What a clinic AI agent must never say: the boundary document you write before launch

Every private clinic already has a boundary document, it is just not written down anywhere. It lives in the head of the veteran receptionist and contains about thirty rules she learned the hard way: what is never answered on the phone, what to tell someone asking whether a treatment suits them, when to interrupt the doctor mid-patient, and how to phrase a "no" so the enquirer is not offended. As long as she answered alone, that document worked perfectly. The moment a system starts writing in the clinic's name at two in the morning, those rules have to leave her head and get written, because a system that was given no boundary will not invent one. This is the work clinic owners fear most, and in practice it closes in a single meeting.
A wrong answer costs more than a lost enquiry
When a clinic considers an AI agent, the question asked out loud is how many enquiries it will save. There is data on that: in our measurement of 98 private clinics in Israel we saw how many enquiries fall between the chairs purely because of response time. But an owner who hesitates almost never hesitates over that number. They hesitate because they picture one message sent in their name that they never saw, containing a sentence they would never say.
The hesitation is justified, because the two risks are not the same size. A lost enquiry costs the margin of one treatment, a known and one-off amount. A wrong answer costs something else: a patient who arrives for a treatment the clinic does not even perform and occupies a slot, a refund, a Google review that stays there for years, and in the worst case a complaint. That asymmetry is why defining what the agent must not say is not a safety clause bolted on at the end of the project but the first part you build.
There is also an upside people miss. A written boundary is exactly what lets you let the agent answer at all: a clinic that defined no boundaries routes only harmless questions to it and everything else to a human, and ends up with slow human service plus a pointless bot layer on top.
A closed knowledge base: where every answer comes from
One distinction explains most of the behaviour described here. The agent answering enquiries in a clinic does not answer from general knowledge of the world, but from a set of documents the clinic approved: the list of treatments you actually perform, price ranges, opening hours, who the doctors are and what each specialises in, the preparation and recovery instructions you already give verbally today, the cancellation policy and how payment works. The knowledge base is larger on Business than on Standard.
The practical meaning is sharp: a treatment that is not on the list does not exist as far as the agent is concerned. A clinic doing botox and fillers, asked about thread lifts, answers along the lines of that not being something we currently do, and the question goes to the team. Not "of course, let us book you in". A language model can produce a fluent paragraph about thread lifts without you ever mentioning the subject, and that is precisely why the gap between what it can write and what it is allowed to write is the whole foundation of a clinic agent.
Hence the point owners find hardest to accept: "I do not have an answer, I am passing this to the team" is a successful answer, and it only becomes a failure if nobody follows up after it.
Seven boundaries written before the agent talks to a first patient
This list comes back almost identical in every clinic, whether it is a dental practice, an aesthetic medicine clinic or a psychotherapy practice. Go through it out loud with whoever is clinically responsible, not only with whoever handles marketing.
- No diagnosis, not even indirectly. Not from a verbal description, not from a photo and not from "that sounds like". Even a careful sentence such as "that sounds like a normal reaction" is a diagnosis to whoever reads it at home.
- No promised outcome, even when it is explicitly requested. You can explain what the procedure includes, how many sessions are typical and how long recovery takes in a typical case. You cannot say how many centimetres, how long it will hold and how it will look.
- No touching medication. Not stop, not continue, not change the dose and not "it is fine to take that before the treatment". Every such question goes to the doctor, even when the answer looks obvious to you.
- Pregnancy and breastfeeding stop the treatment conversation. The agent does not offer a treatment and does not book, answers in wording the clinic approved in advance and offers to return to the subject later. It also does not run a medical enquiry around it, because that is already a doctor's job.
- A minor closes nothing. The agent does not confirm a treatment for a minor, asks for a responsible adult and collects no details about the minor beyond what is needed to route the enquiry.
- A reported complication is handled immediately, at any hour. The list of signs is set by the clinic at setup, and they stop the normal script and trigger an urgent handoff. The agent does not reassure and does not assess severity, because that assessment is exactly what it must not do.
- The clinic is described as it is, not as the enquirer hopes. No invented promotion, no unapproved discount, no availability that is not in the calendar and no extra specialisation added to a doctor. This is the easiest boundary to miss, because breaking it sounds pleasant to everyone the moment it happens.
Where the line runs, question by question
The fastest way to test whether your boundaries are clear is to take real questions from the clinic's WhatsApp and write two answers for each: the forbidden one and the permitted one.
| What the patient asks | The forbidden answer | What the agent actually says |
|---|---|---|
| "I sent a photo, am I suitable for the treatment?" | "Yes, looks great for injectables" | Attaches the photo to the record, explains that the doctor determines suitability and offers a consultation |
| "I have redness two days after the treatment, is that normal?" | "Totally normal, it will pass" | Flags an urgent enquiry, gives the on-call number and hands it to a human immediately |
| "I take blood thinners, should I stop before?" | "Yes, people usually stop a week before" | Gives no instruction, routes the question to the doctor and says when she will be contacted |
| "How long will it last on me?" | "On you it will definitely last a year" | Gives a general range the clinic approved and explains the rest depends on an examination |
| "Do you do this treatment too?" (one not on the list) | "Yes, absolutely, when suits you?" | Says it is not among the treatments we perform and passes the question to the team |
| "I am pregnant, can I book?" | "No problem, let us book next week" | Does not book, answers in the approved wording and offers to return to it later |
| "Cancel my appointment tomorrow" | "Cancelled, have a good day" | Acts only if it has calendar access, otherwise says the request was passed on and confirms once it is done |
Every permitted answer has the same three parts: what can be said, what only the doctor determines, and one concrete next step. That structure is what keeps a refusal from sounding like evasion, and it is why the wordings are written in advance rather than improvised mid-conversation.
Want to consult with us?
We can help you choose, build and deploy the perfect AI solution for your business. Leave your details and we'll get back to you.
A handoff to a human has to be a real handoff
A good boundary that ends in a wall is damage, not protection. A patient who asked a medical question, got "we will get back to you shortly" and then two days of silence feels worse than if nobody had answered at all. So every boundary in the list above is written together with four details: who receives the enquiry, on which channel, within how long during opening hours, and what happens at night and at weekends. The last one is the one that gets forgotten, and it is the only one that matters exactly when something happens.
From the patient's side it looks simple: the agent says the question is going to the team and gives a real time frame. Behind the scenes the conversation moves in the WhaleBiz CRM into a state that is waiting for a human, with the full thread and a short summary, so whoever picks it up does not ask the patient to explain everything again. When a person writes in the thread the agent stops writing there and waits, so there are never two contradictory replies in one thread. We covered this logic of an agent that knows when to stop on the AI consulting and enquiry qualification agent page.
There is one more list worth more than all the others, and it is the list of questions the agent could not answer. Every recurring question there is either a gap in the knowledge base to fill or a new boundary to write, and half an hour a week with it is enough.
The rule that is easy to forget: the agent does not invent about itself either
Most of the boundary discussion is about medical content, and then the second kind of untruth gets forgotten, the one about actions. An agent must not write "I passed this to the doctor and he will get back to you" if nothing was passed, "I cancelled your appointment" when it has no access to cancel, or "I checked the system" when nothing was checked. Sentences like these sound helpful, and they are the surest way to produce a patient who shows up at six in the evening for an appointment they are certain they cancelled. The rule is simple: the agent reports only actions that actually happened, and if the action needs a human it says the request was passed on and confirms again once it is closed.
Identity belongs to the same family. When a patient asks whether they are talking to a person, the answer is that this is the clinic's digital assistant and that the conversation can be moved to the team. That is not only a matter of manners: correspondence with a patient is personal data in every sense, and Amendment 13 to the Privacy Protection Law increased the exposure of any business running such a database, as we covered in our guide to Amendment 13 and AI agents. Two points worth holding already at the boundary stage: on the clinic's channel the clinic is the database owner and we process on its behalf, so the opening message points to the clinic's privacy policy. And the cheapest way to protect medical data is not to collect it, because an agent whose job is to take an enquiry and book an appointment does not need to ask about medication, diagnoses or medical history.
How to write the boundary document in an hour
In the scoping meeting we go through four questions, and that is almost always enough to produce a working draft. First: what you do not do, and what you get confused with most. The answer is immediately the refusal list, and it is specific to each clinic. Second: which three questions nobody but the doctor answers, not even the veteran receptionist. What she is not allowed to answer, the agent certainly is not.
Third: which signs require a human immediately, who is called at night, and what the enquirer is told while they wait. Fourth: what a refusal sounds like when you get it right. The exact same content can read as a brush-off or as professional caution, and the difference is two words of phrasing. The clinic approves those wordings in writing, and they enter the knowledge base like any other content.
The boundary document is not frozen. Rewording, adding a treatment to the list or updating an urgent sign counts as an ordinary change in the monthly quota, which is sized by plan, and a genuine fault is fixed free and outside any quota. A clinic in practice runs on Standard, because it needs the WhatsApp channel and calendar booking, neither of which exists on Start. Several branches, several practitioner calendars, Instagram or in-chat payments move you to Business. The full breakdown is on the price list, and what an agent does in each medical sub-field is collected on the AI agents for private clinics page, including psychologists and therapists, where the boundaries are almost the entire product.
The bottom line is simple: clinics do not fail with an AI agent because the model was not clever enough, but because nobody sat down for an hour and wrote what it must not say. That hour is the difference between a system you can let answer on its own and a system whose every message is checked by hand, and therefore saves nothing.
Frequently asked questions
What does the agent answer when a patient asks something the knowledge base does not cover?
It says it does not have an answer and that the question is going to the team, and it actually routes it along with everything written in the conversation up to that point. It does not fill the gap from general knowledge, does not guess and does not compose an answer that merely sounds reasonable. One message saying the question is going to the doctor, followed by a real reply within the hour, costs the clinic far less than a wrong answer delivered with confidence.
A patient sends a photo and asks whether the treatment suits her. What does the agent do?
It attaches the photo to the enquiry record, explains that suitability is determined by the doctor alone and offers to book a consultation. The agent sees what is in the photo but does not interpret it medically: it does not assess severity and does not say the treatment is or is not suitable. Answering about a photo is diagnosis, and that is a line the agent does not cross in any clinic.
Someone reports a complication after a treatment at two in the morning. What actually happens?
The list of signs the clinic marked as urgent stops the normal conversation immediately. The agent does not reassure, does not assess severity and does not suggest waiting until morning: it gives the on-call number the clinic defined, flags the enquiry as urgent and hands it to a human with the full thread. Who receives that alert at night and on which channel is decided before go-live, not after.
Who is responsible if the agent does say something wrong?
Towards the patient the clinic is responsible, because the agent speaks in its name. That is why the boundaries are written and approved by the clinic before setup, and why every conversation is stored in the CRM and can be opened to see exactly what was said. Rewording a phrase or filling a gap in the knowledge base counts as an ordinary change in the monthly quota, and a fault where the agent did not reply or an enquiry was not saved is fixed free and outside any quota.
How long does it take to define the boundaries, and which plan includes this?
One scoping meeting of about an hour covers most of the list, and the rest is filled in from material the clinic already has. A clinic usually runs on the Standard plan, which includes the WhatsApp channel, calendar booking and a knowledge base. Setup time is counted from the moment we receive all materials, and the monthly subscription starts on the day the agent goes live.

Timur Kolpin
Timur is an investor and serial entrepreneur with extensive experience in strategic consulting, business development and project management. An expert in market analysis, building business models and creating strategic partnerships.