Deployment architecture

Plan the identity, data, action, and operating boundaries before production.

Document the production boundary for identity, sources, models, tools, run state, evidence, residency, support, and ownership.

Reference architecture

Separate the planes. Connect the evidence.

A mature deployment makes ownership and trust boundaries explicit. The architecture below is a design framework to validate against your environment during technical discovery.

Identity plane

SSO, SCIM, groups, roles, service identities, privileged access

Source plane

Connectors, source ACLs, metadata, freshness, regional boundaries

Context plane

Index, graph, memory scopes, lineage, sensitivity, retrieval APIs

Intelligence plane

Model routing, prompt policy, evaluation, cost and latency controls

Action plane

Tools, credentials, write scopes, approvals, idempotency, and compensation

Evidence plane

Run traces, citations, policy outcomes, admin events, audit exports

Shared responsibility

Make ownership visible before production access exists.

Exact hosting, tenancy, region, networking, encryption, model providers, SLOs, RTO/RPO, and support terms remain engagement-specific until documented in a signed scope.

DomainEnterprise ownsS/Runtime engagement ownsJoint evidence
IdentityAuthoritative users, groups, role policyMappings, enforcement points, admin controlsAccess tests and exception review
DataSource authority, classification, retention needsConnector scope, minimization, lineage designData-flow and deletion tests
ModelsApproved use cases and provider policyRouting controls and evaluation instrumentationProvider, prompt, and quality register
ActionsBusiness authority and approval ownersTool scopes, execution checks, run evidenceFailure, idempotency, and compensation tests
OperationsService owners and escalation contactsPlatform monitoring and documented support pathRunbook, incident exercise, recovery targets

Enterprise rollout

Build one production path, then make it reusable.

Discover

Map one workflow, its systems, identities, policy, risk, and accepted outcome.

Connect

Establish the narrowest useful data and action boundary with observable health.

Evaluate

Test retrieval, reasoning, policy, action safety, failure paths, and operator experience.

Operate

Launch with owners, support, change control, dashboards, review queues, and incident paths.

Expand

Reuse connectors, context, evaluations, policies, and agent patterns across adjacent work.

Architecture session

Bring one consequential workflow. Leave with a governed agent blueprint.

We will map the context, systems, decisions, controls, actions, and success measures together.

Talk to an architect