<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Amine</title>
    <description>The latest articles on DEV Community by Amine (@bynevolabs).</description>
    <link>https://dev.to/bynevolabs</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4071344%2Ff93c642e-c62a-46c6-8821-1679a770635b.png</url>
      <title>DEV Community: Amine</title>
      <link>https://dev.to/bynevolabs</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/bynevolabs"/>
    <language>en</language>
    <item>
      <title>Équiper un taxi/VTC en 2026 : le stack matériel qui tient la route</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Thu, 13 Aug 2026 22:58:59 +0000</pubDate>
      <link>https://dev.to/bynevolabs/equiper-un-taxivtc-en-2026-le-stack-materiel-qui-tient-la-route-1ael</link>
      <guid>https://dev.to/bynevolabs/equiper-un-taxivtc-en-2026-le-stack-materiel-qui-tient-la-route-1ael</guid>
      <description>&lt;p&gt;Un véhicule taxi/VTC roule 8 à 12 heures par jour. Le matériel embarqué n'est pas un confort : c'est un outil de travail qui doit encaisser l'usage intensif et servir de preuve en cas de litige. Voici le stack qui tient réellement, du point de vue de quelqu'un qui conçoit ce genre d'équipement.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. La navigation : fiabilité &amp;gt; esthétique
&lt;/h2&gt;

&lt;p&gt;En course, une navigation qui décroche coûte de l'argent et du stress. Deux exigences concrètes :&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CarPlay / Android Auto sans fil&lt;/strong&gt; — on ne veut pas brancher/débrancher un câble à chaque client. Le sans-fil (Bluetooth pour l'appairage + Wi-Fi Direct pour l'image) évite l'usure du port et fait gagner du temps entre deux courses.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Un écran lisible en plein soleil&lt;/strong&gt; — dalle IPS, luminosité suffisante, sinon Waze devient illisible à midi.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pour un véhicule sans écran d'origine compatible, un &lt;strong&gt;écran autonome&lt;/strong&gt; (posé sur le tableau de bord, alimenté sur le 12 V) évite de démonter l'autoradio et se transfère d'un véhicule à l'autre. Exemple : &lt;a href="https://www.carbynevo.fr/produits/ecran-carplay-d4" rel="noopener noreferrer"&gt;écran CarPlay sans fil D4&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. La dashcam : votre témoin neutre
&lt;/h2&gt;

&lt;p&gt;En taxi/VTC, la dashcam n'est pas de la parano — c'est de la protection juridique. En cas d'accident, de litige client ou de comportement agressif d'un tiers, la vidéo tranche. Ce qui compte :&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Résolution avant en 4K&lt;/strong&gt; pour lire les plaques, et &lt;strong&gt;caméra arrière&lt;/strong&gt; pour couvrir l'angle des chocs par l'arrière (fréquents en ville).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GPS embarqué&lt;/strong&gt; : vitesse + position horodatées sur chaque séquence = preuve difficilement contestable.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Super-condensateur&lt;/strong&gt; (pas de batterie lithium qui gonfle l'été) + &lt;strong&gt;mode parking&lt;/strong&gt; pour couvrir les stationnements.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Détail d'une config 4K pensée pour l'usage intensif : &lt;a href="https://www.carbynevo.fr/produits/dashcam-ev4k" rel="noopener noreferrer"&gt;dashcam 4K EV4K&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Ce qu'on sous-estime : l'alimentation et la thermique
&lt;/h2&gt;

&lt;p&gt;Le vrai ennemi du matériel embarqué, ce n'est pas la panne électronique, c'est la &lt;strong&gt;chaleur&lt;/strong&gt; et les &lt;strong&gt;micro-coupures&lt;/strong&gt; d'alimentation. Un boîtier qui chauffe redémarre, corrompt des fichiers, ou lâche après un été. D'où l'importance de composants prévus pour la plage -20/+70 °C et d'une alimentation propre (kit hardwire avec coupe-circuit plutôt qu'un simple adaptateur allume-cigare surchargé).&lt;/p&gt;

&lt;h2&gt;
  
  
  En résumé
&lt;/h2&gt;

&lt;p&gt;Pour un professionnel de la route, le bon réflexe : privilégier la robustesse et la preuve (navigation sans-fil fiable + dashcam 4K GPS) plutôt que les fonctionnalités gadget. Le matériel doit survivre à l'usage, pas juste bien paraître le jour de l'achat.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Écrit par l'équipe de Bynevo Labs (marque &lt;a href="https://www.carbynevo.fr/" rel="noopener noreferrer"&gt;CarByNevo&lt;/a&gt;, voir la page &lt;a href="https://www.carbynevo.fr/taxi" rel="noopener noreferrer"&gt;taxi/VTC&lt;/a&gt;).&lt;/em&gt;&lt;/p&gt;

</description>
      <category>hardware</category>
      <category>iot</category>
      <category>productivity</category>
    </item>
    <item>
      <title>Dashcam 4K : ce que le super-condensateur change vraiment (vs batterie lithium)</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Thu, 13 Aug 2026 22:58:58 +0000</pubDate>
      <link>https://dev.to/bynevolabs/dashcam-4k-ce-que-le-super-condensateur-change-vraiment-vs-batterie-lithium-4lin</link>
      <guid>https://dev.to/bynevolabs/dashcam-4k-ce-que-le-super-condensateur-change-vraiment-vs-batterie-lithium-4lin</guid>
      <description>&lt;p&gt;Si vous regardez de près une dashcam, un détail technique sépare le jouet du matériel fiable : la source d'énergie interne. Batterie lithium ou super-condensateur ? Ça n'a l'air de rien, mais c'est ce qui décide si votre caméra survit à un été garé en plein soleil.&lt;/p&gt;

&lt;h2&gt;
  
  
  Le problème de la batterie lithium dans un pare-brise
&lt;/h2&gt;

&lt;p&gt;Une cellule lithium classique déteste deux choses : la chaleur et le nombre de cycles. Or une dashcam vit exactement dans ce contexte hostile — collée au pare-brise, exposée au soleil direct, avec un habitacle qui peut dépasser 60-70 °C l'été. À ces températures, une batterie lithium :&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;perd de la capacité rapidement (vieillissement accéléré) ;&lt;/li&gt;
&lt;li&gt;peut &lt;strong&gt;gonfler&lt;/strong&gt; — c'est la panne classique de la dashcam d'entrée de gamme après un ou deux étés ;&lt;/li&gt;
&lt;li&gt;présente un risque thermique non négligeable.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Ce que le super-condensateur fait différemment
&lt;/h2&gt;

&lt;p&gt;Un super-condensateur (supercap) ne stocke pas l'énergie chimiquement mais électrostatiquement. Conséquences pour l'embarqué :&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Plage de température&lt;/strong&gt; bien plus large (typiquement -40 à +70/85 °C) → pas de gonflement, pas de dérive en été.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cycles quasi illimités&lt;/strong&gt; → il encaisse les milliers de coupures/redémarrages du contact sans s'user.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rôle réel&lt;/strong&gt; : il ne fait pas tourner la caméra pendant des heures. Sa mission est de &lt;strong&gt;finir proprement l'enregistrement en cours&lt;/strong&gt; quand l'alimentation est coupée (ex. après un choc), pour éviter le fichier vidéo corrompu — le pire scénario quand on a justement besoin de la preuve.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Le compromis : moins d'autonomie "hors alimentation". C'est pour ça que le &lt;strong&gt;mode parking&lt;/strong&gt; sérieux ne repose pas sur la batterie interne mais sur un &lt;strong&gt;kit d'alimentation permanente&lt;/strong&gt; branché sur la boîte à fusibles, avec coupe-circuit pour ne pas vider la batterie du véhicule.&lt;/p&gt;

&lt;h2&gt;
  
  
  Mode parking : ce qu'il protège vraiment
&lt;/h2&gt;

&lt;p&gt;Le mode parking surveille la voiture moteur coupé. Deux déclencheurs :&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Détection de mouvement&lt;/strong&gt; — enregistre quand quelque chose bouge dans le champ.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Détection de choc (G-sensor)&lt;/strong&gt; — se réveille sur impact et verrouille le clip.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Pour tenir dans la durée sans tuer la batterie 12 V, on combine supercap (démarrage propre) + kit hardwire avec seuil de tension bas (ex. coupure à 11,8 V). C'est la seule façon de faire du parking 24/7 sans mauvaise surprise au démarrage.&lt;/p&gt;

&lt;h2&gt;
  
  
  En résumé
&lt;/h2&gt;

&lt;p&gt;Si vous choisissez une dashcam pour de la preuve (assurance, litige, taxi/VTC), regardez d'abord la source d'énergie et le mode d'alimentation parking — avant même le nombre de mégapixels. Un exemple de dashcam 4K conçue avec super-condensateur + kit parking est détaillé ici : &lt;a href="https://www.carbynevo.fr/produits/dashcam-ev4k" rel="noopener noreferrer"&gt;dashcam 4K EV4K&lt;/a&gt;.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Écrit par l'équipe de Bynevo Labs (marque &lt;a href="https://www.carbynevo.fr/" rel="noopener noreferrer"&gt;CarByNevo&lt;/a&gt;), qui conçoit des équipements multimédia embarqués.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>hardware</category>
      <category>iot</category>
      <category>electronics</category>
    </item>
    <item>
      <title>CarPlay sans fil : ce qui se passe vraiment entre le téléphone et l'écran</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Thu, 13 Aug 2026 22:00:11 +0000</pubDate>
      <link>https://dev.to/bynevolabs/carplay-sans-fil-ce-qui-se-passe-vraiment-entre-le-telephone-et-lecran-1124</link>
      <guid>https://dev.to/bynevolabs/carplay-sans-fil-ce-qui-se-passe-vraiment-entre-le-telephone-et-lecran-1124</guid>
      <description>&lt;p&gt;Le CarPlay « sans fil » est souvent présenté comme magique : on monte dans la voiture et l'interface apparaît. Côté hardware, c'est en réalité une chorégraphie précise entre deux liaisons radio. Petit décryptage pour ceux que l'embarqué intéresse.&lt;/p&gt;

&lt;h2&gt;
  
  
  Deux liaisons, deux rôles
&lt;/h2&gt;

&lt;p&gt;Un point contre-intuitif : le Bluetooth seul ne suffit pas. Sa bande passante est trop faible pour transporter un flux vidéo temps réel. Le système combine donc deux canaux :&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Bluetooth (BLE + classique)&lt;/strong&gt; — sert à la &lt;em&gt;découverte&lt;/em&gt; et à l'&lt;em&gt;appairage&lt;/em&gt; initial, puis aux appels et à la négociation. C'est le canal de contrôle, léger.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Wi-Fi Direct (peer-to-peer)&lt;/strong&gt; — une fois l'appairage validé, le téléphone et le récepteur ouvrent un lien Wi-Fi point à point. C'est lui qui transporte l'image de l'interface (rendue côté téléphone) et les données de navigation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;La séquence typique au démarrage : réveil du récepteur → reconnexion Bluetooth au dernier appareil connu → établissement du canal Wi-Fi Direct → projection de l'écran. Tout cela en quelques secondes, sans intervention.&lt;/p&gt;

&lt;h2&gt;
  
  
  Pourquoi l'image est "streamée", pas calculée
&lt;/h2&gt;

&lt;p&gt;CarPlay et Android Auto ne font pas tourner les applications sur l'écran de la voiture. Le rendu se fait sur le téléphone ; l'écran reçoit un flux (proche d'un H.264/H.265 encapsulé) et renvoie les événements tactiles. C'est un modèle &lt;em&gt;thin client&lt;/em&gt; : l'écran est surtout une surface d'affichage + une couche d'entrée. Conséquence pratique : la fluidité dépend autant de la qualité du lien Wi-Fi que de la dalle elle-même.&lt;/p&gt;

&lt;h2&gt;
  
  
  Le cas de l'écran autonome
&lt;/h2&gt;

&lt;p&gt;Là où ça devient intéressant pour le bricoleur : un &lt;strong&gt;écran CarPlay autonome&lt;/strong&gt; embarque son propre SoC, son Wi-Fi/Bluetooth et son alimentation. Il ne se branche pas au bus du véhicule — il se pose sur le tableau de bord et se câble sur l'allume-cigare. Autrement dit, il transforme n'importe quelle voiture (même sans écran d'origine) en client CarPlay, sans toucher au CAN bus ni à l'autoradio.&lt;/p&gt;

&lt;p&gt;Ce découplage a des avantages concrets :&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;installation réversible, transférable d'un véhicule à l'autre ;&lt;/li&gt;
&lt;li&gt;pas de dépendance au firmware constructeur ;&lt;/li&gt;
&lt;li&gt;possibilité d'intégrer d'autres capteurs (caméra de recul, dashcam) dans le même boîtier.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Si vous voulez voir à quoi ça ressemble sur un produit réel, un exemple de ce type d'écran autonome (dalle 10,26", CarPlay + Android Auto sans fil, caméra intégrée) est décrit ici : &lt;a href="https://www.carbynevo.fr/produits/ecran-carplay-d4" rel="noopener noreferrer"&gt;écran CarPlay sans fil D4&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Les points de friction connus
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Latence du tactile&lt;/strong&gt; sur un mauvais lien Wi-Fi (interférences 2,4 GHz).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Consommation&lt;/strong&gt; du téléphone : le combo Wi-Fi Direct + écran allumé chauffe et vide la batterie ; beaucoup d'installations gardent le téléphone en charge.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reconnexion&lt;/strong&gt; capricieuse quand plusieurs téléphones sont appairés.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Rien d'insurmontable, mais ce sont les vrais sujets quand on conçoit ou qu'on choisit ce genre de matériel.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Écrit par l'équipe de Bynevo Labs (marque &lt;a href="https://www.carbynevo.fr/" rel="noopener noreferrer"&gt;CarByNevo&lt;/a&gt;), qui conçoit des équipements multimédia embarqués.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>hardware</category>
      <category>mobile</category>
      <category>iot</category>
    </item>
    <item>
      <title>What a self-hosted, EU alternative to a SaaS support AI actually takes</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Thu, 13 Aug 2026 16:10:03 +0000</pubDate>
      <link>https://dev.to/bynevolabs/what-a-self-hosted-eu-alternative-to-a-saas-support-ai-actually-takes-3f11</link>
      <guid>https://dev.to/bynevolabs/what-a-self-hosted-eu-alternative-to-a-saas-support-ai-actually-takes-3f11</guid>
      <description>&lt;p&gt;If you run support for an e-commerce shop, you have two ways to put an AI in front of your queue. You can switch on a hosted feature inside the tool you already pay for, the way Intercom's Fin sits on top of Intercom. Or you can run your own agent on an open model, on infrastructure you control. Both answer the same tickets. They are not the same product, and the difference is almost entirely architectural.&lt;/p&gt;

&lt;p&gt;I build the second kind for French shops, so I am not neutral. But the honest comparison is more useful than a pitch, so here is what actually changes when you move the agent from someone else's cloud to your own.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where your conversations actually go
&lt;/h3&gt;

&lt;p&gt;A hosted support AI reads the ticket, and to do that it sends the customer's message, and usually a slice of your order and profile data, to the vendor's model. For a lot of teams that is fine. For a shop that sells in the EU and wants a short, defensible answer to "where is our customer data processed", it is the first question, not a detail.&lt;/p&gt;

&lt;p&gt;A self-hosted setup inverts the default. The model runs on an instance you rent in your own name, in a region you pick. In my case that means an open French model on French hosting, so the data-residency answer is one sentence and it does not depend on a sub-processor list that can change with a product update. You give up the convenience of "it just works inside the tool" and you get a boundary you can actually point to.&lt;/p&gt;

&lt;h3&gt;
  
  
  The billing model quietly shapes the product
&lt;/h3&gt;

&lt;p&gt;Hosted support AI is often billed per resolution. That number is easy to reason about on a slide and awkward in practice, because it couples your support cost to your ticket volume forever, and it gives the vendor an incentive to count a "resolution" generously. I keep the current, dated version of that pricing out of this post on purpose, because it changes; the &lt;a href="https://bynevolabs.com/alternative-intercom-france/" rel="noopener noreferrer"&gt;factual Intercom comparison&lt;/a&gt; carries the figures with the date they were read.&lt;/p&gt;

&lt;p&gt;A self-hosted agent moves the cost into two buckets you already understand: an instance you pay for by the month regardless of volume, and model inference that scales with usage but that you can measure and cap. Neither bucket is per-resolution, so a good month for sales is not automatically a more expensive month for support.&lt;/p&gt;

&lt;h3&gt;
  
  
  Lock-in is an architecture decision, not a contract clause
&lt;/h3&gt;

&lt;p&gt;The part teams underestimate is reversibility. When the agent, the knowledge base, the conversation logs and the automations all live inside one SaaS, leaving means rebuilding all of it somewhere else. The lock-in is not the contract. It is that your support logic has no existence outside the vendor's schema.&lt;/p&gt;

&lt;p&gt;Self-hosting forces the opposite shape. The retrieval layer points at your content. The tools the agent can call are your API endpoints. The logs are in your database. If you stop working with whoever set it up, the system keeps running, because nothing about it is secret or proprietary to them. That is worth designing for even if you never exercise it, the same way you keep your data exportable even when you have no plan to migrate.&lt;/p&gt;

&lt;h3&gt;
  
  
  What you take on when you self-host, honestly
&lt;/h3&gt;

&lt;p&gt;This is not free. Running your own agent means you own the operations: the instance, the model updates, the monitoring, the on-call when a tool call starts failing at 9pm. A hosted product absorbs all of that for you, and for a small team with no one to carry it, that trade can be the right one.&lt;/p&gt;

&lt;p&gt;It also means the same engineering discipline a hosted vendor already invested in. The agent has to answer only from your data and refuse when it cannot, or you have swapped a vendor's guardrails for none. It needs typed tool-use with hard limits, a refund ceiling it cannot exceed, and an escalation path that hands a human the full context instead of making the customer repeat themselves. You do not get those for free by choosing open models; you build them.&lt;/p&gt;

&lt;h3&gt;
  
  
  When each one is the right call
&lt;/h3&gt;

&lt;p&gt;If you have no one to operate infrastructure and residency is not a hard requirement, a hosted support AI inside your existing tool is the pragmatic start, and I would not talk anyone out of it. If your data has to stay in a specific jurisdiction, if per-resolution billing fights your margins, or if you want the support logic to be something you own rather than rent, self-hosting on an open model is the setup that matches those constraints. The engineering is real either way. The only question is who holds it, and where your customers' data sits while they do.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I build sovereign AI support agents for French e-commerce: self-hosted in France on an open-source stack, for the pre-sale questions that lift conversion and the after-sale ones that decide whether a customer comes back. More on the approach at &lt;a href="https://bynevolabs.com/" rel="noopener noreferrer"&gt;Bynevo Labs&lt;/a&gt; and on &lt;a href="https://bynevolabs.com/ia-souveraine-service-client/" rel="noopener noreferrer"&gt;sovereign AI customer service&lt;/a&gt;. If you are weighing a hosted tool against running your own, I keep a &lt;a href="https://bynevolabs.com/alternative-intercom-france/" rel="noopener noreferrer"&gt;factual Intercom alternative comparison&lt;/a&gt; up to date.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>selfhosting</category>
      <category>ecommerce</category>
      <category>architecture</category>
    </item>
    <item>
      <title>The two support questions that move revenue, and why we route them differently</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Tue, 11 Aug 2026 07:34:58 +0000</pubDate>
      <link>https://dev.to/bynevolabs/the-two-support-questions-that-move-revenue-and-why-we-route-them-differently-78c</link>
      <guid>https://dev.to/bynevolabs/the-two-support-questions-that-move-revenue-and-why-we-route-them-differently-78c</guid>
      <description>&lt;p&gt;An online shop's support inbox is really two inboxes wearing the same chat bubble. One is the shopper who has not bought yet and is deciding whether to. The other is the customer who already paid and now needs something to go right. They arrive through the same widget, and the cheapest mistake you can make is answering both with the same agent behavior.&lt;/p&gt;

&lt;p&gt;I build &lt;a href="https://bynevolabs.com/automatisation-service-client/" rel="noopener noreferrer"&gt;AI support agents&lt;/a&gt; for e-commerce, and separating these two has done more for results than any model upgrade. Here is how we think about the split and how it shows up in the code.&lt;/p&gt;

&lt;h2&gt;
  
  
  Different goal, different cost of being wrong
&lt;/h2&gt;

&lt;p&gt;A pre-sale question is a conversion event in disguise. "Does this fit a 12-month-old?", "Will it ship before Friday?", "Can I return it if the color is off?" The shopper is holding their card. A fast, correct, confident answer removes the last reason not to buy. A slow or hedged answer loses the sale, and you never even see it in a ticket count.&lt;/p&gt;

&lt;p&gt;A post-sale question is a retention event. "Where is my order?", "I need to send this back." The money is already collected. Now the only variable is whether this person comes back or tells a few friends not to. The cost of a wrong answer is different on each side: pre-sale a bad answer costs one conversion, post-sale a bad answer costs a customer and their word of mouth.&lt;/p&gt;

&lt;p&gt;Same widget, opposite failure modes. That alone justifies routing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Routing on intent, not on page
&lt;/h2&gt;

&lt;p&gt;The naive split is "widget on a product page means pre-sale, widget in the account area means post-sale". It breaks immediately, because people ask "where is my order" from a product page and "do you restock this" from their account.&lt;/p&gt;

&lt;p&gt;So we route on intent, detected from the message, with the page as a weak prior. The first job of the agent is to &lt;a href="https://bynevolabs.com/guides/calibrer-agent-ia-tickets-reels/" rel="noopener noreferrer"&gt;classify the turn into a small, fixed set of intents&lt;/a&gt;, and pre-sale versus post-sale falls out of that classification. It is the same closed intent set I use for everything else: a known list, an explicit "unclear" branch, and no free-form guessing about what the customer "probably" meant.&lt;/p&gt;

&lt;h2&gt;
  
  
  What each branch is allowed to touch
&lt;/h2&gt;

&lt;p&gt;Once the branch is known, it changes what the agent can do, not only what it says.&lt;/p&gt;

&lt;p&gt;The post-sale branch gets tools that read order state: order lookup, tracking, &lt;a href="https://bynevolabs.com/solutions/automatiser-retours-remboursements/" rel="noopener noreferrer"&gt;return and refund eligibility&lt;/a&gt;. Those tools touch personal data and the real order system, so they require an identified customer and they are scoped to that customer's own orders. The pre-sale branch usually needs none of that. It needs the catalog, stock, shipping and returns policy, and it has no business reaching into the order database at all.&lt;/p&gt;

&lt;p&gt;Giving the pre-sale branch fewer tools is a feature. A shopper asking about sizing should not be able to trigger an order lookup, and an agent that does not have the tool will not do it by accident. The permission boundary follows the intent.&lt;/p&gt;

&lt;h2&gt;
  
  
  Tone and escalation thresholds differ too
&lt;/h2&gt;

&lt;p&gt;Pre-sale, the agent should be willing to be helpful and a little forward within the truth: confirm the fact, then add the relevant detail the shopper did not ask for yet ("yes, it ships before Friday, and returns are free for 30 days"). The escalation threshold is high, because pulling a human into a sizing question is overkill.&lt;/p&gt;

&lt;p&gt;Post-sale, the agent should be calmer and quicker to hand off. Someone whose parcel is late does not want a cheerful product pitch, they want a status and a next step. The escalation threshold is lower: a frustrated customer, or a request the tools cannot satisfy, goes to a human fast, with the transcript attached so the customer never has to repeat themselves.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this beats one clever prompt
&lt;/h2&gt;

&lt;p&gt;You can try to encode all of this in &lt;a href="https://bynevolabs.com/guides/chatbot-vs-agent-ia-sav/" rel="noopener noreferrer"&gt;a single system prompt&lt;/a&gt; and hope the model juggles goal, tone, tools and escalation on its own. It mostly works, until the day a pre-sale conversation quietly triggers an order tool, or a late-delivery complaint gets an upbeat upsell. Those are exactly the embarrassing failures that separate &lt;a href="https://bynevolabs.com/chatbot-service-client-ecommerce/" rel="noopener noreferrer"&gt;a scripted chatbot from an agent that acts&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Splitting the two intents makes them structurally hard to reach instead of prompt-dependent. The pre-sale branch cannot read orders because it does not hold the tool. The post-sale branch escalates early because its threshold is set that way. The behavior lives in the routing and the tool permissions, where you can test it, and not only in a paragraph of instructions you are trusting the model to honor.&lt;/p&gt;

&lt;p&gt;For a shop, the payoff is simple: the same chat bubble stops treating a hesitating buyer and an anxious customer as the same person. It answers the first to win the sale and the second to keep it. If you are weighing tools for this, it is worth seeing &lt;a href="https://bynevolabs.com/comparatif-agents-ia-sav-france/" rel="noopener noreferrer"&gt;how the French AI support agents compare&lt;/a&gt; on exactly this kind of routing.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I'm Amine, founder of &lt;a href="https://bynevolabs.com/" rel="noopener noreferrer"&gt;Bynevo Labs&lt;/a&gt;. We build &lt;a href="https://bynevolabs.com/ia-souveraine-service-client/" rel="noopener noreferrer"&gt;sovereign AI support agents&lt;/a&gt; for French e-commerce, answering customer questions before the sale and after it, hosted in France on an open-source stack. Happy to talk architecture in the comments.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>ecommerce</category>
      <category>product</category>
      <category>llm</category>
    </item>
    <item>
      <title>What changes when your support LLM has to stay in the EU</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Tue, 11 Aug 2026 07:34:20 +0000</pubDate>
      <link>https://dev.to/bynevolabs/what-changes-when-your-support-llm-has-to-stay-in-the-eu-4k50</link>
      <guid>https://dev.to/bynevolabs/what-changes-when-your-support-llm-has-to-stay-in-the-eu-4k50</guid>
      <description>&lt;p&gt;Most tutorials for building a support agent start with an OpenAI key and a vector store on someone else's cloud. I build these &lt;a href="https://bynevolabs.com/ia-souveraine-service-client/" rel="noopener noreferrer"&gt;sovereign AI support agents&lt;/a&gt; for French online shops, and for a lot of them that starting point is a non-starter: the customer data has to stay in the EU, on infrastructure they can point to, running a model whose weights they can keep. This post is about the parts of the build that change once "stay in the EU" is a hard requirement instead of a nice-to-have.&lt;/p&gt;

&lt;p&gt;I run one dedicated instance per merchant, self-hosted in France, on an open-weight French model (Mistral). None of that is exotic anymore. What is less obvious is which engineering decisions get harder and which ones get easier once you commit to it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The data map comes first, before any prompt
&lt;/h2&gt;

&lt;p&gt;Before writing a single prompt I draw where each piece of data physically goes. For a support turn there are usually four hops: the customer message, the retrieval query against the shop's knowledge base, the model call, and any tool call that touches the order system. With a hosted US model, hops one, two and three leave the EU by default, and hop four often does too if the order data sits in a foreign helpdesk SaaS.&lt;/p&gt;

&lt;p&gt;Keeping it in the EU means every hop has a named home. The model runs on a box in a French datacenter. The knowledge base and its embeddings live next to it. The order lookups go straight to the merchant's own store API (Shopify, WooCommerce) over a server-to-server call, not through a third party. The map is boring to draw and it is the single most useful artifact in the whole project, because it is what a merchant shows their DPO and what you check every new feature against. We keep &lt;a href="https://bynevolabs.com/guides/ia-souveraine-rgpd-service-client/" rel="noopener noreferrer"&gt;the GDPR groundwork for an automated support desk&lt;/a&gt; in one place for exactly this reason.&lt;/p&gt;

&lt;h2&gt;
  
  
  You give up the frontier model, and it matters less than you think
&lt;/h2&gt;

&lt;p&gt;The honest trade-off is model quality. An open-weight model you can host in France will not top the same leaderboards as the largest hosted models. For open-ended reasoning that gap is real.&lt;/p&gt;

&lt;p&gt;Support is not open-ended reasoning. A support turn is a narrow task: understand one customer intent, pull the right fact from a known knowledge base, then answer or hand off. Once the task is scoped that tightly, the model spends its budget on wording and intent detection rather than on world knowledge. That is exactly where a mid-size open model is strong enough. The heavy lifting moves out of the model and into retrieval and tool design, which you control and can test.&lt;/p&gt;

&lt;h2&gt;
  
  
  Retrieval is where sovereignty is won or lost
&lt;/h2&gt;

&lt;p&gt;If the model does not carry the shop's facts, retrieval has to. Hosting retrieval in the EU is easy. Making it good enough that a smaller model can lean on it is the actual work.&lt;/p&gt;

&lt;p&gt;Two things earned their keep here. First, the knowledge base is curated per merchant, not scraped: return policy, shipping zones, sizing, restock rules, each as a short passage with a source. Second, retrieval returns the passage and its source id, and the agent is only allowed to state facts that came back with a source. A smaller model plus tight retrieval beats a bigger model plus loose retrieval for this job, and it keeps every claim traceable to a document the merchant actually wrote. This is the same discipline that lets &lt;a href="https://bynevolabs.com/logiciel-sav-ecommerce/" rel="noopener noreferrer"&gt;a French e-commerce support tool&lt;/a&gt; answer with facts instead of guesses.&lt;/p&gt;

&lt;h2&gt;
  
  
  Logs are personal data, so treat them that way
&lt;/h2&gt;

&lt;p&gt;The part teams forget: your logs are customer data too. A support transcript is full of names, addresses, order numbers. Ship those to a hosted observability tool outside the EU and you just undid the data map.&lt;/p&gt;

&lt;p&gt;So logging stays in the EU with the rest, transcripts get a retention window instead of living forever, and anything used to improve the system gets stripped of direct identifiers first. Under the GDPR the transcript is processing like any other, so it belongs on &lt;a href="https://bynevolabs.com/guides/checklist-rgpd-sav-automatise/" rel="noopener noreferrer"&gt;a GDPR checklist for an automated support desk&lt;/a&gt; next to retention and access. And "we sent it to a US logging SaaS for debugging" is a transfer you now have to justify, which is why the &lt;a href="https://bynevolabs.com/guides/dpa-agent-ia-sav-clauses/" rel="noopener noreferrer"&gt;data processing clauses for an AI support vendor&lt;/a&gt; are worth pinning down before launch, not after.&lt;/p&gt;

&lt;h2&gt;
  
  
  The EU AI Act made one thing non-negotiable
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://bynevolabs.com/guides/ai-act-article-50-service-client/" rel="noopener noreferrer"&gt;Article 50 of the EU AI Act&lt;/a&gt; requires that a person is told when they are interacting with an AI system, unless it is already obvious. For a support agent that is a one-line disclosure at the start of the conversation and a clean path to a human. It costs nothing to implement and it removes a whole category of argument later. We put the disclosure in the first message and make escalation to a human a first-class action the agent can take, not a fallback it stumbles into.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the constraint actually buys
&lt;/h2&gt;

&lt;p&gt;Working inside "stay in the EU" is more upfront design: the data map, curated retrieval, EU-hosted logging, one instance per merchant instead of one shared model behind an API. What it buys is a system a merchant can explain to their customers and their DPO without hand-waving, running on a model they are not renting by the token from a provider that can change terms next quarter. For an online shop answering real customers, before the sale and after it, that turns out to be worth the extra design.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I'm Amine, founder of &lt;a href="https://bynevolabs.com/" rel="noopener noreferrer"&gt;Bynevo Labs&lt;/a&gt;. We build &lt;a href="https://bynevolabs.com/ia-souveraine-service-client/" rel="noopener noreferrer"&gt;sovereign AI support agents&lt;/a&gt; for French e-commerce, answering customer questions before the sale and after it, hosted in France on an open-source stack. Happy to talk architecture in the comments.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>privacy</category>
      <category>ecommerce</category>
      <category>llm</category>
    </item>
    <item>
      <title>Building a support agent that refuses to make things up</title>
      <dc:creator>Amine</dc:creator>
      <pubDate>Mon, 10 Aug 2026 15:03:59 +0000</pubDate>
      <link>https://dev.to/bynevolabs/building-a-support-agent-that-refuses-to-make-things-up-4g4l</link>
      <guid>https://dev.to/bynevolabs/building-a-support-agent-that-refuses-to-make-things-up-4g4l</guid>
      <description>&lt;p&gt;Most "AI customer service" demos fail the same way. You ask something the model&lt;br&gt;
can't answer from data, and instead of stopping, it produces a plausible answer.&lt;br&gt;
In a chat toy, that is a curiosity. In after-sales support it becomes a promise&lt;br&gt;
the company has to honour: a refund nobody approved, or a delivery date that&lt;br&gt;
never existed.&lt;/p&gt;

&lt;p&gt;I build these agents for e-commerce shops, for the pre-sale questions that decide&lt;br&gt;
whether someone buys and the after-sale ones that decide whether they come back.&lt;br&gt;
Almost all of the engineering goes into one problem: making the agent's honesty a&lt;br&gt;
property of the architecture rather than the prompt. The examples here lean on&lt;br&gt;
after-sales, where a wrong answer costs the most, but the same design carries&lt;br&gt;
pre-purchase questions just as well. This post walks through how.&lt;/p&gt;
&lt;h3&gt;
  
  
  The mistake: treating the model as the source of truth
&lt;/h3&gt;

&lt;p&gt;The naive design is one model, one big prompt, and a pile of documents in a&lt;br&gt;
vector store. Ask "where is my order 41822?" and the retrieval layer returns the&lt;br&gt;
three chunks that look most like the question. None of them contain order 41822,&lt;br&gt;
because it is a live database row rather than a document, so the model gets a&lt;br&gt;
context window full of order-shaped text and answers anyway. The answer is wrong.&lt;/p&gt;

&lt;p&gt;A better prompt does not fix this. What fixes it is removing the model's ability&lt;br&gt;
to answer that class of question at all.&lt;/p&gt;
&lt;h3&gt;
  
  
  Bounded actions instead of free-form generation
&lt;/h3&gt;

&lt;p&gt;Every request the agent handles is routed to exactly one of a fixed set of&lt;br&gt;
intents: order status, delivery delay, return, refund status, exchange, invoice,&lt;br&gt;
product question, cancellation. That set is closed. There is no fallback intent&lt;br&gt;
that means "answer anyway".&lt;/p&gt;

&lt;p&gt;Each intent maps to a typed action with an explicit contract:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="nd"&gt;@dataclass&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;frozen&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="bp"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;OrderStatus&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
    &lt;span class="sh"&gt;"""&lt;/span&gt;&lt;span class="s"&gt;Reads the order system of record. Never generates a status.&lt;/span&gt;&lt;span class="sh"&gt;"""&lt;/span&gt;
    &lt;span class="n"&gt;order_ref&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;

    &lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;resolve&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Resolution&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
        &lt;span class="n"&gt;order&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;commerce&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;get_order&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;self&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;order_ref&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;   &lt;span class="c1"&gt;# Shopify / WooCommerce / API
&lt;/span&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;order&lt;/span&gt; &lt;span class="ow"&gt;is&lt;/span&gt; &lt;span class="bp"&gt;None&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
            &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;Resolution&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;escalate&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
                &lt;span class="n"&gt;reason&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;Reason&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NOT_FOUND&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
                &lt;span class="n"&gt;say&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;I can&lt;/span&gt;&lt;span class="sh"&gt;'&lt;/span&gt;&lt;span class="s"&gt;t find that order number on this account.&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;Resolution&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;answer&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="n"&gt;template&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;order_status&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
            &lt;span class="n"&gt;facts&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;order&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;public_facts&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;   &lt;span class="c1"&gt;# only whitelisted fields
&lt;/span&gt;        &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Two details do the real work here. The first is that &lt;code&gt;facts&lt;/code&gt; is a whitelist.&lt;br&gt;
&lt;code&gt;public_facts()&lt;/code&gt; returns the carrier, the tracking number, the shipped-at&lt;br&gt;
timestamp and the current state. It does not return the margin, the internal&lt;br&gt;
notes, the customer's other orders or the fraud score. The model can't leak a&lt;br&gt;
field it was never handed.&lt;/p&gt;

&lt;p&gt;The second is that the natural-language layer only phrases. The model receives&lt;br&gt;
the resolved facts plus a template intent, and writes one or two sentences in&lt;br&gt;
the shop's tone of voice. It never decides what the status is; it is handed the&lt;br&gt;
status and asked to say it well. There is no open question left at generation&lt;br&gt;
time, so hallucination has nothing to attach to.&lt;/p&gt;
&lt;h3&gt;
  
  
  Making refusal a first-class outcome
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;Resolution.escalate&lt;/code&gt; is not a failure path. It is an expected outcome with its&lt;br&gt;
own quality bar, and the one that matters most.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="k"&gt;class&lt;/span&gt; &lt;span class="nc"&gt;Reason&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Enum&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
    &lt;span class="n"&gt;NOT_FOUND&lt;/span&gt;       &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;   &lt;span class="c1"&gt;# no matching record
&lt;/span&gt;    &lt;span class="n"&gt;OUT_OF_SCOPE&lt;/span&gt;    &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;   &lt;span class="c1"&gt;# intent not in the closed set
&lt;/span&gt;    &lt;span class="n"&gt;POLICY_UNCLEAR&lt;/span&gt;  &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;   &lt;span class="c1"&gt;# rule exists but doesn't cover this case
&lt;/span&gt;    &lt;span class="n"&gt;LOW_CONFIDENCE&lt;/span&gt;  &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;   &lt;span class="c1"&gt;# intent classification below threshold
&lt;/span&gt;    &lt;span class="n"&gt;HUMAN_REQUESTED&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;   &lt;span class="c1"&gt;# customer asked for a person
&lt;/span&gt;    &lt;span class="n"&gt;EMOTIONAL&lt;/span&gt;       &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;   &lt;span class="c1"&gt;# anger / distress detected
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Each reason produces a different hand-off: a specific message to the customer, a&lt;br&gt;
priority in the human queue, and a summary attached to the ticket so whoever&lt;br&gt;
picks it up does not start from zero.&lt;/p&gt;

&lt;p&gt;The &lt;code&gt;EMOTIONAL&lt;/code&gt; branch matters more than it looks. A furious customer is not a&lt;br&gt;
retrieval failure; the system may hold every fact it needs. It still goes to a&lt;br&gt;
human, because "technically resolvable" and "should be handled by a machine" are&lt;br&gt;
different questions. Getting that wrong is how automation loses the trust it was&lt;br&gt;
supposed to earn.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;LOW_CONFIDENCE&lt;/code&gt; needs a real threshold, calibrated per shop rather than a&lt;br&gt;
hard-coded &lt;code&gt;0.7&lt;/code&gt;, and it should be asymmetric: a wrong refund costs far more than&lt;br&gt;
an unnecessary escalation.&lt;/p&gt;
&lt;h3&gt;
  
  
  Writes are gated separately from reads
&lt;/h3&gt;

&lt;p&gt;Reading an order is safe; issuing a refund is not. The two sit behind different&lt;br&gt;
gates, and the gate is configuration the merchant owns rather than a prompt:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;actions&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;order_status&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;   &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;mode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;auto&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
  &lt;span class="na"&gt;return_label&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;   &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;mode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;auto&lt;/span&gt;&lt;span class="pi"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;max_value_eur&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;80&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
  &lt;span class="na"&gt;refund&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;         &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;mode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;propose&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;        &lt;span class="c1"&gt;# drafts it, a human clicks send&lt;/span&gt;
  &lt;span class="na"&gt;cancel_order&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;   &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;mode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;propose&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
  &lt;span class="na"&gt;address_change&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;mode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;auto&lt;/span&gt;&lt;span class="pi"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;before_dispatch_only&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;true&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;propose&lt;/code&gt; mode is what makes the first month of a deployment survivable. The&lt;br&gt;
agent does the work and drafts the action; a human approves it, and you watch&lt;br&gt;
the approval rate. Once an action clears without edits often enough, that history&lt;br&gt;
is what justifies flipping it to &lt;code&gt;auto&lt;/code&gt;: a decision earned from your own data&lt;br&gt;
instead of a vendor's promise.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why the hosting boundary is an architecture decision
&lt;/h3&gt;

&lt;p&gt;I run each shop on its own instance, in France, on a French model&lt;br&gt;
(&lt;a href="https://mistral.ai/" rel="noopener noreferrer"&gt;Mistral&lt;/a&gt;). That sounds like a marketing line, so here is&lt;br&gt;
the engineering behind it.&lt;/p&gt;

&lt;p&gt;Support conversations are among the most sensitive data a shop holds, less for&lt;br&gt;
the order numbers than for what customers write around them: addresses, health&lt;br&gt;
reasons for a return, money troubles, complaints about a named employee. Once&lt;br&gt;
that runs through a shared multi-tenant pipeline in another jurisdiction, "where&lt;br&gt;
is my data" stops being a question you can answer and becomes one you forward to&lt;br&gt;
a vendor.&lt;/p&gt;

&lt;p&gt;A dedicated instance also makes reversibility real instead of contractual. When&lt;br&gt;
a merchant leaves, the export is a database dump and a config file, handed over&lt;br&gt;
without a support ticket in sight.&lt;/p&gt;

&lt;p&gt;The EU AI Act's transparency obligation (Article 50) points the same way: the&lt;br&gt;
customer has to know they are talking to a machine. That is easier to guarantee&lt;br&gt;
when the disclosure lives in your own message-composition layer than when it is&lt;br&gt;
a toggle in someone else's dashboard.&lt;/p&gt;

&lt;h3&gt;
  
  
  What this costs you
&lt;/h3&gt;

&lt;p&gt;The trade-off is real: this design resolves fewer conversations than a model&lt;br&gt;
with a free hand. A closed intent set will not cover the long tail, bounded&lt;br&gt;
actions cannot improvise, and &lt;code&gt;propose&lt;/code&gt; mode keeps a human in the loop for weeks.&lt;/p&gt;

&lt;p&gt;I would make that trade every time. The permissive design has a worse failure&lt;br&gt;
mode. It does not produce a slightly worse answer; it produces a confident wrong&lt;br&gt;
statement that a real person acts on, in a channel where the shop is legally the&lt;br&gt;
one who said it.&lt;/p&gt;

&lt;p&gt;An agent that says "let me get a human on this" is a minor disappointment. An&lt;br&gt;
agent that invents a refund policy is an incident the shop then has to clean up.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I'm Amine, founder of &lt;a href="https://bynevolabs.com/" rel="noopener noreferrer"&gt;Bynevo Labs&lt;/a&gt;. We build&lt;br&gt;
&lt;a href="https://bynevolabs.com/ia-souveraine-service-client/" rel="noopener noreferrer"&gt;sovereign AI support agents&lt;/a&gt;&lt;br&gt;
for French e-commerce, answering customer questions before the sale and after it,&lt;br&gt;
hosted in France on an open-source stack. Happy to talk architecture in the&lt;br&gt;
comments.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>architecture</category>
      <category>ecommerce</category>
      <category>python</category>
    </item>
  </channel>
</rss>
