The diagnostic covers the five readiness areas defined in the playbook. Together they connect responsible experimentation with practical controls, safer agent design and a legitimate path into the organisation.
Foundations and Boundaries
This group covers the ground rules before any agent runs. It is about knowing which information can be used outside official systems, keeping personal experiments fully separate from work tools and accounts, and understanding what your employer actually allows. Get these right and everything built afterwards rests on safe footing.
- Knowing what data is safe to use
- Separating personal experiments from work systems
- Understanding employer AI and acceptable use policy
Knowing what data is safe to use
Not all information can leave official systems. This capability is about telling the difference between data that is fine to feed an agent and data that is confidential, client-owned, regulated, or personal. In a high tech and telecom firm, that line matters because customer records and network details carry real legal weight and obligations.
Separating personal experiments from work systems
This capability is about keeping a hard wall between your personal agent setup and your employer's accounts, devices, networks, and tools. It means no work logins on the laptop, no company files synced across, and no agent reaching into corporate systems. The separation protects both you and the firm if anything goes wrong on the personal side.
Understanding employer AI and acceptable use policy
This capability is about knowing what your employer actually permits when it comes to AI tools, personal devices, and outside experimentation. Policies differ widely and often change quickly. Understanding yours means you can pursue your agent work confidently, stay on the right side of the rules, and avoid an awkward surprise that could damage your standing or your career.
Designing the Agent Team
This group is about building agents that actually work well together. It covers giving each agent a clear job, coordinating how they pass work between them, and choosing the right tools and access for each one. Good design here is the difference between a useful agent team and a confusing, brittle pile of automation.
- Defining a clear role for each agent
- Coordinating how agents hand off work
- Choosing the right tools and access levels
Defining a clear role for each agent
This capability is about giving every agent one well-defined job rather than asking a single agent to do everything. Clear roles make each agent easier to build, test, and trust. When an agent has a narrow purpose, you can tell whether it is doing its job, and the whole team becomes simpler to reason about and improve over time.
Coordinating how agents hand off work
This capability is about how agents pass tasks and information between each other reliably. When one agent finishes and another takes over, the handoff needs to be clean, with the right context carried across. Poor coordination leads to dropped work, repeated effort, and agents talking past each other. Good coordination makes the team feel like one smooth system.
Choosing the right tools and access levels
This capability is about giving each agent exactly the tools and permissions it needs, and nothing more. An agent with too much access is a risk; an agent with too little cannot do its job. Choosing well means each agent can act effectively within tight, sensible limits, which keeps the whole system both useful and safe.
Trust and Human Oversight
This group is about staying in control of what your agents do. It covers checking their output before you rely on it, building in human approval for anything risky, and being ready for the mistakes that agents inevitably make. Oversight is what lets you use agents confidently without being blindsided when they get something wrong.
- Checking agent output before acting on it
- Setting human approval points for risky actions
- Planning for agent mistakes and failures
Checking agent output before acting on it
This capability is about verifying what an agent produces before you treat it as true or act on it. Agents can be confidently wrong, invent facts, or miss the point. Building a habit of checking, especially for anything that feeds a decision or goes to others, protects you from passing on errors. In advisory work, your credibility depends on this.
Setting human approval points for risky actions
This capability is about deciding which actions an agent must never take without a human saying yes first. Sending messages, spending money, deleting things, or anything hard to undo should pause for your approval. Defining these gates keeps you in control of consequences while still letting agents handle the routine work that does not carry real risk.
Planning for agent mistakes and failures
This capability is about expecting agents to fail and being ready when they do. Agents crash, loop, misunderstand, and produce nonsense. Planning means knowing how you will notice a failure, contain the damage, and recover. Without a plan, a single agent error can quietly compound. With one, failures become manageable bumps rather than damaging surprises.
Security and Data Hygiene
This group is about keeping your agent setup secure and clean. It covers protecting the credentials and secrets your agents use, controlling what they are able to reach and do, and choosing safe ways to run them locally or in the cloud. Good security hygiene keeps a powerful agent team from becoming a serious liability.
- Managing credentials and secrets safely
- Controlling what agents can reach and do
- Choosing safe local and cloud setups
Managing credentials and secrets safely
This capability is about protecting the passwords, API keys, and tokens your agents need to work. These secrets are powerful: anyone or anything that gets them can act as you. Storing them safely, never hard-coding them in plain sight, and rotating them when needed keeps your agent team from becoming an open door into systems and accounts.
Controlling what agents can reach and do
This capability is about limiting the surface your agents can touch: which files, networks, services, and actions are within their reach. An agent confined to a small, well-defined space can do its job without becoming dangerous. Controlling reach means that even if an agent misbehaves or is manipulated, the worst it can do stays contained and limited.
Choosing safe local and cloud setups
This capability is about deciding where and how to run your agents safely, whether on your own machine or in the cloud. Each choice has different risks: local setups keep data close but can endanger your device, while cloud setups add convenience but new exposure. Choosing deliberately, with the trade-offs in mind, keeps your whole operation on secure ground.
Bringing It Into the Organisation
This group is about turning your personal practice into something that benefits your firm legitimately. It covers sharing what you learn without exposing sensitive data, making the case for a proper sanctioned environment, and helping others build the same skills. This is how a private experiment becomes a sanctioned capability and stops being a quiet personal risk.
- Sharing patterns without sharing sensitive data
- Making the case for a sanctioned sandbox
- Building agent skills others in the firm can use
Sharing patterns without sharing sensitive data
This capability is about passing on what you have learned, the approaches, designs, and lessons, without ever exposing confidential data or the details of your personal setup. You can share the pattern of how something works while keeping the sensitive substance private. Doing this well lets you contribute openly and build credibility without creating risk for yourself or your firm.
Making the case for a sanctioned sandbox
This capability is about persuading your firm to give you and others a proper, approved environment to do this work in. A sanctioned sandbox replaces risky personal setups with something supported, secure, and blessed by the organisation. Making the case well means framing your experimentation as the valuable, forward-looking activity it is, and showing the firm why supporting it beats ignoring it.
Building agent skills others in the firm can use
This capability is about lifting the people around you, not just yourself. It means sharing your knowledge so colleagues can build their own fluency safely, and helping the firm develop real collective capability. Doing this turns you from a lone experimenter into someone driving the organisation forward, which is both more valuable to the firm and far more rewarding for you.