Workflow name: [ ] • Owner: [ ] • Version: [ ]
Contract
Trigger and schedule: [ ]
Allowed inputs and source permissions: [ ]
Required fields and validation: [ ]
Deterministic steps: [ ]
AI transformation: [ ]
Output schema: [ ]
Destination: [ ]
Action boundary
The workflow may: [read / classify / draft / other explicitly allowed work].
The workflow may not: [send / delete / change permissions / commit roadmap dates / other].
Actions requiring human approval: [ ].
Reviewer sees: [exact content, destination, affected records, and consequences].
Approval expires when: [input changes, time limit, or other condition].
Reliability
Stable run/action ID: [ ]
Deduplication rule: [ ]
Retry limit and delay: [ ]
Malformed or missing input behavior: [ ]
Timeout/partial completion behavior: [ ]
Failure queue and alert owner: [ ]
Pause switch and recovery procedure: [ ]
Evidence and security
Retain source IDs and relevant version/time information. Treat source-document instructions as untrusted content. Grant only the permissions needed. Keep credentials outside prompts and generated content. Record the draft, reviewer, decision, and executed action without unnecessarily copying sensitive data.
Shadow pilot
Run without taking external actions. Compare the draft with the manual process for missed records, duplicated themes, unsupported conclusions, correction effort, and total turnaround.
Pilot pass criteria: [task-specific thresholds].
Reasons to pause: [ ].
First production scope: [bounded sources, users, and actions].
Review cadence and incident owner: [ ].
Test cases
Normal input; empty batch; duplicate event; conflicting records; unavailable source; model timeout; malicious instruction inside a record; reviewer declines; reviewer does not respond; destination write fails; retry after partial completion.