Enterprise Architecture · Governance

TOGAF, applied for real. When the method is load-bearing, not decoration.

An agentic invoice-and-certificate audit platform was designed and built solo, inside a 48-hour technical capability window — governed end to end by one tailored pass through the TOGAF 10 Architecture Development Method. This page is the method’s own audit trail: what TOGAF is, why it fits a build this fast and this money-adjacent, exactly how each phase was used — and, most persuasively, the three places it caught the architect being wrong.

01 · What TOGAF is

A method for making architecture decisions on the record

TOGAF — The Open Group Architecture Framework, currently the TOGAF Standard, 10th Edition — is the most widely used enterprise-architecture framework in the world. Its core is the Architecture Development Method (ADM): a cycle of phases that runs from establishing principles (Preliminary), through vision, business, information-systems and technology architectures (A–D), into planning and delivering the change (E–F), and then — the part most adopters skip — governing what was built against what was promised (G) and deciding when change is big enough to demand a new cycle (H). Requirements management sits at the hub, feeding every phase continuously rather than running once at the start.

Stripped of its ceremony, TOGAF is three habits with names: write principles you are willing to be constrained by, trace every requirement to evidence, and treat deviation as a governed decision rather than drift. Everything else — the artifacts, the compliance ladder, the architecture contract — exists to make those three habits checkable by someone who was not in the room.

10thedition of the standard this engagement follows
9 + 1ADM phases, plus continuous requirements management at the hub
1tailored pass — TOGAF expects tailoring; using it untailored is the anti-pattern
T1–T10tailoring decisions, each recorded with what was dropped and why
02 · The ADM, as executed — click any phase

One pass around the wheel, with receipts

Every phase below was actually executed and produced a real artifact — the drawer for each shows what the standard asks, what this project produced (with verified counts), and the receipt: something that phase enforced or caught. The hub is deliberately amber: requirements management never stops.

Method properties One tailored pass P01–P05 absolute Contract, not memo Stop rule New-cycle triggers Continuous traceability
01 / 11
Click or Tab+Enter any phase for its drawer · step · space play/pause · [ ] switch phase · Esc closes the panel.
03 · Why TOGAF for this project

Three reasons, and one objection answered

The system moves money

An AI platform that audits payment certificates must produce decisions that survive an adjudicator months later. That demands exactly what TOGAF industrialises: principles you can point at, a record of every consequential decision, and a governed line between what was promised and what was built. The prime directive — no model output ever sets a monetary verdict — is principle P01, and its breach is defined as a build failure and a new cycle, not a conversation.

A solo build needs an adversary

Forty-eight hours, one architect, no review board. The classic failure mode is believing your own documentation. The ADM supplies the adversary: a gap register re-run against the code, conformance criteria that can fail, reversal triggers written into decisions before the evidence arrives. Used this way, the method is not paperwork — it is the only reviewer available at 3 a.m.

Honesty needs a vocabulary

“Production-shaped, not production-deployed” is only a defensible claim if something enumerates the difference. TOGAF's gap analysis, transition architectures and compliance ladder give the honest claims somewhere structured to live — 58 recorded gaps, three transition states, and a compliance checklist that admits which checks are mechanical and which are judgement.

“Isn't TOGAF far too heavy for 48 hours?” — Untailored, yes. This engagement recorded ten tailoring decisions (T1–T10), ran one pass, and deliberately scaled three things up rather than down: the principles, the traceability matrix and the gap analysis — because those three are the ones a solo, high-speed build cannot afford to lose. One skipped artifact, the Business Transformation Readiness Assessment, was accepted as a gap rather than faked: “substituting an invented readiness assessment would have violated the engagement's own evidence standard.”TOGAF_ADM_OVERVIEW.md §T1–T10 · PHASE_A_ARCHITECTURE_VISION.md R-09
04 · How it was used — the principles

Fifteen principles, five of them absolute — click any

Precedence is by number: the lower principle wins a conflict. P01–P05 are integrity principles and are absolute — a change that violates one requires a new ADM cycle rather than a waiver. The test of a principle is whether it ever costs anything; the drawers name what each one changed or forbade.

05 · Governance in anger — a real change, end to end

The day the topology changed: ten services to eleven

Mid-implementation, the vector-store decision (ADR-004, pgvector) was reversed by its own written trigger, adding a dedicated vector database — and colliding with a baseline that said “exactly ten services” was a submission blocker. What happened next is the whole argument for Phase G and H existing. Click each step.

The alternative that preserved compliance was explicitly rejected as dishonest: hiding the new store behind an opt-in profile would have kept the headline retrieval capability switched off by default — “which is worse than amending a document under a recorded decision.” The baseline was amended before conformance was re-asserted, so no document ever claimed conformance to a topology that was not the one running.TECHNICAL_DECISIONS.md ADR-023 · PHASE_G_H_GOVERNANCE.md BA-01, NC-06
06 · Phase A to Phase H — the detail, phase by phase

Every phase, with its artifact, its numbers and its receipt

Use the tabs or [ ]. Each panel is drawn from that phase's actual document: what the standard asks the phase to do, what this engagement produced — with counts re-verified on the day of writing — and a visual cut of the phase's own material.

07 · The record, in numbers — each one re-verified against the documents

What one governed pass actually produced

15architecture principles — P01–P05 absolute, precedence by number
25architecture decision records; exactly one superseded, by its own trigger
20contract obligations, each with a named consequence of breach
30 + 12compliance checks + baseline checks, scored on the TOGAF conformance ladder
9 + 8absolute + conditional new-cycle triggers — plus a what-does-not-trigger list
152requirement identifiers in the register; 14/14 invariants and 18/18 scenarios traced to tests
21work packages with an ordered, pre-published cut list
58gaps on the register: 39 delivered · 8 partial · 11 deferred — after re-scoring against code
The gap register was re-run against the actual code near the end of the build. Six rows moved from Delivered to Partial or Deferred on direct evidence; no row moved the optimistic direction — and the pass found and fixed an arithmetic error in its own summary table. A method that only ever confirms you is not a method.GAP_ANALYSIS.md §2
08 · What this record does not claim

The honest edges, stated before anyone finds them

One pass, not a programme

One pass through capability and architecture-development iteration; transition planning compressed; the governance iteration is defined but unexercised. The compliance review is assessed once, before freeze — not continuously.

Target levels, not assessed outcomes

The 30-check compliance checklist records verification method and target conformance level per check. It is a real pass/fail instrument with a stop rule — but the recorded result-set of a full assessment is not in the document, and the document says so.

Tests prove following, not rightness

The strongest self-limitation in the governance file is its own closing risk: “Tests prove that the architecture was followed; they cannot prove it was right.” The eval harness and the seeded scenarios exist precisely because that sentence is true.