Broadly applicable
The pressure must matter across languages, vendors, and workload shapes. A useful specialty rule can remain an overlay instead of becoming a universal factor.
Comparative research · 2026.3
A credible manifesto should show its competitors, not merely cite its ancestor. This comparison asks what each body of work optimizes, what the Twenty-Two- Factor App adopts, and where it deliberately refuses a universal claim.
01 · The selection test
Twenty-two is editorial compression, not numerology. A practice enters the set only when it passes all five tests; otherwise it remains a useful pattern, specialty overlay, standard, or implementation guide.
The pressure must matter across languages, vendors, and workload shapes. A useful specialty rule can remain an overlay instead of becoming a universal factor.
Ignoring it must create a recurring production failure, unsafe default, or lifecycle dead end—not merely miss a fashionable tool or preferred implementation.
The factor needs its own design decision and evidence. Related concerns can overlap, but two labels must not reward the same work twice.
A team must be able to fail a litmus test. Aspirations without an observable boundary, owner, or decision do not qualify as commandments.
The wording names intent and system behavior. Ports, vendors, orchestration products, and deployment fashions may change without invalidating the rule.
02 · Revision note
Edition 2026.3 retires Outcome Ownership and Cost as Architecture as standalone universal factors. Ownership remains required wherever a commandment calls for evidence, authority, or follow-up; cost remains a constraint across capacity, observability, resilience, delivery, and sustainable operation.
Their numbered slots now cover two harder-to-retrofit production blind spots: explicit formal state and functional decision logic, followed by memory-safe languages, total types, explicit absence, and contained unsafe interoperability. Earlier factor URLs redirect here so the revision remains reviewable instead of silently rewriting history.
03 · Compare and contrast
“Overlap” names the factors most directly pressured by each source; it does not claim equivalence. The distinctions matter as much as the borrowings.
The durable original ten remain the foundation. Kevin Hoffman’s API-first, telemetry, and authentication/authorization additions become Contract-First Interfaces, Observability & SLOs, and Secure by Design.
This guide retires transport-specific port binding and promotes logs into a complete signal-and-decision model. It broadens API-first beyond HTTP and broadens identity into the full secure-development lifecycle.
Bounded response time, backpressure, isolation, elasticity, and failure containment sharpen Concurrency, Observability & SLOs, and Resilience & Fault Containment.
Message-driven architecture is a strong pattern, not a universal commandment for every CLI, embedded workload, batch process, or local application. The Twenty-Two-Factor set specifies outcomes and bounds without prescribing one communication model.
SLIs, SLOs, error budgets, release safety, production readiness, steady-state hypotheses, realistic failure injection, and bounded experiments make reliability claims testable.
SRE is an operating discipline and Chaos is an empirical practice; neither is reduced here to a checkbox. Their evidence loops support several factors rather than becoming a vague “test more” commandment.
Version control, continuous delivery, small changes, loosely coupled teams, monitoring, database change management, maintainability, customer feedback, and sustainable pace reinforce the delivery and feedback disciplines.
DORA reports empirically associated capabilities and outcomes; this guide states architectural obligations. It deliberately avoids turning deployment frequency or any single metric into a universal target detached from context.
Operational excellence, security, reliability, performance efficiency, cost, and sustainability confirm that production quality is multi-dimensional and that improving one dimension can tax another.
Provider frameworks are deep review catalogs. This guide is a shorter, vendor-neutral set of application pressures. Performance and cost remain cross-cutting constraints through Concurrency, SLOs, Resilience, delivery, and Sustainability rather than context-free universal factors.
Interoperable contracts, vendor-neutral telemetry, declarative versioned state, automatic reconciliation, and continuous drift detection shape the application and infrastructure boundaries.
Cloud native is one deployment context, not the definition of modern software. The commandments also apply to mobile, desktop, edge, embedded, local-first, and regulated systems where Kubernetes or GitOps may be the wrong implementation.
Threat modeling, security requirements, safe defaults, verification, vulnerability response, supply-chain evidence, memory-safe implementation, and responsibility for customer security outcomes broaden the earlier identity-only rule.
SAMM is a maturity model and SSDF is a practice catalog. Factor XII is the compressed architectural commandment; it does not replace either framework, a domain threat model, or a formal safety case.
Short feedback, working software, direct collaboration, and response to change reinforce representative testing, contract evolution, and progressive delivery.
The Agile Manifesto is about values for making software; this guide is about system properties and lifecycle evidence. Neither can substitute for the other, and process labels do not prove architectural fitness.
Data Lifecycle & Privacy now treats portable export, durable formats, offline usefulness, and provider exit as practical agency—not just compliance workflows.
Local-first is compelling for user-authored and collaborative data, but central authority is appropriate for banking, marketplaces, and other domains. The factor requires agency and lifecycle control without prescribing CRDTs or device-primary storage.
Useful-work units, energy and hardware efficiency, carbon awareness, cost evidence, accessibility, honesty, and explicit trade-offs connect resource use to value and harm.
Cost remains a cross-cutting design constraint rather than a standalone factor, and price is not a physical-impact signal. “Renewable” and offsets do not excuse waste, while efficiency work must not export harm into accessibility, privacy, labor, or reliability.
Prompts, context logic, behavioral specifications, models, evaluation sets, and guardrails are first-class versioned inputs. Quality and tool-use safety must be measured as product behavior, not inferred from HTTP success.
AI introduces distinct hazards, but they fit the universal rules: prompts and specs are source, models are dependencies, memory is state, evaluations are SLO evidence, tools require least privilege, and critical workflows need explicit states and guarded effects. AI-specific standards remain an overlay.
State-machine specifications, safety and liveness properties, immutable functional cores, typed errors, exhaustive matching, memory safety, explicit absence, and isolated unsafe boundaries turn reviewer assumptions into checkable constraints.
Types and safe languages prevent important classes of failure but do not prove requirements, authorization, concurrency, or domain correctness. Formal rigor is proportional to risk, and every model must state its assumptions and connection to implementation.
04 · Honest boundary
These commandments do not replace user research, accessibility standards, secure-development maturity models, domain regulation, formal safety cases, incident command, engineering management, or specialty guidance for AI, medical, financial, embedded, and other high-consequence systems.
Their job is narrower: expose the cross-cutting architectural pressures that are easiest to postpone and hardest to retrofit, state a boundary against cargo culting, and leave every claim open to evidence and revision.