Owen Adira has deployed a portfolio agent that refuses to hallucinate by enforcing a strict citation protocol. The system, built with Mastra and Neo4j, ensures every sentence in a response is backed by specific evidence IDs from a controlled knowledge graph. If the model cannot cite a verified source, it defaults to a fail-closed response rather than guessing. This approach treats the LLM as an untrusted component, boxing it in with deterministic validation layers before any output reaches the user.

The Architecture of Trust

The core design philosophy places the model in the middle of a rigid pipeline. It never chooses what to read, nor does it have the final say on what gets displayed. The workflow begins with a scope check, followed by fixed graph read plans. The model generates structured claims, each linked to evidence IDs, which are then passed to a plain-code validator. This validator drops any claim it cannot verify against the original sources, ensuring that web search results never override the curated graph data.

Deterministic Validation Over Model Freedom

Adira explicitly rejects the trend of letting models write their own database queries. Instead, questions are classified into topics that map to pre-written, fixed read contracts. This prevents prompt injection attacks and ensures consistent performance. The model's output is constrained to a strict JSON schema where each claim must include at least one evidence ID from the curated graph. If a claim fails validation, it is dropped individually, preserving the rest of the answer. This methodical approach increased the success rate of answering React-related questions from 10 out of 12 to 12 out of 12.

Fail-Closed Infrastructure

Every failure mode, from graph unavailability to invalid model output, results in the same polite message: "I do not have enough verified information to answer that confidently." The system logs specific reason codes for operators, such as graph_no_evidence or claims_rejected, but never exposes these technical details to visitors. Infrastructure errors trigger email alerts to Adira, limited to once per reason per hour, and crucially, these alerts never include the visitor's question. This privacy-preserving design ensures that production traffic remains untraced, with debugging data only recorded in local development environments.

Key Takeaways

  • The model is the least trusted part of the system; design deterministic checks around it.
  • Fixed read contracts prevent prompt injection and ensure consistent query performance.
  • "I don't know" is a feature that builds trust, whereas hallucinations destroy it.
  • Validate citations in plain code, not with another LLM, to ensure reliability.

The Bottom Line

Adira’s implementation proves that reliability in AI agents comes from constraining the model, not just prompting it. By making hallucinations a validation error rather than a stylistic choice, he turns a portfolio chatbot into a verifiable credential.