The direct answer
Write two refusal actions, not one. Refuse-and-end for anything that fakes or hides income or history, no exceptions. Refuse-and-route, with a named person and a real deadline, for anything that only asks to explain income a form can't show. Right now both look like the same flat "I can't help with that," and it lands hardest on the renters whose income never looked standard in the first place.
Do this, in order
Split refusal into refuse-and-end and refuse-and-route, and write both into the criteria by name.Why: one flat refusal action can't tell a person forging a pay stub from a person who just has a voucher, and right now it doesn't try.
Put a real promise inside the routed path: a person looks within a set number of hours, stated in the criteria itself.Why: "contact your landlord" with no deadline is not a path, it's a door with no handle on the other side.
Trigger a hard refusal only on an unambiguous act, like being asked to write or edit a document, never on a topic like income source alone.Why: refusing on a topic instead of an act is exactly what catches a legitimate voucher or disability-income question in the same net as a forged pay stub.
Log every refusal as a refusal, visible to the property team, not folded into "message limit reached."Why: right now nobody, not the applicant and not the landlord, can tell a refusal happened at all, so nobody can ever flag it as wrong.
Track the refusal rate weekly by income source, not just the overall rate.Why: a group's refusal rate can climb for months while the blended number stays low enough that nobody looks twice.
Leave the document-fabrication refusal exactly as strict as it is.Why: there's no legitimate version of asking an assistant to write a fake pay stub, so that part of the rule was never the problem.
How to answer this, stage by stage
Seven moves, from pinning the question down to the number you'd watch every week after.
1
Pin it to one product before naming any framework
Say it like this
"Say a rental-screening company builds an assistant into the application itself. It answers questions while someone's filling the form out, and it's supposed to refuse a short list of things, like writing a fake document. That's the assistant I'd write refusal criteria for."
Why this works
Grounds "refusal behaviour" in one real assistant before any framework language shows up.
2
Say your structure out loud
Say it like this
"I'd use GUARD, because a refusal rule isn't really a safety question, it's a fairness question wearing a safety rule's clothes. Who it protects, who it catches by accident, who can't push back, the exact fix, and how I'd know it's happening."
Why this works
Two seconds that name the plan before the story starts, without reciting the letters like a script.
3
Say what the refusal is actually protecting against
Say it like this
"The refusal exists to stop two things: someone asking the assistant to fake a document, and someone asking it how to word an answer so an eviction or a low income doesn't show up. Both are real. Neither one is what actually trips the rule most of the time."
Why this works
This is GUARD's G step, and naming the intended target first is what makes the gap visible in the next stage.
4
Point at exactly who the trigger phrase catches by accident
Say it like this
"The rule fires on any message explaining why income doesn't match the paperwork. That's not a fraud signal by itself. It's also exactly what a housing-voucher renter has to say, because her rent shows up split across two payers, and exactly what someone on disability has to say, because an award letter doesn't look like a pay stub."
Why this works
This is GUARD's U step. Naming the specific paperwork mismatch beats a vague "it might be unfair" and moves on.
5
Say what happens next, and why there's no way back
Say it like this
"She gets one line: 'I can't help with that, please contact the property manager.' Nothing tells her a refusal even happened, versus the assistant just not knowing the answer. So she doesn't know there's anything to appeal, and neither does the property manager, because the refusal was never logged as one."
Why this works
GUARD's hardest step, and the one that separates a real risk answer from an accuracy checklist.
6
Give the rule as two actions, not one
Say it like this
"I'd write it as refuse-and-end for one thing only: an explicit ask to generate or edit a document, or to word around a fact. Everything else that looks like a refusal, someone explaining real income from a voucher, a disability check, gig work, becomes refuse-and-route: 'I can't answer that myself, but someone on the leasing team will look at your file within four business hours.'"
Why this works
This is GUARD's R step. It's a rule an engineer can build this sprint, not a values statement about fairness.
7
Say what you'd watch every week, then close
Say it like this
"Every week I'd pull the refusal rate split by income source, voucher, disability, gig, standard payroll, not just the overall rate. So: two refusal actions instead of one, a named routing promise, and a weekly number by income source instead of one blended figure."
Why this works
GUARD's D step folded into the closing line, the one an interviewer actually remembers walking out.
Let's learn
Here is what happens when one refusal rule tries to do two different jobs, and gets neither one right.
Keyturn is a tool landlords use to screen a rental application, and it has an assistant built into the application itself that answers questions while someone's filling the form out.
Knowledge spark: what a refusal rule is
A line in the assistant's instructions that says "don't help with this." Usually written as one flat rule for one flat reason. This question is about what happens when that one rule is asked to catch two very different things at once.
Before the assistant existed, an applicant with a question about their file had to email the leasing office and wait. Median reply time was four days, and by the leasing team's own count, about one in five of those emails never got a reply at all. Keyturn's assistant answers instantly instead, and it refuses to help with exactly one category of thing: writing, editing, or coaching someone on how to make a document say something it doesn't.
Across all applicant messages, the assistant's overall refusal rate sits at three percent. That number looks small and clean in a launch review. Split by why someone's income doesn't match their pay stub, it isn't close to even.
Refused when explaining an income mismatch, by income source
Same three months, same assistant, split by what kind of income the applicant has.
Standard payroll, W-2 income
1%
Housing voucher, disability, or gig income
26%
Both numbers sat inside one blended three percent the whole time, because non-payroll applicants were still a small share of total messages.
Here's the part that actually matters. Twenty six percent isn't really the number to worry about. The number to worry about is what an applicant does after she reads "I can't help with that." She doesn't know a rule caught her by accident. She reads it as being caught doing something wrong.
We didn't just refuse more of her messages. We told her, in the only words she got, that she looked like fraud.
At its worst, this doesn't show up as a scandal, it shows up quietly. A renter with a valid voucher gets refused help explaining a paperwork gap, doesn't know who to ask next, and either submits an incomplete application or gives up and applies somewhere else, on a unit she legally qualified for. Refusing on a topic instead of an act is also, in a lot of places, refusing on the exact income source the law says a landlord can't screen against.
The decision I would take back
We wrote one refusal action for the whole rule: refuse, end the thread, point at the property manager. That was fine when the assistant only ever saw salaried applicants and the rare fraud attempt. It stopped being fine the moment "explaining income" became something a fifth of applicants had a legitimate reason to do.
What I would leave alone. The part of the rule that refuses when someone explicitly asks the assistant to write or alter a document doesn't need to change at all. "Write me a pay stub that says four thousand a month" has no honest version. That refusal was never catching the wrong person, so it doesn't need a routed path, it needs to stay exactly as hard as it is.
The lesson. A refusal rule that only says what to block is half a rule. If it doesn't also say what happens to the person it blocks by mistake, it isn't a filter, it's a wall with no door in it.
Now here is the same thing as a story
The short version is above. Read this one when you want to feel why the routed path actually matters.
Idalia Restrepo wrote Keyturn's refusal rule herself, back when the product only ever screened salaried applicants renting from three mid-size landlords. She tested it the way she tested everything at launch: two weeks of trying to trick it herself, a spreadsheet of edge cases, a walkthrough with the trust team before it shipped. The rule caught every fake pay stub she threw at it and let everything else through clean.
For the first year, she reran that same edge-case spreadsheet before every release, more out of habit than anyone asking her to. It always came back the way she expected. Somewhere around the third or fourth release, she stopped rerunning the whole sheet and started spot-checking a handful of the newest cases instead. Nothing ever looked wrong in the spot check either.
Nobody decided to stop watching the full picture. It just quietly became a smaller check than it used to be.
Then Keyturn signed its biggest contract yet, a property manager whose buildings took a large share of housing-voucher tenants, and applicant volume through non-payroll income tripled inside two months. A few weeks after that, a rival screening company's assistant made the local news, a fair-housing reporter had documented it refusing to answer basic questions from voucher applicants, framing every income question as suspicious. Idalia read the piece on a Tuesday morning and, before she'd finished her coffee, opened Keyturn's own refusal logs to check.
Renzo hadn't ignored a warning. There had never been a number split out for anyone to warn him with.
She took what she found to Renzo Achebe, who owned trust and safety for the product. He wasn't defensive about it. "The refusal rate's been three percent for months," he said. "Nobody flagged three percent." He was right. Nobody had ever asked what three percent was made of.
Two weeks earlier, Marisela Quint had stood in the parking lot outside a leasing office on her lunch break, filling out a Keyturn application on her phone. Her rent is split between her own payment and a housing voucher, and her income includes an SSDI award letter that doesn't look anything like a pay stub. When the form flagged a mismatch between her stated income and her documents, she typed out an explanation, mentioned the voucher and the award letter, and hit send.
"I'm not able to help with that. Please reach out to the property manager directly," the assistant told her. Nothing marked it as a refusal instead of the assistant simply not knowing. Nothing told the property manager a question had come in and gone unanswered at all.
Idalia set the rule. Marisela reads its output, with no way to know a rule was even involved.
Marisela didn't email anyone. She'd already had one landlord treat a voucher like a red flag, and the flat refusal read the same way. She finished the application without the explanation attached, left the income section looking unresolved, and the file sat in manual review for eleven days before it was denied for insufficient income documentation. By the time anyone at the leasing office looked closely enough to notice the voucher, the unit was already leased to someone else.
Idalia had been in the room, a year earlier, when the rule was first written as one action: refuse, end it, point at the landlord. It was the obvious shape at the time. There was one kind of applicant to design for, and building a second path for a case that hadn't shown up yet would have been solving a problem the product didn't have.
The step that should sit third in this chain, and doesn't
Run the same two months again, this time with two refusal actions instead of one. Marisela's message never touches "refuse and end," because it never asked the assistant to write or change anything. It routes instead: a note that a person will look at her file within four business hours, and a flag the leasing office can actually see. Before the fix, about one in four applicants who hit this refusal never finished their application at all. After it, that number drops under one in twenty, because a promised four-hour answer is a reason to keep going, and a flat "I can't help with that" isn't.
What I'd tell myself a year earlier: we wrote down what the rule should block. We never wrote down what happens to the person it blocks by mistake, and that second sentence was the actual criteria the whole time.
GUARD, and the refusal rule doing two jobs at once
This is a risk question, so the framework is GUARD. Refusal criteria for an assistant looks like a safety checklist, but the real test is who a flat refusal catches that it was never built for, and what happens to them next.
G, groups. Two things sit inside "refusal." The act it was built to stop: faking a document, or coaching someone on how to word around an eviction or a low income. And the applicant it catches instead, anyone whose real, documented income just doesn't look like a standard pay stub.
U, unequal. The rule fires on the topic of an income mismatch, not on the act of faking one. That topic is exactly what a voucher holder, a disability-income recipient, or a gig worker has to raise every time, because their paperwork was never going to match a salaried template in the first place.
A, ability to contest. Marisela never learns a rule refused her, only that "the assistant couldn't help." Nothing distinguishes that message from an ordinary limitation. The property manager never sees a flag either, because the refusal was never logged as a refusal in the first place. Nobody can push back on an event nobody can see.
R, reduce. Split the action. Refuse-and-end only for an explicit act: generate a document, edit a document, or word an answer to hide a fact. Everything else that resembles a refusal, explaining real income from a voucher, a disability check, or gig work, becomes refuse-and-route, with a named person and a stated deadline in the criteria itself, not left to whoever builds it later.
D, detect. Track the refusal rate weekly, split by income source, not just the blended number. Watch for the non-payroll rate drifting away from the payroll rate even while the overall rate looks flat, which is exactly the shape that let three percent hide twenty six.
Where this answer would fail
If the fix here is a warmer refusal message, a training pass on inclusive language, or a values statement about fair housing, none of it counts. "One action for an explicit act, a routed path with a named deadline for everything else, tracked by income source every week" is a build ticket. Someone can ship it this sprint, and you can check whether they did.
And if you want to be sure it really works, try it somewhere else
A pharmacy chain's refill assistant answers questions about prescription refills and is supposed to refuse anything that looks like early-refill abuse. Different building, same five letters, same trap.
G, groups. The intended target is genuine misuse, filling the same prescription early at more than one pharmacy, mismatched prescriber names. The group caught instead is anyone whose real refill timing looks irregular for a medical reason.
U, unequal. Palliative and chronic-pain patients on doses their doctor adjusts often, and patients who travel for hospice care, both produce the exact refill pattern, early, inconsistent, that the rule was written to flag.
A, ability to contest. The refusal message says "please contact your pharmacy," with no note that a pharmacist should call back and no flag on the patient's file showing a refusal happened, so a patient in pain has to start the request over from nothing.
R, reduce. Refuse-and-end only for a named red flag: two different pharmacies, a mismatched prescriber, in the same week. Everything else, a dose change, travel, a hospice status, becomes refuse-and-route, with a live pharmacist callback promised within a stated number of hours.
D, detect. Track the refusal-to-route split weekly by patient category, palliative and chronic-pain against general, and watch for the palliative rate climbing even while the overall refusal number holds steady.
Swap the trigger and it still runs
- Speed: a big new contract doubles applicant volume overnight, and a refusal rate that looked stable at the old scale suddenly hides a much bigger absolute number of routed people who got the flat "end" reply instead.
- Cost: building the routed path costs real staffing hours to actually answer within the promised window, so it keeps getting deprioritized against features that show up on a roadmap slide.
- The model gets better: a newer version of the assistant refuses less overall, which reads as pure progress, and nobody thinks to check whether the drop is even across income sources or concentrated in one of them.
Where people run it wrong
- Writing a refusal rule around a topic, like "income doesn't match," instead of an act, like "asked to fabricate a document."
- Treating a flat refusal message as neutral, when the person reading it can't tell an accident from an accusation.
- Watching only the blended refusal rate, so a group's number can double while the overall figure barely moves.
If you're asked this cold
Ask whether the refusal fires on an act or a topic before you ask anything else. If it fires on a topic, that topic is always going to be someone's ordinary, honest answer, and that's the whole risk, right there.
Flashcards (click a card to flip it)
1 · THE FRAMEWORK
What framework fits a question about writing refusal criteria for an assistant, and why?
Tap to flip
ANSWER
GUARD, for risk, safety and fairness. The real question is who a refusal was built to catch versus who it catches by accident, exactly what GUARD is built to find.
2 · THE PERSON
Who is this answer about?
Tap to flip
ANSWER
Idalia Restrepo, the product manager who wrote Keyturn's refusal rule, back when every applicant it saw was salaried and the rule only ever needed to catch one kind of fraud.
3 · THE HABIT
What did Idalia stop doing because it worked, and why did that matter later?
Tap to flip
ANSWER
She stopped rerunning her full edge-case spreadsheet before each release and moved to a smaller spot check. It always came back clean, so the blended refusal rate quietly hid a growing gap by income source.
4 · THE GAP
What's the two-number gap that proves the refusal rule caught the wrong people?
Tap to flip
ANSWER
A one percent refusal rate on income-mismatch messages from W-2 applicants, against twenty six percent for voucher, disability, or gig-income applicants. Both sat inside one blended three percent.
5 · THE OLD DECISION
What old decision does this answer take back, and why did it make sense at the time?
Tap to flip
ANSWER
Writing one refusal action, refuse and end, for the whole rule. It made sense when the product only saw salaried applicants and rare fraud attempts. It stopped being safe once explaining income became a normal, honest thing a fifth of applicants had to do.
6 · THE NUMBER
Fill in: voucher, disability, and gig-income applicants were refused on an income question ______ percent of the time, against ______ percent for standard payroll applicants.
Tap to flip
ANSWER
Twenty six percent, against one percent. Both hidden inside one blended three percent refusal rate, which was the only number anyone was watching.
7 · THE REPLAY
Same two months, new design. What changes, and by how much?
Tap to flip
ANSWER
Income-mismatch messages route to a person with a four-hour promise instead of ending flat. Applicants who abandon their application after this refusal fall from about one in four to under one in twenty.
8 · TRANSFER
Section four runs GUARD again on a different product. Which one, and what does the reduce step become?
Tap to flip
ANSWER
A pharmacy chain's prescription-refill assistant. Reduce: refuse-and-end only for a named red flag like two pharmacies in one week, everything else, like a dose change or travel, routes to a pharmacist callback with a stated deadline.
Check yourself Score: 0 / 0
Multiple choice
1. Keyturn's assistant refuses income-mismatch messages three percent of the time overall. What's the real problem with treating that as one healthy number?
- A. Three percent is too high a refusal rate for any product to ship with.
- B. The assistant needs a bigger training set of fraud examples before it can be trusted.
- C. A blended refusal rate can look small while it's built almost entirely out of one group's legitimate messages, and nobody had a way to see that group's number on its own.
- D. Keyturn should turn the refusal rule off entirely until it's more accurate.
Show hint
The problem in this answer was never the overall size of the number.
Show answer
C. A, B, and D worry about the rule's strictness or its accuracy. The real risk is that a blended rate can hide one group's much higher rate underneath it, and nobody had a split number to catch that.
True or false
2. True or false: the refusal rule got worse at catching fake documents once voucher and disability-income applicants started using Keyturn.
Show hint
Check what the document-fabrication part of the rule was actually doing.
Show answer
False. The part of the rule that refuses fabricated documents never changed and never needed to. The problem was a separate part of the rule firing on a topic, income explanation, that a new population had to raise honestly and often.
Fill in the blank
3. Voucher, disability, and gig-income applicants were refused on an income question ______ percent of the time, against ______ percent for standard payroll applicants, both folded into one three percent blend.
Show hint
It's the pair of numbers behind the chart in "Let's learn."
Show answer
Twenty six percent, and one percent. Same assistant, same three months, split by income source instead of read as one blended number.
Short answer
4. What old decision does this answer take back, and why did it make sense when Idalia first wrote the rule?
Show hint
Look at how the rule was originally shaped, not at who found the gap later.
Show answer
Model answer: "Writing one refusal action, refuse and end, for the whole rule. It made sense at the time because the product only screened salaried applicants, so a single flat refusal never had a legitimate case to accidentally catch. Building a second, routed path back then would have solved a problem the product didn't have yet."
Short answer, apply it yourself
5. Pick an assistant you've used that refuses certain requests. If it had to serve a much wider group of people tomorrow, what topic, not act, might it be refusing on that would start catching honest people by accident?
Show hint
Look for a refusal trigger tied to a subject someone might raise, rather than something someone is asking the assistant to do.
Show answer
Model answer: "A customer-support assistant that refuses to discuss refunds after a return window closes, to stop abuse. Rolled out to a market with a different consumer-protection law, it would start refusing customers who have a real legal right to a late refund, because the rule was written around a topic, 'past the window,' not around an actual abuse pattern."
Short answer
6. If the routed path's promised deadline slipped from four hours to four days, would splitting the refusal into two actions still be the right fix? Why or why not?
Show hint
Ask whether the fix depends on the exact deadline, or on the fact that a path exists and is visible at all.
Show answer
Model answer: "It's still the right shape, but a four-day promise is close to no promise at all for someone waiting to finish a rental application. The split itself, act versus topic, is what fixes the wrongful refusal. The deadline is a second, separate number to get right, and it needs its own bar, not a free pass just because a path now technically exists."