The governing rule: the agent resolves the common tickets end to end using facts pulled from the systems of record, takes only the actions policy allows, escalates everything else, and every fact it states is injected and verified in code, never generated.
Two decisions carry it. Facts-of-record: order status, tracking, stock, delivery windows, and the returns policy come from Shopify and the policy corpus, verified in code, and the model only writes the connective prose around verified facts. That is the guardrail that closes the "the bot promised me" liability. And a governance envelope: the agent's actions run behind a deterministic authorization layer, so it can only ever touch the authenticated customer's own records (enforced in code, not asked of the prompt), with action limits, returns within policy are autonomous, but refunds above a threshold, policy exceptions, and anything contractual route to a human. A brand-voice judge scores every reply before it sends.
What we deliberately did not do: no invented facts or promises; no autonomous refunds beyond the cap; no access to another customer's data; no prompt-only guardrails; and the agent discloses that it is AI (EU AI Act Article 50 for EU customers).