Human operator reviewing approved sources, evidence checkpoints, and a stop boundary before activating an AI agent.
Picture of John Dawson

John Dawson

What Should An Agent Know Before It Helps?

An AI agent can sound ready long before the workflow around it is ready.

Before an agent enters a real workflow, define what it needs to know, what it may do, when it must stop, and what evidence it must leave behind.

This AI agent context checklist makes those operating boundaries visible for human review. It does not guarantee safety or performance. It helps a responsible owner decide whether to proceed with a bounded trial, revise the workflow, or keep the work human-led.

1. What job is the agent helping with?

Start with one workflow and one job to be done. Name the decision the agent may prepare, the output it may create, and the standard for a useful result.

“Help the team” is too vague. A useful assignment is specific: assemble a weekly exception report from approved sources, draft a customer-response option for review, or prepare evidence for a manager’s decision.

2. Who remains accountable?

Name the person accountable for the workflow and the person expected to review or use the output.

The owner needs the competence, time, evidence access, and authority to correct the work or stop the process. An agent may prepare a decision. It does not inherit the right to own the consequence.

3. Which sources may it use?

List every approved source and its authority. A signed policy, current system record, working draft, meeting note, and general web page do not carry equal weight.

Define freshness and conflict rules. Which source wins when records disagree? How old may a record be before the agent must flag it? What must be quoted or linked so the reviewer can inspect the basis for the answer?

This is why better AI starts upstream: the quality of the surrounding context shapes the quality of the work an agent can prepare.

4. Which information is off limits?

Name the sources, folders, systems, and data types the agent must not use. Include confidential client information, personal data, credentials, restricted financial information, and unapproved external sources.

Write the exclusions down. The agent should never have to infer where a sensitive boundary sits.

5. What may it do without confirmation?

Separate reading, preparing, changing, sending, and transacting. Each action carries a different level of authority.

An agent may read approved records and draft a recommendation while database changes, customer messages, calendar actions, purchases, publications, and deletions still require confirmation. Record those permissions before the first live run.

6. When must it escalate or stop?

Define the signals that require human review: conflicting sources, missing evidence, unusual financial impact, legal or privacy sensitivity, low confidence, an irreversible action, or a request outside the approved workflow.

Name the escalation owner and the safe state. The agent needs to know whom to notify, what evidence to provide, and what must remain unchanged while it waits.

7. What evidence must it leave behind?

Require source links, timestamps, assumptions, confidence, actions taken, exceptions found, and the identity of any approving human.

This evidence trail supports review, correction, and accountability. Fluent output without inspectable evidence can hide weak source authority or an unclear decision path.

8. What ends the run—and what causes revision?

Define the completion condition before the run begins. It might be a completed draft, a reconciled exception list, a prepared recommendation, a confidence threshold, or the first sign that the request exceeds the agent’s authority.

Also define revision triggers. New policy, changed permissions, repeated exceptions, poor evidence quality, or an unexpected consequence should send the workflow back for review. A stopped agent should not leave half-completed external actions or ambiguous ownership behind.

Apply The Checklist To One Workflow

Choose one workflow before choosing an agent. Write down its job, owner, approved and prohibited sources, allowed actions, escalation signals, evidence trail, completion condition, and safe stop state.

If you need help designing the operating layer around an AI workflow, explore FCG’s AI Operating Architecture and Workflow Design services.

5 Comments

  1. The handoff test is what makes this feel real to me. If the next person cannot see which sources governed the work, what the agent changed, and why it stopped, the workflow still depends on someone reconstructing the story. That is usually where adoption gets fragile.

    • That reconstruction problem is also where decision ownership gets blurry. The evidence trail should show what the agent prepared, which human made the commitment, and what would have stopped the action. Without that line, a review can explain the output but still miss who owned the consequence.

    • I see them as complementary. Anthropic's 4Ds—delegation, description, discernment, and diligence—describe the human competencies for working with AI. This checklist turns those competencies into workflow conditions an agent needs before it acts: role, sources, permissions, escalation, evidence, and stop conditions. The 4Ds help a person work well with AI; the checklist helps a team make that work repeatable and reviewable.

      • Dean and Sarah, this connects with something we kept returning to in today’s Mastermind. The individual parts of an AI system can work well while the system still fails in the connections between them. The 4Ds strengthen how the person works with AI. John’s checklist strengthens how the agent works inside the workflow. The real test is what survives between them: intent, source authority, uncertainty, decision ownership, and the ability to stop. That is a connection we are still learning how to design better at FCG.

Leave a Reply