Layers

User → planner (safety + intent + task decomposition) → LLM (constrained). Planner may reject request without LLM call.

Advertisement

Reduces LLM risk

LLM sees only vetted requests. Guardrails apply at planner not LLM. Failure modes at planner easier to reason about.

Advertisement

Task-specific planners

Financial planner rejects trades outside allowed instruments. Medical planner enforces disclaimer. Legal planner requires citation.

Implementation

Small deterministic rules + small LLM. Fast. Auditable. Can log all decisions.