Architect Complete Suite
The definitive enterprise architecture collection containing all 294 Agent Skills. Spans business architecture, DDD, microservices, AI agents, cloud infrastructure, zero-trust security, reliability engineering, testing strategies, visual modeling, and technology selection at a 92% discount.
Works with every agent that reads SKILL.md — Claude Code, Cursor, Codex CLI, Gemini CLI, GitHub Copilot, Windsurf, OpenClaw, and more.
One payment, lifetime access. 290 skills unlock instantly in your library.
30-day refund guarantee
Instant unlock in your library
Free updates from the creator
What's included
290 skillsDesigns actionable alerting contracts: symptom-based triggers, routing matrices, deduplication, and runbook bindings.
Evaluates the Actor Model style: stateful actors, bounded mailboxes, supervision trees, cluster sharding, and persistence.
Designs an autonomous AI agent's runtime: authority, tool and side-effect controls, stop rules, delegation, oversight.
Architects multi-tier AI agent memory systems: short-term, episodic, semantic tiers, consolidation, and privacy rules.
Designs bounded AI agent memory lifecycles: classes, admission authority, conflict resolution, and forgetting.
Designs dynamic context assembly, token budgeting, caching boundaries, and compaction rules for AI agent runs.
Architects enterprise AI evaluation systems: offline golden benchmarks, online judge fleets, red teaming, and CI gates.
Selects AI foundation models: legal reasoning benchmarks, 128k context recall, and prompt caching token savings.
Maps your AI risks and policies to guardrails at input, context, output and tool boundaries, with failure rules.
Designs end-to-end AI system architecture: model lifecycle, data pipelines, serving topology, evaluation, and governance.
Designs AI evaluation frameworks: golden test suites, LLM-as-a-judge rubrics, bias mitigation, and CI/CD quality gates.
Designs AI tool routing layers: intent mapping, schema validation, disambiguation rules, and safe execution boundaries.
Governs API portfolios: cross-service contract standards, error and pagination profiles, stability tiers, and deprecation.
Designs API authentication and authorization contracts: token profiles, scopes, gateway validation, and revocation.
Designs unified API error contracts: RFC 9457 problem details, error code taxonomies, and sensitive data leakage defense.
Designs API query filtering, sorting, and field projection contracts: operator syntax, validation, and DoS query bounding.
Architects API gateway platforms: routing topologies, protocol mediation, authentication offloading, and rate limiting.
Specifies idempotency for side-effecting API calls: key scope, request equivalence, conflicts, replay and expiry.
Designs API collection pagination contracts: cursor tokens, keyset tie-breaking, page size caps, and stable traversal.
Designs API versioning and evolution strategies: compatibility rules, breaking change policies, and sunset schedules.
Architects application security architectures: OWASP controls, automated CI security gates, SBOMs, and supply chain trust.
Rates architectural complexity: McCabe cyclomatic complexity AST parsing, Martin coupling metrics, and CI gates.
Analyzes architectural constraints: mutability classification, regulatory boundaries, cost of compliance, and trade-offs.
Models architectural costs: serverless vs container crossover points, unit economics, and 3-year TCO projections.
Analyzes architecture pros/cons: GraphQL vs REST BFF, N+1 query defense, and sub-45ms p99 checkout execution.
Analyzes architectural risk: Failure Mode and Effects Analysis (FMEA), RPN scoring, and defense-in-depth mitigations.
Discovers architectural risks: impact-probability scoring, failure modes, mitigation controls, and residual risk registers.
Establishes architectural scope boundaries: in-scope vs out-of-scope matrices, non-goals, and scope change governance.
Analyzes architectural ROI: 5-year Discounted Cash Flow models, 34.2% IRR hurdle compliance, and Monte Carlo stress tests.
Analyzes stakeholder interests: hidden objections, organizational resistance, incentive alignment, and compromise paths.
Maps architectural stakeholders: power-interest grids, salience models, RACI decision rights, and engagement pathways.
Architects decision governance: MADR 3.0 standards, immutable decision lifecycles, and automated CI linters.
Audits systems against best practices: 12-factor compliance, API hygiene, cloud-native maturity, and remediation.
Authors architecture decision logs: consolidated ADR registries, cross-decision indexing, status tracking, and audit links.
Architects documentation appendixes: RFC 2119 glossaries, regulatory standards matrices, and data dictionaries.
Architects readiness checklists: declarative YAML schemas, dynamic applicability predicates, and 90-day waivers.
Architects review governance: multi-tier review rubrics, evidence-first intake, ARB charters, and disposition tracking.
Authors formal architecture specifications: system topologies, component contracts, invariants, and traceability matrices.
Detects architectural smells: cyclic dependencies, distributed monoliths, coupling metrics, and false-positive triage.
Architects specifications: IETF RFC 2119 normative keywords, embedded JSON Schema contracts, and CI linter gates.
Compares architectural styles: Event-Driven outbox patterns, synchronous REST traps, and sub-35ms p99 SLAs.
Architects deliverable templates: standard Markdown shapes, placeholder elimination linters, and CI quality gates.
Architects visual diagramming platforms: C4 model hierarchies, Plaintext Diagram-as-Code, and automated SVG builds.
Designs Argo CD GitOps architectures: Application sets, AppProjects, automated sync, self-healing, and sync-wave sequencing.
Designs AsyncAPI contracts for event-driven systems: channels, message schemas, broker bindings, and correlation rules.
Designs async HTTP operations: 202 Accepted polling contracts, job status lifecycles, and webhook completion callbacks.
Designs dynamic ABAC authorization policies: subject/resource attribute schemas, PDP/PEP engines, and conflict resolution.
Designs pod autoscaling control loops: custom KEDA metrics, scaling rules, stabilization windows, and flapping prevention.
Evaluates backend frameworks: startup times, memory footprints, developer ergonomics, and cloud-native runtime trade-offs.
Architects backend microservices: hexagonal boundaries, ports and adapters, outbox event relays, and resilient runtimes.
Architects client-specific BFF layers: tailored view models, downstream parallel aggregation, and mobile payload pruning.
Designs blue-green deployments: active/idle environment switch, synthetic qualification gates, and rollback tripwires.
Designs bounded production prompts: structured delimiters, few-shot exemplars, JSON schemas, and injection defense.
Designs bounded RAG pipelines: document ingestion, chunking rules, retrieval thresholds, citations, and abstention logic.
Architects business architecture: strategy mapping, value streams, business capabilities, and operating models.
Models BPMN 2.0 business processes: cross-functional swimlanes, message flows, and boundary error compensation.
Architects enterprise business capabilities: 3-tier capability maps, maturity scoring, and investment prioritization.
Maps business capabilities to application systems: realization matrices, redundancy detection, and system-of-record bounds.
Models operational business processes: BPMN 2.0 flows, decision gateways, exception routing, and handoff contracts.
Architects rule engines: DMN standards, Rete algorithms, conflict resolution, hot-reloading, and execution sandboxing.
Designs business workflow DAGs: step transitions, human checkpoints, retry timeouts, and compensation handlers.
Models C4 Level 1 system context: perimeter boundaries, external actor personas, and partner banking network links.
Models C4 Level 2 containers: deployable units, mTLS gRPC protocols, single-owner databases, and sub-45ms latency.
Models C4 Level 3 component boundaries: thread-pool bulkheads, transactional outbox relays, and gRPC contracts.
Models C4 Level 4 code diagrams: interface ports, constructor dependency inversion, and thread-safe DTO records.
Designs caching architectures: cache-aside patterns, TTL freshness models, event invalidations, and stampede defenses.
Selects caching technologies: complex data structures, sub-3ms latency, multi-AZ failover, and operational cost.
Designs canary releases: progressive traffic steps, statistical metric analysis, automated gates, and rollback tripwires.
Architects capacity planning: M/M/c queueing models, scheduled pre-warming, and 30% headroom governance.
Evaluates Cell-Based Architecture: cellular blast-radius boundaries, routing keys, state isolation, and failure limits.
Plans chaos experiments: steady-state hypotheses, fault injection blast radius, automated abort tripwires, and game days.
Validates readiness checklists: evidence attachment audits, applicability predicates, waiver lifecycles, and gating.
Architects CDC platforms: log-based Debezium pipelines, schema evolution contracts, outbox patterns, and event streaming.
Evaluates Clean Architecture style: dependency rules, framework-free domain cores, use cases, and testing trade-offs.
Architects cloud FinOps: Cost-per-Transaction unit economics, automated rightsizing, and 32.5% recurring savings.
Architects cloud landing zones: multi-account topology, Transit Gateway, IAM guardrails, and centralized egress inspection.
Selects enterprise cloud providers: European EBA sovereignty enclaves, sub-4ms Aurora databases, and FIPS HSMs.
Architects enterprise cloud security: multi-account landing zones, SCP guardrails, centralized egress firewalls, and CSPM.
Architects enterprise storage systems: block/object storage tiers, IOPS provisioning, replication, and lifecycle.
Selects container runtimes: native Kubernetes CRI containerd, gVisor syscall sandboxing, and sub-1.5s startup.
Architects container infrastructure: runtime engines, cgroup resource slicing, OCI registry topologies, and isolation.
Architects container runtimes: CRI engine selection, kernel isolation, gVisor sandboxing, seccomp, and runtime security.
Plans tool-agnostic consumer/provider contract testing across services: seams, provider states, versions, deploy checks.
Designs safe chaos experiments: steady-state metrics, fault injection, blast-radius bounds, and automated abort triggers.
Plans controlled stress testing: breakpoint discovery, graceful degradation, circuit breaker trips, and recovery velocity.
Evaluates CQRS architecture style: command/query separation, asynchronous projections, eventual consistency, and trade-offs.
Architects enterprise KMS platforms: HSM topologies, envelope encryption, automated key rotation, and dual-custody rules.
Evaluates Data Mesh style: decentralized data ownership, data products, self-serve platforms, and federated governance.
Architects data pipelines: Apache Flink stateful streaming, exactly-once 2PC sinks, and non-halting DLQ isolation.
Designs data encryption: application-layer envelope encryption, FPE tokenization, AES-256-GCM, and FIPS HSM custody.
Designs data privacy architectures: purpose limitation, consent propagation, pseudonymization, and deletion.
Designs database indexes: composite column ordering, index selectivity, write-amplification bounds, and partial indexes.
Defines data retention: statutory retention schedules, automated S3 tiering, WORM legal holds, and cryptographic purging.
Evaluates database technologies: workload access patterns, columnar compression, and standard SQL time-series downsampling.
Designs database backup architectures: continuous WAL archiving, 5-minute RPO, automated restore drills, and WORM vaults.
Designs database sharding: horizontal range-hash partitions, MurmurHash3 routing, and cross-shard 2PC avoidance.
Designs database partitioning: composite range-hash keys, automated chunk lifecycle, and sub-15ms pruning queries.
Designs database replication: synchronous multi-AZ storage quorum, sub-1s cross-region lag, and RPO=0 automated failover.
Designs database migrations: zero-downtime expand-and-contract, adaptive throttling, and automated rollback.
Designs dead-letter queue pipelines: quarantine triggers, diagnostic headers, custody ownership, and safe redrive replay.
Designs graceful degradation and fallback strategies: cached stubs, partial results, staleness bounds, and disclosure.
Designs circuit breaker tripwires: sliding window thresholds, state transitions, fail-fast rules, and recovery probes.
Designs automated rollback systems: decision tripwires, state unwinding, traffic drainage, and schema compatibility.
Authors executable developer migration guides: prerequisites, ordered resumable steps, validation gates, and safe rollback.
Architects DevOps delivery systems: CI/CD pipeline governance, artifact provenance, security gates, and promotion.
Architects distributed caching: multi-tier cache topologies, XFetch stampede defense, and invalidate-on-commit contracts.
Designs distributed sagas: orchestration vs choreography, compensating actions, pivot transactions, and idempotency.
Designs distributed tracing architectures: OpenTelemetry spans, W3C trace context, tail sampling, and trace storage.
Architects business capability portfolios: 3-tier capability hierarchies, maturity heatmaps, and context mapping.
Designs strategic context maps: upstream-downstream models, Anti-Corruption Layers, OHS/PL, and relationship matrices.
Discovers domain entities: identity continuity, lifecycle transitions, invariants, and Value Object boundaries.
Designs domain event contracts: CloudEvents schemas, causation tracking, partition keying, and idempotency guarantees.
Models immutable domain business facts: naming, causal lineage, minimum payloads, and context-to-integration maps.
Architects rich DDD domain models: entity identities, immutable Value Objects, domain services, and invariant rules.
Designs DDD value objects: primitive obsession elimination, structural equality, immutability, and self-validation.
Designs DDD repository contracts: aggregate reconstitution, explicit queries, unit-of-work bounds, and zero N+1 traps.
Designs DDD aggregate boundaries: aggregate roots, encapsulation, transaction invariants, and domain event contracts.
Architects DDD aggregate portfolios: consistency boundaries, transactional invariants, event choreography, and persistence.
Architects edge computing systems: PoP topologies, edge-versus-origin compute tiers, and edge state synchronization.
Architects global edge infrastructure: Anycast routing, CDN caching tiers, edge workers, origin shielding, and sync.
Designs end-to-end deadline budgets, per-hop timeout subtraction, socket bounds, and distributed cancellation propagation.
Plans end-to-end journey testing: critical user flows, test data isolation, flake mitigation, and release gating criteria.
Plans engineering resources: Team Topologies structures, 70/20/10 capacity allocation, and skill gap remediation.
Authors engineering RFCs: proposal motivation, detailed design, trade-off alternatives, security, and rollout phases.
Architects enterprise architecture: BDAT blueprints, architecture review governance, transition roadmaps, and debt control.
Defines binding architecture policies: normative RFC 2119 rules, automated OPA gates, and 90-day waiver lifecycles.
Architects cloud migrations: Strangler Fig API proxies, dual-run shadow reconciliation, and sub-5s rollbacks.
Architects enterprise business process portfolios: process frameworks, governance models, and performance metrics.
Architects enterprise cloud networks: hub-and-spoke transit, CIDR IP planning, Direct Connect hybrid links, and firewalls.
Architects testing platforms: 70/20/10 test pyramids, Consumer-Driven Contract testing via Pact, and mutation testing.
Architects enterprise data governance: Data Mesh domain ownership, automated data contracts, and BCBS 239 lineage.
Architects enterprise data lakes: multi-zone medallion storage, Apache Iceberg ACID tables, and automated compaction.
Architects data platforms: self-service developer portals, decoupled storage/compute, and FinOps quota controls.
Architects data warehouses: Kimball dimensional models, star schemas, SCD Type 2 history, and sub-3s BI queries.
Architects enterprise databases: RDS Proxy connection multiplexing, polyglot persistence tiering, and sub-12ms query speed.
Architects continuous deployment: ArgoCD GitOps, progressive canary analysis, and sub-60s automated rollbacks.
Architects disaster recovery: Warm Standby multi-region pilot lights, Aurora Global DB, and 15-minute RTO.
Architects enterprise desktop apps: Tauri 2.0 Rust core, strict IPC command allowlists, and SQLCipher AES-256 storage.
Architects Docs-as-Code platforms: Git colocation, 90-day freshness review SLAs, and automated markdown linters.
Architects enterprise Domain-Driven Design: ubiquitous language catalogs, strategic context boundaries, and aggregate models.
Architects batch ETL platforms: Airflow DAG orchestration, Apache Spark WAP patterns, and automated ledger reconciliation.
Architects enterprise IAM systems: SSO federation, SCIM provisioning, privileged access (PAM), and zero-trust identity.
Architects enterprise mobile apps: Kotlin Multiplatform shared logic, native SwiftUI/Compose, and SQLDelight sync.
Architects active metadata platforms: OpenLineage collectors, column-level lineage graphs, and CI/CD blast-radius gates.
Architects observability platforms: OpenTelemetry standards, W3C TraceContext linking, and sub-5m root-cause identification.
Architects enterprise organization structures: Team Topologies, operating models, interaction modes, and governance rights.
Architects enterprise reference architectures: golden-path blueprints, standardized stacks, and governance baselines.
Architects enterprise releases: automated release trains, SLSA Level 3 attestations, and non-bypassable CI/CD cutover gates.
Architects enterprise resilience: thread-pool bulkheads, CoDel adaptive load shedding, and edge rate-limiting.
Architects scalable platforms: stateless container fleets, AWS Karpenter sub-45s scaling, and DB read-write splitting.
Architects enterprise search platforms: hybrid dense/sparse retrieval, OpenSearch clusters, and zero-downtime aliases.
Architects enterprise secret platforms: Vault HA clusters, KMS auto-unseal, tenant namespaces, and replication topologies.
Architects enterprise security: holistic zero-trust frameworks, defense-in-depth, threat governance, and control baselines.
Architects end-to-end solution architectures: cross-cutting system blueprints, integration views, and delivery roadmaps.
Architects value stream networks: stage boundaries, flow metrics, capability alignment, and operating topologies.
Architects vector databases: distributed Milvus clusters, HNSW indexing with SQ8 quantization, and sub-10ms recall.
Architects workflow platforms: state persistence, activity queues, signal/timer semantics, and durable execution engines.
Architects enterprise Zero Trust systems: NIST SP 800-207, continuous posture evaluation, PDP/PEP, and microsegmentation.
Models physical ERDs: Crow's Foot cardinalities, RESTRICT foreign keys, and covering composite index candidates.
Architects event streaming: Apache Kafka KRaft clusters, deterministic partition keys, and cooperative sticky rebalancing.
Designs async messaging between services: event vs command, topology, delivery, ordering, retries, replay, recovery.
Evaluates Event-Driven Architecture: temporal decoupling, event stream topologies, ordering, and consistency trade-offs.
Designs external customer SLAs: availability commitments, measurement windows, credit penalty tiers, and remedy claims.
Designs feature flag architectures: evaluation rules, targeting hashing, fallback states, and flag retirement lifecycles.
Plans FinOps waste reclamation: mandatory tag governance, automated anomaly detection, and $4.8M cost reductions.
Analyzes functional requirements: disambiguation, acceptance criteria, conflict resolution, and verification testability.
Architects GitOps delivery models: repo topologies, pull-based reconciliation, drift control, and secret management.
Designs GraphQL schemas: type definitions, query depth/complexity bounds, DataLoader N+1 mitigation, and Relay pagination.
Designs gRPC and Protobuf service contracts: proto3 schemas, field number evolution, rich status errors, and streaming.
Designs health check probes: startup, liveness, readiness separation, cascading failure prevention, and flap damping.
Designs Helm chart APIs: values schema contracts, template modularity, dependency locking, and release testing hooks.
Evaluates Hexagonal Architecture style: ports and adapters, framework-free domain core, and infrastructure pluggability.
Architects high-availability platforms: 3-AZ active-active meshes, sub-3s ARC evacuation, and error budgets.
Architects low-latency performance: DPDK kernel bypass, lock-free SPSC ring buffers, and sub-1,200µs tail-latency SLAs.
Selects identity providers: Keycloak sovereign EKS hosting, FIDO2 WebAuthn passkeys, and sub-20ms token minting.
Designs HTTP payload compression: Brotli/Gzip/Zstd algorithms, MIME allowlists, minimum size thresholds, and Vary headers.
Architects industry-specific reference architectures: BIAN, FHIR, TM Forum ODA, and sector regulatory compliance models.
Architects enterprise IaC platforms: state isolation, module taxonomy, drift detection, and policy-as-code governance.
Designs autoscaling architectures: HPA custom metrics, Karpenter node provisioning, scale-in stabilization, and cost caps.
Models infrastructure capacity: M/M/c/K burst sizing, socket buffer tuning, and 35% headroom allocations.
Architects integration adapters: Anti-Corruption Layers, protocol translation, error mapping, and idempotent relays.
Plans integration seam testing: Testcontainers environments, collaborator mocks, contract drift, and release gating.
Architects shared infrastructure capability platforms: provider-consumer contracts, tenancy, lifecycle APIs, and quotas.
Audits software maintainability: ISO 25010 sub-characteristics, pure domain decoupling, and 85% branch coverage.
Designs secure JWT token profiles: Ed25519/ES256 signing, claims validation, replay prevention, and JWKS key lifecycles.
Designs Kubernetes ingress architectures: Gateway API, TLS termination, host routing, rate limiting, and WAF integration.
Evaluates Layered Architecture style: strict vs relaxed tiers, dependency flows, vertical slicing, and bypass trade-offs.
Designs a shared multi-tenant Kubernetes platform: topology, node pools, isolation, upgrades, capacity, recovery.
Designs Kubernetes workload resources: Deployments, resource QoS classes, disruption budgets, and pod security contexts.
Architects legacy modernizations: Strangler Fig proxies, dual-run shadow reconciliation, and automated rollbacks.
Architects high-throughput LLM serving platforms: vLLM engines, PagedAttention KV-cache, GPU clusters, and batching.
Architects master data management: Fellegi-Sunter probabilistic matching, additive survivorship, and EMPI Golden Records.
Designs the boundary between AI hosts, MCP clients and servers: versions, capabilities, tools, authorization, consent.
Selects message brokers: log-based streams vs transient work queues, ordering, retention models, and operational fit.
Designs telemetry metric schemas: Prometheus/OTel instruments, cardinality bounds, histogram buckets, and aggregation.
Evaluates Microkernel and Plugin style: core stability, extension points, plugin sandboxing, and lifecycle trade-offs.
Evaluates Microservices style: independent deployability, distributed operational tax, data boundaries, and team readiness.
Architects microservice fleets: service boundaries, communication topologies, data autonomy, and resilient runtimes.
Architects modern frontend platforms: micro-frontends via Module Federation, sub-1.8s LCP, and isolated design tokens.
Architects modular monoliths: package boundaries, in-process event seams, schema isolation, and extraction readiness.
Evaluates Modular Monolith: logical module boundaries, in-process calls, schema separation, and microservice trade-offs.
Architects maintainable monolithic systems: layer boundaries, shared-database scaling, and deployment pipelines.
Estimates monthly cloud spend: first-principles unit models, cross-AZ network pricing, and commitment discounts.
Plans mutation testing: mutant operators, test efficacy scores, incremental diff scoping, and CI release quality gates.
Designs mutual TLS peer authentication: TLS 1.3 cipher constraints, SPIFFE SAN validation, and revocation checking.
Models cloud network architectures: Transit Gateway hubs, segregated route domains, and central inspection DMZ firewalls.
Architects enterprise network security: zero-trust microsegmentation, WAF, IDS/IPS inspection firewalls, and DDoS defense.
Discovers and quantifies quality attribute NFRs: latency percentiles, availability, throughput, and verifiable metrics.
Specifies an exact OAuth 2.0 profile: client types, grants incl. PKCE, scopes, tokens, refresh and revocation.
Selects observability platforms: native OpenTelemetry instrumentation, high-cardinality filters, and S3 tiers.
Designs production Dockerfiles and OCI images: multi-stage builds, non-root execution, minimal bases, and signal reaping.
Architects data lakehouses: open Delta Lake storage, ACID transactions, time-travel auditing, and unified BI/ML queries.
Audits software licenses: CycloneDX SBOM scanning, copyleft contamination elimination, and automated third-party notices.
Designs operation and data batching contracts: dual-trigger flushes, partial failure models, and memory buffering bounds.
Designs OpenID Connect profiles: ID token schemas, Discovery endpoints, nonce replay defense, and backchannel logout.
Designs actionable operational dashboards: visual hierarchy, query efficiency, decision mapping, and runbook links.
Designs structured logging schemas: JSON event formats, correlation IDs, PII redaction, and backpressure buffering.
Composes operational scenarios, decision branches, roles, and linked runbooks into a coordinated engineering playbook.
Writes a step-by-step runbook for one operational task: prerequisites, safe actions, checkpoints, stop and escalation.
Maps organizational teams to software architectures: Conway's Law alignment, ownership boundaries, and cognitive load.
Designs physical database schemas: 3NF relational DDL, covering composite B-Tree indexes, and sub-4.5ms query latency.
Evaluates Pipes and Filters style: stream filter boundaries, pipe buffering, backpressure, and poison-pill fault isolation.
Architects platform engineering strategies: platform-as-a-product, DevEx metrics, service scorecards, and operating models.
Architects platform operability: three-tier health probes, executable SSM runbooks, and 30s connection-draining shutdowns.
Architects plugin platforms: extension point SPIs, sandboxed runtimes, lifecycle controls, and developer extension SDKs.
Architects product line architectures: core-asset reuse, feature variability models, and multi-tier product platforms.
Selects programming languages: sub-500µs Rust determinism, zero GC jitter, and compile-time memory safety.
Authors production README files: value proposition, verified quickstarts, architecture overviews, and configuration.
Evaluates architectural options: Pugh weighted decision matrices, normalized weights, and sensitivity stress testing.
Architects enterprise prompt systems: modular metaprompts, versioned prompt catalogs, injection defense, and token budgets.
Enforces CI/CD quality gates: non-bypassable branch protection, automated build breakers, and latency baselines.
Designs queue performance and flow control: consumer concurrency, prefetch limits, backpressure, and lag budgets.
Designs a RAG system: governed sources, index lifecycle, access-aware retrieval, citations, abstention, evaluation.
Architects regulatory compliance architectures: SOC2/PCI controls mapping, automated evidence pipelines, and audit trails.
Audits regulatory compliance: PCI-DSS v4.0 tokenization, GDPR Article 32 security, and 365-day immutable audit trails.
Assesses relational normalization: 3NF/BCNF functional dependencies, update anomaly prevention, and governed caching.
Designs load balancing: weighted least-request routing, outlier detection ejections, panic modes, and slow-start warmups.
Designs resource bulkhead boundaries: thread pool isolation, connection segregation, failure containment, and shedding.
Turns approved API operations into a precise HTTP contract: methods, statuses, headers, caching and OpenAPI.
Designs retry policies: exponential backoff, decorrelated jitter, retry budgets, error classification, and deduplication.
Designs role-based access control: permission matrices, inheritance hierarchies, separation of duties, and audit rules.
Designs rolling deployments: surge/unavailable bounds, step pacing, readiness gates, connection draining, and rollback.
Designs dynamic LLM routing: intent classification, complexity scoring, cost-latency optimization tiers, and failover.
Selects search engines: complex Boolean proximity queries, document-level security, and open Apache 2.0 licensing.
Designs workload secret delivery: in-memory tmpfs mounts, dynamic database credentials, automated rotation, and leases.
Designs immutable security audit logs: actor-action schemas, cryptographic hash chains, WORM storage, and non-repudiation.
Evaluates Serverless style: cold-start latency, scale-to-zero economics, database connection limits, and FaaS trade-offs.
Architects enterprise service mesh platforms: data-plane topology, strict mTLS identity, cross-cluster peering, and egress.
Architects enterprise serverless systems: FaaS runtimes, cold-start mitigation, event source mappings, and concurrency.
Evaluates SOA style: enterprise service bus integration, canonical data models, contracts, and ESB bottleneck trade-offs.
Designs service mesh policies: VirtualServices, AuthorizationPolicies, mTLS enforcement, outlier detection, and retries.
Designs shadow deployments: asynchronous traffic mirroring, diff comparison engines, and zero side-effect safety.
Designs shared-state concurrency control: optimistic locking, distributed mutexes, isolation levels, and deadlock avoidance.
Architects SRE platforms: multi-burn-rate alerting, automated CI/CD deployment freezes, and a strict 50% toil cap.
Architects site reliability: 99.99% availability SLOs, Envoy circuit breakers, degraded fallbacks, and chaos testing.
Defines SLIs, SLOs and error budgets from real user journeys: what counts as good, targets, windows, budget math.
Architects software libraries and SDKs: public API surfaces, zero-dependency cores, SemVer evolution, and error models.
Selects enterprise storage: AWS S3 Object Lock compliance WORM, automated Glacier tiering, and 87% cost reduction.
Discovers hidden architectural assumptions: risk-impact scoring, uncertainty mapping, and falsification experiments.
Architects strategic DDD bounded contexts: ubiquitous language scoping, relationship maps, ACLs, and team alignment.
Decomposes strategic business goals: metric formulation, conflict resolution, and architectural driver alignment.
Architects enterprise context maps: upstream-downstream topology, translation adapters, OHS contracts, and ACL governance.
Architects green cloud platforms: Scope 3 carbon tracking, Graviton3 ARM64 silicon, and renewable grid routing.
Discovers outer system context boundaries: stakeholder viewpoints, regulatory framing, and environmental interfaces.
Enforces technical standards: ArchUnit boundary rules, technology radar allowlists, and AST linter build breakers.
Discovers cross-system dependencies: coupling analysis, circular dependency traps, blast radius, and critical paths.
Benchmarks technologies: Kafka vs RabbitMQ throughput, consumer lag latency, and KRaft consensus trade-offs.
Designs Terraform or OpenTofu modules: interfaces, providers, state boundaries, environments and safe planned changes.
Selects third-party SDKs: official vs handwritten clients, transitive dependency bloat, licensing, and security postures.
Produces an evidence-based threat model for one system or change: attacker scenarios, affected objectives, control gaps.
Designs a threat-modeling practice that stays current across products and teams: scope, assets, trust boundaries, coverage.
Plans threat-informed security testing: SAST/DAST pipelines, penetration testing scope, environment fidelity, and gates.
Designs safe model-to-action boundaries: tool catalogs, argument validation, authority gates, and error recovery.
Models 3-year Total Cost of Ownership: fully-loaded CapEx/OpEx, high-density power facilities, and 36.8% hybrid savings.
Designs transactional inbox patterns: deduplicating-consumer schemas, atomic state commits, and duplicate acknowledgment.
Designs a transactional outbox so state changes and their events never diverge: atomic write, relay, recovery.
Models UML 2.5 class structures: DDD aggregate roots, private encapsulation, and immutable MonetaryAmount objects.
Models UML 2.5 deployment topologies: 3-AZ active-active distribution, topology spread constraints, and CloudHSMs.
Models UML 2.5 sequence flows: synchronous gRPC lifelines, asynchronous event publishing, and 1.5s timeout fragments.
Models UML 2.5 activity diagrams: synchronized fork/join concurrency, decision guards, and exception rollbacks.
Models UML 2.5 state machines: composite state hierarchies, event-driven transitions, and immutable terminal states.
Plans unit testing: state vs behavior verification, mock boundaries, edge-case coverage, and fast sub-minute CI feedback.
Models architectural scalability: Universal Scalability Law (USL), contention/coherency coefficients, and sharding.
Maps value streams: process vs lead times, queue delays, percent complete and accurate (%C&A), and waste elimination.
Architects vector search systems: HNSW indexing, hybrid BM25 fusion, memory budgeting, and sharded vector databases.
Designs hallucination detection systems: atomic claim extraction, citation entailment verification, and routing tripwires.
Designs outbound webhooks: HMAC payload signing, replay defense, delivery retry schedules, and endpoint verification.
Architects workflow orchestration clusters: durable state engines, activity worker topologies, and cluster resilience.
Plans enterprise load testing: workload modeling, throughput profiles, latency SLAs, and capacity saturation gates.
Designs enterprise X.509 PKI: hierarchical CAs, automated ACME rotation, OCSP stapling, and certificate policies.
See it in action
Actionable Alert Contract Design
Example session with this skill installed
Design actionable alerting and routing contracts for our Payments Processing Engine.
- Subject: payment-core v3.2.0 (run-id: payments-alert-001) processing 1,400 peak transactions/sec on Kubernetes across 3 AWS AZs.
- Deciders: Lead SRE Architect (Marcus Vance) and Payment Reliability Lead (Elena Rostova).
- Incidents: In INC-3118, a transient network blip triggered 4,200 individual alerts across 14 Slack channels and paged 8 engineers, causing severe alert fatigue that delayed incident resolution by 35 minutes.
- Tension: Dev team proposed alerts for every internal CPU spike (> 80%), memory threshold (> 75%), and exception log; Marcus Vance strictly forbids cause-based CPU alerts lacking user impact, mandating symptom-based alerting (multi-window SLO error burn rates, authorization p95 latency breaches), Alertmanager alert grouping and inhibition (cluster-down silences pod alerts), a strict 3-tier severity matrix (P1 page on-call, P2 business-hours ticket, P3 informational log), and mandatory runbook URLs (https://runbooks.internal/payments/...) on all paging alerts.
Write the alerting policy spec under docs/.
- Read your context and instructions
- Compiled the actionable alert contract
- Generated the UI component
Wrote docs/architecture/tasks/payments-alert-001/alerting-design/alerting-policy-spec.md. Complete actionable alerting contract specifying symptom-based SLO triggers, alert grouping, inhibition hierarchies, on-call escalation matrices, and mandatory runbook bindings.
---
skill: alerting-design
---
# Alerting Policy Spec: Core Payments Processing [ALERT-PAY-001]
## Summary
This specification establishes the actionable alerting contract, severity taxonomy, inhibition rules, and routing matrix for `payment-core v3.2.0` under run ID `payments-alert-001`, monitoring 1,400 peak payment transactions/second. It resolves the severe alert fatigue and noise demonstrated in incident INC-3118 (where a transient network glitch generated 4,200 simultaneous Slack alerts and paged 8 engineers). The design strictly bans cause-based noise (such as raw CPU > 80% alerts), mandating symptom-based alerting focused on customer experience (multi-window SLO error budget burn rates, authorization p95 latency breaches), Alertmanager grouping with inhibition trees, a 3-tier severity hierarchy, and mandatory validated runbook links (`https://runbooks.internal/payments/...`) on every paging alert.
## Detailed Description
Uncalibrated cause-based alerting produces alert fatigue, noise blindness, and delayed incident recovery. Paging engineers on ephemeral host metrics that have zero impact on customer transactions leads to missed P1 outages. This contract enforces Google SRE symptom-based alerting: an alert must represent an urgent, actionable problem requiring human intervention, with a documented response path.
Ingress Telemetry Stream (1,400 TPS)
│
▼
[ Prometheus Evaluation Engine (15s Interval) ]
├── Check 1: Multi-Window SLO Burn Rate (14.4x 1h / 6x 6h)
└── Check 2: Transaction Latency p95 > 180 ms for 3m
│
▼ (Alert Condition Tripped)
[ Alertmanager Routing & Grouping Core ]
├── Grouping: group_by: [alertname, cluster, service]
├── Inhibition: If ClusterNetworkDown is firing ──► Inhibit PodCrashLoop & InstanceDown
└── Routing:
├── Severity: P1 (Critical) ──► PagerDuty @payment-sre-oncall (Mandatory Runbook)
├── Severity: P2 (Warning) ──► Jira Service Desk (Response SLA: 4h)
└── Severity: P3 (Info) ──► Datadog Diagnostic Dashboard Log
### Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Alert Actionability & Noise Elimination | Paging engineers for transient, non-actionable blips induces alert fatigue and delayed incident response (INC-3118). | 0.40 | Marcus Vance (Lead SRE) |
| Customer-Impact Symptom Alignment | Alerts must track user-facing pain (failed payments, latency) rather than ephemeral node CPU spikes. | 0.30 | Elena Rostova (Payment Reliability) |
| Fast Incident Triage (MTTR Reduction) | Responders must be directed to exact operational runbooks within 30 seconds of receiving a page. | 0.15 | SRE Operations SLA |
| Alert Volume Bounding via Grouping | Aggregating related pod alerts into a single notification prevents Slack and pager floods. | 0.15 | Incident Response Policy |
### Comparison
| Alerting Strategy Candidate | Evaluation Target | Notification Volume under Blip | Responder Action Clarity | Evaluation |
|---|---|---|---|---|
| Option A: Raw Infrastructure Triggers | CPU > 80%, Disk > 75%, Exceptions | Catastrophic: 4,200 alerts across 14 channels | Poor: Unclear if customers are affected | Rejected: Triggered INC-3118 responder paralysis. |
| Option B: Single Static Error Rate (> 1%) | Instantaneous error percentage | High: False alarms on 10-second traffic dips | Moderate | Rejected: Lacks multi-window burn rate smoothing. |
| Option C: Multi-Window SLO Burn + Inhibition (Chosen) | 14.4x 1h / 6x 6h burn + Latency p95 | Single grouped notification per incident | High: Direct link to verified runbook | Selected: High signal-to-noise ratio, mathematically sound. |
### Result
Option C is selected. Prometheus evaluates multi-window SLO burn rates; Alertmanager groups and inhibits downstream noise, routing only actionable alerts to on-call engineers.
---
### Required Mechanisms
#### 1. Severity Classification Taxonomy [MC-ST-01]
| Severity Level | Definition & Customer Impact | Response Channel | Page SLA | Required Artifact |
|---|---|---|---|---|
| **P1 - Critical** | Severe transaction failure rate (> 1% drop) or complete service unavailability | PagerDuty (Phone / Push) | 5 minutes | Mandatory Runbook URL |
| **P2 - Warning** | Elevated latency, degraded redundancy, or single-AZ failure without customer loss | Slack `#alerts-payments` + Jira | 4 hours (business) | Dashboard Link |
| **P3 - Info** | Capacity trend, impending certificate renewal (> 30 days) | Datadog Event Stream | No active response | None |
#### 2. Symptom-Based Alert Triggers & PromQL Formulas [MC-AT-01]
##### Alert 1: PaymentTransactionErrorBurnRateCritical (P1)
Fires when error budget burns at 14.4x over 1 hour AND 14.4x over 5 minutes:
```promql
(
sum(rate(payment_requests_total{status="500"}[1h])) / sum(rate(payment_requests_total[1h])) > (14.4 * (1 - 0.999))
)
and
(
sum(rate(payment_requests_total{status="500"}[5m])) / sum(rate(payment_requests_total[5m])) > (14.4 * (1 - 0.999))
)
- Annotations:
summary: "High payment transaction error rate burning 2% of 30-day budget in 1 hour."runbook_url:https://runbooks.internal/payments/db-failover-remediation
Alert 2: PaymentAuthorizationLatencyP95Degraded (P1)
Fires when authorization latency p95 breaches 180 ms for 3 consecutive minutes:
histogram_quantile(0.95, sum(rate(payment_authorization_duration_seconds_bucket[3m])) by (le)) > 0.180
- Annotations:
runbook_url:https://runbooks.internal/payments/latency-triage-runbook
3. Deduplication, Grouping, and Inhibition Rules [MC-GI-01]
- Grouping Configuration:
group_by: ['alertname', 'cluster', 'service'] group_wait: 30s group_interval: 5m repeat_interval: 4h - Inhibition Hierarchy:
- If
PaymentClusterVPCUnreachableis firing:- Inhibit all
PaymentInstanceDownalerts. - Inhibit all
PaymentDatabaseConnectionTimeoutalerts.
- Inhibit all
- Prevents storm of hundreds of downstream alerts when the underlying root cause is a VPC gateway disconnect.
- If
4. On-Call Routing Matrix [MC-RM-01]
service: payment-core-> PagerDuty Schedulesched_pay_primary_sre.- Escalation: If unacknowledged after 10 minutes, escalate to Secondary SRE on-call; after 20 minutes, escalate to Marcus Vance (Lead SRE).
Invariants and Contracts
Mandatory Runbook URL Invariant [INV-ALT-01]
Every alert assigned severity `P1` must include an active, verified `runbook_url` in its annotations.
Alert definitions omitting runbook URLs are rejected by CI validation linters.
Zero Cause-Based Paging Invariant [INV-ALT-02]
Alerts triggering on raw infrastructure metrics (e.g. `node_cpu_utilization > 80%`, `jvm_memory_used > 80%`)
must never be configured with severity `P1`. Paging is strictly reserved for user-facing symptoms.
Deduplication Grouping Window Floor [INV-ALT-03]
Alertmanager configurations must enforce a `group_wait` of at least 30 seconds to allow related
component alerts to consolidate into a single notification batch before dispatch.
Explicit Unknowns
- Alertmanager webhook delivery retry count limits during external PagerDuty network outages (G-1).
- Effectiveness of Slack notification channel filtering during multi-service cloud provider zone brownouts (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Peak 1,400 transactions/sec | provided | Traffic profile intake | Current |
| Incident INC-3118 4,200 alert flood | provided | Post-mortem evidence | Historical |
| Prohibition of raw CPU alerts | decided | Marcus Vance (Lead SRE) | 2026-09-15 |
| Multi-window SLO burn rate (14.4x 1h / 5m) | decided | Google SRE Alerting Standard | 2026-09-15 |
| Mandatory runbook URL on P1 alerts | decided | Architectural invariant INV-ALT-01 | 2026-09-15 |
| Runbook URL reference | provided | https://runbooks.internal/payments/db-failover-remediation | Current |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against alerting design standards:
- Symptom Alignment: PASS. All P1 alerts track user transaction success or p95 latency.
- Noise Control: PASS. Grouping and inhibition rules collapse redundant pod failure notifications.
- Runbook Binding: PASS. Explicit
runbook_urlannotations provide direct remediation links. - Formatting Compliance: PASS. Conforms strictly to native Markdown rules in
rule_markdown.md.
Open Decisions
DEC-ALT-01: Marcus Vance to determine whether P2 warning alerts should post to a private Discord channel as a secondary notification channel (Owner: Marcus Vance).
Next steps
- Platform team validates Prometheus alert rules YAML using
promtool check rules. - Marcus Vance configures Alertmanager grouping and inhibition tree in
infra/monitoring/alertmanager.yml. - Conduct staging resilience drill triggering synthetic transaction failure to verify single grouped PagerDuty incident generation.
actionable-alert-contract-design.tsx
TSX · React component
Example file from a real run - the skill writes it into your workspace.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every skill in this bundle passes our trust checks.
Security scanned
Passed our 8-point scan before listing
2 installs
Downloaded by developers to date
30-day refund
Not a fit? Get your money back