The important promises are refusals.
Anybody can write “we take compliance seriously” on a page. What follows is the list of things this software will not do, and for each one, the mechanism that makes it unable to, because an intention is not a control.
Five things Lewis will not do
It will not send a fair-housing line, even if you approve it
The check runs on the model’s output, on every message, at every autonomy level, and it runs on messages you dictate too. There is no path through the product that skips it and no button that overrides it. Fair housing.
It will not assert a fact about a property
There is no MLS behind Lewis. It cannot know bedrooms, square footage, price, taxes or availability, so any sentence claiming one is invented by construction. Those are blocked on the way out, and a property question arriving from a lead is escalated to you rather than answered.
The same rule covers distances. An exact distance is arithmetic and free. A travel time is not, and there is no detour multiplier anywhere in the product: East Boston to Back Bay is three miles straight and twenty-odd around the harbour. Unrouted, the sentence says “0.9 miles away in a straight line”, which names its own limitation instead of inviting you to assume a walking mile.
It will not send anything you have not approved, unless you said it could
Every draft is held. If you grant copilot mode (explicitly, in words), Lewis works on its own, and you take that permission back the same way. Even then, what it may say is unchanged.
It will not text somebody who has opted out
A STOP is honoured across the whole brokerage, permanently, and re-checked at the moment of sending rather than only at the moment of composing. That check is keyed on the phone number and is global across every seat. Opt-out policy.
It will not pretend to be a person
Lewis introduces itself as an assistant in its first message, in its own bubble, ahead of any work. Folding a disclosure into a sales pitch makes a legal notice read as a feature. AI disclosure.
Blocked never becomes held. An agent skimming approvals at 7am waves things through.
Why these are code and not prompt instructions
A rule written into a prompt is a request to a model. It usually works. “Usually” is the problem: the failure is silent, it happens on the turn nobody is watching, and there is no record afterwards distinguishing the time the instruction held from the time it did not.
The rails here run after the model, on what it produced. Every verdict is written to the event log with the rule that fired. So the question “did the guardrail work” has an answer you can read rather than an answer you have to trust.
What this is not
It is not legal advice, and it is not a substitute for your brokerage’s own compliance policy. It is a mechanical control on outbound messages plus a record of every decision, which is a useful thing to be able to hand somebody, and is not the same thing as an opinion about the law.
If a guardrail blocks something you wanted to send, the fix is the message rather than the guardrail. That has come up genuinely: a closing line said “I’ll take you off the list”, tripped the promise rule, and the right answer was to rephrase the line.