All requirements SHALL use the format PREFIX-NNN where: - PREFIX is the type code (CAP, UC, FEAT, FN, DATA, INTF) - NNN is a zero-padded sequential number within that type - UIDs are immutable once assigned
Source code referencing a requirement SHALL include a comment with the UID and a verb: - impl -- this code implements the requirement - verify -- this code tests/verifies the requirement - depends -- this code depends on the requirement - related -- this code is related to the requirement
Requirements SHALL use one of these statuses: - Draft -- under development, not yet reviewed - Active -- approved and in effect - Obsolete -- superseded or no longer applicable - Template -- example/placeholder, not a real requirement
The organization shall be able to [capability description].
Business justification: [why this capability matters] Stakeholders: [who benefits] Priority: [critical / high / medium / low]
As a [role], I want to [action], So that [benefit].
Preconditions: - [what must be true before]
Main Flow: 1. [step] 2. [step] 3. [step]
Postconditions: - [what is true after]
Acceptance criteria: - [testable condition] - [testable condition]
The system shall provide [feature description].
Scope: - [included]
Out of scope: - [excluded]
Dependencies: [other features or systems required]
The system SHALL [specific measurable behavior].
Input: [what triggers this] Output: [what the system produces] Constraints: [timing, format, limits] Verification method: [test / inspection / analysis / demonstration]
The system shall maintain [Entity Name] records with:
Attributes: - [attribute]: [type] [constraints]
Relationships: - [belongs to / has many] [Other Entity]
Constraints: - [uniqueness, validation rules]
Lifecycle: - Created when: [event] - Deleted when: [event or retention policy]
Volume estimate: [expected record count] Sensitive data: [yes/no]
The system shall integrate with [external system] to [purpose].
Direction: [inbound / outbound / bidirectional] Protocol: [REST / GraphQL / SMTP / webhook / file transfer] Authentication: [API key / OAuth / certificate] Data exchanged: [what flows in/out] Frequency: [real-time / batch / on-demand] Fallback behavior: [what happens when unavailable]