Shipping a 'simple' lead-capture agent: why privacy and consent keep breaking the architecture
ravann4 · reddit · 2026-10-03
A developer details the real engineering behind a lead-capture chat agent for a real-estate client — originally scoped as one prompt and two tools for a week, it ballooned as requirements changed and the listing feed grew to 80k entries.
Final architecture (3 tiers)
- Tier 1, code only: taps, yes/no, bare email/phone — no model
- Tier 2, a 300ms classifier: abuse, consent, bot checks, privacy questions
- Tier 3, one LLM call with 3 tools; every tool call gated by code, every recorded field checked against the buyer's actual words
Where privacy keeps breaking: the model claimed there was no privacy policy link (there was), rewrote the required consent sentence (now hardcoded), "Did you send it?" got misclassified, local test chats leaked into the client's real CRM via a shared dev database, and a corrected email still sent the old one. Every time the model touched compliance text it drifted; every rule moved into code spawned new edge cases.
Open questions: keep the fast classifier (0 of 33 failures were its fault)? Is GPT-6 Luna the right tool-calling pick (68/9/2 vs 62/13/4 pass/partial/fail, half the cost)? How to guarantee consent steps survive weekly requirement churn?
More from coding & agent
- Replaying agent sessions with cached tool outputs to test fixes and model swaps safely — pauliusztin · 2026-10-03
- Stop building eval sets by hand: grouping agent failures into a regression suite — pauliusztin · 2026-10-03
- Dev argues models are now smart enough to skip GPUI and lay out pixels with raw math — zack_overflow · 2026-10-03
- antirez: AI Coding Tool's Constant Cyber Security Checks Are Blocking Real Work at Redis — antirez · 2026-10-03
- Cheap model's overnight bug-fix PRs: only 6 of 14 survived a stronger model's review — Aggressive-Narwhal-3 · 2026-10-03
- Deep Research MCP open-sources a pipeline to hook five research engines into Claude Code — PMinervini · 2026-10-03