Layers
User → planner (safety + intent + task decomposition) → LLM (constrained). Planner may reject request without LLM call.
Advertisement
Reduces LLM risk
LLM sees only vetted requests. Guardrails apply at planner not LLM. Failure modes at planner easier to reason about.
Advertisement
Task-specific planners
Financial planner rejects trades outside allowed instruments. Medical planner enforces disclaimer. Legal planner requires citation.
Implementation
Small deterministic rules + small LLM. Fast. Auditable. Can log all decisions.