Nestack Agent Care
Industries / Automotive / Safety-recall agent

Automotive AI agent · Safety recall

Safety-Recall & Field-Service-Action AI Agent

Assemble the chronology of principal events behind a defect determination, track the Part 573 and Part 577 clocks, and leave the determination itself with the engineer who has to make it.

4–6 weeksTypical delivery
Your stackDeployment
5 working daysEngineer signs
Agent CareAfter launch

What this agent does

Assembles the chronology, not the determination

In
01

A field report lands, and it is ingested beside warranty claims, supplier 8D files and foreign field actions.

02

A claim is normalised to the manufacturer's date of receipt, the date 49 CFR § 573.6(c)(6) asks the file to carry.

Reason
03

A determination is dated, and the chronology of principal events behind it is assembled from those records.

04

A campaign opens, and the § 573.6(a) five-working-day filing clock runs from that decision, not from the signal.

05

A filing goes in, and the § 577.7 sixty-day owner clock is counted from the filing date, as the rule reads.

Decide
06

A software remedy ships, and it is treated as equipment under NHTSA Enforcement Guidance Bulletin 2016-02.

07

A quarter closes, and the package routes to the named engineer with the six § 573.7 returns tracked to the last.

Out
08

An event is retained with its source, its date of receipt and the engineer who dated the determination.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles and dates; a named engineer at the manufacturer determines, signs the Part 573 report and answers for it.

Example workflow

One campaign, signal to filing

AgentHuman
1Field signal receivedWarranty claim, field service report, supplier 8D or foreign field action
2Chronology assembledPrincipal events, each with its source and the manufacturer's date of receipt
3Package draftedChronology, population, remedy, notice text and confidence
4Controls appliedCompleteness checks, date-of-receipt checks, Part 573 and Part 577 clock checks and confidence threshold
No human action required

Stages 1 to 4 run unaided and determine nothing — the agent assembles and dates, and the engineer's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the safety-office engineer.

Low confidence

Adds a product-investigations read first.

Engineer sign-off

The package is held with its chronology, its named gaps and the confidence.

Approve · Amend · Send to investigations
Signed — the clock starts
6Campaign systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedChronology completeness, amendment distance, filing timeliness and quarterly-return currency
Amendments

Every engineer amendment is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Determining that a defect is safety-related.
Filing the Part 573 report with the agency.
Deciding an update is a customer-satisfaction campaign.
Issuing a do-not-drive or park-outside advisory.
Automation boundaryAgent acts unaided
Assemble the chronology, each event carrying its date of receipt.
Track the § 573.6, § 577.7 and § 573.7 clocks from the dated determination.
Reconcile the § 573.15 VIN lookup and the § 579.5.
Flag the gaps and the missing sources, and hold.
Any write happens inside the boundaries agreed at implementation, never ahead of the signature.
Setting the date the determination was made.
Scoping the population a campaign covers.
Committing to a remedy and a parts-availability date.
Changes to reporting rules or automation thresholds.

Example output

One principal event, annotated

Everything the agent assembles is attached to the record it was drawn from.

Chronology output · single campaignIllustrative example
Campaign
Principal event
Date of receipt
Source of record
Confidence
Clock position
Seat-belt anchorage
Sixth warranty claim naming the same anchorage weld
14 Feb 2026
Warranty claim file
93%
No determination dated yet
As receivedTaken from the warranty file and the supplier's 8D report — nothing on this side is written by the agent.
Source facts used Warranty claim intake Supplier 8D report Foreign field action
Why this dateIt is the date the manufacturer received the claim, not the date the claim was opened.
ActionApproveAmendSend to investigations
What the score decidesBelow the configured threshold the package picks up a product-investigations read before it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every field signalFrom the field record
03Assembly

Assemble from the record

Draw on warranty, field and supplier sources, and on the April 2026 agency orders that start a clock inside you.

01Approved path

The clock starts at the decision

Routine chronology assembly, notice drafting and quarterly returns arrive already prepared.

02Human review

Send review to the dated gaps

Gaps, a stale § 573.15 lookup and low-confidence packages are marked — the lookup was itself a penalised item in November 2024.

04Build an evidence trail

The event, the record it was drawn from and the engineer who determined stay on the chronology.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Quality and warrantyWarranty claims · TREAD
Supplier 8D · field reports
Regulatory filingNHTSA Part 573 portal
Part 577 · quarterly returns
Owner and VIN dataRegistered-owner records
VIN lookup · § 573.15 feed

Agent

Safety recall & field service

Reads the record
Builds the chronology
Holds for signature

Service and partsDMS · dealer service
Parts availability · OTA
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six controls between the model and the filing

Six controls, each nested in the one before. What the whole run misses is named in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to chronology assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, reporting-rule and clock-configuration changes.Track
L4TraceabilityRecord the source event, its date of receipt, the gaps, the amendments and the signature time.Record
L3Engineer sign-offHold packages for the named engineer; it governs release, not whether a signed determination is right.Gate
L2Policy guardrailsTest packages against the configured § 573.6, § 577.7 and § 573.7 rules; a failure returns the package.Restrict
L1Confidence thresholdsRoute low-confidence packages to a product-investigations read before the engineer sees them.Require review
Model corePackage drafted — chronology, population, notice text, clock dates and confidence
L1 – L2Test whether a package may stand
L3Puts the signature in an engineer's hands
L4 – L5Keep the event and the record behind it
L6Narrows to chronology assembly when signals degrade

How Nestack evaluates it

Evaluate the assembly workflow — not only the filed chronology.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the filing the agency reads
Depth of coverage ▼
E1Final-output evaluationDid every event in the chronology match its source record and its date?
E2Step-level evaluationDid the agent use the right sources, reporting rules and clock configuration?
E3Tool evaluationDid it read and write the correct campaign and the correct field?
E4Confidence calibrationDo low-confidence packages actually attract more engineer amendments?
E5Slice evaluationHow does performance change across specific campaign types?
E6Business outcomeHow many packages needed an amendment or a correction after filing?
Floor — the outcome the manufacturer answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
RJ-03

Source omitted

Supplier 8D or foreign field action never reaches the file.

Stage gathersWarranty claims, field reports, 8D and foreign actions
02 · Reasoning2 modes
RJ-04

Determination date drift

The clock is run from the flag, not the decision.

RJ-06

OTA fix left unfiled

A software remedy is closed without a Part 573 filing.

Stage proposesChronology, population, clock dates and confidence
03 · Tool / write2 modes
RJ-02

Quarterly series cut short

Six consecutive § 573.7 returns are set up as four.

RJ-05

Stale VIN lookup

The seven-day refresh lands after the filing did.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
RJ-01

Risk paragraph off-form

The § 577.5(f) wording is replaced by engineering prose.

Stage returnsThe chronology the engineer signs and the agency reads
05 · Change / Version1 mode
RJ-07

Silent rule regression

A model or rule change loosens what counts as an event.

Stage tracksModel, prompt, reporting rules and clock config
Sev-1 · a filing goes out unsigned Sev-2 · a wrong date reaches the chronology Sev-3 · a source degrades, package held

Affected slices

The campaigns you did not open carry the units

A programme-wide filing rate can read as timely while a few campaign cohorts carry most of the late chronologies. Nestack reports the engineer-amendment rate by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Agency-influenced campaigns9.5%3.7× Review
Supplier-originated defects7.6%3.0× Review
Foreign field actions4.8%1.9× Watch
Manufacturer-opened campaigns2.1%0.8× Normal
Bar: amendment-rate lift vs. manufacturer-opened baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

The loop closes on a test, not a memo

A cycle is done when the missed signal has become a case the next release must pass. That suite is what the next determination made is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

The § 573.15 lookup goes stale, or amendments rise in a slice.

02Diagnose

The signal that was visible long before anyone named it is read back until one cause holds.

03Improve

Stamp the change with a version; the campaigns behind it are filed against it.

04Verify

Every touched case is put through again, and a single red stops the release dead.

05Learn

It stays as a standing test, and the reporting rules are rewritten alongside it.

Learn → DetectThe return edge. The next signal is caught against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, assembly workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Recall workflow discovery and boundary definition.
02Warranty, field and supplier source review.
03Part 573, Part 577 and quarterly reporting rules.
04Field-record ingestion and date mapping.
05Chronology logic and source binding.
06Confidence scoring and gap routing.
07Engineer sign-off workflow.
08Filing and campaign-system integration.
09Signal and deadline cases.
10Guardrails and reporting controls.
11Campaign-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne campaign, one market ProductionProduction filing systems AdvancedMultiple markets / brands
Introduced at Pilot
Assembly to your sources and rules
Engineer sign-off
Chronology-completeness baseline
Introduced at Production
Reporting by campaign
Sign-off workflow in your systems
Approved write-back
Field-data integration
Introduced at Advanced
Multi-market reporting rules
Multi-stage safety-office review
High campaign volume
Multi-market campaign controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your field, warranty and supplier sources Field-record ingestion and date-of-receipt mappingWeek 1
02Representative closed campaigns Chronology baseline, source binding and clock modellingWeek 2
03Your reporting rules and notice templates Part 573, Part 577 and quarterly reporting rulesWeek 1
04Access to relevant APIs, feeds or exports Warranty, field and supplier assessment, then integration setupWeek 2
05Determinations you would not want dated Timeliness cases and the evaluation suiteWeek 4
06What no chronology may leave out Confidence scoring, gap routing, guardrails and sign-off controlsWeek 3
07Named safety-office engineers to review packages Engineer sign-off workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The plan is drawn on elapsed weeks, not on slide space, so week 5 legitimately doubles.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Recall workflow discovery, rule mapping and the automation boundary W2Source integration and the chronology baseline W3Assembly workflow, confidence logic and sign-off controls W4Evaluation suite, clock checks and failure-mode testing W5Filing integration, pilot campaigns and targeted corrections W6One campaign run under the safety-office engineer, then Agent Care handover
Reading the bandEach bar sits on the weeks its work is named in and no others. The week 5 doubling is real work, not padding.
At the end of W6The closing checks pass on live campaigns, and Agent Care takes monitoring on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Automotive AI agent

Build a safety-recall agent around your determination clock.

Show us your field sources, your reporting rules and who determines. The determination, its date and the signature on the Part 573 report stay with your safety-office engineer.

Nestack Agents · Safety recall & field serviceAGT-AUT-10 · Agent Care available after launch