Reference: the template in detail
These chapters are the template's reference manual. The lessons link into them constantly, so they are included in full rather than left on GitHub.
| Chapter | Use it for |
|---|---|
| Architecture | the component diagram, trust boundaries and the seven segmented networks |
| Security model | identity, sessions, service credentials and what each boundary defends |
| Approvals | the opt-in signed approval: token fields, the four layers, transactional integrity |
| Guardrails | each input and output rail, its order and what it does not cover |
| Evaluation | the four suites, scorers, gates and provenance |
| Observability | trace structure, redaction and user attribution |
| Configuration | every setting, including the model endpoint |
| Test scenarios | manual scenarios several labs run from |
| Extending the template | replacing the sample domain with your own |
| Limitations | what the template deliberately does not do |
Three operational documents are linked rather than included:
docs/VERIFICATION.md,
docs/EXTRACTION-CHECKLIST.md
and evaluation/README.md.
Note
The editors found some statements in Test scenarios that predate later changes. For example, answers are buffered rather than streamed when output masking is on, and only two of the four evaluation suites are listed. The lab chapters reflect the current behaviour. The full list is in the content audit (see Source revisions and provenance).