advanced 3 min answer

An enterprise software vendor of SAP's shape runs a central design authority: a board of nine meeting fortnightly, 40 product teams, a median of 19 days from submission to decision. Leadership wants it replaced with federated decision-making without losing the ability to say what the company's architecture is. Give the sequence.

design-authorityadrfederationconformancegovernance-migration
Show the full answer Hide the answer

The sequence

  1. Inventory the decisions, not the meetings. Pull the last twelve months of submissions and classify each: repeatable (the same answer every time), advisory (the team was going to do it anyway and wanted cover), and genuinely cross-cutting (two teams would otherwise make incompatible choices). Expect the repeatable category to dominate, which is the finding that makes the rest of the migration arguable. This is the artefact everything else depends on and it takes two people about a week. Reversible: nothing has changed yet.
  2. Convert the repeatable 60% into published standards with automated conformance checks. A decision that has the same answer every time is a rule, and a rule a machine can check is not a meeting. The board stops accepting submissions in those categories on a stated date. Reversible: reopen the category.
  3. Publish the trigger list for what still comes to the authority — irreversibility, a new data or tenancy boundary, regulated data, cross-team interface changes, anything that commits the company to a vendor for more than a set term. Structural triggers, not spend thresholds, because thresholds are split around.
  4. Move the record to ADRs in the teams' own repositories, with a review window rather than an approval queue: reviewers have three working days to object, and silence is assent. Advisory posture — the architect can block only by invoking a trigger.
  5. Migrate the archive before the board stops meeting. This is the point of no return. Once the board is no longer the record of decisions, the ADR store is the only institutional memory, and a decision made in 2019 that nobody can find gets remade badly in 2027.
  6. Sample and measure. Read one in ten ADRs a month. Track decision reversal rate (decisions undone within six months) and time to a recorded decision. Federation is working when reversal rate is flat and lead time has fallen.

Where it diverges and how you would know

The failure mode is not bad decisions; it is unrecorded ones. Teams keep deciding and stop writing, and eighteen months later nobody can say why two products authenticate differently. Detect it by comparing ADR creation rate against change volume: if significant changes are landing without a corresponding ADR, the record is decaying. The automated conformance checks are the second detector, because they catch the drift the missing ADR would have predicted.

The rollback at each stage

Steps 1 to 3 roll back by reopening a submission category. Step 4 rolls back by requiring pre-approval again, which costs a week of annoyance. Step 5 does not roll back, so do it while the board still exists and can validate the archive.

How long it really takes

Two to three quarters, and the constraint is not tooling. It is that step 2 requires someone to write standards precise enough to automate, which is the work the board was avoiding by deciding case by case.

When not to dissolve the board

Keep it when the company is making a genuinely shared bet — one identity platform, one data plane, a migration every product must follow — because federated decisions cannot converge on a choice that only pays off if everyone makes it. Keep it also below about 60 engineers, where the board is three people in a room and the coordination cost is an hour a fortnight. Federation solves a queue; if there is no queue, it just removes the conversation.