Product Safe Delivery & Scaling · Version 0.1
Tools now produce faster than anyone can be accountable for.
That is the change — not that code appears, but the speed at which it appears. This rulebook describes the apparatus against it: who decides, in which body, with which record, and where an agent may write without tearing the evidence chain.
Product Safe Delivery & Scaling is the framework under which I lead an embedded organisation: deliver safely, and be able to grow while doing it. It aims at what engineering work from Germany stands for in this field — safety and reliability across a product's lifetime, not a release's. A claim on the work, not a seal on a service.
Open the deployment ordinanceThe apparatus
Five parts, and none carries alone
Pick a part. Its rule opens below.
Every decision leaves it as a record, or it does not hold.
Not a status meeting and not an architecture circle. The place where platform-wide commitments are made that individual teams may not make alone, because their consequences bind other teams.
What it decides
- Platform boundaries: what belongs to the platform, what to the product.
- Make-or-buy per building block — never for the whole.
- Commitments to tool chains, suppliers and licensing models.
- The classification of agent zones per work step.
- Adding and retiring variants.
What it explicitly does not decide
- Delivery dates and scope — that is product, not architecture.
- Personnel matters — that is leadership, and it does not belong in a committee.
- Implementation detail — that belongs to the team accountable for it.
A council that negotiates dates stops deciding architecture — it becomes the body where the loudest pressure wins.
Composition
| Seat | Brings | Vote |
|---|---|---|
| Platform leadership | Chair, agenda, casting vote | yes |
| Systems architecture | Technical coherence across teams | yes |
| Functional safety | Evidence chain, normative frame | attendance required |
| Tool chain / integration | What the chain really carries, not what it promises | yes |
| Procurement | Licensing models, lock-in duration, exit cost | yes |
| One representative per domain | The consequences for their own domain | yes |
| Affected team, as needed | The specific case | is heard |
Without functional safety, no resolution on a building block that enters the safety case. This one rule prevents the most common committee failure: the decision is made, the safety side hears about it later and carries the consequences.
The limits
The most expensive surprise in this field is not a technical one
Licence
AUTOSAR material is available to download but explicitly “for the purpose of INFORMATION ONLY”; commercial exploitation “requires a license”. “Building open” does not automatically mean licence-free — and that question belongs at gate 1, not gate 5.
Standards
MISRA and ISO 26262 are the requirement frame here, not a claimed qualification. The rulebook says where their requirements must be met and who releases — it replaces neither standards advice nor an assessment.
Not a skill catalogue
Ready-made work steps for agents already exist publicly — 152 skills in builder/reviewer pairs from hazard analysis to safety case. That is precisely the point: skills say HOW a step is carried out. A rulebook says WHETHER it may be carried out, by whom, and what must be true afterwards.
The team
A rulebook that only restrains is a brake
Clarity about where they may decide
The most common cause of standstill is not incapacity but uncertainty about whether one is allowed.
A check that belongs to them
If the chain carries the verification, producing is low-risk and experimenting is permitted. Without it, every proposal becomes personal liability.
Protection from the backlog
Introduce agents without scaling review capacity and you shift the load onto the most experienced people. They are the ones who then leave.
Permission to reopen a decision
Without a review date every record becomes a headstone and dissent becomes disloyalty.
What this rulebook is not
It qualifies nothing, certifies nothing and replaces no assessment by functional safety. The derivation is modelled on the tool classification logic of functional safety — a borrowing of a line of reasoning, not a conformance claim.
The strongest objection, and it stands here deliberately
“The zone assignment is a judgement dressed as a calculation.” Whether an error can reach the product unnoticed is an estimate. That is true. It does not kill the rulebook, for two reasons: the load-bearing question is verifiable — the check runs in the chain or it does not, and it alone caps the zone. And recording the judgement is the point. Today the same estimate is made three times a week, implicitly and inconsistently.
Version 0.1, as of 2026-09-01. Written to be adopted and cut down.