Term Kind Topic What it is
Object-Level Authorization BOLA, IDOR concept Authorization Checking that the caller is entitled to the specific record they requested, not merely that they may call the endpoint.
Observability concept Observability The property of being able to answer new questions about a system's internal state from its external outputs, without shipping new code.
Observability Cost concept Observability Cost Monitoring spend that grows with traffic and frequently reaches a meaningful fraction of infrastructure cost — controlled by sampling, cardinality and retention.
Observable Component Contract Rendered Surface Contract, Implicit Component API concept Component Contracts The full set of things a consumer can depend on in a shared component - DOM structure, class names, computed spacing, specificity and render timing - as distinct from its declared props, which is the only part…
Offset Management concept Event Streaming How a consumer records its position in a stream, and the decision that determines whether processing is at-least-once or at-most-once.
OLTP vs OLAP concept Data Warehousing Two workload shapes with opposite requirements — many small indexed transactions versus few large scans and aggregations — which is why they belong in different stores.
One-Way Door Irreversible Decision, Type 1 Decision, Foreclosed Option concept Reversibility A decision whose reversal is prohibitively expensive or impossible, which is where analytical effort belongs - as distinct from the reversible majority, where deliberation typically costs more than being wrong.
One-Way Door Decision Type 1 Decision, Irreversible Decision concept Reversibility A decision that is very costly or impossible to reverse, warranting deliberation proportionate to that permanence.
Operated Reliability Realised Availability concept Reliability vs Complexity The availability a system actually achieves in the hands of the team running it - as distinct from the availability its topology implies.
Operating Effectiveness concept Control Design vs Operation Whether a control actually ran, consistently, over a period — as distinct from whether it was well designed, and the harder of the two to demonstrate.
Operating Model concept Operating Models How an organisation arranges people, process, technology and governance to deliver its capabilities, which constrains architecture as strongly as any technical factor.
Operating Models concept Operating Models How an organisation arranges people, ownership and decision rights to deliver and run systems — which determines what architectures are viable.
Operational Resilience Requirement concept Financial Services Regulation A supervisory expectation that a firm can continue delivering critical business services through disruption, expressed as an impact tolerance it must evidence.
Operational vs Analytical Store concept Polyglot Persistence The separation between the store serving the application's transactions and the one serving reporting and analysis, and the mechanism connecting them.
Operator Independence concept Digital Sovereignty The requirement that no foreign entity can be compelled to access or disclose data, which goes beyond where the bytes are stored to who controls the operator.
Organisational Constraints concept Organisational Constraints The structural, procedural and human limits that determine which designs can actually be built and operated here.
Organisational Readiness concept Organisational Constraints Whether an organisation has the skills, capacity, structure and appetite to operate a proposed architecture, independent of the design's technical merit.
Orphaned Resource concept Waste Elimination Infrastructure that is billed but serves nothing, typically left behind when the thing it supported was deleted.
Outcome over Output concept Product Thinking Measuring and committing to changes in user or business behaviour rather than to the delivery of features.
Over-Classification Label Inflation, Maximum Propagation Collapse concept Sensitivity Labelling The state in which so much of an estate carries the highest sensitivity label that its controls become unworkable, and people route around them - producing less protection than a coarser scheme would.
Over-Engineering concept Pragmatism Building capability the requirements do not justify, paying its complexity cost continuously in exchange for flexibility that is rarely used.
Over-Fetching concept API Shapes for UI Transferring fields the interface will not display, which costs bandwidth and parse time on exactly the devices least able to afford them.
OWASP Risks OWASP Top Ten concept OWASP Risks The recurring application vulnerability classes — and the architectural decisions that make each one structurally unlikely.
PACELC concept CAP & PACELC An extension of CAP stating that during a partition you trade availability against consistency, and else — in normal operation — you trade latency against consistency.
Parallelism and Concurrency concept Concurrency The distinction between structuring work so it can make progress independently and actually executing work simultaneously on multiple cores.
Partial Index Filtered Index concept Indexing An index built over only the rows matching a predicate, so it is far smaller and cheaper to maintain than a full index.
Partition Assignment concept Competing Consumers The mapping of partitions to consumer instances that determines parallelism, ordering guarantees and what happens when the consumer set changes.
Partition Count Immutability Fixed Partition Count, Key-to-Partition Remap Hazard concept Partition Keys & Ordering The partition count of a keyed log is effectively permanent, because raising it changes which partition a key hashes to and therefore breaks per-key ordering and every table rebuilt by replaying that log.
Partition Key Skew Hot Partition, Key Skew concept Partition Keys & Ordering One partition receiving disproportionate traffic because a small number of key values dominate, capping throughput at what a single consumer can handle.
Partition Pruning concept Storage Layout & Partitioning The query engine skipping entire partitions whose values cannot match the filter, which is where most large-table query performance comes from.
Partition Tolerance concept CAP & PACELC The ability to keep operating when the network drops or delays messages between nodes — not a choice, but a property of any system spanning more than one machine.
Partitioning and Sharding concept Partitioning & Sharding Splitting data by a key — within one database for manageability, or across databases for capacity and isolation.
Pass-Through Cost of Goods Sold Third-Party Unit Cost, Supplier Pass-Through Term concept Cost per Request The part of the cost of serving one unit that is paid to a third party per transaction, which infrastructure optimisation cannot reduce and which eventually decides whether unit cost keeps falling.
Path MTU Discovery PMTUD concept Network Troubleshooting The mechanism by which a sender discovers the largest packet size a path supports, and a common cause of connections that establish and then hang.
Path MTU Discovery Failure MTU Black Hole, PMTUD Blackhole concept Network Troubleshooting Large packets silently discarded because the ICMP messages that would report the size limit are blocked - producing the signature "small requests work, large transfers hang".
Pattern Overuse concept Design Patterns Applying a design pattern where the problem it solves does not exist, adding indirection and vocabulary without benefit.
Pattern Scope Discipline Apply the Pattern to a Use Case, Not the System concept CQRS The rule that heavyweight data patterns - CQRS, event sourcing, materialised read models - belong to the specific part of a domain that needs them, never to a whole product.
Payload Compression Trade-off concept Network Performance Tuning The exchange of CPU time for reduced transfer time, which is favourable on constrained networks and harmful on fast local ones.
Performance versus Cost concept Performance vs Cost The trade between latency and spend — where headroom is the mechanism and high utilisation is the false economy.
Permission Boundary concept Identity & Access Management A policy limiting the maximum permissions an identity can have, used so that the ability to create roles does not become the ability to grant unlimited privilege.
Personally Identifiable Information PII, Personal Data concept Security Architecture Data relating to an identifiable person — a category far broader than name and address, and the trigger for most regulatory obligation.
Physical World Failure Mode concept Physical-World Failure Modes The failure classes that only exist once software controls or observes physical equipment, where the system cannot be restarted and the consequences are not confined to data.
Pipeline Stage Contract concept Delivery & Release Engineering What each pipeline stage promises the next — an artifact of a stated shape plus a specific claim about it that has been verified.
Pivot Transaction concept Sagas & Compensation The step in a saga after which the transaction can no longer be cancelled — everything before it is compensatable, everything after it is retriable until it succeeds.
Platform Abstraction Level concept Abstraction Level Choice How far a platform hides the underlying infrastructure, and the leak-versus-flexibility trade it makes at that height.
Platform API concept Platform APIs The programmatic contract through which teams consume platform capabilities, and the thing that must stay stable while everything behind it changes.
Platform Bypass Signal Adoption as Feedback, Voluntary Platform Use concept Platform as a Product Teams routing around an internal platform read as a product signal about the platform's fitness, not as a compliance failure to be solved with a mandate.
Platform Contract concept Platform APIs The platform's promise to its consumers about interface stability, behaviour and support, treated with the same seriousness as an external API.
Platform Engineering concept Platform Engineering Building internal products that reduce the cognitive load on delivery teams — with self-service as the property that separates it from a service desk.
Platform Funding Model concept Platform Funding How internal platform work is paid for, which determines what the platform optimises for and whether it survives a budget cycle.
Platform Lifecycle Constraint concept Mobile App Architecture The operating system's rules about when your process runs, which are not negotiable and invalidate most assumptions carried over from server code.
Platform Teams concept Platform Teams Teams providing self-service internal capability to reduce the cognitive load on delivery teams — distinguished from a service desk by self-service.
Pod concept Kubernetes The smallest deployable unit in Kubernetes — one or more containers that share a network namespace, storage volumes and a lifecycle, scheduled together on one node.
Point-in-Time Correctness As-Of Join, Temporal Correctness, Leakage Prevention concept Semantic Layer Retrieving each feature's value as it was at the moment of the event rather than its current value, which is what prevents a model from training on information that did not exist yet.
Point-in-Time Recovery PITR concept Backup Strategies Restoring a database to any moment within a retention window by replaying transaction logs onto a base backup, rather than only to a snapshot boundary.
Poison Message concept Dead Letter Handling A record that a consumer cannot process and cannot skip, which halts its partition entirely until someone intervenes.
Policy Bypass Surface Enforcement Gap, Derived-Object Leak concept Row & Column-Level Security The set of objects and paths through which data protected by a row or column policy can be read without that policy being evaluated - typically derived objects refreshed under a privileged identity.
Policy Failure Mode Admission Fail-Open, Fail-Closed Policy concept Policy as Code What an admission-time policy engine does when it cannot be reached - fail open and allow the change, or fail closed and block it - decided per policy class rather than globally, because a uniform answer is wr…
Polyglot Persistence concept Polyglot Persistence Using different storage engines for different workloads within one system — justified by genuine workload divergence, and frequently not.
Port Exhaustion concept NAT & Egress Running out of available source ports for outbound connections through a NAT device, causing new connections to fail while everything appears healthy.