Stage purpose
Decide whether the problem, evidence, authority, data, and accountable owner are clear enough to justify a controlled test.
Use-case boundary
AI can correlate telemetry and prepare hypotheses faster than a person can read every signal. It should preserve raw evidence, distinguish correlation from cause, and make the suggested diagnostic path visible to the operator.
Write the specific population, users, systems, source records, proposed AI contribution, human decision, allowed action, and business consequence. State what remains outside the stage. A bounded plan prevents a successful test of one narrow task from becoming an unsupported approval for a broader operating process.
Entry condition
A repeated operating problem has a named owner, affected population, consequence, current workaround, and plausible AI contribution.
Do not waive the entry gate because a tool is already licensed or a provider offers a short implementation window. Existing access can reduce procurement time, but it does not resolve purpose, authority, evidence, ownership, privacy, security, operating fit, or measurement.
Work to complete
- observe the current workflow
- name the decision and nondelegable judgment
- inventory source data and rights
- identify authority and professional owners
- write the initial value and risk hypotheses
Discovery charter scenario
For operations and incident intelligence, select one decision with a known outcome and one unresolved case that represents the edge of the intended scope. Document the people, source systems, records, timing, current work, consequences, and existing controls. Run only the actions allowed at the discovery charter stage, and keep any generated or recommended output outside a broader production decision until the exit gate is met.
The stage owner should be able to explain why this population is representative, which groups or situations are excluded, how a user challenges an output, where a difficult exception goes, and what evidence will support the next decision. If those answers are not yet available, the correct result may be to narrow the stage rather than accelerate it.
Test design
Use representative records and preserve the denominator. Include a normal path, missing information, contradictory evidence, an unusual case, an authorized override, and a changed source, policy, model, or integration. Capture input, version, output, reviewer action, time, error, rework, exception, and downstream consequence for every test case.
Decision questions
- Which telemetry is missing or sampled?
- Can the model change production or only advise?
- How are hypotheses scored and invalidated?
Evidence requirements
- traceable inputs
- reviewable outputs
- human decision record
- measured outcome and failure evidence
Risk and incident controls
- false causal narratives
- alert suppression
- unbounded remediation actions
Name the person who can stop the stage, the event that requires immediate pause, the fallback process, how affected records will be corrected, who must be notified, and what evidence is needed before work can resume. The plan should also address participant feedback and challenge when outputs affect people, customers, partners, investors, or regulated activity.
Measures
| Dimension | Measure | Decision use |
|---|---|---|
| Quality | Correct, incomplete, unsupported, conflicting, and materially wrong outputs | Determine whether review is practical and error is acceptable |
| Work | Cycle time, touch time, rework, exceptions, and support burden | Test the complete operating case rather than generation speed |
| Outcome | Role-specific business result against the baseline and comparison group | Separate activity from value |
| Risk | Incidents, near misses, complaints, overrides, and affected populations | Test whether controls and escalation work |
| Adoption | Correct use, avoidance, workarounds, challenge, and confidence calibration | Understand whether the operating model is usable |
Authority and policy checkpoint
OWASP Top 10 for LLM Applications 2025
Translate common risk categories into application-specific abuse cases and tests.
The authority record does not certify a product, provider, program, or organization and does not determine buyer-specific applicability.
MITRE ATLAS
Connect threat models, security operations, and incident exercises.
The authority record does not certify a product, provider, program, or organization and does not determine buyer-specific applicability.
Official sources for the stage review
OWASP Top 10 for LLM Applications 2025 — OWASP GenAI Security Project. The authority record does not certify a product, provider, program, or organization and does not determine buyer-specific applicability.
MITRE ATLAS — MITRE. The authority record does not certify a product, provider, program, or organization and does not determine buyer-specific applicability.
Exit condition
A bounded charter states what will be tested, what will not be tested, who owns the decision, which records are permitted, and what evidence is still missing.
The exit record should state what was observed, which claims were supported or rejected, which limitations remain, whether the population was representative, who approved the decision, and what evidence could reverse it. Silence or project momentum is not approval.
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.