Let probabilistic components decide within authority — not define the authority.
Compound systems combine models, retrieval, tools and deterministic code. The architectural problem is not merely orchestration; it is deciding which component is allowed to make which kind of decision, under whose authority, and with what controls.
Authority and deterministic boundaries
Delegated privilege can suit exploratory environments. As systems mature, authority becomes compound: governed product capability is combined with the security principal that supplies delegated authority.
Security context and secrets remain outside the model boundary. Deterministic code mediates authenticated identity, credentials, scopes and other security-critical context.
Models may choose within an approved capability envelope. They should not manufacture, transform or expand that envelope.
Why the distinction matters
Treating LangChain or LangGraph as though they were deterministic application code hides the risk introduced by model behaviour. A node can be operationally healthy while producing a semantically unsafe or incorrect decision. Architecture therefore has to separate the probabilistic decision layer from the deterministic controls that protect authority and security boundaries.
We're here to help
Start a conversation.
Discuss your current architecture, AI, cloud or security challenge and how we can help.