Content OS

Compliance Agent — Plain-English Guide

Audience: reviewers, compliance officers, marketing leads. No technical background needed. Engineering version: technical.md. Back to the agents index.


In one line

It reads content against your own written rulebook and tells you what a reviewer would stop — quoting the exact phrase and citing the rule it came from.


The problem it solves

In regulated financial services, the risk isn't usually a dramatic mistake. It's an ordinary sentence that reads fine to a marketer and reads badly to a regulator: a rate stated as a promise, a comparison with no source behind it, a competitor described a little too warmly.

Catching those means someone reads every piece against every rule, every time. That doesn't scale, and attention fades by the fortieth draft.

The Compliance Agent does that read consistently, then hands the judgement back to a human.


It runs at two different moments

This is the part worth internalising, because the two are genuinely different jobs:

1. On a news article, before you write

"If we wrote something based on this, would that create risk?"

Some topics can't be covered at all without repeating something restricted. Better to know before anyone drafts.

Where: the Discovery card → "Run AI compliance agent".

2. On a finished draft, before you publish

"This is about to go out under our name. Is every claim defensible?"

The bar is higher here. A journalist reporting a rate is reporting a fact. The moment you republish it, it becomes your claim. Same sentence, different liability.

Where: the blog studio → Compliance.


You press the button

It does not run automatically, and that's deliberate — an automatic review becomes background noise people click past. A review you asked for is a review you read.

Two things do run in the background, and they aren't this agent:

  • A keyword scan for blocked phrases, on every draft save and feed read. Edit a blocked term and it takes effect immediately, no re-run needed.
  • A quality check during generation that can ask the writer to try again.

The AI agent is the deeper read, on demand.


What you get back

A list of findings. Each one has:

  • A severity — high, medium or low
  • The exact phrase that triggered it, quoted from your text
  • What to change, in one sentence
  • The rule it fired on, from your own rulebook, with the reasoning that rule was written for

Plus a list of rules it checked and found clean — so you can see the review was thorough, not just that it found three things.

Severity means something specific

SeverityWhat it means
HighCannot be sent without sign-off. This blocks publishing.
MediumCan proceed, but edit it first
LowWorth knowing, nothing more

Working through findings on a draft

Each flagged phrase is highlighted in the editor. Hover it and you get a card with three choices:

ActionWhat happens
Ask AI to fixSends a rewrite request to the normal refine chat — the suggestion comes back as an Accept/Reject proposal, same as any other edit. Nothing changes without your approval
Full reviewOpens the side panel with everything, including cleared rules
Not an issueDismisses that finding

About dismissing: a dismissal sticks. It survives re-running the agent — you already judged that phrase, and having it reappear would train people to ignore the panel. You can undo it in the "Dismissed as non-issues" section. Regenerating the draft from scratch clears them, because it's new text.

Edits make the review stale. Change the draft and the highlights drop away, because the review no longer describes what's on screen. Run it again.


The publishing gate

A high-severity finding blocks "Send to CMS" until a human acknowledges it.

This is enforced on the server, not just hidden in the interface — there's no way around it by refreshing or clicking faster.

To clear it, a reviewer uses "Acknowledge and allow sending". That's stamped against the current version of the draft, so if someone edits afterwards, the gate comes back.

Publishing is always a human action. The gate doesn't decide anything — it only guarantees a person read the findings before deciding.


Your rulebook is the whole product

The agent has no built-in opinion about Indian financial regulation. It applies your rules, which live in the Compliance Intelligence Centre.

Each rule you write carries:

  • What it says
  • Why it exists — the reasoning
  • Where it came from — the source or circular

That "why" is what makes findings useful. Instead of "this violates rule 12", you get the reasoning behind rule 12, so you can judge whether it genuinely applies here.

Up to 40 rules per tenant. Admin access to edit. IIFL's 22-rule book can be loaded in one command.

A rule the agent invents is thrown away. Every citation is checked against your actual rulebook before you ever see it. It cannot make up a rule and attribute a finding to it.


Two behaviours that look like bugs but aren't

An empty result is normal and correct. The agent is explicitly instructed not to flag an article for merely being about finance, for naming a company neutrally, or for reporting verified facts. If you review ten clean articles and get ten empty results, it's working. An agent that flags everything gets ignored, which is worse than one that flags nothing.

No rulebook means no review — not a pass. If you haven't written rules, or the AI service is unavailable, the agent returns nothing to report rather than this is clean. The keyword scan still runs. Silence is never treated as approval.


What it does not cover

  • Video scripts and hooks get the keyword scan but no AI review.
  • Only one checkpoint, at the end. The roadmap sketches an RBI checkpoint at three points in the creative process — during content selection, during creation, and at approval. Today there's one, on blogs, at the end.
  • Keyboard users can reach every finding through the side panel, but the hover cards need a mouse.
  • No record of who acknowledged what beyond the version stamp.
  • Very long articles — it reads the opening portion, not every word.

Subagents

Two framings, then a set of lenses. All in one call today; each lens is a distinct question a reviewer would ask.

  • Source reviewer — would writing from this article create risk?
  • Draft reviewer — this publishes under our name; is every claim defensible?
  • Claim auditor — restricted claims, guaranteed returns, unverified performance or ranking claims
  • Competitor watch — is a named competitor presented favourably?
  • Regulatory reviewer — personalised advice, or a claim needing a disclaimer the brand cannot make
  • Brand-avoid checker — conflicts with the brand's own avoid guidance

Deterministic, deliberately not subagents: the citation resolver (drops any rule id the model invented) and the finding merger (an exact blocked-phrase match outranks a model paraphrase of the same evidence). The model proposes; these adjudicate.

Source: roadmap/marketing-os/agents/compliance-agent/overview.md