AI guardrails enforced in code: rules the sales agent cannot break
A rule in a prompt is a suggestion the model usually follows. A rule in code is a block. Linkubit's assistant runs behind three checks that sit outside the model — before it may use a tool, before a message may leave, and on the reply it wrote — so a persuasive customer cannot talk it past a limit, and a bug fails as a refused action rather than an ungoverned one.
A rule names what it matches — a topic, a field, a value, a tool — and one of a closed set of effects: block, require a person, require approval, hand over. Each effect has an enforcement branch and an unrecognised one is refused rather than ignored. A reply may state a price only when the turn retrieved one; a reply claiming to be a person is caught; a change to a rule, a price or a campaign is a pending approval a person decides; a flood of messages hands the conversation to a human; and every rule that fired is a line on the customer's timeline.
Closed, not free text
Rules with enforced effects
A rule is a condition over what the conversation and the record contain, and an effect from a fixed set. "No quote before the budget is known" makes the quote tool unavailable to the model until the field exists; "hazardous cargo goes to a person" hands over before any reply is written. The set of effects is closed and each has code behind it — a rule that nothing enforces cannot be saved.
- Rules match capabilities, so a new tool cannot slip past an old rule
- Every rule that fired is written on the contact's timeline
Never quote before lane and volume are captured
Tool blockedHazardous cargo always goes to a human
EscalatedDiscounts above 10% need a manager
Approval requiredIt may draft, never decide
Anything that spends waits for a person
A discount past its limit, a new ad campaign, a change to the catalogue, a change to its own rules — the assistant can draft each as an approval and never enact it. A person decides, with the number in front of them. An agent that could edit its own governance is an agent whose constraints it chooses.
- The tool set is closed: five tools, and a sixth needs an argument, not an import
- A person's edit to the assistant is a plan shown first, applied only on approval
12% discount on quote Q-1148 · ₹4.2L
AIRequested by the agent mid-conversation. Above the 10% threshold, so it stops here.
The rest of it
A price only when it was looked up
The reply verifier lets a reply state a price only when the turn actually retrieved a product with one. Grounding is earned by a tool result, never asserted by a caller.
It will not deny being an AI
It does not volunteer it, and it never lies about it. A reply that claims to be a person is caught by a check that sits outside the model and cannot be configured away.
Floods, ceilings and blocks
More than forty messages on one conversation in ten minutes hands it to a human. A workspace has an hourly ceiling on assistant turns. A person can be blocked, and a blocked person is refused on every send path and hidden from the inbox.
Answers that show their source
An answer drawn from your documents points at the document and page it came from. A question those do not cover is handed over, not improvised.
What it is made of
Rules enforced in code, not the prompt
Write a rule in plain words. It’s checked outside the AI, so it isn’t a suggestion: “never give a price before you know their budget” is refused and stopped before sending.
Anything that spends waits for a person
A discount past its limit, a new ad campaign, a change to its own rules — the assistant can draft it and never enact it. A person decides, with the number in front of them.
It will not deny being an AI
It doesn’t volunteer it, and it never lies about it. A reply that claims to be a person is caught by a check that sits outside the model and cannot be configured away.
Messages can’t be edited, and everything is logged
What was said stays exactly as it was said; a correction is a new message. Every change to a deal, a rule or a role is written down with who made it and when, so a dispute has a record to go to.
Questions people ask
How is a rule different from an instruction in the prompt?
An instruction is text the model reads and usually follows. A rule is checked by code the model cannot see or argue with: the tool it would need is withheld, the message it wrote is refused, or the conversation is handed to a person. The model is shown the rule too, so it behaves; the code is what makes it certain.
What can the assistant never do?
State a price it did not look up. Deny being an AI. Enact a discount past the limit, a campaign, a catalogue change or a change to its own rules — each becomes an approval. Reach a person who unsubscribed, was suppressed or was blocked. Use a tool outside the five it has.
Can a customer jailbreak it?
They can try, and the model may even want to comply — which is why the checks are outside the model. A rule that withholds the quote tool cannot be talked around, and a reply that breaks the verifier does not send. A flood of messages hands the conversation to a person rather than letting it run.
Can I see when a rule fired?
Yes — every rule that took effect, every handover and every approval requested is a line on the contact's timeline with what caused it, beside every other thing the product did about that person.
Read next
Ready to put your sales on autopilot?
Start freeNo coding required. No credit card required.