Air-Gapped & On-Prem
Reference Architecture: District Collectorate AI
· 9 minute read
A collectorate does not need a miniature ministry cloud. It needs three workflows, one rack story, and a written list of systems the agent may touch.
District Collectorates are where Indian administration still becomes paper, a hearing, and a signature. They are also where well-meaning AI programmes go to die, because the vendor arrived with a reference architecture drawn for a 200-person digital unit and a hyperscaler landing zone. A collectorate has a District Magistrate, a handful of section officers, a NIC presence, a set of state and central applications it does not own, and a public that arrives in person.
The useful reference architecture is therefore small. It names the workflows a collectorate can actually supervise. It names the systems those workflows already use. It puts inference either in the NIC room or in the state SDC. It refuses to invent a new citizen database. And it assumes the night operator is a person who already has three other duties.
This template is for CIOs, state IT missions and collectors who have been asked to put AI in the district. It is a starting drawing, not a certified design. Change the nouns to match your state applications. Do not change the habit of naming nouns.
Three workflows, not a platform
Start with three desks that already have volume and a human in the loop. A typical honest set is: a grievance or PG portal drafting assistant that reads the existing ticket and the relevant circular; a meeting-brief assistant that summarises yesterday's files for the DM's morning pile; and a circular-and-standing-order retrieval assistant for section officers. Certificate issuance, mutation, and entitlement decisions are possible later. They are not week-one workflows because they change a citizen's legal position.
Each workflow gets a purpose sentence, a system of record it may read, a list of tools it may call, and a rule that it drafts but does not dispose. The collector or the section officer still signs. An agent that closes a grievance is not an assistant. It is an unauthorised officer. Refuse a general chatbot on the public website as the first use. Public chat without retrieval grounded in your circulars will hallucinate scheme names.
| Layer | Typical collectorate placement | Do not |
|---|---|---|
| Officer UI | Browser on NIC/department LAN, SSO via existing AD if any | Install a vendor thick client with its own update cloud |
| Orchestration / agent runtime | NIC room server or SDC, not a clerk desktop | Run on the DM's laptop for the pilot |
| Model inference | Local CPU/GPU box or SDC model service | Call a public model API from the LAN |
| Retrieval corpus | Circulars, SOs, redacted manuals on local store | Index live Aadhaar-bearing applications without a basis |
| Systems of record | Existing state/central apps via documented internal APIs or read replicas | Scrape screens or store a second copy of the whole district database |
| Identity | Existing NIC/department accounts | Vendor cloud users named after officers |
| Logs | Local syslog plus state SIEM copy if policy says so, 180 days in India | Vendor SaaS APM with prompt text |
| Updates | Media or SDC push | Nightly internet pull |
What the NIC room can honestly hold
Many collectorates can hold a 1U or tower inference box, a small disk for the corpus, and a jump host. They cannot hold a Kubernetes circus, a dedicated SRE, and a 24x7 NOC. If your drawing needs those, the drawing belongs in the SDC and the district should be a client.
Power and dust are design inputs. Specify filtered intake, a UPS the building already understands, and a temperature you can actually keep. A GPU that thermal-throttles at 2pm in May is not a reference architecture. It is a summer outage. Network: one processing VLAN without a default route; one management VLAN the NIC lead already uses; no guest Wi-Fi bridge. If the only internet in the room is a 4G router someone brought for Aadhaar eKYC, that router is not an uplink for the model.
Data you will be tempted to index — and should not, yet
The land-records extract. The ration-card dump. The last five years of grievance attachments. The CCTV archive at the gate. Each of these will be offered as context. Each is a legal and operational swamp. Circulars and standing orders are context. Live personal databases are systems of record with their own owners, often not the collectorate.
If a workflow must read a live store, do it through the owning application's interface, for that ticket, under that officer's identity, and do not persist a second copy in the vector index. Persistence is how a retrieval assistant becomes an unauthorised warehouse. DPDP still applies to digital personal data the agent touches. The collectorate, or the state department that owns the purpose, is the fiduciary. The platform vendor is a processor.
- Name three draft-only workflows and the officer who remains accountable.
- Put inference in the NIC room or refuse local inference and use the SDC.
- Index circulars first. Do not clone district databases into vectors.
- Wire identity and 180-day logs before the first live ticket.
- Write the no-outbound or named-egress sentence and test it.
- Publish a one-page drawing the collector can recognise.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
This is too small. Other districts are buying a full platform.
Other districts are buying slideware. A collectorate that runs three supervised workflows with logs and no unofficial ChatGPT desk is ahead of a district with a portal nobody uses.
NIC will not take another box.
Then do not put a box there. Use the SDC and a browser. A box without an owner is a future incident.
We need the public chatbot for digital India optics.
Optics that hallucinate a scheme are worse than no chatbot. If politics demands a public page, ground it in a tiny, approved FAQ corpus and refuse anything else. Do not index the district.
Six weeks to a collectorate drawing you can fund
- Week 1: sit with the reader, the PG cell and one section. Write three purpose sentences.
- Week 2: inventory systems of record and who owns each. Strike any we'll just dump it.
- Week 3: choose NIC-room box versus SDC portal based on power, people and WAN.
- Week 4: draw the VLANs, identity, logs and update path. One page.
- Week 5: run a no-outbound or named-egress staging test on the chosen placement.
- Week 6: put the drawing, the three sentences and the test behind the note seeking approval.
How this shows up in the file
Attach a one-page diagram a collector can annotate, the three workflow cards, the list of systems not to index, and the name of the NIC or SDC owner. If the diagram has more clouds than rooms, redraw it.
This is a template. Your state's application names will differ. The duty to name them does not.
The one-page drawing, in words you can sketch
Draw three boxes on a single sheet. Left: officer browser on the LAN. Middle: agent runtime and retrieval store in the NIC room or a label that says SDC via SWAN. Right: systems of record the collectorate already has. Arrows from middle to right are labelled read, ticket-scoped, officer identity. No arrow from middle to the public internet. A small box under middle says logs / 180 days. A smaller box says updates via media. That is the architecture.
What the public counter should see — and not see
Citizens at the counter should see the same officer as last year, perhaps faster. They should not see a chatbot that invents a scheme. If politics wants a screen, put a search over the approved FAQ corpus on that screen and refuse anything else. Do not put the internal agent on a kiosk.
Staffing the boring roles
Name a corpus owner — the person who decides which circular is current. Name a log owner. Name a media owner. In a small collectorate these may be two people. They may not be zero people. When the DM changes, reprint the names. Reference architectures fail at transfers of charge more often than at first install. Budget two half-days a year for a refresh. If the budget cannot stand two half-days, do not install a box. Use the SDC portal and let HQ own the refresh.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, CERT-In direction, GFR, GeM term, SDC policy and your counsel before you file it.
Questions this usually raises
- Should the Zilla Parishad share the collectorate agent?
- Only with a written purpose and role map. Shared login because it is the same campus creates a joint-control mess. Separate desks can share a model service and still keep separate corpora and logs.
- Where should GPUs live for a single district?
- Usually they should not. Start on CPU or on the SDC's shared GPU. Buy a district GPU only when a named workflow has failed the CPU budget and someone will own the box in May.
- Can we connect eOffice or the state file system on day one?
- Connect read-only, for the files the officer can already see, after the owning unit agrees. Do not grant the agent a superuser on the file system because the demo looks better.
- Is this architecture sovereign because it is in the collectorate?
- Location helps control. It does not finish DPDP, CERT-In, procurement or exit. Sovereignty remains a set of claims you evidence, not a pin on the district map.