Every figure in the book — 135 in all — gathered here in reading order, each with its full caption. A quick way to review the book's visuals in one place; every figure links back to where it appears in the text. The chapter figures come first; the appendix pattern pages follow in a lighter schematic style. (See also the List of Figures and Tables for tables, and a scannable index of short captions.)
Chapter figures
The book-proper figures, hand-drawn to the house palette.
Figure 0.1-1.The book's argument. The Preface and Chapter 1 establish the engineering problem. Chapters 2–5 develop and substantiate MAGE through its software-engineering case study. Chapters 6 and 7 abstract from that case to theory and broader engineering implications, and the Conclusion returns to the opening question through responsibility.
Figure 0.3-1. The MAGE method. Scale creates the enduring reasoning problem; commodity intelligence changes its economics. Modeling makes consequential engineering properties explicit and available to analysis; Alignment makes selected obligations enforceable. Governance conversion turns recurring failures and judgment into models and controls that future work can reuse, so engineering effort can accumulate instead of being paid for again.
Figure 0.4-2. The agent stack and a characteristic failure mode. When a task's reasoning horizon exceeds the working state the harness can keep active, repeated reconstruction contributes to churn.
Figure 0.4-3. The governed environment. Governance mechanisms enforce engineering obligations by acting directly on observable work or through explicit models that expose richer semantics. Durable models, mechanisms, procedures, and documentation accumulate as engineering capital.
Figure 0.5-1.From case to theory. MAGE began with one deeply observed production system, then was compared with seven independent industrial systems. The originating case shows mechanism and sequence; the industrial cases show variation and alternative ways to realize the same moves.
Figure 1.1-1.Where engineering leverage acts. When engineers write most implementation directly, much of their engineering leverage acts through the code. When agents provide abundant realization capacity, more of that leverage moves into the governed engineering environment—the software analogue of the models, fabrication constraints, process instructions, and acceptance criteria surrounding a 3D printer. The environment becomes one means through which engineers retain control while delegating realization: it represents important engineering intent, constrains realization, and evaluates what the fleet produces. MAGE further contends that a governed engineering environment must become the primary means through which engineers exercise control as realization is increasingly delegated.
Figure 1.2-1.DocAble from the user's view. An inaccessible document goes in; a remediated document and evidence of consequential changes come back. Internal structure is omitted because it is not yet relevant.
Figure 1.2-2.Processing one document in DocAble. A user submits a document, creating a job that tracks its processing. The work may be divided into chunks and processed by workers using specialized services for generation, rendering, optical character recognition (OCR), and document-format processing. The resulting changes are reassembled and validated, and the remediated document is returned with evidence.
Figure 1.3-1.Agentic machinery and environment. The foundation model supplies inexpensive semantic reasoning under finite, probabilistic working conditions; the harness turns that reasoning into action, manages its context, and exposes points where the environment can observe or constrain it. These are the properties of the productive substrate the engineered environment must work with.
Figure 1.3-2.The reasoning horizon. At sufficient scale, a task requires more state than a finite reasoner can keep active, so some state must be reconstructed. Representation determines the cost: raw implementation carries irrelevant detail, while purposeful abstraction can keep question-relevant state smaller and cheaper to recover.
Figure 1.4-1.From substrate to method. Finite reasoning state creates the Representation Problem; probabilistic autonomous work creates the Enforcement Problem. Chapters 2 and 3 develop MAGE's corresponding answers: Modeling and Alignment.
Figure 2.1-1.Obligations bound a realization space without selecting one realization. Each region contains implementations satisfying one engineering obligation; their intersection contains implementations satisfying both. The points within that intersection may differ substantially in structure and implementation while remaining acceptable under the represented obligations. Those remaining choices are realization degrees of freedom.
Figure 2.1-2.Obligation, scaffolding, and degrees of freedom. The engineering obligation establishes the minimum consequential content that must be preserved. A particular agent may require additional scaffolding to interpret and realize that obligation reliably. Greater agent capability can reduce this scaffolding and enlarge the realized degrees of freedom, but it does not change the obligation itself.
Figure 2.1-3.From engineering question to engineering consequence. Hold the system fixed and change the question, and the useful representation changes with it. The representation determines which analyses become tractable; analysis produces evidence that can inform architecture and design, expose a property for checking, or both. Chapter 3 takes up the separate question of which obligations should be enforced.
Figure 2.1-4.The engineering modeling repertoire. Familiar representations preserve different relationships for different engineering questions. Similar graphical forms can carry different semantics: an arrow may represent a dependency, transition, flow, permission, ownership relation, or derivation.
Figure 2.2-1.The structural move: entities and typed relations. Nodes are the entities a question needs; edges are the declared relations between them, and the edge label carries the meaning. Its analyses are graph operations — reachability, path, and cycle checks.
Figure 2.2-2.Document-mutation structural model. The reduction preserves one architectural relation: ordinary remediation reaches format-specific mutation through a structured-document seam. Enforcement of that relation is a separate Alignment decision.
Figure 2.2-3.From computations to composition. Typing the dependencies among registered computations separates payload-bearing relations — data-flow and cross-service — from control gates that a computation consults only to decide whether it runs.
Figure 2.3-1.The behavioral move: states and transitions. A model keeps the legal states and the permitted transitions and discards the code; the transition it omits — here the skip from IDLE straight to DONE — is the behavior it forbids. Its analyses search for a reachable bad state or a required event that never arrives.
Figure 2.3-3.Behavioral models expose different classes of properties. A transition relation can support local legality checks, reasoning over reachable states, or temporal claims over executions. The appropriate checker follows from the property; richer machinery is not automatically stronger for every question.
Figure 2.3-4.In-flight ownership model. A current claim records owner, epoch, and lifetime. Completion releases the claim; expiry makes it reclaimable. The model distinguishes a live claim from a stale one without representing the storage machinery that implements the lease.
Figure 2.3-5.Model classes overlap. The same lease state supports ownership, behavioral, and measurement questions. The classes distinguish purpose, not storage objects.
Figure 2.4-1.The decision move: the same arrow, a different mood. A structural edge states that a call happens; a decision edge states that it is permitted. The absent edge carries the weight — "not allowed," not "does not happen" — and the analyses check a declared policy for consistency and least privilege.
Figure 2.4-2.Service-flow model. A declared graph of which service may reach which. The public web tier is the only node facing the outside; an absent edge means the relationship is not permitted by the model, and enforcement is separate.
Figure 2.4-3.Observation and intent answer different questions. The observed system can reveal that A calls C; the decision model can state whether that relationship is permitted. Agreement establishes correspondence, not correctness.
Figure 2.4-4.The upload-entitlement domain. A user belongs to one or more groups; a group carries either a finite credit balance or unlimited use. The admission decision needs both facts, so a representation that can express only the finite balance cannot answer the question the decision asks.
Figure 2.4-5.One distinction, lost and preserved. The scalar reduction cannot represent unlimited entitlement; the revised model preserves the distinction.
Figure 2.5-1.Heterogeneous models over shared identities. DocAble maintains several representations for different engineering questions. Stable identities and explicit correspondence allow those representations to be joined when a question crosses them without requiring one universal model of the system.
Figure 2.5-2.Attribution provenance model. A run contains consequential operations; each operation records its target, mutation, responsible pass, and retained evidence. Audit and explanation can be derived from this shared history.
Figure 2.5-3.Computation structure versus realized history. The computation graph models declared computations and their typed composition; the per-session edit record logs the consequential mutations one run actually produced. They are separate reductions; a shared computation identity can join runtime edits to the static model when an engineering question requires that relation, without collapsing the two representations into one.
Figure 2.5-4.Task-driven traversal. A task enters the modeling substrate through a named system entity and follows only the represented relationships required by its engineering question.
Figure 2.5-5.Three correspondence patterns. Derive where implementation is the source of truth; generate where the model is the source of truth; otherwise maintain traceability and check the correspondences that are decidable.
Figure 2.5-6.Coverage of model correspondence. Mechanical checks cover only claims the representation makes decidable; semantic claims still require judgment, and unmodeled properties have no model-based coverage.
Figure 2.5-7.Checked predicates over a structured model. A structured model supplies the domain; invariants state properties over that domain; a checker evaluates them at a declared cadence. This is one executable-model pattern, not the definition of executability.
Figure 2.5-8.Modeling and enforcement are separate decisions. The measurement model defines the quantity and reference bound; Alignment determines whether the result is observed, used to adapt behavior, used to trigger graceful degradation, or enforced by a gate.
Figure 3.0-1.How intent becomes enforceable. Enforcement begins by placing a mechanism at a boundary where the obligation can be evaluated or constrained. Mechanisms enforce selected obligations; experience reveals additional opportunities for governance; accumulated controls eventually require governance of their own.
Figure 3.1-1.Intervention boundaries. Guidance shapes reasoning input; mechanisms can constrain actions or determine whether completed work, artifacts, or runtime states are accepted. Place the mechanism at the earliest boundary where the obligation is legible and enforceable.
Figure 3.2-1.Three distinct relations. Correspondence tests agreement between representations; conformance tests an artifact against an independent obligation; acceptance asks whether the receiving environment will take the result. Evidence for one relation does not establish the others.
Figure 3.2-2.Correspondence strength and governing role are independent. DocAble's execution machinery consumes an explicit computation model to determine remediation composition. A separate analytical graph view projects that structure and is held in correspondence with its upstream declarations. Stronger correspondence makes the view more trustworthy as a representation; it does not make the view govern execution.
Figure 3.2-3.The semantic gap. A property that spans several events cannot be decided from any event alone. Move the mechanism to the earliest boundary where the evidence required by the obligation is assembled.
Figure 3.3-1.Constraint or sensor. Prefer a constraint when the unwanted state can be excluded cheaply and reliably. Otherwise instrument the relevant state and produce evidence for later evaluation.
Figure 3.3-2.Match the mechanism to the property. An obligation may be held structurally by excluding the invalid state, evaluated by exploring reachable states, or checked as a temporal property over executions (for example with TLA+/TLC). These are alternatives selected by the engineering claim. A gate is a separate decision that enforces the resulting verdict.
Figure 3.3-3.One Measurement, Different Enforcement Decisions. The same measured quantity may be observed without enforcement, used to adapt behavior, trigger graceful degradation, or control admission. The appropriate response follows from the obligation attached to the measurement.
Figure 3.3-4.Negative and positive constraints. A negative constraint removes a forbidden action; a positive constraint requires a specified action or evidence-producing behavior. Both restrict the admissible implementation space.
Figure 3.3-5.Provenance-carried admission. A protected operation must derive through the sanctioned abstraction, which attaches provenance to the resulting operation. The receiving boundary requires that provenance before admitting the operation. The mechanism removes the degree of freedom to obtain the operation through some other implementation path, without requiring the environment to enumerate those alternative paths.
Figure 3.4-1.Governance conversion. When a failure exposes a recurring failure mode rooted in missing representation, obligation, evidence, evaluation, or enforcement, encode the missing structure at the appropriate layer. Future work inherits the result as engineering capital when that durable structure continues to lower future cost or uncertainty.
Figure 3.4-2.Correct judgment without enforcement. The system observed the dangerous condition and evaluated it correctly, but no enforcing mechanism acted on the verdict. The durable repair removed the unsafe capability rather than making the warning louder.
Figure 3.4-3.Where enforcement stops. A concern may remain unrepresented, require judgment, be evaluated without enforcement, or be governed. These are design choices; different obligations should stop at different points.
Figure 3.5-1.The conflict is the edge. Two controls may be individually valid yet impose incompatible demands on the same resource. The interaction belongs to the relation among the controls and shared resource, not necessarily to either control's implementation.
Figure 3.5-2.Three views of the control machinery. The catalogue identifies controls; the interaction view relates controls through shared resources; the coverage view relates controls to the obligations that justify them. Stable identities connect the three views while letting each answer a different engineering question. A missing mechanism appears as a coverage gap; an untraced mechanism appears as a candidate orphan.
Figure 4.1-1.Engineer–agent interaction through Modeling and Alignment. Engineers communicate intent and knowledge through natural language, specifications, and models; delegated realization returns evidence through review, testing, and analysis. The channels are complementary rather than sequential. Modeling makes selected engineering knowledge available to guide realization, while Alignment provides evidence for evaluating and revising it.
Figure 4.1-2.Active and passive alignment. Active alignment uses a model and its alignment mechanisms to transform a realization until the modeled obligations are satisfied. Once correspondence has been established, those models and mechanisms remain in the governed engineering environment as passive alignment: subsequent changes are evaluated against the established obligations so that correspondence is preserved.
Figure 4.1-3.Incrementally extending the alignment kernel. The kernel contains the modeled properties that must already be protected while active alignment changes the system. Additional models extend the governed surface, but each new alignment operates subject to the constraints established by the models already in the kernel. The layers are not different classes of model; they show models such as those introduced in Chapter 2 becoming governing constraints over time.
Figure 4.2-1.Two execution units for document remediation. (a) Whole-document execution keeps the artifact's working state and media resident in one long-running worker. (b) Page-chunked execution divides the document across workers, reducing the working state and memory required by any one worker.
Figure 4.2-2.Chunked residency versus skeletonized residency. (a) Page chunking limits how much document state and associated media a worker holds at once, but media remains part of the worker's resident representation. (b) Skeletonization keeps only document structure and media references resident. Individual media objects stream from external storage to the consumer on demand, so total media size no longer determines persistent worker memory.
Figure 4.2-3.Two execution policies over the same remediation graph. The graph contains actions—page analysis, construction of document context, and GenAI queries—and information dependencies among them. (a) Page-oriented execution groups actions according to where their artifacts occur, so a page partition can span several dependency levels. (b) Frontier execution groups actions according to when they are ready: page analyses execute first, their results enable construction of document context, and that context enables independent GenAI queries for alt text. The work and its dependencies are unchanged; only the execution boundary changes.
Figure 4.2-4.Analysis before implementation. (a) In a weighted dependency graph the heaviest chain is the critical path, which sets the latency floor and names an optimization target. (b) Decomposing the dominant node exposes parallel children and can shorten the path, a possibility visible in the model before the split is built. (c) A serial information dependency can be removed by changing the representation supplied to each operation: instead of sibling-to-sibling context propagation, each image consumes one shared precomputed page context, so the alt-text operations run independently.
Figure 4.2-5.The GenAI dependency chain and its latency floor. A section summary feeds a document summary feeds alt text; because each level waits for the one before it, their per-call times add to an irreducible floor of 7.6589 s. The vision value is measured; the text-summary value is estimated.
Figure 4.2-6.Using prediction error as evidence. (a) The gap between a model's prediction and the observed measurement is a residual, pointing to a wrong parameter, a wrong relation, or a missing mechanism; the numbers are illustrative. (b) Prediction and measurement create a feedback loop: explain the residual, refine the model, and test the revised model against subsequent observations.
Figure 4.2-7.Modeling as a loop. (a) Models produced after implementation: the linear design → implement → document-with-models sequence. (b) A problem drives a model; analysis yields a prediction and a design; those drive implementation and measurement; measurement refines the model, and the loop continues while the questions justify the cost.
Figure 4.3-1.Discovering models in a brownfield system. Weak signals — primitive density, repeated shapes, the component and boundary view — identify places worth inspecting; they do not dictate the remedy. Partitioning separates legitimate primitive-heavy code and mechanical debt from repeated shapes that reveal missing engineering concepts. Naming those concepts as typed vocabulary and explicit relations changes the substrate on which later recovery and enforcement operate.
Figure 4.3-2.Audit, Drain, Promote. A new lint lands audit-only — every finding reported, no commit blocked, so it never breaks an in-flight agent. A fix wave drains it to zero, and only then is it promoted to blocking, so future violations within the mechanism's declared detection surface are refused at that boundary.
Figure 4.4-1.Engineering recurring work. A governed engineering environment combines support for probabilistic reasoning with enforcement of selected obligations; the same models, knowledge, procedures, skills, tools, and evidence may contribute to both. The dashed arrow marks a recurring MAGE move: as judgment becomes better understood, some obligations may become sufficiently clear and evaluable to enforce. The return path observes outcomes and failures and improves the environment; where recurring judgment can be encoded economically, this is the governance conversion developed in §3.4.
Figure 4.4-2.Two evidence boundaries. Evaluate a property as soon as it can honestly be decided, but for consequential work, a later boundary may re-establish evidence whose freshness matters before admission or exposure. Early evaluation limits wasted work; final evaluation protects against stale evidence and intervening change.
Figure 5.1-1.Two problems of factory engineering. Process design determines how production proceeds around the fabricator. Tolerance identifies acceptable variation in what the factory produces; measurement establishes whether a realization remains within those bounds. The two concerns are complementary: a production system may carry engineering knowledge in the organization of production, in explicit bounds on the resulting product, or in both.
Figure 5.2-1.The Seven Build Stages. Retrospective sequence from the March feasibility probe to the July–September period of deployment, iteration, and optimization, giving the dates, the pressure, and the major engineering consequence at each stage. The serverless re-platforming is one episode inside that final period rather than a stage of its own.
Figure 5.2-2.Realization Over Time. Weekly commits landing on main across the project's 29 weeks, split by reconstructed authorship provenance, with dotted build-stage boundaries. The late-era shift from agent-attributed commits to merge-train squashes records a change in landing mechanism, not a slowdown: one squash stands for many underlying agent commits, so the total series is the cross-regime-comparable trace.
Figure 5.2-3.Work Over Time. Epics — DocAble's unit of formalized engineering intent — created and closed per week from the convention's introduction in week 12. A record of intent formalized, not of a backlog drained: creation outpaces closure by roughly three to one. The first week's 111 openings are a formalization event, not a burst of ideation; the trace is invariant to the late-era landing-mechanism change.
Figure 5.2-4.The Controls Accumulate. Project-specific lint files (definition validated against this chapter's snapshot counts), gate/check scripts (independent definition), and system-model files at each week's last commit. The four-snapshot growth curve of the earlier draft, resolved into a 29-week series: flat through week 8, a sharp takeoff at weeks 9–11, then cumulative growth decoupled from weekly realization volume.
Figure 5.2-5.Factory Capital and the Support Ratio, Weekly. Source-tree lines of code by category (left) and the support-to-production ratio (right) at each week's last commit — an independent re-derivation with its own category boundaries, with the two recoverable earlier snapshot ratios overlaid as diamonds. The trajectory matters more than any single value: below parity in the prototype weeks, parity crossed around weeks 5–6, a plateau near three-to-one in the mature era.
Figure 5.2-6.The Model Census. The 130 declared system models at the examined revision, by declared form (left) and by target (right). The factory represents both the product it produces (78) and the system that produces it (51, plus one model of the execution environment). A snapshot of a live census: regenerate at press time rather than treating 130 as frozen.
Figure 5.2-7.The modeling history. DocAble acquired a stable decomposition of remediation computations before it acquired an explicit model of their composition. As locally reasonable choices accumulated consequential global cost, modeling exposed dependency semantics and effect boundedness. Typed declarations made those relationships analyzable and checkable; later redesign made explicit composition authoritative for execution, while separate analytical views continued to grow around stable computation identities. The progression is from a partial model to a richer and increasingly consequential one, not from no model to model.
Figure 5.2-8.The Admission Funnel, One Mature Week. Merge-train runs in the mature era's highest-throughput full week: 592 started, 573 landed on main through the full integration gate, 10 aborted, 192 work spaces retired. Parallel realization fanned out; admission stayed serialized through regenerated evidence. The registry logs only this stage — upstream repair iterations are not retained as events.
Figure 5.2-9.What Experience Became. The twelve governance-conversion episodes by the durable structure each failure became, coloured by enforcement class. Eight land deterministic and blocking; two stay probabilistic or advisory; two stop at measurement, one deliberately without a gate. Three ex-ante confirmations are excluded, keeping the conversion-versus-confirmation distinction; the exhibit restates the chapter's own narrative in structured form rather than censusing the repository independently.
Figure 5.2-10.Modeled and Observed, Not Yet Binding. A timeout incident produced a measurement, a provisional per-chunk model, and reportable evidence. Production admission still does not depend on the model: its bound is not calibrated strongly enough to justify blocking. The terminal enforcement node is left open on purpose — representation and observation can mature before enforcement is earned. The open node is part of the evidence, not an omission.
Figure 5.2-11.The Delegation Staircase. As explicit representation and environmental enforcement accumulated, larger units of engineering work could be delegated. Representation moved system knowledge out of one person's head; enforcement moved repeatable admission decisions out of direct review. Human work moved from reading every diff toward system-level strategy and the residual semantic judgment the environment could not yet decide. A failure in either representation or enforcement could move work back down the staircase.
Figure 5.2-12.Weekly Commit Provenance as a Delegation Proxy. The explicit human-or-unknown residual is about 5.5% of the window's 32,039 main commits — an upper bound on human-authored realization, since early agent commits predating the attribution convention land in the residual. Commit share is a different quantity from how much the engineer read.
Figure 5.3-1.Seven Entry Points. MAGE provides the comparison vocabulary; no source is claimed to implement the complete method. The organizations begin with different problems and invest in different parts of the agentic engineered environment. Note how the figure locates emphasis rather than ranking maturity.
Figure 6.1-1.The MAGE Dynamic Model. Agentic capacity acts through a governed engineering environment to produce realized performance. Mismatch appears as churn, escaped defects, and repeated intervention; diagnosis and adaptation reshape the environment; a stronger environment then supports more ambitious work and exposes a new frontier. Prior engineering knowledge supplies known structure before failure occurs. The model is directional, not fitted. The model is stated for engineering work because that is the setting studied here; §6.3 examines the corresponding structure for agentic engineering beyond software.
Figure 6.1-2.Probability in the software factory. Correct realization depends on correctly encoding consequential intent, correctly interpreting that encoding, and correctly realizing the interpreted intent. One representation R is held fixed throughout the figure, so each probability term is drawn in its short form; the text conditions each of them on R. Process design changes the conditions under which interpretation and realization occur. When a consequential property is represented as an independently evaluable tolerance, evidence and admission can govern that property without relying solely on the producing reasoner.
Figure 6.1-3.The Determinization Frontier. The frontier separates judgment that must be supplied per instance from judgment the environment can carry repeatably. Alignment can directly bind a property already decidable over an action or artifact. Modeling can change the reasoning surface so that a property requiring semantic reconstruction becomes a repeatable predicate that Alignment can bind. Modeling may also reduce realization cost even where Alignment was already possible.
Figure 6.3-1.The economics of explicit engineering. The value of making an obligation explicit determines how much investment it warrants; feasible governability determines how much of that investment can become enforcement. High-value obligations can justify substantial engineering even when they remain judgmental, while highly governable obligations need not be mechanized when little value would result.
Figure 7.1-1.Where Engineering Effort Moves. As the fleet assumes work across the lifecycle, the engineer increasingly works through the surrounding engineering environment: specifying intent, choosing consequential abstractions, evaluating evidence, resolving tradeoffs, and adapting the environment itself.
Figure 7.2-1.Why software modeled differently. Software was never model-free. Compilation and reproduction were cheap, but producing and revising the detailed implementation required skilled labor, and code itself served as an executable engineering representation. Additional models therefore carried a standing correspondence cost. Commodity intelligence lowers both realization labor and parts of the cost of maintaining secondary representations, expanding the surfaces on which live models can repay their upkeep.
Figure 7.2-2.Established traditions, new composition. MAGE draws on two long-running traditions. Engineering disciplines developed explicit models, constrained representations, verification, and external control; AI repeatedly extended reasoners through knowledge representation, planning state, memory, structured reasoning, tools, and surrounding machinery. MAGE brings these inheritances together around autonomous software work: Modeling makes engineering knowledge explicit, Alignment enforces selected obligations independently, and both meet in the Governed Engineering Environment. Governance conversion carries recurring judgment into durable engineering capital. Commodity intelligence changes the economics of this composition, not the provenance of its parts.
Figure 7.3-1.Governing consequential work. Agentic engineering does not require the work to produce an autonomous system. In conventional engineering, the immediate outcome is often an artifact or system that can be inspected, tested, operated, and observed. In knowledge work, the outcome may instead be a decision or action whose consequences become observable through subsequent events. In either case, people delegate work through a governed environment, remain responsible for the consequential outcome, and use evidence from that outcome to inform subsequent work.
Diagrams from the pattern-catalogue appendix, drawn in a lighter reference style.
Figure A-1. Seven reference engineering stacks and their common relationships. Arrows show relationships among capabilities that recurred in one system, not a required architecture or adoption order. Resource Mediation and Context Delivery are shown separately because they provide useful capabilities independently.
Figure A.1-1. The model-coherence composition. An authored MODEL feeds two paths: consumers CONSUME it live rather than copying its facts, and where the model owns the fact it can EMIT downstream artifacts. Consumption flows into a CORRESPONDENCE check — model against world — which DERIVEs its verdict from stable identities where an independent join exists; on disagreement a GATE enforces the modeled property. Solid path: the required composition. Dashed attachment: a useful enhancement, not required for the capability.
Figure A.2-1. The assurance composition. A SPEC states the obligation; a CENSUS establishes the population it applies to; discharge fans out to the evidence each obligation deserves — TEST for examples, LINT for structure, PROVE for semantics — and all three lanes converge on COVERAGE, which joins each obligation back to its evidence so omissions show. Solid path: the required spine.
Figure A.3-1. The auditable-transformation composition. A sanctioned mutation flows through MARK (attach actor and action) to EMIT (persist a structured record); COVER detects any mutation that escaped attribution; READ reconstructs the transformation history from the records; a FIDELITY GATE checks that the transformed artifact kept its required semantics. Solid path: the core path, every step required.
Figure A.4-1. The observe → react composition. An operating model drives WATCH, which reads runtime state; WATCH flows to RESPOND, which recovers. That solid path is required. Two dashed attachments strengthen it where the failure class demands: BEAT adds a liveness heartbeat so a hung process reads differently from a slow one, and BLOCK adds the power to prevent unsafe progress. Solid path: the core path; dashed: enhancement. Dashed attachment: a useful enhancement, not required for the capability.
Figure A.5-1. The resource-mediation composition. A RESOURCE POLICY states which resource is scarce and what capacity is acceptable; a MEDIATOR admits at most N actors through one admission point to the SHARED RESOURCE. A dashed LIVE PRESSURE loop tightens or relaxes effective capacity when justified. N=1 and N>1 are settings of the same mediator, not separate stacks. Solid path: the required path. Dashed attachment: a useful enhancement, not required for the capability.
Figure A.6-1. The governance-conversion composition, a loop. The CONTROL MACHINERY — rules, gates, models, sensors — is inspected and queried to expose GAPS / COUPLING: where control is weak, stale, or entangled. When a failure recurs there, INTERPRET converts the failure class into a durable control, and UPDATE MACHINERY folds it in; a solid feedback edge returns to the machinery for the next iteration. The four moves form the core loop.
Figure A.7-1. The context-delivery composition. Engineering knowledge — models, rules, decisions — splits into a STANDING POLICY that is always seen and a TASK SLICE retrieved as needed; both feed the actor's context, which drives the action. A dashed POINT-OF-ACTION attachment reasserts important obligations at the moment of action, and for critical decidable obligations becomes a deterministic gate rather than a reminder. Solid path: the essential composition. Dashed attachment: a useful enhancement, not required for the capability.
Figure A.8-1. Composing an engineering stack. Begin with a capability and its failure classes. Identify the guarantees required to close those failures, select mechanisms that provide them, determine their dependencies, and retain the smallest required composition that makes the capability claim valid.
Figure B-1.Ten recurring engineering problems and the moves that address them. The moves apply the method developed in Chapters 2–4: model knowledge people repeatedly reconstruct, enforce decidable obligations, and make recurring judgment durable when doing so is worth the cost.
Figure B.1-1.One authoritative representation. BEFORE — copies A, B, C each feed a consumer and can drift apart, so disagreement is possible. AFTER — one authoritative representation, with A, B, C derived or queried from it, so disagreement becomes detectable or impossible.
Figure B.2-1.Query, don't snapshot. BAD — the model is copied into a snapshot that a check reads; the model changes, the snapshot does not. GOOD — the check queries the model directly, so the next check sees the change.
Figure B.3-1.Correspondence runs both ways. A two-way loop joins MODEL and REALITY. One arrow asks whether reality still satisfies the model, catching a wrong modeled fact; the other asks whether something important appeared outside the model, catching unmodeled reality.
Figure B.4-1.Required set minus present evidence. The model derives what must be assured; that required set is compared against existing evidence; the intersection is covered, and the remainder is a gap that raises a finding.
Figure B.5-1.Earliest legible, last safe. A timeline runs from where work begins to consequence. Too-early sits where the property is still invisible; the earliest-legible boundary carries the first check; the last-safe boundary carries a re-check just before the point of no return.
Figure B.6-1.Open surface versus closed seam. OPEN — an actor reaches a raw surface by many routes, including unknown ones. CLOSED — the actor passes through one seam that exposes a small set of named verbs, each able to stamp, validate, constrain, and observe. The distinction is encoded by shape, line style, and weight rather than color.
Figure B.7-1.Knowledge delivery at the decision point. Context selection joins the current work with the rules relevant to its scope and supplies that subset to the decision. The distinction is encoded by shape and line style rather than color.
Figure B.8-1.Cause travels with consequence. A cause mints an identity; the identity rides action to change to artifact; from the final artifact the identity lets a reader reconstruct why, not just what.
Figure B.9-1.From system model to operational guidance. Healthy-state predicates, states, and relations feed an operational model that produces generated procedure where possible and reasoning guidance where judgment remains necessary.
Figure B.10-1.Impact as a graph query. A proposed change reaches a substrate node; typed dependency edges identify the controls and models that depend on it, and their union defines the affected set.
Figure C-1.The executable-model pattern. An engineering question selects a representation containing authored, derived, or observed facts. Correspondence machinery compares represented facts with implementation or runtime evidence. Disagreement may remain advisory or, where the obligation is enforced, feed a deterministic gate.
Figure C.1-1.Structure and boundaries. Authored ownership and permitted seams are reconciled with the observed repository tree. Sanctioned crossings pass through declared doors; forbidden direct access raises a finding.
Figure C.2-1.Behavior plus ownership. The lifecycle FREE → LEASED → DONE is combined with a lease that records the current owner and expiry. The ownership invariant requires exactly one valid owner while LEASED and no active owner while FREE.
Figure C.4-1.Measurement does not imply enforcement. A sensor produces an observed measurement, which is compared with a declared bound. The result remains report-only unless the evidence warrants a warning or an admission gate.
Figure C.5-1.Facts before prose. A structured provenance record supports mechanical validation and re-derivable documentation; independently maintained prose lacks that correspondence.
Figure C.6-1.Composition by reference. Stable identities join the user-journey, service, coverage, test-placement, and execution-policy views. The resulting joined view supports cross-model queries without duplicating those facts into a single stored model.
Figure D.9-1.Brownfield progress. Representation reach and enforcement reach are independent axes. A system may be strong on either dimension without being strong on the other; the next investment should address the highest-value gap rather than maximize both indiscriminately.
Figure E.2-1.Three complementary skills act around one governed engineering environment. Self-Governance improves the environment; Self-Operate runs operational lifecycles within it and returns evidence about deficiencies; Self-Communicate articulates the system to others and contributes canonical documentation to the environment.
Figure F.1-1.MAGE across the product lifecycle. Different lifecycle surfaces ask different engineering questions and therefore benefit from different representations. The horizontal flow is not a waterfall: experience and evidence feed earlier activities, while Assurance & Compliance spans the lifecycle. Each surface can adopt MAGE independently.
Figure F.4-1.Change-scoped models, degrees of freedom, and inheritance. A ticket or issue provides an entry point into a change episode. Bidirectional traceability helps locate the responsible implementation and the models and obligations that govern it. Those inherited obligations bound the realization space while leaving some choices open. Acceptance evidence establishes whether the realized change satisfies its obligations; recurring or consequential lessons can then be converted into durable structure that future work inherits.
Figure F.5-1.From incident repair to governance conversion. An incident provides evidence about the realized system. Traceability connects the failure to the models and obligations it realizes; relationships within those models can expose other instances of the same engineering condition even when their implementations differ. Repair can then address the class rather than only the observed instance, while governance conversion preserves the lesson in models or mechanisms that future work inherits.
Figure F.6-1.Assurance across models and realization. Claims may depend on modeled properties, realized properties, or correspondence between the two. Traceability and Alignment connect the required evidence.
Figure F.8-1.From local MAGE adoption to the product GEE. Each lifecycle surface develops representations suited to its own reasoning problems. Shared identity, relations, provenance, temporal scope, and obligations allow those heterogeneous models to compose without collapsing them into one universal model. Agents reason across the resulting knowledge where semantic or situational judgment remains necessary; Alignment carries the obligations that can responsibly be enforced. Experience from the realized product feeds governance conversion, changing the models and mechanisms future work inherits.
Figure F.9-1.Engineering capital across time and space. A conceptual snapshot of three products shaped by successive engineering episodes. Within each product, useful engineering structure has accumulated selectively; the incomplete constellations represent neither a prescribed product model nor a maturity level. Across products, an assurance obligation connects all three, code-quality mechanisms are shared by two, and connections to a common security posture remain possible. Solid relationships are established; dotted relationships are emerging or possible.
Figure G.1-1.From assistance to bounded delegation. Under assistance, the worker supplies context, judgment, and acceptance directly around the agent. As work is delegated, selected responsibilities move into the environment — models carry context, evidence establishes properties, and mechanisms constrain and admit the result — and the boundary of what the agent may do on its own expands. The change is a shifting boundary, not a sequence of maturity levels.
Figure G.2-1.From recurring cost to engineering capital. Context and guidance can cheaply reduce reconstruction and improve probabilistic judgment. Where residual churn or consequence warrants further investment, organizations can strengthen representation, evidence, evaluation, or enforcement so that later work inherits more of what earlier work established. The paths are investment choices, not maturity levels.
Figure G.2-2.Four figures this appendix puts to work. Each was developed earlier in the book and is reused here at organizational scale, not reintroduced: the value of explicit engineering against feasible governability (§5.3), the governance-conversion loop (§3.4), the support-apparatus ratio, and the redistribution of engineering effort (both in Chapter 5). The appendix refers back to these rather than re-deriving them.
Figure H-2.Spotify projected onto MAGE. Persistent estate representation feeds targeting, concurrent execution, and fleet-level supervision; the reading is judgment moving upstream, not the PR count.
Figure H-3.Shopify projected onto MAGE. The source supports shared externalized knowledge and reusable context; conversion into durable capital is the interpretive step, not an automatic one.
Figure H-4.Siemens projected onto MAGE. Strong evidence for rich Modeling; evidence for analysis and verification; no claim from source silence about generalized model↔code admission.
Figure H-5.Zenseact projected onto MAGE. Shared mechanisms centralize while domain knowledge and judgment remain distributed — a concrete organizational answer to scaling both context and enforcement.
Figure H-6.Uber projected onto MAGE. Public evidence strongly supports engineering the environment around a replaceable reasoner; the executable-model tier stays out of reach.
Figure I-1.Weekly Commit Volume. Commits per week across the project history. Bar height measures repository activity, not engineering productivity; interpreting the hardening interval requires classifying the work represented by those commits.
Figure I-2.Product-Path Line Motion. Lines added above the baseline and deleted below it, by path and study window. Mechanization contains the largest observed line motion. The later reduction in deletions is consistent with less structural rewriting but does not establish its cause.
Figure J.2-1.Model induction. The same move runs in three settings: realized work yields repeated low-level forms, weak detection surfaces candidate regularities, and engineering judgment names the concept that survives comparison. The left rail states the move; the three columns instantiate it in software, knowledge work, and CAD. Software is the grounded case; the extension to knowledge work and CAD is a generalization, not evidence DocAble supplied.