Term Kind Topic What it is
Seam Identification practice Strangler Fig Locating the places in a legacy system where behaviour can be intercepted and redirected, which determines whether an incremental migration is feasible at all.
Seasonality-Aware Threshold Same-Weekday Baseline, Seasonal Band practice Data Quality Dimensions Setting a data quality alarm against the comparable period rather than the previous one, so that a business's own weekly and monthly rhythm does not generate alerts nobody can act on.
Second-System Effect concept Trade-off Fundamentals The tendency for a replacement system to accumulate every capability the first one lacked, producing something more complex than either the old system or the problem requires.
Secret Zero Bootstrapping Problem concept Secrets Management The credential a workload needs in order to authenticate to the secret manager — the one secret that cannot itself be stored in the secret manager.
Secret Zero Problem concept Secrets Management The credential a workload needs in order to authenticate to the secret manager, which cannot itself be stored in the secret manager.
Secrets Management practice Security Architecture Storing, distributing, rotating and auditing credentials so that they never live in code, images or configuration files.
Sector Cloud Rules concept Sector Cloud Rules Sector-specific rules governing cloud use — outsourcing notification, audit rights, concentration risk and exit — which shape provider and service choices.
Secure Aggregation Private Aggregation, Cohort-Level Aggregation protocol Privacy-Enhancing Technologies A cryptographic protocol that lets a server learn only the sum of many clients' model updates and never any single client's update, which is what makes an on-device training claim survive scrutiny.
Secure API Design practice Secure API Design Building an interface where the safe path is the default and the unsafe one requires deliberate effort.
Secure Boot Chain protocol Edge Security & Attestation Each boot stage verifying the signature of the next before executing it, anchored in immutable hardware, so only authorised software runs.
Security Design Review practice Security Design Review A structured examination of an architecture's security properties before it is built, focused on trust boundaries and threat paths rather than on a checklist.
Security Group Firewall Rules, NSG tool Networking A stateful, instance-level firewall that allows specified traffic and denies everything else by default.
Security Group Sprawl concept Network Security The accumulation of firewall and security group rules that nobody can safely remove, producing a permissive posture nobody chose.
Security Incident Response practice Security Incident Response Responding to a compromise — where the architecture determines whether you can detect it, contain it, and prove what happened.
Security Testing in the Pipeline Shift-Left Security, SAST/DAST/SCA practice Security Testing in the Pipeline Automated security analysis embedded in the build, chosen and tuned so that findings are actionable rather than overwhelming.
Security versus Usability concept Security vs Usability Controls that impose too much friction get circumvented — so the usable control is frequently the more secure one.
Segment-Isolated Serving Outlier Tenant Path, Heavy-User Isolation pattern Tail Latency Giving a consistently slow population its own path - pool, precomputed view, or query strategy - rather than optimising the shared path to accommodate it.
Segregation of Duties SoD, Separation of Duties concept Segregation of Duties Ensuring no single individual can both initiate and approve a sensitive action, so that fraud or error requires collusion.
Selective Reliability Partial Reliability, Deadline-Aware Delivery concept Pipes and Filters Retransmitting only what is still useful and discarding what has expired - because for time-sensitive data, late delivery consumes capacity without providing value.
Selector Dependency Label Contract, Implicit Platform Dependency concept Cluster Architecture A production dependency that exists only as a string matching a label or annotation, so it is invisible to code search and to release notes, and a platform upgrade that renames the label silently removes it.
Self-Service Provisioning practice Self-Service Provisioning A developer obtaining infrastructure through an automated interface bound by policy, with no ticket and no human approval in the path.
Self-Service versus Governed concept Self-Service vs Governed Balancing analyst autonomy against consistency — resolved by tiers and enforced definitions rather than by restricting access.
Semantic Cache pattern AI-Era Architecture Caching model responses keyed by the meaning of the request rather than by its exact text, so near-duplicate questions are served without a model call.
Semantic Chunking practice Chunking & Retrieval Splitting documents along their meaning and structure rather than at fixed character counts, because retrieval quality is bounded by chunk quality.
Semantic Coupling Meaning Drift, Invisible Event Coupling concept Publish/Subscribe Dependence on what an event or field means rather than on its shape - the coupling that survives every schema check, breaks nothing when violated, and is the hardest failure to detect in an event-driven system.
Semantic Diffing of API Schemas practice Backward Compatibility Comparing the published contract between builds and failing the build on a breaking change, so compatibility is mechanical rather than remembered.
Semantic Layer Metrics Layer, Headless BI pattern Semantic Layer A single governed definition of business metrics and entities, sitting between physical tables and every consuming tool.
Semantic Schema Break Wire-Compatible Meaning Change concept Streaming Schema Evolution A change that keeps a field's wire format valid while changing what its values mean, so every compatibility check passes and every consumer computes a wrong answer without raising an error.
Semantic Versioning SemVer practice API Versioning A version scheme where the number itself states the compatibility promise — major for breaking, minor for additive, patch for fixes.
Sensitivity Analysis What-Would-Change-The-Answer Analysis practice Trade-off Analysis Methods Identifying which assumption, if wrong, would change the decision - which tells you what to measure early and what to design to change cheaply.
Sensitivity Labelling Data Classification Tagging practice Sensitivity Labelling Attaching a machine-readable classification to data at the column or asset level, so that downstream controls can be applied automatically.
Sensitivity Propagation concept Sensitivity Labelling The rule that a derived dataset inherits the highest sensitivity of its inputs unless a named transformation demonstrably lowers it.
Sensor Input Validation Telemetry Plausibility Checking, Physical Input Sanitisation practice Physical-World Failure Modes Treating readings from physical devices as untrusted input requiring plausibility checks - because a sensor that fails toward a well-formed wrong value is far more damaging than one that stops reporting.
Separation of Concerns concept Separation of Concerns Organising a system so that one kind of change touches one place, and so that different concerns can fail and scale independently.
Separation of Concerns concept Architecture Fundamentals Organising a system so each part addresses one concern, and a change to that concern touches one part.
Sequence Diagram practice Architecture Communication A diagram showing the ordered exchange of messages between participants over time, used to make an interaction's control flow and failure points explicit.
Sequence Diagrams practice Sequence Diagrams Showing the order of interactions over time — the only common diagram that makes latency, ordering and failure behaviour visible.
Server Name Indication SNI, TLS Host Extension protocol TLS & Certificates The cleartext hostname a client sends in its first TLS message, letting one address serve many certificates and letting a proxy route a session before it decrypts anything.
Server State Versus UI State concept Client State Architecture The distinction between data owned elsewhere and cached locally, and state that exists only in this session — conflating them causes most client state bugs.
Server-Driven UI Backend-Driven UI, Remote Screen Definition pattern Mobile Release Strategy Describing screens as data returned by the server and rendered by native components - removing the app-store release from the change loop, in exchange for a permanent compatibility contract with every version …
Server-Sent Events SSE, EventSource protocol WebSockets & Realtime A one-way streaming protocol over plain HTTP in which the server pushes text events to the client on a long-lived response.
Server-Side Request Forgery SSRF concept OWASP Risks Inducing a server to make an HTTP request to an attacker-chosen destination, turning it into a proxy into networks and services the attacker cannot reach directly.
Serverless concept Cloud Architecture A model where the provider allocates and scales compute per request, and you are billed for execution rather than for provisioned capacity.
Serverless Cold Start concept Serverless The additional latency when a function invocation must allocate and initialise a new execution environment rather than reusing a warm one.
Serverless Compute in Practice Functions as a Service, FaaS concept Serverless Compute billed per invocation with no capacity to manage — excellent for bursty low-duty-cycle work, expensive and constrained for sustained load.
Service Boundary concept Software Architecture The line separating what one service owns and is accountable for from what it must ask another service about.
Service Boundary Heuristics practice Service Boundaries The signals that indicate where a service boundary belongs, and the ones that reliably mislead.
Service Catalogue Entry concept Internal Developer Platform The record that makes a service a first-class object in the platform — owner, dependencies, docs, runbooks and health in one place with a single identity.
Service Control Policy SCP, Azure Policy, Organization Policy tool Landing Zones An organisation-level guardrail that limits what any identity in an account may do, regardless of the permissions granted within that account.
Service Discovery pattern Service Discovery How a caller finds a healthy instance of a callee in an environment where instances appear and disappear continuously.
Service Discovery concept Distributed Systems The mechanism by which a caller finds a currently healthy network address for a service whose instances are ephemeral.
Service Level Agreement SLA concept Reliability & Resilience A contractual commitment about service level, with a defined remedy — usually a service credit — when it is missed.
Service Level Indicator SLI metric Reliability & Resilience The actual measurement of a service's behaviour that an objective is set against — a ratio of good events to valid events.
Service Level Objective SLO metric Reliability & Resilience An internal target for a service level indicator, set below the level at which users notice, and used to decide whether to ship or to stabilise.
Service Maturity Scorecard Production Readiness Scorecard practice Platform Adoption An automated per-service assessment against the organisation's operational standards, visible to the owning team.
Service Mesh tool Service Mesh Moving connection-level concerns — discovery, retries, timeouts, mTLS, telemetry — out of application code and into a proxy alongside every service.
Service Mesh tool Architecture Patterns An infrastructure layer of sidecar proxies that handles service-to-service networking — mTLS, retries, timeouts, routing, telemetry — outside the application.
Service Mesh Networking concept Service Mesh Networking What a mesh actually does at the network level, the cost per hop, and the shift from sidecar to shared-proxy models.
Service Mesh Operational Cost concept Service Mesh Operations The ongoing engineering burden a mesh imposes — upgrades, proxy debugging, latency overhead and control-plane availability — weighed against the capabilities it provides.
Service Quota Service Limit concept Cloud Governance A per-account, per-region cap on how much of a resource may be used — a common and easily-avoided cause of scaling failures and DR failures.