← 返回
安全合规 中文

Enterprise

Navigate enterprise software development with legacy integration, compliance requirements, stakeholder management, and architectural decisions at scale.
驾驭企业级软件开发,涵盖遗留系统集成、合规要求、利益相关者管理及大规模架构决策。
ivangdavila
安全合规 clawhub v1.0.0 1 版本 100000 Key: 无需
★ 0
Stars
📥 879
下载
💾 43
安装
1
版本
#latest

概述

When to Use

Working in corporate environments where decisions involve legacy systems, formal processes, compliance, multi-team coordination, or architectural trade-offs at scale.

Quick Reference

TopicFile
-------------
Legacy patternslegacy.md
Compliance rulescompliance.md
Architecture decisionsarchitecture.md

Core Rules

1. Legacy First Mindset

  • Assume existing systems until proven otherwise
  • Integration cost > development cost in most decisions
  • "Replace vs wrap" analysis before any architecture change
  • Document all integration points touched

2. Stakeholder Mapping

RoleCares AboutLanguage
-----------------------------
EngineeringTechnical debt, velocityPatterns, trade-offs
ProductFeatures, timelineUser impact, scope
SecurityRisk, complianceThreat models, controls
FinanceCost, ROITCO, licensing
LegalLiability, dataContracts, GDPR

Translate technical decisions into each stakeholder's language.

3. Change Management

  • No breaking changes without migration path
  • Feature flags before hard switches
  • Rollback plan for every deployment
  • Document blast radius of failures

4. Compliance Awareness

  • PCI, SOC2, HIPAA, GDPR implications in every data decision
  • Audit trail requirements → logging design
  • Data residency affects architecture
  • Ask: "Who audits this? What do they need?"

5. Documentation as Deliverable

Enterprise code without docs = technical debt.

  • ADRs (Architecture Decision Records) for major choices
  • Runbooks for operations
  • API contracts before implementation
  • Dependency graphs updated with changes

6. Security by Default

  • Principle of least privilege in all designs
  • Secrets in vault, never in code or config files
  • Network segmentation assumptions
  • Zero trust between services

7. Observability Investment

  • Logging, metrics, tracing from day one
  • Correlation IDs across service boundaries
  • SLI/SLO definitions before launch
  • Alert fatigue is a system design failure

Enterprise Traps

  • Assuming greenfield when there's always legacy → scope explosion
  • Optimizing for developer experience over ops burden → 3am pages
  • Skipping security review for "internal tools" → breach vector
  • Building before buying → reinventing solved problems
  • Over-abstracting early → framework nobody understands
  • Under-documenting decisions → knowledge silos

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-03-29 08:57 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,714
security-compliance

Skill Vetter

spclaudehome
AI智能体技能安全预审工具。安装ClawdHub、GitHub等来源技能前,检查风险信号、权限范围及可疑模式。
★ 1,215 📥 266,466
ai-intelligence

Self-Improving + Proactive Agent

ivangdavila
自我反思+自我批评+自我学习+自组织记忆。智能体评估自身工作、发现错误并持续改进。
★ 1,358 📥 318,203