Customer-support reply drafts and a personal-data filter
The assistant finds information in documentation and drafts a customer reply for a person to review and send. Its standalone personal-data filter, PII Guard, helps replace detected details before using AI, but it does not find everything.
Writing the reply was only part of the problem
In customer support for a company that sells software to businesses, familiar questions recur. Each still requires the right documentation, an understanding of the equipment and a reply in the customer’s language. The raw material is a customer email: names, contact details, device identifiers and long quoted threads accompany the actual question. Much of that is unnecessary for drafting the answer.
I built the workflow around minimisation and explicit stop conditions before answer generation. AI helps draft; deterministic rules decide what to remove, when to stop and whether a citation matches a real article. A person retains judgement and responsibility for sending.
What was built?
A three-tier directory distinguishes colleagues, partners and customers. Colleague names may remain; partner details use separate markers. Other detected people fall under the customer rule. The system adds local document search, ranking, prompt assembly and citation checks. Output separates English notes for the support engineer, a reply in the customer’s language and open questions.
The project indexed roughly 1,200 documents and the directory covered roughly 1,000 protected identifiers. These describe scope, not customer counts or answer accuracy.
From customer email to a human-reviewed draft
- 01Clean and check
Remove signatures and quoted threads. Replace detected identifiers; the first check looks for residue.
- 02Find supporting sources
Local search and ranking retain eight documents. Retrieved context is filtered too.
- 03Check the whole prompt
Check task, sources and message together. This is the second check before the model.
- 04The model drafts
Only a prompt that passes reaches the external model. Action tools are disabled.
- 05Verify citations
Compare links with the article catalogue. Separate notes; restore names in the reply only.
- 06A person edits and sends
The support engineer reviews substance and open questions. Nothing is sent automatically.
Human decision
Three failures more useful than a green test run
The real identifier had one more digit
A device-identifier pattern expected exactly seven digits; a real ticket had eight. The passing suite did not cover that shape. The lesson was to probe the running system, not only examples written alongside the rule.
A partially hidden address looked finished
Partial replacement of an IPv6 address left part of its value visible. A marker in the middle created a false impression that the work was done. This became a testable property: replace the identifier wholly or leave it wholly intact, never produce a half-redaction. A complete miss remains a limitation, not an acceptable final result.
Right article, broken link
The model could copy an article ID correctly while truncating the readable part of its URL. Comparing citations with the real catalogue exposed the defect. The checker reconstructs identifiable broken links; it does not quietly make a fabricated source look credible.
What did the results actually show?
In the project’s evaluation set, the correct document appeared among the eight selected results in all 21 cases. It ranked first roughly two-thirds of the time. That does not mean every answer was correct: retrieval and citations were measured, not the factual correctness of the prose. The small evaluation set does not represent the entire domain.
These are results from the larger assistant project, not measurements of the downloadable PII Guard.
Limits are part of the design
A pattern-based filter misses things. A role or a description of circumstances can identify someone without a name. The replacement key allows restoration, so pseudonymised text may still be personal data. The tool supports minimisation, not a guarantee of anonymity or GDPR compliance. Model processing location and service terms require separate assessment.
The smaller PII Guard grew out of it
Not everyone needs a complete support assistant. Sometimes the job is simply to review an email before pasting it into an AI chat. The filter became a standalone tool. The OEJ version adds redaction across auxiliary fields, a final assembled-prompt check and protection against stale output. It sends nothing to a model or customer.
Try local PII GuardDiscuss your workflow