Guardrails are code, not prompts.
A rule written into a prompt is a request. This runs on the model’s output, on every send, at every autonomy level, and there is no path through the product that skips it.
Three verdicts, and they are not three severities
Allow: the message goes to your queue.
Hold for approval: commitments. Dates, times, dollar figures, promises. This is the normal verdict for a good draft, because a useful message to a dormant lead usually names a day.
Block: fair housing, and any property fact Lewis cannot source. These never send and are never queued.
Why blocked does not become held
Because holding it would eventually send it.
An agent skimming a queue of approvals at 7am, one thumb, before the school run, will wave through “42 Oak is 1,850 sq ft with a new roof” without knowing whether it is true. Not through carelessness, because it reads like a normal sentence, and the queue’s job is to be got through. The only way to be sure it never goes out is for there to be no button.
So blocked messages are refused on the way out. There is nothing to approve and nothing to override.
What gets blocked
- Fair-housing language. Anything that steers on a protected class, however gently, and however well-intentioned the phrasing.
- Property facts. There is no MLS behind Lewis. It cannot know bedrooms, square footage, price, taxes or availability, so a sentence asserting one is invented by definition.
- Distances and travel times it cannot source. An exact distance is arithmetic and free. A travel time is neither. “About a 12 minute walk to the Prudential Center” passed every other rail and sent, once, and a commute is one of the two or three things somebody actually decides on. Now a minute figure comes from a provider that traced streets or it does not exist, and the unrouted sentence says “0.9 miles away in a straight line”, naming its own limitation instead of inviting you to assume a walking mile.
- A listing agent’s contact details, in a message. Knowing a number is not texting it, and nothing on the drafting path can even read one.
The bar the rails set is the same for everybody
The rails run on OUTPUT, which is the only place they can be trusted. A prompt instruction is checked by nothing; an output check runs on the turn nobody is watching.
They also run at every autonomy level, including copilot. Granting Lewis permission to work the list on its own changes who says yes to a draft. It does not change what is allowed to be a draft.
If a guardrail blocks something you wanted to send, the fix is the message, not the guardrail. That has come up genuinely: a closing line said “I’ll take you off the list”, tripped the promise rule, and the right answer was to rephrase the line.
Blocked never becomes held. An agent skimming approvals at 7am waves things through.