Practitioner worksheet

AI Agent Governance Checklist

A printable evidence checklist for agent ownership, delegated authority, data handling, action controls, monitoring, containment, and retirement.

By · Published

Use this before a pilot gains write access, external reach, or more sensitive data. Bring the business owner, service operator, and identity/security owner. Mark each item proven, gap, or not applicable with a reason. Keep evidence references in your controlled records; do not write secrets or sensitive prompts here.

Agent / workflow / environment:

Business owner / service owner / review date:

Proposed authority change / affected users:

1. Define the job and the boundary

  • □ Purpose: Name the useful outcome, its non-AI baseline, and the person accountable for accepting it. Record what the agent must never do.
  • □ Reach: List readable data, writable systems, tools, external destinations, delegated agents, and background or queued work. Include authority inherited from connectors.
  • □ Consequence: Record what an incorrect action could change, expose, or make irreversible. Use that consequence to choose reviewers and approval requirements.

2. Prove the controls

  • □ Identity: Identify the agent principal, sponsor, credential lifetime, and permission scope. Demonstrate an allowed action and a denied action in a safe test environment.
  • □ Authorization: Enforce policy at the tool or destination boundary. Verify that an instruction in retrieved content cannot grant new authority.
  • □ Approval: Specify which consequential actions require human approval. Ensure the approver sees the actual target, action, and scope; reapprove when those change.
  • □ Data handling: Document permitted inputs, destinations, retention, and access to evidence. Test the handling of sensitive data without using real secrets.
  • □ Traceability: Reconstruct one run from initiating request through identity, permission decision, tool call, and resulting state change. A model’s narrative is not the evidence.

For each control above, record the test date, result, evidence reference, and owner of any gap. A policy document alone is not a test result.

3. Prove the operating path

  • □ Monitoring: Define actionable quality, cost, and safety thresholds, where alerts go, and the fallback when the service exceeds its boundary.
  • □ Containment: Stop new runs, revoke access, and cancel queued and delegated work. Confirm the last downstream action has ceased; do not rely on the agent to stop itself.
  • □ Retirement: Name who removes identities, credentials, data copies, integrations, and vendor commitments when the purpose or sponsor disappears.

4. Record the release decision

Choose proceed within the tested boundary, repair and retest, or do not grant the requested authority. An unresolved material control gap cannot be averaged away by strong task performance. Record any accepted residual risk with its accountable approver and review date.

Decision / permitted scope / approver:

Open gap / owner / evidence required / due date:

Re-review trigger / next review date:

Repeat the relevant tests when the model, tools, data sensitivity, permissions, destinations, or delegation pattern changes.

Underlying guidance

This worksheet adapts John’s minimum viable AI governance model and six agent identity design tests. Use the incident response worksheet to test what happens when a boundary fails. The detailed articles explain the rationale and link to their primary references.