Draft skeleton — fill each section, then remove this note. Owner: architect.
Purpose & audience
Enterprise architects, security reviewers, and prospective design partners evaluating how AORBIT fits an existing estate.The five-capability spine
For each capability: responsibility, interfaces, and what reads/writes it.- Truth — the runtime CMDB/CSDM graph; the system-of-record every other capability reads from.
- Governance — policy envelopes, spend budgets, identity binding; enforcement at the checkpoint.
- Audit — the tamper-evident, cryptographically verifiable record.
- Payments — governed agent payments on national rails (mada · SADAD · Sarie).
- Inference — the private, in-tenant serving path; owning the path makes governance enforceable.
Layered architecture
Read top-to-bottom = outside-in. Build bottom-to-top = infrastructure first.
Deployment models
- In-tenant / sovereign — full stack in-region under local data-residency (KSA profile).
- Air-gapped — no internet egress; offline install and update path.
- Alongside existing ITSM — interoperate, never rip-and-replace.