Blueprints Linted, living reference architectures for agentic systems.

Customer support agent with approved refunds

Routes support requests, answers from a policy knowledge base, and issues refunds only after a person approves.

router risk high v1 customer support seed

Why this topology

  1. interactive-latency: only workflow or router (interactive latency)
  2. high-risk-no-autonomy: autonomous topology removed (risk is high)
  3. prefer-workflow: agentic topologies removed (the task is not open-ended)
  4. autonomous-needs-consent: autonomous topology removed (autonomy is act_with_approval)
  5. multiple-task-kinds: router (3 request kinds)

Mandatory controls: human_gate input_filter audit_log retrieval

Flow

  1. classify → Request router · 600 in / 50 out
  2. answer → Answer writer · 2500 in / 400 out
Diagram source (Mermaid)
flowchart LR
    io_in(["request"])
    io_out(["response"])
    c_router_model(["Request router"])
    c_answer_model(["Answer writer"])
    c_policy_kb[("Policy knowledge base")]
    c_orders_tool[["Orders API"]]
    c_refund_gate{{"Refund approval"}}
    g_pii_filter>"input_filter"]
    g_audit>"audit_log"]
    io_in --> c_router_model
    c_router_model --> c_answer_model
    c_answer_model --> io_out
    g_pii_filter -.-> c_router_model
    g_pii_filter -.-> c_answer_model
    g_audit -.-> c_orders_tool

Components

idnamekindrolemodel / tool / framework
router-modelRequest routermodelclassify the request as order help, policy question or refund claude-haiku-4-5
answer-modelAnswer writermodelwrite the customer answer from retrieved policy text claude-sonnet-5-5
policy-kbPolicy knowledge baseretrievalpolicy and order-help articles
orders-toolOrders APItoollook up orders and issue refunds
refund-gateRefund approvalhuman_gatea support lead approves every refund

Guardrails

idkindprotectswhat it does
pii-filterinput_filterrouter-model, answer-modelRedacts card numbers and national ids before any model sees the text.
auditaudit_logorders-toolEvery order lookup and refund is logged with the request id and the approver.

Failure modes

failurecomponentmitigated by
A refund request is routed to the plain-answer path and the customer is told it is done.Request routerrefund-gate
An answer quotes a policy that has since changed.Policy knowledge baseaudit
Personal data reaches a model or a log.Answer writerpii-filter

Threats

OWASPcomponentmitigated bynote
LLM01 Prompt InjectionAnswer writerpii-filtercustomer text is untrusted input
LLM02 Sensitive Information DisclosureAnswer writerpii-filterpersonal data in prompts
LLM06 Excessive AgencyOrders APIrefund-gatewrite access to orders

Eval plan

metricmethodthreshold
routing accuracy200 labelled tickets, rerun on every prompt change>= 0.95
refund-gate coveragereplay of refund requests; no refund without an approval record100%

Observability and deployment

container behind the support portal · The gate is a queue in the support tool, not a model.

Estimated cost

$0.0098 per request · $1477.50 / month at 5000 requests/day · ~6.63 s end to end

Prices as of 2026-10-01 · source · latency is assumed.

Runnable starter

No starter is offered: no API data for langgraph from Radar yet.

Changelog