The governing rule: the assistant handles administrative tasks (booking, FAQs from an approved corpus, hours, pricing) within tight bounds, escalates anything clinical to a safe templated response plus a human, and never gives clinical advice.
The decision that governs everything is staying firmly administrative, so the system is decision-support, not a medical device. A hard clinical-safety classifier gates every message. Anything clinical gets a clinician-designed templated response ("I can't advise on symptoms, but I can book you an urgent appointment, or you can call us, and if you have [red-flag], contact 111 or urgent dental care") and a handoff to staff. Facts come only from an approved practice-information corpus, cited, never invented. And every non-templated reply is reviewed by a person before it sends.
What we deliberately did not do: no clinical advice, diagnosis, or symptom triage by the model (that is a regulated device); no autonomous action beyond booking within policy; no patient health data sent to third parties; and no prompt-only guardrails, the clinical gate is a deterministic classifier and rules, not a line in the prompt hoping the model complies.