Ask a strong backend engineer to design a notification service and you get fan-out, partitions and a delivery rate. Make the customer a hospital network, running it in its own cloud account, and the first question becomes whether a text may carry a patient’s name. In a customer-framed design round, the customer’s environment sets the architecture, not traffic. Here is how to open: the questions, what each answer moves, and what to say when two collide.

What candidates report being asked

Prepare for two prompts: a CTO role-play about an AI system, and a classic system design with an ’s name on it.

Two people on Blind describe the first. One poster, for a Google (L4) role, reported in July 2026 a 60-minute round in which the interviewer “acted as the CTO of a company looking to implement a smart AI-powered system”; a commenter in another thread wrote that one round is “consulting with a CTO” about building agents. Source 1FDE Interview Experience at Google (L4) - BlindPublisherBlindSource typecandidate report on BlindSource 2Is Google FDE interview same as SWE? - BlindPublisherBlindSource typecandidate report on Blind The poster listed requirements, scoping, architecture, deployment, scalability, security and evaluation; in that second thread, a commenter said it can stay high level but went lower, into prompts, state machines, retries and handling hallucinations. Source 1FDE Interview Experience at Google (L4) - BlindPublisherBlindSource typecandidate report on BlindSource 2Is Google FDE interview same as SWE? - BlindPublisherBlindSource typecandidate report on BlindSource 3Google Forward Deployed Engineer Interview Experience (Blind)PublisherBlindSource typecandidate report on Blind

A candidate for an L5 FDE role in Google’s Cloud AI division reported on Blind, in August 2026, a design interview “specifically for agents”, naming “Evals, guardrails”. Source 4Google FDE vs Remain Amazon SDEPublisherBlind (teamblind.com)Source typecandidate report on BlindSource 5Google L5 FDE vs Remain Amazon L5 SDEPublisherBlind (teamblind.com)Source typecandidate report on Blind

The classic prompt shows up too. A Reddit commenter wrote, in June 2026, that they “got classic system design questions on the name of a production agent” and that “it felt like interviewer didnt know agentic systems”. Source 6Forward Deployed Engineer, GenAI, Google Cloud - EU (comment by u/Cool-Groot)PublisherReddit r/leetcodeSource typecandidate report on RedditSource 7Forward Deployed Engineer, GenAI, Google Cloud - EU (comment by u/Cool-Groot)PublisherReddit r/leetcodeSource typecandidate report on Reddit The thread’s title names Google Cloud’s GenAI FDE role; the commenter named no company.

Agent depth has its own module, the agent design round.

Starting from the customer, not the scale

Open with: “Before I size anything, I want to understand your environment; it will shape this more than traffic will.”

For the hospital, no traffic estimate answers these, and in our reading each moves a box:

  • May a text carry patient data? Assume not until compliance says so: “You have a new message from your care team; sign in to read it.” A sign-in page joins the design.
  • Which SMS provider? One from compliance’s approved list; if patient data could reach it, expect a business associate agreement.
  • Who approves each release? Their change board, so the rollout plan names it.

The constraints to ask about first

Ask one question per constraint below, then a seventh about go-live, and say what each answer changes before you draw. In short: compliance moves where data rests, identity moves where permissions come from, and operations moves what you can afford to run.

ConstraintWhat the answer changes
Compliance regimeWhere data rests, what is logged, which vendors are allowed
Data volume and freshnessBatch or incremental ingestion
Latency and concurrencyStreaming, caching, model size
Identity providerSAML or OIDC; how users and groups are provisioned; where permissions come from
Deployment boundaryYour cloud reached privately, or deployed in their account; egress rules
Budget and operationsManaged or self-run parts; release cadence

Said aloud:

“Before I draw anything, a few questions, because each one changes the design. Which rules and audits apply? How much data, and how fresh? How long will people wait, and how many ask at once? Who signs in, and through what? Where must this run, and what may it call? And who runs it after we leave, and how does a change get to production here? Last one, in two parts: what will your security team need to see before this goes live, and what would convince your service lead the answers are right?”

The seventh moves the evaluation set and the . As of September 2026, OpenAI’s Healthcare FDE posting asks its hires to define launch criteria that measure quality “against customer-specific acceptance thresholds”. Source 8Forward Deployed Engineer (FDE), Healthcare - SFPublisherOpenAI (Ashby)Source typecompany job posting

Ask them as one batch; where the interviewer won’t answer, assume out loud and move on: “I’ll assume Entra, and I’ll flag it.” Clarifying can eat the hour: one candidate reported on Aced, in August 2026, for a mid-level Google FDE role, that by the time their questions about a very abstract system were done, time was almost up. Source 9Google Forward Deployed Engineer Interview ExperiencePublisherAced (formerly Exponent)Source typecandidate’s personal write-up In a decomposition case, two questions that flip the plan are enough; in a design round the constraints are the problem, so ask all seven, fast.

The fictional pump maker this module follows answered like this, on the board:

users:
  - technicians, dispatchers
  - US and EU
  - managed tablets on cellular
ask:
  - cited answers from manuals
  - service history, open orders
later:
  - close the ERP work order
compliance:
  - vendor SOC 2 Type 2 report
  - GDPR for EU staff, site contacts
data:
  - ~40,000 manuals, bulletins
  - a few hundred change a month
  - ~2M service records, in ERP
latency:
  - first words within 3 s
  - full answer within 10 s
concurrency:
  - up to 400 asking at once
  - weekday mornings
identity:
  - Microsoft Entra ID
  - groups by region, product line
boundary:
  - their AWS account, US and EU
  - no public endpoints
  - ERP on premises, via plant link
operations:
  - two FDEs for one quarter
  - then plant IT runs it
  - weekly change board
go_live:
  - their security review
  - service lead signs off on
    answers to real questions

What each answer changed:

  • Entra groups: filter passages by the verified token’s groups inside the search query, before ranking, never in the prompt. Past the token’s group limit, Entra sends a Microsoft Graph pointer instead of the list: ask how many groups a technician has, and use app roles or groups assigned to the application.

  • ERP on premises: the riskiest integration, over their plant link (Direct Connect or a site-to-site VPN), so it goes in version one. Ask how many reads a second its API takes; if morning lookups could exceed that, keep each machine’s history for the session.

  • A few hundred changes a month: ingest manuals incrementally; service records stay in the ERP, looked up live.

  • Latency and concurrency: stream the answer, then size the model, not the app:

    peak:   400 asking at once
    answer: ~10 s, start to end
    => ~40 requests/s at the model
    in:  ~4,000 tokens each
         (question + passages)
    out: ~400 tokens each
    => ~9.6M input tokens/min
    => ~1M output tokens/min

    Say: “The app autoscales; the model quota in your account for that region is what I’d check in week one, because raising it takes time. Is that peak asking at once, or signed in?”

  • EU staff and site contacts: a question can name a site contact, so keep EU personal records in the EU region and answer from a model endpoint in the EU, the simplest answer to GDPR Chapter V. An EU cross-region inference profile stays in EU regions; a global one does not. Ask their data protection officer before promising more.

  • Vendor audit report: every service in the answer path, model endpoint included, passes their vendor review first.

  • Plant IT and a change board: prefer managed services, and ship model or prompt changes as planned changes, with evaluation reports.

Then find two answers that cannot both hold, and resolve them out loud. Here, nothing may be public, yet technicians work over cellular:

“Those two can’t both hold as stated. Two ways through: a per-app VPN from the tablets you manage into your existing network, or an access service in front of the app. That service has an internet address, but refuses any request without a valid Entra sign-in and logs each against a named user. So, for your security team: does ‘nothing public’ mean no unauthenticated endpoint, or no new internet address at all? If the first, I’d lean to the access service: no VPN client on every tablet. If the second, the VPN: the app adds no address of its own. Your network team owns that call.”

Ask what the constraint protects, recommend a way with its reason, and hand the call to its owner. The access service could be AWS Verified Access, which is itself internet-facing. Then read the constraints back in one breath: “So: your AWS account, nothing public, Entra sign-in, EU records in the EU region, releases through the weekly change board, and a security review before go-live. Anything I’ve missed that would stop this shipping?”

Our design rubric’s first dimension scores asking about each of these constraints and what the customer’s security and operations teams require; a conflict resolved with the customer scores higher.

Five ways to lose the first minutes

  • Drawing boxes before the first constraint question.
  • Asking only about scale.
  • Asking questions whose answers change nothing.
  • Asking so long that the design never starts.
  • Saying “we’ll make it compliant”. Compliance is the customer’s whole program: describe the controls you provide, and expect to sign the business associate agreement HIPAA requires of a vendor handling patient data.

The same questions on a data platform prompt

A data prompt: “Unify the pump maker’s plant sensor historians and ERP failure records to predict pump failures”:

ConstraintWhat the answer decides
ComplianceWhich plant data may leave the site
FreshnessChange data capture, or a nightly extract
LatencyNightly batch, or streaming if a prediction must act within a shift
IdentityRow filters by plant: Unity Catalog, or Snowflake row access policies
BoundaryTheir workspace, and whether the plant network reaches the cloud
OperationsWho fixes the pipeline when a historian tag is renamed

One commenter on Blind, replying in September 2026 about a Databricks FDE design round, wrote that it is “mostly” about building a full-stack distributed system, covers data engineering and ML, and focuses on “FDE mindset rather than what tools you are using”; they did not say how they knew. Source 10FDE interview at Databricks (Blind)PublisherBlindSource typecandidate report on Blind

Identity, network and compliance: raise them yourself

Keep them brief, and go deep only if the interviewer follows. The reports we collected name security and deployment, never , network placement or ; postings, below, ask for the skills. One paid prep guide, Sundeep Teki’s, says FDE design interviews ask for deployment, SSO and HIPAA or constraints, citing no candidate reports. Source 11Forward Deployed Engineer Interview Guide 2026PublisherSundeep Teki (personal blog / paid guide)Source typeinterview prep site

As of September 2026, Okta’s FDE postings list identity protocols, among them , and . Source 12Senior Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 13Principal Forward Deployed Engineer - Okta for AI AgentsPublisherOkta (Greenhouse)Source typecompany job postingSource 14Principal Forward Deployed Engineer (Singapore)PublisherOkta (Greenhouse)Source typecompany job posting Cohere’s infrastructure FDE posting covers deploying its North product “in private cloud and on-premises environments”. Source 15Forward Deployed Engineer, Infrastructure Specialist (North America)PublisherCohere (Ashby job board)Source typecompany job posting OpenAI’s Healthcare FDE postings require safeguards for PHI and HIPAA. Source 8Forward Deployed Engineer (FDE), Healthcare - SFPublisherOpenAI (Ashby)Source typecompany job postingSource 16Forward Deployed Engineer (FDE), Healthcare - NYC (Ashby)PublisherOpenAI (Ashby job board)Source typecompany job posting

A structure for the hour

Run the hour in this order, naming each step; each is one dimension of our design rubric.

  1. Requirements and constraints. The seven questions, targets as numbers, one conflict resolved.
  2. . The thinnest deployable version, proving the riskiest integration, with its stages to production and what it skips. For the pump maker: “Version one answers US technicians on one product line from its manuals, through Entra sign-in, with service history from the ERP over the plant link. It skips writing to work orders until plant IT approves a write path.”
  3. Components and data flow. One path from source to user, each box justified, one removed: “Manuals land in S3; a worker re-indexes changed files, tagging passages by region and product line; the API sits behind the access service; the model runs in the technician’s region; history is a live ERP call, kept for the session. Removed: a copy of the service records; the ERP holds them.”
  4. Trust boundaries and identity. Who authenticates how, where permissions are enforced (the data layer, never the prompt), what may leave, and what a stolen credential reaches: “The ERP call uses a read-only service identity; a stolen tablet token reaches one technician’s manuals and history until the session ends.” Practice with the SSO design question.
  5. Failure modes and rollback. What fails per dependency, what the user sees, and how code, prompt, config and data are undone through their change process: “If the plant link drops, answer from the manuals and say history is unavailable.” Practice with rolling out a risky change.
  6. Observability and evaluation. Traces, a measure of answer quality, and agreed launch criteria: “The technicians’ question set, scored on every model or prompt change.” Practice with How do you know it works?
  7. Trade-offs, cost and communication. Close with two sentences to the CTO: “We chose [X] over [Y] because [reason], and version one proves [the risk] first. The cost driver is [A]; I’d revisit [B] if [C] changes.”

Our design rubric gates on the walking skeleton and on observability and evaluation: a run that falls short on either cannot pass, however strong the rest.

Get Pro to go further today: Clarify before you solve covers when to stop asking and commit, Narration, the board and the clock paces a sixty-minute run, and the walking skeleton builds step two. This module’s page shows which of its Pro lessons are live.

Now write your opening for the court retrieval question: a state court’s clerks want cited answers from its procedure manuals, inside the court’s own cloud tenancy, with no case records leaving it. Write your seven questions, each with what its answer could move. Name the two answers most likely to conflict, and what you’d say to the court’s IT lead. Then compare yours with the question’s framework.

GlossaryAgentA system in which a model chooses steps and tool calls to complete a task, within limits the design sets.More on AgentGlossaryForward deployed engineerA software engineer who builds and ships production systems inside a customer’s problem and environment, accountable to that customer’s outcome.More on Forward deployed engineerGlossaryLaunch criteriaThresholds agreed with a customer before building that decide whether a system goes live.More on Launch criteriaGlossaryHIPAAThe US law whose Privacy and Security Rules govern protected health information and the vendors that handle it.More on HIPAAGlossarySingle sign-onSigning in once through a central identity provider and using that session across many applications.More on Single sign-onGlossaryData residencyA requirement that data, including logs and backups, be stored and processed in a specific region.More on Data residencyGlossaryVirtual private cloudAn isolated network inside a cloud provider where the customer controls addressing, routing, egress and private links to other accounts.More on Virtual private cloudGlossarySOC 2An auditor’s attestation report on a service organization’s controls against the AICPA trust services criteria.More on SOC 2GlossarySAMLAn XML-based standard for exchanging authentication assertions between an identity provider and an application.More on SAMLGlossaryOpenID ConnectAn identity layer on top of OAuth that lets an application verify who a user is and get basic profile claims.More on OpenID ConnectGlossarySCIMA standard protocol for provisioning and deprovisioning users and groups from an identity provider into applications.More on SCIMGlossaryWalking skeletonThe thinnest end-to-end version of a system that performs one small real function across its main components, built first and then extended.More on Walking skeleton