Work arrives
An email, a WhatsApp message, a scanned page, a certificate request. The agent receives it with the account’s context — policies, history, open items — already attached.
Draft, with citations
The agent drafts the change and cites it. Every field it filled carries where the value came from and when it was fetched — a policy page, a county record, a prior conversation.
The checker runs
A second pass verifies the draft: requirements met, entities matched against the state registry, arithmetic re-done. The results are pinned next to the item — met, on file, or flagged.
A person reviews
The queue shows the change field by field, old value against new, with what accepting it would touch downstream. Clean items can be approved together; flagged ones cannot.
The owner sent a WhatsApp asking to add a fourth building at 1420 W 12 Ave. The agent pulled the parcel, drafted the carrier request and staged eight field changes. Nothing has been written to the policy.
One write event
Approval writes the change, appends the audit entry in the same transaction, and freezes a snapshot of what was issued. This is the only door into the record — and a human holds it.
Three things the agents cannot do.
Train on your data
Client accounts, documents and correspondence never train models — contractually. Model calls go through one internal gateway that strips identifiers before anything leaves.
Send anything on their own
No agent can email, message or file anything outbound by itself. Outbound is an action like any other: drafted, checked, and released by a person.
Take instructions from a document
External text — an email, a scanned contract, a web page — is processed as data, never as instructions. A clever sentence in a PDF cannot steer the agent.