What an AI application is
Strip away the demos and an AI application is a normal enterprise system with three new parts: a model you do not control, retrieval that feeds it context, and tools it is allowed to call. Everything around those three is engineering you already know: networks, databases, identity, integration, operations and cost.
That is why the map above has lenses. Pick one and the same system turns into a networking problem, a data problem or an identity problem, with the components that matter for that discipline lit up.
The shape that survives production
- Edge and API gateway own the way in: TLS, WAF, authentication, rate limits.
- Agent decides what happens next. In most systems it is a supervisor with a small set of specialist workers.
- LLM gateway is the only way out to a model: routing, budgets, redaction and one place to trace every call.
- Retrieval supplies the knowledge the model was never trained on, filtered by who is asking.
- Ingestion keeps that knowledge fresh from the systems that own it.
- Tools are typed MCP servers with explicit permissions in front of real enterprise APIs.
Where teams get hurt
Observability arrives too late, evaluation is a spreadsheet, identity stops at the web app, and the deployment story is "it runs on my laptop". The guides attached to each component address these in order.
Node by node
Web App
Frontend3 linked
Identity
SSO · OBO2 linked
Understand
- ExplainerYour agent should not be a superuser
Operate
API Gateway
AuthN · limits4 linked
Secrets
Vault · KMS1 linked
Operate
Agent
Orchestration34 linked
Understand
- ExplainerAnswer complex questions in parts, and check each part
- ExplainerReflection helps only when it checks against evidence
- ExplainerGive an agent an outcome, a boundary and a stop condition first
- ExplainerAgent behavior is a loop, not a prompt
- ExplainerPlan before acting when actions cost money or carry risk
- 19 more on the map
Implement
Decide
Use
- ToolOpenAI Agents SDK
- ToolLangGraph
Reference
- ReferenceBuilding Effective Agents
Audit
Every call7 linked
Understand
- ExplainerAgents need arbitration rules before they disagree
- ExplainerGovernance is architecture, not a document after launch
- ExplainerYou cannot instruct a model into data protection
- Architecture patternPattern: the outbox for agent actions
Operate
LLM Gateway
Route · budget10 linked
Understand
- ExplainerTokenization quietly sets your cost, limits and reliability
- ExplainerGood guardrails make safe progress possible, not just block
- ExplainerEvery autonomous run needs a budget for cost, time, actions and risk
- ExplainerSafety is an architecture decision, not a moderation setting
- ExplainerUntrusted text does not get to give orders
- 5 more on the map
Observability
Traces · evals18 linked
Understand
- ExplainerEvaluate RAG in parts: retrieval, grounding, generation, citations
- ExplainerIf you cannot trace it, you cannot run it
- ExplainerEvaluate the workflow users see, not just the model
- ExplainerThe 3am agent run that nobody is watching
- ExplainerYou cannot run RAG on user complaints
- 11 more on the map
Use
- ToolOpenTelemetry
Reference
- ReferenceOpenTelemetry Documentation
Model
Provider API13 linked
Understand
- ExplainerModel choice is rarely your first production problem
- ExplainerLLMs generate one token at a time, so design for it
- ExplainerTokenization quietly sets your cost, limits and reliability
- ExplainerMore context can make an AI system worse
- ExplainerVague prompts become vague systems
- 3 more on the map
Implement
Operate
- ChecklistWhen to bring in a compliance review
Use
- ToolLiteLLM
- ToolGuardrails
Reference
- ReferenceAttention Is All You Need
Sources
Docs · tickets · DBs5 linked
Understand
Operate
- ChecklistWhen to bring in a compliance review
Ingestion
Chunk · embed8 linked
Understand
- ExplainerRetrieval quality is decided before anyone searches
- ExplainerChunk boundaries decide what your RAG system can know
- ExplainerSimilar is not the same as correct: the limits of embeddings
- ExplainerWhen the evidence is a table, a chart or a recording
- ExplainerA stale answer is a wrong answer
- 3 more on the map
Vector Index
Embeddings · hybrid4 linked
Retrieval
Hybrid · rerank23 linked
Understand
Operate
- ChecklistRAG production-readiness checklist
- Failure storyThe retrieval cache that served stale policies
Use
- ToolLlamaIndex
- Toolpgvector
- ToolRagas
Reference
Tools
MCP servers20 linked
Understand
- ExplainerStructured output turns model text into something software can trust
- ExplainerProduction knowledge lives in systems of record, not only in PDFs
- ExplainerTool access is where AI becomes operational risk
- ExplainerA handoff is a contract: state, evidence, open questions, an owner
- ExplainerRetrieved content is data, never instructions
- 9 more on the map
Decide
Operate
Use
- ToolInstructor
Reference
- ReferenceModel Context Protocol
- ReferenceOWASP Top 10 for LLM Applications
Enterprise APIs
ERP · CRM · ITSM2 linked
Understand
Decide
Memory
Session · long-term6 linked
Understand
- ExplainerAgent memory is several stores, each with its own rules
- ExplainerShared state needs structure, attribution and versions
- ExplainerShared agent memory is an access-control problem
- ExplainerA handoff is a contract: state, evidence, open questions, an owner
- ExplainerFour kinds of agent state, and only one of them is memory
- 1 more on the map