FDEInterviews logo
← The FDE reading room

A field guide for forward deployed engineers / October 2026

Architecting and building
enterprise personal agents

The model proposes. Infrastructure decides.

An agent that reads someone's mail, remembers what they asked last month and books their travel overnight needs more than a good model. It needs delegated identity, a gatekeeper the model cannot talk past, consent bound to the exact action, writes that are safe to retry, memory a person can delete, and fast decision models and caches that keep it affordable. This guide builds each one, and shows where it fails.

Every answer, concept and course, all published video lessons, hands-on FDE Lab missions, Premium PDF guides and companion files, the full practice-test bank and work-sample downloads. Referral Premium excludes guide PDFs and their companion files.

Study alongside free video lessons.

Premium guide PDFs and companion files require active paid Premium or approved complimentary access. Referral Premium includes the rest of the site, but excludes these downloads.

177 pages · 42 chapters · PDF + tested reference code

Architecting and Building Enterprise Personal Agents cover: a brass key passing through three deep indigo gateways on an ivory plinth.

Identity / authority / memory / evidence

pages of architecture and delivery
177
original vector diagrams
32
tests in the reference code
86
primary sources, checked October 2026
229

Deploying a platform agent

Decide identity, consent, connector scopes, approval rules and evaluation for the assistant your customer licensed.

Building on an agent platform

Choose which components to buy, and build the gatekeeper, approvals and effect ledger the platform leaves to you.

Preparing for the design round

Answer “design an assistant that reads my email and books meetings” one decision at a time, with the failure modes.

Open the book

The gate, the decision model and the overnight task.

Read three complete pages from the PDF. Open a preview at full size to inspect the diagram and the decision it supports.

42 chapters in four parts

One architecture, one control at a time.

The job

Define the system, read the October 2026 landscape, score the first jobs and run discovery at the customer.

  1. 01

    What an enterprise personal agent is

    p. 7
  2. 02

    The landscape in October 2026

    p. 10
  3. 03

    Choose the first jobs

    p. 14
  4. 04

    Discovery at the customer

    p. 17

Identity, execution and effects

Two planes, delegated identity, durable workflows and writes that are safe to retry.

  1. 05

    The reference architecture

    p. 20
  2. 06

    Identity and delegation

    p. 24
  3. 07

    Durable execution and the agent loop

    p. 28
  4. 08

    Side effects you can retry

    p. 30

Authority and guardrails

The gatekeeper, injection as a data-flow problem, bound approvals, credentials, tools, sandboxes and the limits that stop an agent being used against other people.

  1. 09

    The gatekeeper

    p. 32
  2. 10

    Prompt injection is a data-flow problem

    p. 34
  3. 11

    Approvals people can trust

    p. 37
  4. 12

    Credentials and connectors

    p. 39
  5. 13

    Tools and MCP

    p. 41
  6. 14

    Sandboxes, egress and browsing

    p. 44
  7. 15

    Guardrails: misuse, safety and well-being

    p. 47

Memory and personalization

Memory with provenance and deletion, the stores behind session, episodic and long-term recall, preferences learned from evidence and deterministic context.

  1. 16

    Memory a person can trust

    p. 51
  2. 17

    Memory architecture: stores and recall

    p. 55
  3. 18

    Personalization

    p. 63
  4. 19

    Assemble the context deterministically

    p. 66

Reach and scale

Scheduled and proactive work, one agent across chat, voice and messaging surfaces, tenancy and budgets.

  1. 20

    Proactive work and notifications

    p. 68
  2. 21

    One assistant across surfaces

    p. 72
  3. 22

    Tenancy, isolation and residency

    p. 76
  4. 23

    Cost, routing and budgets

    p. 78

Models, caching and domains

A model ladder from rules to reasoning, caches scoped to the data that produced them, decision models such as Jev, and domain packs for each profession.

  1. 24

    The model portfolio

    p. 80
  2. 25

    Caching at every layer

    p. 87
  3. 26

    Decision models in the loop

    p. 90
  4. 27

    Specializing for a domain

    p. 99

Evidence, workflow and governance

Traces, audit, service levels, trajectory evaluation, an engineering workflow with mutation checks, and the customer's review packet.

  1. 28

    Observability and audit

    p. 102
  2. 29

    Evaluation and release gates

    p. 105
  3. 30

    The engineering workflow

    p. 107
  4. 31

    Governance the customer can sign off

    p. 109

Delivery and the reference build

A ninety-day plan, pilot measures, runbooks, four worked deployments, a design clinic, the reference build on Google ADK and the invariants.

  1. 32

    The first ninety days

    p. 113
  2. 33

    Pilot, adoption and value

    p. 115
  3. 34

    Operate it

    p. 117
  4. 35

    Case: the account executive's agent

    p. 120
  5. 36

    Case: the financial advisor's assistant

    p. 122
  6. 37

    Case: the delayed flight

    p. 124
  7. 38

    Case: the claims adjuster's agent

    p. 127
  8. 39

    Design review clinic

    p. 130
  9. 40

    The reference build on Google ADK

    p. 133
  10. 41

    The companion toolkit

    p. 140
  11. 42

    The invariants and a working vocabulary

    p. 144

The chapters close with the twelve release-blocking invariants, a working vocabulary and 229 primary references, each attached to the bounded claim it supports.

The customer changes the design.

Four fictional deployments apply the architecture to a sales organization, a regulated advisory firm, an overnight travel task and an insurance claims team. Names and figures are teaching examples; the travel and claims cases are printed by the shipped code.

Halden Software / 120 sellers

The account executive's agent

Treat forecast fields as records of truth, read only what the seller can open, and keep every external email a draft until the person sends it.

Corbel Wealth / regulated communications

The financial advisor's assistant

Let the compliance conversation remove every send and account tool, place drafts inside the firm's archived channel and flag payment-change requests.

Northwind Freight / an overnight rebooking

The delayed flight

Refuse an injected forward, bind consent to one fare, reconcile a lost reply to exactly one booking and keep the audit chain valid after erasure.

Lakeshore Mutual / a domain pack with a decision model

The claims adjuster's agent

Send injury and legal mentions to the adjuster by rule, let a decision model file and flag the rest by confidence, and cache the policy context across each multi-step task.

Included / reference code and worksheets

Read the controls as code.

Sixteen small modules implement the decisions the guide describes, and a reference build wires them into an agent on Google's Agent Development Kit: the gatekeeper, exact-action approvals, delegated tokens, the effect ledger, budgets, memory with provenance, hybrid recall, context assembly, the notification outbox, the audit chain, scoped caching, the model ladder, decision-model routing, abuse limits, learned preferences and scheduled actions. Two scenarios run them together on the delayed-flight and claims cases.

The core runs on Python 3.10 or later with no packages, keys or network; the ADK build needs the pinned google-adk. The shipped archive passed 86 tests, and its verification reintroduced 47 design mistakes, each caught by a test.

10 worksheets for the customer.

  1. Job scorecard and discovery inventory
  2. Action catalog with classes and limits
  3. Threat model and memory policy
  4. Approval request and evaluation plan
  5. Release gate, runbooks and pilot measures

Worksheets organize the decisions. They do not replace the customer's policies, contracts or legal advice.

Practice each control.

The PDF links to the concepts, questions and course lessons that drill each part of the architecture. Each resource keeps its displayed access level.

Before you download

Who is this guide for?

Forward deployed engineers and platform engineers who build or deploy agents that act for one person inside an organization, and candidates preparing for agent design rounds. It assumes you write production software; it does not assume you have shipped an agent that holds someone's credentials.

What does the download include?

The 177-page PDF with 32 original vector diagrams, four fictional worked deployments and a twelve-prompt design clinic, plus a separate companion: standard-library Python reference implementations of the gatekeeper, approvals, delegation, effect ledger, budgets, memory and hybrid recall, context assembly, notifications, audit chain, scoped caching, model routing, decision-model routing, abuse limits, learned preferences and scheduled actions, with 86 tests and 10 editable worksheets.

Is it tied to one framework or vendor?

The controls are not: the architecture chapters describe decisions that hold across platforms, and the reference code for them uses only the Python standard library. The reference build in chapter 40 then wires those controls into an agent on Google's Agent Development Kit, with tests that run through ADK's own runner. Chapter 2 records what major vendors and standards bodies had published as of October 2026, each statement tied to the owner's own page, so you can map the design onto the platform your customer chose.

How current is it?

Every dated fact was checked against its official source between 6 and 9 October 2026, including the MCP 2026-07-28 revision, A2A 1.0, the OWASP Top 10 for Agentic Applications and the EU AI Act dates. The guide cites 229 primary references.

Where do decision models like Jev fit?

Chapter 26 places a decision model inside the architecture for the many small, bounded calls an agent makes: intent, tool choice, triage, notification priority, whether a fact is worth remembering, whether a step is done. Its confidence decides whether the agent acts, checks with a larger model or asks the person, and it can add friction to the gatekeeper but never grant permission. The claims case in chapter 38 runs the pattern end to end.

Is the code production software?

It is teaching code: small enough to read in an afternoon, with tests that state what each control must refuse. A verification script reintroduces 47 design mistakes into the shipped archive and requires a test to catch each. Port the tests first when you build the production version.

Do I need Premium or a separate purchase?

The full PDF and companion are included with active paid Premium or approved complimentary guide access. No separate purchase is needed. Three complete sample pages are public. Referral-only online Premium does not include guide downloads.

How was the guide checked?

Sources were verified against primary publications, every scenario value is printed by the shipped code, the extracted companion runs its tests and mutation checks, and the PDF passes layout, link and figure checks. AI assisted research, writing, code and the cover illustration. This edition is prepared for publisher review; automated checks do not imply independent human approval.

FDEInterviews / enterprise personal agents

Delegate authority. Never beyond the person.

The complete 177-page guide and the reference code are included with active paid Premium or approved complimentary guide access.

© 2026 FDEInterviews.com. AI-assisted educational material prepared for publisher review. Synthetic cases and starting values are labeled. Not legal or compliance advice. See the guide's use notice and Terms of Service.