Start here. This is the direct spoken answer to practice first.
Overview
The first choice is a stronger output contract. Repair exists for recoverable failures, not to make an unsuitable task appear reliable.
I prefer provider-supported schema-constrained output. Otherwise I parse and validate the response, classify the failure, and retry only when a bounded repair is likely to help. A repair prompt includes the validation error and the original required contract without asking the model to change unrelated values. After the retry budget, I use a safe fallback or request review.