The Eight Agentic Workflow Control Surfaces Methodology v1.1

A modular diagnostic grammar for AI-mediated workflows

Agentic Workflow Control Surfaces are the auditable boundaries, checkpoints, and responsibility layers that determine whether an AI-agent workflow can be governed before execution, reconstructed after execution, and repaired after failure.

A control surface is not limited to technical permissions. It may be informational, operational, financial, legal, clinical, procedural, evidentiary, or reliance-based. Any point where AI output can change behavior, authority, responsibility, or risk is a potential surface.

The complete surface map

Surface Governing question Common failure signature
Objective Did the agent preserve the assigned objective? Task substitution or unauthorized expansion
Scope Did the agent stay within its permitted surface? Advice crosses into execution or commitment
State / Source of Truth What authoritative state governed the action? Stale, inferred, or generated state becomes authoritative
Verification Did verification prove the work that mattered? Green checks while the obligation remains unmet
Stop Condition When should the agent have stopped? Continuation through uncertainty or missing authority
Evidence Can preserved records establish the trajectory? Logs show events but not authority, state, or verification
Handoff / Reliance Who or what relied on the output? Generated content enters a decision or institutional record
Recovery What repair path existed after failure? System shutdown without correction or user-level repair

Why use surfaces instead of a single score?

A total score can hide the material gap that controls a decision. Strong logging does not compensate for an absent stop condition. A reconstructable incident does not prove the workflow was adequately governed. A mature policy does not prove a specific event can be reconstructed.

The current determination model therefore answers material questions individually and reports each as established, limited, contradicted, or not established. It identifies blocking gaps and their decision consequences without collapsing them into an aggregate readiness label.

Can the surfaces be adopted independently?

Yes. A team may need only a source-of-truth binding review, false-green completion exposure test, stop-condition assessment, evidence sufficiency register, handoff review, or recovery-readiness assessment. The relevant unit is the decision the evidence must improve, not the amount of framework installed.

Minimum viable review

A minimum review asks:

  1. What was the agent supposed to do?
  2. What was it allowed to touch, say, change, or commit?
  3. What source of truth governed the action?
  4. What proved the action or output was valid?
  5. When did the workflow have to stop?
  6. What evidence remains?
  7. Who or what could rely on the output?
  8. What recovery path existed?

If a material question cannot be answered, the review records the gap and its consequence rather than inferring readiness.

Evidence Control Surface — The control surface that defines which records must remain to reconstruct an AI-agent workflow, its authority, verification, reliance, and recovery.

Handoff and Reliance Control Surface — The control surface that governs how AI-agent output moves into another actor, workflow stage, decision, institutional record, or real-world action.

Objective Control Surface — The control surface that defines what an AI agent is supposed to accomplish and separates the authorized task from adjacent or self-authorized work.

Recovery Control Surface — The control surface that defines how an AI-agent workflow detects, reverses, repairs, escalates, compensates, or safely exits after error or harm.

Scope Control Surface — The control surface that defines what an AI agent may touch, change, influence, represent, advise, or commit.

State and Source-of-Truth Control Surface — The control surface that distinguishes authoritative state from stale context, model memory, generated assumptions, incomplete retrieval, or hallucinated references.

Stop-Condition Control Surface — The control surface that defines when an AI agent must suspend action, request direction, escalate, or refuse to proceed.

Verification Control Surface — The control surface that defines what must be checked before an AI-agent action or output can be treated as complete, correct, safe, or usable.