Policy catalog
All release gates are separated by framework dimension, with named ownership, weights, evidence expectations, and traffic-light thresholds.
Business outcome and capability alignment
Ensures every API has a stable business purpose, domain ownership, and identified consumers.
5 gatesSpecification and data-contract quality
Makes the machine-readable API specification the authoritative build and release contract.
5 gatesLean API and resource design
Reduces endpoint and payload waste while preserving reusable resource access patterns.
6 gatesSecurity and role-aware authorization
Validates authentication, actor/subject context, object-level access, delegation, and policy-as-code.
6 gatesNoSQL transactional and data integrity
Makes aggregate ownership, concurrency, event reliability, projections, and reconciliation explicit.
9 gatesCross-layer observability and auditability
Requires business transaction traceability across synchronous, asynchronous, MCP, and A2A boundaries.
6 gatesTesting automation and mock coverage
Requires deterministic contract, authorization, failure-path, and scenario-based mock evidence.
4 gatesHealth and business-impact exposure
Requires technical readiness plus dependency, capability, integrity, and consumer-impact visibility.
6 gatesAI, MCP, and Agent-to-Agent governance
Keeps agent discovery, delegation, tool use, approval, and audit within enterprise control boundaries.
2 gatesLifecycle, versioning, and reuse
Ensures APIs can evolve predictably, be deprecated safely, and deliver portfolio reuse.
4 gates