Intended use
What deliverable or operating decision does the output support, and what must the automation never decide?
DefinedA useful scope identifies the intended use, source authority, representative test, decision rights, operating responsibility, environment, evidence, and explicit exclusions before a build is proposed.
If the engagement cannot answer them, the workflow is not ready to automate.
What deliverable or operating decision does the output support, and what must the automation never decide?
DefinedWhich systems, files, versions, data classes, and access routes are permitted, and who can authorize them?
NamedWhich representative examples, measures, thresholds, error classes, and reviewer checks determine usability?
MeasuredWho can correct, reject, approve, release, escalate, stop, and change the workflow?
AssignedWho owns access, support, incidents, monitoring, change control, retention, deletion, export, and exit?
RecordedWhich data, systems, roles, decisions, and outcome claims remain outside the engagement?
VisibleThe proposal names the people and qualified roles required for interpretation, review, approval, release, representation, and escalation.
Client-controlled cloud, on-premises, hybrid, and open-source-capable directions can be assessed. The label alone establishes none of the outcomes buyers care about.
Tenancy, hosting, identity, network paths, model/provider use, logs, backups, and data location.
Installation, support, observability, incidents, updates, access review, change control, and exit.
Intended use, testing, security/privacy analysis, validation responsibility, procedures, acceptance, and review.
A controlled workflow can support a regulated process. It does not become compliant, validated, secure, private, or fit for use because of a model name, integration, audit history, or deployment label.
Not by itself. Privacy depends on the complete data flow, access, storage, model use, support, retention, deletion, and incident responsibilities.
No. Applicable requirements, intended use, the complete system, procedures, validation evidence, records, access, operations, and accountable client roles must be assessed.
No. Output is measured against an agreed representative set and reported with denominators, limits, error types, and exceptions. Fitness for use remains engagement-specific.
Yes. AI use is task-specific and requires client permission. A non-AI route can remain available when the material or environment requires it.
Bring the workflow, intended use, source types, reviewer, timing, and environment at a non-confidential level. We will identify the evidence and exclusions before proposing a build.