Skip to content

Architecture review checklist

Enterprise AI data-flow checklist

Work out where your documents go at every step of an enterprise AI deployment, who holds them there, how long they stay and what deletion removes.

Updated 21 Aug 2026

Definition

A useful data-flow review names the data, processor, location, purpose, retention, access and owner at every stage.

01

Inventory data classes

List every place a copy of your content comes to rest, from the original file to the logs and backups.

  • Source files and parsed text
  • Metadata and embeddings
  • Prompts, inputs and outputs
  • Logs, traces and backups
02

Draw every processor and store

For each class, record service/operator, location, encryption, identity, network path, retention, deletion and whether data can enter training or human support workflows.

  • Service, operator and location
  • Encryption and identity
  • Network path and retention
  • Deletion and training exposure
03

Trace identity and permission changes

Test onboarding, role change, revoked source access, departed users, connector deletion and organisation separation through retrieval and generated output.

  • Onboarding and role change
  • Revoked and departed access
  • Connector deletion
  • Organisation separation
04

Trace operations

The successful request flow is the easy diagram.

  • Monitoring and error reporting
  • Backup and recovery
  • Updates and vulnerability response
  • Incident and break-glass access
05

Compare deployment options

Draw managed, customer-cloud, self-hosted and any local-model variant separately. Do not reuse one diagram when the processors or responsibilities differ.

  • Managed and customer-cloud
  • Self-hosted variant
  • Local-model variant
  • Separate diagram each
06

Turn gaps into decisions

Assign an owner and disposition to every unknown: provide evidence, change configuration, accept risk, add a control or reject the design.

  • Data class
  • Processor and location
  • Purpose and retention
  • Identity and access
  • Deletion and recovery
  • Named responsibility

What this page does not prove

  1. B1A diagram is not evidence that the implementation follows it.
  2. B2Legal roles and transfer mechanisms require qualified review.
  3. B3Self-hosting can still involve external model, telemetry or support paths.
  4. B4Re-review after material architecture or provider changes.

Test the claim on your documents

Pick a real piece of work, agree what a good answer looks like, then go through the results together.