Architecture and Intent Tony Malott · Source dated 2026-07-17 https://shareplane.malott.ai/artifacts/architecture-and-intent/ Architecture Thesis Architecture and Intent The system diagram is only half the architecture. Your architecture diagram shows what the system can reach. It usually does not show what the system should trust, who has authority, how contradictions are resolved, what may be changed, or how far the consequences can spread. Architecture and Intent Artifact record Architecture and Intent Metadata JSON Receipt Graph Publication Author Tony Malott Published July 17, 2026 Format Architecture Thesis Privacy public-safe JavaScript artifact-local Provenance owner-approved-public-safe-presentation-family-v02 This package uses generalized examples involving architecture records, policies, controls, services, operational assets, repositories, databases, evidence, incidents, approvals, lifecycle, and organizational knowledge. It contains no employer or customer names, private estate counts, regulated records, internal control identifiers, private topology, internal URLs, named private owners, credentials, secrets, or security-sensitive production configuration. The artifact expresses Tony Malott's architecture doctrine and a proposed review method. It does not claim enterprise approval, regulatory certification, or universal applicability. Public sources 5 NIST AI 600-1: Generative Artificial Intelligence Profile Current authoritative risk-management context for governance, provenance, testing, information integrity, information security, and human-AI configuration. Open source OWASP LLM01: Prompt Injection Current security guidance for direct and indirect prompt injection, including retrieved external content and the limits of RAG as a mitigation. Open source OWASP LLM06: Excessive Agency Current security guidance for narrow tools, least privilege, downstream authorization, human approval for high-impact actions, monitoring, and rate limiting. Open source Regulation (EU) 2024/1689, Artificial Intelligence Act Current legal authority for risk-proportionate human oversight, including interpretation, override, reversal, interruption, and safe stopping. Open source W3C PROV Overview Foundational provenance authority retained as an explicit evidence-floor exception for entities, activities, derivation, versioning, reproducibility, and trust assessment. Open source Related work 1 Architecture Review Plane: Three Interactive Product Concepts Three interactive, dependency-free Architecture Review Plane product concepts. Open artifact Share or reuse Send the page or take its public context with you. What’s included The agent package contains the canonical public HTML, public metadata, receipt, plain-text context, package guide, and member-hash manifest. Agent context is a generated public-safe plain-text projection. It is not canonical Markdown and does not replace the artifact or its versioned authority. SOURCE REFERENCES NIST AI 600-1: Generative Artificial Intelligence Profile https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf OWASP LLM01: Prompt Injection https://genai.owasp.org/llmrisk/llm01-prompt-injection/ OWASP LLM06: Excessive Agency https://genai.owasp.org/llmrisk/llm062025-excessive-agency/ Regulation (EU) 2024/1689, Artificial Intelligence Act https://eur-lex.europa.eu/eli/reg/2024/1689/oj W3C PROV Overview https://www.w3.org/TR/prov-overview/