CARL v1.0 keeps eight published pillars. v1.1 adds deltas to all eight and drafts six more. Pillars are not weighted against each other; a subject must make progress across the catalog to advance.
Deltas to published pillars
These pages extend v1.0 BLD/CQV/TST/TIR/SEC/DLM/DOC/OBS with 1xx criterion
IDs. Several checks use scope: portfolio so a multi-application subject is
scored as one product, not as a pile of unrelated apps.
| Pillar | Prefix | Registry code | What it measures |
|---|---|---|---|
| Build & Environment | BLD- | bld | Portfolio toolchain, secret-free proof, slice deploys. |
| Code Quality & Validation | CQV- | cqv | Shared quality config, import graph, forbidden patterns. |
| Testing | TST- | tst | Honest coverage, package contracts, fake/staging split. |
| Task Intake & Routing | TIR- | tir | Application-scoped intake, shared labels, owner routing. |
| Security & Access Control | SEC- | sec | Path-attributed secrets, per-slice audit, deploy identity. |
| Delivery & Measurement | DLM- | dlm | Affected-slice CI, isolated previews, portfolio DORA. |
| Documentation & Knowledge | DOC- | doc | Nested agent context, portfolio map, classified env. |
| Observability | OBS- | obs | Shared telemetry schema, trace propagation, per-slice SLO. |
Build & EnvironmentBLD-1xx · Toolchain matrix, secret-free proof, per-slice deploys.Code Quality & ValidationCQV-1xx · Shared config, dead-code gates, forbidden-pattern ratchet.TestingTST-1xx · Coverage include, contract tests, hybrid fake/staging.Task Intake & RoutingTIR-1xx · Slice-named intake, shared labels, owner routing.Security & Access ControlSEC-1xx · Attributed secrets, per-slice audit, short-lived identity.Delivery & MeasurementDLM-1xx · Affected-slice CI, isolated previews, portfolio DORA.Documentation & KnowledgeDOC-1xx · Nested agent context, portfolio map, classified env.ObservabilityOBS-1xx · Shared schema, trace propagation, per-slice error budget.
New pillars with draft criteria
| Pillar | Prefix | Registry code | What it measures |
|---|---|---|---|
| Cost & FinOps | COST- | cost | Token, infrastructure, and operating-cost visibility. |
| Agent Governance | AGV- | agv | Autonomy bounds, approval gates, and policy-as-code. |
| Composition | COM- | com | Module boundaries and published composition contracts. |
| Data | DAT- | dat | Data contracts, classification, retention, and access. |
| Design | DSN- | dsn | Design tokens, accessibility, and UI primitives. |
| Resilience | RES- | res | Failure handling, backup, restore, and degradation. |
Why com instead of cmp
The v1.1 ticket lists this pillar as CMP. The app already uses cmp for the
v1.0 Compliance scorecard pillar. v1.1 Composition therefore uses registry
code com and criterion prefix COM-. Compliance cmp is unchanged.
The six draft pillars
Cost & FinOpsCOST-1xx · Queryable budgets, attributed usage, stop on exhaust.Agent GovernanceAGV-1xx · Autonomy bounds, approval gates, policy-as-code.CompositionCOM-1xx · Module boundaries and reusable contracts.DataDAT-1xx · Contracts, classification, retention, and access.DesignDSN-1xx · Tokens, accessibility, and UI primitives.ResilienceRES-1xx · Backups, restore drills, and degradation paths.
Related
- v1.1 overview — draft status and catalog table.
- v1.0 pillars — the eight published pillars.