# Foundation (/docs/foundation)



Foundation is the shared platform layer beneath AI and Data. It turns infrastructure into governed services for identity, inference, networking, observability, storage, databases, policy, workflows, and software delivery.

Most users do not need Foundation component detail. Platform engineers use this section to understand responsibility boundaries, make architecture decisions, and diagnose the services behind a customer workflow.

## Foundation capabilities [#foundation-capabilities]

| Capability                     | Responsibility                                                                           | Start with                                                          |
| ------------------------------ | ---------------------------------------------------------------------------------------- | ------------------------------------------------------------------- |
| **Identity and policy**        | authenticate users and services, enforce tenant and team boundaries, and deliver secrets | [Security and compliance](/docs/security#identity-and-access)       |
| **Inference**                  | schedule and serve models with the required compute, runtime, and gateway behavior       | [Inference](/docs/foundation/inference)                             |
| **Networking**                 | expose services through DNS, certificates, gateways, routes, and trust relationships     | [Networking](/docs/foundation/networking)                           |
| **Observability and audit**    | collect metrics, logs, traces, dashboards, and operational evidence                      | [Observability and audit](/docs/foundation/observability-and-audit) |
| **Storage and databases**      | provide persistent object, block, relational, and vector storage                         | [Storage and databases](/docs/foundation/storage-and-databases)     |
| **Core services and delivery** | reconcile configuration, run durable workflows, enforce policy, and deliver releases     | [Operating model](/docs/foundation/operating-model)                 |

## How Foundation supports a request [#how-foundation-supports-a-request]

<Mermaid
  chart="flowchart TD
    REQUEST[&#x22;User or application request&#x22;] --> IDENTITY[&#x22;Identity and policy&#x22;]
    IDENTITY --> ROUTING[&#x22;Networking and routing&#x22;]
    ROUTING --> SERVICE[&#x22;AI or Data service&#x22;]
    SERVICE --> COMPUTE[&#x22;Inference or compute&#x22;]
    SERVICE --> STATE[&#x22;Storage and databases&#x22;]
    SERVICE --> TELEMETRY[&#x22;Metrics, logs, traces, and audit&#x22;]"
/>

The exact components can change without changing the customer-facing contract. Applications integrate through documented product interfaces such as the BSQAI API, while internal services remain behind the Foundation boundary.

## Operating boundaries [#operating-boundaries]

* **Provider administrators** own installation-wide configuration, hard limits, and tenant lifecycle.
* **Platform engineers** own service health, capacity, networking, storage, upgrades, and recovery.
* **Tenant administrators** own federation, membership, delegation, and policies inside one tenant.
* **Application and data teams** consume Foundation services through AI and Data interfaces.

Use [Core concepts](/docs/core-concepts) for the installation, tenant, team, and resource hierarchy. Use [Deploy and operate](/docs/operate) for the lifecycle that begins before installation and continues through upgrades and recovery.

## Architecture and implementation [#architecture-and-implementation]

<Cards>
  <Card title="Reference architecture" href="/docs/foundation/reference-architecture" />

  <Card title="Operating model" href="/docs/foundation/operating-model" />

  <Card title="Security model" href="/docs/foundation/security-model" />

  <Card title="How products rely on Foundation" href="/docs/foundation/how-products-rely-on-foundation" />

  <Card title="Foundation component catalog" href="/docs/foundation/components" />

  <Card title="Troubleshooting" href="/docs/troubleshooting" />
</Cards>
