Skip to content

Maps, decisions and failures from enterprise systems

Real systems,
revealed.

How enterprise systems fit together, as maps you can open: what each part does, what I decided and what broke. AI first, because that is where I build now, on the data, integration, cloud and security platforms it depends on.

By Vamsi Krishna · GitHub

entries121
maps6
series published18
last entryOct 8, 2026
Fig. 1 · AI Application, layer by layer. Scroll, and the layers settle into the full map below.
InternetYour networkPrivate subnetSystems of recordModel providerSecurity scopeOn-premisesHTTPSSSOtokenprivateapproveOBOcredsauditspansUserEmployeeEdgeCDN · WAFWeb AppFrontend3IdentitySSO · OBO2API GatewayAuthN · limits4SecretsVault · KMS1AgentOrchestration34AuditEvery call7LLM GatewayRoute · budget10ObservabilityTraces · evals18ModelProvider API13SourcesDocs · tickets · DBs5IngestionChunk · embed8Vector IndexEmbeddings · hybrid4RetrievalHybrid · rerank23ToolsMCP servers20Enterprise APIsERP · CRM · ITSM2MemorySession · long-term6Human reviewApproval queue3

How to read this

Each box is a role. Pick a lens to see the system as a networking, data, security or identity problem. Pick a stack, or mix stacks per component, to see the product that fills each role.

  • Request
  • Async or batch
  • Telemetry and audit
  • Trust boundary
  • Cross-platform seam
  • Seam not drawn as a line

Adds identity carried end to end, secrets in a vault, an audit record for every call, and real systems of record behind the tools.

Components

All disciplines. Roles only.

The whole estate

Six maps, one company

AI is the top layer, not the whole system. It runs on the platforms below and answers to the controls down the side. 1 of 6 maps are drawn in full, 2 are documented and 3 are being drawn.

All maps

Read in order

Pick a track

8 five-day tracks of five short parts each, from the first decision to running it in production. Or follow a path: Agents in production, without a shared robot, Enterprise RAG, from problem to production, New to RAG, in order.

Read by discipline

Pick the question you actually have.

Recently written

The journal

01

Build log · · 1 min read · shipped

Build log: shipping Unseen UI to npm

How the component library behind this site went from a private workspace to two published packages, including the three things the first consumer broke.

02

Comparison · · 1 min read

LangGraph vs the OpenAI Agents SDK

Two ways to write the same supervisor. Compared on control flow, tracing, provider coupling, testing and what each makes hard.

04

Checklist · · 12 checks

RAG production-readiness checklist

Twelve checks to pass before a retrieval system answers a real user. Tick them locally; progress stays in your browser.