- Data boundary
- Which fields the workflow can see, which stay masked, and which never leave your systems at all. This decision sets what the workflow is allowed to be, so it is taken first.
- Access model
- Who can run it, who reviews the output, who approves an exception, and who can read the log. Named roles rather than a shared login.
- Human review Kept human
- Which outputs need a person to approve them before they reach a client, an account or a financial decision, and what that person is expected to check.
- Deployment route
- A governed pilot, a private tenant, or a dedicated environment. The workflow is identical in all three. The isolation and the cost are what change.
- Audit trail
- Inputs, sources, outputs, approvals and exceptions, logged from the first pilot rather than added when somebody asks for them.
- Escalation path
- What happens when the output is uncertain, incomplete, sensitive or outside policy. A workflow with no escalation path escalates to whoever notices.
What counts as working. Accepted output against your own baseline is
the proof, and it is the one number your finance, IT and compliance owners can all argue
with. The baseline gets taken before the build exists, and afterwards the workflow is
measured against it with review burden and rework counted openly, because a system that
produces plenty and needs checking twice has saved nothing. Usage, prompt counts and
enthusiasm are signals. How we measure AI work sets
out the method.