One card per instrument. Definitions live in Part I; these are for the desk.
Second row source: domain-shape facts per effectful operation — inverse exists? value decays? reshapeable (idempotent / commutative / append-only)? · change-driver facts per rule set / data class — how often does the governing logic change, under whose control? (PFD’s change-driver analysis feeds here; presses in combination, rarely alone.)
Entry gate: priced (a nine has a price; “what changes in the 53rd minute?”) · scoped (per operation / data class / path) · decomposed (“team independence” → ownership ≠ release independence; “audit” ≠ replay) · triaged (requester’s clock vs system’s clock; observed failure ≠ stated target) · contradictions surfaced early.
| Axis | Values (null first) |
|---|---|
| Deployment topology | single deployable (± modules; ± role-selective activation) / multiple / unified runtime / serverless |
| Composition substrate | direct / event-based / streaming |
| Read/write model | unified (+ chain rungs) / separated |
| State storage | current-state (+ audit log) / event-sourced |
| Persistence | single shared / distributed shared / sharded (→ cells) / per-component / polyglot |
| Recovery (no null) | design-out / compensate (BER) / degrade-and-continue (FER) |
Values apply at demand scope. Hybrids are compositions: parts + boundary cost. Deployment prices two countables: release coupling + delivery plumbing (pipelines, the version matrix) bill to the artifact; scaling shape and runtime blast bill to the unit. Unique container: strict × multi-region × zero-loss on one data class → distributed shared only.
Would a second copy help?
Time-answer triage: requester’s clock (statutory window — inert) vs system’s clock (response target — presses).
hardware sizing → cache → coalescing → replicas → projections
↑ the axis move
Thin tiers (LB, cache, coalescer, admission gate) own no business logic and no data of record → never in the vector. Hardware rung’s ceiling is economic: it ends where the working set or write rate outgrows one box’s price curve.
next_step)Conflict rule: opposing pressures on one axis → different scopes: split at the boundary (pay: contract, consistency decay, translation seam, ops seam) · same scope: decompose further · still opposed: contradiction → renegotiation menu with prices (bend the softest demand first; every branch re-enters the derivation).
Refusals: targets, recovery ties, contradiction choices, product picks.
Consistency lens, per operation: guarantee + mechanism + failure behavior. Guarantee without mechanism = wrong vector or fake answer. One-bit labels banned in the system’s own docs.
Budget arithmetic:
Pre-build: load models (with correlation), capacity vs rung ceilings, failure injection per lens row.
Audit — for every held position: name the answer that forces it. Silence = debt, by construction. Unchanged answers must derive “no change.”
Increment — a changed answer implicates exactly the axes its rows press; re-derive those; the rest is untouched by construction. Merges are outputs too.
Path — deltas don’t commute. Constraints per intermediate: operable · affordable · calendar-feasible (dual state must not span a freeze wall). Weigh by six indicators (reversibility, intermediate feasibility, coupling, dual-state duration, dependency, failure amplification) — reject by named indicator, never by weighted sum. Reversible deltas early; one-way doors late. Scaffolds are allowed when priced with their own demolition.
Trail — per axis move: position · forcing answers · mechanism · costs accepted · revisit when.