In this post10 sections
- Why ‘design a feed’ prep misses the enterprise round
- What FDE postings say you will deploy into
- Start from constraints: five questions before any box
- Worked design: a retrieval assistant inside a court’s own cloud
- The decision table: what you choose and why
- Rollout, rollback and who can turn it off
- Will they actually ask about SSO and VPCs?
- Questions people ask
- Keep reading
- More from the blog
You spent a week on sharding timelines and fan-out on write. Then the prompt names a customer: a state court wants its clerks to ask questions of its procedure manuals, the system has to run inside the court’s own cloud, and no case record may leave it. That is the enterprise system design interview, and this post walks through one answer; for where the round sits in the loop, read the FDE interview guide.
The short answer: an enterprise system design interview asks you to design for one named customer, so their identity provider, network boundary, data rules and change process shape the architecture before load does. Open with those constraints. Say the thinnest version that proves the riskiest integration, a walking skeleton. Then draw the components, and finish with a rollout and a rollback the customer controls.
Why ‘design a feed’ prep misses the enterprise round
Feed prep trains one reflex: estimate the traffic, then let the numbers pick the boxes. Put the same service inside a hospital’s cloud account and the first questions become which vendors their compliance team allows and who signs off a release. None of those has a number for an answer, and each one changes the diagram.
The free enterprise design lesson runs the full opening on a pump maker; here we make the same move on a court.
What do reports say? One Blind poster interviewing for a Google (L4) role reported, in July 2026, choosing an Design track in a system architecture round run as a role-play, with the interviewer as the CTO of a company that wanted an AI-powered system; the discussion covered requirements, scoping, architecture, deployment considerations, scalability, security and evaluation. Source 1FDE Interview Experience at Google (L4) (Blind)PublisherBlindSource typecandidate report on BlindSource 2Google Forward Deployed Engineer Interview Experience (Blind)PublisherBlindSource typecandidate report on BlindSource 3Is Google FDE interview same as SWE? (Blind)PublisherBlindSource typecandidate report on Blind
One commenter wrote, in August 2026, in a Reddit thread about Google’s FDE (GenAI) loop, that they had to design an agent, with the design “focused mostly on the enterprise (security, , model routing, multi agent...)”; they did not name the company or the role. Source 4Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 5Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 6Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on Reddit
A Blind commenter in a thread about Google’s FDE interview described the same CTO format, without naming the company. Source 3Is Google FDE interview same as SWE? (Blind)PublisherBlindSource typecandidate report on Blind All of these reports concern Google and agents; we have none for other employers, so prepare for a classic prompt too. If your prompt is an agent for a CTO, the agentic system design walkthrough takes that shape.
What FDE postings say you will deploy into
Postings are where the enterprise constraints show up by name. Here is what they said in September 2026. Source 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job postingSource 10Forward Deployed Engineer, Infrastructure Specialist (North America)PublisherCohere (Ashby job board)Source typecompany job postingSource 11Forward Deployed Engineer (FDE), Healthcare - SF (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 12Forward Deployed Engineer (FDE), Healthcare - NYC (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 13Forward Deployed Engineer IV, GenAI, Google Cloud — Google CareersPublisherGoogleSource typecompany job postingSource 14AI Deployment Strategist @ SnowflakePublisherSnowflake (Ashby job board)Source typecompany job postingSource 15Forward Deployed Engineer (FDE) - SFPublisherOpenAI (Ashby)Source typecompany job posting
- Identity. Okta’s FDE postings list identity protocols by name, among them , , and . Source 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting
- Deployment boundary. Cohere’s Forward Deployed Engineer, Infrastructure Specialist (North America) posting covers deploying its North product “in private cloud and on-premises environments” and asks for production Kubernetes and Helm experience. Source 10Forward Deployed Engineer, Infrastructure Specialist (North America)PublisherCohere (Ashby job board)Source typecompany job posting
- Regulated data. OpenAI’s Healthcare FDE postings require building with safeguards for PHI and , and the San Francisco posting’s line also names privacy, security, authorization, governance and auditability. Source 11Forward Deployed Engineer (FDE), Healthcare - SF (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 12Forward Deployed Engineer (FDE), Healthcare - NYC (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job posting
- Their environment, not yours. Google Cloud’s GenAI FDE postings describe an embedded builder who codes, debugs and jointly ships agentic solutions “directly within the customer’s environment”. Source 13Forward Deployed Engineer IV, GenAI, Google Cloud — Google CareersPublisherGoogleSource typecompany job posting Snowflake describes its Forward Deployed Engineering team as inside enterprise customers’ environments to design, build and deploy production AI systems. Source 14AI Deployment Strategist @ SnowflakePublisherSnowflake (Ashby job board)Source typecompany job posting
- The rollout. OpenAI’s San Francisco FDE posting says the hire will “own discovery, technical scoping, system design, build, and production rollout”. Source 15Forward Deployed Engineer (FDE) - SFPublisherOpenAI (Ashby)Source typecompany job posting
Labs, a data platform, an identity vendor and a cloud provider all write these lines, which is why we choose to drill identity, network, data and rollback. To turn lines like these into a prep list for one role, use how to read a job posting.
Start from constraints: five questions before any box
Ask these before you draw, and say what each answer changes. In our method, a question whose answer changes nothing is filler.
- Identity: who signs in, and through what? The answer picks SAML or OIDC for sign-in, SCIM or a directory sync for users and groups, and where permissions come from.
- Boundary: where must this run, and what may it call? The answer decides between your cloud reached over a private endpoint and a deployment in their account, sets the egress rules, and says whether any managed model service is allowed. For government networks, where the boundary comes with a clearance, see FDE jobs that need a security clearance.
- Data: what is sensitive, where may it rest, and for how long? The answer sets data residency, what you may log, and retention. It also tells you whether the user’s question is itself sensitive.
- Change: how does a release reach production here, and who runs it after you leave? The answer sets release cadence, managed versus self-run parts, and what rollback means.
- Security review: what does their security team need to see before go-live? The answer lists the documents you owe, such as a data flow diagram and a list of every service, and often changes what you build first.
Said aloud, in one breath:
“Before I draw anything, a few questions, because each one changes the design. Who signs in, and through which identity provider? Where must this run, and what may it call out to? Which data is sensitive, and where may it rest? How does a change reach production here, and who runs it after we leave? And what will your security team need to see before go-live?”
Size one thing, and name it: here, the model endpoint at the hour clerks start work, since the app tier is small.
Then find two answers that cannot both hold, recommend a side, and hand the call to its owner.
One phrase to avoid: “we’ll make it HIPAA compliant”. No system is compliant on its own: compliance covers the organization’s policies, agreements and controls. Name the controls you provide, and expect to sign the business associate agreement HIPAA requires of a vendor that handles patient data.
Worked design: a retrieval assistant inside a court’s own cloud
The prompt, which is fiction: “A state court system wants its clerks to ask questions of its procedure manuals and standing orders and get answers with citations. It runs inside the court’s own cloud tenancy. No case record may leave it.”
You ask the questions above. The court’s answers, as you would write them on the board:
| Question | Court’s answer |
|---|---|
| Users | Court staff in county offices, not the public |
| Identity | Court’s identity provider; groups by office and role |
| Restricted | Sealed and juvenile procedures, some roles only |
| Boundary | Court’s tenancy; no public egress from the app tier |
| Models | No external model service approved yet |
| Change | Monthly change board; court IT runs it after handover |
| Security review | Data flow diagram and a list of every service |
The conflict, and what you say
Two answers collide: no external model service is approved, so models would run on GPUs inside the tenancy, and court IT runs everything after handover. Say:
“These pull against each other. Open-weights models on your GPUs keep every query inside, but your team would run GPU inference after we leave. Your provider’s managed model over a private endpoint is far less to run, but the query leaves your network. I’d lean to the managed option with region pinning and no prompt retention, put to your security office in writing, because GPU operations is the likelier failure after handover. It’s their call: which will they sign?”
The components
This is the move that turns a generic diagram into a design for this court. Clerks will paste case details into their questions, so the question text is a case record. The embedding call, the model call, the logs and the error tracker all have to sit inside the boundary, or cross it only with the security office’s signature. Say that, and draw the boundary first.
In the order data flows:
- Ingest worker. It reads from the court’s document system, which stays the source of truth, and splits each manual by section. Every chunk carries its manual, section number, effective date, a link back and the document’s access list. Access lists sync separately and more often than text, and a deleted document’s chunks are removed on the next sync; say the revocation delay out loud and agree it with the court.
- Search index. Keyword plus vector (hybrid search), because manuals are full of rule numbers and form codes that embeddings match poorly.
- Assistant API. It takes the user’s groups from the validated identity token, never from the request body. If the token can’t carry every group (Entra drops the claim past 200, per Microsoft’s docs), look membership up in Microsoft Graph, as those docs advise, or in a directory you sync by SCIM, keyed on the token’s subject.
- Models. Wherever the conflict lands: open-weights models on GPUs in the tenancy, or managed models over a private endpoint such as AWS PrivateLink, which keeps traffic off the public internet while the model still runs outside the court’s network. Hence the signature.
- Answer step. The prompt holds only permitted chunks. Every claim cites a section the clerk can open, and with no supporting passage it says so and links the manual index.
- Evaluation. Senior clerks write questions the way clerks type them, each paired with the section that answers it, plus some the manuals can’t answer. Rerun on every prompt, model or index change.
- Audit log. Who asked what, and which chunks the answer used. Because queries hold case details, retention is the court records officer’s call, not yours.
Where the permission check lives
Put it inside the search, before ranking. Filtering after ranking can return nothing, or leak that a restricted section exists. A toy version, with a clerk who is not cleared for sealed procedures:
chunks = [
{"id": "seal-4", "acl": {"seal"}, "s": .91},
{"id": "seal-9", "acl": {"seal"}, "s": .88},
{"id": "civ-12", "acl": {"all"}, "s": .74},
]
groups = {"all"} # from the verified token
k = 2
def ok(c):
return bool(c["acl"] & groups)
def top(cs):
return sorted(cs, key=lambda c: -c["s"])[:k]
# Wrong: rank, then filter
wrong = [c["id"] for c in top(chunks) if ok(c)]
# Right: filter inside the search
right = [c["id"] for c in top(filter(ok, chunks))]
print(wrong)
print(right)
The first line prints []: the top results were sealed, so the clerk gets no answer even though a permitted section exists. The second prints ['civ-12']. In Elasticsearch, put the filter inside the kNN clause: it is applied during the search so k matching results come back, while a post-filter can return fewer than k (Elastic docs). “The prompt tells the model not to show sealed content” is the wrong answer; expect the follow-up: where exactly is the check?
The walking skeleton for the court
Say it before the first box; the walking skeletons lesson, in Pro, drills this. “Version one answers clerks in one office from the civil procedure manuals, signed in through the court’s identity provider, with the open and restricted split enforced in the search. It skips the other manual sets and the feedback buttons until that office has used it.”
That version proves the boundary and the permissions before anything else. For our full model answer, see the court retrieval question. For the retrieval internals on their own, read the RAG system design walkthrough.
The decision table: what you choose and why
Each row is one sentence you can say: “We chose this because that.”
| Decision | Choice | Because |
|---|---|---|
| Sign-in | Court’s identity provider | No new passwords; groups drive access |
| Permissions | Filter in the search, before ranking | Top results are all ones the clerk may open; nothing hints at sealed sections |
| Models | Managed over a private endpoint, if signed off | Court IT can run it after handover |
| Search | Keyword plus vector | Rule numbers and form codes |
| Ingest | By document ID and content hash; access lists synced separately | Reruns are safe; a re-sealed section closes without a re-embed |
| Chunk with no access list | Readable by nobody until synced | Fail closed |
| Answers | Cite a section or say none found | Clerks can check every claim |
| Telemetry | Court’s monitoring, no query text | Traces carry case details |
| Your team’s access | None standing; logged break-glass | The court holds the keys |
| First release | One office, civil manuals | Proves boundary and permissions first |
Say one row aloud the way you would to the court’s IT lead: “We keep query text out of metrics and traces, because a stack trace with a clerk’s question in it is a case record in the wrong place. Only the audit log holds it, under your retention rules.”
Rollout, rollback and who can turn it off
“Redeploy the previous version” is not a rollback plan here. An assistant release can change code, a prompt or model, the index and a schema, and a redeploy undoes only the first.
| Change | How you undo it |
|---|---|
| Code | Previous signed image in the court’s registry |
| Prompt or chat model | Revert the versioned config, rerun the eval set |
| Embedding model | Treat it as an index change: flip back to the old index |
| Index | Build the new version, flip the active pointer, flip back |
| Schema | Expand first, contract in a later release |
Four habits make that table work:
- Ship through their process. Every model or prompt change goes to the change board with its evaluation report attached, as a planned change, not a hotfix.
- Start small. Release to one office first, a canary release, and agree with the court what healthy looks like before you widen it.
- Rehearse the rollback. Run it once in a copy of their environment. A rollback nobody has run is a hope.
- Give them the off switch. The court’s on-call can turn it off without you.
Say the last one out loud: “Your on-call can switch this off without us, and clerks fall back to the manual index. Nothing about their work depends on the assistant being up.”
To drill this part alone, answer rolling out a risky change in a customer’s environment; its follow-ups cover a schema migration and a change window that closes halfway. The sign-in half has its own question: design SSO with same-day deprovisioning.
Will they actually ask about SSO and VPCs?
Maybe not by name. One prep site says they do, and cites no reports. Source 16Forward Deployed Engineer Interview Guide 2026PublisherSundeep Teki (personal blog / paid guide)Source typeinterview prep site Neither candidate quoted above named , placement or .
What to do with that gap:
- Raise identity, boundary and data yourself, as short questions in the first minutes.
- Go deep only when the interviewer follows.
- If they say “assume it’s all handled”, state the assumption in one sentence and move on: “I’ll assume sign-in through your identity provider and everything inside your tenancy. Stop me if either is wrong.”
Before your next design round
- Write the opening questions from memory, with what each answer changes.
- Say a in two sentences for a prompt you have not seen.
- Draw the court design with the boundary first, and point to the permission check.
- Answer “how do you know it’s right?” with your evaluation set.
- Say the rollback for code, prompt, embeddings, index and schema without notes.
- Say the court conflict aloud in under a minute, with your recommendation.
Now do it cold: write your five questions and your walking skeleton for the court retrieval question, then compare with our model answer. The enterprise design lesson is free and gives you a structure for the whole hour. Then practice against a customer who answers back in the free practice case (you sign in first). The walking skeletons lesson and the rest of the Pro lessons come with Pro, which starts with a 7-day free trial. The pricing page has the details.
Questions people ask
What is enterprise system design in an FDE interview?
It is a design question framed around one customer. Their identity provider, network, data rules and existing systems come first, and scale comes later. We teach it this way because FDE postings list such constraints as requirements, for example identity protocols such as OAuth, OIDC, SAML and SCIM, or safeguards for protected health information.Source 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job postingSource 11Forward Deployed Engineer (FDE), Healthcare - SF (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job postingSource 12Forward Deployed Engineer (FDE), Healthcare - NYC (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job posting
Do candidates report being asked about SSO and VPC deployment in FDE system design interviews?
Not by name in the reports we collected. One candidate reported, in July 2026, a design round covering security, deployment considerations and evaluation, and another candidate reported, in August 2026, a design focused on the enterprise, including security. Neither named SSO, VPC placement or data residency. Employers do list identity and compliance requirements in FDE postings, so raise them briefly yourself.Source 1FDE Interview Experience at Google (L4) (Blind)PublisherBlindSource typecandidate report on BlindSource 2Google Forward Deployed Engineer Interview Experience (Blind)PublisherBlindSource typecandidate report on BlindSource 3Is Google FDE interview same as SWE? (Blind)PublisherBlindSource typecandidate report on BlindSource 4Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 5Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 6Google FDE (GenAI) — team match before HC? Curious about others' timelines (comment by u/Firm_Set2163)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 7Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 8Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 9Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting
How is enterprise design different from a classic system design interview?
Classic prep scales a consumer product. The enterprise version asks you to fit inside someone else’s environment. Users sign in through their identity provider, data may not leave their cloud, a security review stands before go-live, and they control the rollout and the rollback.
Keep reading
Lessons
Questions
- Design a retrieval assistant over a state court system’s procedure manuals, deployed inside the court’s own cloud tenancy, with no case records leaving it.
- Design how your product authenticates a large customer’s employees through their identity provider and removes access the day someone leaves.
- How do you roll out a risky change to a system running in a customer’s environment?
- Design a bulk import service that validates customer spreadsheets and explains every rejected row.
More from the blog
Interview rounds
RAG system design interview: a worked answer from ingestion to evaluation
Design a RAG system in the interview: ingestion, chunking, hybrid search, reranking, permissions, citations, evaluation, and cost and latency budgets.
Interview rounds
Agentic system design interview: tools, permissions, stuck agents and hand-off to a person
Design a safe agent in the interview: tool allowlists, scoped credentials, loop and cost budgets, idempotent actions, human approval and evals.
Interview rounds
Discovery call questions for engineers: what to ask a customer in the first meeting
What to ask a customer in the first meeting, by outcome, users, data, systems and constraints, with follow-ups that turn vague answers into requirements.