HomeProductsTwo Anchors

PRODUCT · TWO ANCHORS

The Two-Anchor architecture: an AI-driven corporate SDLC.

The end of the application, and a new contract between Business, IT and AI. AI generates only the user’s interaction with a system—never the system itself.

Reference architecture Operating model Governance by design Platform-neutral

The bad fork

Organisations face two poor options. Shadow IT is fast, ungoverned and unmaintainable. The delivery pipeline is governed, but it spends months on analysts translating needs into specifications, losing fidelity at every handoff. AI changes the economics of that translation—but only if it avoids an old trap.

Every past attempt to generate software from models failed for the same reason: the model had to absorb all of the implementation complexity. Any AI vision that repeats “the prototype is the spec” repeats that failure.

The core claim

The generated artefact does not specify the system. It specifies the interaction with the system.

Implementation complexity stays where it belongs—engineered, tested and owned by IT. AI abstracts only the user’s interaction with it. That single boundary is what makes generation safe to use at the pace the business wants.

The architecture

LAYER 1 UX skin

Generated, iterated and disposable. It holds only what the user sees and intends, and it can speak only the intent vocabulary below it.

LAYER 2 Translation layer: the intent catalogue

The headless application. It exposes no raw CRUD—only versioned, permissioned business intents such as ApproveExpense or CancelSubscription.

LAYER 3 Canonical domain layer

Enforces concepts, constraints and invariants, then delegates to the underlying systems.

LAYER 4 Systems of record

Engineered, tested, owned and operated by IT, exactly as today.

Two anchors, one fluid span

Only two artefacts are stable, one per audience. Everything between them is fluid, and safe to be so.

  • The canonical representation (above): the fixed notation people comprehend and agree with—designed like cartography, learned like a language, stewarded by the business, never personalised. It is where users verify that what they intended is what happened.
  • The intent catalogue (below): the versioned vocabulary of everything systems may be asked to do—engineered by IT, federated per business domain, evolving like a public API. Its growth rate is the system’s true throughput metric.
  • Skins can only speak the intent vocabulary, and results are always verified against the shared canonical picture
  • Comprehension anchored above, action anchored below, generation confined between

How it works in practice

Business iterates with AI inside an explicit constraint envelope. Hard constraints—volume, latency, permissions—are checked automatically in the loop. Soft ones—legal, commercial, strategic—are handled by advisory architect review, gating only at promotion. Iteration emits process models, decision logs and check results as evidence, not as implementation source. The typed boundary lets skin and headless application be contract-tested independently, and turns fault attribution into a log lookup rather than a border dispute.

The ownership contract

IT owns the translation layer down: data, integrity, security, availability, the headless application, and on-call. Business owns everything above: the skin, the pace, the canonical view—and answers for what its interfaces mean.

Surfaces are risk-tiered. Personal and team surfaces morph freely. Shared surfaces are change-controlled. Regulated surfaces are converged with AI, then promoted, frozen and certified.

What is new, and what is not

The components have a proven lineage: task-based interfaces, domain-driven design, hexagonal architecture, contract testing, data mesh, composable capabilities. The contribution is the composition. Two canons instead of one—for machines and for human comprehension. A hard boundary on generation: AI never generates the anchors. Federation instead of a universal model. And a platform-neutral contract owned by the organisation, not licensed from a vendor.

Open questions we are honest about

  • Containment—“near-zero blast radius”—must be proven with pilot metrics, not asserted
  • Encoding soft constraints is unsolved
  • Accessibility of generated surfaces needs conformance gates, not statistics

Shadow IT disappears because the sanctioned path is the fastest path. The translation chain disappears because use replaces specification. Human agreement—the scarcest resource—is spent on the two artefacts where agreement is the product.

Discuss a Two-Anchor pilot.

A pilot starts with one business domain, one intent catalogue, and one team that is currently choosing between shadow IT and waiting. We will tell you whether yours is a good first case.