Toolkit
Architecture without tools remains theory. This module bundles building blocks for implementing technology strategies. It consolidates methods, technical standards, legal frameworks, and software evaluations into an operational reference. The focus is on standardisation (boring technology), so engineering teams face fewer one-off decisions and compliance requirements remain traceable.
This module serves as a technical reference for day-to-day operations. It supports decisions about software licences, programming languages, and infrastructure services.
The Four Categories
The toolkit is divided into four operational areas:
- Methods: Process frameworks (C4 Model, DDD, SRE) that define how systems are designed, built, and operated.
- Standards: Legal and regulatory requirements (nFADP, EU AI Act, ISO 27001) that form the framework for secure IT systems.
- Licences: Analysis of open-source licence models (AGPL, MIT, GPLv3) to avoid legal risks in the software supply chain.
- Software and Services: Evaluations of programming languages (Go, Rust, PHP), databases (PostgreSQL), and cloud services (AWS, Azure, Cloudflare) for specific use cases.
Table of Contents
Methods
Methods turn technology strategy into repeatable practice for architecture documentation, stable operations and agile scaling in growing IT organisations.
- Agile Scaling and Descaling: Agile scaling restores team momentum through simpler structures, stream-aligned ownership and end-to-end responsibility for products or features.
- Bounded Context: Clear domain boundaries create maintainable models, shared understanding between teams and a solid basis for microservice architectures.
- C4 Model and Docs-as-Code: Current architecture diagrams earn trust when C4 Model structure and Docs-as-Code keep services, dependencies and changes aligned with code.
- Compliance as Code: Continuous Compliance as Code keeps regulatory controls machine-readable, testable and integrated into delivery pipelines and audit trails.
- DDD (Domain-Driven Design): Domain-Driven Design creates clear Bounded Contexts where terms have one meaning and microservice architecture gets a reliable domain basis.
- FinOps and Cloud Economics: FinOps makes cloud economics transparent through tagging, right-sizing and operating practices that keep infrastructure spending accountable.
- GitOps and Reconciliation: GitOps keeps infrastructure consistent through pull requests, declarative configuration, reviewable changes and fast disaster recovery.
- Golden Path: Golden Paths speed up delivery with supported development routes while preserving team autonomy for justified deviations.
- InnerSource and Code Openness: InnerSource opens codebases across the organisation for pull-request fixes, smoother delivery flow and broader knowledge sharing.
- ITIL vs. SRE: SRE makes ITIL service management executable with software engineering, automated operations and reliability control through error budgets.
- Requirements and Functional Specifications: Clear requirements come before implementation: Lastenheft defines the buyer view, Pflichtenheft the supplier solution and delivery scope.
- Nearshoring and Vendor Integration: Vendor integration improves delivery quality when service providers use the same GitOps, CI/CD and documentation practices as internal teams.
- Blameless Post-Mortems: Blameless post-mortems turn incidents into timelines, systemic analysis and concrete action items for stronger operational resilience.
- RASCI Matrix: RASCI matrices create ownership clarity by assigning clear responsibility, accountability, support, consultation and information roles.
- Refactoring: Regular refactoring keeps code easier to extend, defects easier to control and technical debt visible while behaviour remains stable.
- RFCs and ADRs: RFCs and ADRs make architecture decisions reviewable, searchable and open to expert feedback across teams and time zones.
- Strangler Fig Pattern: The Strangler Fig Pattern replaces legacy systems incrementally, letting new capabilities grow around existing production systems.
- 20% Tech Debt Rule: The 20% Tech Debt Rule keeps delivery speed sustainable by reserving capacity for refactoring, updates and architecture improvements.
Standards
Market access and trust rest on clear IT standards: regulatory requirements, technical norms and operating context for engineering teams.
- Age Verification: Age checks can satisfy youth protection duties while keeping identity data private: legal drivers, technical options and practical failure points.
- Cyber Resilience Act: Market access in the EU now includes cybersecurity duties for digital products: CRA requirements, security by design and manufacturer responsibility.
- GDPR: EU data protection stays clear of Swiss law: GDPR reach, processing principles, data subject rights and fines for Swiss firms with EU exposure.
- EMBAG: Federal IT tenders gain an open source baseline: EMBAG relevance and duties for providers working with Swiss federal authorities.
- EU AI Act: AI obligations become role-specific: EU AI Act risk classes, value-chain roles and why Swiss firms can fall within its scope.
- DORA: DORA is clearly separated from DevOps metrics: EU financial regulation for ICT resilience, reporting, testing and third-party risk.
- EU Whistleblower and Secure Cryptography: Confidential reporting stays protected by technical and organisational measures: EU whistleblower duties, anonymity rules and Swiss scope.
- GraphQL: Precise API responses with one endpoint: GraphQL explains requested data shapes, suitable use cases and limits compared with fixed REST routes.
- Green IT and Software Carbon Intensity: Lower IT emissions through efficient code, right-sized hardware and renewable data-centre energy, measured with Software Carbon Intensity.
- ISO 27001 and Compliance-as-Code: Information security becomes a managed routine: ISO 27001 links risk-based controls, organisational processes and continuous improvement.
- ISO 42001: Auditable AI governance for lasting AI operations: ISO 42001 requirements, PDCA structure and its relationship to the EU AI Act.
- MCP (Model Context Protocol): Interoperable AI agents need open tool connections: MCP links LLMs with databases, Git repositories and APIs through servers and clients.
- nFADP / DSG and Privacy by Design: Swiss privacy compliance rests on nFADP duties: personal fines, breach notification thresholds, privacy by design and access rights.
- NIS2: EU cybersecurity duties become concrete through NIS2: in-scope entities, risk management, staged incident reporting and the Swiss angle.
- Open Source Definition (OSI) and SLSA: Open source remains usable and auditable through OSI rights plus SLSA maturity levels for protected software supply-chain builds.
- Software Asset Management (SAM): Licence clarity improves audits and cost control: SAM centralises inventory, tracks usage and reconciles software with contract terms.
- SBOM (Software Bill of Materials): Software dependencies become traceable with an SBOM: libraries, affected systems and supply-chain requirements stay visible after incidents.
- SOC 2: Cloud and SaaS controls become verifiable through SOC 2: an AICPA attestation report for service providers, complementary to ISO 27001.
- US Cloud Act and Sovereign Cryptography: Sovereign cryptography strengthens data control under the US Cloud Act, while metadata, support access and lawful orders need separate assessment.
- WCAG and the European Accessibility Act: Accessible services rest on two layers: WCAG as the technical norm, EAA as legal duty, with conformance levels and the Swiss angle.
- YAML Frontmatter: Markdown pages gain machine-readable fields through YAML frontmatter: titles, publication dates, layouts, publishing state and common YAML pitfalls.
Licences
Clear licence orientation for enterprise decisions: common open source licences and hybrid models are analysed in strategic context.
- AGPL: Source availability for network services: AGPL keeps modified service code under the same licence when remote users access the service.
- Apache 2.0: Commercial certainty for proprietary products: Apache 2.0 permits closed source embedding and includes an explicit patent grant.
- BSD: Maximum code freedom with few obligations: BSD licences permit broad use, modification and sale without copyleft requirements.
- BSL and Fair Source: Shared source with controlled commercial use: BSL and Fair Source restrict managed-service competition and later convert to open source.
- GPLv3: Reliable source access for recipients: GPLv3 keeps distributed modifications under the same licence and addresses patents and hardware locks.
- MIT: Simple use for commercial software: MIT permits proprietary combinations and broad reuse, with patent coverage handled separately.
Software
Long-term software choices made clearer: evaluations of languages, frameworks, databases and applications for recruiting, maintenance and scalability.
- Banana Accounting: Local accounting with full data sovereignty: Banana covers double-entry bookkeeping, income-expense accounting and VAT through local installation.
- C# and .NET: Productive enterprise development: C# and .NET combine strong typing, a broad standard library and mature Visual Studio and Azure tooling.
- Chatwoot: Centralised customer support with data sovereignty: Chatwoot bundles channels and keeps accounts, conversations and attachments on in-house infrastructure.
- Claude Code: AI-assisted development in the local project context: Claude Code can read files, prepare refactorings and work under clear supervision.
- Contao: Accessible CMS foundations: Contao provides semantic output, accessible templates and back-end tooling, while editorial discipline remains essential.
- Cursor IDE: Faster editor-driven changes: Cursor integrates language models into the IDE context and orchestrates multi-file work through natural language.
- Drupal: Structured content for complex portals: Drupal separates content, configuration and presentation and maps rich data relationships through entities.
- Duplicati: Sovereign backups with tested restore: Duplicati encrypts data client-side and stores incremental backups on NAS, cloud or other storage targets.
- Euro-Office: European office work with open code: Euro-Office is an AGPL fork of ONLYOFFICE, backed by European providers and aimed at digital sovereignty.
- Figma: Collaborative product design in the cloud: Figma is the market standard and makes data location a sovereignty question in the Swiss context.
- Flutter: Cross-platform UI development from one codebase: Flutter compiles to machine code and shortens development cycles with Hot Reload.
- Go: Portable infrastructure services with simple Deployment: Go produces static binaries and combines static typing, garbage collection and goroutines.
- Grav CMS: Fast, database-free and Git-managed websites: Grav reduces runtime overhead, keeps SQL injection surface closed and keeps content portable.
- Joomla: Flexible portals with built-in access control: Joomla supports hierarchical user groups, access levels, modules and position-based layouts in core.
- LAMP Stack: Portable web hosting foundations: Linux, Apache, MySQL and PHP form a proven open-source stack available as standard on many hosting platforms.
- Laravel: Standardised PHP application development: Laravel includes migrations, authentication, queue management and full-stack building blocks out of the box.
- LibreChat: Shared AI access under organisational control: LibreChat provides one self-hostable interface for many models, keys and data on owned infrastructure.
- LibreOffice: Local office work with desktop autonomy: LibreOffice uses OpenDocument natively and serves as a sovereignty reference for Microsoft compatibility.
- Matomo: Privacy-compliant web analytics with owned data storage: Matomo stores analytics on Swiss or EU infrastructure and simplifies nFADP and GDPR checks.
- Mautic: Centralised campaign automation with open source: Mautic combines landing pages, email workflows and lead scoring in one campaign platform.
- Nextcloud: Data, accounts and access rules stay under organisational control with Nextcloud, an AGPL platform for files, collaboration and communication.
- Node.js: Scalable real-time services and APIs gain a JavaScript runtime with Node.js, built on an event loop and backed by the broad npm ecosystem.
- Obsidian: Knowledge stays local, readable and extensible with Obsidian: Markdown files, strong linking and plugins for notes through project work.
- OpenCode: Code work moves into the terminal with OpenCode: an open AI coding agent that reads projects, proposes changes and keeps model choice open.
- Open WebUI: Language models gain an independent chat interface with Open WebUI, pooling local and compatible external models for offline-capable use.
- Penpot: Design files stay portable and controllable with Penpot: MPL 2.0 open source code, an open file format and browser-based workflows.
- PHP: Robust web applications gain a proven scripting language with PHP: simple scaling, shared-nothing execution and modern frameworks like Laravel.
- Podman: Container work stays close to Docker workflows with Podman, adding daemonless operation, rootless containers and Kubernetes manifest support.
- PostgreSQL: Transactional data and AI vectors share one stable base with PostgreSQL: strict SQL, modern extensibility and extensions such as pgvector.
- PostHog: Product behaviour becomes measurable with PostHog: events, funnels, session recordings and feature flags, with a self-hostable open core.
- Python: Data work, automation and AI gain a readable language with Python, backed by a broad standard library and early access to new AI models.
- Rocket.Chat: Team communication stays on chosen infrastructure with Rocket.Chat, combining real-time chat, Matrix interoperability and plan-based compliance options.
- rsync: Large file sets stay aligned efficiently with rsync: delta transfer sends changed data and supports backup, mirroring and distribution routines.
- Rust: System software gains performance and compile-time safety with Rust, whose ownership model supports secure infrastructure and WebAssembly work.
- Symfony: Large PHP projects gain a stable foundation with Symfony: reusable components, clear design patterns and architecture for long-lived applications.
- Syncthing: Files stay current across devices with Syncthing: peer-to-peer synchronisation for sovereign infrastructure and clear backup boundaries.
- Tryton: Business processes fit into one modular ERP with Tryton: accounting, sales, warehousing, production and projects on a clean technical core.
- TYPO3: Large multilingual portals gain structure and longevity with TYPO3: clear editorial roles, fine-grained permissions and a predictable LTS cycle.
- Vtiger CRM: Sales and service processes gain structure with Vtiger CRM: leads, quotes, invoices and project tracking in one integrated PHP application.
- Wiki.js: Maintained knowledge becomes machine-readable with Wiki.js: versioned Markdown pages, YAML headers and programmatic access through GraphQL.
- WiseMapping: Mind maps stay on self-run infrastructure with WiseMapping: open-source browser mapping, collaborative idea work and a clear view of project maturity.
- WordPress: Content-rich websites become manageable with WordPress: editorial workflows, broad plugin extensions and access for non-technical teams.
Services
Managed services and cloud platforms in balance: lower operational overhead, preserved digital sovereignty, and the right level of control.
- Adobe Creative Cloud: Integrated design workflows with Adobe Creative Cloud: SaaS licensing, cloud services, Stock, Fonts and connected tools across design disciplines.
- authentik: Central login, multi-factor and permissions on self-hosted infrastructure: authentik as an open-source identity provider with open core and Enterprise option.
- AWS: Highly available, globally distributed cloud architectures with AWS: modular services, strong APIs and automation for scalable operations.
- Azure: Hybrid cloud architectures with Azure: on-premises data centres, cloud services and identity management connected through Entra ID.
- Backstage: Central developer portals with Backstage: services, software templates and infrastructure status collected in one searchable internal platform.
- Bexio: Swiss SME administration in one cloud platform: CRM, order processing, accounting and banking integration with VAT, QR invoice and fiduciary access.
- Classic Frontend: Fast, durable websites with Classic Frontend: server-side logic, browser standards and less framework overhead for performance and SEO.
- Claude: Long-document analysis and high-quality code generation with Claude: large context windows and precise language model output for complex text tasks.
- Cloudflare: Fast, protected web delivery at the network edge with Cloudflare: WAF, DDoS protection, caching and global optimisation near each request.
- ERPNext: Open ERP processes with ERPNext: finance, warehouse, manufacturing, sales, HR and projects on the Frappe Framework with Python and JavaScript.
- Gemini: Google Workspace automation with Gemini: multimodal models, Drive, Gmail and Docs access in suitable configurations, plus very large context windows.
- GitLab: Integrated DevOps with GitLab: planning, Git, CI/CD automation and security scans in one platform, including self-managed operation.
- Google Cloud: Data-centric cloud architectures with Google Cloud: BigQuery, GKE, Kubernetes and global network connectivity for cloud-native platforms.
- Grafana and Prometheus: Stable observability with Prometheus, Grafana and OpenTelemetry: metrics, visualisation and neutral instrumentation for asynchronous monitoring.
- Java and Spring Boot: Stable enterprise backends with Java and Spring Boot: type safety, a broad library ecosystem and production-ready applications by convention.
- Keycloak: Central identity management with Keycloak: OIDC, SAML 2.0, Active Directory integration and MFA for modern single sign-on architectures.
- Kubernetes: Declared infrastructure state with Kubernetes: cluster orchestration keeps workloads scaled, healthy and self-healing through continuous reconciliation.
- Llama: Data-resident language models with Llama: downloadable model weights, self-hosted operation and clear licence boundaries under Meta conditions.
- Magento: Complex commerce operations with Magento: multi-store, multi-currency, B2B catalogues and shop architectures as open-source edition or Adobe Commerce.
- Microsoft 365: Connected collaboration with Microsoft 365: Teams, SharePoint and Office apps integrated through central identity and governance with Entra ID.
- Mistral: European AI model operation with Mistral: EU jurisdiction, open downloadable models, Apache 2.0 options and clear licence boundaries.
- NetBird: One encrypted private network across devices, servers, and sites: NetBird uses direct peer-to-peer traffic for simpler distributed access.
- Odoo: One shared ERP database for CRM, warehousing, projects, e-commerce, and accounting: Odoo grows through modular apps as needed.
- Okta: Centralised authentication as a hosted identity service: Okta shows outsourced IAM, protocols, and data handling with a US provider.
- OpenAI: Current language and image models through APIs: OpenAI supports AI functions with model infrastructure operated by the provider.
- OpenRouter: Lower integration effort for language models: OpenRouter routes one shared API to hundreds of models from OpenAI, Anthropic, Google, and others.
- Pickware: Native shop and inventory flow: Pickware connects commerce and warehouse processes with mobile scanners and shared operational data.
- Power BI: Self-service reporting for Microsoft-adjacent BI teams: Power BI connects business reports, Excel data and the Microsoft 365 estate.
- Sage: Swiss accounting and payroll compliance: Sage supports bookkeeping and salary processing in classic on-premises and cloud-hybrid setups.
- Salesforce: CRM plus cloud application development: Salesforce combines sales, service, marketing, custom apps, and a large extension ecosystem.
- SAP S/4HANA Cloud: Standardised enterprise processes with real-time insight: SAP S/4HANA Cloud applies best practices across large organisations.
- SAP Commerce Cloud (Hybris): Complex B2B commerce at scale: SAP Commerce Cloud combines PIM, multi-site management, large product catalogues, and high concurrent usage.
- Shopify: Hosted commerce operations: Shopify combines payments, security, updates, and a broad app ecosystem for extensions in one managed platform.
- Shopware: API-first commerce with high customisability: Shopware 6 adds native AI Copilot features and an MIT-licensed Community Edition.
- Squarespace: Curated website design in one platform: Squarespace bundles templates, hosting, domain, SSL, and a simple shop for visual websites.
- Tailscale: One encrypted local network across sites, cloud resources, and work devices: Tailscale uses WireGuard and direct peer-to-peer traffic.
- Terraform and OpenTofu: Reproducible cloud environments as code: Terraform and OpenTofu create execution plans and control cloud APIs through providers.
- TypeScript: Earlier code feedback for JavaScript applications: TypeScript uses static types so editors catch errors during development.
- Userback: Reproducible bug reports from visual feedback: Userback captures browser context as screenshots, videos, and console logs.
- Vibe Kanban: Manageable AI coding workflows: Vibe Kanban combines task boards, isolated agent workspaces, diff comments, browser previews, and PR creation.
- Webflow: Visual development on the CSS box model: Webflow combines code-free design work, integrated CMS, and enterprise-grade AWS-based hosting.
- Wix: Fast website creation with flexible layout control: Wix provides built-in operations and apps for booking, shop, events, and other functions.