# Pending — Give an assistant real business tools and verify what it actually did

Course: [full Markdown course](../course-content/appengine-build-an-ai-business-assistant.md).

Only the unfinished acceptance work is listed here. Completed application repairs and their evidence are in the [AI repair report](../application-fixes/ai-assistant-local-review.md) and [persisted ticket-tool report](../application-fixes/ai-ticket-persisted-acceptance.md).

## Remaining checks

1. **Live refusal and unchanged-booking readback.** With only customer search enabled, run the separate fictional booking-change request and verify the booking remains unchanged. The successful customer-search run does not establish this behavior. The specific provider approval covered the training customer search; do not silently expand it to ticket or booking data.
2. **Model-mediated support-ticket acceptance.** Verify a separately configured support assistant carries the authenticated caller through model selection and tool execution. The twelve passed persisted-tool/HTTP checks establish ownership, current grants, a saved staff update and actual customer readback; the update used a scoped repository adapter and notification sink. The full model conversation and complete repository mutation pipeline were not exercised. Any notification-delivery claim requires separate delivery evidence.

For support triggered through voice or a channel, an email, phone number or channel handle alone must not unlock private tickets. Establish a verified customer session or specifically authorized staff automation identity before claiming those workflows are supported end to end.
