Search⌘ K
AI Features

Design Defence: Rubric-Led Review and Recommendation

Explore how to conduct a rubric-led review and assemble a comprehensive design defense package for enterprise AI systems. Learn to trace architecture claims to evidence, address stakeholder criteria, handle challenges, and prepare a decision memo for board approval, ensuring your AI design meets governance, security, and cost requirements.

The unit economics model from the last lesson gave the capstone a defensible cost model. This final lesson brings the chapter’s artifacts, including the intake brief, ADRs, boundary design, release gates, security and governance closure, and economics model, into a single review package for the board. Treat the design defense as a traceability exercise across claims, artifacts, and evidence. Every architecture claim in the capstone portfolio should trace directly to a supporting artifact and verifiable evidence, such as a gate definition, control enforcement point, metric, ownership record, or documented cost assumption. A defensible package meets the acceptance criteria of each approval audience. It must also provide enough evidence for reviewers to verify and approve the design.

State the decision request as a single sentence naming the recommendation type and the approval being sought. Make the acceptance criteria for each audience explicit and bounded, so reviewers can approve or block with a concrete reason:

  • Executive sponsor: Approves measurable outcomes, funding bounds, and the recommendation type across proceed, reshape, buy, partner, defer, stop, with clear success metrics and phase gates.

  • Security: Approves the threat model, trust boundaries, data classification assumptions, and the control set with enforcement points and audit evidence.

  • Compliance and privacy: Approve the obligation-to-control mapping, data retention and residency constraints, and the human review requirements where policy demands it.

  • Operations: Approves operability, on-call ownership, incident and change workflows, rollback strategy, and the runbooks that make the service supportable at the intended reliability level.

  • Platform team: Approves integration fit, identity and network boundaries, quota and capacity assumptions, and the deployment and policy mechanisms that make controls enforceable by default. ... ...