Start with consequence
An AI workflow should be designed around the consequence of a wrong, delayed, or unauthorized output - not around what a model can demonstrate.
Classify decisions by reversibility and materiality. Use that classification to decide where validation, human approval, and escalation belong.
Make the boundaries observable
Define permitted data, identities, tools, output schemas, approval states, and retention. Instrument those boundaries so operators can see when behavior leaves the expected path.
Recovery is part of the feature
Version prompts and policies, preserve decision context, record corrections, and plan how the workflow degrades safely when a model, integration, or source is unavailable.
