Clinical AI Kit home Documentation hub / End-to-End Request Flow

End-to-End Request Flow

Every request crosses three security gates and one routing decision. BPMN-style lanes: User, Security, Orchestrator, Pipelines.

flowchart TD
    subgraph LANE_USER["Lane: User"]
        START([User request]) --> IN[Message enters agent]
        RESP([Response delivered])
    end

    subgraph LANE_SEC["Lane: Security (callbacks.py)"]
        L1{Layer 1
content_safety_callback
injection? unicode attack?} L2{Layer 2
tool_authorization_callback
args valid? rate ok? secrets?} L3{Layer 3
output_safety_callback
PII/PHI/secret leak?} BLOCK1[Block + log_security_event] BLOCK2[Block + log_security_event] REDACT[Redact or block + log] end subgraph LANE_ORCH["Lane: Orchestrator (flash-lite)"] ROUTE{Intent routing} MCPT[MCP tools / memory recall / HITL approval] end subgraph LANE_PIPE["Lane: Pipelines (SequentialAgent)"] P1[Image Extraction
7 specialist LLM agents] P2[Patient Q&A
8 specialist LLM agents] P3[DB Intelligence
6 specialist LLM agents] TOOLS[Tool execution
Pydantic-validated] end IN --> L1 L1 -->|blocked| BLOCK1 --> RESP L1 -->|clean| ROUTE ROUTE -->|image workflow| P1 ROUTE -->|patient question| P2 ROUTE -->|database question| P3 ROUTE -->|direct| MCPT P1 --> L2 P2 --> L2 P3 --> L2 MCPT --> L2 L2 -->|blocked| BLOCK2 --> RESP L2 -->|valid| TOOLS TOOLS --> L3 L3 -->|found| REDACT --> RESP L3 -->|clean| RESP

Key facts:

Related: Security Layers · Agent Architecture · Image Extraction Pipeline · Patient QA Pipeline · DB Intelligence Pipeline