Trusted-side implementation laws for servers and APIs: validate at the boundary, one ORM, secrets never in client paths, implement within the boundaries ARCHITECTURE.md defines. Triggers when server or API work is in scope. Not for architecture decisions themselves (systems-architecture), UI (frontend), or accepting finished work (product-acceptance).