2. Compare architecture alternatives using displayed evidence
The project’s software-security Agent performed AuthenticationThreatModelingWork-TM4 by applying
ProjectSoftwareSecurityThreatModelingMethod. That Work produced AuthenticationThreatModelResult-TM4, which
supplies two constraints used here: regional cache replication must be mutually authenticated and encrypted,
and acceptance of a revoked credential must end within 120 seconds. The architecture Agent uses those constraints
to admit alternative A and exclude a ten-minute bearer token under the current threat model. The architecture
Agent remains responsible for the architecture choice, and the release Agent retains release authority.
Using SYSE.5, the architecture Agent develops three materially different bearer and interface alternatives.
Using SYSE.6, the same Agent compares them against four declared limits: failed logins below 1%, acceptance of a revoked credential for no more than 120 seconds,
95th-percentile login latency no greater than 3 seconds, and rollback within 30 minutes. A controlled partition
replay for configuration candidate AS-7.5-rc2 returns these values:
| Alternative | Failed logins | Revoked-credential exposure | p95 login latency | Rollback | Result |
|---|---|---|---|---|---|
A — replicated regional session cache | 0.6% | 80 s | 2.4 s | 18 min | Meets all four limits; adds replication and operating complexity. |
B — signed ten-minute tokens with a revocation feed | 0.4% | 600 s | 1.8 s | 12 min | Rejected for this use because the 120-second security limit fails. |
C — retain the single-region session store | 8.2% | 35 s | 2.1 s | 8 min | Rejected because the failed-login limit fails during the partition. |
AuthenticationArchitectureDecision-AD7 therefore selects A for canary preparation. It records the added
replication burden as an accepted loss. The choice uses AuthenticationThreatModelResult-TM4; the table does not establish that specialist result or
transfer the specialist’s authority.