Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Casebook: Applying the Architecture Beyond KYC

The capstone uses an auditable case system because regulated review makes the control problems obvious. The architecture is broader than KYC. This casebook shows how the same seven pillars transfer to other expensive workflows.

Use each case as a design exercise:

  • what behavior must be evaluated?
  • what state must be typed?
  • where does human control sit?
  • what must be observed?
  • what can go wrong securely?
  • what does the workflow cost?
  • what trust artifact would help adoption?

Case 1: Agentic Revenue Operations

Production Pressure

A revenue team wants AI to research accounts, draft outreach, update CRM fields, and suggest next actions. The expensive failure is not only a bad email. It is silent CRM corruption, embarrassing external communication, duplicate outreach, or an agent spending money on low-value leads.

System Boundary

account signal intake
  -> enrichment
  -> lead scoring
  -> draft recommendation
  -> human approval
  -> CRM update
  -> outreach send
  -> outcome tracking

Seven-Pillar Design

PillarDesign move
Evaluationgolden accounts with expected qualification, disqualification, and escalation outcomes
Typed workflowProspectStatus, OutreachDraft, ApprovedMessage, CrmMutationRequest
Human controlAI drafts and recommends; human approves external sends and high-impact CRM changes
Observabilitytrace account source, model route, draft version, approval, send result, reply outcome
SecurityCRM write tools are scoped by account, field, and approval state
Economicscheap enrichment first, frontier model only for high-value accounts or ambiguous strategy
Distributiontrust artifact: “how the system prevents spam and CRM corruption”

Hard Rule

The model may draft an email. It may not send a first-touch enterprise email without approval.

Case 2: Civic Evidence Engine

Production Pressure

A civic organization wants to collect public evidence, summarize claims, identify contradictions, and publish explainers. The expensive failure is publishing unsupported claims, mixing opinion with evidence, or losing source provenance.

System Boundary

source intake
  -> provenance capture
  -> claim extraction
  -> evidence clustering
  -> contradiction review
  -> editor approval
  -> public publication
  -> correction loop

Seven-Pillar Design

PillarDesign move
Evaluationfixtures for unsupported claims, quote fidelity, source-date handling, and contradiction detection
Typed workflowSourceId, ClaimId, EvidenceCluster, EditorDecision, CorrectionRequest
Human controlAI prepares claim maps; editors approve public language
Observabilityrecord source URL, fetch time, extraction prompt, claim cluster, editor decision
Securityuntrusted web content cannot become system instruction or publication authority
Economicsbatch low-priority source clustering; reserve frontier models for contested summaries
Distributiontrust artifact: public methodology page with source and correction policy

Hard Rule

The model may suggest a claim summary. It may not publish a public accusation without editor approval and source traceability.

Case 3: Realtime Translation Quality System

Production Pressure

A conference or live event needs realtime translation. The expensive failure is not only mistranslation. It is latency that makes the stream useless, repeated segments, missing numbers, political phrase distortion, or no way to evaluate style changes.

System Boundary

audio stream
  -> transcription
  -> segment stabilization
  -> translation draft
  -> optional refinement
  -> listener delivery
  -> post-session evaluation

Seven-Pillar Design

PillarDesign move
Evaluationcorpus with source transcript, reference translation, required terms, number preservation, and latency targets
Typed workflowSessionId, SegmentId, DraftTranslation, CommittedTranslation, Revision
Human controlspeaker/admin controls session style and glossary; post-session reviewers correct gold data
Observabilitytrace first-token latency, segment commit latency, duplicate segments, provider reconnects
Securitylistener access is public only when intended; provider credentials stay server-side
Economicsrealtime path uses bounded models; expensive refinement can be async after the live event
Distributiontrust artifact: benchmark report by language pair and event style

Hard Rule

The system may revise a draft segment. It must not silently rewrite a committed transcript without preserving revision history.

Case 4: Developer Agent for Repository Maintenance

Production Pressure

A developer agent can inspect code, edit files, run tests, and propose fixes. The expensive failure is a destructive command, secret exposure, unreviewed production change, or a patch that passes tests while violating architecture.

System Boundary

issue or task
  -> repository inspection
  -> plan
  -> bounded file edits
  -> tests
  -> review summary
  -> human merge

Seven-Pillar Design

PillarDesign move
Evaluationregression tasks with expected diffs, tests, and forbidden destructive behavior
Typed workflowTaskId, ReadOnlyInspection, PatchProposal, ValidatedPatch, HumanMerge
Human controlagent may propose and validate; human owns merge and production deploy unless policy says otherwise
Observabilityrecord commands, files touched, tests run, failures, and rationale
Securityshell tools are permissioned; secrets and destructive commands are blocked or approval-gated
Economicslocal static checks before expensive model passes; use smaller models for search and summarization
Distributiontrust artifact: transparent run log and patch rationale

Hard Rule

The agent may edit a working tree under policy. It must not silently destroy user changes or deploy production without an explicit release gate.

Transfer Pattern

Across domains, the same architecture repeats:

untrusted input
  -> scoped evidence
  -> typed workflow
  -> model as assistant
  -> validation and eval
  -> human-owned sensitive transition
  -> semantic observability
  -> audit or trust artifact

When a new AI product idea appears, do not start with the prompt. Start by filling this pattern.