Governance Domains

Resilience

Coverage ratios over five configuration signals, gated so a rating is issued only when both survival and recoverability were observable.

Currentengine 9.0.0Verified 2026-08-30

Weight: 0.3.

The signals

SignalResource family
Databases configured across multiple availability zonesRDS
Databases retaining automated backupsRDS
Auto Scaling groups spanning two or more zonesAuto Scaling
Load balancers spanning two or more zonesLoad balancing
Object storage with versioning enabledS3

Each is a coverage ratio over real resources. A signal with no in-scope resources is recorded and excluded from scoring, so an account that runs no databases is not penalised for it.

The gate

Two governance concerns, not five signals:

ConcernThe question
AvailabilityDo workloads survive a failure?
RecoverabilityCan data be recovered?

Both must be evidenced before the domain is scored. A rating that can see only one of them is half a resilience rating.

Why the gate is not a signal count

The five signals are neither independent nor evenly spread. Databases emit two of them from a single population, so counting signals would let a database-only estate satisfy a breadth test it has not met, while an estate spanning storage and load balancing failed one it had.

Resources are counted once per family, so a service exposing two signals from one population does not count twice.

Minimum population

At least five distinct applicable resources, counted per family.

What the collector does not observe

Point-in-time recovery on managed NoSQL, AWS Backup plans, EBS snapshots, EFS, Aurora, container services, cross-region replication, and standalone compute instances.

For a predominantly serverless estate its coverage of the real resilience surface is close to zero. That is published rather than absorbed. See Coverage limits, domain by domain.