Your Architecture Is Declared.
Nothing Enforces It.
TOGAF defines the target. Platform engineering paves the golden path. IaC declares the desired state. Three generations of architectural intent — and in most enterprises, nothing validates that a change conforms to any of them before it runs.
Three layers of aspiration, one shared assumption.
Each practice declares what the environment should be, and each quietly assumes something else will hold reality to it.
The target architecture
TOGAF and enterprise architecture define principles, roadmaps, and the intended shape of the estate. The blueprint lives in documents and diagrams that describe — and are consulted by people, not by change.
The golden path
Platform engineering paves the approved route: templates, paved pipelines, sanctioned patterns. The path is easier than the alternatives, but easier is not the same as enforced, and teams under deadline route around it.
The declared state
IaC states what managed resources should be — for the resources it manages, in the repositories that stay current. Around that footprint, change arrives by console, ticket, and script, and drift accrues where nothing declares anything.
Aspiration without an enforcement point.
Documents are consulted by people, not by change
A change does not read the architecture repository before it executes. Conformance depends on the reviewer remembering the principle, recognizing the violation, and having the standing to stop the work.
Adoption is voluntary where it matters most
The teams most likely to leave the golden path are the ones under the most pressure — precisely the changes that most need governing. A paved road with optional exits governs only the compliant.
Coverage ends at the managed footprint
IaC validates what it applies. It cannot speak for the change that reaches infrastructure through a console session, an emergency fix, or a vendor tool — and cannot see its own declared state go stale against reality.
Review arrives after the decision
Architecture review boards evaluate designs, not executions. By the time drift is visible in an assessment, it is embedded in production and priced accordingly.
Declared intent becomes enforceable intent.
Keep the framework you already chose. TOGAF, platform engineering, infrastructure as code — the IOM replaces none of them and has no opinion about which is right. It is the enforcement point all of them assumed existed: the place a declaration lives where change consults it before running, rather than where review remembers it afterwards.
The target becomes a checkable statement
Architecture principles, placement rules, and permitted patterns are expressed against the running-state model — and the model continuously compares reality against them, surfacing drift instead of waiting for the next assessment.
The golden path gains a gate
Connected change is validated against the declared architecture whether it took the paved road or not. The path stays paved; leaving it stops being invisible.
Declared state extends past the IaC footprint
The model reconciles what IaC declares with what the environment actually runs — including everything IaC never managed — so drift is visible wherever it occurs, not only where a plan happens to be applied.
One enforcement point for every actor
People, automation, and AI clear the same validation. The architecture governs the change regardless of who or what proposed it, or which tool carried it.
From documents to enforcement, in order.
Capture the declarations
Target architecture, platform standards, and IaC-declared state are expressed against the model. Most of the rules already exist; this gives them an address.
Reconcile with running state
The model compares the declarations with what the environment actually is. The disagreements are the first architectural findings.
Surface the drift
Where reality departs from the declared architecture — inside or outside the managed footprint — the departure is visible continuously, not per assessment cycle.
Govern connected change
Proposed change is validated against the declared architecture before it executes. Non-conforming change is held with a structured reason.
Verify and feed back
Executed change is verified against the model and the result feeds back — so the declared and the actual stop diverging silently.
Architecture that is enforced, not archived.
The review board governs execution, not just design
Decisions made in review are expressed where change consults them — the board’s authority extends past the meeting.
Conformance is continuous
Drift is surfaced as it occurs rather than discovered in the next architecture assessment, when it is already load-bearing.
The golden path earns its adoption case
When conformance is checked at execution, the paved road is both the easiest route and the governed one — the incentive and the control finally agree.
The architecture survives its author
Intent expressed in the model outlives the architect who wrote the document, the reorg that dissolved the board, and the contractor who owned the repo.
Put your target architecture somewhere change can consult it.
The whiteboard maps where your declared architecture and running reality diverge today, and the scope where enforcement should begin.
Governed before execution applies to connected change. Start with the operating model and the first 30 days.