KSKS Security Research
Learning map / Session 2 / Scenes 13–16

SECURITY 05 · STACK

Choose one layerfor the problem it owns.

Map UI, API, orchestration, models, tools, state, observability, evaluations, and guardrails to the problem each layer owns.

LangGraphAgents SDKLangfuseNeMo Guardrails
Learning guide
Level
Applied
Reading time
14 min
Presentation
Session 2
Progress
5 of 6

01 · Mental model

A framework is a component, not the architecture

The UI manages interaction. The API terminates identity and transport. Orchestration owns sequence and state transitions. The runtime connects models and tools. Storage persists approved state. Observability records execution evidence. Evaluations measure behavior. Guardrails and policy enforce boundaries across every layer.

Select technologies from required behavior: explicit graphs and resumability may justify LangGraph; a smaller agent loop may fit an Agents SDK; Langfuse supports tracing and evaluation; NeMo Guardrails provides programmable conversational and execution rails. Do not add a framework merely because it appears in a reference stack.

02 · Visual explanation

01ExperienceReact / Next.js
02API + identityFastAPI / Node
03Orchestrationgraph / manager / code
04Models + toolsSDK / MCP / RAG
05Evidence + policytraces / evals / gates
The governed agent stackSecurity and auditability cross the stack; they are not a final box added after the runtime.

03 · Compare and decide

Use a tool when its control need appears

Decision lensTechnologyUse when
Agents SDKA focused agent runtime and tool loopYou need tool calls, handoffs, tracing hooks, and limited orchestration
LangGraphStateful graph orchestrationYou need checkpoints, branching, resumability, and explicit workflow nodes
LangfuseLLM observability and evaluationYou need traces, sessions, scores, datasets, and release comparison
NeMo Guardrails / OPAProgrammable rails or policyYou need reusable safety flows or deterministic authorization decisions

04 · Cybersecurity example

A right-sized first production stack

A read-only security review agent has one skill, three tools, and an expert reviewer.

01

Use a small SDK loop rather than a large graph.

02

Store typed run state and artifacts in PostgreSQL.

03

Trace sanitized execution in Langfuse.

04

Apply schema, policy, and approval gates in application code.

Outcome: The stack remains explainable and can add orchestration only when workflow evidence demands it.

05 · What to remember

The 60-second recall

01

Architecture decisions start from behavior and controls, not brand lists.

02

Observability and evaluation are different: one explains runs, the other measures quality.

03

Cross-cutting policy must remain independent of model choice.

Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.

06 · Questions people ask

FAQ

Use the smallest relevant packages and official integration guidance for your chosen version. The architectural question is whether you need an explicit state graph, not the brand sequence.

07 · Primary sources

Continue with authoritative guidance