Rule Cascade
ReferenceDecision records (ADRs)

ADR 0004: One parent per ruleset, and parents decide what children may change

Status: accepted

Status: accepted

Context

Rules are configured at several levels: enterprise, organization, business unit, agency, application, feature. Lower levels need to adapt rules without being able to quietly weaken them.

Decision

A ruleset extends at most one parent, and its scope must be the parent's scope plus at least one more level. Each rule and parameter carries an overridePolicy: locked, tighten-only or open. Every rule override must state a reason. Violations fail the load.

Why

  • A chain matches how organisations are structured and has no diamond problem: every inherited rule has exactly one origin.
  • tighten-only as the default for rules makes the safe thing the easy thing. Raising a severity needs no permission; lowering one needs the parent to have said open.
  • Failing the load, rather than ignoring an illegal override, makes governance visible in CI instead of in production.

Consequences

  • Sharing rules across unrelated branches of the hierarchy means placing them at a common ancestor. Mix-in style reuse is not supported in 1.0; the extends field is a list so that it can be added later without a breaking change.
  • Inheritance is resolved once at load time, so hierarchy depth has no cost per request.

On this page