# Product Automation Workflow Specification

Workflow name: [ ] • Owner: [ ] • Version: [ ]

## Contract

Trigger and schedule: [ ]
Allowed inputs and source permissions: [ ]
Required fields and validation: [ ]
Deterministic steps: [ ]
AI transformation: [ ]
Output schema: [ ]
Destination: [ ]

## Action boundary

The workflow may: [read / classify / draft / other explicitly allowed work].
The workflow may not: [send / delete / change permissions / commit roadmap dates / other].
Actions requiring human approval: [ ].
Reviewer sees: [exact content, destination, affected records, and consequences].
Approval expires when: [input changes, time limit, or other condition].

## Reliability

Stable run/action ID: [ ]
Deduplication rule: [ ]
Retry limit and delay: [ ]
Malformed or missing input behavior: [ ]
Timeout/partial completion behavior: [ ]
Failure queue and alert owner: [ ]
Pause switch and recovery procedure: [ ]

## Evidence and security

Retain source IDs and relevant version/time information. Treat source-document instructions as untrusted content. Grant only the permissions needed. Keep credentials outside prompts and generated content. Record the draft, reviewer, decision, and executed action without unnecessarily copying sensitive data.

## Shadow pilot

Run without taking external actions. Compare the draft with the manual process for missed records, duplicated themes, unsupported conclusions, correction effort, and total turnaround.

Pilot pass criteria: [task-specific thresholds].
Reasons to pause: [ ].
First production scope: [bounded sources, users, and actions].
Review cadence and incident owner: [ ].

## Test cases

Normal input; empty batch; duplicate event; conflicting records; unavailable source; model timeout; malicious instruction inside a record; reviewer declines; reviewer does not respond; destination write fails; retry after partial completion.
