TK. Talal Khawaja, home Résumé

Case study · 2026 · Hackathon

ScopeGuard AI

Turns scattered client instructions (briefs, notes, emails, chats) into an evidence-backed scope that a person reviews and confirms before any work is committed.

OpenAI Build Week (Work & Productivity) · Devpost · 18 Jul 2026

SAFIG. 01 — SYSTEM SKETCHGENERATED FROM STACK · NOT A SCREENSHOTSANEXT.JSTYPESCRIPTOPENAI APICODEXVITEST
Fig. — generated system sketch from the project’s stack. Not a product screenshot.

Overview

ScopeGuard AI turns scattered client instructions into an approved, evidence-backed delivery plan. Talal Khawaja, Aqeela Urooj and Umer Anis built it for the Work & Productivity category of OpenAI Build Week on Devpost, with Codex doing most of the implementation.

Problem

Anyone who has run agency or client delivery knows the pattern. The brief says five pages, the kickoff call adds a second homepage concept, and a chat message three weeks later moves the launch date. None of those sources contradicts the others explicitly, so the conflict only shows up at handover. Keyword rules can't catch it either. A new request doesn't have to use the word "new", two dates can conflict in different formats, and a suggestion can read a lot like a commitment.

How it works

The user enters the project, the client, the agreed baseline and any number of dated source cards: briefs, meeting notes, emails, chats, tasks and change requests. A server-only route sends them to the OpenAI Responses API and asks for strict JSON Schema output. The system instruction tells the model to:

  • compare every source with the baseline;
  • cite valid source IDs for consequential findings;
  • separate confirmed facts from uncertainty;
  • treat later requests as proposed changes rather than approved commitments.

The route then validates the response a second time with Zod and rejects any citation that doesn't match a supplied source.

The workspace lays the findings out by category, with confidence labels and source IDs, covering requirements, conflicts, decisions, assumptions, scope creep, dependencies, risks, questions, tasks, acceptance criteria and a change summary. On the review screen, every requirement gets approve, reject and edit controls plus a reviewer note, and every clarification question has to be resolved. Final confirmation stays locked until nothing is pending, and any edit after confirmation returns the project to draft. The confirmed scope exports as a Markdown brief, a JSON record, a client-facing summary or an internal checklist.

The model name comes from configuration. The deployed build used a smaller model for faster structured analysis. The API key stays in the Node server route and never reaches the client.

Key decisions and trade-offs

  • The AI drafts and people commit. ScopeGuard never approves scope, contacts a client or assigns work. Task owners are only suggestions.
  • Traceability, not proof. A citation shows where a finding came from. It doesn't make the finding true or legally binding, and the product says so.
  • Prototype storage. The workspace lives in browser local storage, with no authentication, multi-user collaboration or server-side audit log.
  • Testing. Automated tests cover the analysis contract, source-ID integrity, exports, input validation, prompt-injection fixtures and safe API errors, and CI runs lint, tests and the build.
  • Honest attribution. Codex turned the product brief into the architecture, schemas, review state, exports and tests. The team kept the decisions about evidence, approval authority and responsible-AI limits.

What's next

The roadmap lists team workspaces with version history and immutable approvals, side-by-side source excerpts, PDF, DOCX, email and transcript ingestion, re-analysis diffs when a new source arrives, and change-cost estimates based on rate cards that people set.

Problem

Delivery scope rarely lives in one place. The signed brief says one thing, kickoff notes add another, and a later email quietly moves the date. Teams spend hours reconciling fragments and still miss requirements, absorb unpriced work, and end up in awkward client conversations.

Approach

A server route asks the model for strict JSON Schema output that compares every dated source against the agreed baseline. It returns requirements, conflicts, scope creep, dependencies, risks, questions, tasks and acceptance criteria, each citing source IDs. The response is validated again with Zod, and unknown citations are rejected. A person then approves, rejects or edits every requirement and resolves every question before the scope can be confirmed and exported.

My contribution

Team member (teqprotech).

  • Talal KhawajaTeam member (teqprotech)
  • Aqeela UroojTeammate
  • Umer AnisTeammate

Architecture

01Next.js02TypeScript03OpenAI API04Codex05Vitest
Diagram — the recorded stack, in project-record order. A sketch, not a screenshot or a data flow.

The detailed architecture for ScopeGuard AI hasn’t been documented yet, so this sketch only lists the technologies on the project record. Nothing here is guessed.

Features

  • Dated source cards, with .txt and .md import

  • Strict JSON Schema output plus a second Zod validation

  • Findings cite source IDs; unknown citations are rejected

  • Conflict, scope-creep and needs-clarification views

  • Per-requirement approve, reject, edit and reviewer notes

  • Final confirmation blocked while questions are open

  • Four exports: Markdown brief, JSON record, client summary, internal checklist

Stack

Shipped on Devpost, GitHub and Vercel.

Outcome

Submitted to OpenAI Build Week (Work & Productivity) on Devpost, 18 Jul 2026.

Not among the listed winners.

Built with Teqprotech · Custom Web Applications, AI Agents with Human Approval.