The problem
Most automated SEO tools either only report problems or make changes no one reviewed. Site owners need help that acts, but never acts beyond what they approved.
What I built
A growth engine with a policy layer between the AI and every action it can take, a job queue, and publishing integrations that stop at a reviewable step.
My role
Founder and sole builder: product, backend, policy engine, infrastructure and the public site.
Architecture
- Node.js 22 backend with ES modules and a deliberately small dependency list.
- PostgreSQL with pgvector used as the datastore, the vector store and the job queue (using SKIP LOCKED).
- A policy engine that checks every tool call an agent wants to make against the owner's chosen autonomy mode.
- Firebase Hosting in front of a Cloud Run service, with a managed Postgres database.
Technologies
How it works
Rankelo crawls and audits a site, stores the evidence, and plans changes. Each planned action goes through the policy engine, which allows, blocks or escalates it depending on the autonomy mode. Code changes to a GitHub repository are opened as draft pull requests for the owner to review.
Key engineering decisions
- One database for data, vectors and queue, to keep the system small and cheap to run.
- Five autonomy modes so owners choose how much the system may do on its own.
- Outbound requests validated against SSRF before any fetch.
- GitHub publishing stops at a draft pull request; nothing is merged automatically.
Challenges
- Writing policies that a language model cannot talk its way past.
- Keeping a useful free tier while paying for model calls.
What I learned
Safety in agent products is an architecture decision, not a prompt. Putting the policy engine outside the model made the behaviour predictable.
Current status
Live, in early access.
Links
More case studies: Capital Intelligence OS · GridResolve AI · Vaani · TalkBot · Bizia