- 01
The LLM extracts. The server decides.
Model output is a proposal. Deterministic code resolves it against real records, and code does any writing.
Runs in SkillSchedule’s session setup · a 12-rooftop auto group’s statement pipeline
- 02
Read-only data roles
The database role an AI feature runs under cannot write. The database enforces it, and tests prove it.
Runs in a 12-rooftop auto group’s accounting assistant · Pour Path’s AI data API
- 03
Audit logs
Sensitive actions leave a row that says who did what, and why.
Runs in Permission overrides with a stated reason at a 12-rooftop auto group · every SMS, email and call attempt at TriaPet
- 04
Kill-switches
Capabilities that touch money or message customers ship disarmed, behind an explicit switch.
Runs in Willow’s money and messaging features
- 05
Penny-exact validation
A statement must balance against its printed totals to the penny, or it is quarantined for review.
Runs in a 12-rooftop auto group’s bank-statement pipeline
- 06
Disclosure boundaries
Tested limits on what an AI may say out loud, with hard-fail gates on anything outside them.
Runs in TriaPet’s voice agent