bRRAInDev · Expert
v2.0

bRRAIn Certified Platform Architect

Design, govern and defend bRRAIn estates: organizations, hosting, identity, integrations, models, security and continuity.

Level
Expert
Learning time
40 hours
Price
$499
Credential
Valid 3 years
What's new in v2.0

What changed in this edition.

  • Rebuilt on the real topology: one dedicated brain pod per organization, the four hosting options, and console and account.brrain.io roles, replacing v1's invented multi-tenant cloud design.
  • Architect-level depth on the eight zones (Z1-Z8), the governed write path and the invariants that hold under failure.
  • Identity now teaches OIDC SSO with Okta, Entra ID and Google, group-to-role mapping, custom roles and per-project permissions as they work today.
  • The joint-session protocol and Universal Interconnection Principle are taught as methods mapped to real mechanisms, including Robo Compliance auditor access.
  • New modules on AI model architecture (Handler default, LLM Registry, LLMOps, Operator ENV) and integration architecture (MCP Gateway, Exchange MCP, Data Pipe, SDK).
  • Lifecycle and continuity use the real install channel, brrain upgrade, in-place upgrades, brrain dr and brrain export, with no invented SLAs or regions.
  • Assessment is now an online LOFT exam with AI-scored performance tasks and an AI role-play capstone, replacing the v1 project and panel.
Outcomes

What you will be able to do.

  • You will be able to decide organization boundaries, hosting options and project structures for a multi-entity estate and justify them by hard drivers.
  • You will be able to design identity and access with OIDC SSO, group mappings, custom roles, per-project permissions and scoped non-human identities.
  • You will be able to connect outside systems and AI models through governed gateways with the Handler as default and governed opt-ins.
  • You will be able to build governance methods, cross-organization collaboration and auditor access into designs using recorded decisions and corrections.
  • You will be able to threat-model a deployment and design security and compliance evidence without overstating what the platform provides.
  • You will be able to plan upgrades, migrations, offboarding and continuity with the real lifecycle tooling and prove recovery objectives with drills.
  • You will be able to author reference architectures and ADRs and defend an architecture to a review board and a board of directors.

Who it's for

  • Principal engineers and architects responsible for bRRAIn across a large organization or corporate group
  • CTOs and lead architects at partner firms running bRRAIn for many client organizations
  • Platform engineering leads operating bRRAIn as an internal platform
  • Security and enterprise architects who must review and approve bRRAIn designs

Not covered here

  • Building individual integrations end to end (see Integration Engineer)
  • Application development with the SDK (see SDK Developer)
  • Operating governance of what runs on the platform (see Operations Controller — the Platform Architect designs the platform; the Operations Controller governs what runs on it)
Syllabus

15 modules, 129 lessons.

About 40 hours of learning. Open a module to see every lesson.

  1. bRRAIn Architecture for Architects 9 lessons · 3 h

    The eight zones (Z1-Z8), their seams and invariants; the governed write and read paths; client surfaces and how they reach an organization's brain pod.

    1. Module 1 pretest Diagnostic pretest · 5 min
    2. The eight zones and what each one owns Reading · 15 min
    3. The governed write path: Workspaces, Consolidator, Vault Reading · 15 min
    4. The read path: search, context loading and session tools Reading · 15 min
    5. Client surfaces and how they reach the brain pod Reading · 15 min
    6. Zone seams and invariants under failure Scenario · 15 min
    7. Lab 1: Walk a CISO through one request across the zones AI role-play lab · 45 min
    8. Lab 2: Review a design that bypasses the write path AI role-play lab · 45 min
    9. Module 1 retrieval check Retrieval check · 10 min
  2. Estate Topology and Hosting 9 lessons · 3 h

    One organization, one brain pod; choosing hosting options under the Residency Language Prohibition; multi-organization estates; projects as the internal boundary; the split-or-combine decision.

    1. Module 2 pretest Diagnostic pretest · 5 min
    2. One organization, one brain pod Reading · 15 min
    3. Choosing a hosting option Reading · 15 min
    4. Multi-organization estates: groups, subsidiaries and partner-served clients Reading · 15 min
    5. Projects as the internal boundary Reading · 15 min
    6. Worked example: split into organizations or combine into projects? Worked example · 15 min
    7. Lab 3: Design the estate for a three-entity group AI role-play lab · 45 min
    8. Lab 4: Defend a hosting choice to a compliance officer AI role-play lab · 45 min
    9. Module 2 retrieval check Retrieval check · 10 min
  3. Knowledge Architecture and Governance by Design 10 lessons · 3 h 15 min

    Vault information architecture, POPE tagging and the ontology graph, designing for the session method, methodology stage tags and learning capture as defaults, corrections and the Conflict Zone, and search at scale.

    1. Module 3 pretest Diagnostic pretest · 5 min
    2. Vault information architecture: folders, naming and file types Reading · 15 min
    3. POPE tagging and the ontology graph Reading · 15 min
    4. Designing for the session method Reading · 15 min
    5. Methodology stage tags and learning capture as defaults Reading · 15 min
    6. Attribution, corrections and the Conflict Zone Reading · 15 min
    7. Search, indexes and the read limit at scale Scenario · 15 min
    8. Lab 5: Knowledge architecture for three practice areas AI role-play lab · 45 min
    9. Lab 6: Answer a request to retro-edit decision records AI role-play lab · 45 min
    10. Module 3 retrieval check Retrieval check · 10 min
  4. Organization Lifecycle: Install, Upgrade, Migrate, Offboard 9 lessons · 3 h

    Provisioning order, self-hosted install from the release channel, upgrade architecture with pinning and supervised rollback, moving between hosting options with brrain dr migrate, and offboarding with brrain export.

    1. Module 4 pretest Diagnostic pretest · 5 min
    2. Provisioning an organization and its pod Reading · 15 min
    3. Self-hosted install from the release channel Reading · 15 min
    4. Upgrade architecture: checks, pins, supervised rollback, in-place upgrade Reading · 15 min
    5. Moving an organization between hosting options Reading · 15 min
    6. Offboarding and data handover Scenario · 15 min
    7. Lab 7: Write the upgrade policy with an operations lead AI role-play lab · 45 min
    8. Lab 8: A pod was recreated and integrations broke AI role-play lab · 45 min
    9. Module 4 retrieval check Retrieval check · 10 min
  5. Identity and Access Architecture 9 lessons · 3 h

    account.brrain.io and OIDC SSO with Okta, Entra ID and Google; group-to-role mapping; the seven tiers and custom roles; per-project permissions and Nexus surface gating; privileged, automated and break-glass identities.

    1. Module 5 pretest Diagnostic pretest · 5 min
    2. Identity architecture: account.brrain.io, SSO and tokens Reading · 15 min
    3. Designing group-to-role mapping Reading · 15 min
    4. The seven tiers and custom roles Reading · 15 min
    5. Per-project permissions and Nexus surface gating Reading · 15 min
    6. Privileged, automated and break-glass identities Scenario · 15 min
    7. Lab 9: Federate two identity providers after a merger AI role-play lab · 45 min
    8. Lab 10: Review a custom-role design AI role-play lab · 45 min
    9. Module 5 retrieval check Retrieval check · 10 min
  6. Cross-Organization Collaboration 9 lessons · 2 h 30 min

    The Certification Standard's joint-session protocol taught as a method: scoping external access, dual authorization as two recorded approvals, audit, expiry and termination, external auditors on sealed sessions, and the Universal Interconnection Principle.

    1. Module 6 pretest Diagnostic pretest · 5 min
    2. The joint-session protocol as a method, not a feature Reading · 15 min
    3. Scoping access for an external party Reading · 15 min
    4. Dual authorization as two recorded approvals Reading · 15 min
    5. Audit, expiry and termination Reading · 15 min
    6. External auditors: sealed sessions and the auditor portal Reading · 15 min
    7. Applying the Universal Interconnection Principle Scenario · 15 min
    8. Lab 11: Design a cross-organization engagement AI role-play lab · 45 min
    9. Module 6 retrieval check Retrieval check · 10 min
  7. AI Model and Agent Architecture 9 lessons · 3 h

    The Handler as default model, commercial models through the LLM Registry, LLMOps model governance, Security Policy Engine rules for model calls, and agents with service identities and Operator ENV credentials.

    1. Module 7 pretest Diagnostic pretest · 5 min
    2. The Handler as the default model Reading · 15 min
    3. Commercial models through the LLM Registry Reading · 15 min
    4. LLMOps: model cards, evaluations and drift Reading · 15 min
    5. Data-handling policy for model calls Reading · 15 min
    6. Agents, service identities and Operator ENV Scenario · 15 min
    7. Lab 12: Model-routing decision with a CFO and a CISO AI role-play lab · 45 min
    8. Lab 13: Run an LLMOps drift review AI role-play lab · 45 min
    9. Module 7 retrieval check Retrieval check · 10 min
  8. Operations, Capacity and Continuity 9 lessons · 2 h 30 min

    Observability signals, alerting and runbooks, setting and proving RPO and RTO, continuity drills with brrain dr, capacity planning for pods and vaults, and client resilience with the Nexus Mobile outbox.

    1. Module 8 pretest Diagnostic pretest · 5 min
    2. Observability for a bRRAIn estate Reading · 15 min
    3. Alerting and runbooks Reading · 15 min
    4. Setting and proving RPO and RTO Reading · 15 min
    5. Worked example: a continuity drill with brrain dr Worked example · 15 min
    6. Capacity: pod sizing and vault growth Reading · 15 min
    7. Client resilience: the Nexus Mobile outbox and offline limits Reading · 15 min
    8. Lab 14: Continuity plan for a regulated organization AI role-play lab · 45 min
    9. Module 8 retrieval check Retrieval check · 10 min
  9. Compliance Architecture 9 lessons · 3 h

    The responsibility line between bRRAIn and the customer, Robo Compliance in the architecture, and architecture decisions for SOC 2, HIPAA and GDPR programs.

    1. Module 9 pretest Diagnostic pretest · 5 min
    2. What the platform provides and what the customer owns Reading · 15 min
    3. Robo Compliance in the architecture Reading · 15 min
    4. SOC 2: architecture decisions that produce evidence Reading · 15 min
    5. HIPAA: architecture decisions for protected health information Reading · 15 min
    6. GDPR: rights requests, erasure and residency language Reading · 15 min
    7. Lab 15: Compliance architecture for a health-services group AI role-play lab · 45 min
    8. Lab 16: Walk an external auditor through the evidence AI role-play lab · 45 min
    9. Module 9 retrieval check Retrieval check · 10 min
  10. Security Architecture 9 lessons · 3 h

    Threat modeling for AI memory, zero trust at every boundary, designing with the Security Policy Engine, the Code Sandbox and extension isolation, and preventing leakage across organizations.

    1. Module 10 pretest Diagnostic pretest · 5 min
    2. Threat modeling an AI-memory deployment Reading · 15 min
    3. Zero trust at every boundary Reading · 15 min
    4. Designing with the Security Policy Engine Reading · 15 min
    5. Code Sandbox and extension isolation Reading · 15 min
    6. Preventing leakage across organizations in an estate Scenario · 15 min
    7. Lab 17: Threat model a firm's bRRAIn deployment AI role-play lab · 45 min
    8. Lab 18: Respond to a red-team finding AI role-play lab · 45 min
    9. Module 10 retrieval check Retrieval check · 10 min
  11. Integration Architecture 9 lessons · 2 h 30 min

    Governed gateways; the MCP Gateway with Exchange MCP and the Tool Registry; Data Pipe and document ingestion; the Platform SDK and extensions; outbound events through the Notifier; choosing integration patterns.

    1. Module 11 pretest Diagnostic pretest · 5 min
    2. Governed gateways: the integration rule Reading · 15 min
    3. MCP Gateway, Exchange MCP and the Tool Registry Reading · 15 min
    4. Data Pipe and document ingestion Reading · 15 min
    5. Platform SDK and extensions Reading · 15 min
    6. Outbound events: Notifier and webhooks Reading · 15 min
    7. Worked example: choosing the integration pattern Worked example · 15 min
    8. Lab 19: Integration architecture for a firm's systems AI role-play lab · 45 min
    9. Module 11 retrieval check Retrieval check · 10 min
  12. Reference Architectures and the Pattern Library 8 lessons · 2 h 15 min

    Authoring buildable reference architectures on real capabilities, curating the pattern library in the vault, deprecating patterns safely, running the architecture review board, and mentoring builders.

    1. Module 12 pretest Diagnostic pretest · 5 min
    2. Authoring reference architectures others build against Reading · 15 min
    3. Curating the pattern library Reading · 15 min
    4. Deprecating patterns without breaking organizations Reading · 15 min
    5. Running the architecture review board Reading · 15 min
    6. Mentoring Integration Engineers and SDK Developers Scenario · 15 min
    7. Lab 20: Author a reference architecture AI role-play lab · 45 min
    8. Module 12 retrieval check Retrieval check · 10 min
  13. Architecture Decision Records 7 lessons · 2 h

    The ADR format, decisions that survive turnover, keeping ADRs in the vault with record_decision and supersession, and build-versus-buy decisions.

    1. Module 13 pretest Diagnostic pretest · 5 min
    2. The ADR format Reading · 15 min
    3. Decisions that survive turnover Reading · 15 min
    4. Keeping ADRs in the vault Reading · 15 min
    5. Build-versus-buy decisions Scenario · 15 min
    6. Lab 21: Write three ADRs and defend one AI role-play lab · 45 min
    7. Module 13 retrieval check Retrieval check · 10 min
  14. Board-Level Architecture Communication 7 lessons · 2 h

    The one-page architecture summary, communicating risk with the Risk & Contingency standard, communicating cost with the current commercial model, and communicating strategic implications.

    1. Module 14 pretest Diagnostic pretest · 5 min
    2. The one-page architecture summary Reading · 15 min
    3. Communicating architectural risk Reading · 15 min
    4. Communicating cost Reading · 15 min
    5. Communicating strategic implications Reading · 15 min
    6. Lab 22: Present a one-page summary to a board member AI role-play lab · 45 min
    7. Module 14 retrieval check Retrieval check · 10 min
  15. Architecture Review Defense and Capstone 7 lessons · 2 h

    Structuring an architecture presentation, anticipating reviewer questions, articulating trade-offs, handling challenge, and the capstone architecture review.

    1. Module 15 pretest Diagnostic pretest · 5 min
    2. Structuring an architecture presentation Reading · 15 min
    3. Anticipating reviewer questions Reading · 15 min
    4. Articulating trade-offs Reading · 15 min
    5. Handling challenge without conceding the design Scenario · 15 min
    6. Capstone: Architecture review for Halvorsen & Pike AI role-play lab · 45 min
    7. Module 15 retrieval check Retrieval check · 10 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · bRRAIn Architecture for Architects

    A CISO's request to trace one assistant request across the zones

  • Lab 2 · bRRAIn Architecture for Architects

    Review of an integration that writes to the vault volume, edits records in place and posts full records to a partner channel

  • Lab 3 · Estate Topology and Hosting

    Estate design for a three-entity group with an EU subsidiary and competing clients

  • Lab 4 · Estate Topology and Hosting

    A compliance officer demanding a 'never leaves the EU' guarantee

  • Lab 5 · Knowledge Architecture and Governance by Design

    Knowledge architecture for a firm with three practice areas and confidential forensic work

  • Lab 6 · Knowledge Architecture and Governance by Design

    A managing partner asking to retro-edit decision records before a client review

  • Lab 7 · Organization Lifecycle: Install, Upgrade, Migrate, Offboard

    An operations head who wants automatic same-day upgrades across 22 organizations

  • Lab 8 · Organization Lifecycle: Install, Upgrade, Migrate, Offboard

    Incident after a pod recreation broke MCP clients and a Data Pipe connector

  • Lab 9 · Identity and Access Architecture

    Federating Okta and Entra ID after a merger with overlapping group names

  • Lab 10 · Identity and Access Architecture

    Review of a law firm's broken custom roles and broad matter grants

  • Lab 11 · Cross-Organization Collaboration

    An Operations Controller who wants to make an outside consultancy Operators for 60 days

  • Lab 12 · AI Model and Agent Architecture

    A CFO and a CISO with opposing views on commercial models

  • Lab 13 · AI Model and Agent Architecture

    An LLMOps drift alert after a provider model change

  • Lab 14 · Operations, Capacity and Continuity

    A risk officer demanding 'zero data loss' for a self-hosted clinic group

  • Lab 15 · Compliance Architecture

    Compliance architecture for a group with HIPAA, SOC 2 and GDPR obligations

  • Lab 16 · Compliance Architecture

    An external auditor's fieldwork questions on evidence integrity

  • Lab 17 · Security Architecture

    Threat-modeling session with a firm's head of security

  • Lab 18 · Security Architecture

    A prompt-injection red-team finding through an ingested PDF and an over-scoped MCP server

  • Lab 19 · Integration Architecture

    An integration lead who wants one admin token and direct vault database access

  • Lab 20 · Reference Architectures and the Pattern Library

    An Integration Engineer trying to build from your reference architecture

  • Lab 21 · Architecture Decision Records

    A principal engineer reviewing three ADRs

  • Lab 22 · Board-Level Architecture Communication

    A non-executive director preparing for a board meeting

  • Lab 23 · Architecture Review Defense and Capstone

    Full architecture review of Halvorsen & Pike before a CTO and a CISO

Capstone

Architecture review for Halvorsen & Pike

AI role-play scored against the published rubric

Pass mark: 75%

Scored on

  • Estate and hosting topology20%
  • Identity and access architecture15%
  • Integration and AI model governance15%
  • Governance methods and cross-organization access15%
  • Security, compliance and continuity20%
  • Decision records and communication15%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
66
Time allowed
180 min
Pass mark
75%
Performance tasks
6
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 3 years.
  • Renewal: At 3 years by passing the then-current exam; CE modules keep the credential current between renewals
Before and after

Where this course sits.

Prerequisites

Stacks well with

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 66 items in 180 minutes, on a form assembled for you from the course's item bank. 6 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 75%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Also in bRRAInDev

Related courses.

See every bRRAInDev course · Full catalog

Enroll

bRRAIn Certified Platform Architect

Design, govern and defend bRRAIn estates: organizations, hosting, identity, integrations, models, security and continuity.