• A persona is held by verbatim prohibitions, not prescriptions: no exclamation marks, no "of course"
  • A persona has 3–5 places where the voice slips; in Russian the main one is verb gender
  • Prohibitions grow out of incidents: a month of operation yields 20–30 rules

The problem

A team deploys an agent with a named character that reads and replies in a long-running work chat; everyone in it knows it's an AI. The brief: be friendly, professional, warm, like a junior producer. By the fiftieth message, the agent is doing what the model does by default: it adds an exclamation mark when it's pleased with a quick reply; it opens with "Of course! Happy to help"; it reaches for the em dash because "it looks better"; and in Russian it slides into the masculine past tense, forgetting the character is a woman.

None of these is a mistake on its own. Together they produce the voice of a default assistant instead of a character. The persona falls apart because the rules were prescriptions, and "friendly" is whatever the model itself considers friendly.

flowchart TD
    P[Prescriptions:<br/>friendly, warm] --> E[Exclamation<br/>mark]
    P --> K[Of course!<br/>Happy to help]
    P --> T[Em<br/>dash]
    P --> G[Masculine<br/>verb forms]
    E & K & T & G --> B[Default<br/>assistant voice]
    classDef key stroke:#FF3600,stroke-width:2px
    class B key

The move

Identity doesn't survive on prescriptions like "be warm" or "match the team's energy." It survives on a short, explicitly named set of hard prohibitions, each aimed at a specific spot where the model's default breaks the voice. Prescriptions can stay — they set the color. The load-bearing structure is a list of what the agent must not do, written verbatim into the system prompt, with specific forbidden phrases and characters.

The "Hard rules" section of the persona file from the case:

- Never use an exclamation mark.
- Never write "of course," "happy to," "glad to help."
- Never use an em dash, only a hyphen.
- Emoji are forbidden, except one approving one.
- Feminine gender ALWAYS in past-tense verbs. Never the masculine form.
- Time is always local, never confuse it with UTC.

Why this holds while prescriptions drift. The model is trained to be helpful, smooth, warm. A prescription like "professional but friendly" collides with those defaults and compiles into the model's own voice with a light tint — recompiled on every turn. A prohibition works on a different layer: it removes specific tokens from the allowed output space. "Never use an exclamation mark" is a syntactic constraint that applies the same way every time; "be warm" is an aesthetic one that gets reinterpreted each time. Hence the asymmetry: a persona built on prescriptions is a bit perkier today, drier tomorrow, and back to assistant-default by Friday. A persona built on prohibitions stays in the same shell for thousands of messages, because the shell is defined by what can't be in it.

flowchart TB
    subgraph pre[Prescription: aesthetic constraint]
        direction LR
        A[Be warm] --> A2[Reinterpreted<br/>every turn]
        A2 --> A3[By Friday<br/>assistant-default]
    end
    subgraph ban[Prohibition: syntactic constraint]
        direction LR
        B[Never use an<br/>exclamation mark] --> B2[Tokens removed<br/>from output]
        B2 --> B3[One shell,<br/>thousands of messages]
    end
    pre ~~~ ban
    classDef key stroke:#FF3600,stroke-width:2px
    class A3 key

Slip points. Every persona has 3–5 places where a single slip is enough to break the voice. In Russian, past-tense verbs are marked for gender: the feminine and masculine forms differ by one suffix, and a single masculine verb in a chat with thirty native speakers breaks the persona. For an English-speaking persona, it's the model's habit of reaching for the em dash. For any persona, it's assistant boilerplate like "as a language model," which breaks the voice. The prohibition list names each such point explicitly and with examples: a vague "talk like a woman" catches nothing; a list of forbidden forms catches them.

flowchart TD
    S[Voice slip<br/>points: 3–5] --> R[Russian: masculine<br/>verb form]
    S --> E[English-speaking<br/>persona: em dash]
    S --> N[Any persona:<br/>as a language model]
    R & E & N --> L[List of<br/>forbidden forms]
    classDef key stroke:#FF3600,stroke-width:2px
    class L key

The incident → prohibition loop. Prohibitions aren't designed in advance — they appear in response to slips an observer noticed. A triple send of one message after a network timeout produced the rule "after sending, verify it went out exactly once; delete a duplicate immediately." A mention of a retired project produced the rule "retired projects are removed from memory." Each incident yields one line; by the end of a month of operation, the file has 20–30 rules, each tied to a specific past mistake. The file stays short because the rules are specific.

flowchart LR
    I[Slip<br/>in chat] --> O[Noticed by<br/>an observer]
    O --> R[One line<br/>of prohibition]
    R --> F[20–30 rules<br/>in a month]

Update, September 2026. Over the summer, the same agent's working rules were rewritten from scratch: process, change classification, escalation, reply templates. The persona file wasn't touched by a single line. That's a test of the layer separation: the persona governs how the agent talks, the operational layer governs what it's allowed to do, and one changes without the other. The operational prohibitions were written in the same form as the speech ones, as verbatim "nevers": don't discuss cost on your own behalf; don't forward messages; don't offer the client additional work; don't promise anything free until the change has been classified. A vague "be careful with money" wouldn't be followed any better than a vague "be warm."

flowchart TD
    A[Agent] --> P[Persona:<br/>how to talk]
    A --> O[Operational layer:<br/>what it may do]
    D[New working<br/>rules] --> O
    classDef key stroke:#FF3600,stroke-width:2px
    class O key

What's left for prescriptions. Tone, role, default. The persona file from the case opens with the line "dry-professional by default, warmer if the client is warm." It works as a surface above the floor, but on its own it won't hold the persona. A useful test: strip every prescription from the file. If the persona is still recognizable (no exclamation marks, no "of course," short replies, feminine gender), the floor is solid enough. The same principle in a broader form — for faces, products, and brand voice — is described in the Lock Layer pattern: preservation moves into a separate layer, and a persona's prohibition list is a special case of it.

Where it breaks

  • Too few prohibitions. Five rules in the file, three real slip points left uncovered. That's exactly where the persona drifts, and the search becomes reactive. List the slip points before deployment, and expect another 3–5 prohibitions in the first month.
  • Prohibitions without examples. "No overly chatty greetings" leaves the model room to interpret. Only "never write: of course, glad to help, great question, feel free to reach out" is enforceable.
  • The wrong context. Where the persona is supposed to change (creative co-writers, role-play systems, character bots), prescriptions become the load-bearing part, and prohibitions are only a safety floor.

Summary

  • A persona is held by a list of what it must not do, not by a description of what it should be.
  • Every prohibition names a specific phrase, character, or form; general words aren't enforceable.
  • Voice slip points are listed before launch; the rest accumulates from incidents.
  • The pattern is strongest for agents with a named character in long-running work chats where everyone knows it's an AI, as well as for brand voice and client-facing assistants.

© Alex Nikulin. Quote with attribution and a link · LLM version