Skip to content
Mike Reams

03 — 18 resources · 8 roles · checked 2026-10-03

Architect's Toolbox Guide

Pick the job before the tool. Tools, methods and learning resources for eight architecture roles: what each one helps you produce, what to check first, and the sources behind every fact.

What Is in the Guide

Tools
Software you install, run in a browser or subscribe to.
Methods and Standards
Frameworks, notations, bodies of knowledge and practice guidance. Not software.
Learning
Lessons and reference material for building the skill.

These are starting points, not endorsements or a procurement shortlist. Nothing here is sponsored, and the list is alphabetical, not ranked. For the platforms I have worked with myself, see Technology.

Start with Your Role

Each guide is a starting workflow: the question, what to produce, the steps and the resources that fit.

Resources

Alphabetical, not ranked. Open Details for the evidence behind each one, or pick two or three tools to compare.

  • ToolResearched

    Archi

    Phillip Beauvoir and Jean-Baptiste Sarrodie

    A free desktop editor for building ArchiMate models, views and sketches.

    Access
    No cost; some plugins are for supporters only
    Fits
    Enterprise Architect, Business Architect
    Details for Archi
    Use it when
    • You want to learn or apply ArchiMate without a license budget.
    • One person or a small team keeps models in files under version control.
    Helps you produce
    • ArchiMate models and views
    • Sketch views
    • Scripted reports (with the jArchi plugin)
    Think twice
    Team work depends on git-based collaboration plugins; check which version you need and whether it is for supporters only. (editorial)
    Deployment
    Desktop app
    License
    MIT
    AI features
    Not found on reviewed pages
    Edition
    5.10.0 (September 2026)
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • Method or StandardI've used it

    ArchiMate

    The Open Group

    The Open Group's standard visual language for modeling business, application and technology architecture together.

    Access
    Free for non-commercial use, with registration; commercial use needs a license
    Fits
    Enterprise Architect, Business Architect, Solution Architect
    Details for ArchiMate
    Use it when
    • Several architects must read each other's models the same way.
    • Views must connect strategy, business, applications and technology.
    Helps you produce
    • Layered architecture views
    • Capability and application cooperation views
    • Model exchange files
    Think twice
    It pays off only with a tool and modeling discipline behind it; read the license before commercial use. (editorial)
    Deployment
    Not applicable
    License
    Open Group license
    AI features
    Not applicable
    Edition
    ArchiMate 4
    Experience
    Mike has used this in his own work. See it on my Technology page.
    Sources
    Checked
    October 3, 2026
  • Method or StandardResearched

    Architecture Decision Records

    Michael Nygard; ADR community

    A short record of each significant design decision: the context, the choice and its consequences.

    Access
    No cost
    Fits
    Solution Architect, Software Architect, Enterprise Architect
    Details for Architecture Decision Records
    Use it when
    • A decision will be questioned later by people who were not in the room.
    • You want design reviews to leave a trail.
    Helps you produce
    • Decision records
    • A decision log
    Think twice
    A template doesn't create the habit; decide where records live and who writes them. (editorial)
    Deployment
    Not applicable
    License
    Original post CC0; adr.github.io MIT
    AI features
    Not applicable
    Edition
    Practice described by Michael Nygard in 2011
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • ToolI've used it

    Ardoq

    Ardoq AS

    A SaaS enterprise architecture platform that keeps applications, capabilities and dependencies in one graph for planning and governance.

    Access
    Commercial subscription, priced per application
    Fits
    Enterprise Architect, Business Architect
    Details for Ardoq
    Use it when
    • The portfolio needs one shared inventory that many teams update.
    • You plan change with scenarios rather than single diagrams.
    Helps you produce
    • Application portfolio views
    • Capability maps and value streams
    • Future-state scenarios and roadmaps
    • Dependency views
    Think twice
    Ask which AI features are generally available, which are on the roadmap and which cost extra. (editorial)
    Deployment
    Vendor-hosted (SaaS)
    License
    Proprietary
    AI features
    Documents an AI assistant, AI-generated capability maps and value streams, and an MCP server; some listed items are roadmap entries or paid add-ons.
    Experience
    Mike has used this in his own work. See it on my Technology page.
    Sources
    Checked
    October 3, 2026
  • Method or StandardResearched

    Azure Well-Architected Framework

    Microsoft

    Microsoft's design principles, checklists and trade-offs for reliable, secure and cost-aware workloads on Azure.

    Access
    No cost
    Fits
    Cloud and Platform Architect, Solution Architect
    Details for Azure Well-Architected Framework
    Use it when
    • You are designing or reviewing a workload that runs on Azure.
    • Reliability, security and cost need to be weighed together.
    Helps you produce
    • Workload design reviews
    • Pillar checklists
    • Recorded trade-off decisions
    Think twice
    Azure-specific in its detail, although the pillars carry over to other clouds. (editorial)
    Deployment
    Not applicable
    License
    Docs CC BY 4.0
    AI features
    Not applicable
    Edition
    Not versioned; updated September 2026
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • Method or StandardResearched

    BIZBOK Guide

    Business Architecture Guild

    The Business Architecture Guild's body of knowledge for capability maps, value streams and related business blueprints.

    Access
    Introduction and glossary free; full guide for members
    Fits
    Business Architect, Enterprise Architect
    Details for BIZBOK Guide
    Use it when
    • You are building a first capability map and want a common vocabulary.
    • Business and IT disagree on what a capability is.
    Helps you produce
    • Capability maps
    • Value streams
    • Information and organization maps
    Think twice
    Most of the substance is for members only; the free parts are an introduction. (editorial)
    Deployment
    Not applicable
    License
    Not stated
    AI features
    Not applicable
    Edition
    v15.0
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    • Free resources (Business Architecture Guild) (opens in a new tab)
    • Resources (Business Architecture Guild) (opens in a new tab)
    Checked
    October 3, 2026
  • ToolBuilt by Mike

    Blueprint Modeler

    Mike Reams

    A free, browser-only canvas for modeling applications in ServiceNow CSDM, with rules that flag invalid relationships as you draw.

    Access
    No cost, no sign-up
    Fits
    Enterprise Architect, Solution Architect, Cloud and Platform Architect
    Details for Blueprint Modeler
    Use it when
    • You need a CSDM-shaped picture of one application before it goes into the CMDB.
    • You want to check relationships against public CSDM guidance.
    Helps you produce
    • CSDM application models
    • ArchiMate-notation views
    • SVG, draw.io and ServiceNow import files
    Think twice
    Models live in your browser, so export regularly. It is a new tool with one maintainer and no affiliation with ServiceNow. (editorial)
    Deployment
    Runs in your browser
    License
    MIT
    AI features
    None
    Experience
    Built by Mike Reams, who writes this guide. Listed in the same order and checked against the same rules as everything else.
    Sources
    • README (Blueprint Modeler on GitHub) (opens in a new tab)
    • LICENSE (Blueprint Modeler on GitHub) (opens in a new tab)
    Checked
    October 3, 2026
  • Method or StandardResearched

    C4 model

    Simon Brown

    A simple way to diagram software at four levels of zoom: context, containers, components and code.

    Access
    No cost
    Fits
    Solution Architect, Software Architect, Cloud and Platform Architect
    Details for C4 model
    Use it when
    • Developers and stakeholders need the same picture at different levels of detail.
    • You want a notation-light alternative to UML.
    Helps you produce
    • System context diagrams
    • Container and component diagrams
    • Deployment diagrams
    Think twice
    It deliberately skips business and enterprise views; pair it with something else for those. (editorial)
    Deployment
    Not applicable
    License
    CC BY 4.0
    AI features
    Not applicable
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • Method or StandardResearched

    DAMA-DMBOK

    DAMA International

    DAMA's reference body of knowledge for data management: governance, modeling, quality, metadata and more.

    Access
    Book purchase
    Fits
    Data Architect, Enterprise Architect
    Details for DAMA-DMBOK
    Use it when
    • You are setting up data governance and need a shared reference.
    • Data roles and ownership are unclear.
    Helps you produce
    • Data governance frameworks
    • Data management capability assessments
    • Roles and responsibilities for data
    Think twice
    It describes rather than prescribes, and version 3.0 is in progress. (editorial)
    Deployment
    Not applicable
    License
    Not stated
    AI features
    Not applicable
    Edition
    2nd Edition Revised (2024); 3.0 in progress
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    • DAMA-DMBOK (DAMA International) (opens in a new tab)
    Checked
    October 3, 2026
  • Method or StandardResearched

    NIST AI Risk Management Framework

    NIST

    NIST's voluntary framework for finding and managing AI risk through four functions: govern, map, measure and manage.

    Access
    No cost
    Fits
    AI Architect, Security Architect, Enterprise Architect
    Details for NIST AI Risk Management Framework
    Use it when
    • You need a recognized structure for AI risk decisions.
    • Generative AI use needs specific risk categories.
    Helps you produce
    • AI risk registers
    • AI governance policies
    • Risk actions by function, with the Generative AI Profile
    Think twice
    It is voluntary and high-level, so you still have to turn it into controls. A revision is coming. (editorial)
    Deployment
    Not applicable
    License
    Not stated on reviewed pages
    AI features
    Not applicable
    Edition
    AI RMF 1.0 (2023) and Generative AI Profile (2024); revision underway
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • ToolResearched

    OWASP Threat Dragon

    OWASP Foundation

    An open-source tool for drawing data flow diagrams and recording threats and mitigations against each element.

    Access
    No cost
    Fits
    Security Architect, Software Architect
    Details for OWASP Threat Dragon
    Use it when
    • You want a free, lightweight way to start threat modeling.
    • Threat models should live next to the code in a git repository.
    Helps you produce
    • Threat models on data flow diagrams
    • Threat and mitigation lists (STRIDE, LINDDUN and others)
    Think twice
    It records threats but doesn't track remediation; plan how findings reach your backlog. (editorial)
    Deployment
    Desktop app, Self-hosted
    License
    Apache-2.0
    AI features
    Not found on reviewed pages
    Edition
    Version 2
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • Method or StandardResearched

    OWASP Threat Modeling

    OWASP Foundation

    OWASP's practical guidance for finding, ranking and addressing security design threats early.

    Access
    No cost
    Fits
    Security Architect, Software Architect, Solution Architect
    Details for OWASP Threat Modeling
    Use it when
    • A new design or a major change needs a security review.
    • Teams need a repeatable way to ask what can go wrong.
    Helps you produce
    • Data flow diagrams with trust boundaries
    • Threat lists (for example STRIDE)
    • Mitigations written as security requirements
    Think twice
    It is a practice, not a tool; it works when repeated with the right people in the room. (editorial)
    Deployment
    Not applicable
    License
    CC BY-SA 4.0
    AI features
    Not applicable
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • Method or StandardResearched

    OWASP Top 10 for LLM Applications

    OWASP GenAI Security Project

    A community list of the most critical security risks in applications built on large language models, with mitigations.

    Access
    No cost
    Fits
    AI Architect, Security Architect, Software Architect
    Details for OWASP Top 10 for LLM Applications
    Use it when
    • You are adding an LLM feature and need a security baseline.
    • An AI design review needs common names for risks.
    Helps you produce
    • LLM threat checklists
    • Security requirements for AI features
    • Design review and red-team scope
    Think twice
    It is an awareness list, not a control framework, and it changes yearly; pin the edition. (editorial)
    Deployment
    Not applicable
    License
    CC BY-SA 4.0
    AI features
    Not applicable
    Edition
    2026 edition
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    • LLM Top 10 (OWASP GenAI Security Project) (opens in a new tab)
    • LLM Top 10 2026 (OWASP GenAI Security Project) (opens in a new tab)
    Checked
    October 3, 2026
  • ToolI've used it

    SAP LeanIX

    SAP

    A SaaS inventory of applications, capabilities and technology for assessing the portfolio and planning change.

    Access
    Commercial subscription, priced per application
    Fits
    Enterprise Architect, Business Architect
    Details for SAP LeanIX
    Use it when
    • You need a governed application inventory shared across the business.
    • Technology obsolescence and roadmaps are recurring questions.
    Helps you produce
    • Application fact sheets and portfolio assessments
    • Business capability maps
    • Technology risk and roadmap views
    Think twice
    Pricing is per application, so agree on what counts as an application before you load data. (editorial)
    Deployment
    Vendor-hosted (SaaS)
    License
    Proprietary
    AI features
    Documents an enterprise architecture assistant, Joule in SAP LeanIX, an inventory builder and an MCP server.
    Experience
    Mike has used this in his own work. See it on my Technology page.
    Sources
    Checked
    October 3, 2026
  • LearningResearched

    Software Architecture Monday

    Mark Richards

    Free short video lessons on software architecture topics and the soft skills of the role, with a new one each month.

    Access
    No cost
    Fits
    Software Architect, Solution Architect
    Details for Software Architecture Monday
    Use it when
    • You are moving from developer to architect.
    • You want a short lesson on one pattern or trade-off.
    Helps you produce
    • Pattern choices and trade-off analysis
    • Migration approaches
    Think twice
    Short lessons from one practitioner: a starting point, not a reference. (editorial)
    Deployment
    Not applicable
    License
    Not stated
    AI features
    Not applicable
    Edition
    Monthly; 223 lessons as of September 2026
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • ToolResearched

    Sparx Enterprise Architect

    Sparx Systems

    A full modeling environment for UML, SysML, BPMN, ArchiMate and data models, from single users to shared team repositories.

    Access
    Commercial license; 30-day trial
    Fits
    Enterprise Architect, Solution Architect, Data Architect
    Details for Sparx Enterprise Architect
    Use it when
    • You need many notations in one repository, traced to each other.
    • Models must be shared by a team with controlled access.
    Helps you produce
    • UML, SysML and BPMN models
    • ArchiMate views
    • Database models and generated DDL
    • Requirements traceability
    Think twice
    Choose the repository before the edition; the entry edition can't use a shared database repository. (editorial)
    Deployment
    Desktop app, Self-hosted, Vendor-hosted (SaaS)
    License
    Proprietary
    AI features
    Kernaro AI, sold separately, adds natural-language model editing and an assistant.
    Edition
    Professional, Corporate, Unified and Ultimate; SaaS editions
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    Checked
    October 3, 2026
  • ToolResearched

    Structurizr

    Structurizr (Simon Brown)

    Diagrams as code: define one software architecture model in text and generate consistent C4 views from it.

    Access
    Open tools cost nothing; the prebuilt server needs a license
    Fits
    Solution Architect, Software Architect
    Details for Structurizr
    Use it when
    • Architecture views should be versioned and reviewed like code.
    • Several diagrams must stay consistent with one model.
    Helps you produce
    • C4 context, container, component and deployment views
    • PlantUML and Mermaid exports
    Think twice
    Guides that mention Lite or the cloud plan are out of date; access control needs the licensed server. (editorial)
    Deployment
    Desktop app, Self-hosted
    License
    Apache-2.0 core; licensed prebuilt server
    AI features
    Documents DSL generation and an MCP server.
    Edition
    Local and server; the cloud service and Lite reached end of life
    Experience
    Public documentation reviewed. Not a claim of personal use.
    Sources
    • Structurizr (Structurizr) (opens in a new tab)
    • End of life (Structurizr) (opens in a new tab)
    • AI (Structurizr) (opens in a new tab)
    • LICENSE (Structurizr on GitHub) (opens in a new tab)
    Checked
    October 3, 2026
  • Method or StandardI've used it

    TOGAF Standard

    The Open Group

    The Open Group's framework and method for setting up and running an enterprise architecture practice.

    Access
    Free for non-commercial use, with registration; consultancy needs a commercial license
    Fits
    Enterprise Architect, Business Architect
    Details for TOGAF Standard
    Use it when
    • You are setting up or maturing an architecture practice.
    • Architects need a shared method vocabulary.
    Helps you produce
    • Architecture vision and target states
    • Gap analysis and roadmaps
    • Architecture governance artifacts
    Think twice
    Broad and heavy, so tailor it; consultancy for clients counts as commercial use. (editorial)
    Deployment
    Not applicable
    License
    Open Group license
    AI features
    Not applicable
    Edition
    10th Edition (2022)
    Experience
    Mike has used this in his own work. See it on my Technology page.
    Sources
    Checked
    October 3, 2026

Before You Adopt a Tool

Eight questions for any of the resources above, or any that are not on this page.

  1. What decision and what artifact must it support?
  2. Which information is authoritative here, and who maintains it?
  3. Can objects and relationships be reused across views, or is each diagram separate?
  4. How do review, collaboration and versioning work for a team like ours?
  5. What can we export, in what format, and how much is lost?
  6. Where does our data go, and what changes when AI features are switched on?
  7. What licensing, maintenance and adoption effort comes with it?
  8. How will we test its value on a small, real example first?

This is a starting point for a conversation, not a procurement, security or compliance review. The Technology Intake Checklist diagram shows where these questions sit in an intake process.

How This Guide Works

Every fact on a card (access, license, deployment, edition, AI features) was checked against the publisher's own pages on the date shown, and each card lists those sources. Tools are rechecked every 90 days and methods every 180; anything past its date is marked Review due. Where something couldn't be confirmed, the card says so rather than guessing.

“Use it when”, “Think twice” and the role guides are my own editorial judgment. Each card also says how I know it: Built by Mike for my own tools, I've used it for platforms I have used in my work, and Researched for everything else, which means public documentation reviewed, not personal use.

Spotted something out of date or wrong? Tell me and I'll correct it.