State model
Short-lived turn state references an immutable transcript and context manifest. It does not copy source records or create durable customer memory by default.
Protection depends on the legal entity holding a deposit, ownership structure and applicable limit, which may not align with the customer-facing brand or account grouping.
The explainer resolves accounts to legal entities and beneficial owners, applies effective protection rules and presents covered, aggregated and uncertain amounts with cited assumptions.
Organisations, systems and operating conditions are intentionally anonymised and recomposed. The design demonstrates engineering and banking-domain reasoning; it does not represent a named client estate, vendor product or measured production result.
Five operating planes separate interaction, identity, decision control, authoritative state and operating evidence.
Permitted workThe system explains approved information and calculations. Product eligibility, suitability, tax interpretation and legal effect remain separately governed.
Consistency ruleResolve brand, legal entity, product version, jurisdiction and effective date before using a rule or term.
Hard boundaryThe model is not a system of record, identity provider, policy authority or proof that an external effect occurred.
A customer or service operator needs a grounded answer from live state and controlled knowledge, without a direct business effect.
The response cannot collapse brands into entities, assume beneficial ownership or present an uncertain balance as protected.
A deterministic outer workflow contains model-led work inside typed, observable calls. Dashed messages remain proposals until policy or a human grants authority.
Short-lived turn state references an immutable transcript and context manifest. It does not copy source records or create durable customer memory by default.
Use direct read APIs for stable same-domain calls. Use a mediated gateway when the call crosses trust boundaries, needs shared throttling, or exposes reusable capabilities.
Bind all facts to a snapshot or as-of time. A partial source set remains partial; the system never substitutes a plausible zero or stale value.
These roles are deliberately vendor-neutral. Each can be independently owned, versioned and replaced.
Returns candidate entities and typed relationships with match features, contradictions, effective dates and non-merge evidence.
Serves owned, audience-qualified and effective-dated content; exposes supersession, withdrawal and dependency metadata.
Builds time-qualified projections from source events and reconciliations without becoming the legal system of record.
Presents claims beside evidence, alternatives, uncertainty, missing information, permitted actions and current custody.
Appends request, versions, policy result, model proposal, approval, action receipt, readback, correction and custody events under one correlation key.
Evaluates identity, purpose, capability, amount, risk tier and policy version; returns allow, deny, step-up or human-review with reasons.
Durable records carry provenance, authority, effect and custody without turning a transcript into an uncontrolled memory store.
Resolve brand, legal entity, product version, jurisdiction and effective date before using a rule or term.
The selected design is not universally superior. It is the safer fit for this boundary and failure cost.
Bias consequential journeys against false merge and retain unresolved candidates.
Automatically merge the highest-scoring candidate.
Cost acceptedMore cases require clarification, but one person's authority or risk cannot silently attach to another.
Federate authoring while centralising lifecycle metadata, validation and serving rules.
Create one centrally authored knowledge corpus.
Cost acceptedFederation requires stronger contracts and owner discipline, but preserves domain accountability and release velocity.
Use event-fed projections for scale and direct readback for consequential effects.
Fan out to all systems of record for every interaction.
Cost acceptedRead models introduce lag and reconciliation work, but reduce source load and make cross-system views feasible.
Keep people at irreversible, ambiguous and policy-exception points; sample lower-risk automated outcomes independently.
Require the same manual approval at every step.
Cost acceptedRisk-tiering reduces review load but needs calibrated thresholds, sampling and immediate withdrawal of authority when drift appears.
Use append-only events plus a rebuildable current-state projection.
Overwrite the case row with its latest status.
Cost acceptedReplay and storage are more complex, but point-in-time reconstruction and correction lineage remain possible.
Compile stable decision logic and retain retrieval for explanation and residual ambiguity.
Ask a model to interpret the source document for every request.
Cost acceptedRule compilation needs controlled change, but creates repeatable decisions, regression tests and clear exceptions.
Retries are bounded by knowledge of business effect; unknown outcome remains visible, owned and independently reconciled.
Actual thresholds belong to accountable service owners. The design exposes the equations and observables that those owners must baseline.
peak_read_qps = concurrent_sessions x turns_per_minute x source_fanout / 60p95_turn_latency = max(required_source_reads) + policy + model + validationcontext_cost = admitted_input_tokens x routed_turnsUse customer holdings only when necessary for the current explanation and keep external or assumed circumstances visibly separate.
A design is production-ready only when teams can prove what happened, recover it and change it safely.
product and rule applicability
guidance-versus-advice boundary
superseded-content withdrawal
calculation and citation verification
Account-to-entity links, ownership basis, balance timestamp, rule version, aggregation calculation, exclusions and uncertainty.
A specialist resolves disputed ownership or entity mapping before consequential reliance.
Begin with one read-only journey and explicit fallbacks. Add personalisation only after freshness, source precedence and context-minimisation evidence hold.
Product, conduct, legal, tax, knowledge and advisory owners define the permitted answer boundary.