Every field write passes through one driver before it reaches the page. Not a rule the agent follows — a rule it cannot break.
Omniya prepares funded gift orders for shoppers in Saudi Arabia: an agent claims an order, opens the retailer’s own site, and fills it in up to the payment step. It had to stop there every time, with no branch a model could talk past.
Retailers redesign overnight, sessions expire mid run, prices drift, and a generic script breaks on the first surprise. I built Omniya around eleven small steps instead of one: a store module per retailer with a shared fallback, and seven deterministic gates — identity, variant, price, cart, stock, idempotency, payment — a model can perceive but never overrule.
The payment boundary lives in the browser driver itself: every field write is checked against a pattern list before it happens, so a card number cannot be typed even if a model decides to try.
- 01Store modules per retailer, one shared fallback
- 02Seven deterministic gates before every payment
- 03A payment boundary enforced inside the browser driver
- 04Recipient data masked pending an operator's request
- 05A manual-review queue with a screenshot and a reason




