SPROUTSAI ENTERPRISE AGENT PILOT CHECKLIST Public field guide ยท August 2026 1. OUTCOME [ ] Name one repeatable workflow and its accountable business owner. [ ] Define the trigger, accepted outcome, volume, baseline cycle time, and cost. [ ] Define what must remain a human decision. 2. CONTEXT AND DATA [ ] Inventory authoritative systems, records, documents, events, and owners. [ ] Map user, group, object, record, field, and regional access boundaries. [ ] Decide what is indexed, embedded, cached, queried live, logged, and retained. [ ] Record source freshness, conflicts, deletion, and data-exit requirements. 3. MODEL AND AGENT THREATS [ ] Approve model providers, routes, regions, retention, and restricted uses. [ ] Test direct and indirect prompt injection and poisoned context. [ ] Separate memory read and write authorization. [ ] Keep credentials outside model context and delegate narrow scopes. 4. ACTION SAFETY [ ] Define tool, object, field, destination, rate, and transaction limits. [ ] Re-authorize consequential actions at execution time. [ ] Test idempotency, preconditions, partial failure, reconciliation, and compensation. [ ] Provide pause, revoke, disable, escalation, and incident paths. 5. EVALUATION [ ] Create representative, adversarial, policy, and failure-path test sets. [ ] Measure accepted outcomes, edits, citations, exceptions, latency, and cost. [ ] Run shadow mode before enabling writes. [ ] Record release gates and who approves each autonomy increase. 6. OPERATIONS AND VALUE [ ] Name service owners, review queues, support paths, and change control. [ ] Exercise an incident and recovery path; define RTO and RPO targets. [ ] Measure sustained adoption and full operating cost. [ ] Expand only when value, quality, control, and operator trust meet the charter. This checklist is a planning aid, not a certification, legal opinion, or assurance report.