Skip to main content

Reference Architecture

A role-specific AI agent model must be architecture-first. Agents are execution components, not policy owners. Policies, boundaries, and decision rights remain human-owned.

Required Architecture Layers

LayerPurposeOwner
Intent LayerCaptures business intent, scope, and risk tierProduct Manager + Solution Architect
Orchestration LayerRoutes work between role-specific agents and human checkpointsPlatform Engineer
Execution LayerRuns role-specific agents within constrained scopesRole owners
Governance LayerEnforces policy, approvals, and risk controlsGovernance Lead + Security
Evidence LayerStores traceability artifacts, approvals, and audit recordsCompliance Officer

Role-Agent Topology

Each role SHOULD have one primary agent profile with a narrow charter:

  • developer-agent: implementation and unit-test drafting
  • qa-agent: risk-based test matrix and regression proposals
  • security-agent: secure-code findings and remediation checks
  • platform-agent: pipeline and gate policy updates
  • product-agent: story hardening and acceptance criteria quality
  • scrum-agent: sprint risk and capacity recalibration
  • dev-manager-agent: quality and enablement oversight synthesis
  • cto-agent: architecture and tooling strategy options
  • executive-agent: board-level risk and ROI synthesis
  • compliance-agent: audit evidence completeness checks
  • solution-architect-agent: cross-agent architecture conformance and handoff integrity

Non-Negotiable Constraints

  1. Agents MUST NOT merge code directly into protected branches.
  2. Agents MUST execute with least privilege and scoped credentials.
  3. Agents MUST attach prompt and output references to each handoff.
  4. Agents MUST route through Governance Gate before production.

Architecture Review Cadence

ReviewFrequencyParticipants
Agent contract reviewBi-weeklySolution Architect, Platform, Security
Pattern drift reviewMonthlySolution Architect, CTO, Tech Leads
Governance evidence reviewMonthlyCompliance, Security, Platform
Executive risk reviewQuarterlyExecutive, CTO, Compliance

For governance controls, use PRD-STD-009.