33. Treat security and compliance as domain rules
Security, privacy, legal duties, and approval rules are often part of the domain, not afterthoughts. This chapter shows how to model authorization, consent, audit trails, retention, fraud controls, and compliance workflows without hiding them in generic infrastructure.