Shipping a 'simple' lead-capture agent: why privacy and consent keep breaking the architecture

ravann4 · reddit · 2026-10-03

A developer details the real engineering behind a lead-capture chat agent for a real-estate client — originally scoped as one prompt and two tools for a week, it ballooned as requirements changed and the listing feed grew to 80k entries.

Final architecture (3 tiers)

Where privacy keeps breaking: the model claimed there was no privacy policy link (there was), rewrote the required consent sentence (now hardcoded), "Did you send it?" got misclassified, local test chats leaked into the client's real CRM via a shared dev database, and a corrected email still sent the old one. Every time the model touched compliance text it drifted; every rule moved into code spawned new edge cases.

Open questions: keep the fast classifier (0 of 33 failures were its fault)? Is GPT-6 Luna the right tool-calling pick (68/9/2 vs 62/13/4 pass/partial/fail, half the cost)? How to guarantee consent steps survive weekly requirement churn?

Original post →

More from coding & agent

coding & agent channel →