Checklist · AI Agents
AI Agent Deployment Checklist
Before an agent is allowed to act on real systems, task selection, tool scope, approval gates, caps and the reliability arithmetic that decides whether it will work at all.
About the numbers here. Numbers here are thresholds the checklist proposes, not measurements.
Markdown. No sign-up, no email.
Agent: _______________ Date: _______
1. Is this the right task for an agent?#
- [ ] The task has many steps
- [ ] It has a clear, verifiable success criterion
- [ ] The cost of a mistake is tolerable and correctable
- [ ] The steps vary. If they are always the same, write a script instead
- [ ] It is tedious, high-volume work a person is glad to hand over
Ruled out if any of these are true:
- [ ] There is no clear definition of "done"
- [ ] Actions are irreversible
- [ ] It needs judgement where accountability matters
2. The reliability arithmetic#
| Steps | Success rate at 95% per step |
|---|---|
| 5 | 77% |
| 10 | 60% |
| 20 | 36% |
- [ ] Expected chain length estimated: ______ steps
- [ ] Resulting completion rate acceptable to the business
- [ ] If not: chain shortened, or per-step reliability raised. There is no third option
3. Tools: the most important section#
- [ ] Complete list written down
- [ ] Each tool is specific, not general (
get_customer_orders, neverrun_query) - [ ] Read-only unless writing is genuinely required
- [ ] Each tool reviewed: could it be used for an unintended purpose?
- [ ] Tool chaining assessed. Read + send is an exfiltration path even if neither is dangerous alone
- [ ] No component holds both broad read and broad write access
4. Permissions#
- [ ] Runs with the requesting user's permissions, not a service account
- [ ] Cannot reach systems beyond its declared tools
- [ ] Permission checks happen at the tool, not in the prompt
5. Gates and caps#
- [ ] Human approval before anything destructive
- [ ] Human approval before anything financial
- [ ] Human approval before anything outbound (email, message, publication)
- [ ] Approval cannot be bypassed by rephrasing the task
- [ ] Maximum steps per task. Enforced, verified by triggering it
- [ ] Maximum time per task. Enforced
- [ ] Maximum spend per task. Enforced
6. Observability#
- [ ] Every decision logged: what it chose and why
- [ ] Every tool call logged with actor, arguments, result
- [ ] Full trajectory retrievable for any given run
- [ ] Stored memory / context can be inspected and cleared
- [ ] Incomplete tasks surfaced, never reported as complete
7. Failure behaviour verified#
- [ ] Tool failure → retries sensibly or reports. Does not give up silently
- [ ] Impossible task → stops and says so
- [ ] Ambiguous instruction → asks or states its assumption
- [ ] Interruption → leaves consistent state
8. Security#
- [ ] Goal hijacking tested, hostile instructions in retrieved content
- [ ] Memory poisoning tested
- [ ] Permission boundary tested
- [ ] Findings converted to permanent regression cases
9. Rollout#
- [ ] Read-only first. Proposes actions rather than taking them
- [ ] Run in parallel with the current process before switching
- [ ] Write access added one tool at a time
- [ ] Metrics from day one: completion rate, steps, cost per completed task, failure behaviour
10. Ownership#
- [ ] Named owner accountable for its behaviour
- [ ] Named person who can switch it off
- [ ] Written statement of what it does and does not decide
- [ ] AI disclosure in place where it interacts with people (EU AI Act Art. 50, in force since 2 Aug 2026)
Sign-off#
| Name | Date | |
|---|---|---|
| Built by | ||
| Security review | ||
| Approved to act on production systems by |