Home / Blog / AI agent risk checklist
September 7, 2026 Enterprise Agents Commercial
Enterprise AI Agent Risk Checklist: What to Gate Before Production
Enterprises do not stall on model quality first. They stall when an agent can read a mailbox, call a CRM, and “just try” a write with no owner on the exception queue. Map the first agent with Discovery $99 before unsupervised writes land in production.
Map your first agent — Discovery $99
We write the job, the tools, the hottest risk class, the human gate, and who owns exceptions. You decide the next track.
This checklist is the pre-production gate for CIO, CISO, and ops buyers. Product detail lives on autonomous AI agents. The long-form control narrative is AI agent governance for enterprise. Strategy framing sits on AI consulting services. Spend envelopes pair with FinOps consulting.
We will not invent a governance score, a “risk reduced” percentage, or a certification you can print on a slide. The test is operational: can a reviewer see what the agent did, why it stopped, and who was supposed to pick up the thread?
Data risks
What may the agent read, retrieve, or embed? Customer records, tickets, contracts, and chat history are not “context.” They are data with an access and retention rule.
Gate before production — data
- Named corpus: which systems and indexes the agent may retrieve from — unit- or tenant-scoped, not a shared kitchen sink.
- Allow-list of sources; ban on pasting secrets into unmanaged chats or consumer models.
- Retention rule for prompts, tool outputs, and embeddings — who can see them, how long they live.
- PII / customer / regulated handling written in the same language your security team already uses — not a slide that says “enterprise-grade.”
- No cross-business-unit retrieval “for better answers” without an explicit decision and owner.
Failure modes are familiar: a shared retrieval index across units, a prompt that pastes another customer’s thread, a plugin that ships content to a consumer endpoint with no data-processing language. We do not claim a data-loss percentage. We ask whether a reviewer can say which corpus the last step used.
In stricter industries, map to existing control language. Fintech-style identity and ledger patterns: Fintech IT / AI. Do not treat that page as a fake certification — it is industry framing for the same checklist.
Action risks
What may the agent change? Read and draft are usually acceptable on a first agent. Writes to CRM, ERP, identity, payments, or infrastructure are a different class.
Gate before production — actions
- Action matrix: allowed / allowed-with-approval / forbidden — per tool, not per slogan.
- Destructive vs reversible called out. Refunds, provisions, access grants, and customer-facing closures stay behind a human gate until the runbook says otherwise.
- Demo tools disconnected. A connector that was “just for the pilot” is still a production risk if the key lives.
- Least privilege service principal — not a copied admin token from a laptop demo.
- Definition of done for the job. “Help the business with AI” is not a job; “enrich and route L1 tickets of type X” is.
Closing a customer-facing ticket or changing production access without a gate is how you create incidents, not how you prove autonomy. Product language for that boundary is on autonomous AI agents.
Map your first agent — Discovery $99
Job, tools, and irreversible actions on one page.
Spend risks
Every tool call and every retry is a cost event. Agents are chatty by default: they re-read the thread, re-embed the same document, and loop when the job is unclear. A shared API key with no budget is a credit card on the table.
Gate before production — spend
- Per-workflow keys or budgets — not one org-wide key for every pilot.
- Spend envelope with a named person who can pause the job in the same shift.
- Owner tags on model/API and cloud lines so finance can see which workflow burned the budget.
- Kill switch that does not require a vendor ticket to stop a runaway loop.
- Baseline taken when the envelope is set — so usage is measured against something real.
Pair this class with FinOps consulting. We will not invent a savings percentage for “governed agents.” You measure usage against the baseline you take when the envelope is set. A copilot with an untagged key is still an unowned bill.
Audit / ownership
If you cannot reconstruct the last twenty steps, you do not have an enterprise agent. You have a conversation that vanished.
Gate before production — audit
- Step log: who invoked the job, which tools ran, what was retrieved, what was proposed, who approved, why the agent stopped.
- Log stored where your existing review process can read it — incident review, change advisory, or examiner request.
- Replay path for a decision — not a narrative slide after the fact.
Gate before production — ownership (RACI)
- Agent owner (business) — definition of done and exception priority.
- Security — allow-lists, data class, tool privilege review.
- Platform / IT — runtime, keys, kill switch, logging.
- Ops / service desk — queue handoff when the agent stops.
Builders do not silently own production allowlists without security review. Separated duties are part of the checklist, not a later “maturity” phase. Deep control write-up: AI agent governance for enterprise.
For payments, identity, or regulated ledger stacks, keep Fintech IT / AI in the same conversation as pattern language — not as a substitute for the step log. Zion will not print a fake audit certification in place of that log.
HITL defaults
Human-in-the-loop is not a person sitting on every token. It is a gate on the steps that can hurt you. Design the gate the way you would design a change window: default deny on irreversible actions, default allow on reversible preparation.
Default production posture for a first agent
- Intake — read the ticket, email, or form from sources the system of record already allows.
- Classify — type, severity, queue. Escalate when confidence is low or the schema does not match.
- Enrich — attach approved context only.
- Draft — a reply or internal note a human can accept, edit, or reject.
- Route — the right queue or owner. Stop. Do not close. Do not send. Do not write — unless the runbook and the gate say so.
The human is the authority on send, write, refund, provision, and close. You can later move a narrow class of writes behind an automated rule if the definition of done is boring and the blast radius is small. You do not start there.
HITL also needs an exception path faster than the agent. If the only way to stop a runaway job is to open a vendor ticket, you do not have a kill switch. The owner named in Discovery must be able to disable the agent in the same shift the anomaly appears. Isolation is part of HITL: no other tenant’s or unit’s tickets in the same step.
When Discovery shows more than one job, AI consulting is where the action matrix and HITL map get written. Discovery itself stays cheap and narrow on purpose: one agent, one gate, one owner.
Map your first agent — Discovery $99
Controls first: job, tools, gate, owner. Autonomy only where the runbook allows it.
Discovery as the paid map
The commercial path is a first-agent map, not a transformation program.
- Discovery ($99) — 30 minutes on the queue, the system of record, the tool list, and the irreversible actions. Book via Discovery.
- Written follow-up — job, risk class (data / actions / spend / audit), human gate, exception owner, and whether the next track is consulting, a managed agent, FinOps, or stop.
- Build only after the boundary is written — tools, stop rules, step log, kill switch. No unsupervised closures as a default.
Published path chips only: Discovery $99 · Consulting $499 · Starter $2,500 · Growth $8,000/mo · Response within 24h. Starter implements one governed agent end-to-end. Growth operates and iterates under agreed controls. Prices and industry context also sit under solutions — the offer itself is on Discovery and the service landings.
If Discovery shows that you do not have a job — only a desire for “an agent” — we will say so. That is a successful diagnostic. Paying $99 to avoid a six-figure platform with no owner is the point of the offer.
Prefer email? kleber@ziontechgroup.com
Map your first agent — Discovery $99
Controls first: job, tools, gate, owner. Autonomy only where the runbook allows it.
FAQs
What should be on an enterprise AI agent risk checklist before production?
Four risk classes plus HITL and ownership: data (what may be read/retained), actions (what may be written, with an approval matrix), spend (envelopes, tags, kill switch), and audit (step log and replay). Add a named agent owner, security review of allowlists, and a human gate on irreversible steps. Deep read: AI agent governance for enterprise.
When should an agent act without a human?
Only on reversible, low-blast-radius steps that already have a definition of done: classify, enrich, draft, route. Writes to a system of record, production access, refunds, and customer-facing closures stay behind a human-in-the-loop gate until the runbook says otherwise. Default production posture is read + suggest or tightly scoped writes.
Do you need a certification to start gating AI agents?
No. Governance starts with owners, tool scope, spend envelopes, and an audit trail. Zion does not sell a fake SOC 2, ISO, or HIPAA certificate as a substitute for those controls. In regulated stacks we map your existing control language to the agent design — see Fintech IT / AI when payments or identity are in scope.
What does Discovery $99 produce for agent risk?
A first-agent map: the job, the tools, the hottest risk class, the human gate, and who owns exceptions. It is not an implementation and it does not include a promised risk-reduction percentage. Book via Discovery. Next tracks may be AI consulting, FinOps, Starter, or stop.
How do spend risks relate to FinOps?
Model/API quotas, owner tags, and kill switches are FinOps controls applied to agent workloads. Pair the spend class with FinOps consulting. We do not invent savings percentages for governed agents — you measure against the baseline set with the envelope.
See also: Autonomous AI agents · AI agent governance for enterprise · FinOps consulting · AI consulting services · Fintech IT / AI · Solutions · Discovery $99