July 5, 20267 min read

Industry readiness for agents depends on rights, interfaces, consequences, and review

QD

By Equipo Quantum Developers

Four connected cards show a protected document, system connection, damaged package with warning, and human review above an approval gate.
Share

An industry use case is ready for an agent only when it demonstrates sufficient data rights, a controllable integration surface, bounded error consequences, and real review capacity; a specialized prompt cannot compensate for any red dimension. “Healthcare agent,” “banking agent,” or “logistics agent” describes a market, not an operating contract.

Assess the use case, not the industry label

Within one organization, summarizing public documents and approving a sensitive transaction have opposite profiles. Apply the rubric to a specific decision and action with an identified population, sources, systems, and people.

The NIST AI RMF calls for mapping context, risks, affected people, roles, and tolerances before measurement and management. That order prevents excitement about a model from replacing operational analysis.

Dimension one: data rights

Ask who may access, use, transform, retain, and share every source for the proposed purpose. Distinguish proprietary, licensed, public, personal, confidential, and derived data. Record provenance, restrictions, effective period, and deletion mechanism.

State Minimum evidence
Green inventoried sources, permitted use, provenance, and defined retention
Amber partial restrictions or required review before use
Red unknown origin, incompatible purpose, or unproven right

A provider contract is insufficient if the flow mixes attachments, histories, or third-party data outside scope. Do not assume that permission to read means permission to use for training, evaluation, or decision.

Dimension two: integration surface

Map systems read and written, object identity, APIs, files, interfaces, limits, idempotency, sandbox, confirmation, and compensation. A controllable integration has versioned contracts, distinguishable errors, and a way to verify the result.

Green means bounded reads and actions with identity and observability. Amber may be an unstable interface or a write allowed only through review. Red is an action without confirmation, without authority limits, or impossible to reverse where policy requires reversibility.

The existence of a graphical interface does not make integration safe. If a change depends on visual position or variable text, treat that fragility as operational risk.

Dimension three: error consequence

Describe the worst plausible outcome, who bears it, and how it is detected, stopped, corrected, and appealed. Separate content error, omission, delay, disclosure, discrimination, duplicate action, and unauthorized action.

The OECD AI Principles include human-centered values, transparency, robustness, safety, and accountability. In practical assessment, that requires looking beyond average accuracy: an output can be statistically strong while producing an unacceptable consequence for a group or case.

Green corresponds to a reversible proposal with limited harm and detection. Amber requires approval or stronger compensation. Red means severe consequence without effective control; the agent may help prepare evidence but should not execute.

Dimension four: review capacity

Review is operating capacity, not a checkbox. Identify qualified people, volume, calendar, available information, conflict of interest, authority, escalation, and coverage when a reviewer does not respond.

Green means the reviewer understands the decision, receives evidence, and can stop or correct. Amber means queues or skills may not support peaks. Red appears when “human approval” is automatic, late, or impossible to exercise.

Measure disagreement, edits, time to review, expired queues, overrides, and later outcomes. If nobody analyzes those signals, review is labor rather than a learning control.

A decision rule without misleading averages

Do not average one red with three greens. Use this rule:

  • Explore: any red dimension; authorized data only, protected environment, and no real action.
  • Assist: no external action; a person receives sources, reasons, and full control.
  • Act within bounds: all dimensions green for the exact population and action, with policy and rollback.
  • Do not proceed: purpose, right, or consequence cannot be made acceptable.

A state is specific to version and population. Reassess when adding a source, jurisdiction, tool, or action.

Readiness worksheet

Complete for each case:

Question Evidence State Owner Exit condition
May we use every source for this purpose? inventory, contract, applicable assessment G/A/R data/legal restriction resolved
Can we read and act verifiably? integration contract and test G/A/R technology confirmation and rollback
What happens when it fails? consequence and appeal analysis G/A/R risk/operations limit approved
Who reviews on time with evidence? capacity, runbook, and measures G/A/R operations sustainable queue

Add date and version. “Reviewed” without an owner or artifact is not evidence.

Illustrative examples of two profiles

These profiles are illustrative.

Procurement-document classification: the organization has rights over documents, an idempotent queue API, correctable classification, and analysts receiving evidence. It can begin assistive and aim for bounded action for stable classes. Spend approval remains outside scope.

An eligibility decision affecting a person: even with available data and integration, consequence and appeal capacity may be red. An agent might organize documents or check completeness under approved rules; it should not turn that assistance into an autonomous decision.

The difference is not industry. It is the specific combination of rights, surface, consequence, and review.

From readiness to the economic case

Do not calculate benefit over a population excluded by the gates. Define eligible volume after the rubric, include control, review, evaluation, and incident costs, and select an observable operating outcome. ROI that assumes autonomy while the case is ready only for assistance combines two designs.

The UK Government AI Playbook emphasizes accountability, understanding data, lifecycle management, and meaningful human oversight. Readiness is a condition of the economic case rather than a later appendix.

Representing readiness in Quantum

In Quantum Automation Center, a use case can link sources and artifacts, integrations and executions, business objects and outcomes. Permissions define accessible actions; human approval represents review; timelines and logs preserve evidence; the catalog records version and owner. The security and governance documentation connects permissions and traceability.

The rubric should live as a versioned agent artifact and block promotion when a red dimension affects the proposed action.

Counterargument: a conservative rubric can freeze learning

A conservative rubric can block learning and favor trivial cases; red states should block autonomous action, not protected exploration, synthetic tests, or shadowing with exit criteria. Every experiment should attack one uncertainty without exposing the consequence not yet controlled.

Do not turn green into a guarantee. Changes in data, integration, volume, or staffing can degrade the state; define reassessment triggers.

When not to use this rubric

Do not use it as legal advice, regulatory certification, vendor selection, or an ROI calculation. It is an operational-readiness tool that must integrate with specialist assessments.

Do not aggregate an entire industry into one score. Decompose cases and actions. An industry average cannot represent who has rights, what is written, or who can appeal.

The readiness test

Request four pieces of evidence: right and provenance for every source, an integration contract with confirmation, consequence analysis with correction, and a capacity-backed review plan. Then name the maximum permitted action. If the answer relies on the model “knowing the industry,” the use case is not ready.

Sources