Home / Case Studies / AI agents
AI agents

An AI support agent that only answers from approved answers.

A support assistant for an online gaming operator that answers players from an approved FAQ, hands everything else to a person, and has no way to touch accounts, data, or money.

Online gaming · Client name withheld under NDA

Answer source

One approved FAQ, owned by the support team.

0

Tools available to the agent: No shell, files, web, or database.

3

Tickets handled in parallel: Anything the FAQ does not cover goes to a person.

ClaudeAWSAmazon EC2Telegram

The challenge

Players ask the same questions around the clock in the operator's support chat: deposits, verification, bonus terms, withdrawal times. The support team was answering the same things by hand, shift after shift.

In a gambling business an AI assistant is also a risk. A wrong promise about a bonus or a payout becomes a dispute, and some players will actively try to talk a bot into saying something it should not.

The constraints

  • No access to player accounts, balances, or payments.
  • Answers must come only from content the operator has approved.
  • When the assistant is not sure, a person must take over.
  • Every player message has to be treated as untrusted input.

Decisions & tradeoffs

We designed for what the agent cannot do before what it can.

  • One source of truth: the agent answers only from an FAQ that the support team writes and owns. If nothing in it matches, the ticket goes to a person instead of the model improvising.
  • No tools at all: the support runtime has shell, file, web, and database access switched off. A successful prompt injection has nothing to call.
  • Right-sized models: support runs on Claude Sonnet or Haiku for speed and predictable cost; the largest model is blocked for this role.
  • Explicit defences against prompt injection in the instructions, and player text is never treated as an instruction.

The implementation

The agent runs as a service on Amazon EC2 and works in the operator's Telegram support chat, handling up to three tickets in parallel. Each conversation is answered with the approved FAQ as its only context.

It is one part of a wider agent suite for the same operator: a lightweight router sends internal questions to specialist agents (analytics, risk, payments), each with only the access its role needs.

Players write in a Telegram support chat; an agent runtime on Amazon EC2 answers with Claude using only the approved FAQ as context, and hands unmatched questions to the support team.
Support agent architecture. The agent has no tools and no data access by design.

Outcomes

Routine questions get an immediate, consistent answer, and the support team spends its time on the conversations that need a person. Because the agent has no tools and no data access, the worst case is a handed-off ticket, not a wrong payout or a leaked account.

Handover & ongoing ownership

The support team owns the FAQ. Changing what the agent says means editing a document, not changing code.

Planning something similar? Talk to an AWS partner in Armenia that has built it before.

What’s next for
your business?

Let’s talk