Identity plane
SSO, SCIM, groups, roles, service identities, privileged access
Deployment architecture
Document the production boundary for identity, sources, models, tools, run state, evidence, residency, support, and ownership.
Reference architecture
A mature deployment makes ownership and trust boundaries explicit. The architecture below is a design framework to validate against your environment during technical discovery.
SSO, SCIM, groups, roles, service identities, privileged access
Connectors, source ACLs, metadata, freshness, regional boundaries
Index, graph, memory scopes, lineage, sensitivity, retrieval APIs
Model routing, prompt policy, evaluation, cost and latency controls
Tools, credentials, write scopes, approvals, idempotency, and compensation
Run traces, citations, policy outcomes, admin events, audit exports
Shared responsibility
Exact hosting, tenancy, region, networking, encryption, model providers, SLOs, RTO/RPO, and support terms remain engagement-specific until documented in a signed scope.
Enterprise rollout
Map one workflow, its systems, identities, policy, risk, and accepted outcome.
Establish the narrowest useful data and action boundary with observable health.
Test retrieval, reasoning, policy, action safety, failure paths, and operator experience.
Launch with owners, support, change control, dashboards, review queues, and incident paths.
Reuse connectors, context, evaluations, policies, and agent patterns across adjacent work.
Architecture session
We will map the context, systems, decisions, controls, actions, and success measures together.