PAN Lab example
Propel in-app SNAP benefits assistant
Read-only by design: a benefits assistant grounded on the record it never writes
For once the memory loop is cut at the source. This assistant reads a state-verified deposit record to tell a recipient a payment is missing, then steers them to fix it on the state's own system — and it never writes to that record. Modeled on Propel's in-app Supplemental Nutrition Assistance Program (SNAP) tools. The contamination that dominates other cells barely runs here. The risk moved somewhere quieter: onto the human who catches what the AI misses, and onto the fact that no one outside the company checks any of it.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Propel-class read-only benefits assistant network: 6 components and 11 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 5 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the read-only, state-verified-grounding assistant pattern documented in the Propel case file — not a reconstruction of the actual app.
- assumed
The people using the app are served recipients, not the modeled operator network. Following the atlas convention for direct-to-consumer tools, the group of staff modeled here is Propel's own support and escalation staff; no benefit-restoration outcome and no differential recipient harm is computed from these dynamics.
- baseline
The model-to-record write is drawn empty because the help surfaces are read-only by design: they read a state-verified deposit record but never write to the authoritative government record, which only the state agency can change. This severed write-back is the case's defining protective feature and the map's strongest control.
- baseline
The escalation channel is drawn as a present collective check (the peer-review pathway) rather than a per-case second read: when the AI reaches a dead-end it hands off to a named human, a capacity-limited channel the pilots sized by capping cohort at about 1,000 users so staff could absorb every escalation.
- assumed
External oversight is drawn as an oversight node whose check pathway starts closed: no state agency, regulator, or independent auditor governs the tool, and the only published evidence that it works is the company's own, so the containment on the diagram is internal and discretionary — levers can open the closed check.
- assumed
The third-party chat platform is drawn as a standing data-leaving pathway (low but real, privacy-sensitive) because the generative half genuinely runs on an outside commercial platform with no documented data-processing agreement — the one place app data leaves the recipient-owned surface.
- assumed
Every outcome figure in the underlying case is vendor-published and the effect magnitudes were withheld, so the model encodes mechanism and direction only, never a calibrated harm size.
What this example does not show
- A relatively safe starting baseline is a property of this model, not a safety promise for any real deployment.
- The people using the app are served recipients, not the modeled operator network. No benefit-restoration outcome and no differential recipient harm is computed from these dynamics; the deposit-arrived ground truth and the vendor-reported pilot effects live outside any diagram like this one.
- Every outcome figure in the underlying case is vendor-published, the effect magnitudes were withheld, and no independent evaluation exists — the model encodes the mechanism and direction, never a calibrated size.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
In a spring-2025 randomized pilot inside a large consumer EBT app, the vendor reports that 53% of eligible SNAP recipients took up in-app AI help for missed deposits and that treated users were restored faster and more often in the same month than a control group, with every AI dead-end escalated to a named human; all outcome figures are vendor-published and the effect magnitudes were not disclosed.
empirical- Vendor Propel Inc. (Propel Insights), Using AI to help SNAP recipients diagnose and restore lost benefits (2025) https://www.propel.app/insights/using-ai-to-help-snap-recipients-diagnose-and-restore-lost-benefits/
- Vendor Guarino, Using AI to help SNAP recipients diagnose and restore lost benefits and reduce churn (Substack, 2025) https://daveguarino.substack.com/p/using-ai-to-help-snap-recipients-377
By the vendor's own account of the design, the assistant grounds on a state-verified deposit record it reads but does not write to, and steers recipients to act on the state system of record rather than acting for them.
empirical- Vendor Propel Inc. (Propel Insights), Using AI to help SNAP recipients diagnose and restore lost benefits (2025) https://www.propel.app/insights/using-ai-to-help-snap-recipients-diagnose-and-restore-lost-benefits/
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
All of them in context on the Benefits navigation & public-facing chat domain page.
Levers available here and the patterns behind them
- Mark AI-written records — Provenance labeling
- Escalate checks — State-feedback vigilance
- Keep prompts neutral — Framing and mirroring reduction
- Peer sharing rules — Peer-edge governance
- Gate record entries — Human-in-the-loop write gating
- Vet connections — Connection authorization
- Gate vendor updates — Vendor quality gate
- Store less data — Data minimization
- Review on schedule — Oversight cadence & retrospectives
Documented case histories
- Propel in-app SNAP benefits assistant
- Nava assistive benefits chatbot
- Caddy adviser copilot at Citizens Advice
- GOV.UK Chat
- Mass.gov Virtual Assistant
- Frida (NAV Norway)
- SSA 800-Number Conversational AI Assistant
- EDD Virtual Assistant
- Burokratt
- Singapore's chatbot fleet refresh: eighty scripted engines slated for retirement onto a shared LLM platform
- IRS collection chatbots: expanded and made permanent with no performance measures
- Albert France Services
- GetCalFresh: the nonprofit front door that carried most of California's online SNAP intake
- MyFriendBen benefits screener
- Benefits Data Trust wind-down