Quick Reference Cards
Use these cards when reviewing a design. They compress the book into questions a team can answer in a meeting.
Pillar Cards
| Pillar | Production question | Required artifact |
|---|---|---|
| Evaluation | How do we know behavior is good enough? | golden fixtures, rubric evals, release gate |
| Typed workflows | What states and transitions are legal? | transition table, domain events, data constraints |
| Human control | Which actions require accountable review? | approval policy, review queue, reason codes |
| Observability | What happened, why, at what cost, and with what evidence? | traces, semantic events, audit records |
| Security and governance | What must never leak, execute, or silently decide? | threat model, tool matrix, retention policy |
| Economics | Can the workflow scale without destroying margin? | cost model, routing policy, retry budget |
| Distribution | How does the buyer inspect trust? | demo, eval report, audit packet, security note |
Design Review Questions
| Question | Good answer shape |
|---|---|
| What is the unit of work? | case, ticket, claim, account, session, or task |
| What is the truth source? | typed state plus evidence and audit records |
| What can the model mutate? | drafts and proposals by default; sensitive transitions require approval |
| What blocks release? | hard invariant failure, high-risk fixture regression, unsafe tool access |
| What proves the decision later? | evidence packet, prompt/model versions, human action, audit event |
| What cost should rise with risk? | review depth and stronger model routes |
| What cost should fall with scale? | deterministic preprocessing, caching, batching, better routing |
Failure Diagnosis Cards
| Symptom | Likely missing pillar |
|---|---|
| prompt feels better but production worsens | evaluation |
| same case appears in impossible state | typed workflow |
| reviewers rubber-stamp AI output | human control |
| incident cannot be reproduced | observability |
| uploaded text gives the model orders | security |
| adoption raises losses | economics |
| buyer likes demo but will not buy | distribution |
Minimum Serious System
A serious production AI system should have:
- one golden dataset
- one adversarial fixture set
- one typed transition table
- one human approval boundary
- one semantic event schema
- one tool-permission matrix
- one cost model
- one audit packet example
- one buyer-facing trust artifact
If any item is missing, the design may still be useful, but it is not mature.