Habitat Hero Academy
An educational ecosystem-building game that turns curriculum practice into systems thinking — with responsible AI patterns, graceful degradation, and governance built into the product architecture.
Executive Summary
Section titled “Executive Summary”- An educational game turns curriculum practice into systems thinking. Learners answer age-aligned riddles to earn species, then build a food web that must remain balanced across multiple simulation cycles.
- AI enhances the experience without becoming a dependency. Language models can generate new riddles and provide contextual help, while a reviewed static content bank and offline-capable application keep the core game available when AI or network services are unavailable.
- Safety and governance are product architecture, not prompt wording. Generated content passes layered safety and quality checks before learners can see it, chat receives only minimized game context, and operators have controls for oversight, auditing, and rapid intervention.
- The result demonstrates end-to-end product engineering. The project combines learning design, ecological simulation, responsible AI patterns, resilient web architecture, governance tooling, and a production build backed by 523 passing automated tests across 39 test suites.
The Product Challenge
Section titled “The Product Challenge”Many educational quiz products reward recall but do not give learners a meaningful reason to apply what they know. Habitat Hero Academy connects puzzle-solving to a living system: correct answers unlock plants, herbivores, predators, and decomposers, while progress depends on building an ecosystem that can sustain itself.
The design had to satisfy four goals at the same time:
- Make curriculum practice feel purposeful rather than disconnected from play.
- Model ecology through understandable cause and effect, not arbitrary scoring.
- Use generative AI without treating model output as automatically trustworthy.
- Preserve a complete, responsive experience even with no network or AI service.
This combination changed the role of AI in the product. The model is an optional content and interaction layer; it does not own progression, simulation rules, or the availability of the core learning experience.
How the Experience Works
Section titled “How the Experience Works”Learners choose a school year, subject, and difficulty, then solve curriculum-aligned multiple-choice riddles. Correct answers award species that can be placed into a biome. Each simulation cycle evaluates feeding relationships, reproduction, scarcity, population pressure, and extinction risk.
Success is based on sustained balance rather than a single score. Every species has a viable population range, and the ecosystem must remain within those ranges for consecutive cycles. A food web with too little prey can collapse; unchecked consumers can exhaust the level below them; and biodiversity improves resilience only when the relationships between species work.
Hints create a guided retry loop before an answer is revealed. This keeps mistakes useful and separates learning support from the reward mechanics of the ecosystem game.
Architecture Designed for Graceful Degradation
Section titled “Architecture Designed for Graceful Degradation”The system separates deterministic game behavior from optional AI capabilities. This keeps model latency, availability, and variability away from the critical learning loop.
Learner | vOffline-capable web application |-- Curriculum puzzle system |-- Ecosystem simulation and progression |-- Reviewed static content fallback | +--> Optional AI service boundary |-- Minimized interaction context |-- Input, instruction, and output guardrails |-- Content integrity and quality verification |-- Pre-approved riddle pool | +--> Interchangeable model providers
Restricted governance console |-- Operational controls |-- Content-pool oversight |-- Audit history and evaluation signals +--> Optional AI service boundaryThe learner application is a modular JavaScript and CSS single-page application built with Vite and packaged as an installable Progressive Web App. A lightweight edge service provides optional AI, authentication-aware features, and cloud persistence. Model-specific behavior sits behind a provider abstraction so generation, chat, moderation, and verification can evolve independently of the game client.
Puzzle practice and game modules communicate through a small reward contract. This allows the ecosystem experience—and future learning games—to change without coupling their internal state to question delivery. Saved state is versioned so the product can evolve without silently misreading older progress.
Safety Begins Before Content Reaches a Learner
Section titled “Safety Begins Before Content Reaches a Learner”AI-generated riddles are prepared away from the learner’s request path. Content is generated in advance, evaluated, and placed into an approved pool. A learner request reads from that pool rather than waiting for a model to invent a question live. When approved AI content is unavailable, the game immediately uses its reviewed static bank.
Generated content passes independent checks before publication. Low-cost deterministic validation first checks structure, answer consistency, duplicate choices and hints, and age-related language constraints. Content then passes safety screening and a separate quality evaluation that solves the riddle without seeing its answer key. Ambiguous, factually inconsistent, off-topic, unsafe, or incorrectly keyed content is rejected rather than served.
Chat is constrained by purpose and data minimization. The assistant receives only an allowlisted subset of the current learning and game state. Unknown fields are discarded, unnecessary player details are excluded, and the current answer is not supplied to the tutoring prompt. Aggregate ecosystem context is preferred over detailed player state when it is sufficient to explain why a habitat is unstable.
Guardrails operate at several points. Incoming text is screened before generation, model instructions define the educational scope, and outgoing text is checked before display. Output safety and generated-content verification fail closed: if a required check cannot complete, unchecked model content is withheld. The non-AI game remains available through its static fallback.
High-risk situations are not treated as ordinary off-topic chat. Distress-related language follows a separate, short, age-appropriate response path that encourages contact with a trusted adult. Operational signals can indicate that this path was used without making the raw disclosure part of that safety signal.
These measures reduce risk but do not make an open-ended model inherently safe. The product therefore treats safety as an evolving system of constraints, evaluation, monitoring, human judgment, and fallback behavior.
Governance Is Part of the Product
Section titled “Governance Is Part of the Product”The AI layer includes operational controls intended to make model behavior reviewable and reversible:
- Model-facing instructions are centralized in a structured prompt library with review metadata, expected variables, and known consumers. This creates a review surface instead of scattering prompts through application code.
- Generation, chat, moderation, and verification can use independently configured model providers. This supports safer evaluation and replacement without redesigning the client.
- Bounded usage controls limit abuse and unexpected cost, while a live disable control can pause AI activity without disabling the core game.
- A restricted operator console separates administrative authority from learner accounts. Changes to sensitive operational controls are recorded in an audit history.
- Tracing connects model activity with guardrail and rejection outcomes, supporting investigation of quality regressions and model or prompt changes.
- Content-pool tools support review, removal, controlled replenishment, and visibility into generation outcomes before broader use.
Together, these controls establish a practical governance loop: configure, evaluate, release, observe, intervene, and improve.
Product and Engineering Decisions
Section titled “Product and Engineering Decisions”Offline-first was treated as a product promise. AI failures do not become learner-facing loading failures. Static content, cached application assets, and deterministic game rules preserve the complete core experience.
The food web is the simulation’s source of truth. Species behavior is defined through feeding relationships and sustainable population bands. This produces explainable consequences and makes ecological reasoning part of the game rather than decorative theme.
Curriculum scope is explicit. School year maps to key stage, available subjects, age bands, and content selection. New year groups can remain unavailable until their content is ready, rather than being exposed automatically because the data model permits them.
AI tasks are separated by responsibility. Content generation, tutoring, moderation, and quality verification are distinct tasks. This makes it possible to choose fit-for-purpose models and evaluate each responsibility separately.
Reliability behavior is tested, including failure. The automated suite covers simulation rules, progression, persistence, curriculum selection, PWA behavior, context minimization, safety gates, quality verification, provider behavior, access controls, rate and budget controls, administrative auditing, and fallback paths. At the time of this case study, the production build completes successfully and all 523 tests across 39 suites pass.
Technology Summary
Section titled “Technology Summary”- JavaScript ES modules, semantic HTML, and modular CSS
- Vite build tooling and Progressive Web App capabilities
- Edge-hosted service layer and scheduled background work
- Key-value content pools and configuration storage
- Account authentication and cloud save support
- Local and hosted LLM provider abstraction
- Structured prompt management and model evaluation
- Distributed tracing for AI and guardrail behavior
- Vitest and DOM-based automated testing
Skills Demonstrated and Developed
Section titled “Skills Demonstrated and Developed”- Responsible AI product design for younger users
- Layered LLM safety, failure handling, and graceful degradation
- Content-quality evaluation and independent answer verification
- Prompt governance and provider-independent AI architecture
- Privacy-aware context selection and trust-boundary design
- Curriculum modelling and age-appropriate interaction design
- Deterministic simulation and systems-based game mechanics
- Modular front-end architecture, responsive UI, and PWA engineering
- Edge services, authentication, access control, and auditability
- Observability, operational controls, and cost-aware system design
- Automated testing of success, rejection, and dependency-failure paths
- Iterative product decision-making supported by explicit trade-offs
Further Work
Section titled “Further Work”The next stage would strengthen assurance rather than expand AI autonomy. Priorities include evaluating a dedicated independent moderation service; broader adversarial, multilingual, and age-segmented safety testing; a formal child-data and retention review; human content-review and incident-response workflows; accessibility validation; and supervised classroom research with learners and educators.
Additional product evaluation would measure whether riddle difficulty matches observed learner outcomes, whether hints support understanding rather than guessing, and whether the ecosystem loop improves engagement without distracting from the learning objective. These steps are necessary before describing the system as production-certified for broad educational use.