidence, failure, or an explicit reason for non-applicability.

Profiles

Profiles configure which production obligations apply. They do not redefine the 13-domain taxonomy.

prototype

The commissioned adapter uses this profile to resolve applicable domain controls and proof obligations.

production

The commissioned adapter uses this profile to resolve applicable domain controls and proof obligations.

enterprise

The commissioned adapter uses this profile to resolve applicable domain controls and proof obligations.

regulated

The commissioned adapter uses this profile to resolve applicable domain controls and proof obligations.

Proof levels

01

Structural

Required artifacts, schemas, bindings, and coverage are valid.

02

Semantic

Commissioned adapters and thresholds prove the intended behavior.

03

Authoritative

An independent trusted runner, provider, signer, or authority attests the result with rollback-resistant state.