Architecture governance has two problems that every team eventually runs into. The first is getting started: translating the organisation's real obligations into a structured set of directives that can actually be enforced. The second is knowing whether the governance you have built is working. Not just whether projects are being reviewed, but whether the rules you wrote are being followed, which ones are being challenged, and where the architecture team's attention needs to go.
cajeX has shipped two features that address both of these problems directly. Neither is a minor update. Together, they change what it means to adopt architecture governance on the platform and what architecture teams can know about the state of their own standards.
Feature One: The Frameworks Library
304 frameworks · available nowArchitecture governance has a blank-page problem. Every team knows they need to translate their regulatory obligations into enforceable directives. Almost no team has the time or the framework expertise to build that library from scratch, and most governance programmes stall before they finish it.
The Frameworks Library solves this. 304 regulatory and industry frameworks are now available directly inside cajeX, each pre-mapped into structured directives ready for AI review. The library spans the full range of what modern organisations are actually governed by:
- European regulation: NIS2, DORA, GDPR, EU AI Act, the Cyber Resilience Act, eIDAS 2.0
- Global privacy: UK GDPR, Switzerland nFADP, Singapore PDPA, Saudi PDPL, CCPA/CPRA
- Financial and operational resilience: DORA, APRA CPS 234/230, MAS TRM, UK FCA/PRA Operational Resilience, Basel
- Information security: ISO 27001, NIST CSF 2.0, CIS Controls, SOC 2, CMMC 2.0, FedRAMP
- AI governance: ISO 42001, NIST AI RMF, EU AI Act, Singapore Model AI Governance Framework
- Industry-specific: IATF 16949 (automotive), 21 CFR Part 11 (pharma), DO-178C (aerospace), HL7 FHIR (healthcare)
Select the frameworks that apply to your workspace, review the clause-to-directive mappings cajeX suggests, approve what fits, refine what does not. Your first project review runs against a governed directive set from day one.
Figure 1 — 304 frameworks across eight categories, each pre-mapped into structured directives ready for AI review.
What makes this different from a compliance checkbox tool is the model underneath it. cajeX treats each framework clause as a question that expects a specific, justified answer from your organisation. NIS2 §21 is not asking you to tick a box. It is asking how your organisation handles cybersecurity risk management and whether you can prove it. Your directive is your organisation's answer. cajeX suggests the mapping; the architect reviews it, refines it where needed, and approves it. The decision stays with the team.
The compliance posture this builds is evidence, not a score. Every finding carries the full trail: framework, clause, directive, evidence. You can drill from any framework through its clauses to the specific directive and finding that supports or challenges it. No black-box verdict, and no conclusion the platform asserts for you.
Figure 2 — From framework selection to first project review in minutes, not months.
For teams with NIS2, DORA, or EU AI Act obligations, this is the fastest path from regulatory exposure to demonstrable evidence. Days, not months.
This also changes who can adopt cajeX. Previously, getting the most from the platform required a team that had already done significant governance work. The Frameworks Library means a team with strong regulatory obligations but limited internal governance infrastructure can start reviewing projects against real, approved standards on day one. For more on what directives are and how they work, see What Are Architecture Directives.
Feature Two: Directive Intelligence
Part of the Intelligence module — comingEvery finding the cajeX AI co-worker produces is evidence about a rule, not just a problem found in a project. The directive is the question. The finding is the answer. What was missing was the connection in the other direction: from the directive back to the findings it has produced across all projects.
That loop is now closed. Every finding shows the directive it maps to. Every directive shows its current conformance status, calculated live from the findings it has generated: conformant, partially conformant, non-conformant, or not yet evaluated. Across the portfolio, the dashboard surfaces the directives generating the most open findings, giving architecture teams a clear signal about where their attention needs to go.
Figure 3 — Directive Intelligence. Every review produces evidence. Evidence updates the directive. Governance learns.
In practice, this means the architecture team gets a portfolio-level view of which directives are holding and which are being consistently challenged. A directive that generates eight open non-conformant findings across six projects is telling you something specific — and the platform now makes that visible directly rather than requiring someone to manually trawl through findings data to spot the pattern.
Figure 4 — Portfolio conformance view. See which directives are holding, which are being challenged, and which have never been tested.
Why this matters
The strategic shift this enables is from governance as administration to governance as intelligence.
Before this feature, cajeX could tell you whether individual projects were compliant. Now it can tell you whether your standards themselves are working. That is a different question, and for architecture teams it is often the more important one.
When a directive consistently generates findings across multiple projects, that pattern carries information. The rule may be unclear: project teams are not understanding what the directive requires. It may be unrealistic: the standard creates friction that teams work around rather than through. Or it may need updating because the technology landscape has evolved and the directive no longer reflects how the organisation actually builds things.
Without visibility into which directives are generating the most findings, the architecture team is guessing about all of this. Directive Intelligence makes this visible. It converts the output of every review into a feedback signal about the quality and clarity of the governance standard itself. Governance stops being a one-way process and becomes a learning loop: findings inform directive quality, directives improve, governance gets better.
Shi's post, Findings That Prove Your Directives, explains the design in detail, including how conformance is computed live rather than stored as a snapshot so the status always reflects the current state of evidence.
What These Features Mean Together
The Frameworks Library solves the getting-started problem. Directive Intelligence solves the knowing-if-it's-working problem. Together, they address the full lifecycle of a governance standard: from the moment it enters the system to the moment it needs to be reconsidered.
A team adopting cajeX today can start with the Frameworks Library to get a governed directive set immediately, add organisation-specific directives alongside the framework-derived ones, review projects against the full active set, and use the findings data as feedback. The directives generating the most friction surface clearly. The architecture team knows exactly where to focus its communication and education effort. The full clause-to-finding trail means every piece of evidence is inspectable and every conclusion is yours to reach.
Both features are available now. The Frameworks Library is accessible from workspace setup and from the Frameworks tab. Directive conformance is visible on every directive page and on the main dashboard.