Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Quick Reference Cards

Use these cards when reviewing a design. They compress the book into questions a team can answer in a meeting.

Pillar Cards

PillarProduction questionRequired artifact
EvaluationHow do we know behavior is good enough?golden fixtures, rubric evals, release gate
Typed workflowsWhat states and transitions are legal?transition table, domain events, data constraints
Human controlWhich actions require accountable review?approval policy, review queue, reason codes
ObservabilityWhat happened, why, at what cost, and with what evidence?traces, semantic events, audit records
Security and governanceWhat must never leak, execute, or silently decide?threat model, tool matrix, retention policy
EconomicsCan the workflow scale without destroying margin?cost model, routing policy, retry budget
DistributionHow does the buyer inspect trust?demo, eval report, audit packet, security note

Design Review Questions

QuestionGood answer shape
What is the unit of work?case, ticket, claim, account, session, or task
What is the truth source?typed state plus evidence and audit records
What can the model mutate?drafts and proposals by default; sensitive transitions require approval
What blocks release?hard invariant failure, high-risk fixture regression, unsafe tool access
What proves the decision later?evidence packet, prompt/model versions, human action, audit event
What cost should rise with risk?review depth and stronger model routes
What cost should fall with scale?deterministic preprocessing, caching, batching, better routing

Failure Diagnosis Cards

SymptomLikely missing pillar
prompt feels better but production worsensevaluation
same case appears in impossible statetyped workflow
reviewers rubber-stamp AI outputhuman control
incident cannot be reproducedobservability
uploaded text gives the model orderssecurity
adoption raises losseseconomics
buyer likes demo but will not buydistribution

Minimum Serious System

A serious production AI system should have:

  • one golden dataset
  • one adversarial fixture set
  • one typed transition table
  • one human approval boundary
  • one semantic event schema
  • one tool-permission matrix
  • one cost model
  • one audit packet example
  • one buyer-facing trust artifact

If any item is missing, the design may still be useful, but it is not mature.