DFD — RAG Support Assistant
Retrieval-augmented support assistant from knowledge-base ingest to grounded answer, isolating the third-party embedding and completion APIs so the 8 flows leaving the trusted VPC — prompt text included — are counted as attack surface.
Make it your own.
title "Support assistant — retrieval-augmented generation"
level 1
entity Customer
entity "Support agent"
entity "Embedding API"
entity "LLM provider API"
process 1 "Ingest knowledge base"
process 2 "Chunk and embed"
process 3 "Retrieve context"
process 4 "Compose prompt"
process 5 "Generate answer"
process 6 "Redact and log"
process 7 "Evaluate groundedness"
store D1 "Document corpus"
store D2 "Vector index"
store D3 "Conversation history"
store D4 "Prompt + completion log"
boundary "Trusted VPC" { 2, 3, 4, 5, 6, 7, D1, D2, D3, D4 }
boundary "Vendor (third party)" { "Embedding API", "LLM provider API" }
"Support agent" -> 1 : "article export"
1 -> D1 : "normalised markdown"
D1 -> 2 : "documents"
2 -> "Embedding API" : "chunks (1 024 tokens)"
"Embedding API" -> 2 : "1 536-dim vectors"
2 -> D2 : "vectors + metadata"
Customer -> 3 : "question"
D2 -> 3 : "top-8 nearest chunks"
3 -> 4 : "retrieved passages"
D3 -> 4 : "last 6 turns"
4 -> 5 : "system + user prompt"
5 -> "LLM provider API" : "completion request"
"LLM provider API" -> 5 : "answer + token usage"
5 -> 6 : "draft answer"
6 -> D3 : "turn transcript"
6 -> D4 : "prompt hash + citations"
6 -> Customer : "answer + sources"
D4 -> 7 : "5% sample"
7 -> "Support agent" : "ungrounded-claim report"