bRRAIn Certified Platform Architect
Design, govern and defend bRRAIn estates: organizations, hosting, identity, integrations, models, security and continuity.
- Level
- Expert
- Learning time
- 40 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- Rebuilt on the real topology: one dedicated brain pod per organization, the four hosting options, and console and account.brrain.io roles, replacing v1's invented multi-tenant cloud design.
- Architect-level depth on the eight zones (Z1-Z8), the governed write path and the invariants that hold under failure.
- Identity now teaches OIDC SSO with Okta, Entra ID and Google, group-to-role mapping, custom roles and per-project permissions as they work today.
- The joint-session protocol and Universal Interconnection Principle are taught as methods mapped to real mechanisms, including Robo Compliance auditor access.
- New modules on AI model architecture (Handler default, LLM Registry, LLMOps, Operator ENV) and integration architecture (MCP Gateway, Exchange MCP, Data Pipe, SDK).
- Lifecycle and continuity use the real install channel, brrain upgrade, in-place upgrades, brrain dr and brrain export, with no invented SLAs or regions.
- Assessment is now an online LOFT exam with AI-scored performance tasks and an AI role-play capstone, replacing the v1 project and panel.
What you will be able to do.
- You will be able to decide organization boundaries, hosting options and project structures for a multi-entity estate and justify them by hard drivers.
- You will be able to design identity and access with OIDC SSO, group mappings, custom roles, per-project permissions and scoped non-human identities.
- You will be able to connect outside systems and AI models through governed gateways with the Handler as default and governed opt-ins.
- You will be able to build governance methods, cross-organization collaboration and auditor access into designs using recorded decisions and corrections.
- You will be able to threat-model a deployment and design security and compliance evidence without overstating what the platform provides.
- You will be able to plan upgrades, migrations, offboarding and continuity with the real lifecycle tooling and prove recovery objectives with drills.
- You will be able to author reference architectures and ADRs and defend an architecture to a review board and a board of directors.
Who it's for
- Principal engineers and architects responsible for bRRAIn across a large organization or corporate group
- CTOs and lead architects at partner firms running bRRAIn for many client organizations
- Platform engineering leads operating bRRAIn as an internal platform
- Security and enterprise architects who must review and approve bRRAIn designs
Not covered here
- Building individual integrations end to end (see Integration Engineer)
- Application development with the SDK (see SDK Developer)
- Operating governance of what runs on the platform (see Operations Controller — the Platform Architect designs the platform; the Operations Controller governs what runs on it)
15 modules, 129 lessons.
About 40 hours of learning. Open a module to see every lesson.
-
bRRAIn Architecture for Architects
The eight zones (Z1-Z8), their seams and invariants; the governed write and read paths; client surfaces and how they reach an organization's brain pod.
- Module 1 pretest
- The eight zones and what each one owns
- The governed write path: Workspaces, Consolidator, Vault
- The read path: search, context loading and session tools
- Client surfaces and how they reach the brain pod
- Zone seams and invariants under failure
- Lab 1: Walk a CISO through one request across the zones
- Lab 2: Review a design that bypasses the write path
- Module 1 retrieval check
-
Estate Topology and Hosting
One organization, one brain pod; choosing hosting options under the Residency Language Prohibition; multi-organization estates; projects as the internal boundary; the split-or-combine decision.
- Module 2 pretest
- One organization, one brain pod
- Choosing a hosting option
- Multi-organization estates: groups, subsidiaries and partner-served clients
- Projects as the internal boundary
- Worked example: split into organizations or combine into projects?
- Lab 3: Design the estate for a three-entity group
- Lab 4: Defend a hosting choice to a compliance officer
- Module 2 retrieval check
-
Knowledge Architecture and Governance by Design
Vault information architecture, POPE tagging and the ontology graph, designing for the session method, methodology stage tags and learning capture as defaults, corrections and the Conflict Zone, and search at scale.
- Module 3 pretest
- Vault information architecture: folders, naming and file types
- POPE tagging and the ontology graph
- Designing for the session method
- Methodology stage tags and learning capture as defaults
- Attribution, corrections and the Conflict Zone
- Search, indexes and the read limit at scale
- Lab 5: Knowledge architecture for three practice areas
- Lab 6: Answer a request to retro-edit decision records
- Module 3 retrieval check
-
Organization Lifecycle: Install, Upgrade, Migrate, Offboard
Provisioning order, self-hosted install from the release channel, upgrade architecture with pinning and supervised rollback, moving between hosting options with brrain dr migrate, and offboarding with brrain export.
- Module 4 pretest
- Provisioning an organization and its pod
- Self-hosted install from the release channel
- Upgrade architecture: checks, pins, supervised rollback, in-place upgrade
- Moving an organization between hosting options
- Offboarding and data handover
- Lab 7: Write the upgrade policy with an operations lead
- Lab 8: A pod was recreated and integrations broke
- Module 4 retrieval check
-
Identity and Access Architecture
account.brrain.io and OIDC SSO with Okta, Entra ID and Google; group-to-role mapping; the seven tiers and custom roles; per-project permissions and Nexus surface gating; privileged, automated and break-glass identities.
- Module 5 pretest
- Identity architecture: account.brrain.io, SSO and tokens
- Designing group-to-role mapping
- The seven tiers and custom roles
- Per-project permissions and Nexus surface gating
- Privileged, automated and break-glass identities
- Lab 9: Federate two identity providers after a merger
- Lab 10: Review a custom-role design
- Module 5 retrieval check
-
Cross-Organization Collaboration
The Certification Standard's joint-session protocol taught as a method: scoping external access, dual authorization as two recorded approvals, audit, expiry and termination, external auditors on sealed sessions, and the Universal Interconnection Principle.
- Module 6 pretest
- The joint-session protocol as a method, not a feature
- Scoping access for an external party
- Dual authorization as two recorded approvals
- Audit, expiry and termination
- External auditors: sealed sessions and the auditor portal
- Applying the Universal Interconnection Principle
- Lab 11: Design a cross-organization engagement
- Module 6 retrieval check
-
AI Model and Agent Architecture
The Handler as default model, commercial models through the LLM Registry, LLMOps model governance, Security Policy Engine rules for model calls, and agents with service identities and Operator ENV credentials.
- Module 7 pretest
- The Handler as the default model
- Commercial models through the LLM Registry
- LLMOps: model cards, evaluations and drift
- Data-handling policy for model calls
- Agents, service identities and Operator ENV
- Lab 12: Model-routing decision with a CFO and a CISO
- Lab 13: Run an LLMOps drift review
- Module 7 retrieval check
-
Operations, Capacity and Continuity
Observability signals, alerting and runbooks, setting and proving RPO and RTO, continuity drills with brrain dr, capacity planning for pods and vaults, and client resilience with the Nexus Mobile outbox.
- Module 8 pretest
- Observability for a bRRAIn estate
- Alerting and runbooks
- Setting and proving RPO and RTO
- Worked example: a continuity drill with brrain dr
- Capacity: pod sizing and vault growth
- Client resilience: the Nexus Mobile outbox and offline limits
- Lab 14: Continuity plan for a regulated organization
- Module 8 retrieval check
-
Compliance Architecture
The responsibility line between bRRAIn and the customer, Robo Compliance in the architecture, and architecture decisions for SOC 2, HIPAA and GDPR programs.
- Module 9 pretest
- What the platform provides and what the customer owns
- Robo Compliance in the architecture
- SOC 2: architecture decisions that produce evidence
- HIPAA: architecture decisions for protected health information
- GDPR: rights requests, erasure and residency language
- Lab 15: Compliance architecture for a health-services group
- Lab 16: Walk an external auditor through the evidence
- Module 9 retrieval check
-
Security Architecture
Threat modeling for AI memory, zero trust at every boundary, designing with the Security Policy Engine, the Code Sandbox and extension isolation, and preventing leakage across organizations.
- Module 10 pretest
- Threat modeling an AI-memory deployment
- Zero trust at every boundary
- Designing with the Security Policy Engine
- Code Sandbox and extension isolation
- Preventing leakage across organizations in an estate
- Lab 17: Threat model a firm's bRRAIn deployment
- Lab 18: Respond to a red-team finding
- Module 10 retrieval check
-
Integration Architecture
Governed gateways; the MCP Gateway with Exchange MCP and the Tool Registry; Data Pipe and document ingestion; the Platform SDK and extensions; outbound events through the Notifier; choosing integration patterns.
- Module 11 pretest
- Governed gateways: the integration rule
- MCP Gateway, Exchange MCP and the Tool Registry
- Data Pipe and document ingestion
- Platform SDK and extensions
- Outbound events: Notifier and webhooks
- Worked example: choosing the integration pattern
- Lab 19: Integration architecture for a firm's systems
- Module 11 retrieval check
-
Reference Architectures and the Pattern Library
Authoring buildable reference architectures on real capabilities, curating the pattern library in the vault, deprecating patterns safely, running the architecture review board, and mentoring builders.
- Module 12 pretest
- Authoring reference architectures others build against
- Curating the pattern library
- Deprecating patterns without breaking organizations
- Running the architecture review board
- Mentoring Integration Engineers and SDK Developers
- Lab 20: Author a reference architecture
- Module 12 retrieval check
-
Architecture Decision Records
The ADR format, decisions that survive turnover, keeping ADRs in the vault with record_decision and supersession, and build-versus-buy decisions.
- Module 13 pretest
- The ADR format
- Decisions that survive turnover
- Keeping ADRs in the vault
- Build-versus-buy decisions
- Lab 21: Write three ADRs and defend one
- Module 13 retrieval check
-
Board-Level Architecture Communication
The one-page architecture summary, communicating risk with the Risk & Contingency standard, communicating cost with the current commercial model, and communicating strategic implications.
- Module 14 pretest
- The one-page architecture summary
- Communicating architectural risk
- Communicating cost
- Communicating strategic implications
- Lab 22: Present a one-page summary to a board member
- Module 14 retrieval check
-
Architecture Review Defense and Capstone
Structuring an architecture presentation, anticipating reviewer questions, articulating trade-offs, handling challenge, and the capstone architecture review.
- Module 15 pretest
- Structuring an architecture presentation
- Anticipating reviewer questions
- Articulating trade-offs
- Handling challenge without conceding the design
- Capstone: Architecture review for Halvorsen & Pike
- Module 15 retrieval check
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · bRRAIn Architecture for Architects
A CISO's request to trace one assistant request across the zones
-
Lab 2 · bRRAIn Architecture for Architects
Review of an integration that writes to the vault volume, edits records in place and posts full records to a partner channel
-
Lab 3 · Estate Topology and Hosting
Estate design for a three-entity group with an EU subsidiary and competing clients
-
Lab 4 · Estate Topology and Hosting
A compliance officer demanding a 'never leaves the EU' guarantee
-
Lab 5 · Knowledge Architecture and Governance by Design
Knowledge architecture for a firm with three practice areas and confidential forensic work
-
Lab 6 · Knowledge Architecture and Governance by Design
A managing partner asking to retro-edit decision records before a client review
-
Lab 7 · Organization Lifecycle: Install, Upgrade, Migrate, Offboard
An operations head who wants automatic same-day upgrades across 22 organizations
-
Lab 8 · Organization Lifecycle: Install, Upgrade, Migrate, Offboard
Incident after a pod recreation broke MCP clients and a Data Pipe connector
-
Lab 9 · Identity and Access Architecture
Federating Okta and Entra ID after a merger with overlapping group names
-
Lab 10 · Identity and Access Architecture
Review of a law firm's broken custom roles and broad matter grants
-
Lab 11 · Cross-Organization Collaboration
An Operations Controller who wants to make an outside consultancy Operators for 60 days
-
Lab 12 · AI Model and Agent Architecture
A CFO and a CISO with opposing views on commercial models
-
Lab 13 · AI Model and Agent Architecture
An LLMOps drift alert after a provider model change
-
Lab 14 · Operations, Capacity and Continuity
A risk officer demanding 'zero data loss' for a self-hosted clinic group
-
Lab 15 · Compliance Architecture
Compliance architecture for a group with HIPAA, SOC 2 and GDPR obligations
-
Lab 16 · Compliance Architecture
An external auditor's fieldwork questions on evidence integrity
-
Lab 17 · Security Architecture
Threat-modeling session with a firm's head of security
-
Lab 18 · Security Architecture
A prompt-injection red-team finding through an ingested PDF and an over-scoped MCP server
-
Lab 19 · Integration Architecture
An integration lead who wants one admin token and direct vault database access
-
Lab 20 · Reference Architectures and the Pattern Library
An Integration Engineer trying to build from your reference architecture
-
Lab 21 · Architecture Decision Records
A principal engineer reviewing three ADRs
-
Lab 22 · Board-Level Architecture Communication
A non-executive director preparing for a board meeting
-
Lab 23 · Architecture Review Defense and Capstone
Full architecture review of Halvorsen & Pike before a CTO and a CISO
Architecture review for Halvorsen & Pike
AI role-play scored against the published rubric
Pass mark: 75%
Scored on
- Estate and hosting topology20%
- Identity and access architecture15%
- Integration and AI model governance15%
- Governance methods and cross-organization access15%
- Security, compliance and continuity20%
- Decision records and communication15%
One exam. A credential anyone can verify.
The exam
- Items per form
- 66
- Time allowed
- 180 min
- Pass mark
- 75%
- Performance tasks
- 6
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: At 3 years by passing the then-current exam; CE modules keep the credential current between renewals
Where this course sits.
Prerequisites
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 66 items in 180 minutes, on a form assembled for you from the course's item bank. 6 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 75%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
Related courses.
bRRAIn Certified Platform Architect
Design, govern and defend bRRAIn estates: organizations, hosting, identity, integrations, models, security and continuity.