Stamp the hour each incident signal was received and the hour a determination was made, so the responsible party can file inside the window 21 U.S.C. 350f leaves open.
2Finding context assembledThe lot, the hour each signal landed, the distribution already made and the plan on file
3Determination file draftedThe signals, their hours, the check population and completeness
4Controls appliedClock checks, consignee-depth checks, element checks against § 350f and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is determined at any of them — the agent is assembling, and the recall lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the responsible party to determine.
Anything thin
Adds a quality director read first.
Recall review
The file is held with its signals, their hours and the distribution behind them.
Determine · Append evidence · Send to recall review
Determined — twenty-four hours run from here▼
6Recall and lot records updatedOnly where write access and records policy allow it
7Outcome evaluatedDetermination latency, consignee coverage, reviewer corrections and what the read found
Corrections
Each recall correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Determining that a food is reportable, § 350f.
Filing the report through the electronic portal.
Classifying a recall — § 7.41(b) leaves that to FDA.
Signing and dating the food safety plan, § 117.310.
Automation boundaryAgent acts unaided
✓Stamp the hour each incident signal was received on the record.
✓Time the determination apart from the signals that led up to it.
✓Build the distribution depth by consignee level.
✓Flag the finding whose hour the record cannot show.
Nothing is determined, filed or classified except by a named person or by FDA itself.
Choosing the effectiveness-check level under § 7.42.
Requesting termination of a recall under § 7.55.
Answering a cease-distribution order within two days.
Changes to lot, consignee or distribution records.
Example output
One finding, annotated
No signature falls due per recall event; this record is what one finding carried while nobody had yet determined anything.
Recall evidence · single findingIllustrative example
Finding
Recorded as
Signal class
Evidence of record
Confidence
Held for
Consumer complaint, § 350f
Received in the shared mailbox, no determination yet made
Complaint signal
Received 3 August 2026, hour stamped
Held undetermined
The responsible party, by name
As receivedTaken from the complaint intake and the distribution list — it reaches as far as those sources do.
What the record holdsComplaint intake logDistribution listDetermination note
Why no determination hereWhether a food is reportable is a § 350f judgement reserved to a person.
ActionDetermineAppend evidenceSend to recall review
What the score decidesBelow the configured threshold the file picks up a recall read before it moves.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every findingFrom the channel that raised it
03Evidence
Where the evidence is used
Our supply-chain traceability agent owns the lot graph and hands a named person the release decision, and its own duty is deferred to 20 July 2028 by Pub. L. 119-37 while the clock on this page is live today — what the two share is exactly the consignee list.
01Approved path
The clock starts on a finding
21 U.S.C. 350f runs from the moment a responsible party determines a food is reportable, and wants the report as soon as practicable inside that period.
02Human review
What was checked, and not found
No rule amending Part 7 Subpart C was located for 2024 to 2026 and no Unified Agenda check was performed, so nothing proposed here means nothing found rather than nothing existing; whether the Safety Reporting Portal presents an attestation at submission could not be verified, and § 7.42 was last amended at 88 FR 45064 on 14 July 2023.
04Build an evidence trail
The finding, the hour it was made and the person who determined it stay on the record.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Complaint and consumer channelsCare inbox · call logs Complaint intake records
Laboratory and monitoringLIMS · environmental swabs Certificates of analysis
Distribution and consigneesERP · shipment records Consignee and account lists
Agent
Recall and reportable food
Reads the signals Stamps the hours Holds for determination
Plans and proceduresFood safety plan · § 117.139 Written recall procedures
Integration availability depends on the client's existing systems and API access.
Agent controls
Six cuts between the model and the determination
Six cuts at the same finding, each one sharper. Whatever holds through all of them is mapped out below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and clock rules; no amendment to Part 7 Subpart C was found for 2024 to 2026, and the FDA letter to industry of 15 December 2025 is a letter and not a rule.Track
L4Hour trailRecord each signal, the hour it landed, the hour of determination and every read of the file.Record
L3Determination gateHold the file for the responsible party registered under § 350d(a); the hold governs release, not whether the article is reportable.Gate
L2Scope guardrailsTest the file against §§ 350f, 7.42 and 7.53; a mandatory recall under § 350l follows a refused voluntary one, and § 350l(h) leaves that order to the Commissioner alone.Restrict
L1Confidence thresholdsRoute a thin file to a recall read first; the December letter presses on speed and restates § 117.139(b)(3) effectiveness checks.Require review
Model coreFile assembled — the signals, their hours, the distribution and completeness
L1 – L2Test whether a file may stand
L3Puts the determination in a person's hands
L4 – L5Keep the finding and the hour behind it
L6Steps back to evidence assembly when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the determination file that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the file an investigator reads
Depth of coverage ▼
E1Final-output evaluationDid the file carry the hour each signal actually landed?
E2Step-level evaluationDid the agent read the right lot, the right consignee level and the live distribution?
E3Tool evaluationDid it read and write the correct finding record and the correct hour?
E4Confidence calibrationDo low-confidence files actually attract more recall corrections?
E5Slice evaluationHow does performance change across specific signal channels?
E6Business outcomeHow many files needed a correction before the determination was made?
Floor — the record the firm answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each placed at the stage where the clock first slips.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
JS-03
Stale distribution read
The consignee list read is not the one now in force.
Stage gathersThe signals, the hours, the lots and the lists
02 · Reasoning2 modes
JS-04
Hour asserted, not shown
A determination hour is stated with no record beneath it.
JS-06
Guidance read as rule
The recall guidance is worked as though binding.
Stage proposesThe findings, their hours and completeness
03 · Tool / write2 modes
JS-02
Thin file passed forward
A file moves on without the recall read.
JS-05
Signal bound to wrong lot
A record is filed against the wrong lot.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
JS-01
Determined, hour unrecorded
The file shows a determination but not its hour.
Stage returnsThe file a named person reads before determining
05 · Change / Version1 mode
JS-07
Silent clock regression
A configuration change moves the clock, not the record.
Stage tracksModel, prompt, clock rules and evidence fields
Sev-1 · a determination made on no recordSev-2 · wrong hour reaches the fileSev-3 · source degrades, file holds open
A finding-level determination-latency figure can read clean while consumer complaint channels carry most of the rework. Nestack reports the correction rate by signal channel, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Consumer complaint channels
7.4%
3.6×
Review
Environmental monitoring hits
5.3%
2.6×
Review
Supplier certificates of analysis
3.3%
1.6×
Watch
In-house laboratory results
1.3%
0.6×
Normal
Bar: correction-rate lift vs. in-house-laboratory baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a late determination costs
A loop ends when the late determination has become a case the next release must pass. That suite is what the next finding logged is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on consumer complaint channels.
02Diagnose
The complaint that sat in a shared mailbox while a statutory day ran is opened again until one cause remains.
03Improve
Number the change; the findings that drove it are filed underneath it.
04Verify
Each touched finding case is run once more, and one red holds it back.
05Learn
It stays on as a standing test, and the escalation rules move with it.
Learn → DetectThe return edge. The next finding is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Recall-clock discovery and automation-boundary work.
02Complaint, lab and distribution sources.
03Signal-to-determination and consignee-depth mapping.
04Incident signal ingestion.
05Finding, hour and lot binding.
06Completeness scoring and review routing.
07Responsible-party determination flow.
08Recall and lot-system integration.
09Determination and check cases.
10Guardrails and escalation controls.
11Finding-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne site, one recall laneProductionProduction recall workflowAdvancedMultiple sites / brands
Introduced at Pilot
Evidence assembly to your channels✓✓✓
Responsible-party determination✓✓✓
Distribution-depth baseline✓✓✓
Introduced at Production
Reporting by consignee level—✓✓
Determination workflow in your systems—✓✓
Approved write-back—✓✓
Complaint-channel integration—✓✓
Introduced at Advanced
Multi-brand recall plans——✓
Cross-channel evidence packs——✓
Large consignee lists——✓
Multi-clock notification controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, consignee list size, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your registered facilities and their signal channels→Channel mapping and hour captureWeek 1
02Representative complaints, results and distribution records→Record binding, clock logic and the evidence baselineWeek 2
03Your written recall plan under § 117.139→Channel mapping, hour stamping and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Complaint, laboratory and distribution-source assessment, then integration setupWeek 2
05Findings you would not want examined→Determination cases and failure testingWeek 4
06What no recall record may prove→Completeness scoring, review routing, guardrails and release controlsWeek 3
07A responsible party named to determine→Determination workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The spans below are honest working weeks rather than spacing, so two of them must share week five.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Recall workflow discovery, channel mapping and the automation boundaryW2Source integration and the distribution-depth baselineW3Evidence assembly, clock logic and release controlsW4Evaluation suite, determination cases and failure-mode testingW5Record integration, pilot findings and targeted correctionsW6One recall exercise run under the quality director, then Agent Care handover
Reading the bandEvery bar runs across the weeks its own work is named in, and the fifth holds two of them because that is what the work costs.
At the end of W6When the finding record validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Food & Beverage AI agent
Build a recall agent around the hour your own people made the call.
The law gives a clock and no ceremony. Show us your complaint channel, your distribution lists and the plan a named officer signed under § 117.310. What can be asked for afterwards is the record of when you knew. CPSC product safety reporting is a different agent.