Concepts Overview
PRISM provides a multi-dimensional model for organizing metrics, ownership, and maturity tracking across your organization.
The PRISM Model
PRISM organizes metrics using four key dimensions:
| Dimension | Purpose | Values |
|---|---|---|
| Domain | Functional area with standards | operations, security, quality |
| Layer | Ownership boundary in stack | code, infra, runtime |
| Stage | Lifecycle phase | design, build, test, runtime, response |
| Category | Type of control | prevention, detection, response, reliability, efficiency, quality |
These dimensions work together to classify every metric and clarify accountability.
Organizational Model
Domains
Domains represent functional areas with overlay teams that define standards:
| Domain | Description | Overlay Team |
|---|---|---|
| Operations | Reliability, performance, efficiency | SRE/Platform |
| Security | AppSec, CloudSec, compliance | Security Team |
| Quality | Testing, code quality, defects | QE Team |
Layers
Layers represent the full value stream from ideation to support:
| Layer | Description | Typical Owner |
|---|---|---|
| Requirements | Product ideation, specs, design | Product/Design |
| Code | Application code, libraries, dependencies | Stream-aligned teams |
| Infra | Cloud resources, networking, platform | Platform team |
| Runtime | Running services, production workloads | Stream-aligned + SRE |
| Adoption | Product analytics, user engagement | Product/Growth |
| Support | Customer support, incident management | Support/CS |
Each layer can define golden signals (latency, traffic, errors, saturation) pointing to specific metrics.
Teams
Teams follow the Team Topologies model for clear accountability:
| Type | Role | Owns |
|---|---|---|
| Stream-Aligned | Build and run services | Services, code/runtime metrics |
| Platform | Provide infrastructure | Infrastructure layer |
| Enabling | Help adopt practices | Cross-team capabilities |
| Overlay | Define standards | Domain standards |
Services
Services are deployable units that connect teams, layers, and metrics:
- Owned by a team
- Deployed in a layer
- Associated with metrics and SLOs
Metrics and SLOs
Metric Classification
Every metric belongs to:
- A domain (what functional area)
- A stage (when in lifecycle)
- A category (what type of control)
- Optionally a layer (where in stack)
- Optionally a service (which system)
- Optionally a quality vertical (ISO 25010 characteristic)
SLO Definition
Metrics can have machine-evaluable SLOs:
Maturity Roadmap
Goals
Goals represent strategic objectives with SLO-backed maturity levels:
- Define 5-level maturity progression
- Specify which SLOs must be met at each level
- Track progress from Reactive to Optimizing
Phases
Phases organize work into time-bounded periods (quarters):
- Set goal maturity targets (enter/exit levels)
- Group initiatives into swimlanes
- Track completion and SLO compliance
Connecting It All
The PRISM model creates a clear chain of accountability:
Example flow:
- Payments Team (stream-aligned) owns Payments API (service)
- Payments API has Availability metric (operations/runtime/reliability)
- Availability has SLO:
>=99.99%over 30 days - Reliability Goal requires this SLO at Level 4
- Q2 2026 Phase targets Reliability Goal from Level 3 to Level 4
- Security Team (overlay) defines security standards that apply to all services
Scoring
PRISM Score
A composite health score (0.0-1.0) combining:
- Maturity scores (40% weight) - organizational capability
- Performance scores (60% weight) - metric achievement
- Awareness multiplier - customer communication effectiveness
Customer Awareness
Track customer awareness through four states:
| State | Weight | Description |
|---|---|---|
| Unaware | 0.0 | Customer not aware |
| Aware (not acting) | 0.25 | Aware but not remediating |
| Remediating | 0.5 | Actively working on fix |
| Remediated | 1.0 | Issue resolved |
Framework Mappings
Map metrics to industry standards:
- DORA metrics
- SRE practices
- NIST Cybersecurity Framework
- MITRE ATT&CK
Getting Started
- Define your organizational model
- Identify domains relevant to your org
- Map teams to Team Topologies types
-
List services and their ownership
-
Define metrics
- Classify by domain, stage, layer
- Set baselines and targets
-
Define SLOs with operators
-
Create goals
- Define maturity levels
- Specify SLO requirements per level
-
Link initiatives to goals
-
Plan phases
- Set quarterly goal targets
- Organize initiatives into swimlanes
-
Track progress and SLO compliance
-
Calculate and report
- Generate PRISM scores
- Create roadmap reports
- Track maturity progression