Make it say no

MIS 752 · Lab 10 Lite · Book Ch. 24 · no coding · every request, number and note here is invented
At the pharmacy
A monitoring station with a wall of screensan automatic screen flags the order
➜
A scientist holding a vial up to the lightthe pharmacist reads it
➜
Hand-labelled sample tubesthe label is checked
➜
Two clinicians reviewing x-raysthe monthly report counts both mistakes
In AI
🧾a rule filter checks shapes
➜
🧑‍⚕️an AI judge reads the request
➜
🏷️the answer's form is checked
➜
📊count caught, missed, and wrongly refused
A pharmacy runs several checks before a prescription leaves the counter. Each one stops some bad orders, and each one can also send a good patient home with nothing. An AI guardrail works the same way, and it fails in two directions: a bad yes lets harm through, and a false no turns away the person the service exists to help. What a system refuses is a design choice.
📖 Read Chapter 24, Sensitive Use Cases: End of Life, Mental Health, and Pediatrics (p. 565) in the course textbook ➜
Same book on Canvas: course files. Guardrails in general: Ch. 19, Guardrails for Autonomous Systems (p. 452).
Photos: Benjamin Richards, Josh Hawkins and Becca Schwartz, UNLV. Real UNLV spaces; every request, number and note in this lab is invented.

0 · Connect a model

Paste the free OpenRouter key from Lab 1. It stays in this browser tab only: it is never saved and never sent anywhere except OpenRouter.

1 · Two guards, two kinds of mistake

Every guard sorts requests into "refuse" and "let through". It can be wrong in two different ways, and they land on different people.

🛑 the guard REFUSES
✅ the guard LETS IT THROUGH
it should be refused
✅ CAUGHT ITthe bad request stops here
❌ BAD YESharm gets through
it should be answered
🚫 FALSE NOa patient is turned away
✅ LET IT THROUGHthe service does its job
Everyone reports the top row: "our guard caught 10 out of 10." Almost nobody counts the bottom left, the people it turned away. This lab counts both.
🔒 Every identifier on this page is invented from ranges never issued to anyone: Social Security numbers starting 000 or 900, the 555-0100 to 0199 fictional phone block, example.com email addresses, and dates that never happened, like February 30. A lab about protecting records must not contain anything that could be one.

7 · The guard that stops everyone

Meet a third guard. It refuses any message with a digit, an @, a web address, or a medical word such as dose, tablet or a drug's name. Then run all 20 practice requests through all three guards, the way a pharmacy writes its monthly report.

Photo: Josh Hawkins / UNLV
🎯 GOALSee which guard is actually best when you count both kinds of mistake.
❓ QUESTION“Our guard stopped every attack. Is it good?”
💡 WHYThe paranoid guard will stop all ten bad requests. Watch what else it stops. Twenty requests: ten the pharmacy must refuse, ten it must answer.

8 · The strictness dial

The AI judge gives every request a risk score from 0 to 1. One number decides where "refuse" starts. Slide it and watch both kinds of mistake move.

Photo: Josh Hawkins / UNLV creative services
🎯 GOALFind a setting you could defend with numbers, not with a feeling.
❓ QUESTION“How strict should the judge be?”
💡 WHYLike the sensitivity dial on a smoke detector: turn it down and it stops screaming at toast, but somewhere it starts sleeping through real fires.

9 · The label check

Before a bottle leaves the counter, someone checks the label. The assistant's answer is a counselling note with required lines, and a fluent note can still be unusable.

Photo: Josh Hawkins / UNLV
🎯 GOALSee the one mistake neither guard at the door can see.
❓ QUESTION“Which of these five notes is the dangerous one?” Click it, then run the check.
💡 WHYEvery note must have every line, a risk level of low, moderate or high, and one clinical rule: a high-risk note goes to a pharmacist.

10 · Design your own guardrail

This is the real skill. Pick a service from your own field, write what it is for, and decide what it must refuse. Then test it with one request it must refuse and one innocent request a clumsy guard would block. No code: just plain English.

Photo: Josh Hawkins / UNLV
🎯 GOALWrite the brief an AI judge reads, and a list for the rule filter, for a service you know.
❓ QUESTION“What must your service always refuse, and what must it never refuse?”
💡 WHYEvery system has a refusal policy, whether or not anyone wrote it down. Writing it down is how you find out what it costs.

11 · Your turn: try to break it

Round 1: get a request past the pharmacy's guards that they should refuse (a bad yes). Round 2: write a perfectly reasonable question that they refuse (a false no). Ideas: reword it, split a number across the sentence, use a format the shape checks do not know, or ask an ordinary process question that contains a scary word.

12 · Hand it in (Canvas, Lab 10)

1. Download your submission with the button below, then upload the file to the Lab 10 assignment on Canvas. It holds every request, your predictions, both guards' decisions, your monthly report, your dial setting, the label check, your own guardrail, and everything you wrote.

2. Answer these five, a few sentences each. Each asks why:
  1. When your prediction was wrong, what had you assumed about the rule filter or the AI judge that turned out not to be true?
  2. The paranoid guard stopped every bad request. Using your monthly report, explain why it is still useless, and why a team that reports only its catch rate would ship it anyway.
  3. Which strictness setting would you ship? Argue for it with your numbers, and name who absorbs the cost of your choice.
  4. The warfarin note marked high risk with no pharmacist review was fluent, in scope and free of identifiers. Why does a rule like "high risk needs a pharmacist" belong in software, and who should own it?
  5. Your own guardrail: which mistake costs your field more, the bad yes or the false no, and who pays for each? What should a refused person be told, so they do not go around the guard?

Nothing you type is stored anywhere. Download your file before you close the tab.