top of page

What guardrails and PDPA compliance does SJ build into client AI agents?


Autonomy without boundaries is a risk, not a capability, so every SJ Digital Media Solutions deployment ships with guardrails and data protection built in from the workflow setup stage, not appended after an incident.

The guardrail framework covers:

  • Authority limits: what each agent may commit to, pricing within defined parameters, standard terms only, no contractual promises, with everything beyond routed to staff
  • Escalation rules: complaints, sensitive situations, high-value accounts and out-of-knowledge questions handed to humans by rule, with full context
  • Knowledge boundaries: agents answer from the client's approved knowledge base and decline to improvise beyond it, which is what prevents confident wrong answers
  • Tone and conduct standards: the agent's behaviour held to the client's brand and service standards across languages
  • Audit trail: every conversation and action logged, so behaviour is reviewable and accountable

PDPA compliance is treated as a design requirement under Singapore's Personal Data Protection Act:

  • Purpose limitation: personal data collected in conversations used only for the stated business purposes
  • Consent handling: appropriate notification and consent built into conversation flows where required
  • Data minimisation and retention: agents collect what the process needs, with retention aligned to the client's policy
  • Access and security: agent system access controlled, and data handled within the protection standards the client's obligations require

Guardrails are tested as seriously as capabilities during the test and trial stage, including deliberate attempts to push agents outside their boundaries, so what reaches live customers is not only capable but contained.

Comments


bottom of page