A booking is never confirmed because the AI said so.
These are types, constraints and triggers, not prompt guidelines. A test proves each one; 800 run on every push.
A model saying "booked" is not evidence. Curse you, Hallucinat-inator!
01Only confirm() can confirm, and only with evidence
A quoted yes on the call, a Y by text, or a rule the owner approved. Nothing else can be expressed.
export function confirm(ctx, bookingId,
evidence: ConfirmationEvidence) {
// "call" | "text" | "rule". A transcript
// alone cannot be expressed here.
const actor = verifyEvidence(ctx, booking, evidence);
booking/engine.ts ↗
02Consent cannot exist without its proof
The database refuses a consent row without the owner's sentence and the call.
CHECK (
(source = 'call' AND call_id IS NOT NULL
AND LENGTH(quoted_sentence) > 0)
OR (source = 'join_text'
AND message_id IS NOT NULL)
)
migrations/001_init.sql ↗
03Every change is an append-only event
Actor, reason and confidence on every event. Nobody can edit history, including us.
CREATE TRIGGER events_no_update
BEFORE UPDATE ON events
BEGIN
SELECT RAISE(ABORT, 'events are append-only');
END;
002_events_append_only.sql ↗
04Only allowed numbers can ever ring
Checked right before anything that can reach a phone, in the real adapter and the fakes.
export function assertAllowedNumber(number,
allowed = parseAllowedNumbers(env.ALLOWED_NUMBERS)) {
if (!allowed.includes(number))
throw new NumberNotAllowedError(number);
}
shared/src/safety.ts ↗