Eight standards. Every system, every time.
Thirty years of lessons, written down as the rules we work to. They apply to infrastructure, security, software and AI alike.
- 01
Every change can be undone.
Nothing goes live without a tested way back, and the way back is rehearsed before it is needed.
Learned from Automation & DevSecOps, 2013 to 2022 - 02
Every restore is timed.
A backup proves nothing until a restore has run against the clock and the business has worked from what it saved.
Learned from What a DR test should actually prove - 03
Every permission has an owner.
Access is granted at the narrowest point that works, owned by a named person, and removed when it stops being used.
Learned from What NetWare taught us - 04
Every boundary is designed in.
Isolation, identity and trust are part of the architecture from the first diagram, never added afterwards.
Learned from Virtualisation & security, 2000s - 05
Every interface has a contract.
Systems talk through defined, versioned and tested interfaces, never through assumptions.
Learned from Software engineering, from 2011 - 06
Every agent has an off switch.
Any automated or AI system can be paused at once by a named person, and everything it did can be traced afterwards.
Learned from Least privilege for AI agents - 07
Every answer shows its source.
AI output can be traced to the data behind it, so a person can check it before it is trusted.
Learned from Production AI, 2023 onward - 08
Every failure is planned for.
Systems are designed for the busiest day with something broken, not for the average day.
Learned from Capacity planning