Skip to main content

AI Go-Live Checklist

Use this checklist before moving an agent or workflow into production. Record an owner and evidence link for every applicable item.

Governance

  • Business owner, technical owner, and support owner are assigned.
  • Purpose, users, prohibited uses, and success criteria are documented.
  • The use case has an approved risk classification.
  • Legal, privacy, security, and employee or customer review is complete where required.

Data and Access

  • Data sources have owners and classifications.
  • Public, internal, confidential, and restricted sources are separated.
  • Roles, teams, sharing, and collection access were tested with non-admin users.
  • Retention, deletion, refresh, and offboarding procedures are defined.

Models, Agents, and Tools

  • Provider, model, deployment type, processing location, and preview status are documented.
  • Prompt, skills, memory, tools, and interfaces are reviewed and versioned.
  • Each tool function has an explicit automatic, confirmation, or disabled policy.
  • Provider credentials follow least privilege and have a rotation owner.
  • Public agents have no unnecessary private data, file upload, or write-capable tools.

Testing and Operations

  • Quality, safety, authorization, prompt-injection, tool, and failure tests passed.
  • Approval requests show the exact action and target.
  • Tool Executions, Audit Log, provider logs, and correlation are available.
  • Token, cost, quota, and rate limits are configured.
  • Incident containment, credential rotation, rollback, and escalation were rehearsed.
  • User training, support route, review cadence, and release owner are defined.

The checklist is evidence of review, not proof that a system is risk-free. Reapprove the use case after a material change to audience, data, tools, model, autonomy, or business impact.