What an AI application is

Strip away the demos and an AI application is a normal enterprise system with three new parts: a model you do not control, retrieval that feeds it context, and tools it is allowed to call. Everything around those three is engineering you already know: networks, databases, identity, integration, operations and cost.

That is why the map above has lenses. Pick one and the same system turns into a networking problem, a data problem or an identity problem, with the components that matter for that discipline lit up.

The shape that survives production

  • Edge and API gateway own the way in: TLS, WAF, authentication, rate limits.
  • Agent decides what happens next. In most systems it is a supervisor with a small set of specialist workers.
  • LLM gateway is the only way out to a model: routing, budgets, redaction and one place to trace every call.
  • Retrieval supplies the knowledge the model was never trained on, filtered by who is asking.
  • Ingestion keeps that knowledge fresh from the systems that own it.
  • Tools are typed MCP servers with explicit permissions in front of real enterprise APIs.

Where teams get hurt

Observability arrives too late, evaluation is a spreadsheet, identity stops at the web app, and the deployment story is "it runs on my laptop". The guides attached to each component address these in order.

Node by node

Web App

Frontend3 linked

Identity

SSO · OBO2 linked

API Gateway

AuthN · limits4 linked

Secrets

Vault · KMS1 linked

Agent

Orchestration34 linked

Audit

Every call7 linked

LLM Gateway

Route · budget10 linked

Observability

Traces · evals18 linked

Model

Provider API13 linked

Sources

Docs · tickets · DBs5 linked

Ingestion

Chunk · embed8 linked

Vector Index

Embeddings · hybrid4 linked

Retrieval

Hybrid · rerank23 linked

Tools

MCP servers20 linked

Enterprise APIs

ERP · CRM · ITSM2 linked

Memory

Session · long-term6 linked

Human review

Approval queue3 linked

On this map