| name | choosing-system-architecture |
| description | Use when choosing system architecture is required during architecture work, especially when the result must be traceable, independently reviewable, and safe to hand to another agent. |
| license | MIT |
| compatibility | ForgeOS-compatible Agent Skills hosts; no provider-specific model required. |
| metadata | {"author":"forgeos-community","version":"0.2.0","pack":"architecture","kind":"core","status":"stable"} |
Choosing System Architecture
Overview
This skill owns one bounded responsibility: choosing system architecture. Its focus is select the simplest architecture that satisfies quality attributes, failure boundaries, extension needs, and operational constraints. It converts declared inputs into typed artifacts and reproducible evidence without silently changing product scope.
Trigger
Activate only when the project is in one of these stages: architecture, all contract preconditions pass, and the router identifies a missing output this skill can produce. Do not activate merely because the skill name resembles the user request.
Required Inputs
product-definition
ux-contract
- Optional:
domain-blueprint
- Optional:
product-thesis
- Optional:
capability-map
- Current gate result, open findings, artifact hashes, and invalidation state
- Required tools: none
- Optional tools: none
- Confirmed human decisions relevant to this scope
Method-Specific Protocol
- Translate product capabilities into measurable quality attributes and workload assumptions.
- Model at least two viable architectures with boundaries, data ownership, failure propagation, deployment, and cost.
- Use decision drivers and disqualifiers rather than trend preference.
- Threat-model and operate the leading option on paper, including migration and rollback.
- Record the decision, rejected alternatives, assumptions, validation experiments, and expiry conditions.
Procedure
- Read product capabilities, quality attributes, and domain constraints.
- Define boundaries and stable contracts before implementation details.
- Translate product capabilities into measurable quality attributes and workload assumptions.
- Model at least two viable architectures with boundaries, data ownership, failure propagation, deployment, and cost.
- Use decision drivers and disqualifiers rather than trend preference.
- Threat-model and operate the leading option on paper, including migration and rollback.
- Record the decision, rejected alternatives, assumptions, validation experiments, and expiry conditions.
- Model data, failures, extension points, and operational behavior.
- Evaluate at least two viable alternatives and trade-offs.
- Threat-model the selected design and its dependencies.
- Publish an architecture decision with validation evidence.
Verification Questions
- Can the architecture be explained through bounded responsibilities?
- Is each added component justified by a current quality attribute?
- What happens when every dependency is slow, unavailable, or duplicated?
- Which future change would force this decision to be revisited?
Evidence Packet
Produce or reference all applicable evidence:
architecture decision record
quality-attribute scenarios
failure map
validation plan
Evidence must identify the current artifact hash, command or method used, result, reviewer identity, timestamp, and limitations.
Output Contract
Produce:
system-boundaries
architecture-decision
The primary artifact must include schema version, provenance, consumed artifact IDs, decisions, evidence references, residual risks, validation state, and invalidation targets. Narrative explanation may accompany the artifact but cannot replace it.
Quality Gate
Reviewer: independent-reviewer
- The output directly and completely performs choosing system architecture within its declared boundary.
- Can the architecture be explained through bounded responsibilities?
- Is each added component justified by a current quality attribute?
- What happens when every dependency is slow, unavailable, or duplicated?
- Which future change would force this decision to be revisited?
- Every material claim is traceable to an input, decision, executable check, or evidence item.
- Required fields are complete and machine-readable.
- The producing agent is not the approving reviewer.
- Open uncertainty and residual risk are explicit; critical findings are never hidden by an aggregate score.
Pass only when: All mandatory rules pass, evidence targets the current artifact hash, and no unresolved critical finding applies.
Forbidden Shortcuts
- Do not infer a material requirement that the user has not confirmed.
- Do not replace a typed artifact with a long explanation.
- Do not approve work produced by the same agent identity.
- Do not hide a critical failure behind a high aggregate score.
- Do not load unrelated project history, files, references, or skill bodies.
- Do not mark evidence complete when it targets a different artifact hash or version.
Failure Modes
- guessing a material requirement
- producing prose without the contracted artifact
- self-approving the output
- expanding scope without a decision record
- architecture by fashion
- microservices without isolation needs
- future-proof layers without consumers
Escalation and Invalidation
Stop and request a human decision when scope, risk acceptance, irreversible action, cost ceiling, privacy boundary, or product direction is materially ambiguous. When this artifact changes, invalidate only descendants named by the artifact graph; preserve unaffected verified branches.
Handoff
- Next transition: the graph router selects a real consumer of
system-boundaries, architecture-decision.
- Required evidence:
contract-validation, independent-review, architecture decision record, quality-attribute scenarios, failure map, validation plan.
- Required envelope fields:
artifactId, schemaVersion, sha256, producingSkill, producingAgent, consumedArtifacts, decisionIds, evidenceIds, residualRisks, validationState, invalidationTargets, stopCondition.
- Stop condition: Output contract is satisfied, a blocker is recorded, or a material human decision is required.
Token and Context Policy
Load at most 8 direct artifacts and reference depth 1. Use stable IDs, hashes, signatures, and deltas instead of repeating full history. Use established domain terminology, state each requirement once, and spend context on decisions, code, tests, or evidence rather than narration.
Reference Playbook
Load skills/references/core/architecture.md only when this skill needs pack-wide decision tables, evidence patterns, or cross-skill handoff rules.
See contract.json for the machine-readable contract.