Guardrailed LLM Request Path (PlantUML)
The full inbound and outbound guardrail chain around a retrieval-augmented answer, including citation verification and audit logging.
Rendering…
Make it your own.
@startuml
title Guardrailed LLM request path
autonumber
actor User
participant "API gateway" as GW
participant "PII redactor" as PII
participant "Policy classifier" as POL
participant "Retriever" as RET
participant "LLM" as LLM
participant "Citation checker" as CIT
database "Audit log" as AUD
User -> GW : prompt
GW -> PII : redact(prompt)
PII --> GW : prompt with 3 entities masked
GW -> POL : classify(prompt)
alt disallowed category
POL --> GW : block - self harm
GW --> User : refusal with signposting
GW -> AUD : blocked, category, hashed prompt
else allowed
POL --> GW : allow
GW -> RET : search(prompt, tenant scope)
RET --> GW : 8 chunks, document ACLs already applied
GW -> LLM : system + context + prompt
LLM --> GW : draft answer with inline citations
GW -> CIT : verify every claim maps to a retrieved chunk
alt uncited claim found
CIT --> GW : fail
GW -> LLM : regenerate under a stricter instruction
else clean
CIT --> GW : pass
end
GW --> User : answer with sources
GW -> AUD : latency, tokens, model version, chunk ids
end
@enduml