Skip to main content

Product recommendation agent

A recommendation is a ranked intervention, not a neutral list.

A product recommendation agent helps customers compare eligible products using their stated needs, permitted context and current offers. The design Werkon would validate makes compatibility, availability, ranking objectives and sponsored influence visible. Software enforces product and offer rules; qualified people set recommendation policy, and customers retain control over preferences and purchases. Clicks alone do not establish suitability or customer value.

Intent, identity and customer control

Keep the requester, recipient, account and current session distinct. A gift search, shared device, accidental dwell, return or purchase for another person is weak evidence of a lasting preference. Declared needs, observed behavior, inferred preferences and model scores need separate records and an approved purpose. Anonymous or session-only options, preference reset, objection and deletion should operate under the policy chosen by qualified owners.

Sensitive traits and vulnerable circumstances must not become tools for predicting susceptibility or maximum spend. That includes health, disability, ethnicity, religion, politics, sexual orientation, financial distress, addiction, grief, pregnancy and children, including proxies that reconstruct those attributes. Qualified privacy, consumer and product owners determine the permissible context and boundaries for age-restricted or consequential products.

Build the eligible product set before ranking

Preserve exact product family, variant, pack, bundle, seller and offer identity. Alternatives, replacements, accessories and consumables need evidenced directional relationships; descriptions, co-clicks and visual similarity cannot establish compatibility. Record the candidate universe, source snapshot, exclusions and missing evidence before applying ranking. Eligible alternatives should not disappear silently because of margin, supplier pressure or popularity.

Inventory states have different meanings: on-hand, reserved, allocated, available-to-promise, backordered, in-transit, held, recalled, quarantined, damaged and expired stock do not all support a sellable offer. Check freshness at the exact item and location. Preserve seller, market, quantity, currency, taxes, mandatory fees, delivery terms and effective period for prices. Price does not establish affordability or willingness to pay.

Explain ranking and commercial influence

Keep candidate generation, filtering, feature construction, scoring, business adjustments, diversification, sponsored insertion and rendering as versioned stages. Owners should define the priorities among relevance, compatibility, availability, novelty, seller exposure, customer effort and business value. Hidden coefficients or a single engagement objective must not decide those tradeoffs. New, niche and long-tail products need consideration where relevant.

Direct marketing, advertising, contextual ranking, personalized recommendations, search and editorial curation require distinct treatment. Disclose paid inclusion, house-brand boosts, inventory-clearing rules and contractual placement where applicable, preserving sponsor, payer, campaign and placement details. Item explanations must reflect the actual material factors without revealing another person’s behavior, fabricating a reason or creating false urgency, scarcity or social proof.

Keep customer action and later evidence separate

A recommendation is a choice to consider. It must not become advice, endorsement, a suitability guarantee or an autonomous cart, reservation, subscription, purchase or message. Any permitted action needs a current explicit request, exact preview and an authorized idempotent operation. Unclear intent, sparse evidence, distribution shifts and consequential fit should lead to clarification, abstention or a supported non-profiled ordering.

Preserve rendered, viewable, exposed, clicked, compared, selected, ordered, paid, canceled and returned states. Experiments need defined allocation, duration, stopping and spillover controls. Evaluate returns, regret, complaints, service burden, overconsumption and customer-reported usefulness alongside transactions. Negative feedback should retain its reason, including wrong variant, already owned, too expensive or unsafe; a skipped item is not automatically disliked. Profile and product corrections must reach derived features and caches.

Recommendation boundary

Suggest products without disguising the intervention.

Intent, eligibility, relevance, commercial influence and customer choice are different systems. Four boundaries preserve the ranking.

01

Requester, intent, and permitted context

Resolve the current requester and recipient, session, explicit task, declared preferences and exclusions, market, locale and recommendation surface; use only context allowed for that purpose and expose profile and ranking controls without converting weak behavior into identity or stable preference.

Required evidence: Tenant and channel, requester and recipient roles, session and request, declared intent and constraints, explicit preferences and negative feedback, context source, purpose and basis, consent or other authority where required, profile version, retention, objection or reset state, non-profiled or customer-directed option, market, locale, accessibility, surface and decision time.

02

Candidate universe and deterministic eligibility

Construct the broad source-linked product and offer set before scoring, preserve exact variants and sellers and apply market, catalog, safety, compatibility, inventory, price, delivery and policy gates with visible exclusion reasons and unknown states.

Required evidence: Query and category scope, candidate-generation method and version, all candidate identifiers, product and offer source versions, variant and pack, seller and market, relation and compatibility evidence, recall and safety state, catalog publication, inventory and offer freshness, currency, tax, fees and delivery, eligibility rules, included and excluded sets, reason codes, fallback and zero-result state.

03

Ranking, commercial influence, and explanation

Separate relevance scoring, business rules, diversity, deduplication and sponsored insertion; preserve objective weights, uncertainty and cohort limits and explain the actual material reasons and commercial influence without claiming best or exposing private signals.

Required evidence: Feature and cutoff versions, baseline and model, score and uncertainty, objective and weights, hard and soft constraints, popularity and novelty, diversity and coverage, seller and category exposure, business-rule adjustment, sponsor, payer and placement, disclosure, final order, item-level reasons, system parameters, customer controls, unsupported cohort and abstention.

04

Exposure, choice, feedback, and outcome

Record what was rendered and genuinely exposed, keep click, comparison, selection, cart, order, payment, cancellation, return and retained use distinct, accept explicit corrections and evaluate usefulness and harm without treating behavior as unconfounded preference.

Required evidence: Request and ranking receipt, surface, position and surrounding alternatives, renderer and display, exposure definition and event, experiment assignment, explicit feedback and reason, preference change, click and comparison, selected variant and offer, cart and order, payment, cancellation, return and complaint, repeat contact, customer-reported usefulness, correction, deletion propagation and causal review.

Intent-to-outcome path

Keep context, candidate set, ranking, exposure, and outcome separate.

A relevant item can be unavailable, a visible item can be unseen and a purchase can still be the wrong choice.

  1. 01

    Define the recommendation contract

    Name requester and recipient roles, the immediate task, market, channel, surface, locale, allowed context, profile and non-profiled options, prohibited inferences, product scope, customer controls, actions and accountable owners.

    Owner
    Customer, product, privacy, consumer, safety, merchandising and channel owners
    Evidence
    Purpose and task, requester and recipient, session, explicit intent, context and source, data categories, purpose and basis, profile option and controls, exclusions and sensitive-data blocks, market and locale, recommendation surface, product scope, success and harm measures, action boundary, retention and stop owner.
  2. 02

    Build and filter the candidate universe

    Retrieve the broad product and offer set at decision time, resolve exact variants and sellers, deduplicate and apply current catalog, market, safety, compatibility, inventory, price, delivery, age and customer-policy rules before any model score.

    Owner
    Catalog, product, inventory, pricing, commerce, safety and policy owners
    Evidence
    Candidate query and source, item, variant, pack, seller and offer identifiers, product and offer versions, relation and compatibility, recall and safety state, market and channel eligibility, inventory and price reads, delivery, age and policy gates, included and excluded sets, reason, missing evidence, fallback and coverage receipt.
  3. 03

    Rank inside visible objectives and constraints

    Apply time-safe features and evaluated relevance models, then separately apply approved diversity, deduplication, business and sponsored rules; preserve every stage, uncertainty, unsupported cases and the reasons that actually changed order or prominence.

    Owner
    Recommendation, model-risk, merchandising, advertising, customer and marketplace owners
    Evidence
    Feature and origin versions, model and baseline, cohort and validation, score and interval, objective and weights, constraints, diversity and seller exposure policy, popularity and novelty treatment, commercial adjustment, sponsor and payer, disclosure, intermediate and final lists, explanations, parameter disclosure, profile option and abstention.
  4. 04

    Render choices and preserve customer control

    Recheck current item, inventory and offer eligibility, render exact variants, price scope, material tradeoffs, sponsored labels and actual recommendation reasons accessibly, allow preference changes and require explicit authority for any cart or other action.

    Owner
    Channel, ecommerce, accessibility, consumer, privacy and customer-experience owners
    Evidence
    Freshness and eligibility recheck, final item and offer, image and copy versions, price, tax, fees and availability time, sponsored or business label, explanation, ranking option, preference and reset controls, accessibility result, exact preview, action request and authorization, render and display receipt, expiry and correction path.
  5. 05

    Measure exposure, choice, and realized outcomes

    Join valid exposure to explicit feedback, choice, transaction, return and customer-reported usefulness, preserve experiments and confounders and correct profiles, product facts and affected rankings without turning silent behavior into preference.

    Owner
    Analytics, experimentation, privacy, commerce, support, correction and outcome owners
    Evidence
    Exposure definition, position and alternatives, event and time, experiment eligibility and assignment, click and comparison, explicit feedback and reason, profile change, selected item and offer, cart, order, payment, cancellation, return, complaint, repeat contact, reported usefulness, product or profile correction, cache and feature invalidation, deletion receipt, uncertainty and causal review.

Authority map

Separate ranking controls, model assistance, and customer authority.

A relevance score can order eligible items. It cannot decide what data to use, what to advertise or what someone should buy.

01

Deterministic recommendation controls

Software owns tenant, requester and product identity, purpose and profile permissions, source authority, candidate construction, eligibility, compatibility, safety, inventory and price gates, commercial disclosures, action rights, corrections and receipts.

  • Tenant, session, profile, candidate, product, offer, ranking, exposure, choice and outcome identifiers
  • Purpose, data category, source, version, feature cutoff, eligibility, price and freshness enforcement
  • Safety, compatibility, sponsored, customer-control, action, retention, objection, deletion and correction gates
  • Intent, candidate, ranking, render, exposure, feedback, transaction and outcome receipts
02

Bounded AI assistance

Models can interpret free-text intent, map it to governed attributes, generate and score eligible candidates within evaluated boundaries, summarize tradeoffs and draft faithful explanations, but cannot define policy or act for the customer.

  • Intent and attribute mapping candidates with ambiguity visible
  • Semantic and collaborative relevance estimates inside approved cohorts
  • Candidate, feature, score and uncertainty explanations
  • Product comparison, disambiguation and explicit-feedback prompt drafts
03

Human policy and customer authority

Qualified people own data purpose, profiling, sensitive and child boundaries, product and compatibility policy, objective weights, sponsored treatment, customer controls, experiments, consequential-use limits and stop decisions; the customer owns the choice and explicit action.

  • Privacy, profiling, objection, retention and non-profiled option decisions
  • Catalog, safety, compatibility, eligibility, ranking and diversity decisions
  • Advertising, sponsor, seller, business-objective and disclosure decisions
  • Experiment, customer action, complaint, correction, rollback and retirement authority

Recommendation components

Build an intent-to-outcome ledger, not a black-box carousel.

The products eligible to be seen, the order displayed and the item ultimately used are different records.

01

Intent, context, and profile ledger

Bind requester, recipient, session, declared task, preferences and exclusions, observed interactions, inferred attributes, purpose, data authority, profile and option versions, market, locale, controls, objections, reset, correction, retention and deletion.

Operating contract: Device is not person, household is not requester, gift intent is not preference, click is not interest, transaction is not suitability, inferred is not declared, permission for one purpose is not every purpose, pseudonymous is not anonymous and profile reset is not deletion until derived features and caches are cleared.

02

Candidate, product, and offer ledger

Preserve candidate-generation scope, exact product, variant, pack, seller and offer, catalog and relationship sources, compatibility, safety, recall, market and channel eligibility, inventory state, price, delivery, included and excluded sets, reasons and missing evidence.

Operating contract: Related is not relevant, alternate is not compatible, listing is not eligible, event is not sellable stock, on-hand is not available-to-promise, price is not value, missing evidence is not false, excluded is not rejected by the customer and a scored item is not a valid candidate until every hard gate passes.

03

Ranking, influence, and explanation ledger

Version time-safe features, baselines, model scores, uncertainty, objective and weights, hard and soft constraints, diversity, deduplication, popularity, novelty, seller exposure, business adjustment, sponsored insertion, disclosures, final order, system parameters and item reasons.

Operating contract: Similarity is not relevance, popularity is not quality, engagement is not value, margin is not customer benefit, score is not certainty, diversity is not fairness, sponsored is not organic, parameter transparency is not item explanation and fluent reason is not faithful influence.

04

Render, exposure, choice, and outcome ledger

Record exact rendered list, surface, position and alternatives, display and valid exposure, profile option, explicit feedback, clicks, comparisons, selection, cart, order, payment, cancellation, return, complaint, usefulness report, experiment, correction and causal review.

Operating contract: Rendered is not viewable, viewable is not seen, seen is not considered, click is not preference, cart is not purchase, purchase is not retained use, non-return is not satisfaction, feedback is not a universal label and later revenue or retention is not recommendation causation.

Delivery path

Prove one recommendation surface through customer choice and correction.

Start where declared intent, candidate coverage, offers, exposures and returns can all be replayed.

  1. 01

    Choose one bounded surface

    Select one market, channel, product family and recommendation task such as complementary items, alternatives or intent search; name product, privacy, consumer, safety, merchandising, advertising, inventory, commerce, model-risk and stop owners.

  2. 02

    Map context, candidates, and influence

    Inventory declared and inferred signals, profile controls, product and offer sources, compatibility, safety, stock, price and seller gates, candidate generation, ranking objectives, commercial rules, sponsored placements, exposure events and feedback.

  3. 03

    Build eligibility and explanation gates

    Encode purpose limits, exact identities, candidate coverage, hard exclusions, live offer checks, time-safe features, baselines, uncertainty, diversity, sponsor labels, faithful reasons, non-profiled or customer-directed options and action blocks.

  4. 04

    Pilot with shadow rankings

    Replay and shadow representative anonymous, new-user, sparse, gift, shared-device, unavailable, incompatible, recalled, sponsored and corrected cases; let qualified reviewers assess candidates, exclusions, order, reasons, controls and harms before customer exposure.

  5. 05

    Release narrowly and measure long-term harm

    Expose only proven low-risk surfaces, keep actions explicit, monitor eligibility and offer drift, preserve valid exposure and explicit feedback and evaluate transactions, returns, complaints, usefulness and seller concentration with controlled comparisons before expansion.

Release controls

Six controls before ranking can shape customer choice.

A strong click rate cannot repair an incomplete candidate set, hidden sponsor or invalid product offer.

Context is purposeful and controllable
Bind requester, recipient, session, declared intent, permitted signals, market, locale and surface; separate declared from inferred preferences, block sensitive and vulnerable inference and make profile, reset, objection and non-profiled or customer-directed controls effective.
The candidate universe is inspectable
Record broad source candidates before scoring, exact products, variants, sellers and offers, included and excluded sets and reasons; detect missing categories, duplicate variants, silent suppression and zero-result cases.
Every candidate is currently eligible
Apply deterministic catalog, market, channel, age, safety, recall, compatibility, inventory, price, delivery and customer-policy gates with exact source versions and freshness; reject unknown consequential fit and stale offers.
Ranking objectives and influence are visible
Version time-safe relevance features, baselines, uncertainty, objective weights, diversity and seller policy, business adjustments and sponsored insertion; separate organic reason from commercial influence and abstain for unsupported cohorts.
The customer receives choices, not pressure
Show exact variant and offer, material tradeoffs, current price and availability scope, faithful why-this-item reason, sponsored label and ranking controls accessibly; prohibit fabricated urgency, hidden scarcity and autonomous cart or purchase actions.
Exposure and outcome are not conflated
Preserve surface, position, alternatives and valid exposure, distinguish click, comparison, selection, cart, order, payment, return and usefulness, accept explicit negative feedback and corrections and withhold causal claims without suitable experiments or analysis.

Proof model

Measure eligible choice and long-term customer evidence.

A ranking can increase clicks by narrowing choice, repeating popular items or hiding commercial influence.

Baseline

  • Markets, channels, surfaces, requester and recipient modes, session and profile options, product families, categories, variants, sellers, offers, price bands, inventory locations, intent types, locales, customer controls and owner groups
  • Current purpose and signal coverage, profile objections and resets, candidate generation coverage, catalog and offer age, eligibility exclusions, compatibility and safety unknowns, sponsored placements, ranking objectives, explanations and correction latency
  • Current offline candidate and ranking results, calibration, diversity, popularity and new-item behavior, exposure concentration, unsupported cohorts, reviewer changes, abstention and profile-option operation by material segment
  • Current valid exposure, explicit feedback, clicks, comparisons, selections, carts, transactions, cancellations, returns, complaints, repeat contacts, customer-reported usefulness and seller outcomes kept separate from causal value

Outcome evidence

  • Correct requester and session scope, permitted context, effective customer controls, broad candidate coverage, exact product and offer identity, complete eligibility, compatibility, safety, inventory and price evidence and honest zero-result states
  • Stable ranking against simple and current-policy baselines, decision-relevant uncertainty, visible objectives and business influence, sponsor disclosure, faithful explanations, diversity and exposure monitoring and appropriate abstention by material cohort
  • Accessible customer choice, accurate offer rendering, no unauthorized actions, valid exposure receipts, explicit and negative feedback capture, prompt profile and product correction, effective reset, objection, deletion and affected-ranking invalidation
  • Selection, transaction, return, complaint, usefulness, repeat contact, revenue and seller exposure measured separately, with catalog, stock, price, promotion and market changes visible and causal benefit withheld without suitable comparison

Guardrails

  • Wrong tenant, requester, recipient, household, session, market or locale; gift or shared-device behavior becomes profile; withdrawn permission, objection, reset or deletion ignored; sensitive trait or vulnerability inferred; child profile; cross-tenant or private signal leakage
  • Candidate universe incomplete, eligible alternatives suppressed, duplicate variant, wrong pack or seller, related called compatible, recall missed, unsafe substitute, event called stock, stale price or delivery, unavailable item ranked, missing evidence treated eligible or sponsor disguised
  • Future outcome leakage, holdout reused, popularity loop, new user or item unsupported, engagement called value, objective or margin hidden, diversity called fairness, business rule bypasses hard gate, explanation mismatches influence, non-profiled option unavailable or preference control decorative
  • Urgency or social proof fabricated, consequential choice presented as advice, model adds to cart or buys, render called exposure, click called preference, purchase called satisfaction, negative feedback discarded, correction not propagated, return or complaint hidden, conversion or retention attributed without evidence

Fit test

Use this pattern when the candidate universe and customer controls can be audited.

Good reason to begin

  • One bounded market, channel, product family and surface has named product, merchandising, privacy, consumer, safety, advertising, catalog, inventory, pricing, commerce, model-risk, correction and stop owners with review capacity.
  • Declared intent, permitted context, profile and non-profiled or customer-directed options, product and offer identifiers, candidate sources, hard eligibility, compatibility, safety, stock, price and sponsored rules are explicit.
  • Representative data includes anonymous and new users, sparse and gift intent, new and long-tail products, unavailable and incompatible offers, negative feedback, returns, complaints, corrections and profile objections without future leakage.
  • Ranking stages, objective weights, commercial adjustments, explanations, exact rendering, valid exposures, feedback, choices, transactions, returns, complaints and customer usefulness can be replayed from decision-time packets.

Resolve before beginning

  • Purpose, requester scope, customer controls, candidate universe, eligibility, compatibility, safety, inventory, price, ranking objective, sponsored disclosure, exposure definition, correction or stop owner is undefined.
  • The process cannot distinguish declared from inferred intent, candidate from eligible offer, related from compatible, popularity from relevance, sponsored from organic, system parameters from item reason, rendered from exposed or click from preference.
  • Sensitive and child boundaries, profile objection and deletion, commercial influence, consequential products, seller exposure, experiment ethics, negative feedback, returns and complaints have no qualified owner or review path.
  • The agent is expected to infer vulnerability, hide paid influence, rank unavailable or unsafe items, optimize only engagement or margin, manipulate urgency, take cart or purchase action, resist customer controls or promise conversion, satisfaction and fairness.

Source basis

Sources behind the control model.

  • 01

    GS1

    GS1 Web Vocabulary 1.18.0

    GS1 describes its current Web Vocabulary, version 1.18.0 published 1 June 2026, as linked-data terms for consumer-facing product properties, offers, parties and product relationships. A vocabulary term or supplier-defined equivalent, alternate, replacement or offer does not authenticate a source, prove exact identity, compatibility, eligibility, availability, relevance or safe substitution, define recommendation objectives, authorize profiling or commercial influence, certify compliance or prove customer outcome.

  • 02

    GS1

    EPCIS 2.0.1

    GS1 lists EPCIS 2.0.1, published 1 July 2025, as the latest standard for sharing supply-chain visibility events with business context. It does not authenticate an event producer, guarantee identifier mapping, event completeness, ordering or current location, provide sellable inventory or a customer promise, determine product eligibility or relevance, authorize ranking or disclosure, certify safety or prove recommendation or outcome.

  • 03

    EUR-Lex

    Regulation (EU) 2022/2065, Digital Services Act

    Article 27 of the EU Digital Services Act requires covered online platforms using recommender systems to describe main parameters and recipient options in plain language, while Article 38 requires covered very large services to provide a non-profiling option. It does not apply to every recommender, select governing scope, define product relevance, approve parameters, objectives, sponsored treatment, interface or model, replace other consumer or data-protection duties, certify compliance or prove customer value.

  • 04

    EUR-Lex

    Regulation (EU) 2016/679, General Data Protection Regulation

    The GDPR defines personal-data profiling, governs transparency, accuracy, purpose and data minimization, includes rights to object and limits certain solely automated decisions with legal or similarly significant effects. It does not decide territorial scope, lawful basis, feature or proxy acceptability, whether a recommendation has significant effect, the meaning of relevance or fairness, product eligibility, ranking policy, compliance or customer or commercial outcome for a particular service.

[ WORKFLOW / SYSTEMS AUDIT ]
THE FIRST ENGAGEMENT

Start with one real workflow

A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.

Show Us the WorkflowStart with the free automation readiness checklist

OBSERVEQUANTIFYDECIDEBUILD