What should be assessed before building an AI agent?
The safest first agent is usually narrow, frequent, valuable, and easy to review. Use these checkpoints before implementation.
1. Workflow frequency and commercial value
Start with recurring work, not novelty. Good candidates include reporting, sales follow-up preparation, CRM hygiene, content refreshes, website checks, inbox triage, knowledge answers, and management summaries.
2. Data readiness and source-of-truth quality
AI agents need reliable context. A useful assessment names trusted sources: CRM records, approved offers, website pages, SOPs, knowledge bases, calendars, spreadsheets, and previous decisions. It should also flag sensitive data. Use the AI Data Readiness Checklist for NZ Businesses when this checkpoint needs a deeper source-of-truth review.
3. Tool access, permissions, and integration risk
The assessment should identify which tools the workflow touches and what access the agent might need. Read-only access is lower risk than permission to edit records, send messages, publish pages, or change settings. Permissions should be minimal.
4. Human approval points and escalation rules
Every workflow needs a clear stop sign. Sales messages, customer commitments, pricing, public publishing, sensitive records, legal copy, privacy decisions, and high-risk system changes should stay behind human approval.
Business.govt.nz guidance on safe and smart AI use highlights privacy, cybersecurity, transparency, and data sovereignty. In an assessment, those concerns become workflow questions: what can the agent access, prepare, approve, and log?
5. Measurement: how to know if the agent is working
Do not measure success only by output volume. Measure whether the workflow becomes more reliable: cleaner CRM records, fewer missed follow-ups, faster summaries, consistent website maintenance, or fewer handoff gaps.