SovAIHub
ModulesSAI-120
SAI-120 table of contents
Assessment3 min readContent reviewed

SAI-120 knowledge check

Verify architecture completeness, traceability, boundary control, decision quality, portability, operability, and evidence coverage.

Last content review 2026-08-03Included in SAI-120

Assessment instructions

Complete the scenarios and use the answer guidance to challenge the reference-architecture workshop package. This public assessment verifies architecture reasoning, not product-specific implementation skill or professional certification.

Questions

1. Product diagram

A proposed architecture contains a user interface, vector database, and model server. Which major responsibility layers and lifecycle concerns are missing?

2. Control bypass

All user requests pass through an AI gateway, but administrators can invoke the model endpoint directly. What architecture problem remains?

3. Multiple views

Why should a deployment diagram not replace the system context, trust-flow, supply-chain, and evidence views?

4. Managed-service decision

What should an ADR record when a managed model endpoint is selected over a customer-hosted runtime?

5. Portability

An application uses a compatible model API, but prompts, evaluation data, identity policy, logs, and runbooks cannot move. Is the workload portable?

6. Evidence placement

Where should evidence requirements appear in the architecture rather than being deferred to operations?

7. Failure behavior

The external model route is unavailable. Which decisions must the architecture define before this happens?

8. Traceability

Describe the trace from a sovereignty requirement to proof that the deployed system satisfies it.

Answer guidance

  1. Typical gaps include purpose and consuming systems, identity/gateway, workload orchestration, ingestion and permissions, artifact supply chain, tools, platform boundary, operations/evaluation, evidence, backup, recovery, update, and retirement.
  2. The gateway is not an effective enforcement point if a privileged or alternate path bypasses its identity, policy, and evidence controls.
  3. Each view answers different questions. Combining them obscures actors, ownership, trust changes, lifecycle movement, administrative paths, and evidence flows.
  4. Record drivers, alternatives, threats, data and administrative boundaries, control consequences, reliability, cost, skills, evidence, dependencies, limitations, exit, and reconsideration triggers.
  5. Only one interface is portable. Practical workload portability remains weak across behavior, policy, assurance, and operations.
  6. At every material control and decision point: supply-chain gates, gateways, retrieval permissions, model routing, tool approval, deployment, evaluation, incidents, and recovery.
  7. Define rejection, retry, approved fallback, local route, user communication, queueing, data handling, service objectives, evidence, escalation, and recovery.
  8. Requirement -> architecture driver -> decision and view element -> control objective -> implementation -> positive/negative test -> versioned evidence -> review and residual decision.

Completion rubric

SAI-120 is complete when:

  • Architecture drivers are prioritized and traceable.
  • Logical responsibilities are complete and owned.
  • Trust, deployment, lifecycle, operations, and evidence views are consistent.
  • Material interfaces include identity, policy, failure, version, and evidence contracts.
  • Decisions state alternatives, trade-offs, dependencies, limitations, and reversal triggers.
  • Controls and evidence are placed at enforceable architecture points.
  • Portability and recovery are defined and testable.
  • Remaining gaps form a prioritized readiness backlog.