PromptBase
Upgrade
Close icon
General
Home
Marketplace
Create
Hire
Login
Chat
Sell
Explore

Prompt Details

Model
Chat - (gpt-5.6)
Token size
1,177
Example input
[WORKFLOW]: An internal product-marketing assistant drafts first versions of frequently asked questions from approved public product documentation. Ten marketing employees use the workflow. Every draft must be reviewed before publication. [AUTONOMY]: The AI summarizes approved source material and drafts FAQ text. It cannot publish content, send messages, modify source documents, make customer commitments, or perform external actions. A product marketer reviews, edits, approves, and publishes every draft. [DATA_SYSTEMS]: The workflow uses public product documentation stored in an approved knowledge folder. The AI has read-only access. It does not process customer data, employee data, credentials, confidential records, or payment information. It has no API access, write permissions, system credentials, or external integrations. [FAILURES]: Potential failures include inaccurate feature statements, omitted product limitations, unsupported claims, incomplete answers, and inconsistent brand tone. These errors could confuse prospective customers or create misleading marketing content, but mandatory review should normally identify them before publication. The affected parties are prospective customers, marketing employees, and the company. [CONTROLS]: Human review and approval are mandatory before publication. Generated answers must cite their approved sources. Twenty representative test cases passed factual-review checks, although two required minor wording corrections. Drafts and approval decisions are logged. The workflow is currently operating as a limited internal pilot. Formal monitoring thresholds, periodic regression testing, and documented incident procedures have not been specified
Example output
# AI Workflow Risk Triage ## 1. Executive Decision * **Final tier:** Moderate * **Base score:** 6/24 * **Confidence:** Medium * **Status:** Provisional * **Disposition:** Controlled pilot only **Brief rationale:** The workflow has a narrow, low-privilege boundary: it uses public approved documentation, has read-only access, performs no external actions, and requires human review before publication. These controls materially limit data, autonomy, and reversibility risks. The Moderate tier is driven primarily by incomplete operational controls. Monitoring thresholds, periodic regression testing, incident procedures, and documented rollback conditions have not been specified. Confidence is Medium because several control-enforcement details are unknown, including whether the review gate is technically enforced, how source changes are governed, and how published errors would be withdrawn. No risk floor raises the result above the Moderate base band. --- ## 2. Workflow Boundary ### Intended business outcome Produce first drafts of frequently asked questions from approved public product documentation, reducing drafting effort for ten internal marketing employees. ### AI responsibilities * Retrieve or use material from the approved knowledge folder. * Summarize approved public product documentation. * Draft FAQ answers. * Cite the approved sources used. ### Human responsibilities * Review every generated draft. * Check factual accuracy, limitations, unsupported claims, completeness, and brand tone. * Edit the draft where necessary. * Approve or reject the draft. * Publish approved content. * Retain accountability for the final published statement. ### Systems and data **Verified facts:** * Public product documentation in an approved knowledge folder. * Read-only AI access. * No customer data, employee data, credentials, confidential records, or payment information. * Drafts and approval decisions are logged. * No API access, system credentials, write permissions, or external integrations. ### Actions the AI may perform * Read approved source material. * Summarize that material. * Generate draft FAQ text. * Produce source citations. ### Actions that must remain human-controlled * Editing authoritative source documents. * Final factual and marketing review. * Approval or rejection. * Publication. * External communication. * Customer commitments. * Changes to system access or workflow configuration. ### Deployment stage Limited internal pilot. ### Scope ambiguities and unknowns * **Unknown:** Whether mandatory review is technically enforced or only procedurally required. * **Unknown:** Whether users can copy and publish unapproved text outside the intended workflow. * **Unknown:** Who can add, modify, or approve documents in the knowledge folder. * **Unknown:** How obsolete or superseded documentation is identified. * **Unknown:** Whether citations are checked automatically, manually, or both. * **Unknown:** Model, hosting, retention, and prompt-logging configuration. * **Unknown:** Time required and authority needed to withdraw incorrect published content. * **Unknown:** Whether the workflow scope will remain limited to public documentation and FAQ drafting. No assumption that these controls exist has been made. --- ## 3. Risk Scorecard | Dimension | Score | Evidence | Rationale | Main gap | | ---------------------------------------------- | -------: | ------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------- | | 1. Business and decision impact | 1 | FAQ drafts may influence prospective customers; publication requires marketer approval. | Incorrect statements could mislead customers or create unsupported marketing claims, but the AI does not make final decisions or publish directly. | No defined severity classification for factual or marketing errors. | | 2. Data sensitivity and privacy | 0 | Only public product documentation is used; no personal, confidential, credential, or payment data is processed. | Exposure is low within the stated scope. | Data-boundary enforcement and model-retention configuration are unverified. | | 3. Autonomy, permissions, and external actions | 0 | Read-only access; no APIs, credentials, write access, external integrations, messaging, publication, or commitments. | The AI has no meaningful action authority and cannot directly create external consequences. | Technical verification of permissions and continued scope restriction is missing. | | 4. Failure severity and reversibility | 1 | Known failure modes include inaccurate statements, omissions, unsupported claims, and incomplete answers. Human review occurs before publication. | Most errors should be reversible during review. A missed error could affect public marketing content, but no irreversible action is described. | No documented withdrawal, correction, or rollback process for published errors. | | 5. Security, misuse, and prompt injection | 1 | Sources are restricted to an approved folder and the AI has no tools or external actions. | Prompt injection or manipulated source content would have limited direct impact, but could still distort drafts or citations. | No evidence of source-content validation, instruction isolation, abuse testing, or access review. | | 6. Human oversight and accountability | 0 | Every draft requires product-marketer review, editing, approval, and publication; approval decisions are logged. | Human oversight is direct, mandatory, and positioned before external impact. | Enforcement mechanism, reviewer criteria, and exception handling are not documented. | | 7. Testing, evaluation, and evidence | 1 | Twenty representative cases passed factual review; two required minor wording corrections. | Initial evidence is positive but limited. It does not establish performance across product changes, difficult cases, omissions, or adversarial inputs. | No acceptance thresholds, coverage analysis, regression suite, or recurring evaluation schedule. | | 8. Monitoring, incident response, and rollback | 2 | Draft and approval logs exist. Formal thresholds, regression testing, incident procedures, and rollback arrangements are unspecified. | Logging provides traceability, but operational detection, escalation, correction, and recovery controls are incomplete. | No defined metrics, alert thresholds, incident owner, response procedure, or tested rollback. | | **Total** | **6/24** | | **Base band: Moderate** | | ### Fact, assumption, and evidence separation **Verified:** Limited pilot, mandatory review, source citations, public data only, read-only access, no integrations or external actions, twenty factual-review tests, logging of drafts and approvals. **Prudent assumptions used only for interpretation:** A published FAQ can probably be edited or removed, but this has not been counted as a verified rollback control. **Missing evidence:** Technical enforcement of review, permission configuration, source governance, test coverage, monitoring thresholds, incident handling, retention settings, and rollback testing. --- ## 4. Risk-Floor Review | Floor | Result | Explanation | Effect on final tier | | -------------------------------------------------------------- | ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | | A. Autonomous high-impact actions | **Does not apply** | The AI cannot transfer funds, delete authoritative records, change access rights, make binding commitments, or approve or reject people. | None. | | B. Sensitive data combined with risky access or communications | **Does not apply** | The stated workflow uses public documentation and has no external communication, write access, credentials, or integrations. | None. | | C. High-impact regulated or essential-service decisions | **Does not apply** | The workflow drafts marketing FAQs and does not materially determine employment, credit, insurance, healthcare, legal rights, physical safety, or essential-service access. | None. | | D. Tool-using agent with absent or unknown action safeguards | **Does not apply** | The AI has no tool-calling authority, APIs, external integrations, write permissions, or action capabilities. | None. If tools or external actions are added, this floor must be reassessed. | | E. Critical facts unknown | **Applies** | Enforcement of mandatory review, source-folder governance, data-retention settings, access verification, and correction or rollback capability are not evidenced. | Does not raise the tier by itself. It lowers confidence to Medium and makes the result Provisional. | The tier could rise to **High** if evidence shows that review can be bypassed, untrusted content can enter the approved source set without control, sensitive data is introduced, external actions are added, or deployment expands without monitoring and rollback controls. --- ## 5. Five Priority Gaps ### Gap 1: Mandatory review is not shown to be technically enforced * **Risk created:** Unreviewed or rejected content could be published or reused. * **Why it matters:** Human review is the principal control reducing factual and marketing harm. * **Minimum control:** Enforce a distinct draft state and require recorded human approval before content can enter the publishing path. Restrict publishing permissions to authorized humans. * **Accountable role:** Workflow owner and publishing-process owner. * **Evidence needed:** Workflow configuration, permission records, approval-state logic, and a test demonstrating that an unapproved draft cannot be published through the intended process. ### Gap 2: Evaluation coverage and acceptance criteria are incomplete * **Risk created:** The twenty cases may not reveal omission, outdated-source, unsupported-claim, citation, edge-case, or product-limitation failures. * **Why it matters:** Passing a small test set does not establish consistent performance as documentation or prompts change. * **Minimum control:** Define measurable acceptance thresholds and expand testing to include feature limitations, ambiguous questions, unsupported requests, conflicting documents, obsolete sources, citation accuracy, and refusal to speculate. * **Accountable role:** Product marketing quality owner with workflow or model evaluation support. * **Evidence needed:** Versioned test set, expected answers, scoring rubric, test results, failure analysis, and approval of release thresholds. ### Gap 3: No formal monitoring thresholds * **Risk created:** Declining factual accuracy, citation quality, reviewer correction rates, or source freshness may go unnoticed. * **Why it matters:** Logs alone do not identify when intervention or suspension is required. * **Minimum control:** Track a small set of operational measures, such as material correction rate, unsupported-claim rate, citation-error rate, approval rejection rate, and incidents reaching publication. Define investigation and pause thresholds. * **Accountable role:** Workflow owner. * **Evidence needed:** Metric definitions, baseline results, thresholds, review cadence, and records showing that exceptions are investigated. ### Gap 4: Incident response and rollback are undocumented * **Risk created:** Incorrect published claims may remain visible or be corrected inconsistently. * **Why it matters:** Marketing inaccuracies can affect customer understanding and company credibility even when the initial drafting process is low risk. * **Minimum control:** Document how to report, assess, remove or correct affected content, preserve evidence, identify related drafts, and suspend the workflow when necessary. * **Accountable role:** Business content owner and workflow owner. * **Evidence needed:** Incident procedure, escalation contacts by role, correction log, suspension criteria, and one tabletop or rollback test. ### Gap 5: Approved-source governance is unclear * **Risk created:** Outdated, conflicting, manipulated, or incorrectly approved documentation could produce systematically inaccurate FAQs. * **Why it matters:** Source quality is a dependency of every generated answer. Human review may not detect plausible but outdated statements. * **Minimum control:** Limit who can modify the approved folder, identify authoritative versions, remove superseded material, record source ownership, and define how conflicting documents are handled. * **Accountable role:** Product-documentation owner and access-control owner. * **Evidence needed:** Folder permissions, source inventory, version or freshness metadata, approval records, and a documented conflict-resolution rule. --- ## 6. Minimum Safe Next Steps ### Before further testing 1. Freeze the pilot boundary to public approved product documentation, read-only retrieval, FAQ drafting, source citation, and mandatory human publication. 2. Record the actual permissions granted to the AI, users, and source-folder maintainers. 3. Define factual-review criteria covering: * Accurate feature statements. * Product limitations. * Unsupported claims. * Completeness. * Citation correctness. * Brand tone. 4. Preserve the current twenty cases as a versioned regression baseline, including the two wording corrections. 5. Add cases for conflicting sources, stale documents, missing answers, ambiguous questions, attempts to induce speculation, and text in sources that resembles instructions. 6. Define what constitutes a minor correction, material error, test failure, and release-blocking defect. ### Before deployment beyond the controlled pilot 1. Demonstrate that the intended publishing process cannot accept an unapproved draft. 2. Establish measurable evaluation gates and obtain documented approval from the responsible business and technical roles. 3. Verify least-privilege access and confirm that no external integrations, credentials, or write capabilities have been introduced. 4. Establish source ownership, version control or equivalent freshness tracking, and removal of superseded documents. 5. Define monitoring metrics and thresholds, including conditions requiring investigation, suspension, or rollback. 6. Document incident reporting, escalation, correction, and workflow-disable procedures. 7. Test rollback by: * Disabling generation. * Removing access to the knowledge folder. * Identifying affected drafts from logs. * Correcting or withdrawing a simulated published error. 8. Confirm log retention, access, integrity, and review responsibilities. 9. Reassess risk before any expansion to confidential data, automated publication, external messaging, APIs, or customer commitments. ### During operation 1. Continue recording drafts, sources, reviewer decisions, material edits, and publication outcomes. 2. Review a defined sample of approved and rejected drafts for factual accuracy and omission patterns. 3. Run the regression suite after model, prompt, retrieval, documentation, permission, or workflow changes. 4. Monitor correction and rejection trends against documented thresholds. 5. Record incidents and near misses, including errors caught before publication. 6. Escalate repeated or material failures to the accountable business and technical roles. 7. Suspend the workflow when: * Mandatory review cannot be assured. * Source integrity is uncertain. * Material unsupported claims repeatedly occur. * Logs are unavailable. * A change introduces unassessed permissions, data, or external actions. 8. Restore service only after the triggering issue is corrected, evidence is retained, and relevant regression checks pass. --- ## 7. Evidence Requests ### Required now * **Required now:** Current AI permission and access configuration. * **Required now:** Confirmation of the exact data sources available to the AI. * **Required now:** Description of how mandatory review and approval operate. * **Required now:** The twenty test cases, expected outcomes, review criteria, and recorded results. * **Required now:** Samples showing draft, citation, reviewer edit, approval, and publication records. * **Required now:** Confirmation of whether model prompts, outputs, and retrieved content are retained by any provider. ### Required before pilot continuation * **Required before pilot:** Named accountable roles for business ownership, technical operation, source ownership, and incident escalation. * **Required before pilot:** Source-folder permission records and authorized-maintainer list. * **Required before pilot:** Definition of authoritative, current, and superseded documentation. * **Required before pilot:** Evidence that the intended publishing path requires approval. * **Required before pilot:** Defined material-error and pilot-suspension criteria. * **Required before pilot:** Expanded evaluation results for omissions, limitations, conflicting sources, stale sources, citation failures, and instruction-like source text. ### Required before broader deployment * **Required before deployment:** Approved evaluation thresholds and release-gate results. * **Required before deployment:** Versioned regression-testing procedure. * **Required before deployment:** Monitoring metrics, baselines, thresholds, and review cadence. * **Required before deployment:** Incident response and content-correction procedure. * **Required before deployment:** Tested workflow-disable and rollback evidence. * **Required before deployment:** Log-retention, access-control, and integrity configuration. * **Required before deployment:** Formal confirmation that the workflow scope has not expanded to sensitive data, automated actions, or external integrations. ### Required during operation * **Required during operation:** Periodic regression-test results. * **Required during operation:** Reviewer correction, rejection, citation-error, and unsupported-claim metrics. * **Required during operation:** Records of incidents, near misses, escalation, correction, and closure. * **Required during operation:** Source-change and stale-document review records. * **Required during operation:** Access and permission review records. * **Required during operation:** Evidence of reassessment after material model, prompt, data, integration, or workflow changes. --- ## 8. Recommended Specialist Review ### Primary next review: Observability and SLO design This review should come next because the largest scored weakness is not excessive autonomy or sensitive-data exposure; it is the absence of measurable operational detection and response controls. The review should define a proportionate set of quality and safety indicators, including material factual-error rate, reviewer correction rate, unsupported-claim rate, citation validity, rejection rate, source freshness, and incidents reaching publication. It should also establish thresholds for investigation, suspension, and recovery. ### Dependent secondary review: Control-evidence audit After the monitoring, approval, incident, and rollback controls are documented, a focused control-evidence review should verify that they are actually configured and operating. It should not be treated as a substitute for implementing the missing controls. --- ## 9. Limitations ### Supported conclusions The following conclusions are supported by the supplied facts: * The workflow currently has limited autonomy. * It has no stated external-action, write, credential, or integration capability. * It uses public documentation rather than sensitive records. * Mandatory human review materially reduces the likelihood that draft errors reach publication. * Initial factual testing provides some evidence of usefulness but is not sufficient for broader assurance. * Monitoring, incident response, regression testing, and rollback controls are incomplete or unspecified. ### Provisional conclusions The Moderate tier and Controlled pilot only disposition depend on the stated boundaries remaining accurate. They are provisional because technical evidence of permission restrictions, review enforcement, source governance, log configuration, and rollback capability was not supplied. ### This triage does not establish * Legal or regulatory compliance. * Certification. * Security assurance or penetration-test results. * Absence of all privacy or intellectual-property risk. * Model safety. * Production readiness. * Effectiveness of controls not supported by evidence. * Authorization to deploy or expand the workflow. * Accuracy of any individual FAQ. * Suitability for use with confidential data or autonomous actions. ### Final accountability Final accountability for testing, control implementation, risk acceptance, publication decisions, and deployment remains with the organization’s designated business owner, technical owner, content approver, and authorized deployment decision-maker. It does not transfer to the AI system or to this triage assessment.
🤖 GPT

Workflow Risk Checklist

Add to Library
Instant accessInstant access
Usage rightsCommercial use
By downloading this prompt, you agree to our terms of service
GPT-5.6
Tested icon
Guide icon
4 examples icon
Screen an AI workflow before pilot or deployment. Scores impact, data sensitivity, autonomy, reversibility, security exposure, human oversight, evidence, and monitoring; flags critical risk floors, top control gaps, missing evidence, and the next specialist review. For AI consultants, product teams, and automation agencies.
...more
Added 4 days ago
Report
Browse Marketplace