04
Use · AI scoping

Scope AI safely

“Where can an agent act, and where must it not?”

An agent can only act on what is explicit. Cross the AI lens with sensitivity and workflows and you get a defensible order of automation — safe, well-mapped steps first, restricted ground fenced off.

How to run it
  1. Pick a workflow whose steps are already mapped.
  2. Mark each step's data sensitivity and criticality.
  3. Automate the low-risk steps; gate the rest with a human.
What you're looking for

Repetitive, low-sensitivity steps ready to delegate — and restricted or Tier-1 steps that must keep a human in the loop.

The decision

A phased automation plan with guardrails drawn from real classifications, not guesses.

A worked example

Take account provisioning. The create-ticket and notify-manager steps are low-sensitivity and repetitive, safe to automate. The grant-access-to-restricted-systems step is Tier-1 and highly classified, so it keeps a human approver. The model draws that line for you.

Try it: open the catalog By AI view →
Open it in the model: By AI + Workflows →
← All uses
← Prioritize risk & continuity Improve the experience →