The Foundation
The 12 Enterprise Trust Primitives
Every modernization changes technologies, relationships, decisions, or operating processes. These twelve name what must be preserved or strengthened while that change occurs.
They are not regulations or product requirements. They are durable architectural questions.
Identity, Access, and Delegation
Establishes who or what can act in a system, under whose authority, and within what limits.
“Who or what is allowed to act, under which authority, and within what limits?”
Auditability and Traceability
Ensures every consequential action can be reconstructed: what happened, by whom, when, and why.
“Can a knowledgeable reviewer reconstruct what happened, when, why, and under whose authority?”
Evidence and Assurance
Makes trustworthy operation demonstrable with evidence produced by the system itself, not assembled by hand after the fact.
“Can the organization prove that a control or process operated as designed over a defined period?”
Data Governance and Protection
Governs what data exists, who owns it, how it is classified, protected, retained, and destroyed.
“What data exists, who owns it, how may it be used, and how is it protected throughout its lifecycle?”
Change and Configuration Governance
Controls how systems change: who may change them, how changes are reviewed, and how state is known.
“How are changes authorized, tested, released, observed, and reversed?”
Decision and AI Governance
Defines which decisions systems and AI agents may make, at what consequence level, with what oversight.
“Which decisions are made or influenced by systems, and what governance is proportional to their consequence?”
Transparency and Explainability
Ensures the people affected by a system can understand what it does and why it did what it did.
“Can the appropriate audience understand the outcome, its principal reasons, its provenance, and its limits?”
Operational Monitoring and Observability
Keeps the real behavior of systems visible so deviation is noticed before it becomes damage.
“How will the organization know when systems, controls, agents, data, or decisions are behaving abnormally?”
Resilience and Continuity
Designs systems to degrade gracefully, recover predictably, and keep essential promises under stress.
“What must continue, how may it degrade, and how will it recover when dependencies fail?”
Third-Party and Supply-Chain Trust
Extends trust discipline to vendors, platforms, models, and services the enterprise depends on but does not control.
“What external parties and components does the capability depend on, and how is that dependency governed?”
Asset and Knowledge Governance
Keeps the enterprise's systems, dependencies, and institutional knowledge known, owned, and current.
“What assets and knowledge exist, who owns them, how are they related, and how are they kept current?”
Lifecycle and Value Governance
Governs systems across their whole life: why they exist, what value they deliver, and when they should be retired.
“Why does this capability exist, how is value measured, and when should it be changed or retired?”
The primitives work as a system. Modernization is weakened when one advances while the others are ignored.
Coming soon
See the primitives appliedNaming the questions is the start. Working them through real modernization decisions—one primitive at a time—is where the method comes alive. Video walkthroughs are coming to the YouTube channel; the deeper “how” will live there.