Principles

What the platform does when something is missing.

A principle is only worth stating if it decides behaviour at the moment of failure. Each of these is written as the rule the code follows when a dependency is unavailable, a session cannot be verified, or a record cannot be written.

Article 01Fail closed

When a system cannot establish that an action is permitted, it refuses the action.

In practice

Access is denied by default. A missing provider, an unreachable audit store or an unverifiable session all produce refusal — never a quiet grant. Degrading into permissiveness is the one failure mode we do not accept.

Article 02Evidence over assertion

A claim that cannot be verified by a machine is not a claim the platform makes.

In practice

Release gates run as audits that fail the build. Capability states are read from the running system rather than written into documentation and left to rot.

Article 03One source of truth

Every fact has exactly one authoritative home, and everything else reads from it.

In practice

Content, configuration and schema are defined once and consumed. Duplication is treated as a defect, because two copies of a fact are two chances to be wrong.

Article 04Governed mutation

A connection to a datastore is not authorization to change what is in it.

In practice

Writes require a verified session, durable persistence and durable audit together. If any one of the three is unavailable, the write is refused rather than performed unrecorded.

Article 05Boundaries are load-bearing

The separation between planes and between businesses is the architecture, not decoration.

In practice

Each plane owns its concern and exposes a contract. One business's incident stays one business's incident because the boundary is enforced by the platform.

Article 06Reversibility

Anything that can be shipped forward can be taken back.

In practice

Releases are promoted from verified artefacts and can be rolled back to a known-good one. Schema changes are applied as ordered, re-runnable migrations.

In practice

The planes are where the doctrine is enforced.

Each principle above is owned by one or more of the five planes, and is enforced by the platform rather than left to the convention of whoever is writing the service.

The architecture

Next route 04SecurityHow AXIS Core protects the estate it underpins, and how to report a flaw.