AI Go-Live Checklist
Use this checklist before moving an agent or workflow into production. Record an owner and evidence link for every applicable item.
Governance
- Business owner, technical owner, and support owner are assigned.
- Purpose, users, prohibited uses, and success criteria are documented.
- The use case has an approved risk classification.
- Legal, privacy, security, and employee or customer review is complete where required.
Data and Access
- Data sources have owners and classifications.
- Public, internal, confidential, and restricted sources are separated.
- Roles, teams, sharing, and collection access were tested with non-admin users.
- Retention, deletion, refresh, and offboarding procedures are defined.
Models, Agents, and Tools
- Provider, model, deployment type, processing location, and preview status are documented.
- Prompt, skills, memory, tools, and interfaces are reviewed and versioned.
- Each tool function has an explicit automatic, confirmation, or disabled policy.
- Provider credentials follow least privilege and have a rotation owner.
- Public agents have no unnecessary private data, file upload, or write-capable tools.
Testing and Operations
- Quality, safety, authorization, prompt-injection, tool, and failure tests passed.
- Approval requests show the exact action and target.
- Tool Executions, Audit Log, provider logs, and correlation are available.
- Token, cost, quota, and rate limits are configured.
- Incident containment, credential rotation, rollback, and escalation were rehearsed.
- User training, support route, review cadence, and release owner are defined.
The checklist is evidence of review, not proof that a system is risk-free. Reapprove the use case after a material change to audience, data, tools, model, autonomy, or business impact.