Compensating Layers Pattern: Visual Routing and Constraints in Diagram Design
The compensating security layers pattern routes to the Layer-stack visual type and requires diagrams to display 3–5 ordered defensive layers with explicit residual risk propagation between each stage.
The compensating layers pattern is a semantic routing rule in the cathrynlavery/diagram-design repository that maps security architecture concepts to specific visual representations. When modeling defense-in-depth strategies where each control addresses gaps left by the previous one, this pattern ensures diagrams maintain clarity about residual risk rather than implying complete elimination.
Visual Type Routing
According to the semantic-patterns routing table in skills/diagram-design/references/semantic-patterns.md at line 17, the Compensating security layers semantic pattern explicitly routes to the Layer-stack visual type. This mapping distinguishes ordered compensation flows from containment relationships that might otherwise use Nested diagrams.
The routing decision appears in the reference documentation alongside seven other behavioral patterns, establishing Layer-stack as the default visualization when the meaning depends on sequential risk mitigation rather than hierarchical containment.
Pattern Constraints and Requirements
The pattern enforces six categories of constraints defined at line 104 of skills/diagram-design/references/semantic-patterns.md. These rules prevent misleading security postures and ensure accurate risk communication.
Selection Triggers
Each layer must demonstrably address a failure left by the preceding layer. The diagram must visually represent how residual risk narrows, transfers, or remains after each mitigation stage, creating a clear propagation chain from initial threat to final residual state.
Required Primitives
Valid diagrams must include six mandatory elements:
- Ordered threat or risk input
- Named defensive layers
- Mitigation description per layer
- Explicit limitation or escape clause per layer
- Residual-risk carrier between layers
- Final residual-risk statement
Complexity Budget
The strict complexity budget limits diagrams to:
- 3–5 layers maximum
- One primary risk thread
- Maximum two mitigations per layer
- One final residual-risk statement
Anti-Patterns to Avoid
Designers must avoid four specific misleading representations:
- Implying the final layer eliminates risk completely
- Rendering equal opaque slabs without visible risk propagation
- Treating audit mechanisms as preventive controls
- Using shrinking shapes without numeric or verbal explanation of the reduction
Static Fallback and Alternatives
When dynamic rendering fails, the static fallback requires showing the full propagation chain: initial risk → mitigation → escaped risk at each layer → final residual risk. Use the Nested visual type only when containment boundaries—not ordered compensation—carry the semantic meaning.
Implementation Examples
The repository supports both JSON and YAML definitions for pattern instances.
JSON Definition
{
"semanticPattern": "Compensating security layers",
"layers": [
{
"name": "Firewall",
"mitigation": "Block unauthorized inbound traffic",
"escapes": "Limited to known ports"
},
{
"name": "IDS/IPS",
"mitigation": "Detect & block suspicious payloads",
"escapes": "Zero‑day exploits may slip through"
},
{
"name": "Application‑level hardening",
"mitigation": "Input validation & sandboxing",
"escapes": "Logic flaws remain"
}
],
"finalResidualRisk": "Limited to targeted phishing attacks"
}
YAML Definition (CLI Format)
semanticPattern: Compensating security layers
layers:
- name: Firewall
mitigation: Block unauthorized inbound traffic
escapes: Limited to known ports
- name: IDS/IPS
mitigation: Detect & block suspicious payloads
escapes: Zero‑day exploits may slip through
- name: App hardening
mitigation: Input validation & sandboxing
escapes: Logic flaws remain
finalResidualRisk: Limited to targeted phishing attacks
Both examples respect the 3–5 layer budget and include the mandatory finalResidualRisk field required by the pattern constraints.
Summary
- The compensating layers pattern routes to the Layer-stack visual type as defined in
skills/diagram-design/references/semantic-patterns.md. - Diagrams must contain 3–5 ordered layers with explicit risk propagation between each stage.
- Each layer requires mitigation descriptions and escape limitations to show residual risk carriers.
- The Nested visual type serves only as an alternative when containment rather than ordered compensation is the primary semantic.
- Valid implementations must provide a final residual-risk statement and avoid implying complete risk elimination.
Frequently Asked Questions
What visual type does the compensating layers pattern use?
The pattern routes to the Layer-stack visual type according to the routing table at line 17 of skills/diagram-design/references/semantic-patterns.md. This visualization emphasizes ordered defensive layers and sequential risk reduction rather than hierarchical containment.
How many layers can a compensating layers diagram contain?
The complexity budget restricts diagrams to 3–5 layers maximum. This constraint ensures the diagram remains readable while accurately representing defense-in-depth without oversimplifying the security architecture.
What is the difference between Layer-stack and Nested visual types for this pattern?
Use Layer-stack when the semantic meaning depends on ordered compensation—where each layer addresses failures left by the previous one. Reserve Nested visual types for scenarios where containment boundaries carry the primary meaning rather than sequential risk mitigation flows.
What must be included in the final layer of a compensating layers diagram?
The final layer must include an explicit residual-risk statement showing what risk remains after all mitigations. The pattern strictly prohibits implying that the final layer eliminates risk completely; diagrams must show the final escaped or residual risk state.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →