Inside the product
AI that answers from the records, and stops before it changes them.
PrimeLabs adds practical AI to applications when it removes work, finds the right document, or helps someone decide. A model that drafts the software is a separate matter. This page is about the feature a user meets.
Example interface. Not a client project.
Accounts · September 2026 · example organisation
Which supplier invoices from this month need attention, and why?
Read from open invoices, purchase orders and the stored PDFs. Limited to this organisation. No write is included.
| Invoice | Why | Reading |
|---|---|---|
| INV-4701 · Harbour Hire · $1,160 | Amount differs from PO-1902 | High · both numbers are stored fields |
| INV-4688 · City Glass · $890 | Same supplier, date and total as INV-4680 | High · duplicate check is a query |
| INV-4628 · Westbridge · $4,280 | No purchase order on the PDF | Medium · the file was read, the field was empty |
| INV-4714 · Northside · $220 | Supplier is not on the approved list | High · the list is a table |
Sources used
- D1 open invoices for September 2026, this organisation only.
- Purchase orders PO-1884 and PO-1902.
- R2 originals: the four invoice PDFs named above.
Passages the model suggested were checked against those records before this table was shown. A line without a source is not included.
Suggested next actions
- Ask Harbour Hire which figure is right before the invoice is approved.
- Hold INV-4688 until someone confirms it is not INV-4680 entered twice.
- Leave INV-4628 in review until a purchase order is attached or waived.
Nothing has been written. Recording a follow-up is a separate, explicit step.
Two different uses of AI. Only one of them is a product feature.
AI that helps build the software
Models draft code, tests and notes. A person reads the diff, edits it, and decides whether it ships. That shortens delivery of a custom web application. It is not, by itself, an AI product.
AI inside the application
A signed-in user asks a question, searches by meaning, or receives a proposed classification. The application constrains the data, shows the source, and refuses to write unless someone confirms it.
The engineering loop on the homepage covers the first. The rest of this page covers the second.
Capabilities that earn a place in the workflow
- Questions over known records
- Natural language in, a table or a short finding out. The finding is computed from rows the user is allowed to see, not from a general chat.
- Semantic search and retrieval
- Find a passage by meaning, then show the document and the section. Exact lookup, such as an invoice number, stays a database query.
- Extraction and classification
- Pull fields from a PDF, or label a message. Low confidence is a review state, not a silent write.
- Summaries, recommendations, anomalies
- A digest of a long thread, a “similar document”, or a total that moved. Each one names the inputs. None of them is a guarantee about next month.
- Assistants with a boundary
- An assistant can propose the next step inside one workflow. It does not receive a blank mandate to operate the business.
- Human confirmation
- Approving a suggestion is a button with a consequence the user can see. The example on this page records a follow-up and does not post an invoice.
A reliable feature is mostly ordinary software
The model is one step. Around it sits the application that already knows the rules: who the user is, which organisation they belong to, which rows exist, and which states a record may enter. Retrieval pulls passages or documents. Validation checks types, totals and required fields. The screen shows sources and a reading of confidence in words, not only a colour.
If the step can be done with a query, it is a query. Duplicate invoices in the example are found by comparing supplier, date and total. The model is reserved for the PDF that has no purchase-order field to compare.
Workflow state still matters. A flagged invoice sits in review until a person moves it. A long wait, a retry, or an approval that must survive a crash belongs to a workflow, not to a chat session that disappears when the tab closes.
Where the model runs, and what else has to exist
None of these is mandatory. The provider can change. The application’s rules should not have to be rewritten when it does.
Workers AI
Inference on Cloudflare for a defined task: a label, an extraction, an embedding. The model catalogue changes, so a feature pins the behaviour it needs rather than “whatever is newest”.
Other model providers
Some tasks want a different model. AI Gateway can sit in front of Workers AI and external providers so logs, caching, limits and fallback are visible in one place.
Vectorize
Stores embeddings for similarity and retrieval. It is not the membership list and it is not the ledger.
D1 and R2
Structured records stay in D1. Original files stay in R2. The answer cites both when both were used.
Workflows and Queues
A classification that must wait for a reviewer, or a batch of documents, leaves the request path. Durable Objects are for coordination, not for storing the corpus.
Service-by-service limits are on the Cloudflare application development page. Later notes on individual services are not published yet.
Governance, in operational language
The model sees only what the user could have opened. A prompt is not an access-control list. Permission is checked in the application before retrieval, and again before any write.
Hallucination is treated as a normal failure mode. The interface prefers a structured result with sources. If a source is missing, the line is omitted or marked as unchecked. Sensitive fields are not sent to a provider because it is convenient. The choice of provider is written down, including what is logged and how long a prompt is kept.
Latency and cost are design inputs. A model call on every page view is usually a mistake. A call on a search miss, or on a document that just arrived, can be justified. Observability means a later reader can see that the call happened, what it returned, and whether a person accepted it.
When this is the right feature
Add it
- People already hunt through documents or tables to answer a repeated question.
- The corpus is known, and the user is allowed to see it.
- A wrong answer is tolerable if it is visibly uncertain and cannot post a transaction by itself.
- Staff time is spent retyping fields that a checked extraction could propose.
Leave it out
- The rule is already deterministic. Adding a model would only obscure it.
- There is no source of record, so the assistant would be improvising.
- The organisation wants an agent with standing permission to change money, access or customers.
- Nobody will review the output, and the output is allowed to write.
Related
Straight answers
Do you build autonomous agents?
Only bounded ones: a defined task, a defined set of records, and a stop at any write. An open-ended agent with production credentials is not an offering.
Which model do you standardise on?
None. Workers AI is convenient when the task fits a hosted model. Another provider is used when the quality, the data terms or the latency say so. AI Gateway is how that choice stays observable.
Can the assistant update the database?
Not by answering. A separate action, confirmed by a person, can write. The example on this page is explicit about that line.