Product thinking
Think of the thing as something that will be used again, by people, and will have to change. Design for that life, not for the handover.
Discipline · Meaning Coherence Assurer
The discipline. What it produces: Decision Instruments, Meaning, Coherence, Data and Assurance Products — delivered as governed Executables.
The method says how an organisation decides, and the architecture says what it runs on. This page is about the thing in between: how I think about building what a client actually receives, and what has to be true of it before anyone is asked to rely on it.
Four thinking skills sit under everything: decomposition, algorithms, pattern recognition and abstraction. The work then climbs an abstraction layer, descends a logical continuum into something that runs, and is kept alive by life-cycling. Three engineering domains do the building, with support and additional domains behind them.
| Step | What it does |
|---|---|
| Abstraction layer | Moves from problem to opportunity, options, choices and hypotheses; from concept through a schematic or visual to a logical form; and from principles through key business questions (KBQ) to purpose, goals and objectives. All of it is held in context, so that nothing is decided in the abstract. |
| Logical continuum | The logical form becomes a physical model, then a mathematical, operations research or simulation model, then a prototype that can be tried. |
| Life-cycling | Versioning management and optimisation turn the prototype into a solution that can be kept, changed and retired in good order. |
| Domains | Decision, Coherence and Meaning Engineering are the three that carry the work. Model-Driven Software Engineering, Mathematical Engineering and Site Reliability Engineering support them. Evidence and Implementation are additional domains. |
Pattern recognition earns its place by saving effort. CQRS, for instance, keeps the write model apart from the read models, so each can be shaped for its own job.
A product here is not a deliverable that happens to work. It is built from four principles, and judged against eight qualities.
Think of the thing as something that will be used again, by people, and will have to change. Design for that life, not for the handover.
Meaning by default. The default semantics are right, so the product is correct without configuration, and a user has to work to make it wrong.
Every part answers a stated purpose. What cannot be tied to one is removed.
The user is the person who must decide, act or answer for the result, and the product is shaped around what that person needs to know.
| Useful | It serves a decision or task that someone actually has. |
| Usable | The people it is for can use it without special help. |
| Understandable | Its logic and its results can be explained in plain terms. |
| Trustworthy | Honest about its limits: it says what it does not cover and how sure it is. |
| Coherent | Its parts agree with one another and with the meanings it declares. |
| Maintainable and evolvable | It can be corrected and extended without breaking what depends on it. |
| Efficient | It uses no more effort and resource than the purpose warrants. |
| Accountable | Every output can be traced to its sources, its rules and its owner. |
Two words set the ambition. Better means the product measurably improves the decision it serves. Beyond means it changes which decisions are possible at all.
Requirements are sorted by kind, because each kind is tested, owned and changed in a different way.
| Category | What it states |
|---|---|
| Functional | What the product does: the behaviour a user can observe. |
| Non-functional | How well it does it: the quality attributes, such as accuracy, speed, availability, security and explainability. |
| Constraining (specification) | A limit on how the product may be built or run, set from outside the design: a standard, a platform, a jurisdiction, a format. |
| Business rule | A rule of the organisation that the product must apply or respect, owned by the business and not by the engineers. |
| Architectural contract | The interface and the invariant that other parts may rely on. It is promised to the rest of the system, so changing it is a breaking change. |
Every offering has a type, which says what it is for, and a form, which says how it is delivered. Read together they make a grid of five types by four forms.
Decision Instrument. Meaning Product. Coherence Product. Data Product. Assurance Product.
Product. Instrument. Offering. Executable: governed, versioned and runnable. The Executable is the form that carries the full set of guarantees.
Each delivered product carries a Product Contract, so a client can see what was promised without asking.
| Purpose · Users | What it is for, and who it is for. |
| Inputs · Outputs | What goes in, and what comes out. |
| Semantics | What the terms and the results mean. |
| Quality attributes · Invariants | How well it performs, and what must always hold. |
| Evidence · Limits | What supports it, and where it stops being reliable. |
| Versioning · Ownership · Retirement | How it changes, who answers for it, and how it ends. |
Scores measure maturity. Warrants govern reliance.
The medallion runs from Bronze to Silver to Gold. Two planes sit alongside it rather than above it, and promotion between layers is by contract.
The two planes are alongside, not on top, because meaning and abstraction apply at every medallion layer. They are not a fourth and fifth step that data climbs.
Data moves between layers only through six promotion gates, P1 to P6. Each gate is a contract check, and each check is held under one of three enforcement classes.
| Class | Meaning |
|---|---|
| E · Enforced | A machine applies the check and blocks promotion if it fails. |
| M · Monitored | A machine watches and raises a flag, and a person decides what follows. |
| A · Attested | An accountable person states that it holds, and their name stays on the record. |
This works with a Data Mesh, where domains own their products, and with a Logical Data Fabric or virtual ODS, where data is queried in place. The planes are what keep meaning consistent across domains.
A product stands on three legs. A short leg is not made up for by a long one.
The right thing: it does what the decision actually needs.
The right cost and effort: no more than the purpose warrants.
The right quality and craft: it is made properly and will hold.
The Tripod Floor is the rule that keeps this honest: no product ships if any one leg is below its floor, however strong the other two are.
Mining runs the architecture in reverse. Instead of building from intent toward evidence, it starts from what is there and works out what is actually happening. It has seven disciplines.
| Discipline | What it looks for |
|---|---|
| Data mining | Patterns and structure in the data itself. |
| Decision mining | The decisions that are really being made, and on what. |
| Process mining | The process as it runs, against the process as described. |
| Coherence mining | Where decisions, rules and measures disagree with one another. |
| Meaning mining | The meanings in use, and where one term carries several. |
| Evidence mining | What is relied on, and what it rests on. |
| Outcome mining | What followed, and how it connects to what was decided. |
Findings do not go straight into the design. Each enters as a Discovery Case, which is examined before anything is built on it.
Things said in a product will sometimes be wrong. The design makes correcting them visible, and makes meaning behave like state that is managed.
A claim can be revised or withdrawn, and the trail stays visible and versioned. Nothing is silently overwritten. I think of it as an “unsay” pattern: to unsay something, you say so, on the record.
Every term and every claim has a type and a lifecycle. Only legal transitions are allowed, so a term cannot move from draft to retired without passing through the states between.
The axioms the product rests on are held in their own layer and declared, not scattered through the rules. Changing one is a constitutional change, handled as such.
This is the newest part of the doctrine, and I hold it more tentatively than the rest. It asks a plain question of every claim a product makes: what kind of claim is this, and so what could count against it?
| Kind | What it is | Verdict |
|---|---|---|
| Meaningless | No defined subject, domain or interpretation. It is not even false. | Cannot be tested, and cannot be relied on. |
| Unfalsifiable by kind | Values, axioms and constitutive commitments. They are not the sort of thing evidence settles. | Legitimate, if declared as what they are. |
| Immunised | Testable in principle, but worded or governed so that nothing may count against it. This can happen by wording, by compression or by capture. | The pathology. |
The rule: absence of falsification is not truth, and prevention of falsification is evidence against the claim.
In a product, each claim is given one of eight types: value, belief about reality, empirical hypothesis, assumption, preference, causal claim, warrant or authority. The type decides what evidence is owed. Creed is not fact, and neither is warrant: a creed is declared, a fact is observed, and a warrant is the ground on which reliance is placed.
| Form | Where it shows |
|---|---|
| Declared | What the institution says it believes. |
| Embedded | What its rules and metrics assume. |
| Revealed | What its repeated, costly choices show. |
| Presupposed | What must be true for its reasoning to make sense at all. |
Gaps between the four are measurable incoherence. Argyris and Schön called the first gap espoused theory against theory-in-use; organisational studies call a related one decoupling.
A creed is not proved. It is declared, and kept contestable. Whether it is healthy shows in how it defends itself, in the sense Lakatos gave to research programmes.
It absorbs contrary evidence by making new commitments, and those commitments turn out to be right.
It meets contrary evidence with ad hoc reinterpretation, each one protecting the creed and adding nothing.
Single-loop learning corrects actions. Double-loop learning can revise the creed itself, and it needs a protected, independent and authorised challenge process.
A preference is built into rules or metrics, and the result is then presented as what “the process produced”. The counter is to require every material outcome to trace to a named decision record, so that a person, not a process, is visibly the one who chose.
Doctrine is what an institution says it lives by. Dogma is what it actually rewards, forgives and protects. Neither has to be guessed at, because both leave records. Three readings show the gap.
| Reading | The question | What it reveals |
|---|---|---|
| Rewards | What leads, reliably, to promotion, recognition and safety? | The operative creed. People learn the reward system, not the value statement. |
| Mistakes | When a well-reasoned decision turns out badly, and a careless one turns out well, which is rewarded? | Whether decisions are judged on their warrant at the time, or only on how they turned out. |
| Mute symbols | Which words and practices arrived without a decision, and cannot be questioned without social cost? | Preferences that were adopted for legitimacy and never declared as preferences. |
A mute symbol is a term or practice presented as neutral or necessary, which no one remembers choosing. It often arrives because respected peers or powerful groups adopted it first. In this architecture no term enters the governed vocabulary without a type, a definition, an owner, the decision rule it changes and the evidence that would show it is not working. A term without these is flagged as unbound: present in what is said, absent from what is done. De-muting it means naming it as a choice, saying whose preference it serves and what it costs, and allowing alternatives to be heard.
Changes actions within the current rules.
Changes the decision rules, constraints and goals.
Changes the rules by which the decision rules may be questioned. An institution can be busy at the first two levels and still never change at the third.
Ordinary warrants ask whether the evidence supports the conclusion. Meta-warrants ask why this evidence, this authority and this constraint count at all. Reasoning can be rigorous at the first level and rest on an unexamined answer at the second. Independence at that level must itself be shown: who appoints the reviewer, who funds them, who can remove them, and what evidence they may use. Being external is not the same as being independent.
The framework applies this to itself. It declares its own axioms and its own revision path, and it is open to the same challenge it asks of others.
Where a light footprint is needed, the engineering runs on a small event-sourced stack. Each tool does one job.
| Job | Tool |
|---|---|
| Store of record | Postgres |
| Event backbone | NATS JetStream |
| Change data capture | Debezium Server |
| Read models and search | SQLite FTS5 |
| Edge gateway | KrakenD, declarative and stateless |
| Plant and IoT telemetry | OpenDAX, the open-source Data Acquisition and Control tool, as a Bronze source |
You can try the read side on this site’s own pages in search, see how the capture options compare in the CDC head-to-head, and read the fuller design in the architecture.
The method it serves → The architecture it runs on → The work →
Start with one decision, or one meaning that needs to hold across systems. I will tell you plainly what kind of product it is, what it must promise, and where it should stop.