system-architect

Design security-first system architectures for multi-tenant SaaS applications.

9|2|Updated Dec 10, 2025
One-click install
npx skills add https://github.com/ilandahan/AID --skill system-architect-ilandahan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: system-architect
Source: https://github.com/ilandahan/AID/tree/main/.claude/skills/system-architect
Command: npx skills add https://github.com/ilandahan/AID --skill system-architect-ilandahan

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

System Architect consolidates security-first principles and ISO 27001 controls to help teams design robust, scalable software architectures.

Core Features & Use Cases

  • Architecture reviews and security-focused design guidance for multi-tenant SaaS
  • Threat modeling, secure SDLC alignment, and ISO 27001 control mapping
  • API design, cloud infrastructure planning, and data protection strategy

Quick Start

Design a secure, multi-tenant SaaS architecture outline including data flow, components, and controls.

Frequently Asked Questions about system-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a secure multi-tenant SaaS architecture?

Threat modeling identifies potential security threats and aligns with a secure SDLC to mitigate risks early. It maps directly to ISO 27001 controls, ensuring compliance checkpoints are integrated across architecture artifacts.

How does ISO 27001 control mapping work for system architecture?

RBAC implementation in multi-tenant SaaS requires enforcing strict role-based access controls alongside encryption and audit logging. Defense in depth strategies further secure data flow, components, and API endpoints across the architecture.

What is the best way to map ISO 27001 controls to architecture artifacts?

Defense in depth applies multiple layers of security controls including encryption, RBAC, and audit logging across cloud infrastructure. This strategy protects multi-tenant SaaS architectures by securing data flow, components, and API endpoints comprehensively.

Can I use this approach for API design and cloud infrastructure planning?

A secure SDLC integrates threat modeling, compliance checkpoints, and security reviews into the development lifecycle. This alignment ensures robust, scalable software architectures meet ISO 27001 controls and data protection requirements.

Do I need threat modeling to align with a secure SDLC?

Audit logging enforces accountability and supports compliance checkpoints within multi-tenant SaaS architectures. Combined with encryption and RBAC, it ensures data protection strategy and defense in depth across all architecture artifacts.