In this post10 sections
  1. Why ‘design a feed’ prep misses the enterprise round
  2. What FDE postings say you will deploy into
  3. Start from constraints: five questions before any box
  4. Worked design: a retrieval assistant inside a court’s own cloud
  5. The decision table: what you choose and why
  6. Rollout, rollback and who can turn it off
  7. Will they actually ask about SSO and VPCs?
  8. Questions people ask
  9. Keep reading
  10. More from the blog

You spent a week on sharding timelines and fan-out on write. Then the prompt names a customer: a state court wants its clerks to ask questions of its procedure manuals, the system has to run inside the court’s own cloud, and no case record may leave it. That is the enterprise system design interview, and this post walks through one answer; for where the round sits in the loop, read the FDE interview guide.

The short answer: an enterprise system design interview asks you to design for one named customer, so their identity provider, network boundary, data rules and change process shape the architecture before load does. Open with those constraints. Say the thinnest version that proves the riskiest integration, a walking skeleton. Then draw the components, and finish with a rollout and a rollback the customer controls.

Why ‘design a feed’ prep misses the enterprise round

Feed prep trains one reflex: estimate the traffic, then let the numbers pick the boxes. Put the same service inside a hospital’s cloud account and the first questions become which vendors their compliance team allows and who signs off a release. None of those has a number for an answer, and each one changes the diagram.

The free enterprise design lesson runs the full opening on a pump maker; here we make the same move on a court.

What do reports say? One Blind poster interviewing for a Google (L4) role reported, in July 2026, choosing an Design track in a system architecture round run as a role-play, with the interviewer as the CTO of a company that wanted an AI-powered system; the discussion covered requirements, scoping, architecture, deployment considerations, scalability, security and evaluation. Source 1FDE Interview Experience at Google (L4) (Blind)PublisherBlindSource typecandidate report on BlindSource 2Google Forward Deployed Engineer Interview Experience (Blind)PublisherBlindSource typecandidate report on BlindSource 3Is Google FDE interview same as SWE? (Blind)PublisherBlindSource typecandidate report on Blind

One commenter wrote, in August 2026, in a Reddit thread about Google’s FDE (GenAI) loop, that they had to design an agent, with the design “focused mostly on the enterprise (security, , model routing, multi agent...)”; they did not name the company or the role. Source 4Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 5Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 6Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on Reddit

A Blind commenter in a thread about Google’s FDE interview described the same CTO format, without naming the company. Source 3Is Google FDE interview same as SWE? (Blind)PublisherBlindSource typecandidate report on Blind All of these reports concern Google and agents; we have none for other employers, so prepare for a classic prompt too. If your prompt is an agent for a CTO, the agentic system design walkthrough takes that shape.

What FDE postings say you will deploy into

Postings are where the enterprise constraints show up by name. Here is what they said in September 2026. Source 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job postingSource 10Forward Deployed Engineer, Infrastructure Specialist (North America)PublisherCohere (Ashby job board)Source typecompany job postingSource 11Forward Deployed Engineer (FDE), Healthcare - SF (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 12Forward Deployed Engineer (FDE), Healthcare - NYC (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 13Forward Deployed Engineer IV, GenAI, Google Cloud — Google CareersPublisherGoogleSource typecompany job postingSource 14AI Deployment Strategist @ SnowflakePublisherSnowflake (Ashby job board)Source typecompany job postingSource 15Forward Deployed Engineer (FDE) - SFPublisherOpenAI (Ashby)Source typecompany job posting

Labs, a data platform, an identity vendor and a cloud provider all write these lines, which is why we choose to drill identity, network, data and rollback. To turn lines like these into a prep list for one role, use how to read a job posting.

Start from constraints: five questions before any box

Ask these before you draw, and say what each answer changes. In our method, a question whose answer changes nothing is filler.

  1. Identity: who signs in, and through what? The answer picks SAML or OIDC for sign-in, SCIM or a directory sync for users and groups, and where permissions come from.
  2. Boundary: where must this run, and what may it call? The answer decides between your cloud reached over a private endpoint and a deployment in their account, sets the egress rules, and says whether any managed model service is allowed. For government networks, where the boundary comes with a clearance, see FDE jobs that need a security clearance.
  3. Data: what is sensitive, where may it rest, and for how long? The answer sets data residency, what you may log, and retention. It also tells you whether the user’s question is itself sensitive.
  4. Change: how does a release reach production here, and who runs it after you leave? The answer sets release cadence, managed versus self-run parts, and what rollback means.
  5. Security review: what does their security team need to see before go-live? The answer lists the documents you owe, such as a data flow diagram and a list of every service, and often changes what you build first.

Said aloud, in one breath:

“Before I draw anything, a few questions, because each one changes the design. Who signs in, and through which identity provider? Where must this run, and what may it call out to? Which data is sensitive, and where may it rest? How does a change reach production here, and who runs it after we leave? And what will your security team need to see before go-live?”

Size one thing, and name it: here, the model endpoint at the hour clerks start work, since the app tier is small.

Then find two answers that cannot both hold, recommend a side, and hand the call to its owner.

One phrase to avoid: “we’ll make it HIPAA compliant”. No system is compliant on its own: compliance covers the organization’s policies, agreements and controls. Name the controls you provide, and expect to sign the business associate agreement HIPAA requires of a vendor that handles patient data.

Worked design: a retrieval assistant inside a court’s own cloud

The prompt, which is fiction: “A state court system wants its clerks to ask questions of its procedure manuals and standing orders and get answers with citations. It runs inside the court’s own cloud tenancy. No case record may leave it.”

You ask the questions above. The court’s answers, as you would write them on the board:

QuestionCourt’s answer
UsersCourt staff in county offices, not the public
IdentityCourt’s identity provider; groups by office and role
RestrictedSealed and juvenile procedures, some roles only
BoundaryCourt’s tenancy; no public egress from the app tier
ModelsNo external model service approved yet
ChangeMonthly change board; court IT runs it after handover
Security reviewData flow diagram and a list of every service

The conflict, and what you say

Two answers collide: no external model service is approved, so models would run on GPUs inside the tenancy, and court IT runs everything after handover. Say:

“These pull against each other. Open-weights models on your GPUs keep every query inside, but your team would run GPU inference after we leave. Your provider’s managed model over a private endpoint is far less to run, but the query leaves your network. I’d lean to the managed option with region pinning and no prompt retention, put to your security office in writing, because GPU operations is the likelier failure after handover. It’s their call: which will they sign?”

The components

This is the move that turns a generic diagram into a design for this court. Clerks will paste case details into their questions, so the question text is a case record. The embedding call, the model call, the logs and the error tracker all have to sit inside the boundary, or cross it only with the security office’s signature. Say that, and draw the boundary first.

In the order data flows:

  • Ingest worker. It reads from the court’s document system, which stays the source of truth, and splits each manual by section. Every chunk carries its manual, section number, effective date, a link back and the document’s access list. Access lists sync separately and more often than text, and a deleted document’s chunks are removed on the next sync; say the revocation delay out loud and agree it with the court.
  • Search index. Keyword plus vector (hybrid search), because manuals are full of rule numbers and form codes that embeddings match poorly.
  • Assistant API. It takes the user’s groups from the validated identity token, never from the request body. If the token can’t carry every group (Entra drops the claim past 200, per Microsoft’s docs), look membership up in Microsoft Graph, as those docs advise, or in a directory you sync by SCIM, keyed on the token’s subject.
  • Models. Wherever the conflict lands: open-weights models on GPUs in the tenancy, or managed models over a private endpoint such as AWS PrivateLink, which keeps traffic off the public internet while the model still runs outside the court’s network. Hence the signature.
  • Answer step. The prompt holds only permitted chunks. Every claim cites a section the clerk can open, and with no supporting passage it says so and links the manual index.
  • Evaluation. Senior clerks write questions the way clerks type them, each paired with the section that answers it, plus some the manuals can’t answer. Rerun on every prompt, model or index change.
  • Audit log. Who asked what, and which chunks the answer used. Because queries hold case details, retention is the court records officer’s call, not yours.

Where the permission check lives

Put it inside the search, before ranking. Filtering after ranking can return nothing, or leak that a restricted section exists. A toy version, with a clerk who is not cleared for sealed procedures:

chunks = [
  {"id": "seal-4", "acl": {"seal"}, "s": .91},
  {"id": "seal-9", "acl": {"seal"}, "s": .88},
  {"id": "civ-12", "acl": {"all"}, "s": .74},
]
groups = {"all"}  # from the verified token
k = 2

def ok(c):
    return bool(c["acl"] & groups)

def top(cs):
    return sorted(cs, key=lambda c: -c["s"])[:k]

# Wrong: rank, then filter
wrong = [c["id"] for c in top(chunks) if ok(c)]
# Right: filter inside the search
right = [c["id"] for c in top(filter(ok, chunks))]
print(wrong)
print(right)

The first line prints []: the top results were sealed, so the clerk gets no answer even though a permitted section exists. The second prints ['civ-12']. In Elasticsearch, put the filter inside the kNN clause: it is applied during the search so k matching results come back, while a post-filter can return fewer than k (Elastic docs). “The prompt tells the model not to show sealed content” is the wrong answer; expect the follow-up: where exactly is the check?

The walking skeleton for the court

Say it before the first box; the walking skeletons lesson, in Pro, drills this. “Version one answers clerks in one office from the civil procedure manuals, signed in through the court’s identity provider, with the open and restricted split enforced in the search. It skips the other manual sets and the feedback buttons until that office has used it.”

That version proves the boundary and the permissions before anything else. For our full model answer, see the court retrieval question. For the retrieval internals on their own, read the RAG system design walkthrough.

The decision table: what you choose and why

Each row is one sentence you can say: “We chose this because that.”

DecisionChoiceBecause
Sign-inCourt’s identity providerNo new passwords; groups drive access
PermissionsFilter in the search, before rankingTop results are all ones the clerk may open; nothing hints at sealed sections
ModelsManaged over a private endpoint, if signed offCourt IT can run it after handover
SearchKeyword plus vectorRule numbers and form codes
IngestBy document ID and content hash; access lists synced separatelyReruns are safe; a re-sealed section closes without a re-embed
Chunk with no access listReadable by nobody until syncedFail closed
AnswersCite a section or say none foundClerks can check every claim
TelemetryCourt’s monitoring, no query textTraces carry case details
Your team’s accessNone standing; logged break-glassThe court holds the keys
First releaseOne office, civil manualsProves boundary and permissions first

Say one row aloud the way you would to the court’s IT lead: “We keep query text out of metrics and traces, because a stack trace with a clerk’s question in it is a case record in the wrong place. Only the audit log holds it, under your retention rules.”

Rollout, rollback and who can turn it off

“Redeploy the previous version” is not a rollback plan here. An assistant release can change code, a prompt or model, the index and a schema, and a redeploy undoes only the first.

ChangeHow you undo it
CodePrevious signed image in the court’s registry
Prompt or chat modelRevert the versioned config, rerun the eval set
Embedding modelTreat it as an index change: flip back to the old index
IndexBuild the new version, flip the active pointer, flip back
SchemaExpand first, contract in a later release

Four habits make that table work:

  • Ship through their process. Every model or prompt change goes to the change board with its evaluation report attached, as a planned change, not a hotfix.
  • Start small. Release to one office first, a canary release, and agree with the court what healthy looks like before you widen it.
  • Rehearse the rollback. Run it once in a copy of their environment. A rollback nobody has run is a hope.
  • Give them the off switch. The court’s on-call can turn it off without you.

Say the last one out loud: “Your on-call can switch this off without us, and clerks fall back to the manual index. Nothing about their work depends on the assistant being up.”

To drill this part alone, answer rolling out a risky change in a customer’s environment; its follow-ups cover a schema migration and a change window that closes halfway. The sign-in half has its own question: design SSO with same-day deprovisioning.

Will they actually ask about SSO and VPCs?

Maybe not by name. One prep site says they do, and cites no reports. Source 16Forward Deployed Engineer Interview Guide 2026PublisherSundeep Teki (personal blog / paid guide)Source typeinterview prep site Neither candidate quoted above named , placement or .

What to do with that gap:

  • Raise identity, boundary and data yourself, as short questions in the first minutes.
  • Go deep only when the interviewer follows.
  • If they say “assume it’s all handled”, state the assumption in one sentence and move on: “I’ll assume sign-in through your identity provider and everything inside your tenancy. Stop me if either is wrong.”

Before your next design round

  • Write the opening questions from memory, with what each answer changes.
  • Say a in two sentences for a prompt you have not seen.
  • Draw the court design with the boundary first, and point to the permission check.
  • Answer “how do you know it’s right?” with your evaluation set.
  • Say the rollback for code, prompt, embeddings, index and schema without notes.
  • Say the court conflict aloud in under a minute, with your recommendation.

Now do it cold: write your five questions and your walking skeleton for the court retrieval question, then compare with our model answer. The enterprise design lesson is free and gives you a structure for the whole hour. Then practice against a customer who answers back in the free practice case (you sign in first). The walking skeletons lesson and the rest of the Pro lessons come with Pro, which starts with a 7-day free trial. The pricing page has the details.

GlossaryForward deployed engineerA software engineer who builds and ships production systems inside a customer’s problem and environment, accountable to that customer’s outcome.More on Forward deployed engineerGlossaryAgentA system in which a model chooses steps and tool calls to complete a task, within limits the design sets.More on AgentGlossaryRetrieval-augmented generationAnswering with a model that is given passages retrieved from a document collection as context.More on Retrieval-augmented generationGlossaryOAuthA standard for granting an application limited, revocable access to resources on a user’s behalf without sharing passwords.More on OAuthGlossaryOpenID ConnectAn identity layer on top of OAuth that lets an application verify who a user is and get basic profile claims.More on OpenID ConnectGlossarySAMLAn XML-based standard for exchanging authentication assertions between an identity provider and an application.More on SAMLGlossarySCIMA standard protocol for provisioning and deprovisioning users and groups from an identity provider into applications.More on SCIMGlossaryHIPAAThe US law whose Privacy and Security Rules govern protected health information and the vendors that handle it.More on HIPAAGlossaryEmbeddingA vector representation of text or other data used to measure similarity of meaning.More on EmbeddingGlossarySingle sign-onSigning in once through a central identity provider and using that session across many applications.More on Single sign-onGlossaryVirtual private cloudAn isolated network inside a cloud provider where the customer controls addressing, routing, egress and private links to other accounts.More on Virtual private cloudGlossaryData residencyA requirement that data, including logs and backups, be stored and processed in a specific region.More on Data residencyGlossaryWalking skeletonThe thinnest end-to-end version of a system that performs one small real function across its main components, built first and then extended.More on Walking skeleton

Questions people ask

What is enterprise system design in an FDE interview?

It is a design question framed around one customer. Their identity provider, network, data rules and existing systems come first, and scale comes later. We teach it this way because FDE postings list such constraints as requirements, for example identity protocols such as OAuth, OIDC, SAML and SCIM, or safeguards for protected health information.Source 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job postingSource 11Forward Deployed Engineer (FDE), Healthcare - SF (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 12Forward Deployed Engineer (FDE), Healthcare - NYC (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job posting

Do candidates report being asked about SSO and VPC deployment in FDE system design interviews?

Not by name in the reports we collected. One candidate reported, in July 2026, a design round covering security, deployment considerations and evaluation, and another candidate reported, in August 2026, a design focused on the enterprise, including security. Neither named SSO, VPC placement or data residency. Employers do list identity and compliance requirements in FDE postings, so raise them briefly yourself.Source 1FDE Interview Experience at Google (L4) (Blind)PublisherBlindSource typecandidate report on BlindSource 2Google Forward Deployed Engineer Interview Experience (Blind)PublisherBlindSource typecandidate report on BlindSource 3Is Google FDE interview same as SWE? (Blind)PublisherBlindSource typecandidate report on BlindSource 4Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 5Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 6Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting

How is enterprise design different from a classic system design interview?

Classic prep scales a consumer product. The enterprise version asks you to fit inside someone else’s environment. Users sign in through their identity provider, data may not leave their cloud, a security review stands before go-live, and they control the rollout and the rollback.

Keep reading