Set permission boundaries before scaling
A checklist for keeping AI experiments inside clear access, approval, and rollback boundaries.
Source: Rookmint-authored AI safety guide
Start with the smallest useful access
Map the exact data and action a workflow needs before connecting a tool. Read-only access, limited fields, and a separate test path make it easier to understand what the workflow can actually reach.
Name approval points
Customer-facing changes, high-impact decisions, and access changes need an accountable human owner. Write down who can approve the action and what evidence they should check first.
- Avoid shared credentials and broad default roles.
- Separate drafting permission from send or publish permission.
- Keep a short record of access changes and review dates.
Prepare the way back
A rollback plan should say how to disable the trigger, revoke access, find pending work, and return to the existing process. If nobody can perform those steps, the experiment is not ready to scale.
Keep going
Turn the guidance into a next step
Keep the first move narrow, reviewable, and owned by someone who can pause it.