Verification is not optional
A consequential action should not be marked complete merely because AI generated instructions or a tool returned success text. Preserve evidence that the intended bounded result actually happened.
Audit without oversharing
Audit policy should record workflow, policy, permission, confirmation, action, verification, errors, corrections and owner without copying unnecessary sensitive data or secrets.
Correction is normal
Wrong output, source, overclaim or workflow state should create a correction event. Update current truth while preserving provenance of what happened.
Kill switches can be narrow
A risk in one workflow need not destroy every safe capability. Disable the narrow workflow, tool, memory access, model/provider or public feature needed to contain the risk, then define restart evidence.
Fallback must be real
Human handoff, qualified professional, emergency route or support channel must not be promised unless it actually exists for that workflow. If unavailable, say unavailable and offer only the bounded alternative that really exists.
Reflection
Questions to sit with
- What evidence verifies this action?
- What exact capability should stop if it fails?
- Is the promised fallback actually available?