An AI support demo can look finished after it answers one question and calls one API.
The production tension appears later: the model has instructions, tools, customer messages, and credentials in the same context—but nobody can clearly say which part authorizes what.
That is not just an AI problem. It is a systems-design problem hiding behind natural language.
A reliable support copilot needs at least two separate layers:
Runbooks explain how to investigate a particular class of problem.







