Architecture Atlas
This atlas turns the book’s arguments into diagrams. Use it as a visual checklist when designing or reviewing a production AI system.
The Production Boundary
flowchart LR
User["User or operator"] --> Intake["Input boundary"]
Intake --> Evidence["Evidence layer"]
Evidence --> Prompt["Prompt and context builder"]
Prompt --> Model["Model call"]
Model --> Validate["Validation and eval checks"]
Validate --> Human["Human review"]
Human --> State["Typed workflow state"]
State --> Audit["Audit packet"]
State --> Observe["Observability"]
Observe --> Improve["Eval and improvement loop"]
Improve --> Prompt
The model is one component inside a controlled workflow. The system owns evidence, state, review, audit, and improvement.
Evaluation Loop
flowchart TD
Change["Prompt, model, retrieval, or code change"] --> Fixtures["Golden and adversarial fixtures"]
Fixtures --> Run["Eval run"]
Run --> Score["Risk-weighted score"]
Score --> Gate{"Release gate"}
Gate -->|pass| Deploy["Deploy"]
Gate -->|fail| Fix["Fix source of regression"]
Deploy --> Monitor["Production monitoring"]
Monitor --> Corrections["Human corrections and incidents"]
Corrections --> Fixtures
Evaluation is not a one-time benchmark. Production corrections should feed the fixture set.
Typed Workflow
stateDiagram-v2
[*] --> Open
Open --> WaitingForDocuments: DocumentUploaded
WaitingForDocuments --> WaitingForDocuments: MissingDataDetected
WaitingForDocuments --> ReadyForAnalystReview: ExtractionSucceeded
ReadyForAnalystReview --> ApprovedByHuman: AnalystApproved
ReadyForAnalystReview --> RejectedByHuman: AnalystRejected
ApprovedByHuman --> [*]
RejectedByHuman --> [*]
The important absence is as meaningful as the arrows: there is no ModelApproved transition.
Human-Control Ladder
flowchart BT
Decide["AI decides"] --> Validate["AI validates"]
Validate --> Route["AI routes"]
Route --> Draft["AI drafts"]
Draft --> Recommend["AI recommends"]
Recommend --> Prepare["AI prepares"]
Risk should push the system downward toward preparation and recommendation, with human-owned transitions for consequential decisions.
Observability Records
flowchart LR
Workflow["Workflow execution"] --> Debug["Debug logs"]
Workflow --> Trace["Traces and spans"]
Workflow --> Semantic["Semantic AI events"]
Workflow --> Audit["Audit records"]
Debug --> Engineer["Engineer debugging"]
Trace --> SRE["Operations and latency"]
Semantic --> Eval["Evaluation and drift"]
Audit --> Compliance["Compliance and accountability"]
Do not force one record type to serve every audience. Debugging, operations, evaluation, and audit have different needs.
Security Boundary
flowchart TD
Trusted["Trusted policy and developer instructions"] --> Builder["Prompt/context builder"]
User["Authenticated user request"] --> Builder
Docs["Retrieved documents as untrusted evidence"] --> Label["Evidence labeling"]
Tools["Tool results as untrusted evidence"] --> Label
Label --> Builder
Builder --> Model["Model"]
Model --> Proposal["Proposal or draft"]
Proposal --> Policy["Policy and permission checks"]
Policy -->|low risk| Action["Allowed action"]
Policy -->|high risk| Review["Human approval"]
Policy -->|forbidden| Block["Blocked"]
The core rule is authority separation: evidence is not instruction, and proposal is not decision.
Economics Routing
flowchart TD
Task["Workflow task"] --> Rules{"Can deterministic code solve it?"}
Rules -->|yes| Code["Use code or database constraints"]
Rules -->|no| Risk{"High risk or high ambiguity?"}
Risk -->|low| Small["Small or medium model"]
Risk -->|high| Frontier["Frontier model plus review"]
Small --> Cache{"Safe to cache?"}
Frontier --> Review["Human review"]
Cache -->|yes| Cached["Cache with version and tenant rules"]
Cache -->|no| Direct["Run uncached"]
Model routing is not only cost optimization. It is risk routing.
Tool Permission Matrix
flowchart LR
Model["Model"] --> Read["Read scoped evidence"]
Model --> Draft["Draft internal note"]
Model -. blocked .-> External["External communication"]
Model -. blocked .-> Final["Final case decision"]
External --> Human["Human approval"]
Final --> Human
Human --> Audit["Audit log"]
The model may prepare and draft. High-risk writes route through human approval and audit.
Capstone Flow
flowchart TD
Open["Case opened"] --> Upload["Document uploaded"]
Upload --> Outbox["Outbox extraction request"]
Outbox --> Extract["Extraction worker"]
Extract --> Evidence["Versioned evidence packet"]
Evidence --> AI["AI draft and risk signal"]
AI --> InlineEval["Inline eval and policy checks"]
InlineEval --> Queue["Analyst review queue"]
Queue --> Decision{"Human decision"}
Decision -->|approve| Approved["ApprovedByHuman"]
Decision -->|reject| Rejected["RejectedByHuman"]
Decision -->|more evidence| Upload
Approved --> Audit["Audit packet finalized"]
Rejected --> Audit
Audit --> Metrics["Metrics, traces, eval candidates"]
The capstone combines every pillar: evaluation, typed state, human control, observability, security, economics, and distribution-grade trust artifacts.