Title: RAG Architecture Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — AI Governance Lead] Status: Draft Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Architecture, Security, AI Governance
Details the RAG architecture within the boundary set by ADR-003: approved retrieval content only, never a system of record.
flowchart LR
subgraph Ingestion
D1[Approved source documents: policy, process, JD reference] --> D2[Chunking - see rag-ingestion-and-chunking.md]
D2 --> D3[Metadata tagging: tenant, classification, access policy, dates]
D3 --> D4[Embedding generation]
D4 --> D5[(Vector Store)]
end
subgraph Retrieval
Q1[User/agent question] --> Q2[Metadata ACL filter - BEFORE similarity search]
Q2 --> Q3[Hybrid search: vector + keyword]
Q3 --> D5
D5 --> Q4[Reranking]
Q4 --> Q5[Minimum sufficient context selection]
Q5 --> Q6{Sufficient grounding?}
Q6 -- No --> Q7[No-answer fallback]
Q6 -- Yes --> Q8[Answer + citations]
end
rag_document/source content — treat the index as a derived cache, not a backup-critical store (see resilience-and-disaster-recovery.md).Each tenant’s approved content is either stored in a tenant-scoped namespace/index, or in a shared index with mandatory tenant_id metadata filtering enforced server-side before any vector search executes — never left to client-supplied filters alone.
rag-ingestion-and-chunking.md · retrieval-and-grounding-policy.md · rag-config.schema.json · rag.default.yaml
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |