Blueprints with Teeth#
Fail-Closed Architecture Conformance for AI-Built Systems
Design, Checker Validation, and First Production Experience of bce
Mitchell Tieleman · 36 pages · September 1, 2026 draft
Working draft — shared for discussion. This version is still being revised. Feedback on the argument, methods, and unclear passages is welcome.
What the paper explores#
The same codebase can receive a perfect architecture score under one blueprint and fail under another, even when no code has changed. The difference is whether the rules can detect a violation.
The paper develops that problem through executable architectural contracts, checks that a blueprint can actually fail, validation of the checker itself, and evidence from the author's early deployment. It includes the system design, seeded-defect measurements, production incidents, and the limits of those observations.
Reading this draft#
This is a historical account of the system and its early deployment. Its measurements are scoped to the dates, engine versions, corpus, and author-operated environment stated in the paper. They do not establish general improvements in coding-agent outcomes or describe every capability in today's public engine.
September 8 reading note: subsequent route-extractor counterexamples show that a green result can coexist with omitted handler exports or a guard call that does not enforce access. The route evidence boundary distinguishes the released limitation, the source correction, and the semantic properties still unverified. The draft PDF is unchanged. Its checker-validation and seeded-corpus results do not establish complete route coverage or an authentication/tenant-isolation guarantee.
For current released behavior and evidence, see the specification and Trust and evidence.
Share feedback on the argument, methods, or unclear passages.