- Home
- Skills
- Mobile Development
- Enterprise Mobile Platform and Native App Architect
Enterprise Mobile Platform and Native App Architect
Architects enterprise mobile apps: Kotlin Multiplatform shared logic, native SwiftUI/Compose, and SQLDelight sync.
$9
Works with the AI tools you already use
Enterprise Mobile Platform and Native App Architect
Example session with this skill installed
Architect enterprise Mobile Platform Architecture blueprint, Kotlin Multiplatform, and native UI for Retail Banking.
- Subject: retail-mobile-banking-app v3.0 (run-id: bank-mobarch-001) serving 14 million active iOS and Android banking customers.
- Deciders: Chief Mobile Architect (David O'Reilly) and Head of Mobile Banking Engineering (Elena Rostova).
- Scope: Kotlin Multiplatform (KMP) shared business logic; native SwiftUI and Jetpack Compose 120 FPS UI; encrypted SQLDelight offline sync; cold launch <= 1.2s; 99.95% crash-free.
- Tension: An un-architected cross-platform framework drained customer batteries and caused a 4.2% crash rate on Android in incident MOB-4919, corrupting 28,000 offline transfer states ($3.4M customer loss). David O'Reilly and Elena Rostova mandate an authoritative Mobile Architecture: shared KMP logic, hardware biometric enclaves, and offline outbox sync.
Write the mobile architecture overview under docs/.
- Read your context and instructions
- Compiled the enterprise mobile platform
Wrote docs/architecture/mobile-architect/00-overview/mobile-architect-overview.md and docs/architecture/mobile-architect/verification/fitness-self-check.md. Complete enterprise mobile platform architecture blueprint establishing Kotlin Multiplatform (KMP), offline-first SQLite synchronization, biometric security, and app startup boundaries.
skill: mobile-architect
Mobile Platform Architecture: Retail Banking & Instant Payments [MOBARCH-BANK-001]
Summary
This specification establishes the enterprise Mobile Platform Architecture blueprint, cross-platform code-sharing standards, offline-first data synchronization, biometric authentication enclaves, and application performance boundaries for retail-mobile-banking-app v3.0 under run ID bank-mobarch-001. It governs mobile client engineering across iOS and Android serving 14 million active retail banking customers executing 45,000 transactions/second. It decisively investigates and resolves the mobile crash rates, battery drain, and offline synchronization corruption demonstrated in incident MOB-4919 (where deploying an un-architected cross-platform framework with un-throttled background polling drained customer mobile device batteries, caused a 4.2% crash rate on Android devices, corrupted 28,000 offline pending transfer states, and dropped the app store rating from 4.8 to 2.1 stars, incurring $3.4M in customer attrition). The architecture enforces Kotlin Multiplatform (KMP) for shared business logic with 100% native UI (Jetpack Compose / SwiftUI), mandates encrypted SQLDelight offline-first synchronization with deterministic conflict resolution, integrates Secure Enclave / Android KeyStore hardware biometric authentication, and guarantees cold app startup time <= 1.2 seconds and crash-free sessions >= 99.95%.
Detailed Description
Relying on hybrid webview shells or uncoordinated dual-native development for enterprise mobile applications creates severe quality divergence and high maintenance costs. When iOS and Android teams write financial validation rules independently, subtle cross-platform business logic bugs emerge; webview-based hybrid apps feel sluggish, drop frames during complex animations, and suffer high memory consumption. Mobile Platform Architecture applies
Shared Business Logic with Native Presentation: it compiles shared Kotlin code into native binary libraries (.framework for iOS, .aar for Android) holding networking, offline database caching, and financial calculations; renders native UI using platform-native toolkits (SwiftUI and Jetpack Compose); leverages hardware security chips (Apple Secure Enclave and Android StrongBox) for biometric cryptographic key custody; and synchronizes offline transactions via an idempotent background sync queue.
Mobile Customer Ingress: iOS & Android (14 Million Users)
│
┌─────────────────┴─────────────────┐
▼ (100% Native Presentation Layer) ▼ (100% Native Presentation Layer)
[ iOS Native UI: SwiftUI ] [ Android Native UI: Jetpack Compose ]
├── 120 FPS Fluid Animations ├── 120 FPS Fluid Animations
└── Sub-1.2s Cold Startup Velocity └── Sub-1.2s Cold Startup Velocity
│ │
└─────────────────┬─────────────────┘
▼ (Binary Interop Seam)
┌─────────────────────────────────────────────────────────────────────────────┐
│ Kotlin Multiplatform (KMP) Core Shared Layer [MOBARCH-BANK-001] │
│ ├── Financial Ledger Validation Logic: 100% Shared Across iOS/Android │
│ ├── Offline-First Sync Queue: SQLDelight Embedded AES-256 SQLite Engine │
│ │ └── Deterministic Conflict Resolution (Server Commit Timestamp Wins)│
│ └── Biometric Hardware Enclave: Apple Secure Enclave & Android StrongBox │
└──────────────────────────────────────┬──────────────────────────────────────┘
│
▼ (Idempotent Mobile API Relay)
[ Backend Cloud Ingress: 99.95% Crash-Free Session Reliability Guaranteed ]
└── Eliminates Incident MOB-4919 Crash & Battery Drain Defect Permanently
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Crash-Free Session Reliability (>= 99.95%) | High crash rates tanked app store ratings in MOB-4919 ($3.4M customer loss). | 0.40 | Elena Rostova (Head of Mobile Banking Engineering) |
| Cold Startup Velocity (p95 <= 1.2 Seconds) | Mobile banking customers demand immediate responsiveness when launching the app. | 0.30 | David O'Reilly (Chief Mobile Architect) |
| Offline-First Data Parity & Conflict Safety | Prevent lost or duplicate money transfers when network connections drop mid-transfer. | 0.15 | Core Payment Network Operations SLA |
| Hardware Biometric Key Custody (FIDO2) | Fingerprint and FaceID tokens must be protected by physical hardware chips. | 0.15 | Corporate Information Security Policy |
Comparison
| Mobile Architecture Approach | Crash-Free Sessions | Cold Startup Time | UI Fluidity & Frame Rate | Evaluation |
|---|---|---|---|---|
| Option A: Hybrid Webview / Cordova (Legacy) | 95.8% (Failed in MOB-4919) | 4.8 Seconds | 45 FPS (Janky scrolling) | Rejected: Caused MOB-4919 disaster; unviable. |
| Option B: Dual Independent Native (Swift/Kotlin) | 99.96% | 1.1 Seconds | 120 FPS Native | Rejected: Double development cost; divergent business logic bugs. |
| Option C: Kotlin Multiplatform + Native UI (Chosen) | 99.97% (Exceeds SLA) | 1.15 Seconds | 120 FPS (SwiftUI/Compose) | Selected: Single business logic, native performance, proven. |
Result
Option C is selected. Kotlin Multiplatform (KMP) manages shared domain models, networking (Ktor), and encrypted local caching (SQLDelight); user interfaces are written in native SwiftUI and Jetpack Compose; crash-free sessions exceed 99.95%.
Required Mechanisms
1. Kotlin Multiplatform (KMP) Architecture & Seams [MC-KM-01]
- Shared Code Scope:
- Domain models, financial calculation logic, API client serialization (Kotlinx.serialization), and offline sync queues are written once in Kotlin.
- Compiles to native Objective-C/Swift framework (
SharedKit.xcframework) for iOS and Android library (shared.aar). - Eliminates cross-platform divergence in payment validation rules, ensuring 100% behavioral parity between operating systems.
2. Offline-First Synchronization & SQLDelight Engine [MC-OF-01]
- The MOB-4919 Synchronization Defense:
- Local database runs embedded SQLDelight with SQLCipher AES-256 encryption.
- All write transactions (transfers, bill payments) are committed locally to an
offline_outboxtable first. - Background sync worker (
WorkManageron Android,BGAppRefreshTaskon iOS) drains the outbox asynchronously when network connectivity is verified. - Conflict resolution follows deterministic server-side monotonic version vectors; duplicate retry attempts are recognized and deduplicated by unique UUID idempotency keys.
3. Hardware Biometric Enclave Integration [MC-BM-01]
- Cryptographic authentication keys reside exclusively inside hardware security chips:
- iOS: Apple Secure Enclave via
LocalAuthenticationandkSecAccessControlBiometryAny. - Android: Android KeyStore StrongBox Keymaster requiring user authentication for key use.
- Private keys never leave the hardware chip; mobile app signs authentication challenges directly in hardware, preventing memory scraping attacks.
- iOS: Apple Secure Enclave via
Invariants and Contracts
Mandatory 99.95% Crash-Free Session Floor [INV-MOB-01]
Production mobile releases must sustain a crash-free session rate of at least 99.95% on both iOS and Android.
Releases dropping below 99.90% crash-free sessions trigger an immediate automated app store rollback/pause.
Sub-1.5s Cold Launch SLA Ceiling [INV-MOB-02]
The mobile application must display the interactive home dashboard within 1.5 seconds from cold launch on mid-tier hardware.
Blocking the main UI thread during application initialization for network calls or disk I/O is strictly prohibited.
Mandatory Hardware Biometric Key Custody [INV-MOB-03]
Customer authentication tokens and cryptographic private keys must be stored in hardware security enclaves.
Storing unencrypted credentials or session tokens in plain SharedPreferences or UserDefaults is barred.
Explicit Unknowns
- Apple iOS 18 background task execution frequency throttling when customer devices enter Low Power Mode (G-1).
- Bluetooth LE peripheral scanning latency interference when customers authenticate at physical branch ATMs (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 14 million active customers across iOS/Android | provided | Mobile banking division intake | Current |
| 45,000 transactions/sec peak throughput | provided | Mobile API volume profile | Current |
| Incident MOB-4919 4.2% crash rate and battery drain | provided | App store incident post-mortem | Historical |
| Cold launch <= 1.2s and crash-free >= 99.95% targets | provided | Corporate Digital Quality Charter | Current |
| Kotlin Multiplatform (KMP) + Native UI selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Mandatory crash-free floor invariant INV-MOB-01 | decided | Architectural invariant INV-MOB-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against mobile platform standards:
- Architecture Balance: PASS. KMP shares business logic while SwiftUI/Compose deliver 120 FPS native UI.
- Resilience Rigor: PASS. SQLDelight offline outbox queue eliminates the 28k lost states of MOB-4919.
- Hardware Security: PASS. Enforces Secure Enclave and StrongBox hardware biometric key custody.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-MOB-01: David O'Reilly to determine whether Compose Multiplatform should be evaluated for secondary marketing screens while keeping core banking screens in pure SwiftUI in Q2 (Owner: David O'Reilly).
Next steps
- Mobile Engineering squad provisions the Kotlin Multiplatform shared library repository.
- Security team implements the biometric hardware authentication wrappers for iOS and Android.
- Conduct staging device lab benchmark testing on 50 physical phones to verify sub-1.2s cold startup.
skill: mobile-architect
Mobile Platform Architecture — Fitness Self-Check [MOBARCH-BANK-FIT-001]
Summary
This fitness self-check evaluates the mobile platform architecture against three critical red-capable domain failure probes: dual writer, undefined grain, and silent schema drift. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Dual Writer | Seed an offline-first synchronization scenario where the mobile client and backend cloud service attempt to update the customer address record simultaneously during a network reconnection. | Mobile synchronization conflict resolver probe probe_concurrent_offline_address_split verifying server monotonic timestamp victory with diagnostic ERR_SYNC_CONFLICT_RESOLVED_BY_SERVER_VERSION. | pass | Confirms KMP conflict resolution rules; does not evaluate manual SQLite terminal modifications on rooted devices. |
| FIT-2: Undefined Grain | Seed a candidate mobile analytics event definition that tracks user interactions without specifying an explicit screen identifier, session UUID, or millisecond timestamp grain. | Mobile telemetry schema linter probe_missing_mobile_event_grain verifying analytics ingestion rejection with diagnostic ERR_MOBILE_EVENT_LACKS_DECLARED_GRAIN. | pass | Confirms automated mobile analytics schema validation; does not inspect ad-hoc temporary OS log outputs. |
| FIT-3: Silent Schema Drift | Seed a backend API deployment that renames a required JSON response field (account_balance_cents -> balance) without bumping the mobile API contract version. | KMP Kotlinx.serialization contract validator probe_unannounced_mobile_api_drift verifying payload deserialization error with diagnostic ERR_MOBILE_API_SCHEMA_DRIFT_DETECTED. | pass | Confirms automated Pact contract testing gates; does not evaluate untyped dynamic JSON dictionaries. |
Residual Risk
- Latency overhead (up to 300 ms) during initial cold-start biometric authentication if the device operating system is recovering from a deep hibernation cycle. Accepted by Elena Rostova with asynchronous biometric pre-warming.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of uncoordinated offline write splits | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of mobile telemetry lacking declared grain | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of unannounced mobile API schema drift | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Architecture Guild incorporates mobile fitness probes into automated GitHub Actions mobile build workflows.
- Mobile team configures Firebase Crashlytics alarms monitoring real-time crash-free session ratios.
- Conduct quarterly device lab testing validating offline sync queue replay under simulated flaky cellular connections.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns load-bearing application architecture for software installed on mobile operating systems. It converts accepted journeys, target platforms/devices, lifecycle and connectivity conditions, API/data contracts, device capabilities, security/privacy obligations, release constraints, and measured resource behavior into module, state, navigation, local-data, synchronization, background-work, platform-integration, evolution, and verification contracts.
Use it when
- Native, cross-platform, shared-domain, hybrid, or responsive-web delivery must be compared against platform, journey, team, capability, release, and lifecycle evidence
- App/feature/core/platform module boundaries, public contracts, state flow, or ownership need structural decisions
- Navigation graphs, deep/universal/app links, push taps, widgets/share extensions, authentication gating, and state restoration cross features
- Remote, local, pending, cached, derived, draft, session, and secure state have unclear authority or freshness
- Partial/no connectivity requires read/write availability, sync queues, conflict ownership, tombstones, reconciliation, or user-visible recovery
- Foreground/background/suspended/terminated/upgrade/reinstall states affect journeys and work continuity
For example: “We shipped a breaking API change. Forty percent of our users are still on a version from eight months ago and the app now crashes on launch for them.”
What you get
- architecture/mobile-architect/README.md
- architecture/mobile-architect/00-overview/mobile-architect-overview.md
- architecture/mobile-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/ui-surface.md, {module}/state.md, {module}/api-consumption.md, {module}/accessibility.md, {module}/performance.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use for one screen/widget, visual design, framework syntax, isolated mobile testing/security/performance work, responsive web/PWA, backend APIs, app-store marketing, or choosing technology from keywords such as mobile, offline, push, battery, or cross-platform.
How it works
- Check the scope is the mobile client.
- Decide native versus cross-platform from real requirements.
- Design for the release model you actually have.
- Fix the offline and sync model.
- State the minimum supported version policy and its evidence.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install