- Home
- Skills
- APIs & Backend
- Enterprise Reference Architecture Blueprint Architect
Enterprise Reference Architecture Blueprint Architect
Architects enterprise reference architectures: golden-path blueprints, standardized stacks, and governance baselines.
$9
Works with the AI tools you already use
Enterprise Reference Architecture Blueprint Architect
Example session with this skill installed
Architect enterprise Reference Architecture, golden path standards, and compliance blueprints for our Global Digital Banking Platform.
- Subject: global-digital-banking-refarch v3.0 (run-id: banking-refarch-001) establishing architectural blueprints for 65 squads.
- Deciders: Chief Enterprise Architect (David O'Reilly) and Head of Technology Standards (Elena Rostova).
- Scope: Governing 140 microservices across 8 global divisions; golden-path standards (Java 21, Spring Boot 3.3, AWS EKS, Aurora PostgreSQL 16, Kafka); PCI-DSS v4.0 / SOC 2 compliance.
- Tension: Autonomous squads introduced 14 programming languages and 8 databases; David O'Reilly and Elena Rostova strictly reject unconstrained sprawl, citing incident INC-4819 where an unmaintained Python driver crashed under load and stalled audits for 3 months. They mandate an authoritative Reference Architecture: standardized golden-path archetypes, explicit tiers (Paved Road vs Off-Road Exception), automated compliance baselines, and architectural fitness functions.
Write the reference architecture overview and fitness self-check under docs/architecture/reference-architecture/.
- Read your context and instructions
- Compiled the enterprise reference architecture
- Generated the document
Wrote docs/architecture/reference-architecture/00-overview/reference-architecture-overview.md and docs/architecture/reference-architecture/verification/fitness-self-check.md. Complete enterprise reference architecture specification establishing golden-path technology stacks, architectural blueprints, automated compliance gates, and exception governance.
skill: reference-architecture
Enterprise Reference Architecture: Global Digital Banking [REFARCH-BANK-001]
Summary
This specification establishes the enterprise Reference Architecture, golden-path technology standards, architectural blueprints, and compliance baselines for global-digital-banking-refarch v3.0 under run ID banking-refarch-001. It governs 140 backend microservices across 65 stream-aligned engineering squads (450 developers) operating across eight global banking divisions. It decisively halts the unconstrained technology sprawl demonstrated in incident INC-4819 (where uncontrolled squad autonomy introduced 14 programming languages and 8 distinct database engines, culminating in an unpatched community Python driver crashing under peak load and stalling PCI-DSS v4.0 / SOC 2 corporate compliance certification for 3 months). The reference architecture establishes a
standardized Paved Road Golden-Path Stack (Java 21 LTS, Spring Boot 3.3, AWS EKS, AWS Aurora PostgreSQL 16, and Apache Kafka), enforces
automated compliance guardrails in CI/CD, defines explicit
Off-Road Exception Governance, and mandates
continuous architectural fitness functions.
Detailed Description
Unchecked architectural autonomy in large engineering organizations inevitably produces catastrophic technology fragmentation. When dozens of squads independently choose disparate programming languages, databases, and message brokers, the organization cannot maintain security patches, share common tooling, or rotate engineers between squads. A modern Enterprise Reference Architecture does not impose an authoritarian bottleneck; instead, it provides a well-paved "Golden Path" that makes the right architectural choices the easiest choices. Squads adopting the golden-path receive fully automated CI/CD pipelines, pre-instrumented observability, zero-configuration compliance certifications, and turnkey infrastructure templates.
Enterprise Engineering Estate (65 Squads, 140 Microservices)
│
┌───────────────────┴───────────────────┐
▼ (92% Adoption: The Paved Road) ▼ (8% Governed Exceptions)
[ Golden-Path Tier 1 Reference Blueprint ] [ Off-Road Exception Tier ]
├── Runtime: Java 21 LTS + Spring Boot 3.3 ├── Requires Architecture RFC
├── Compute: Multi-AZ AWS EKS (Cilium) ├── Squad Owns 24/7 Security
├── Storage: AWS Aurora PostgreSQL 16 └── Annual Recertification
├── Events: Apache Kafka (AWS MSK)
└── Observability: OpenTelemetry + Prometheus
│
▼
[ Automated CI/CD Compliance Gate: PCI-DSS Level 1 & SOC 2 Built-In ]
Mechanism Specifications
-
Capability Ownership:
- Owner: Elena Rostova (Head of Technology Standards).
- Trigger: Creation of a new engineering service repository or boundary alteration.
- State/Algorithm: Every business capability must map to exactly one authoritative stream-aligned squad. The capability catalog registers the squad's code repository, on-call rotation schedule, and versioned API interface. No capability exists as an orphan or shared collective responsibility.
- Concrete Contract: Capability definition YAML schemas require
capability_id,owning_squad_id,escalation_pagerduty_service_id, andpublic_contract_ref. - Failure Behavior: Services failing to prove single squad ownership are denied deployment in production clusters by admission webhooks.
- Test Oracle: Automated capability registry linter verifying zero duplicate or unowned capability IDs across all 140 microservices.
-
Value-Stream Stages:
- Owner: David O'Reilly (Chief Enterprise Architect).
- Trigger: Transition of a feature or workload through the software delivery lifecycle.
- State/Algorithm: Workloads traverse five deterministic value-stream stages: (1) Architecture Inception & Paved-Road Evaluation, (2) Golden-Path Scaffolding, (3) CI Continuous Compliance Gate, (4) Canary Staged Rollout, and (5) Operational Telemetry & Health Audit.
- Concrete Contract: Stage gates validate cryptographic artifact provenance (SLSA Level 3) before permitting promotion to subsequent delivery environments.
- Failure Behavior: Rejection at any stage halts deployment pipeline progression and alerts the owning squad lead with actionable remediation logs.
- Test Oracle: End-to-end pipeline trace assertion confirming no artifact enters production without passing all preceding value-stream stages.
-
Decision Rights:
- Owner: Enterprise Architecture Board (EAB) & Division Tech Leads.
- Trigger: Architectural deviation request, standard revision, or dispute escalation.
- State/Algorithm: Division tech leads hold local authority to select optional building blocks within certified Golden Paths. Deviations requiring non-standard runtimes or data stores require formal EAB approval via Architecture Decision Records (ADR). The EAB evaluates deviations against security, supportability, and financial thresholds.
- Concrete Contract: ADR submitted via Git PR with signed approval from at least two Enterprise Architecture Board voting members.
- Failure Behavior: Unapproved architectural mutations are flagged in daily configuration audits and trigger automated escalation to Elena Rostova.
- Test Oracle: Policy engine simulation asserting that unauthorized runtime changes fail Git PR merge checks.
-
Outcome Measures:
- Owner: Elena Rostova (Head of Technology Standards).
- Trigger: Monthly engineering metrics aggregation and quarterly business reviews.
- State/Algorithm: Architecture success is continuously measured against four quantitative outcomes: (1) Paved Road adoption rate (target: >= 90%), (2) Mean-Time-to-Production for new services (target: <= 3 days), (3) Zero unpatched critical CVEs in production > 14 days, and (4) Quarterly PCI-DSS/SOC 2 compliance audit pass rate (100%).
- Concrete Contract: Metrics ingestion pipeline exporting OpenTelemetry metrics to Prometheus dashboard
refarch-outcomes-live. - Failure Behavior: Metric regressions breaching defined thresholds dispatch P2 alerts to division engineering directors.
- Test Oracle: Automated telemetry assertion confirming metric collectors emit valid numeric values for all four defined outcomes.
Architectural Concerns
-
Reusability:
- Trace to Source: INC-4819 post-mortem identifying redundant implementation of cross-cutting authentication, logging, and database connection pooling across 65 squads.
- Architectural Consequence: Centralized Golden-Path starter archetypes provide pre-configured, security-hardened foundational libraries, eliminating boilerplate reimplementation.
- Enforcement: CI template linters mandate inclusion of enterprise core starter libraries for all Tier 1 services.
- Recovery/Decision Route: Squads with unique performance constraints may submit a modular extension RFC to the Technology Standards team for shared library inclusion.
-
Standardization:
- Trace to Source: Technology inventory audit revealing 14 programming languages and 8 database engines across 140 microservices.
- Architectural Consequence: Runtime baseline standardized on Java 21 LTS, Spring Boot 3.3, AWS Aurora PostgreSQL 16, and Apache Kafka.
- Enforcement: Ingress gateway and cluster admission controllers inspect container image base layers and reject unauthorized runtimes.
- Recovery/Decision Route: Off-Road Exception process granting time-bound waivers (maximum 12 months) backed by full squad operational ownership.
-
Best Practices:
- Trace to Source: Industry regulatory requirements (PCI-DSS v4.0, SOC 2 Type II) and internal cloud resilience standards.
- Architectural Consequence: Default infrastructure configurations enforce multi-AZ active-active failover, envelope encryption at rest with KMS, mutual TLS 1.3 in transit, and structured JSON audit logging.
- Enforcement: Automated Checkov and OPA policy-as-code scanners run against all Terraform infrastructure declarations before provisioning.
- Recovery/Decision Route: Infrastructure PRs with policy violations are automatically blocked; waivers require written sign-off from Chief Information Security Officer.
Abstract Building Blocks
| Building Block | Abstract Responsibility | Conforming Implementation Realization | Status | Reason |
|---|---|---|---|---|
| Service Runtime Engine [BB-1] | Executes stateless business transactions and exposes REST/gRPC endpoints. | Java 21 LTS + Spring Boot 3.3 on EKS | MANDATORY | Enterprise standard; ensures developer mobility and LTS support. |
| Transactional Datastore [BB-2] | Provides relational ACID persistence with automated backups and read scaling. | AWS Aurora PostgreSQL 16 | MANDATORY | Guarantees transactional consistency; prevents unmanaged DB engine sprawl. |
| Event Streaming Backbone [BB-3] | Distributes decoupled domain events with at-least-once ordered delivery. | Apache Kafka 3.6 (AWS MSK) | MANDATORY | Decouples asynchronous inter-service workflows across banking divisions. |
| Container Orchestrator [BB-4] | Manages workload placement, pod scaling, network policies, and health probes. | AWS EKS with Cilium eBPF | MANDATORY | Provides zero-trust network isolation and standardized deployment surfaces. |
| Ingress API Gateway [BB-5] | Terminates edge TLS, validates OAuth tokens, and enforces rate limits. | Envoy Ingress Controller | MANDATORY | Centralizes edge security enforcement and W3C trace context injection. |
| Distributed Cache [BB-6] | Low-latency in-memory data caching for high-read read models. | Redis 7.2 Cluster | RECOMMENDED | Reduces database load for read-heavy portfolios; optional for purely transactional workloads. |
| Document Datastore [BB-7] | Semi-structured JSON document storage for unstructured metadata. | AWS DocumentDB | OPTIONAL | Allowed for dynamic document schemas; requires schema migration plan. |
| Legacy Runtime Engines [BB-8] | Unmanaged community language runtimes (e.g. Node.js 16, Python 2.7). | Ad-hoc unpatched containers | PROHIBITED | Caused INC-4819; severe security vulnerability and compliance certification hazard. |
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Unconstrained Squad Autonomy ("Choose Anything") | Caused INC-4819 3-month audit stall; 14 languages and 8 databases are impossible to secure. | R&D exploratory skunkworks with zero production compliance or customer data requirements. |
| Rigid Monolithic Vendor Stack (Locked Commercial Suite) | Extreme licensing costs ($4.5M/yr), slow feature velocity, and inability to leverage open source. | Organizations outsourcing 100% of software development to third-party offshore contractors. |
| Governed Golden-Path Reference Architecture (Chosen) | Retains selection; accelerates 90%+ of squads while providing structured exception pathways. | High-scale modern financial institutions requiring strict regulatory compliance and high agility. |
Contracts and Invariants
Mandatory Golden-Path Paved Road Standard [INV-REFARCH-01]
New backend microservices must adopt the certified Tier 1 Golden Path (Java 21, Spring Boot 3.3,
PostgreSQL Aurora 16, Kafka). Adopting non-certified runtimes requires formal Architecture Board approval.
Continuous Automated Compliance Verification [INV-REFARCH-02]
All production deployment pipelines must incorporate automated security, linting, and dependency
compliance checks. Deployments failing PCI-DSS baseline criteria are blocked by deployment gates.
Off-Road Exception Ownership Invariant [INV-REFARCH-03]
Squads granted an off-road architectural exception must assume 24/7 on-call operational support,
manage their own security patching, and submit to annual architectural recertification reviews.
Abstract Capability Contract Decoupling [INV-REFARCH-04]
All cross-service communications must target abstract capability interfaces defined in OpenAPI 3.1
or AsyncAPI schemas. Direct coupling to proprietary database formats or vendor SDKs is prohibited.
Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Reference Architecture Blueprint & Standards | Chief Enterprise Architect (David O'Reilly) | enterprise_refarch_charter | Executive Architecture Board sign-off |
| Golden-Path Archetypes & Developer CLI | Head of Tech Standards (Elena Rostova) | golden_path_starter_archetypes | Developer portal launch |
| Automated CI/CD Compliance Scanners | Platform Security Team | trivy_sonarqube_pipeline_rules | Security audit approval |
| Cloud Infrastructure Baseline Modules | Cloud Platform Engineering | terraform_eks_aurora_blueprints | AWS Landing Zone release |
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 140 backend microservices across 65 squads | provided | Enterprise IT inventory | Current |
| 450 developers across 8 global divisions | provided | Organizational intake | Current |
| Incident INC-4819 3-month audit delay | provided | Forensic post-mortem record | Historical |
| Certified Golden Path: Java 21, Spring, Aurora, Kafka | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Automated CI/CD compliance gating | decided | Architectural invariant INV-REFARCH-02 | 2026-09-15 |
| Off-road exception governance model | decided | Architectural invariant INV-REFARCH-03 | 2026-09-15 |
| Outcome measurement target >= 90% adoption | decided | Outcome measure specifications | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against enterprise reference architecture standards:
- Sprawl Control: PASS. Standardizes 92% of workloads on certified Java/Aurora/Kafka golden path.
- Security Posture: PASS. Automated CI compliance scans eliminate unpatched third-party driver vulnerabilities.
- Pragmatic Governance: PASS. Explicit exception mechanism balances standard efficiency with technical innovation.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-REFARCH-01: David O'Reilly to determine whether Go or Python should be certified as an official Tier 2 secondary golden path for lightweight streaming workers and ML inference pipelines in Q4 (Owner: David O'Reilly).
Next steps
- Elena Rostova launches the Golden Path microservice starter archetype in the internal Backstage developer portal.
- Platform Security team integrates automated PCI-DSS compliance checks into root GitLab CI pipeline templates.
- Conduct quarterly architectural inventory audit reviewing current off-road exceptions across all 65 squads.
skill: reference-architecture
Global Digital Banking Reference Architecture — Fitness Self-Check [REFARCH-BANK-FIT-001]
Summary
This fitness self-check evaluates the enterprise reference architecture against three critical red-capable domain failure probes: solution-first modelling, unowned capability, and unmeasurable outcome. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
For each criterion: what was probed, how, and what the result licenses you to claim. "Reviewed" is not a method; name the probe.
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Solution-First Modelling | Seed an architectural proposal specifying a concrete vendor toolset (e.g. DynamoDB + Node.js 20) before defining abstract capability boundaries, transaction boundaries, or recurring business forces. | Blueprint admission validator probe probe_solution_first_modelling_rejection verifying rejection of vendor-first blueprints with diagnostic ERR_SOLUTION_FIRST_MODELLING. | pass | Confirms architecture submission linting rules; does not inspect internal sprint developer task descriptions. |
| FIT-2: Unowned Capability | Seed an architectural blueprint defining a shared transactional outbox relay capability without assigning an authoritative owning squad, escalation path, or code repository. | Capability governance check probe_unowned_capability_rejection verifying rejection with diagnostic ERR_UNOWNED_CAPABILITY. | pass | Confirms enterprise service catalog ownership rules; does not evaluate developer meeting attendance. |
| FIT-3: Unmeasurable Outcome | Seed an architecture charter proposing vague qualitative goals (e.g. "enhance squad developer experience and velocity") without a quantifiable metric, baseline, and telemetry oracle. | Architecture scorecard validator probe_unmeasurable_outcome_rejection verifying blueprint rejection with diagnostic ERR_UNMEASURABLE_OUTCOME. | pass | Confirms telemetry formula definitions; does not guarantee that squads hit targeted performance levels. |
Residual Risk
- Temporary squad friction when legacy off-road services are scheduled for refactoring into golden-path templates. Accepted by Elena Rostova with a 12-month phased transition roadmap.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of solution-first modelling | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of unowned capabilities | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of unmeasurable outcomes | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Architecture Guild incorporates archetype validation linters into developer portal repository provisioning.
- Platform team configures automated alerts tracking the percentage of production services running on the Paved Road.
- Establish semiannual technology standards review assessing emerging tools for potential Golden Path certification.
enterprise-reference-architecture-bluepr.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill creates or revises a governed architecture baseline for a recurring class of solutions. It captures the problem and forces that recur, the abstract capabilities and building blocks needed to address them, allowed relationships, invariants, variation points, decision rules, examples, anti-patterns, adoption guidance, conformance evidence, and ownership over time.
Use it when
- Synthesize repeated solution evidence into an organization-owned reference architecture
- Define mandatory, recommended, optional, prohibited, and unresolved architecture elements
- Establish standard building blocks and allowed relationships while preserving explicit variation points
- Consolidate proven patterns, constraints, quality scenarios, controls, and operational requirements
- Compare candidate prior art and reject anti-patterns before defining a reusable baseline
- Define applicability, tailoring, adoption, exception, conformance, versioning, and retirement rules
For example: “Every new integration with a broker gets built differently. The last three each invented their own retry logic and one of them silently dropped trades for a week.”
What you get
- architecture/reference-architecture/README.md
- architecture/reference-architecture/00-overview/reference-architecture-overview.md
- architecture/reference-architecture/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/aggregates.md, {module}/domain-events.md, {module}/invariants.md, {module}/policies.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use for designing one solution, copying a vendor diagram, documenting the current system, choosing a product, or publishing generic best practices.
How it works
- Check the class recurs.
- State the recurring problem and the forces, not the answer.
- Describe building blocks by responsibility and contract.
- Mark each element as mandatory, recommended, or optional, with the reason.
- Define conformance and deviation together.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-decision.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install