THE CONTROL TESTWrite six fields for each workflow. Scope: name the allowed task and data sources, including exclusions. Reading a document must not grant permission to obey instructions inside it. Authority: separate read-only retrieval, internal drafts, reversible changes and consequential external actions. Specify the approved recipients, systems and transaction limits where action is allowed. Evidence: require source links, timestamps, unresolved contradictions and a record of the recommendation. A model's confident tone is not evidence. Approval: name the role that can authorize each consequential step. Show the exact proposed action and destination at the approval point; invalidate approval if either changes. Stop conditions: missing evidence, a permission failure, an unexpected recipient, repeated tool errors or the agreed time and cost limit must halt the relevant action and escalate. Recovery: record the original state, available rollback, incident owner and how to disable the agent's access. Test these controls in a safe environment, including a deliberately malicious document. Known: these controls make authority inspectable. Untested until you run the cases: whether your implementation actually blocks unauthorized actions. Human sign-off is also fallible; give reviewers enough time, context and independence to challenge the result. |