Article chapter 01 of 08
Begin with the consequence of a wrong answer
Trace one plausible wrong answer into the next step of the workflow. A prototype usually concentrates on the path where the request is understood, the source is available and the output looks plausible. Now follow what happens when somebody acts on the output, a system changes state, or a customer sees information they trust.
Choose one supported task and follow an incorrect result forward. Record who receives it, what they might do, how the error could be noticed, and which records would need correction. If the output is a draft that a trained person approves, the immediate consequence may be limited. If it changes an account, sends a message or updates another system, recovery becomes more involved.
Write the workflow as a sequence of states rather than a description of the interface. A useful sequence includes the initial request, source retrieval, model output, validation, approval, action, confirmation and any later amendment. Name the system responsible for each state. Check for gaps such as an action recorded as complete before the receiving system confirms it.
Classify wrong outcomes by their operational effect. Some can be corrected in the same screen. Others create duplicated work, disclose information, deny access, trigger a financial adjustment or leave two systems in disagreement. Use categories clear enough to determine approval, logging and recovery requirements; an elaborate scoring formula is optional.
For each supported task, capture:
- the action a person or system may take from the output;
- the worst credible wrong outcome inside the release boundary;
- who is likely to detect it and how quickly;
- the records needed to investigate it;
- whether the action can be reversed;
- who has authority to correct it;
- the condition that should stop further processing.
The answers may narrow the first release. A workflow can support read-only research before it is allowed to update records. It can prepare an action for approval while tool execution remains disabled. Set the scope around controls the team can operate on launch day.