AI Studio: from a use case to operations
An illustrated use case connects knowledge, AI Gateway, customizable workflows, sandbox execution and data controls.
Choose a chapter · 16 chapters
Read the story
One question. Too many places to look.
An employee wants to understand how to purchase equipment for their team. The answer is scattered across documents, email, and colleagues. Finding a paragraph is only the start. Is it current? Is the employee allowed to see it? And who approves the next step?
One request, one connected process.
Follow an illustrative use case: an internal purchasing assistant. An employee asks a question in an application built with AI Studio. The application finds the relevant procedure, helps draft a request, and passes it to a responsible reviewer. This is a process you can design, not a built-in purchasing system for every organization.
OCR, NER and knowledge pipelines.
Inputs may include documents or images that need OCR to extract text. NER helps identify entities such as personal names, alongside policy-based PII rules. Detection is assistance, not a guarantee that every sensitive detail will be found. Configure processing, chunking, and indexing next. Folders, synchronized sources, knowledge pipelines, hybrid retrieval, and reranking help organize the collection and test its quality.
Retrieve the right data, with the right access.
Before a document becomes part of an answer, the caller needs appropriate access. Organization boundaries, departments, and sensitivity levels affect retrieval. Unauthorized documents should not enter the context. In this example, the assistant retrieves the permitted passages needed to prepare the next step.
Customize the workflow to fit your work.
A workflow is not a fixed path. Connect node families for inputs, retrieval, models, branches, loops, data processing, and outputs. Define input variables, run a test, and inspect each step to find problems. Drafts, version history, DSL import and export, and reusable graph snippets support deliberate changes before publication.
AI Gateway: route the model request.
With context ready, the application still needs a route to a model. In this diagram, AI Gateway describes the model orchestration layer in AI Studio. It filters eligible models by policy, manages connection credentials, and can fall back to an allowed model after a suitable error. Both internal and external models must meet the configuration and data policy.
What is allowed to leave the boundary?
Data protection takes several layers. On the chat path, personal information can be masked according to the configured policy. Sensitivity labels determine whether an external provider is allowed. Tool calls also pass destination controls. A disallowed request must be blocked. Masking personal information alone does not make every payload safe to send outside.
Run custom code in a separate sandbox.
For custom logic, a Code node sends work to a separate sandbox service. This execution boundary separates user code from the main process and applies the sandbox limits. The node stays disabled when the service is not configured. A sandbox does not replace permissions or outbound controls; tool calls still need their own policies.
AI drafts. A person decides.
Back to the purchasing request. AI prepares a draft for a responsible person to review. If changes are needed, it returns for revision. Only after approval does this designed workflow continue to the configured tool. Build this gate for actions with consequences; do not assume that every model output should be executed automatically.
Connect tools without hiding their effects.
Connect built-in tools, API tools, MCP servers, or a workflow exposed as a tool. Data source integrations and external knowledge services bring in information from other systems. Moderation extensions require a compatible service contract. Enable only the operations you need and verify access, connection settings, and permitted destinations before use.
From a draft to channels and triggers.
After testing, publish an application to the web, embed a widget, or integrate through API and MCP access with appropriate permissions. Messaging channels need provider-specific setup. Scheduled triggers and webhooks can start workflows with suitable authentication and event configuration. API documentation, access keys, and quotas help manage how other systems call the application.
Conversations, memory and more modalities.
Configure conversation starters, inputs, follow-up questions, and business behavior. Long-term memory includes evidence review, approval, and retention settings tied to a subject. Speech recognition, text-to-speech, and image generation depend on connected models. Enable the capabilities that serve the use case, and review what the application retains.
Measure quality before expanding.
Inspect conversations and run logs to understand what happened. Use evaluation datasets, compatible run comparisons, and annotations to check quality. Monitor usage and operations to detect problems. Data can be prepared for training, while fine-tuning still depends on a runner, resources, and deployment configuration, not just a button.
Manage workspaces and the installation.
Manage members, invitations, roles, keys, and quotas at workspace level. Identity, data protection, model providers, and S3 storage support operations. Instance administrators have separate access to organization and account views, service health, and runtime configuration. Some network and feature-flag screens are read-only inspection surfaces, not direct editing controls.
One platform, several use cases.
The same building blocks can support internal policy questions, assist customer support staff, process documents, or coordinate business approvals. Each application needs its own data sources, access rules, tools, and evaluation criteria. Test within a small scope before expanding.
From a question to a controlled outcome.
AI Studio connects people, knowledge, models, and workflows. The value is more than a faster answer. It is a process you can inspect: where the data came from, which model was called, who made the decision, and what happened. Start with a concrete use case, evaluate quality, and observe operations before expanding.



