Skip to content
AI Inside the WorkflowShippedAI

Rules get the last word on every model-drafted plan

Rules rewrite banned words, named protocols, and practitioner names in every plan before it is stored. Ten adversarial fixtures prove it with no model call.

  • Supabase
  • Custom

The problem

A wellness plan can never say cure, heal, or patient. It can never name a protocol or a practitioner from the knowledge base. A rule in the prompt gets you most of the way, and most of the way is not good enough when the plan goes out under a clinic's name. The model also sometimes refuses, or returns a fragment, and the clinic still needs a plan.

What we built

Three ordered passes run on every plan after synthesis and before it is stored, so the PDF only ever renders scrubbed text. The first rewrites ten banned terms with case-preserving replacements and is always on. The second replaces named protocols with a plain description of what they are. The third replaces a practitioner's name in every form it shows up in a plan. The second and third are configured per clinic. The practitioner-name pass also runs on the intake's free text before it reaches a prompt, and all three re-run on every staff edit. A hit is rewritten in place, never blocked; the counts are stored with the plan version and the activity row says how many were rewritten.

When the model refuses or returns a fragment, a detector flags it, a retry ladder regenerates with progressively less sensitive context, and a deterministic fallback assembles a plan from the briefs if every attempt fails. Every outcome is recorded, and a partial fallback marks the plan "review recommended."

The proof is a golden set: ten intakes, each paired with a draft deliberately seeded with the exact names and protocols the scrubber must remove. Sixty-two test cases assert zero leaks. None of them call a model, so the guardrail is tested for free and the result is the same every time.

Where AI does the work

A model drafts the plan from the intake and the methodology briefs. It writes under compliance rules in every stage's prompt, and it never decides whether its own output is compliant.

Where rules do the work

Three regex passes run on every plan before it is stored: a banned-word rewrite for the cure, heal, and patient families, a named-protocol scrubber, and a practitioner-name scrubber. The same passes re-run on every staff edit. A refusal detector flags drafts that refuse or come back too short, a retry ladder regenerates with less sensitive context, and a deterministic fallback assembles a plan when the model never produces one. A golden set of adversarial drafts asserts zero leaks without calling a model.

Outcome

On the golden set, ten adversarial drafts seeded with the exact names and protocols the scrubber must remove come out with 0 name leaks, 0 protocol leaks, and 0 cure, heal, or patient terms, across 62 test cases that never call a model. The live pipeline's timing run reported 0 compliance violations. The golden set runs on demand, not on every deploy.

Who this fits

  • Teams putting a model in front of regulated or brand-sensitive copy
  • Anyone whose AI output needs a rule to have the last word before it is stored
  • Products that need proof the guardrail works without paying for a model call

See it running first.

Proof first. Then we'll talk about your stack.

How we work →