How we engineer

Eight standards. Every system, every time.

Thirty years of lessons, written down as the rules we work to. They apply to infrastructure, security, software and AI alike.

  1. 01

    Every change can be undone.

    Nothing goes live without a tested way back, and the way back is rehearsed before it is needed.

    Learned from Automation & DevSecOps, 2013 to 2022
  2. 02

    Every restore is timed.

    A backup proves nothing until a restore has run against the clock and the business has worked from what it saved.

    Learned from What a DR test should actually prove
  3. 03

    Every permission has an owner.

    Access is granted at the narrowest point that works, owned by a named person, and removed when it stops being used.

    Learned from What NetWare taught us
  4. 04

    Every boundary is designed in.

    Isolation, identity and trust are part of the architecture from the first diagram, never added afterwards.

    Learned from Virtualisation & security, 2000s
  5. 05

    Every interface has a contract.

    Systems talk through defined, versioned and tested interfaces, never through assumptions.

    Learned from Software engineering, from 2011
  6. 06

    Every agent has an off switch.

    Any automated or AI system can be paused at once by a named person, and everything it did can be traced afterwards.

    Learned from Least privilege for AI agents
  7. 07

    Every answer shows its source.

    AI output can be traced to the data behind it, so a person can check it before it is trusted.

    Learned from Production AI, 2023 onward
  8. 08

    Every failure is planned for.

    Systems are designed for the busiest day with something broken, not for the average day.

    Learned from Capacity planning