Review Discovery as a connected document set
Trace a requirement through the specification, architecture, data flow, and security documents. Handle revisions before planning depends on stale assumptions.
Published by TaigaHow we write
What you will learn
- Explain why document order and publication state matter.
- Find the impact of a changed specification on dependent documents.
- Distinguish generated, published, reviewed, and outdated content.
Follow one requirement through the set
This scenario continues the fictional equipment request service. The first specification allows managers to enter requests. The team then adds employee self-service.
That change affects more than a screen. Employees need an identity and access to their own requests. Manager visibility needs a defined boundary. The data flow and security analysis must reflect both roles.
Use Discovery’s Context, Conversation, and Documents steps to establish and inspect that intent. For an imported product, repository analysis replaces the conversation; follow the separate import workflow.
Know the required documents
There are eight required documents, including the specification:
| Document | Question to check in this scenario |
|---|---|
| Specification | Who may request equipment and for what purpose? |
| User flows | How does an employee submit and track a request? |
| Architecture | Where is the access decision enforced? |
| Technology decisions | Does the design use the approved identity and data services? |
| Data flow | Which components receive employee and request data? |
| DPIA | Does the privacy assessment reflect the actual processing? |
| Threat model | Can one employee read another employee’s request? |
| Risk register | Who owns each unresolved risk and its treatment? |
Generation follows dependencies and publication order. Review an early document before accepting the assumptions that later documents use. A generated DPIA is assessment material; its presence does not itself establish legal compliance.
Look & Feel and Service Blueprint are optional. Use them when a rendered interface direction or a service description helps the team assess the product.
Distinguish publication from review
The specification begins as a draft. Downstream generation uses the published version. Editing creates a new draft; the changes take effect downstream when you publish the new version.
Other documents carry publication and review information. Generate remaining can generate the missing set in sequence, with each result needing review. Generation finishing is not a human conclusion that the assumptions are correct.
For the equipment service, inspect the access rule in all relevant documents. A correct specification and an outdated data flow are not a consistent design.
Handle changes deliberately
When you republish the specification, dependent generated documents can become Outdated. Taiga does not silently rewrite them. A change to another source document can also affect documents further down the chain.
Regenerate affected documents while Discovery is open. Generate remaining includes outdated documents. Inspect the new results, especially assumptions that changed across several documents.
All eight required documents must be published before Finish Discovery becomes available. An Outdated document does not prevent finishing. Check consistency yourself rather than treating the button as evidence that every review is complete.
Finishing locks the set and opens the downstream product workflow. Reopen Discovery from a document when you need to change a locked set.
Hand a coherent intent to planning
Before planning, state the current user roles, accepted constraints, and unresolved decisions. Check that the initiative proposals cite documents that describe the same product.
A useful review result is concrete: “Employee self-service is reflected in the flows, authorization design, data flow, and threat treatment.” Continue with initiatives to turn that intent into work.
Do the exercise
The fictional equipment service changes from manager-only use to employee self-service. Identify the effects on user flows, architecture, data flow, DPIA, threat model, and risk register. Describe which documents you would inspect or regenerate before finishing Discovery.
Download worksheet (Markdown)Check your understanding
Sources & further reading
Clearing this selection deletes all progress saved in this browser.
Progress stays in this browser. No account, no tracking.