# AEGIS — Architecture Governance Model - **Document ID:** ARCH-34 - **Phase:** E.1 — Governance Foundation - **Status:** Draft for review (post four-reviewer discipline) - **Version:** 0.1 - **Date:** 2026-07-10 - **Owner:** Chief Security Architect --- ## 1. Purpose Define who governs the AEGIS architecture, how, and with what authority. Implements mandate #51. Governance is what keeps architecture a strategic asset rather than a static document set. **Design intent.** Roles are role-based, not person-based. Every role has documented responsibilities, a documented approver of decisions, and a documented backup. No single individual is a governance SPOF. ## 2. Roles ### 2.1 Chief Security Architect (CSA) - **Purpose.** Custodian of the Engineering Constitution and Platform Design Principles. Final approver on principle amendments, Kernel-critical architecture, threat model, and Architecture Freeze milestones. - **Authority.** May halt a design proceeding to implementation if it violates principles. - **Backup.** Deputy CSA rotated per policy; documented handoff for prolonged absences. ### 2.2 Platform Architect (PA) - **Purpose.** Cross-subsystem consistency. Owns the ARCH-* corpus's coherence. Resolves cross-team architectural conflicts. Sponsors ADRs that span multiple subsystems. - **Authority.** Blocks integration of subsystem work that conflicts with global architecture. - **Reports to.** CSA on architecture questions; independent on engineering coordination. - **Backup.** Named deputy per rotation. ### 2.3 Security Reviewer (SR) - **Purpose.** Executes Security Design Reviews (ARCH-36). One or more reviewers per subsystem, drawn from a qualified pool. - **Authority.** Assigns Review verdicts (Approved / Conditional / Rejected). Cannot self-approve; independence enforced. - **Backup.** Reviewer pool ensures at least two qualified reviewers per critical subsystem area. ### 2.4 Operational Reviewer (OR) - **Purpose.** Executes Operational Reviews (part of ARCH-36 gate 3). Evaluates recovery, availability, maintenance, observability, upgrade safety, and long-term operability. - **Authority.** Blocks progression on operational grounds. - **Backup.** Rotating operational-lead assignment. ### 2.5 Implementation Owner (IO) - **Purpose.** Named engineering lead accountable for a specific subsystem's implementation, its adherence to architecture, and its Debt Register entries. - **Authority.** Directs implementation decisions within the approved architecture scope. - **Reports to.** PA on architectural questions; SR/OR on gates; CSA on principle-scope issues. - **Backup.** Named deputy IO per subsystem. ## 3. Additional Governance Roles - **Auditor.** Independent-from-line-of-management observer. Sees every ceremony, every gate exception, every Debt Register entry, every ADR. Cannot make architecture decisions; ensures visibility. - **Owner (executive).** Referenced in ARCH-14/22/29 as final approver for the highest-consequence ceremonies (Root-of-Trust rotation, principle amendments, hidden-debt-audit conclusions). ## 4. Governance Meetings and Cadence | Forum | Attendance | Cadence | Purpose | |---|---|---|---| | **Architecture Council** | CSA (chair), PA, SR pool leads, OR lead, Auditor | Biweekly | Standing architecture questions, ADR pipeline, Debt trend | | **Design Review Board** | CSA, PA, SR, OR, IO of subsystem in scope, Auditor | Per subsystem gate | Review + verdict at each Security Design Review gate | | **Continuous Architecture Review** | CSA, PA, SR pool leads, OR lead, Auditor, Owner | Annual + on trigger events | ARCH-* corpus health, principle drift, threat-landscape response | | **Architecture Freeze Board** | CSA, PA, Owner, Auditor | Once (before implementation) | Approve Architecture Freeze milestone | | **Post-Incident Architecture Review** | CSA, PA, SR, OR, Auditor | Per SEV-1 incident, within 10 business days | ARCH-* diffs required by the incident | Cadence changes require an ADR. ## 5. Decision Rights | Decision class | Proposer | Reviewer | Approver | |---|---|---|---| | ADR (subsystem scope) | IO or SR | PA | CSA (if principle-touching) or PA | | ADR (cross-subsystem) | PA | CSA + SR pool | CSA | | Principle amendment | CSA | PA + Auditor | Owner (per ARCH-33 §5) | | Kernel-critical architecture change | PA | SR + OR + Auditor | CSA + Owner (ceremony) | | Subsystem architecture change | IO | SR + OR | PA (SR-scope) or CSA (principle-scope) | | Debt Register entry | Anyone | SR + OR | Owner + Auditor sign-off | | Debt renewal | IO | SR | Owner | | Debt retirement | IO | SR + Auditor | PA | | Governance change | CSA | Owner + Auditor | Owner | | Architecture Freeze | CSA | Owner + Auditor | Owner (ceremony) | **Rule of two.** No single individual can serve two of {Proposer, Reviewer, Approver} for the same decision. This enforces separation of duties across governance. ## 6. Escalation - **Deadlock at Design Review Board.** PA escalates to Architecture Council; unresolved → CSA decides with documented reasoning. - **Principle-conflict with commercial pressure.** CSA + Auditor + Owner form a triad; CSA's principle-guardianship is preserved. - **Debt-renewal disagreement.** Escalates to Owner + Auditor; documented rationale. ## 7. Independence Guarantees - SR and OR pools cannot review their own team's subsystem — cross-team review is mandatory. - Auditor's read access spans everything; write access is nil (observers, not deciders). - CSA's decisions are auditable; large or contested decisions are ceremony-audited. ## 8. Independent Architecture Review - **F-1.** *Governance introduces overhead.* Cadence is bounded; per-decision approver mapping avoids meeting-per-decision. - **F-2.** *Role assignment sustainability.* Backup deputies; rotation; ownership matrix in ARCH-23. - **F-3.** *Auditor could be captured.* Rotation + external audit annually; multiple auditors permitted. ## 9. Adversarial Architect Review - **A-1.** *Insider serves as both Proposer and Approver.* Rule of two structurally forbids. - **A-2.** *Attacker compromises an SR account to approve bad architecture.* MFA + ceremony for high-impact + Auditor visibility + cross-team reviewers. - **A-3.** *CSA compromise.* CSA operations audited by Auditor + Owner; principle changes require Owner; Kernel-critical requires ceremony with multiple parties. ## 10. Operational Reliability Review - **O-1.** Meeting cadence sustainable. - **O-2.** Escalation paths documented + drilled. - **O-3.** Role transitions during personnel changes have a runbook. - **O-4.** External audit provides governance-health signal. ## 11. Self-Critique - **S-1.** *Small teams may not have distinct SR/OR pools.* At small scale, PA may serve dual role — documented as a Debt Register entry with target resolution when team scales. - **S-2.** *"Rule of two"* is strong but can slow small teams. Accepted cost of governance. - **S-3.** *Auditor role* depends on culture + funding. External-audit backup covers. ## 12. First-Target Analysis and Redesign **Target:** the Chief Security Architect role. It's the single most consequential role in governance. If the CSA is compromised or captured (organizationally), principle-guardianship weakens quietly. **Response:** 1. **Auditor + Owner triad** for principle-touching decisions — CSA cannot unilaterally change principles. 2. **Ceremony recording** of significant CSA decisions. 3. **CSA succession planning** documented; Deputy CSA rotated; institutional memory in ARCH-* corpus. 4. **External CSA advisor** engaged annually to review the CSA's decision pattern (Continuous Architecture Review, ARCH-47). 5. **Owner reserve powers** — Owner can invoke external CSA review at any time. **Second target:** Auditor capture. Response: rotation, external audit annually, multi-auditor permitted. ## 13. Decisions ### D-34-1. Five-role model with Rule of Two + Auditor - **Reason.** Mandate #51 + Zero SPOT applied to governance. ### D-34-2. CSA principle-guardianship balanced by Owner + Auditor triad on amendments - **Reason.** §12 first-target response. ## 14. Change Log - **0.1 (2026-07-10)** — Initial draft.