Alti
tudes
The world's most advanced enterprise AI coding architecture platform.
Massive token reduction from day 1 with the proven Altitudes design system. Mixing the best of AI and deterministic design to reduce agent overhead 10-20x and ensure requirements never shift.
Eight levels of design decision, each written down once and then enforced: a gate when the decision is made, a detector when the code drifts from it, a gate again before release. Your agents read the record instead of re-deriving it.
Built for
Written for the people accountable for the codebase.
Compliance across every agent session
When a dozen agents work the same base at once, every one of them starts from the same recorded design floor — and a detector fires the moment the code stops matching it.
Token spend that stops repeating
Re-deriving your architecture on every run is a bill you pay twice. Recorded decisions cut agent overhead 10-20x and make design context a versioned asset rather than a prompt someone retypes.
Decisions that outlive their author
Eight altitudes, 34 catalogued axes, one contract graph. Tiers are chosen explicitly and deviations recorded, so the architecture is read from the record rather than reconstructed from the code.
Ship into code you did not write
The capability floor is mined from real manifests, never guessed. Read the records and hand the agent a specification instead of a codebase tour.
The terms this platform uses, defined.
- 01Artifact
Record
The written design decision for one altitude, stored beside the code it describes and versioned with it.
- 02Check
Gate
A check that must pass before work continues: once in plan mode when the decision is made, again at release before a cut ships.
- 03Check
Detector
A check that compares the record against the current code and opens an issue — a gap — when the two diverge.
- 04Release
Cut
A release candidate. Milestones ship as alphas and then GA; a staged cut is blocked until every altitude reconciles against it.
- 05Model
Axis and tier
An axis is one dimension of a design decision — persistence, tenancy, retention. A tier is the level chosen on that axis. Thirty-four axes are catalogued.
- 06Model
Contract graph
The shared index of producer-to-consumer edges between recorded entities, so a change can be traced to everything that consumes it.
Eight levels. Each one owns a class of decision.
Open a row for its concerns, records and gates.
Records
*.design.md sidecars
Which structural pattern this function embodies — and what choosing it forecloses.
Concerns
- Pattern selection.One of seven catalogued answers: pipeline, interceptor, railway, effects-as-data, reactive-form, schema-as-data, plain-code.
- Freedom foreclosure.A pattern is a commitment; the catalog records what each one rules out, not only what it enables.
- Bidirectional pressure.Every change runs a de-escalation pass (YAGNI) and an escalation pass (hard constraint). Escalation wins ties.
- The decision trace.The rationale is recorded beside the label, so a reader can check whether the prose agrees with the field.
- Drift.Whether the recorded pattern still describes the code it names.
Design gateplan_mode.design_phase
Cut gaterender.no_triage_design_gaps
Drift detectorcode_design_drift_gap
Render order4
Every altitude is worked through one surface.
Switch panes to see what each surface holds.
forge-manager is the surface the altitudes are worked through: a three-pane shell where milestones, issues, discussions, entity records and decisions all read from the same registry. The status bar reports the live state — which alpha is active, whether data is confirmed, and whether a cut is staged.
Plan a line, ship it in alphas
Each milestone carries a GA target and the alphas beneath it, with closed counts and acceptance-criteria totals shown against the plan discussion that drives it.
Gaps arrive as work, not as prose
Detector output lands as issues against the active alpha, each with its own acceptance criteria and the files touched while closing it.
Plans and RFCs, with scope state
Every alpha has a plan discussion; design changes arrive as RFCs. Scope is tracked as released, live, or not assessable.
Entities and the choices behind them
Entity records carry identity scheme, lifecycle states and axis materializations. Decisions name the RFC that authorises them and the gate that enforces them.
Every altitude closes the same loop.
An altitude is not a category. Each one is enforceable at three moments, and a level that cannot be enforced at all three is a taxonomy rather than an altitude. Gaps a detector finds arrive as issues against the active alpha, and a staged cut stays blocked until they are closed.
Gate at design time
The plan_mode gates engage while the decision is being made, and stay engaged when agents run unattended, because the decision outlives the session that made it.
Detector while it runs
Each altitude has a drift detector that fires when the code no longer matches its record, and files the difference as a gap.
Gate at the cut
Before a release candidate ships, every altitude must reconcile against it. An unreconciled altitude blocks the cut.
| Altitude | Render | Axes | In the contract graph |
|---|---|---|---|
| 1 · function-sidecar | 4 | 1 | yes |
| 2 · architecture | 3 | 26 | yes |
| 3 · infra | 2 | 3 | yes |
| 4 · repo-layout | 1 — first | 1 | yes |
| 5 · runtime-dynamics | 5 | — | yes |
| 6 · capability | 6 | — | yes |
| 7 · requirements | 7 | 1 | yes |
| 8 · process | 8 | 3 | no |
Three altitudes carry no axes: function-sidecar records against a pattern catalog, while runtime-dynamics and capability record observables and axioms rather than tier choices on a ladder.
Book a technical walkthrough
06 / ContactBring one repository and one agent workflow. We record its eight altitudes with you and show the token delta on the second run.
Sourced from registry/altitudes.yaml v1.2.0 and registry/axes/catalog.yaml v9.0.0, plus each altitude's own topic file in the skill prose.