Architecture & Stewardship Standard · v1.0

The discipline underneath the promise.

The five functions describe what the business must be capable of doing. The six architecture layers describe how the operating system supports that work.

Architectural principles

The rules that shape an installation.

Authoritative ownership

Each important class of information has a defined system of record. Convenience copies have a reason and a rule for staying current.

Capture near creation

Capture information as close as practical to the event that creates it. Bad source data needs attention at the source.

Visible human judgment

Material judgment belongs to accountable humans unless a deliberately governed decision rule says otherwise.

Observable automation

A consequential workflow that can fail needs to expose that failure through an agreed queue or notification path.

Named responsibility

Every important workflow has a named role or rule responsible for its outcome.

Explicit completion

Define how the system knows the intended result occurred, including the evidence needed to verify it.

Deliberate integration

Keep capable domain software in its appropriate role. Add connections when the operating work needs them.

Portability

Documentation, credentials and ownership allow a responsible transition to another operator.

Reference architecture

Six interacting layers.

Six interacting layers of a Business Nervous System Systems of record, integration and human interfaces exchange information with shared business memory and processing. Control checks outcomes and sends exceptions back into the operating work. Connections run in multiple directions. Systems of record Accounting · CRM · job software Business memory Notion · shared operating state Integration Automations · APIs · webhooks Processing Rules · calculations · selective AI Interface People · queues · useful context Control Checks · exceptions · escalation
Systems of record The software that knows its part.
Business memory A shared picture of the operating work.
Integration Information moves between systems.
Processing Events become useful context.
Interface Each person can see and do their part.
Control Failures and unfinished work become visible.
Information moves in several directions. Control checks the outcomes and routes exceptions back to the people and systems responsible.
Architecture × function

Each function crosses several layers.

How the six layers support the five operating functions
Layer Sensing Signaling Processing Deciding Regulating
Systems of record Primary Supporting Evidence
Business memory Supporting Primary Supporting Context Supporting
Integration Event capture Primary Transform Route Status return
Processing Classify Enrich Primary Rules Evaluate
Interface Observe Deliver Explain Human action Confirm
Control Monitor Monitor Monitor Escalate Primary

The Notion standard

Use Notion as business memory and interface where appropriate. Databases represent durable business entities or operating states. Relationships and rollups clarify that model. Views expose the next useful action for each role.

Templates encode real repetition. Archive rules preserve history while keeping inactive work out of current queues. Replication of authoritative information needs an explicit purpose.

The automation standard

Every production automation has a name, purpose, owner, trigger, downstream effects and failure path. Credentials use client-controlled accounts or documented service ownership wherever practical.

Retries are deliberate and bounded. Duplicate protection or idempotency is used where repeated triggers could create harmful duplicate actions. Source schema and field changes are treated as architecture changes when they affect downstream work.

AI steps have a defined failure behavior, confidence expectation and human escalation when consequences are material.

Represent the operating state.

A useful minimum state model is created → owned → in progress → waiting or blocked → completed → verified. Actual implementations can use different states. Ambiguous limbo needs a way to become visible.

Control checks the business outcome.

Technical success is distinct from business completion. Surface economically meaningful stale states, unowned items, overdue transitions and failed integrations. Reconcile systems that should agree.

An exception queue is often more useful than a broad dashboard when the operator needs to know what requires action.

Stewardship operating standard

The continuing responsibility.

Routine monitoring
Review automation health and surfaced exceptions at an appropriate, agreed cadence.
Maintenance
Repair ordinary integration drift, broken references and bounded workflow defects.
Change control
Record meaningful architecture changes and their downstream effects.
Small improvements
Modify existing views, fields, rules and workflows within the installed architecture.
Periodic recalibration
Review whether records, states, responsibilities and exception rules still match reality.
Documentation
Keep the operating map, automation inventory and material dependencies current enough for continuity.
Security and access
Use least-privilege access where practical, review access as roles change and avoid unnecessary copies of sensitive data.
Offboarding
Provide a current operating map, automation inventory, ownership notes and reasonable transition information.

A substantial new system, business function, department, data model, migration, application or materially different workflow architecture receives a separate build scope.

Definition of healthy

Important work reaches a verified outcome.

The business can notice events, route information, create useful context and put decisions with the right person or rule. The owner’s memory is no longer the primary control mechanism.

See Stewardship at $2,000/month