Changelog
What changed, at two grains: releases of the system, and revisions of each entry.
Overview
Every meaningful change to AZOTH is recorded here so the evolution of our standards is transparent and auditable.
Why This Exists
This page previously listed every release twice, once as a set of "planned topics" and again in its own version history, and the two had already drifted. That is the failure the Documentation standard names: two definitions of one thing, which disagree by construction. So nothing here is typed by hand. Both lists below are derived from data each entry already carries.
Two grains, two sources
How a version is decided
Entry Activity
45 ENTRIESEstablished from the cost of extracting a shared foundation before the evidence for it existed.
Established from a set of controls that were converted from remembered rules into structural ones, each after a near miss.
Established after the same refusal pattern appeared independently five times in one codebase.
Established. Renamed from the planned "Multi-tenancy", which presumed the answer. Covers the four models and the failure each accepts, how to choose, working inside either, and what isolation does not solve.
Established. Separates the four fused concerns, states the provider contract and capability rule, makes keys policy-owned, records why a prefix is not an access boundary, gives the crash-safe orderings, and covers the two-store desynchronisation and shared upload policy.
Written from real experience, and bounded. The principle held, but the practice behind it did not: the absence of continuous integration is recorded as the gap it is. Maturity kept at Draft for that reason.
Written from real experience. Added route-arounds as diagnostics, names as API, aggregate problem reporting, and permanent partial adoption.
Written from real experience. Absorbed the completion criterion, a change is finished when what it replaced is deleted, plus residue as a named category and the uneven distribution of care.
Marked weakened: the four platform projects were built largely alone and supplied little direct support. Its evidence comes from the team quality work, and the solo substitute is now recorded as a substitute rather than an equivalent.
Written from real experience. Added comments-carry-decisions, documents split by the question they answer, and the received-versus-decided test for inherited structure.
Written from real experience. Extended past deployment to delivery: how a version reaches what runs it, and knowing the cost of each recovery path before it is needed.
Written from real experience. Added startup gates, the liveness/readiness distinction, proving function over construction, and the standard a checklist must meet to be a control rather than theatre.
Written from real experience. Extended from code style to design restraint: refusal as a deliverable, and deferrals that carry their own reopening criteria.
Written from real experience. Added the limit of review, that assumptions about dependencies are invisible to it, and the pattern of policy questions answered implicitly.
Written from real experience. Added the crash-safe ordering rule, capability-over-identity, lifecycle separation, and the finding that the isolation model is upstream of everything else.
Written from real experience. Covers the envelope and the responses that must escape it, errors carrying codes and field-level detail, lifecycle transitions as their own routes, pagination clamped where it is used, expand and contract for shape changes, and the unsolved problem of two hand-maintained mirrors of one contract.
Written from real experience. Covers opaque sessions over self-contained tokens, the different hashing requirements for passwords and tokens, session policy as data including the rotation defect, the defaults that must be forced rather than configured, splitting authentication from account state, and the gaps most session systems share.
Written from real experience, most of it from the cost of not having a pipeline. Separates integration from deployment, orders the stages by cost, records why verification must run where the artifact is built, gives the two rules that keep a pipeline credible, and marks where automated deployment stops being obviously correct.
Written from real experience. Separates what review reliably catches from the two classes it structurally cannot, with the structural control for each. Adds the received-versus-decided question, feedback that changes outcomes, and an honest account of what review means without a second person.
Written from real experience. Establishes product ownership of schema and tenancy, the single query layer with the honest limit of a scoping helper, transaction scope as the business operation, the specific failure modes of generated migrations, and the conventions worth settling early.
Written from real experience. Establishes the test for whether an item belongs at all, separates the one-time go-live gate from the per-release gate, gives the short release list, and defines stop conditions and what signing asserts.
Written from real experience. Establishes comments as records of decisions rather than descriptions, splitting documents by the question each answers, writing down refusals with their reopening criteria, and what makes documentation stay true. Closes with what not to write.
Written from real experience. Fixes the restore-before-investigate ordering, classifies severity by user impact, states honestly what a team without a rotation can commit to, and treats the postmortem as a guardrail with the possible outputs ranked. Closes with the recurring failure shapes.
Written from real experience. Covers the inert-observation contract, correlation and static identity, privacy enforced structurally rather than by discipline, the diagnostics that repeatedly answer real questions, the rule for stopping, and the liveness/readiness split.
Written from real experience. Separates the four claims a deployment can make in ascending order of cost, scopes smoke tests to few real end-to-end journeys, names the failures only a browser can see, defines the watching window and its signals, and ties the keep-or-roll-back decision to the answer recorded during review.
Written from real experience. Covers permissions as the unit, one shared evaluator, the fail-closed semantics including the empty-requirement defect found through a consumer's workaround, deriving the route posture test rather than maintaining it, the reference-data endpoint, and reconciliation with its production risk.
Written from real experience. Covers the architectural facts the process derives from, the additive posture, expand/migrate/contract with the rollback justification rather than the mixed-traffic one, the deployment sequence with a reason per step, the two rollback paths, downtime as a budget, and what is deliberately not recommended.
Written from real experience. Covers upstream decisions, crash-safe ordering, capability-over-identity, lifecycle separation, the must-not-disagree boundary, and startup gates. It also states explicitly what it does not cover and why.
Wrote the remaining documents with real evidence behind them: Database Design, API Design, Code Reviews (what review structurally cannot catch, and the control for each class), Documentation, and CI/CD. Architecture reached 7 of 7. Added a derived activity view, so what changed most recently is visible rather than inferred, and corrected the changelog itself: it had been listing every release twice, once as "planned topics" and again in its own history, and the two had drifted by four releases. Both lists are now computed from data each entry already carries.
Written. Documents the three layers (principles, decisions, standards), the knowledge-graph and metadata models, provenance and evidence movement, and states plainly where the evidence comes from and what that limits.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Initial structure and metadata established.
Related Documents· 1
Referenced By· 1
Version History
- v0.1.0
Foundation, structure and initial document set.
- v0.2.0
Maturity model, version history, breadcrumbs and command-palette search.
- v0.3.0
Decomposed the QA Process handbook into atomic Quality documents grouped by practice (Engineering Gates, Testing, Defects, Automation, Measurement) and expanded Operations to the full production lifecycle.
- v0.4.0
Migrated the real content out of the legacy QA handbook into the atomic Quality documents at full fidelity, preserving workflows, tables, decision matrices, and worked examples, and moved to a flexible page structure (summary, overview, why, then extracted content) instead of a fixed placeholder skeleton.
- v0.5.0
Wrote all ten Core Principles from real engineering experience and added three more (Evidence Before Abstraction, Make the Unsafe Unrepresentable, State the Choice), taking the constitution to thirteen. Extended the principle model with what each principle forbids, where it was learned, and whether a revision strengthened or weakened it against evidence, including one principle recorded as weakened and two kept at Draft because the practice behind them fell short.
- v0.6.0
Added Decisions as a first-class layer between principles and standards, with its own landing, records and navigation. A decision carries the options genuinely weighed (including the rejected ones), what deferring costs, how expensive it is to undo, and the evidence that would reopen it, the field that separates a deliberate deferral from an oversight. Three records established, and the ADR node type declared since v0.3 finally has instances.
- v0.7.0
Wrote the Overview: the three layers, the graph and metadata models, provenance and evidence movement, and a plain statement of where the evidence comes from and what that limits. Added an integrity check over every relationship and provenance link, after two silently-broken links were shipped and caught by luck; it reports all problems at once and gates on a non-zero exit.
- v0.8.0
Completed the first vertical slice, so the three-layer structure is demonstrated end to end rather than merely described: Think in Systems (principle) → The Isolation Model (DR-004) → System Design (standard). The standard also states explicitly what it does not cover, scaling, caching, queues, event-driven architecture, service decomposition, and why, rather than repeating guidance nothing here earned. The integrity check grew to cover inline markdown links in prose, the same silent-404 class it was built for.
- v0.9.0
Opened the Operations domain, which had eight documents and no content. Wrote Release Process (the architectural facts a release process derives from, the additive posture, expand/migrate/contract justified by rollback rather than mixed traffic, and the two rollback paths priced against each other), Monitoring & Observability (the inert-observation contract, correlation, privacy enforced structurally, and the rule for stopping), and Deployment Checklist (the test for whether an item belongs at all, plus stop conditions). Each states what it deliberately does not recommend.
- v0.10.0
Added Production Verification (the four claims a deployment can make, in ascending order of cost, and the failures only a browser can see) and Incident Response (restore before investigate, what a team without a rotation can honestly commit to, and the postmortem as a guardrail with its outputs ranked). Added Architecture, Isolation Models, the standard DR-004 implies, renamed from the planned "Multi-tenancy" because the old name presumed the answer.
- v0.11.0
Wrote the evidenced half of Architecture: Storage (four fused concerns separated, keys as policy, why a prefix is not an access boundary), Authentication (opaque sessions, the rotation defect that was a policy question answered implicitly, and the defaults that must be forced rather than configured), and RBAC (one shared evaluator, fail-closed semantics, and deriving the route posture test rather than maintaining it).
- v0.12.0
Wrote the remaining documents with real evidence behind them: Database Design, API Design, Code Reviews (what review structurally cannot catch, and the control for each class), Documentation, and CI/CD. Architecture reached 7 of 7. Added a derived activity view, so what changed most recently is visible rather than inferred, and corrected the changelog itself: it had been listing every release twice, once as "planned topics" and again in its own history, and the two had drifted by four releases. Both lists are now computed from data each entry already carries.