AI workflow governance checklist
Use this checklist before any AI agent is allowed to work with live business tools.
1. Name the workflow and business owner
Write the workflow in one sentence: "This agent helps [person or team] by preparing [specific output] from [approved sources] so a human can [decision or action]." Then name the owner who can approve, review, and pause the workflow.
2. List the data sources the agent can use
Name the approved sources: CRM fields, call notes, templates, website pages, knowledge-base articles, spreadsheets, reports, procedures, or public pages. Mark sensitive sources clearly and avoid broad access when a narrow source will do.
3. Define read, draft, update, send, publish, and delete permissions
Separate every permission. Read-only access is not edit access. Drafting a message is not sending it. Preparing a website recommendation is not publishing it. Deleting, overwriting, pricing, legal, privacy, and customer-facing actions should start as human-approved or blocked. For a deeper permission-level map, use the AI Agent Permissions Checklist.
4. Set the human approval gate
Define where the agent stops. The reviewer should know what they are checking: accuracy, source quality, privacy risk, tone, claims, customer context, and commercial fit. For more examples, read AI Approval Gates for Business Automation.
5. Write the exception and escalation path
A useful agent should know when not to continue. Escalate when sources conflict, private data appears, the request is outside scope, output quality is weak, or the action would affect trust.
6. Log decisions and review early outputs
Record what the agent prepared, what the human approved or changed, which exceptions appeared, and whether the output saved review time. Early logs are how the workflow improves safely.