Spring AI: retrieval and tools with controlled authority
Prerequisites: 01-ecosystem
Who owns authority when the model calls a tool?
Goal & mental model verified
Spring AI offers model, embedding, vector-store and tool abstractions. RAG retrieves context for generation; tools let the model request application capabilities. The application executes those capabilities and owns the resulting authority.
[S55] [S56]Worked example · design exercise synthesis
An assistant retrieves permitted policy wording and drafts an explanation. A requested issuePolicy tool must still validate the agent, tenant, eligibility and required approval in ordinary application code.
[S55] [S56] [S57]Engineering decision synthesis
Use the framework to integrate models, not to outsource business authorization. Retrieval improves grounding under suitable data and chunking, but cannot guarantee factual correctness.
[S55] [S56] [S57]Pitfall & diagnosis synthesis
Retrieved text and model output can be untrusted. A tool exposed to a model may have real side effects; prompt wording alone cannot enforce access rules or prevent repeated operations.
[S55] [S56] [S57]Improve & validate synthesis
Build a small evaluation set covering wrong-tenant retrieval, unsupported answers and unsafe tool requests. Trace sources and measure correctness, latency and cost before broadening capabilities.
[S55] [S56] [S57]Check yourself: Does retrieved context make every answer true?
No. Retrieval can be incomplete or wrong, and generation can still misinterpret it.