Back Matter
Index
A term index over the chapters and the appendix. A curated concept entry leads with the paragraph that defines it and the paragraphs that exemplify it; a plain term entry links the pages where it appears, capped so the index leads with the significant sites.
Book length
Word counts of the prose a reader reads — auto-generated on every build from the rendered text (code listings, diagrams, and figure captions excluded), so these numbers stay current and cannot drift.
| Part | Words |
|---|---|
| Body (narrative) | |
| Front Matter | 2,753 |
| Part 1 — The Context | 7,902 |
| Part 2 — The Mindset | 2,323 |
| Part 3 — The Governed Engineering Environment | 10,333 |
| Part 4 — The Model Zoo | 11,364 |
| Part 5 — Putting It to Work | 10,513 |
| Back Matter | 5,367 |
| Body subtotal | 50,555 |
| Appendix | |
| Appendix A | 19,855 |
| Appendix B | 14,713 |
| Appendix C | 9,235 |
| Appendix D | 2,148 |
| Appendix E | 1,151 |
| Appendix subtotal | 47,102 |
| Total | 97,657 |
#
A
- ADA / document accessibility Ch. 1, Ch. 14, Ch. 2, Ch. 3
- Adapter Ch. 3, Appendix A - 3
- Adopt the schema, skip the runtime Appendix B - 11
- Agent-orchestration modeldefinition of: Ch. 16
- agentic harness Ch. 6
- Audit Ch. 2, Ch. 3, Ch. 7, Ch. 8
- Audits into lintsdefinition of: Ch. 21
B
- ban-lint Appendix B - 14, Appendix C - 3, Ch. 6, Appendix C - 1
- Bill of materialsdefinition of: Ch. 14
- Blast radius Ch. 15, Appendix A - 17, Appendix B - 3, Appendix B - 5
- Bottom-up inductiondefinition of: Ch. 17
- Bounded model checkingdefinition of: Ch. 13
- Brownfield migrationdefinition of: Ch. 17
- Bun (runtime port example) Ch. 8, Implications for Software Engineering, Appendix A - 4
C
- canonical walker Appendix, Appendix C - 1, Appendix D - 5
- caused-by provenance Appendix, Appendix A - 14, Appendix D - 6
- census Ch. 18, Conclusion, Appendix E - 1
- Characterization / golden test Ch. 19, Appendix, Appendix B - 10, Appendix C - 10
- Cherry-pick Appendix A - 7, Appendix A - 19, Appendix A - 20
- Circuit breaker Ch. 18
- Claude Code, OpenCode Ch. 6
- Code smelldefinition of: Ch. 17
- Codemod Appendix C - 18, Appendix, Appendix A - 6, Appendix C - 19
- Component-zone modeldefinition of: Ch. 14
- Compounding failure probabilitydefinition of: Ch. 19
- conditioning the probability distribution Ch. 5
- Conditioning the searchdefinition of: Ch. 20
- Constraint Ch. 8, Appendix A - 3, Ch. 3, Ch. 6
- Constraint (prevents drift)definition of: Ch. 8
- Constraints and sensorsdefinition of: Ch. 8
- context window / compaction Preface, Ch. 4, Ch. 5, Ch. 6
- Control-substrate dependencydefinition of: Ch. 15
- coverage over model nodes Ch. 11, Ch. 16
- Coverage-to-model mappingdefinition of: Ch. 16
- cron-alerts gate Appendix, Appendix A - 15, Appendix D - 6
D
- Data-flow diagramdefinition of: Ch. 12
- DDT Appendix C - 10, Ch. 10, Appendix, Appendix A - 14
- Definition of Done (DoD) Ch. 3, Ch. 7, Conclusion, Appendix A - 23
- Demoable vs. productizabledefinition of: Ch. 20
- deployment topology Appendix B - 1, Appendix B - 7
- Deployment-topology modeldefinition of: Ch. 15
- Derivation directiondefinition of: Ch. 11
- Derive and joindefinition of: Ch. 11
- Deterministic vs. judgment splitdefinition of: Ch. 9
- Development view Ch. 11, Ch. 13, Ch. 14, Ch. 15
- Dispatch Appendix, Appendix A - 4, Preface, Ch. 2
- Diátaxis Ch. 18, Ch. 19, Appendix E - 1
- Diátaxis project Ch. 18
- Drift Ch. 7, Ch. 11, Appendix B - 9, Appendix C - 9
- drift gate Ch. 11, Ch. 15, Appendix A - 14, Appendix A - 18
- drift-parity gates Ch. 8, Appendix A - 27
E
- engineering environment Ch. 6, Ch. 8, Ch. 17, Implications for Software Engineering
- Epic Appendix A - 23, Appendix A - 24, Ch. 7, Ch. 11
- Ex-ante governancedefinition of: Ch. 8
- Ex-post governancedefinition of: Ch. 8
- Executable source-of-truthdefinition of: Ch. 11
- Explicit state machine (FSM) Conclusion
- Explicitness is essentialdefinition of: Ch. 21
F
- Facade Appendix C - 3
- Failure mode and effects analysisdefinition of: Ch. 9
- Failure to mechanismdefinition of: Ch. 8
- Fault / failure injection Ch. 4, Preface, Ch. 5, Ch. 6
- fitness function (correctness definition) Ch. 17
- Flake Appendix A - 12, Appendix C - 12
- flock / semaphore Ch. 13, Ch. 15, Ch. 16, Appendix
- Formal invariant verificationdefinition of: Ch. 13
- foundation model / model tier Ch. 5, Ch. 6, Ch. 20, Appendix B - 7
- Fuzzing Ch. 2, Appendix C - 11, Appendix C - 12
G
- Gate Ch. 11, Appendix, Appendix A - 8, Appendix A - 9
- Gating Appendix A - 11, Ch. 15, Appendix, Appendix A - 26
- Governance as design patternsdefinition of: Conclusion
- Governance mechanism Preface, Ch. 7, Ch. 8, Ch. 15
- Governance packagedefinition of: Ch. 8
- Governance-centricdefinition of: Ch. 21
- Greenfielddefinition of: Ch. 17
H
- Heartbeat Appendix A - 16, Appendix, Appendix A - 8, Appendix A - 20
- Hook (hard mechanism)definition of: Ch. 6
I
- Injection pointdefinition of: Ch. 6examples of: Ch. 7
- injection point (where a mechanism attaches) Ch. 6, Appendix A - 3
- Invariantdefinition of: Ch. 11
- invariant / policy over a model Ch. 13, Ch. 15, Ch. 16, Appendix B - 11
- Invariant-DAG execution policydefinition of: Ch. 15
J
- join key Ch. 16, Appendix B - 6, Ch. 11, Ch. 12
- Journey-criticality test placementdefinition of: Ch. 16
- Judgment into infrastructuredefinition of: Ch. 21
- Judgment is the scarce resourcedefinition of: Conclusionexamples of: Ch. 21
L
- lexicon Ch. 18, Ch. 19, Appendix E - 1
- Lifecycledefinition of: Ch. 9
- Lintdefinition of: Ch. 17
- Lint, cover, inducedefinition of: Ch. 17
- lint-cover-induce Ch. 17
- Liveness propertydefinition of: Ch. 13
- Logical view Ch. 11, Ch. 12, Ch. 13, Ch. 16
- Loop engineeringdefinition of: Ch. 5examples of: Ch. 5
M
- Make a lint blockingdefinition of: Ch. 17
- make-lint-blocking Ch. 17
- Map and territorydefinition of: Ch. 7
- Marker interface / attribute Ch. 20, Appendix B - 6, Appendix C - 2, Appendix C - 3
- Measure one level deeperdefinition of: Ch. 10
- Measure one level deeper (Ousterhout) Ch. 10
- Mediator registrydefinition of: Ch. 13
- merge-train Appendix, Appendix A - 5, Ch. 21, Appendix A - 4
- meta-sync Appendix, Appendix B - 20, Appendix D - 1
- model Ch. 3, Ch. 5, Ch. 7, Ch. 10
- model (as map / cheaper approximation) Ch. 3, Ch. 5, Ch. 7, Ch. 10
- Model as mapdefinition of: Ch. 7examples of: Ch. 7 Ch. 11
- Model driftdefinition of: Ch. 11examples of: Ch. 7
- Model only where a failure livesdefinition of: Ch. 15
- Model-from-codedefinition of: Ch. 11
- Model-to-codedefinition of: Ch. 11
- Models join, they do not repeatdefinition of: Ch. 16
- models-bridge Appendix, Ch. 7, Ch. 18, Ch. 20
- mutator stamp Appendix C - 16
N
- Node coveragedefinition of: Ch. 16
O
- Observabilitydefinition of: Ch. 8examples of: Ch. 8
- Optionality is poisondefinition of: Ch. 21
- Oracle Ch. 2, Ch. 10, Implications for Software Engineering
- orchestrator Ch. 5, Ch. 7, Ch. 9, Ch. 16
- orthogonal (complementary) models Appendix E - 1, Ch. 18
P
- Performance-and-cost modeldefinition of: Ch. 15
- Physical view Ch. 11, Ch. 14, Ch. 15, Ch. 16
- Picture vs. modeldefinition of: Ch. 4examples of: Ch. 4
- pre-canned brief Ch. 9
- Probabilistic reasoning machinedefinition of: Ch. 5
- Process view Ch. 7, Ch. 11, Ch. 12, Ch. 13
- Property-based test Appendix C - 12
- Protocols and TLA+definition of: Ch. 16
Q
R
- reasoning steps / chain of thought Ch. 19
- Refactoring is freedefinition of: Ch. 21
- Reference classdefinition of: Ch. 20
- reference class (imposed by the model) Ch. 20
- reflection-facet Appendix A - 18, Appendix, Appendix A - 3, Appendix A - 14
- repair vocabulary Appendix
- Rollback Appendix A - 8
- Rolls-Royce, Boeing (high-assurance modeling) Ch. 7
- Root-cause analysis (RCA) Ch. 6, Appendix B - 12
- Rubricdefinition of: Ch. 9
- Rule-metadata registrydefinition of: Ch. 14
- Runbookdefinition of: Ch. 9
- runbook / playbook Ch. 9, Appendix A - 26, Appendix A - 27, Ch. 2
S
- Safety propertydefinition of: Ch. 13
- Scenarios view Ch. 11, Ch. 16
- search space (narrowing / conditioning) Ch. 20
- Self-communicatedefinition of: Ch. 18
- self-communicate (skill) Ch. 18, Ch. 19, Appendix E - 1
- Self-governancedefinition of: Ch. 18
- self-governance (skill) Ch. 18, Ch. 19, Appendix E - 1
- Self-operatedefinition of: Ch. 18
- self-operate (skill) Ch. 18, Ch. 19
- Semantic gap Ch. 7, Appendix A - 28
- Sensor Ch. 8, Ch. 3, Ch. 10, Ch. 11
- Sensor (detects drift)definition of: Ch. 8
- sentinel Appendix A - 7, Appendix, Appendix A - 5, Appendix A - 6
- Service-oriented architecture (SOA) Ch. 12, Appendix B - 18
- Shift-left Appendix A - 11
- Single source of truth Appendix B - 18, Ch. 12, Appendix B - 8
- Single-writer registrydefinition of: Ch. 13
- Sizing the leapdefinition of: Ch. 19
- Skill (soft mechanism)definition of: Ch. 6
- SLO / SLI Preface, Ch. 1, Ch. 2, Ch. 3
- smell (code smell) Ch. 17, Ch. 18, Conclusion, Appendix B - 5
- Smoke test Ch. 2, Appendix A - 8
- soft / hard enforcement Ch. 7, Ch. 10, Ch. 21, Implications for Software Engineering
- Soft vs. hard governancedefinition of: Ch. 21
- Specification-driven developmentdefinition of: Ch. 8
- Staged deploy Appendix, Appendix A - 8
- Starry Night (diffusion example) Ch. 20
- State machinedefinition of: Ch. 13
- success metric / rubric Ch. 5, Ch. 9, Ch. 17
- Synchronization modeldefinition of: Ch. 13
T
- teetering tower of governance Ch. 18
- Temporal logicdefinition of: Ch. 13
- temporal logic (LTL) Ch. 7, Ch. 13
- test-onion Appendix C - 13, Appendix, Appendix C - 10, Appendix C - 11
- Tests for agent failure modesdefinition of: Ch. 21
- The 4+1 viewsdefinition of: Ch. 11
- the agent Ch. 16, Ch. 18, Preface, Ch. 2
- The agent stackdefinition of: Ch. 6
- The agentic harnessdefinition of: Ch. 6
- The autonomy amplifierdefinition of: Ch. 21
- The broken cost estimatordefinition of: Ch. 21
- The context windowdefinition of: Ch. 6
- The Development viewdefinition of: Ch. 14
- The diffusion analogydefinition of: Ch. 20
- The drift gatedefinition of: Ch. 11
- The engineering environmentdefinition of: Ch. 6
- The fitness functiondefinition of: Ch. 17
- The foundation modeldefinition of: Ch. 6
- The governance cataloguedefinition of: Ch. 18
- The governed environmentdefinition of: Ch. 8
- The lexicondefinition of: Ch. 18
- The Logical viewdefinition of: Ch. 12
- The model zoodefinition of: Ch. 11
- The novelty axisdefinition of: Ch. 20
- The per-model templatedefinition of: Ch. 11
- The Physical viewdefinition of: Ch. 15
- The pre-canned briefdefinition of: Ch. 9
- The printer metaphordefinition of: Ch. 4
- The Process viewdefinition of: Ch. 13
- The right level of enforcementdefinition of: Ch. 7
- The Scenarios viewdefinition of: Ch. 16
- The search spacedefinition of: Ch. 5examples of: Ch. 20
- The semantic gapdefinition of: Ch. 7examples of: Ch. 7
- The success metricdefinition of: Ch. 5
- The teetering towerdefinition of: Ch. 18
- Three ways to run an agentdefinition of: Ch. 21
- TLA / model checking Ch. 7, Ch. 11, Ch. 13, Ch. 16
- tombstone Appendix A - 19, Ch. 5, Ch. 16, Ch. 18
- Tool (deterministic action)definition of: Ch. 6
- Top-down refinementdefinition of: Ch. 17
- Traceabilitydefinition of: Ch. 11
- traceability (quality case) Ch. 3, Appendix B - 19, Ch. 10, Ch. 11
- traceability round-trip Ch. 11
- Training-data biasdefinition of: Ch. 20
- Transformationdefinition of: Ch. 19examples of: Ch. 3
- transformation (input→output) Ch. 19, Ch. 3
- Typed seam Ch. 17, Ch. 18, Appendix A - 3, Appendix B - 2
U
- UML (Unified Modeling Language) Ch. 7, Appendix B - 21
- user journey Ch. 7, Ch. 16, Appendix B - 21
- User-journey modeldefinition of: Ch. 16
V
- Validator Appendix C - 7, Preface, Ch. 3, Ch. 10
- Velocity exposes the dangerdefinition of: Ch. 21
- Vibe-coding vs. engineeringdefinition of: Ch. 21
W
- WCAG / conformance Appendix, Ch. 1, Ch. 2, Ch. 10
- Whose fault is a bad builddefinition of: Ch. 4examples of: Ch. 4
- Worker pool Appendix A - 17
- Worktree Appendix A - 12, Ch. 2, Ch. 5, Implications for Software Engineering
© James C. Davis, 2026–present