02 · Commercial finance · Deterministic engine with an approval gate

Governed Pricing

A governed pricing engine where business rules stay deterministic and no model is in the runtime path.

At a glance

Status
Built, first live round pending
What this label is based on

“the first live round is pending”

The business story

Spreadsheet-based pricing needed clearer validation, approvals and traceability.

A typed, tested engine now sits behind an approval gate. The gate decides what may be confirmed. The interface only renders that decision.

My contribution

  • Coordinated the review of requirements and translated agreed controls into the build specification
  • Wrote the audit of the incumbent workbook, the data standard whose invariants became acceptance tests, the input schemas and the build specification
  • Built and reviewed the application through AI-assisted development with test-first practices
  • Ran the final review pass, fixed numbered defects and wrote a handover prompt so an external reviewer can inspect code without receiving pricing data

The process

  1. Discovery

    Mapped the existing workflow and agreed the validation and review requirements.

  2. Mapping

    Every master-data sheet given an input schema, and the written specification’s invariants turned into tests.

  3. Build

    Constructed a tested engine, approval workflow, draft exports and a change log.

  4. Validation

    The verification gate chains type checking, architecture linting, tests, a credential scan and an Excel validator; numbered defects were fixed before handover.

How it works

A locally installed pricing application: a pure calculation engine with an engine-level approval gate, wrapped in a small user interface over an embedded database. It validates inputs on load, flags issues by severity, blocks confirmation until every below-floor line carries a named approval, and can only ever create email drafts.

Master data feeds a deterministic pricing engine; an approval gate blocks lines that need a named approval, and the only output is a draft. Schematic workflow, not a product screenshot.
Schematic workflow of Foodservice Pricing, not a product screenshot or a measured result.
01PROBLEM02RULES + DATA03ENGINE04AI05GATE06WORKFLOW07OUTCOMEQuarterlypricing in anerror-proneworkbookMaster data,cost forecast,pricing rulesPure pricingengine withtyped issuesNo AI at runtimeApproval gate:cost, floor,open issuesPrice-masterdraft,confirmations asdraftsAttributableprices, errorsdesigned out 01PROBLEM02RULES + DATA03ENGINE04AI05GATE06WORKFLOW07OUTCOMEQuarterly pricing in anerror-prone workbookMaster data, cost forecast,pricing rulesPure pricing engine with typedissuesNo AI at runtimeApproval gate: cost, floor,open issuesPrice-master draft,confirmations as draftsAttributable prices, errorsdesigned out
  • Deterministic stage
  • Gate: human decision point
  • No AI at runtime
AI role No AI at runtime. AI built it, under governance.
  1. 01 Problem

    Quarterly pricing in an error-prone workbook

    Manual pricing preparation needed clearer review controls.

  2. 02 Rules + data

    Master data, cost forecast, pricing rules

    A multi-sheet master-data workbook is validated sheet by sheet on upload; one bad sheet rejects the whole file.

  3. 03 Engine

    Pure pricing engine with typed issues

    A tested calculation layer applies documented rules and reports validation issues.

  4. 04 AI

    No AI at runtime

    There is no model in the runtime path. AI coding agents built the engine under a written spec, test-first.

  5. 05 Gate

    Approval gate: cost, floor, open issues

    Confirmation is blocked for any line with missing cost, any below-floor line without a named approval, or any open high-severity issue.

  6. 06 Workflow

    Price-master draft, confirmations as drafts

    Prices are saved as drafts in one transaction; customer confirmations are generated as email drafts only.

  7. 07 Outcome

    Attributable prices, errors designed out structural

    Pricing changes are attributable and checked before approval.

Step by step
  1. Approved source inputs are uploaded and checked against the required schema.
  2. A deterministic engine applies documented business rules and reports validation issues.
  3. Issues are emitted as typed records with a severity and a business category.
  4. The approval gate checks whether the required validation and review conditions are satisfied.
  5. Analysts work in a draft price-master workspace saved in a single transaction with optimistic concurrency.
  6. Exports: a price master, a formula-driven working paper, a per-customer confirmation attachment and batch email drafts.
  7. A period lock refuses any further write once a round is final.

AI and engineering judgement

Where AI is used

Nowhere in the runtime. The AI engineering is in how the system was built: a director-council decision record, a written build specification whose invariants became tests, and subagent-driven development with per-task briefs, reports and reviews checked into the repository.

What remains deterministic

  • Business calculations, input validation and approval conditions
  • Input validation and issue severity
  • The approval gate and the enabled state of every confirmation control
  • The audit log, the period lock and the export formats

How risk is controlled

  • Engine purity enforced mechanically: the engine package may not import the store, the interface or any third-party package
  • Append-only change log protected by database triggers; an actor is required on every write
  • No send capability anywhere in the source, enforced by a tree-wide test that also catches indirect calls
  • Overrides require an approver name and reason, remain visible and can be withdrawn
  • Loopback-only binding fixed in both configuration and launcher
  • A single verification gate chains type checking, architecture linting, tests, a credential scan and an Excel validator
Verification and controls
  • Strict static typing across the whole package
  • Automated tests mirroring the package layout, including a golden-value test on a frozen fixture and a real-data anchor test with a minimum coverage floor
  • Interface tests and a browser smoke check at desktop and phone widths for overflow, hidden headings and console errors
  • Single-folder packaged build with an installer and a bundle verifier that prints the hash for endpoint allow-listing

Tech stack

Data

  • SQLite (WAL, append-only triggers) every change is logged with an actor and cannot be edited in place
  • openpyxl master data validated sheet by sheet on upload, and the Excel exports

Application

  • Python with strict typing the pricing engine and its approval gate
  • Streamlit a small interface that renders the gate result

Automation

  • Outlook drafts via COM customer confirmations are created as email drafts only

Testing and CI

  • pytest and import-linter Automated tests, and engine purity enforced mechanically

Deployment

  • Packaged installer one-folder install for the pricing analysts

AI-assisted development (not at runtime)

Built by AI coding agents under a written specification; nothing in the product calls a model.

  • Subagent-driven development per-task briefs, reports and reviews checked into the repository
  • Director-council review the agreed control conditions were carried into the build specification

Adoption and outcomes

Pricing preparation moves into a validated draft workflow with clear approvals and traceability. Commercial impact is not disclosed.; the first live round is pending. structural

  • Outcome

    Controlled decisions

    validation and approval rules support traceable pricing decisions

    structural

  • Engineering

    Pure engine

    no third-party code in the calculation layer, enforced by an automated boundary check

    structural

  • Control

    Draft only

    confirmations are email drafts; an automated test rejects any code that could send

    structural

Status Built, first live round pending

What I learned

The gate decides. The UI renders. Put every eligibility rule in a pure, dependency-free engine, enforce that purity mechanically, and make every control's enabled state a direct read of the gate result rather than a re-derivation.

Related work