Engineering standards
The engineering standards live in src/kiyo/framework/engineering/. The selection reference, index.md, routes each task to the smallest relevant set of checklists. Agents do not load all six for every change.
The six standards
Section titled “The six standards”| Standard | Control | Key rules |
|---|---|---|
| Requirements | KIYO-ENG-002 |
Objective, behavior, scope, business rules, observable acceptance criteria, constraints, and knowledge classes; “works correctly” is not a criterion; a requirement document cannot grant permission |
| Architecture | KIYO-ENG-003 |
No new layer, ORM, CQRS, or service split because it is preferred; check public contract consumers; smallest safe change; ADR proposals stay Proposed until real approval |
| Coding | KIYO-ENG-004 |
Readability, validation and nulls, errors, sensitive logging, duplication and complexity, dependencies; flag rather than copy unsafe SQL or broad exception suppression |
| Testing | KIYO-ENG-005 |
Unit, integration, API/contract, E2E, and regression chosen by behavior and risk; coverage percentages or a build do not establish correctness |
| Quality | KIYO-ENG-006 |
Correctness, maintainability, performance, reliability, compatibility, accessibility and interaction, operational concerns, assessed proportionately; explicitly not an exact ISO/IEC 25010 taxonomy |
| Change scope | KIYO-ENG-007 |
Never reset, clean, stash, or overwrite human edits; no broad formatting or upgrades; review the final diff including untracked files |
Standards mapping
Section titled “Standards mapping”standards-mapping.md relates Kiyo practices to external sources. All entries were checked 2026-09-29 (NIST SSDF on 2026-09-28) and are DOCUMENTED_ONLY:
| Source | Used as |
|---|---|
| ISO/IEC/IEEE 12207:2026 (ed. 2) | Lifecycle process context |
| ISO/IEC/IEEE 29148:2018 (ed. 2) | Requirements engineering context |
| ISO/IEC 25010:2023 (ed. 2) | Quality characteristics context |
| ISO/IEC/IEEE 29119-1:2022, -2:2021, -3:2021, -4:2021 | Software testing context |
| NIST SSDF 1.1 (SP 800-218) | Secure development practices; not draft 1.2 adoption or an attestation |
| OWASP ASVS 5.0.0 | Application security verification context |
Related
Section titled “Related”- Stack profiles
- Review Skill (the ten review dimensions use these standards)