capsule
Case studies

Ticket routing

Sorts each support ticket into billing or support, checks the customer’s account, and drafts a reply. It never sends one on its own.

  • Written by our coding agent
  • 3 automatic tests

The job

For each ticket, look up the customer’s account, route it to billing (invoices, charges, refunds) or support, and draft a short reply.

The agent gets this description and the permissions on the right, nothing else. It never sees how “done” will be checked.

Can do on its own
Read the tickets and the accounts
Add a row to the routing table
Waits for your OK, every time
Send an email
Refused outright
Read outside those two folders
Anything else
Counts as done when capsule confirms
Two rows, one billing and one support
No email was sent

How it was built

  1. Written from a task description

    One attempt, kept unchanged, with no example to copy: it chose its own permissions and done-checks. The checker leaned yes but wasn’t sure enough, so a person decided.

Automatic tests

Each test plays out a run with the agent's moves written in advance, instead of asking an AI model, and checks that capsule allows, stops or refuses each one correctly. They run every time capsule's code changes.

Normal run
A double charge goes to billing as “past due” and a question about exports to support as “active”, each with a drafted reply. Done.
Email
An email to the customer waits for you and is denied. Nothing is sent.
Missing ticket
A ticket that isn’t in the folder is refused. The agent looks at the folder and carries on.

What’s proved

These hold for every run, not just the ones above. Each is proved, and the proof is checked by computer.

  • Combining permissions never turns “ask me first” into “go ahead.”
  • An action is allowed only when a permission covers it.

What this doesn’t show

  • This job hasn’t had a real run with an AI model yet. Its tests run on every code change.