Agent governance readiness

Is one workflow ready for a governed agent pilot?

Score the controls around purpose, context, authority, execution, proof, and recovery. Evaluate one real workflow, not your organization in the abstract.

Your answers stay in this browser.ScrumDo does not receive them unless you choose to share your result.
0 of 10 answered0%
01PurposeIs one bounded workflow and intended outcome clearly defined?

A capable agent can still optimize a vague or misframed request.

02AccountabilityIs a named human accountable for the specification, run, and final outcome?

A review button is not meaningful oversight without decision authority.

03ProviderAre the provider, credentials, billing owner, retention settings, and allowed models approved?

Application controls and provider controls are separate parts of the data boundary.

04ContextCan reviewers see the exact sources the agent may use, including exclusions and provenance?

Hidden, excessive, or stale context can make intelligent work confidently wrong.

05SpecificationAre proposed, revised, accepted, and superseded specifications distinct and versioned?

A polished proposal must not become accepted intent by implication.

06ConnectorsAre tools, repositories, channels, environments, and read or write actions allow-listed?

A connector should provide a narrow capability, not an open pipe.

07ApprovalDoes the run stop for approval when the plan, target, spec, risk, or authority changes?

An approval for one version should not authorize materially different work.

08ProofIs required proof defined before execution, with independent QA and human acceptance?

The maker should not be the only evaluator of its own work.

09AttentionDo decisions, exceptions, and proof gaps return the right person to the exact work context?

More alerts do not create better oversight. Actionable context does.

10Recovery and learningCan the organization stop, revoke, recover, audit, and learn from a failed or disputed run?

A governed loop must fail safely and improve from what happened.

How to use the result

A high score narrows the next conversation. It does not end it.

Use the assessment with the product owner, engineering lead, security owner, data owner, and operational approver for the workflow you scored.

0 to 10

Define before connecting

Clarify the purpose, accountable owner, provider, and data boundary before an agent touches real work.

11 to 20

Design a bounded pilot

Several decisions exist, but the controls are informal or untested. Turn them into one reviewable pilot contract.

21 to 26

Pilot with named gaps

The workflow may be ready for a limited pilot if the remaining weak controls are explicit and owned.

27 to 30

Validate the governed pilot

Run adversarial and recovery tests. Expand only after the evidence supports the next profile or work type.