Lessons
1Enterprise RAG architecture48 min read
The forward-deployed deliverable is not “an LLM in a VPC” — it is a control plane (auth, policy, audit, guardrails) wrapped around a data plane (ingest, retrieve, generate), both landed in the customer’s environment. Why you ship a gateway and a corpus, not a model; the layered reference architecture; and how Morgan Stanley actually built it.
- →Enterprise RAG Architecture
- →Private Deployment
2Auth, SSO, RBAC & auditability48 min read
RBAC on the chat surface is easy and worth almost nothing; RBAC on the retrieved document is the enterprise contract, and it is where the leaks happen. Pre- vs post-filter ReBAC (AuthZed/Pinecone), why pre-baked ACLs go stale, SSO down to the agent identity, and the audit schema a regulator actually wants.
- →Identity and Governance
- →Private Deployment
3Private/VPC deployment patterns46 min read
Isolation means every egress from the agent runtime terminates in something the customer can route and audit — their keys, their bucket, their DNS, their model. PrivateLink and private endpoints, the air-gap spectrum, what each posture actually buys you under GDPR/HIPAA/ITAR, and the three-year TCO reality.
- →Private Deployment
4Evals & observability in the field48 min read
Monitoring answers “is it working?”; observability answers “why did it behave this way?” — and on a customer site you often can’t see their data, so the trace IS the artifact. RAGAS metrics, ground-truth from production traffic (Shopify’s GTX), the stale-index SLO, and the self-hosted observation spine that lives in the customer VPC.
- →RAG Quality Operations
5Guardrails & PII handling48 min read
Every prior layer can fail, so guardrails are the last line — and PII has three redaction opportunities, each mandatory. Presidio + NeMo + Bedrock as defense in depth, redaction at ingest/retrieval/output, indirect prompt injection (CVE-2025-32711), embedding inversion, and the permission-leak failure mode confronted directly.
- →RAG Security and PII
6Capstone: private RAG for a regulated customer50 min read
Put it together: a worked, defensible private-RAG design for a regulated healthcare customer in their VPC — the request lifecycle end to end, the discovery questions that frame it, the 30/60/90 deployment motion, and the full FDE system-design interview rubric you’ll be scored against.
- →Enterprise RAG Architecture
- →Private Deployment
- →Identity and Governance
Skills in this course
- 01Enterprise RAG ArchitectureDesign a grounded retrieval system with clear data and model boundaries.
- 02Private DeploymentChoose SaaS, VPC, or air-gap patterns from risk, time, and operations needs.
- 03Identity and GovernanceEnforce current authorization and produce useful, privacy-safe audit evidence.
- 04RAG Quality OperationsMeasure retrieval, grounding, freshness, latency, and field quality.
- 05RAG Security and PIIControl PII, prompt injection, unsafe output, and permission leakage.