Term Kind Topic What it is
Testability as a Design Property concept Test Architecture Strategy How cheaply a system's behaviour can be observed and controlled, which is decided by architecture and largely fixed before any test is written.
Testing in Production TIP practice Testing in Production Deliberately validating behaviour against real traffic, data and scale, using controls that bound the blast radius.
Testing Strategies practice Testing Strategies Choosing what to test at which level, optimising for confidence per unit of time and maintenance rather than for coverage.
Testing Strategy Shape concept Testing Strategies The distribution of tests across levels, chosen so that feedback is fast where it can be and confidence is real where it must be.
Testing Trophy concept Test Pyramid Shapes A distribution weighted towards integration tests rather than unit tests, appropriate where most of the risk lives at boundaries rather than in logic.
The Spotify Model and Why Its Authors Warned Against Copying It Squads and Tribes case-study Platform Team Topologies An influential description of Spotify's team structure was widely adopted as a template, and people who were there have since cautioned that it was aspirational and never fully implemented.
Theory of Constraints concept Constraint Thinking The principle that a system's throughput is set by a single binding constraint, so improvement anywhere else produces nothing.
Third-Party Risk Assessment Vendor Risk, Supplier Assurance practice Third-Party Risk Evaluating the security, resilience and compliance posture of suppliers whose failure would become your incident.
Third-Party Script Governance Page as an Execution Environment, Vendor Script Review practice Frontend Security Reviewing and constraining what executes on a page, because every third-party script runs with the page's full privileges - and each one is added individually while the aggregate determines the security posture.
Third-Party Weight Budget Tag Budget, Non-Application Script Allowance metric Web Performance Budgets An enforced allowance for scripts the application build does not produce - count, bytes and main-thread time - with a named owner and a technical enforcement point, because these are the scripts a bundle-size …
Thread Pool Isolation pattern Bulkheads & Isolation Giving each downstream dependency its own pool of threads or permits, so one slow dependency cannot consume the capacity needed to serve everything else.
Threat Model Trust Boundary concept Threat Modelling The line across which data or control passes from a less trusted context to a more trusted one, and where validation and authorisation must occur.
Threat Modelling practice Security Architecture A structured exercise that identifies what can go wrong with a design, before it is built, by walking the system's trust boundaries.
Three Lines Model Three Lines of Defence concept Three Lines Model The organisational separation between those who own and manage risk, those who oversee and challenge, and those who provide independent assurance.
Throughput metric Throughput Work completed per unit time — bounded by the system's narrowest resource, and traded against latency.
Thundering Herd concept Distributed Systems A large number of clients acting simultaneously because they were synchronised by a shared event, producing a spike that the steady-state design never sized for.
Ticket Ops Ticket-Driven Operations concept Self-Service Provisioning An operating model where teams obtain infrastructure and change by requesting it from another team, making that team a queue.
Tiered Storage Remote Storage Offload, Long-Term Log Retention, Hot-Cold Log Tiering pattern Streaming Cost Keeping recent log segments on broker local disk and older ones in object storage, which decouples retention from broker sizing and turns replay from an emergency measure into a routine design tool.
Time to Detect MTTD metric Incident Management The interval between a problem beginning and someone knowing about it, which is often the largest and most reducible component of total incident duration.
Time to First Success Time to Hello World, Onboarding Latency practice Platform Adoption How long it takes a new team to get something working on the platform - the single best proxy for developer experience and the strongest predictor of adoption.
Time to Interactive Gap metric Hydration Cost The interval between a page appearing complete and actually responding to input, during which the user's taps do nothing.
Time to Market concept Time to Market How long from idea to customer value — an architectural property determined by coupling, batch size and the number of teams required.
Time Travel Data Versioning, Snapshot Query concept Data Lakes & Lakehouses Querying a table as it existed at a previous version or timestamp, made possible by keeping the metadata and files of prior commits.
Time-Boxed Waiver practice Exception & Waiver Management An approved deviation from a standard that carries an owner, a justification, a compensating control and an expiry date after which it is reconsidered.
Timeout Budget Deadline Propagation pattern Distributed Systems Assigning a request an overall deadline at the edge and passing the remaining time down each hop, so no service works on something already out of time.
TLS Transport Layer Security, SSL protocol Networking The protocol that gives a network connection encryption, integrity and server authentication, underneath HTTPS and most other secure transports.
TLS Termination Boundary Encryption Termination Point, Decryption Boundary concept Network Security The exact point where ciphertext becomes plaintext, which is the real answer to "is data encrypted in transit" - everything past it travels in the clear on a wire somebody owns.
TOGAF practice Enterprise Architecture An enterprise architecture framework whose central element is the ADM, an iterative cycle from vision through business, data, application and technology architecture to implementation governance.
TOGAF in Practice practice TOGAF The most widely adopted enterprise architecture framework — useful as a checklist and vocabulary, harmful when followed as a process.
Toil concept Reliability Culture Manual, repetitive, automatable operational work that scales linearly with the size of the service and produces no lasting improvement.
Token Audience Validation Audience Restriction, aud Claim practice Tokens & JWTs Verifying that a signed token was issued for the service consuming it, without which a legitimately obtained low-privilege token is replayable against a high-privilege service.
Token Bucket pattern Rate Limiting A rate-limiting algorithm holding a replenishing allowance of tokens, permitting controlled bursts while bounding the sustained rate.
Token Budget Enforcement practice AI Gateways Limiting token consumption per user, tenant, feature or time window at a central point, so cost cannot run away unobserved.
Token Cost Attribution practice AI Cost Management Assigning inference spend to features, tenants and users, so that cost can be managed by the people who influence it.
Token Domain Entropy Tokenised Value Space, Surrogate Input Entropy concept Tokenisation & Masking The size and guessability of the value space a deterministic token is computed from, which decides whether that token is a usable pseudonym or a lookup key an attacker can rebuild without ever touching the vault.
Token Exchange RFC 8693, Delegation Token protocol OAuth 2.0 & OIDC Trading one token for another with different scope, audience or subject, so a service can call downstream on a user's behalf without reusing the original token.
Token Introspection protocol OAuth 2.0 & OIDC Asking the authorisation server whether a token is currently valid, rather than validating it locally from its signature.
Token Revocation Gap concept Tokens & JWTs The window between deciding a token should no longer be valid and it actually ceasing to work, which for self-contained tokens is its remaining lifetime.
Tokenisation pattern Tokenisation & Masking Replacing a sensitive value with a meaningless surrogate, where the mapping back is held in a separate, tightly controlled vault.
Tolerant Reader pattern Backward Compatibility A consumer that ignores fields it does not recognise and depends only on what it actually needs, so a producer can add to a contract without breaking it.
Tombstone Accumulation Metadata Growth, CRDT Garbage Problem concept CRDTs The unbounded growth of deletion markers and causal metadata that a coordination-free replica must retain so a peer it has not yet seen cannot resurrect removed data.
Tool Authorisation Boundary Model as Untrusted Proposer, Authorise Outside the Model concept Prompt Injection Defence Authorising every tool invocation against the initiating user's own permissions, outside the model - because the model cannot distinguish instructions from data and no prompt-level defence is reliable.
Tool Calling Function Calling pattern AI-Era Architecture Giving a model a set of typed function definitions it can request to invoke, with the application executing the call and returning the result.
Tool Result Budget Tool Output Capping, Result Truncation Contract pattern Tool Calling A hard cap on the tokens any single tool may return into the model's context, with pagination and summarisation behind it, so that one unlucky query cannot fill the window and end the run.
Tool Schema Design practice Tool Calling Defining the tools available to a model — names, descriptions, parameters and errors — in a way that makes correct selection likely.
Total Cost of Ownership TCO concept Total Cost of Ownership The full lifetime cost of a choice — infrastructure, licences, and the engineering time that is usually the largest term and the one omitted.
Total Cost of Ownership TCO metric Cost & FinOps The full lifetime cost of a capability, including the people, operations, upgrades and exit that a licence comparison leaves out.
Toxic Combination concept Segregation of Duties A pair of permissions that is acceptable individually and dangerous together, which is what a segregation-of-duties model exists to identify.
Trace Exemplar Metric Exemplar, Sampled Trace Pointer concept OpenTelemetry A trace ID attached to a histogram bucket or counter sample, letting a responder jump from an aggregate graph straight into one real request that produced it - without adding a single active series.
Trace Sampling Strategy Head Sampling, Tail Sampling practice Sampling Deciding which traces to keep, since retaining all of them at scale is unaffordable and retaining a random few loses exactly the interesting ones.
Trade-off Analysis practice Meta-Skills Making the costs of an architectural choice explicit and comparable, rather than presenting a recommendation as if it were free.
Trade-off Analysis Methods practice Trade-off Analysis Methods Structured ways to compare architectural options — valuable for making reasoning explicit, dangerous when they produce false precision.
Trade-off Framing practice Explaining Trade-offs Presenting a decision as a choice between named costs rather than as a search for a best option, so the audience can exercise the judgement that is properly theirs.
Trade-off Fundamentals concept Trade-off Fundamentals Every architecture is a set of purchases; the skill is naming what was bought, what was sold, and at what exchange rate.
Trade-off Surface concept Trade-off Analysis The set of achievable combinations of competing qualities, on which improving one attribute necessarily costs another.
Traffic Shading Traffic Marking, Shadow Tagging, Request Tainting pattern Testing in Production Marking a request as synthetic and propagating that mark through every hop so downstream services can route its writes to shadow storage and suppress its side effects, which is the single mechanism that makes …
Traffic Shadowing Dark Traffic, Mirroring, Shadow Testing pattern Parallel Run Sending a copy of real production traffic to a new implementation while the existing one continues to serve users, comparing results without exposing anyone to the new system's mistakes.
Traffic Shadowing Dark Launch, Mirroring, Shadow Traffic practice Strangler Fig Sending real production traffic to a new implementation alongside the old one, serving the old response and comparing - the only reliable way to find undocumented behaviour before it matters.
Traffic Splitting pattern Service Mesh Networking Directing a defined percentage or subset of requests to a different version of a service, configured at the routing layer rather than in application code.
Traffic-Mix Skew Canary Population Bias, Assignment Bias concept Testing in Production A canary or experiment arm receiving a population that differs systematically from the baseline - so the comparison measures who was routed rather than what changed.