Outcome & scope
Define the decision or workflow, accountable owner, success metric, prohibited uses and stop conditions.
TEN FOUNDATIONS
Use these as a readiness gate. A missing foundation does not always block experimentation, but it should limit autonomy and scale.
Define the decision or workflow, accountable owner, success metric, prohibited uses and stop conditions.
Know source, provenance, quality, sensitivity, freshness, retention, usage rights and data owner.
Know every human and synthetic actor and what each may read, write, send, buy, delete, share or change.
Benchmark the minimum sufficient model, automation or conventional software against the real job.
Record what supported an output or action, the version used, what changed and what remains uncertain.
Test normal, edge, adversarial, change and recovery scenarios and measure false-clear behavior.
Threat-model prompts, tools, agents, credentials, data flows, memory and third parties.
Measure cost per accepted task, human intervention, latency, compute and resource consumption.
Define who approves, overrides, escalates, trains, audits and owns the outcome when AI is wrong.
Design kill, rollback, restore, export and provider-exit paths before critical dependency develops.
COME AS YOU ARE
AI literacy, privacy boundaries, verification habits, age/role limits, trusted contacts and a clear human decision owner.
One measurable workflow, approved tools, data rules, SOPs, cost controls and a monthly quality/ROI review.
Central inventory, decision rights, lifecycle gates, vendor controls, evidence, cost allocation, incident response and portfolio governance.
Representative evals, permissions, observability, change revalidation, receipts, tool security and rollback.
Public accountability, records, accessible explanations, procurement evidence, continuity, correction and durable human authority.
Risk classification, separation of duties, validation, audit trail, fail-safe modes, DR, domain experts and independent review where required.
INTERACTION DESIGN
Needs understandable boundaries, consent, evidence, uncertainty, escalation, accessibility, correction and override.
Adds machine-verifiable identity, scoped delegation, lineage, TTL/depth/budget limits, tool permissions, loop termination, handoff receipts and a route back to accountable humans.
External anchors: NIST AI RMF · ISO/IEC 42001 · Q10 Research Observatory