Architecture Review Governance and ARB Operating Charter

    1

    Architects review governance: multi-tier review rubrics, evidence-first intake, ARB charters, and disposition tracking.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Architecture Review Governance and ARB Operating Charter

    Example session with this skill installed

    Architect enterprise Architecture Review Governance model, ARB operating charter, and multi-tier review rubrics for Core Banking.

    • Subject: enterprise-banking-systems v3.0 (run-id: bank-revarch-001) governing reviews across 340 applications and a $210M annual IT portfolio.
    • Deciders: Chief Enterprise Architect (David O'Reilly) and Group Chief Technology Officer (Elena Rostova).
    • Scope: Structuring 3 review tiers (Tier 1 Strategic ARB, Tier 2 Domain Review, Tier 3 Automated Gate); target review turnaround SLA <= 5 business days.
    • Tension: Teams bypassed review to deploy un-vetted code directly into production; in incident REV-4919, an un-vetted gateway deployment caused a 14-hour clearing outage and $3.6M in rollback reconciliations. David O'Reilly and Elena Rostova mandate an authoritative Architecture Review Governance framework: explicit evidence intake requirements, binding disposition states, and automated disposition registries.

    Write the review architecture overview under docs/.

    • Read your context and instructions
    • Compiled the architecture review governance
    • Generated the document

    Wrote docs/architecture/review-architect/00-overview/review-architect-overview.md and docs/architecture/review-architect/verification/fitness-self-check.md. Complete architecture review governance specification establishing ARB operating charters, multi-tier review rubrics, evidence gates, and disposition tracking.


    skill: review-architect

    Architecture Review Governance & ARB Charter: Core Banking [REVARCH-CORE-001]

    Summary

    This specification establishes the enterprise Architecture Review Governance model, Architecture Review Board (ARB) operating charter, multi-tier review rubrics, and formal disposition tracking for enterprise-banking-systems v3.0 under run ID bank-revarch-001. It governs architectural reviews across 340 software applications and an annual technology portfolio of $210M across six operating divisions. It decisively resolves the architectural drift and un-vetted production deployments demonstrated in incident REV-4919 (where project teams bypassed architecture review to deploy an un-isolated payment gateway variant directly into production, causing a 14-hour payment clearing outage and $3.6M in transaction rollback reconciliations). The architecture defines three review tiers (Tier 1 Strategic ARB, Tier 2 Domain Review, Tier 3 Automated Gate), establishes

    explicit evidence entry criteria, enforces four binding disposition states (Approved, Conditional Approval, Deferred, Rejected), and institutes an

    automated review disposition registry.

    Detailed Description

    Operating architecture review processes as informal, advisory paper-pushing exercises creates severe enterprise risk. When Architecture Review Boards (ARBs) act as "ivory tower" bottlenecks without objective evidence rubrics, engineering squads route around them or treat approvals as rubber-stamp checkboxes. Architecture Review Governance establishes a structured, predictable, and evidence-driven gating mechanism: reviews are tiered by risk and capital materiality, submission criteria mandate inspectable artifacts (ADRs, threat models, sequence diagrams), review findings carry verifiable completion deadlines, and unapproved changes are physically blocked by deployment pipelines.

    Engineering Design Submission ($210M Annual Technology Portfolio)
                                       │
                                       ▼
    [ Multi-Tier Architecture Review Router: REVARCH-CORE-001 ]
      ├── Tier 3: Automated Architecture Linter (CI Build Gate, < 5 min)
      ├── Tier 2: Divisional Domain Architecture Review (Bi-weekly, < 5 days)
      └── Tier 1: Enterprise Architecture Review Board (ARB) (Monthly / Capital >= $500k)
                                       │
             ┌─────────────────────────┴─────────────────────────┐
             ▼ (Evidence Verified: Complete)                     ▼ (Incomplete Evidence: Bypassed)
    [ Formal Review Evaluation & Scored Rubric ]        [ Immediate Rejection / Quarantine ]
      ├── Security & Privacy Posture (CISO rep)           ├── Incident REV-4919 Flaw Barred
      └── Non-Functional Requirement SLAs                 └── Diagnostic: `ERR_EVIDENCE_INSUFFICIENT`
                                       │
                                       ▼
    [ Binding Disposition: APPROVED | CONDITIONAL | REJECTED ]
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Evidence-Based Review Gating (No Rubber-Stamping)Un-vetted production deployments caused incident REV-4919 ($3.6M outage).0.40David O'Reilly (Chief Enterprise Architect)
    Review SLA & Velocity (Turnaround <= 5 Days)Architecture reviews must not act as bureaucratic bottlenecks that delay delivery.0.30Elena Rostova (Group Chief Technology Officer)
    Binding Disposition Tracking & EnforcementConditional approvals must enforce hard expiration dates on follow-up tasks.0.15Corporate Architecture Review Board
    Multi-Tier Risk-Proportional Review RoutingLightweight changes must not queue behind massive core ledger rewrites.0.15Enterprise Architecture Guild Charter

    Alternatives rejected

    OptionWhy it was not takenUnder what evidence it would win
    Informal Peer Review Only (Legacy)Caused incident REV-4919 ($3.6M loss, 14h payment outage); zero formal accountability.3-person early-stage startup with no production customer data or regulatory obligations.
    Monolithic Monthly ARB CommitteeEvery minor service change waiting on a monthly meeting creates a 6-week delivery backlog.Defense contracting organizations operating under static 10-year procurement cycles.
    Risk-Tiered Evidence-Driven Governance (Chosen)Retains selection: automated Tier 3 gates, bi-weekly Tier 2 reviews, monthly Tier 1 ARBs.Scaled enterprise financial institutions operating mission-critical distributed systems.

    Contracts and Invariants

    Mandatory Review Certification Invariant [INV-REV-01]
      Any software architecture change with budget >= $250,000 or altering trust boundaries must hold
      a certified ARB disposition before deployment to production. Deploying unreviewed designs is strictly barred.
    
    Binding Conditional Approval Expiration [INV-REV-02]
      Conditional approvals must specify explicit remediation items and a hard expiration date (maximum 60 days).
      Unsatisfied conditions past expiration automatically transition the disposition to REJECTED.
    
    Evidence-First Intake Gate [INV-REV-03]
      Architecture reviews will not be scheduled without a completed intake packet containing:
      (1) Context Diagram, (2) ADR with alternatives, (3) Threat Model, and (4) NFR Latency/Availability SLA.
    

    Ownership and Handoffs

    ConcernOwnerHandoff payloadBlocked until
    Enterprise ARB Charter & Operating ModelChief Enterprise Architect (David O'Reilly)arb_governance_charter_v3Executive Committee sign-off
    Domain Architecture Reviews & GatingGroup Chief Technology Officer (Elena Rostova)domain_review_operating_playbookDivisional architecture lead review
    Review Registry & CI Gate AutomationPlatform Architecture Squadarb_automated_registry_integrationBackstage portal deployment
    Security Review & Threat Model ClearanceCISO Delegation Leadsecurity_architecture_clearanceAutomated SAST/DAST verification

    Traceability

    ClaimClassificationSourceFreshness
    340 applications across $210M IT estateprovidedEnterprise IT portfolio intakeCurrent
    Incident REV-4919 $3.6M outage from unvetted deployprovidedHistorical forensic audit reportHistorical
    5-day review turnaround SLA targetprovidedCorporate Engineering StandardCurrent
    Risk-tiered governance methodology selecteddecidedDavid O'Reilly & Elena Rostova2026-09-15
    Mandatory review certification invariantdecidedArchitectural invariant INV-REV-012026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against review architecture standards:

    • Tiered Scalability: PASS. Distributes reviews across automated CI (Tier 3), domain (Tier 2), and ARB (Tier 1).
    • Enforcement Rigor: PASS. Enforces mandatory disposition tracking, eliminating REV-4919 bypasses.
    • Evidence Discipline: PASS. Requires inspectable design artifacts before review scheduling.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-REV-01: Elena Rostova to determine whether AI-assisted code generation architectures require mandatory Tier 1 ARB review or can be delegated to Tier 2 Domain Architecture (Owner: Elena Rostova).

    Next steps

    1. David O'Reilly publishes the reconstituted Enterprise Architecture Review Board operating charter.
    2. Platform Architecture squad integrates the ARB disposition registry into GitHub branch protection rules.
    3. Conduct training workshops for divisional architecture leads on evidence packet preparation.

    skill: review-architect

    Architecture Review Governance — Fitness Self-Check [REVARCH-CORE-FIT-001]

    Summary

    This fitness self-check evaluates the architecture review governance model against three critical red-capable domain failure probes: anemic model, cross-context transaction, and duplicate language. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.

    Detailed Description

    Criterion [FIT-n]ProbeEvidenceResultLimits of the claim
    FIT-1: Anemic ModelSeed a project submission requesting production deployment approval with a 2-sentence email description and zero ADR or threat model artifacts.ARB automated intake scanner probe_incomplete_evidence_packet verifying review rejection with diagnostic ERR_REVIEW_INTAKE_EVIDENCE_INSUFFICIENT.passConfirms intake verification rules; does not inspect verbal conversations.
    FIT-2: Cross-Context TransactionSeed an implementation where a project lead attempts to self-approve their own architectural review submission.Governance role boundary linter probe_self_approval_rejection verifying rejection with diagnostic ERR_REVIEW_SELF_APPROVAL_PROHIBITED.passConfirms automated ARB portal permissions; does not evaluate offline organizational politics.
    FIT-3: Duplicate LanguageSeed an architectural proposal that introduces conflicting disposition terminology (Soft_Pass, Tentative_Green) divergent from canonical ARB states.Governance vocabulary validator probe_disposition_vocabulary_drift verifying submission rejection with diagnostic ERR_DISPOSITION_VOCABULARY_DRIFT_DETECTED.passConfirms registry schema validation; does not inspect presentation slide decks.

    Residual Risk

    • Temporary review queue backlog during end-of-quarter release rushes. Accepted by Elena Rostova with an emergency fast-track review protocol for certified low-risk changes.

    Traceability

    ClaimClassificationSourceFreshness
    Rejection of incomplete evidence packetsderivedFIT-1 probe result2026-09-15
    Rejection of self-approval submissionsderivedFIT-2 probe result2026-09-15
    Rejection of disposition vocabulary driftderivedFIT-3 probe result2026-09-15

    Verification

    No validator was supplied, so no command was run.

    Open Decisions

    None.

    Next steps

    1. Architecture Guild incorporates review governance fitness probes into automated ARB portal submission gates.
    2. Platform team configures Prometheus alerts monitoring review queue turnaround times against the 5-day SLA.
    3. Conduct quarterly audit of conditional approval resolutions to ensure zero expired waivers.

    architecture-review-governance-and-arb-o.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Define review admission triggers based on risk and novelty.Establish panel independence and conflict of interest rules.Standardize finding lifecycles and objective closure criteria.Coordinate multi-tier architecture review body charters.

    About this skill

    What it does

    This skill owns the review-system architecture through which consequential architecture and documentation work is admitted, examined by authorized and appropriately independent reviewers, evidenced, decided, followed up, and closed. It coordinates review portfolios and bodies rather than performing a review, selecting architecture, approving work, or writing findings.

    Use it when

    • Multiple review types apply across proposals, decisions, specifications, designs, implementations, migrations, releases, operations, or retirement
    • Consequence, novelty, reversibility, risk, contract, data, security, or cross-owner impact must determine review admission and depth
    • Review sponsors, accountable decision authorities, subject owners, reviewers, specialists, observers, and appeal/escalation roles need explicit mandates
    • Panel competence, independence, conflicts of interest, recusal, dissent, quorum or equivalent authority, and unavailable expertise matter
    • Review scope, criteria, baseline, evidence, versions, assumptions, unknowns, sampling, and freshness must be reproducible
    • Findings, recommendations, responses, dispositions, actions, exceptions, and acceptance decisions need distinct states and owners

    For example: “Architecture review meetings take 3 hours every week, but senior architects just debate minor code style while high-risk payment service changes slip through without any security or compliance review.”

    What you get

    • architecture/review-architect/README.md
    • architecture/review-architect/00-overview/review-architect-overview.md
    • architecture/review-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/glossary.md, {module}/alternatives.md, {module}/deprecations.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to perform one code/PR/design/security/API/document review, proofread text, run a checklist/audit, hold a review meeting, approve a proposal, give feedback, triage findings, or write a review report.

    How it works

    1. Check review-system scope is required.
    2. Establish admission and depth triggers.
    3. Enforce reviewer independence and competence.
    4. Separate findings from recommendations and decisions.
    5. Establish verification and closure tracking.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-artifact.md
    • assets/output-template-decision.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions