{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "id": "6fc97ff2-68bb-400a-a79a-fac5daeb1bd8",
      "key": "BIAC",
      "title": "Reviewable infrastructure plan pipeline",
      "field": "Cloud infrastructure",
      "summary": "Validate infrastructure changes as bounded plans with drift and recovery context.",
      "context": "A fictional application team manages a small database, cache, and object store. Reviewers struggle to distinguish harmless configuration changes from destructive replacements.",
      "stack": [
        "TypeScript",
        "Terraform plan JSON",
        "Policy fixtures"
      ],
      "prerequisites": [
        "Author synthetic infrastructure plans and state snapshots; use local files only and no cloud credentials."
      ],
      "developerValue": "Practice infrastructure risk analysis, plan integrity, and least-privilege change workflows.",
      "companyValue": "Give infrastructure reviewers concrete change scope and recovery consequences.",
      "delivery": "Deliver an offline plan-review tool and synthetic workflow; provision nothing externally.",
      "phases": [
        {
          "id": "parse",
          "title": "Parse plan authority",
          "goal": "Normalize resource actions and unknown values."
        },
        {
          "id": "review",
          "title": "Review risk",
          "goal": "Surface destructive changes and policy failures."
        },
        {
          "id": "apply",
          "title": "Bind execution intent",
          "goal": "Verify freshness, ownership, and recovery information."
        }
      ],
      "tickets": [
        {
          "id": "f9be7500-9325-4b6e-82c8-9697acd44d67",
          "key": "BIAC-101",
          "title": "Normalize infrastructure resource actions for review",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "parse",
          "dependsOn": [],
          "scenario": "Review summaries collapse updates and replacements into one change count.",
          "acceptanceCriteria": [
            "Separate create, update, replace, and delete actions.",
            "Preserve resource addresses and dependencies.",
            "Represent unknown values explicitly."
          ],
          "implementationNotes": [
            "Treat plan JSON as untrusted data."
          ],
          "verification": [
            "Parse a valid mixed-action plan.",
            "Reject malformed action combinations."
          ],
          "deliverables": [
            "Plan action model."
          ],
          "rollout": "Adopt read-only summaries before any execution integration.",
          "skills": [
            "Infrastructure analysis"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 70
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "779ee956-1f16-4366-bca3-08797bff0f55",
          "key": "BIAC-102",
          "title": "Redact sensitive plan values while preserving review context",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "parse",
          "dependsOn": [
            "BIAC-101"
          ],
          "scenario": "A database password appears in a generated review report.",
          "acceptanceCriteria": [
            "Honor sensitive markers recursively.",
            "Remove seeded secret values from report and errors.",
            "Keep resource identity and action visible."
          ],
          "implementationNotes": [
            "Unknown nested formats must fail safely."
          ],
          "verification": [
            "Review a non-sensitive change.",
            "Seed secrets in nested arrays and verify redaction."
          ],
          "deliverables": [
            "Plan redaction boundary."
          ],
          "rollout": "Block report publication if redaction validation fails.",
          "skills": [
            "Data protection"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "94bd55f6-2cef-4ff7-b1a9-6f8730e71143",
          "key": "BIAC-103",
          "title": "Flag replacements of persistent resources with recovery requirements",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "review",
          "dependsOn": [
            "BIAC-101",
            "BIAC-102"
          ],
          "scenario": "A small naming change replaces the database resource.",
          "acceptanceCriteria": [
            "Identify persistent resource replacements.",
            "Require declared backup and restore context.",
            "Show dependent application impact."
          ],
          "implementationNotes": [
            "Do not infer that a snapshot policy proves restorability."
          ],
          "verification": [
            "Flag a synthetic database replacement.",
            "Allow a stateless replacement with its distinct risk classification."
          ],
          "deliverables": [
            "Replacement risk rule."
          ],
          "rollout": "Require review before any persistent-resource execution path.",
          "skills": [
            "Change risk"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 50
            },
            {
              "field": "Site reliability",
              "percentage": 50
            }
          ],
          "patterns": []
        },
        {
          "id": "b80bdc5a-27a9-4668-81af-fd820d07cd8b",
          "key": "BIAC-104",
          "title": "Reject public exposure introduced by default configuration",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "review",
          "dependsOn": [
            "BIAC-102"
          ],
          "scenario": "An omitted access setting turns a private storage resource public.",
          "acceptanceCriteria": [
            "Evaluate effective exposure including defaults.",
            "Identify the exact field causing exposure.",
            "Keep unknown defaults unresolved."
          ],
          "implementationNotes": [
            "Use explicit provider-schema fixtures rather than live provider assumptions."
          ],
          "verification": [
            "Detect a public-access transition.",
            "Keep unknown provider behavior blocked for review."
          ],
          "deliverables": [
            "Exposure policy check."
          ],
          "rollout": "Start with the modeled resource types; reject unsupported exposure analysis.",
          "skills": [
            "Cloud security"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 70
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "0d746fc5-48d7-433a-94cc-561872e7ea3b",
          "key": "BIAC-105",
          "title": "Validate backup retention changes against declared recovery policy",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "review",
          "dependsOn": [
            "BIAC-103"
          ],
          "scenario": "A retention reduction removes the recovery window the application team relies on.",
          "acceptanceCriteria": [
            "Compare proposed retention with the scenario requirement.",
            "Account for deletion of old backup generations.",
            "Require an explanation for incompatible changes."
          ],
          "implementationNotes": [
            "Policy requirements are explicit inputs."
          ],
          "verification": [
            "Accept a compatible retention update.",
            "Flag a shorter recovery window and missing policy."
          ],
          "deliverables": [
            "Retention plan rule."
          ],
          "rollout": "Review changes alongside the restore rehearsal record.",
          "skills": [
            "Recovery policy"
          ],
          "fieldMix": [
            {
              "field": "Site reliability",
              "percentage": 60
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "238c088a-de04-4857-b972-0742a0e88733",
          "key": "BIAC-106",
          "title": "Detect plan drift between review and execution",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 180,
          "phaseId": "apply",
          "dependsOn": [
            "BIAC-104",
            "BIAC-105"
          ],
          "scenario": "A plan is reviewed, then regenerated with additional deletions before execution.",
          "acceptanceCriteria": [
            "Bind approval intent to plan digest and target identity.",
            "Check state serial and configuration revision.",
            "Reject modified or stale plans."
          ],
          "implementationNotes": [
            "No actual cloud apply is performed in this exercise."
          ],
          "verification": [
            "Accept an unchanged synthetic reviewed plan.",
            "Change one action and reject the execution intent."
          ],
          "deliverables": [
            "Plan binding verifier."
          ],
          "rollout": "Require regeneration and review on drift; preserve prior plan artifacts.",
          "skills": [
            "Integrity",
            "Change control"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 50
            },
            {
              "field": "Security",
              "percentage": 30
            },
            {
              "field": "Developer tooling",
              "percentage": 20
            }
          ],
          "patterns": []
        },
        {
          "id": "7eea29b1-f2ae-419b-910e-5a21db689301",
          "key": "BIAC-107",
          "title": "Keep infrastructure workspace identities from crossing environments",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "apply",
          "dependsOn": [
            "BIAC-106"
          ],
          "scenario": "A staging plan is accidentally paired with production target metadata.",
          "acceptanceCriteria": [
            "Bind workspace, account class, and resource namespace.",
            "Reject mixed-environment inputs.",
            "Show sanitized target context in the review summary."
          ],
          "implementationNotes": [
            "Use fictional account identities and no credentials."
          ],
          "verification": [
            "Verify a matching staging plan.",
            "Reject a production identity substituted after review."
          ],
          "deliverables": [
            "Environment binding guard."
          ],
          "rollout": "Fail closed on ambiguous identity.",
          "skills": [
            "Configuration",
            "Authorization"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 60
            },
            {
              "field": "Security",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "e6c0a5bb-8028-47ba-8083-65d44e360210",
          "key": "BIAC-108",
          "title": "Model partial apply recovery without assuming atomic infrastructure changes",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 300,
          "phaseId": "apply",
          "dependsOn": [
            "BIAC-103",
            "BIAC-106",
            "BIAC-107"
          ],
          "scenario": "A plan contains several resource updates, and the third may fail after earlier changes succeed.",
          "acceptanceCriteria": [
            "Identify dependency-ordered partial states.",
            "Compare forward repair and rollback per resource.",
            "Preserve completed changes in the recovery record."
          ],
          "implementationNotes": [
            "Do not present infrastructure apply as one database transaction."
          ],
          "verification": [
            "Simulate failure after two accepted changes.",
            "Reject a rollback that would delete newly authoritative data."
          ],
          "deliverables": [
            "Partial-apply recovery decision record."
          ],
          "rollout": "Keep execution hypothetical until target-specific recovery is verified.",
          "skills": [
            "Infrastructure design",
            "Recovery"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 40
            },
            {
              "field": "System design",
              "percentage": 30
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "a941bf32-2501-4121-8322-10d60662a653",
          "key": "BIAC-109",
          "title": "Generate an infrastructure change summary for application owners",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 120,
          "phaseId": "apply",
          "dependsOn": [
            "BIAC-108"
          ],
          "scenario": "Application owners cannot determine whether a plan changes endpoints or causes downtime.",
          "acceptanceCriteria": [
            "Summarize connectivity, storage, and availability impacts.",
            "Link impacts to exact resource actions.",
            "List unresolved values and required follow-up."
          ],
          "implementationNotes": [
            "Do not hide unresolved risks behind an overall green status."
          ],
          "verification": [
            "Explain a cache replacement and endpoint change.",
            "Show unknown replacement timing explicitly."
          ],
          "deliverables": [
            "Owner review report."
          ],
          "rollout": "Attach reports to the exact plan digest.",
          "skills": [
            "Technical communication"
          ],
          "fieldMix": [
            {
              "field": "Cloud infrastructure",
              "percentage": 70
            },
            {
              "field": "Developer tooling",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "2cd68dc6-d2a7-413c-abae-fedfc6319856",
          "key": "BIAC-110",
          "title": "Document how to retire a policy exception",
          "type": "CHORE",
          "priority": "LOW",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 60,
          "phaseId": "apply",
          "dependsOn": [
            "BIAC-109"
          ],
          "scenario": "A temporary public-access exception remains active after the migration finishes.",
          "acceptanceCriteria": [
            "Require owner, scope, reason, and expiry.",
            "Reject expired or wildcard exceptions.",
            "Preserve exception history after retirement."
          ],
          "implementationNotes": [
            "Exceptions cannot bypass plan identity checks."
          ],
          "verification": [
            "Retire a scoped synthetic exception.",
            "Verify an expired exception blocks the next plan."
          ],
          "deliverables": [
            "Exception lifecycle guide."
          ],
          "rollout": "Inventory exceptions before enabling enforcement.",
          "skills": [
            "Policy governance"
          ],
          "fieldMix": [
            {
              "field": "Security",
              "percentage": 60
            },
            {
              "field": "Cloud infrastructure",
              "percentage": 40
            }
          ],
          "patterns": []
        }
      ]
    }
  ]
}
