20  Reference Architecture: The Layered Trust Pipeline

Part II ended with an empty cell: composed systems that generate their own accountability. This chapter fills it with a reference architecture — abstracted from working systems (the cases in the next two chapters) and deliberately stated as layers and rules rather than products, so it survives any vendor’s roadmap.

20.1 The seven layers

1. Market and catalog. The public surface: a catalog of standard outputs rendered on synthetic data, each entry carrying its spec, verdict, and a one-command reproduction; documentation that doubles as a demo and a regression instrument. Strangers can verify the product without talking to anyone.

2. Experience. The interactive tier: review portals, TLF viewers, exploration apps. Its rule: consume only through the platform’s contracts, inherit authentication from one shared module, and stay stateless so the data governance story is simple. This layer is where users live; it is never where truth lives.

3. Access and identity. One pluggable identity boundary — SSO token verification written once and included by every app, server-side authorization at the data service, layered permissions (milestone, dataset, application). The rule from the case literature: identity is an interface, not an assumption, so the same product can live in a partner portal, an off-the-shelf OIDC provider, or a demo mode.

4. Orchestration. A gateway that accepts contract-validated jobs, queues them atomically, and serves status and artifacts. Quota and authentication tiers belong here — the border where “who may ask for what” is enforced before anything executes.

5. Execution. Sandboxed workers: hardened containers, read-only filesystems, dropped capabilities, no network to model APIs by default, memory and CPU limits, pinned engine versions. Inside a worker, any language; across workers, only contracts and artifacts pass.

6. Evidence. The heart, and the layer the incumbent stacks lack by construction: hash-addressed artifacts with lineage edges; locked references for every approved deliverable; independent recomputation with cell-level, tri-state comparison; render gates that stop the line; append-only audit chains; manifests that make every execution replayable. Evidence generated as a side effect of work, never as a write-up afterward.

7. Data. Study data stays put — in the customer’s environment, on their shares, under their governance — and the pipeline travels to it. Synthetic data with recorded provenance fuels every public surface.

20.2 The rules that bind the layers

Layers alone are a diagram; four rules make them a system:

  • Contracts at every border. Versioned, additive-only, self-declaring payloads; consumers reject unknown majors. (Principle Two in Part III.)
  • One artifact economy. Everything a layer emits — dataset, figure, verdict, log — is content-addressed and lineage-linked. Side doors (email, ad-hoc exports) are closed by design.
  • Gates have authority. A failed comparison halts the render. Escalation is a signed, recorded human act.
  • The kernel is portable. Layers 5–6 plus the engines constitute a kernel that runs identically in a public demo, a customer VPC, and an internal reference deployment (Principle Nine).

20.3 Why this beats both alternatives

Against the validated monolith: every layer is swappable behind stable contracts, so no single vendor negotiation owns your roadmap, and the validation evidence is yours — generated by your system about your work — rather than rented annually about a tool. Against the loose ecosystem: the evidence layer exists, which is the entire difference between capability and accountability. The costs are honest ones: you own integration, you own operations, and you must resist rebuilding commodity parts (Principle Eight) — the architecture only works if the layers stay thin and the engines stay absorbed.

The next two chapters show two-thirds of this architecture running in production: the experience-and-operations spine as a composed review platform, and the evidence layer as a validation gateway. The full assembly — one product across all seven layers — is the roadmap this book’s closing chapters describe.

The test. For any “platform” pitch, ask which of the seven layers the vendor actually occupies — and who fills the evidence layer if they do not. Diagrams that omit layer six are hosting arrangements wearing architecture clothes.