Do this first: complete the pilot card
User and job:
When [role] needs to [make a recurring decision]...
Approved sources:
[List the smallest source set needed]
Excluded data:
[Sensitive fields and systems this pilot cannot use]
Visible proof:
[The brief, checklist, status, or comparison another person can review]
Human approval:
[Named role that checks consequential output]
Stop rule:
[Missing source, uncertainty, restricted data, or hard case that returns the work to a person]1. Name one handover risk
- Choose one repeated decision or request.
- Name one accountable owner.
- Record the current time, sources opened, and review effort.
2. Approve the source set
- Label each source authoritative, contextual, or restricted.
- Link to the system of record instead of copying everything.
- Add a version or review date to every active source.
3. Set the AI boundary
- Define what AI may read, draft, compare, or flag.
- Exclude beneficiary, safeguarding, employment, and confidential donor data unless an authorized owner approves the use.
- Write the uncertainty or missing-access condition that stops the workflow.
4. Build a reviewable artifact
- Show purpose, sources, owner, decisions, access level, and next review date.
- Require a source link for factual claims.
- Send unresolved questions to a named person.
5. Test and decide
- Run one normal case and one hard case.
- Ask a newer colleague to retrieve five known answers.
- Expand only if the workflow saves time without reducing care.
30-day review standard
| Measure | Evidence |
|---|---|
| Retrieval time | A newer owner finds five verified answers faster than the baseline. |
| Source coverage | Every active record has a source, owner, access label, and review date. |
| Reviewer trust | Unsupported claims are caught before external use. |
| Safety | Restricted data stays outside the workflow; target: zero incidents. |