# Marketing Jobs That Must Stay Deterministic (Not LLM Agents)

- Source: https://simeoncreatives.com/blog/marketing-jobs-that-must-stay-deterministic
- Hub: AI & Business Automation
- Author: Simeon Matheka, Founder & Creative Director
- Published: 2026-10-01
- Updated: 2026-10-01
- Reading time: 13 min

Lead routing, tracking tags, consent flags, send-time rules, and invoice copy all have a right answer. Put a score on each job before you hand any of them to a language model, and keep the model for the work that has no single correct output.

A team gets excited about agents and starts moving jobs. Lead routing goes first, because it is easy to describe. Then the weekly report. Then the tracking audit. A month later, a lead from a regulated industry lands with the wrong owner, and nobody can say why, because the model gave a reasonable-sounding answer that was different from last Tuesday’s.

Some marketing jobs have one right answer. Those should be rules. If you are still deciding which processes deserve automation at all, start with [which business processes to automate with AI](https://simeoncreatives.com/blog/which-business-processes-to-automate-with-ai). This page is the next filter: of the jobs you will automate, which ones must never be left to a model’s judgment?

## The test: can two runs disagree and both be fine?

Ask one question of every job. If you ran it twice on the same input and got two different outputs, would both be acceptable? For a social caption, yes. Two captions can both be good. For “which sales rep owns this lead,” no. One is right and one is a mistake.

A large language model (LLM) is built to produce plausible variation. That is a feature for drafting and a defect for anything with a closed answer. The model can be right nine times and wrong on the tenth with no change in tone, and you will not see the tenth one coming.

```mermaid
flowchart TD
    A["Marketing job"] --> B{"One right answer?"}
    B -->|Yes| C["Rule or script"]
    B -->|No| D{"Wrong output costs money, trust, or compliance?"}
    D -->|Yes| E["Model drafts, human approves"]
    D -->|No| F["Model with sampled review"]
    C --> G["Log and monitor"]
    E --> G
    F --> G
```

> Framework: if a closed table can answer the question, a closed table should answer it. Reserve the model for text that has no single correct form.

## A five-question determinism score

Score each job one point per “yes.” This is a judgment aid, not a law of physics. The point is to make you say the answers out loud.

| Question | Yes means | Points |
| --- | --- | --- |
| Is there a written rule a new hire could follow? | The logic already exists. Encode it. | 1 |
| Would two different outputs on the same input be a bug? | You need repeatability. | 1 |
| Does a wrong output change money, consent, legal exposure, or a customer record? | The cost of a quiet error is high. | 1 |
| Do you need to explain the decision to an auditor, client, or colleague? | You need a reason you can show, not a paragraph the model wrote afterward. | 1 |
| Is the input structured (fields, enums, numbers) rather than free text? | A model adds risk and no skill here. | 1 |

- **4 to 5: **Deterministic. Write the rule. No model in the decision.
- **2 to 3: **Hybrid. Rules for validation and routing, one narrow model step, human approval.
- **0 to 1: **Model-friendly. Drafting, summarizing, rewording. Sample the output weekly.

## Job by job: where marketing teams get this wrong

| Job | Keep deterministic? | Where a model may help |
| --- | --- | --- |
| Route a lead to an owner by region, size, or product | Yes. A routing table. | Extract the company name or need from a messy form note, then the table decides. |
| Apply consent and unsubscribe status before any send | Yes. Read the stored flag. | Nowhere. A send gate is a boolean. |
| Fire analytics events and campaign tags (Urchin Tracking Module, or UTM, parameters) | Yes. A naming convention and a validator. | Suggest names in a draft sheet. Code enforces the pattern. It never writes tags into production tracking. |
| Choose send time or frequency caps | Yes. Fixed rules and limits. | Analyze past engagement in a report that a person reads. |
| Calculate commissions, discounts, or invoice totals | Yes. Arithmetic. | Nowhere near the number. Maybe the cover note wording. |
| Sync fields between the customer relationship management (CRM) system and email tool | Yes. A mapping table. | Nowhere. Mapping errors are silent and expensive. |
| Write ad or social copy variants | No. | Good fit. Gate on claims and approval. |
| Summarize a call or a research page | No. | Good fit. Require sources and review where the output is used. |
| Classify an inbound message by topic | Partly. | Model labels from a closed list. A rule handles anything not in the list. |

Look at the pattern. The model touches text. Rules touch records. When the output of a text step has to become a record, you validate it against a schema, and anything that fails goes to a person.

## The hybrid shape: rules outside, model inside

Most real jobs score in the middle, and the answer is a sandwich. Deterministic checks go in front and behind. The model sits in a small, constrained step between them. [Deterministic workflows vs LLM agents](https://simeoncreatives.com/blog/deterministic-workflows-vs-llm-agents) lays out the architecture, and [rules, retrieval, or an agent](https://simeoncreatives.com/blog/rules-retrieval-or-agent) helps when the question is about knowledge rather than action.

#### Hybrid flow (JS)

```js
// 1. Deterministic: validate the raw form fields
if (!isValidEmail(form.email)) return reject('bad_email');

// 2. Model step: extract only. No routing, no reply.
const extracted = await llmExtract(form.notes, leadSchema);
if (!validate(extracted)) return queueForHuman(form, 'schema_fail');

// 3. Deterministic: routing is a table
const owner = ROUTING_TABLE[extracted.region]?.[extracted.size];
if (!owner) return queueForHuman(form, 'no_route');

// 4. Deterministic: consent gate before any message exists
if (!consent.hasOptIn(form.email)) return assign(owner, { send: false });

assign(owner, { send: false, note: extracted.need }); // a person writes the reply
```

#### Routing table

```json
{
  "EU":   { "small": "owner_a", "large": "owner_b" },
  "US":   { "small": "owner_c", "large": "owner_b" },
  "OTHER": { "small": "owner_a", "large": "owner_b" }
}
```

*Hypothetical hybrid lead intake. The model only extracts. The table decides. Anything unclear goes to a person.*

The model never picks an owner and never sends. If it extracts the wrong region, the failure is visible in the record and the table still returns a valid owner. That is a bounded mistake, which is what you want.

## Why agents make this worse, not better

An agent is a model that can choose tools and take actions. That raises the stakes on every job that is already closed-answer. The Open Worldwide Application Security Project (OWASP) names Excessive Agency as damaging actions taken in response to unexpected, ambiguous, or manipulated model outputs, and traces it to excessive functionality, permissions, or autonomy. A routing job does not need any of those. Sourced: [OWASP LLM06:2025 Excessive Agency](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/) (checked 1 October 2026).

The fix is the same boring answer: give the job the least power it needs. For a closed question, that is a table and no model at all.

## Filled hypothetical: scoring five jobs

Hypothetical, not a client. A studio scores five jobs. Lead routing by region: 5, rule. Consent check before send: 5, rule. Weekly competitor summary: 1, model with a source requirement and review. First-reply draft: 2, hybrid, with a human approving every send. Campaign tag naming: 4, rule, with a model allowed to suggest a name that a validator then checks.

Two of five jobs get no model at all, and that is the outcome you should expect. The model earns its place in the other three, and each of those has a gate. Nobody had to argue about agents in the abstract. They scored the work.

## Failure modes

- **Demo drift: **A model handles ten routing examples perfectly, so the team concludes it can route. Ten is not a table with every region and size band.
- **Silent variance: **The output is right 95 times and subtly wrong five. Without a golden set and logging, nobody sees the five.
- **Rule rot: **A deterministic table goes stale because nobody owns it. Name an owner and a review date, same as any other asset.
- **Over-correction: **Some teams refuse any model, then pay people to rewrite the same boilerplate forever. The score is a tool, not a religion.

## What this does not prove

The score does not measure savings or quality. It only sorts jobs by how much variance you can tolerate. A job that scores deterministic may still not be worth automating. A job that scores model-friendly may still need review. Use the score to decide the shape of the workflow, then evaluate the result with real inputs.

Print the [marketing determinism scorecard](https://simeoncreatives.com/resources/marketing-determinism-scorecard) and score every job on your list before building. When a job lands in the middle, build the model step with a schema and a review queue, as in [evaluate an AI workflow before production](https://simeoncreatives.com/blog/evaluate-ai-workflow-before-production). If you want a second opinion on where a job belongs, [send it over](https://simeoncreatives.com/contact).

## FAQs

### What does deterministic mean in a marketing workflow?

The same input produces the same output every time, and you can say why. A rule that sends every lead from a given country to a given owner is deterministic. A large language model (LLM) asked to “decide who should get this lead” is not, even if it usually agrees with the rule.

### Does this mean I should not use AI in marketing?

No. It means the model gets the jobs where wording, summarizing, or sorting messy text helps, and a person or a rule keeps the jobs where being wrong has a cost. Most good workflows are hybrids: rules on the outside, one model step in the middle, review at the end.

### Can an LLM draft the rule and then I run the rule?

Yes, and that is often the best use. A model can help you write a routing table or a regular expression. You then review it, test it, and run it as plain code. The model helped build the machine. It is not the machine.

### What if a job scores in the middle?

Split it. Keep the deterministic part (validation, routing, limits, logging) as code. Put the model only on the narrow ambiguous step, give it a schema, and send the result to a human queue. Do not hand the whole job to an agent.

### Why are tracking and consent on the list?

Because they have compliance and measurement consequences, and a plausible-looking wrong tag is worse than a missing one. Whether a flag is set is a fact in your system, not an opinion. Read it, do not infer it. For legal questions, ask a qualified professional.

### How do I revisit a decision later?

Re-score the job after any incident or when volume changes. A job that was fine as a person-reviewed draft at ten a week may need stricter rules at a thousand. Log the score and the date so you can see what changed.
