Inspiration

Institutional real estate managers, asset operators, and housing providers oversee thousands of residential and commercial square feet across dozens of conflicting municipal jurisdictions. In cities like New York (DOB/FDNY), San Francisco (DBI/SFFD), and Seattle (SDCI), building codes, annual backflow certifications, facade inspections, and elevator safety mandates are notoriously fragmented, opaque, and rapidly evolving. A single missed inspection or delayed certificate of occupancy can trigger catastrophic daily compounding fines, stop-work orders, and severe asset devaluations. Today, property managers juggle these obligations using brittle spreadsheets, manual mail-in audits, and reactive legal retainers. We asked ourselves: What if property managers had an autonomous, 24/7 compliance copilot that proactively audits municipal codes, quarantines untrusted contractor documents, calculates financial risk exposure, and prepares remediations with human-in-the-loop oversight? This inspired PermitPilot—an autonomous dual-model AI agent engineered specifically for statutory compliance and proactive risk mitigation.

What it does

PermitPilot is an autonomous multi-tier compliance intelligence platform that automates the municipal permitting and building compliance lifecycle for property portfolios: Edge PII Sanitization & Intake Defense: Quarantines unverified contractor notices, inspection reports, and violation PDFs, scrubbing private personal data (SSNs, phone numbers, emails) and neutralizing prompt injection attacks before reasoning begins. Autonomous Regulatory Cross-Referencing: Deeply analyzes municipal codes (e.g., NYC Admin Code § 28-301.1, Seattle SMC 22.206.130, SF Building Code § 106A) to detect active code violations, calculate statutory cure deadlines, and assess non-compliance exposure. Dynamic Financial Exposure & Risk Modeling: Computes deterministic property risk scores and projects compounding daily financial liabilities across entire multi-family and commercial asset portfolios. Autonomous Remediation Synthesis: Automatically structures prioritized vendor remediation tickets (e.g., dispatching certified backflow testers, elevator contractors, fire marshal expediters) with estimated budget costs and due dates. Human-in-the-Loop (HITL) Pre-Flight Gateway: Generates complete, professional dispatch orders and formal municipal appeal letters, locking execution behind explicit executive review with strict CapEx budget thresholds.

How we built it

PermitPilot is built using a dual-model asynchronous architecture designed for security, accuracy, and operational transparency:

[Unverified PDF / Notice] │ ▼ ┌───────────────────────────────┐ │ Gemma Intake Guard Layer │ ◄── PII Redaction & Adversarial Token Defense └──────────────┬────────────────┘ ▼ ┌───────────────────────────────┐ │ Gemini 2.5 Pro Agent Engine │ ◄── Function Calling / Municipal Cross-Reference └──────────────┬────────────────┘ ▼ ┌───────────────────────────────┐ │ Risk Scoring & Matrix Synth │ ◄── Dynamic Exposure & Risk Formulations └──────────────┬────────────────┘ ▼ ┌───────────────────────────────┐ │ Human-in-the-Loop Gateway │ ◄── Pre-Flight Authorization & CapEx Caps └───────────────────────────────┘

  1. Dual-Model Architecture Intake Guard (Gemma 2B): Unverified uploads undergo strict client-side extraction. Gemma redacts PII and neutralizes adversarial prompt injection payloads (e.g., "ignore prior instructions", "bypass compliance"). Statutory Reasoning Core (Gemini 2.5 Pro): Gemini utilizes multi-turn tool calling (getMunicipalCodeRules, queryPropertyHistory, calculateFineExposure, synthesizeRemediationTasks) via @google/genai to perform multi-step statutory cross-referencing and synthesize remediation workflows.
  2. Mathematical Risk & Exposure Formulation PermitPilot calculates projected financial fine exposure based on compounding statutory rates, cure deltas, and violation severities: Where: is the statutory daily fine rate for violation . represents the days elapsed past the mandatory cure date. is the non-linear severity escalation multiplier corresponding to . The composite property risk index is defined by: (with tuning weights , , and ).
  3. Technology Stack AI & Agent Core: Google GenAI SDK (@google/genai), Gemini 2.5 Pro with structured tool calling and system instruction grounding. Frontend: React 18, TypeScript, Tailwind CSS, Motion for transition layouts, and Recharts for portfolio analytics. Backend: Node.js & Express with live audit logging, in-memory transactional store, and full REST APIs.

Challenges we ran into

Adversarial Injections in Public Document Scans: Real estate violation notices often contain noisy OCR artifacts or malicious strings. Designing a lightweight sanitization barrier to scrub PII and neutralize jailbreak phrases without degrading regulatory details required rigorous prompt-boundary calibration. Jurisdictional Code Conflicts: Municipal codes differ drastically by city and building classification. We structured our tool schemas so Gemini dynamically maps specific municipal bylaws (e.g., Seattle SDCI vs. NYC DOB) without cross-contaminating fine schedules or compliance timelines. Balancing Agent Autonomy with Executive Safety: Fully autonomous agents can create real-world liabilities if given unrestrained dispatch authority. Finding the optimal interface pattern—where the agent performs 95% of the heavy lifting (statutory analysis, vendor drafting, deadline calculation) while leaving the final authorization button to the human operator—was essential for enterprise compliance readiness.

Accomplishments that we're proud of

True End-to-End Dual-Model Pipeline: Successfully connected Gemma's privacy defense layer directly into Gemini 2.5 Pro's multi-step statutory reasoning loop. Interactive Multi-Step Execution Visualizer: Built a live agent dashboard displaying reasoning logs, tool call arguments, PII redaction metrics, and remediation synthesis in real time. Pre-Flight Human Authorization Gateway: Designed a full HITL queue that converts raw compliance violations into ready-to-dispatch vendor contracts and municipal appeal letters with strict budget caps. Zero-Friction Regulatory Sandbox: Enabled instant switching across multiple jurisdictions (NYC, SF, Seattle) and property archetypes (Commercial, Multifamily, Industrial) with live portfolio analytics.

What we learned

Dual-model pipelines are essential for untrusted input: Offloading PII sanitization and safety classification to a dedicated, lightweight intake layer drastically reduces reasoning latency and operational cost on larger frontier models. Tool-grounded statutory analysis eliminates hallucination: Grounding Gemini with concrete function definitions for local municipal statutes ensures that every generated violation citation matches actual municipal code sections with exact deadline calculations. Visualizing the agent's thought trail builds user trust: Providing an interactive execution visualizer showing the transition from Intake Guard Statutory Cross-Reference Remediation Synthesis HITL Dispatch gives operators complete transparency into the AI's decision-making process.

What's next for PermitPilot

Live Municipal Portal Integrations: Connect directly to public municipal open-data APIs (e.g., NYC OpenData, SF DBI Portal, Seattle Services Portal) to auto-ingest newly posted violations the minute they are filed. Automated Digital Permit Submission: Expand the HITL gateway to support automated PDF form-filling and electronic signature filing for standard permit renewals. Multimodal Visual Inspection Analysis: Enable on-site property managers to take photos of fire escapes, backflow valves, and boiler tags with mobile cameras, using Gemini 2.5 Pro Vision to verify physical compliance tags on-site. Sub-Contractor Dispatch & Invoice Reconciliation: Integrate with property accounting systems (Yardi, RealPage, AppFolio) to automatically match completed vendor work orders with resolved violation notices.

Built With

Share this project:

Updates

Submission history