Technical Case Study8 min read

Building BeaconAI: Deterministic Job Intelligence & Resume Engine

How I engineered an autonomous, model-agnostic CLI pipeline combining two-tier cost shielding, the Selector Pattern, and sandboxed PDF compilation to bypass hiring noise.

Daniel Giovinazzo
Daniel Giovinazzo
Full-Stack Software Engineer

The Operational Dilemma: The Algorithmic Sifting Trap#

Between 2024 and 2026, the modern hiring market reached peak algorithmic friction. Job seekers find themselves trapped in 20-hour weekly manual sifting loops across syndicated job boards—navigating ghost requisitions, vanity postings, and keyword-stuffed job boards that prioritize platform stickiness over candidate-role fit.

Most AI-assisted job applications make this dilemma worse. Generic chatbots and browser extensions dump an applicant's entire career history into an unconstrained prompt, synthesize strange hybrid resumes, hallucinate unverified skills, and rack up expensive API bills re-evaluating unqualified postings.

I engineered BeaconAI to invert this paradigm through systems thinking over toy AI prompting. It is an autonomous, model-agnostic CLI pipeline that ingests unstructured RSS feeds and native IMAP email alerts, enforces zero-cost deterministic constraint gates before calling foundation models, routes candidates through discrete persona tracks via the Selector Pattern, and compiles ATS-compliant single-page PDF resumes using a sandboxed WeasyPrint engine.

BeaconAI CLI Execution Cockpit
BeaconAI unified CLI execution trace: stream ingestion, Tier 1 Cost Shield evaluation ($0 API spend), LiteLLM scoring, and sandboxed PDF generation.

System Architecture: Two-Tier Filtering & The Deterministic Cost Shield#

The core architectural principle of BeaconAI is simple: zero LLM tokens are consumed until deterministic logic certifies that a posting meets every non-negotiable candidate boundary.

The pipeline executes a two-tier filtering topology. In Tier 1, incoming job descriptions pass through zero-overhead regex and numeric thresholds that enforce hard constraints: strict compensation floors, physical lifting limits (e.g. dropping warehouse roles requiring 50lb lifts), transit boundaries, and schedule constraints (blocking unpredictable overnight shifts).

Postings clearing Tier 1 encounter a financial circuit breaker (MAX_LLM_EVALS_PER_RUN) to prevent bill runaways during high-volume feed syncs. Clear postings are then evaluated in Tier 2 via a model-agnostic LiteLLM layer—compatible with Gemini 2.5 Flash Lite, Claude 3.5 Sonnet, GPT-4o, or local Ollama instances—which enforces strictly typed Pydantic V2 schema validation on all scoring outputs.

BeaconAI System Architecture & Data Pipeline
End-to-end data pipeline: multi-source RSS and IMAP stream ingestion, SQLite state deduplication, two-tier filtering gates, and dynamic artifact compilation.
cost_shield.py
python
class Tier1CostShield:
    """Zero-cost deterministic constraint gate evaluated prior to LLM invocation."""

    def __init__(self, profile_constraints: CandidateConstraints):
        self.constraints = profile_constraints

    def evaluate_posting(self, posting: RawJobPosting) -> GateResult:
        # 1. Enforce minimum compensation floor
        if posting.max_hourly_rate and posting.max_hourly_rate < self.constraints.min_pay_floor:
            return GateResult(passed=False, reason="Below compensation threshold", cost=0.0)

        # 2. Enforce physical lifting and safety constraints
        if self.contains_physical_restrictions(posting.description):
            return GateResult(passed=False, reason="Violates physical lifting boundary", cost=0.0)

        # 3. Enforce geographic transit boundaries
        if posting.commute_distance_miles > self.constraints.max_commute_miles:
            return GateResult(passed=False, reason="Exceeds commute radius", cost=0.0)

        # 4. Enforce shift schedule boundaries (e.g., graveyard / on-call)
        if self.is_disallowed_shift(posting.description):
            return GateResult(passed=False, reason="Incompatible shift schedule", cost=0.0)

        return GateResult(passed=True, reason="Cleared all Tier 1 deterministic gates", cost=0.0)

The Multi-Track Persona Engine (The Selector Pattern)#

Most generative resume tools fail due to context poisoning. If a candidate has a versatile background spanning software engineering, operations, and accounting, an unconstrained LLM blends unrelated skills into bizarre Frankenstein hybrids—submitting an Accounts Payable resume boasting about Kubernetes clusters and React hooks.

Furthermore, high-throughput lightweight models (such as Gemini 2.5 Flash Lite) struggle with negative constraints when given generative freedom. When prompted to generate skills from scratch, they hallucinate software tools the candidate never touched, or generate varying paragraph lengths that spill over onto page 2 by 4 to 6 lines, violating hiring manager standards.

BeaconAI eliminates context poisoning and hallucinations through The Selector Pattern. Candidate experience is compartmentalized into discrete profile tracks (clerical_data_entry, accounting_bookkeeping, technical_support_qa, data_analysis_reporting, software_engineering). The deterministic track router (resolve_profile_track) analyzes title tokens to bind the posting to a single persona pool with a 100% frozen skills matrix.

The Selector Pattern vs Unconstrained Generative AI
The Selector Pattern: replacing unstructured generative prompts with deterministic profile track routing and a 100% frozen skills matrix.
profile_router.py
python
def resolve_profile_track(job_title: str, description: str, profile: UserProfile) -> ProfileTrack:
    """Deterministically route posting to an isolated persona track based on token overlap."""
    title_lower = job_title.lower()
    
    # Priority token matching against configured track triggers
    for track in profile.registered_tracks:
        if any(keyword in title_lower for keyword in track.title_triggers):
            return track

    # Fallback to secondary body heuristic scoring
    scores = {
        track.id: sum(1 for kw in track.body_keywords if kw in description.lower())
        for track in profile.registered_tracks
    }
    best_track_id = max(scores, key=scores.get)
    return profile.get_track(best_track_id) or profile.default_track

Defensive Engineering: Sandboxed WeasyPrint & Context Encapsulation#

Processing untrusted web feeds introduces serious security threat vectors. Job board postings can carry adversarial prompt injection payloads designed to override system prompts or exploit document compilation engines.

To protect against prompt injection, all external job text is encapsulated inside immutable XML boundaries (<untrusted_job_posting>), while raw HTML is sanitized through BeautifulSoup to strip tracking pixels, CSS expressions, and script tags.

For document compilation, BeaconAI uses a sandboxed WeasyPrint PDF engine configured with a custom zero-trust URL fetcher (blocked_url_fetcher). By intercepting and blocking external network requests and local file URIs, the engine guarantees immunity against Server-Side Request Forgery (SSRF) and local credential exfiltration during PDF rendering.

sandboxed_pdf.py
python
def blocked_url_fetcher(url: str) -> dict:
    """Zero-trust fetcher blocking all external network and local filesystem access."""
    log_security_audit("blocked_external_asset_request", requested_url=url)
    raise SecurityPolicyViolation(f"External asset fetching disabled in PDF sandbox: {url}")

def compile_sandboxed_pdf(html_content: str, output_path: Path) -> Path:
    """Compile ATS-compliant PDF with strict network isolation and physical page budgeting."""
    html_doc = HTML(string=html_content, url_fetcher=blocked_url_fetcher)
    html_doc.write_pdf(
        target=str(output_path),
        stylesheets=[CSS(string="@page { size: letter portrait; margin: 0.5in; }")]
    )
    return output_path

Zero-Storage Automation & Engineering Takeaways#

BeaconAI is engineered for zero maintenance and strict privacy. It runs unattended via GitHub Actions on ephemeral runners, scanning feeds and email alerts on a daily schedule with zero cloud database storage requirements.

When high-fit matches occur, transactional alerts are dispatched directly to the candidate's inbox via Resend, complete with attached single-page tailored PDF resumes and pre-populated mailto cover letters for 1-click applications.

Building BeaconAI reaffirmed my engineering conviction: the most resilient AI applications are not built by writing complex prompts, but by building rigorous systems architectures—deterministic boundaries, typed schemas, and strict operational cost guards around the model.

Topics:Autonomous PipelinePythonPydantic V2LiteLLMSystems ArchitectureDefensive Engineering
Let's Build Together

Have an engineering challenge or role in mind?

I'm open to full-stack software engineering and AI engineering opportunities. Reach out to discuss technical architecture, system design, or team collaboration.