The Eight Agentic Workflow Control Surfaces Methodology v1.1
A modular diagnostic grammar for AI-mediated workflows
A control surface is not limited to technical permissions. It may be informational, operational, financial, legal, clinical, procedural, evidentiary, or reliance-based. Any point where AI output can change behavior, authority, responsibility, or risk is a potential surface.
The complete surface map
| Surface | Governing question | Common failure signature |
|---|---|---|
| Objective | Did the agent preserve the assigned objective? | Task substitution or unauthorized expansion |
| Scope | Did the agent stay within its permitted surface? | Advice crosses into execution or commitment |
| State / Source of Truth | What authoritative state governed the action? | Stale, inferred, or generated state becomes authoritative |
| Verification | Did verification prove the work that mattered? | Green checks while the obligation remains unmet |
| Stop Condition | When should the agent have stopped? | Continuation through uncertainty or missing authority |
| Evidence | Can preserved records establish the trajectory? | Logs show events but not authority, state, or verification |
| Handoff / Reliance | Who or what relied on the output? | Generated content enters a decision or institutional record |
| Recovery | What repair path existed after failure? | System shutdown without correction or user-level repair |
Why use surfaces instead of a single score?
A total score can hide the material gap that controls a decision. Strong logging does not compensate for an absent stop condition. A reconstructable incident does not prove the workflow was adequately governed. A mature policy does not prove a specific event can be reconstructed.
The current determination model therefore answers material questions individually and reports each as established, limited, contradicted, or not established. It identifies blocking gaps and their decision consequences without collapsing them into an aggregate readiness label.
Can the surfaces be adopted independently?
Yes. A team may need only a source-of-truth binding review, false-green completion exposure test, stop-condition assessment, evidence sufficiency register, handoff review, or recovery-readiness assessment. The relevant unit is the decision the evidence must improve, not the amount of framework installed.
Minimum viable review
A minimum review asks:
- What was the agent supposed to do?
- What was it allowed to touch, say, change, or commit?
- What source of truth governed the action?
- What proved the action or output was valid?
- When did the workflow have to stop?
- What evidence remains?
- Who or what could rely on the output?
- What recovery path existed?
If a material question cannot be answered, the review records the gap and its consequence rather than inferring readiness.
Evidence Control Surface — The control surface that defines which records must remain to reconstruct an AI-agent workflow, its authority, verification, reliance, and recovery.
Handoff and Reliance Control Surface — The control surface that governs how AI-agent output moves into another actor, workflow stage, decision, institutional record, or real-world action.
Objective Control Surface — The control surface that defines what an AI agent is supposed to accomplish and separates the authorized task from adjacent or self-authorized work.
Recovery Control Surface — The control surface that defines how an AI-agent workflow detects, reverses, repairs, escalates, compensates, or safely exits after error or harm.
Scope Control Surface — The control surface that defines what an AI agent may touch, change, influence, represent, advise, or commit.
State and Source-of-Truth Control Surface — The control surface that distinguishes authoritative state from stale context, model memory, generated assumptions, incomplete retrieval, or hallucinated references.
Stop-Condition Control Surface — The control surface that defines when an AI agent must suspend action, request direction, escalate, or refuse to proceed.
Verification Control Surface — The control surface that defines what must be checked before an AI-agent action or output can be treated as complete, correct, safe, or usable.