Terminology
991 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas991
Architecture Fundamentals38
Distributed Systems73
Data Architecture71
Cloud Architecture55
Networking51
API & Integration Architecture45
Reliability & Resilience40
Observability33
Performance & Capacity Engineering34
Security Architecture50
Cost Architecture & FinOps30
Business Architecture28
Architecture Communication27
Enterprise Architecture27
Legacy Modernization27
AI-Era Architecture34
Software Architecture & Engineering37
Architecture Patterns34
Architecture Decision-Making30
The Architect's Meta-Skills27
Delivery & Release Engineering20
Platform Engineering & Developer Experience20
Testing & Quality Architecture20
Data Platform Architecture20
Streaming & Real-Time Data20
Data Governance & Semantics20
Frontend & Experience Architecture20
Edge, Mobile & IoT20
Regulatory & Data Protection Architecture20
Assurance, Audit & Model Risk20
20 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| Adversarial Evaluation | practice | Model Evaluation & Red-Teaming | Deliberately attempting to make a model behave badly, because a probabilistic system with no fixed expected output cannot be verified by conventional testing. |
| Assurance Map | practice | Assurance, Audit & Model Risk | A single view of which risks are covered by which assurance activity, exposing both the gaps nobody is looking at and the duplication several parties are paying for. |
| Automation Bias | concept | Human-in-the-Loop Design | The tendency of a human reviewer to accept a system's output rather than evaluate it, which is what turns human oversight into a rubber stamp. |
| Certification Scope Boundary | concept | Certification Impact on Architecture | The declared set of systems, locations and people a certification covers, which determines both its cost and what it actually tells a customer. |
| Conformance Automation | practice | Architecture Compliance Checks | Encoding architectural standards as automated checks, so review effort is spent on novel design decisions rather than on verifying known rules. |
| Control Test Automation | practice | Continuous Controls Monitoring | Executing a control's test continuously against the whole population rather than sampling it annually, which changes both the detection latency and the strength of the evidence. |
| Design Review Trigger | practice | Security Design Review | The stated conditions under which a change requires security review, so that review capacity goes to what warrants it and everything else proceeds. |
| Evidence Based Approval | practice | Change Advisory vs Automated Gates | Replacing a human judgement about whether a change is safe with a machine-produced record of the checks it passed, assessed once for the class rather than per instance. |
| Evidence by Construction | practice | Audit Evidence | Designing systems so that operating them produces the audit evidence automatically, rather than reconstructing it from screenshots when an assessment arrives. |
| Fairness Definition Choice | concept | Bias & Fairness Controls | Selecting which mathematical fairness criterion applies, given that the main criteria are provably incompatible and the choice is a value judgement. |
| Independent Assurance | concept | Three Lines Model | Assessment by a function with no involvement in designing or operating the control, which is what makes the assessment worth anything. |
| Model Card | practice | Model Documentation | A structured record of what a model is for, how it was built and where it should not be used — written for the people who will deploy or be affected by it. |
| Model Inventory | practice | Model Risk Management | A complete register of models in use with their purpose, owner, risk tier and validation status — the artifact everything else in model governance depends on. |
| Operating Effectiveness | concept | Control Design vs Operation | Whether a control actually ran, consistently, over a period — as distinct from whether it was well designed, and the harder of the two to demonstrate. |
| Quantified Risk Estimate | practice | Risk Assessment Methods | Expressing a risk as a probability distribution over financial loss rather than as a colour, which makes risks comparable and mitigations arguable on cost. |
| Review Scope Discipline | practice | Design Authority | Stating what an architecture board does not review, which is what determines whether it stays useful or becomes a queue. |
| Risk Tolerance Statement | concept | Risk Appetite | The board-level declaration of how much of each risk type the organisation will accept, which is what tells an architect which risks may be accepted without escalation. |
| Time-Boxed Waiver | practice | Exception & Waiver Management | An approved deviation from a standard that carries an owner, a justification, a compensating control and an expiry date after which it is reconsidered. |
| Toxic Combination | concept | Segregation of Duties | A pair of permissions that is acceptable individually and dangerous together, which is what a segregation-of-duties model exists to identify. |
| Use Case Risk Classification | practice | AI Risk Tiering | Assigning an AI application to a risk tier based on the consequence of it being wrong, which then determines the obligations that apply. |
Nothing on this page matches. Search the whole glossary.