Resources · Blog

Enterprise notes from the ForgeCrux architecture practice

Decision records, cutover patterns, and security write-ups for platform, SRE, GRC, and AI CoE teams—not a product changelog.

Enterprise data

Uses, installation, setup, and security—the same operating model as the platform and solutions pages.

Enterprise uses

What this library is for—not a consumer changelog.

  • Architecture decision records for platform and security forums
  • Cutover and dual-run patterns for API modernization programs
  • Governance mappings for SOC 2, ISO 27001, HIPAA, and GDPR
  • FinOps views of tokens, MCP calls, and API products
  • SRE runbooks for SLO burn, policy hits, and agent pause
  • Integration notes for IdP, SIEM, ITSM, and GitOps

Security & compliance notes

Topics we publish for GRC and security architecture.

  • Workload identity vs human SSO on the control plane
  • PII redaction in prompts, traces, and MCP arguments
  • Retention, legal hold, and residency for audit lakes
  • Break-glass, dual control, and time-boxed waivers
  • Default-deny MCP catalogs and HITL for mutating tools
  • Evidence packs: who changed policy, who approved, who replayed

Want this as an architecture workshop?

We run working sessions on dual-run cutover, AI policy-in-path, and zero-trust MCP.