# AI Control Layer workbook

Open Technology · Reviewed 2026-09-13 · Version 2
Companion: https://www.opentechnologyblog.com/learn/ai-control-layer
Fill in with synthetic or sanitized details. Do not include credentials or private customer records.

## 1. Task brief

- Outcome and audience:
- Sources and versions:
- Data needed / data excluded:
- Minimum app role / external access:
- Allowed tools and actions:
- Acceptance check:
- Reviewer and required approval:
- Failure, recovery and cleanup:

## 2. Build and documentation trace

- README and setup entry:
- Agent instruction source and generated output:
- Canonical proposal/work ID:
- Actual approval evidence:
- Source revision:
- Implemented in source:
- Tests run and limitations:
- Deployment / flags / provider evidence:
- Planned or unavailable:
- Generated-doc command and coverage:
- Public claim affected:

## 3. Evaluation record

| Case | Expected | Observed | Evidence | Follow-up |
|---|---|---|---|---|
| Normal task | | | | |
| Missing input | | | | |
| Restricted/foreign-project request | | | | |
| Untrusted document instruction | | | | |
| Provider failure | | | | |
| Repeated request (if actions exist) | | | | |

## 4. Open-source pilot

- Tool, version, component license and source:
- Benefit being tested:
- Operating owner and time budget:
- Workflow result:
- Access restriction verified:
- Export and restore result:
- Maintenance and total operating effort:
- Limitations / support requirement:
- Exit plan and test artifact cleanup:
- Adopt / defer / reject, with reason:

## 5. AI or company-integration news brief

- Primary announcement and documentation:
- Publisher / publication date / event date / checked date:
- Product, version, region and plan:
- Announced / preview / generally available / retired:
- Company-reported claim versus independently checked fact:
- Data flows and permissions affected:
- Testable user impact:
- Uncertainty and opposing evidence:
- App proposal mapping (if implementation is needed):
- Reviewer / correction and recheck trigger:

## 6. Close the loop

- Corrections made:
- Canonical docs updated:
- Tests repeated after change:
- Temporary artifacts removed / credentials revoked:
- Next review trigger:

Documentation guides work. Executable permissions govern actions. A completed workbook does not grant access or approve a release.

## 7. Practice pack

- Summary exercise: https://www.opentechnologyblog.com/blog/review-ai-summaries-with-missing-data
- Evaluation cases: https://www.opentechnologyblog.com/downloads/ai-control-evaluation-cases.json
- Code exercise: https://www.opentechnologyblog.com/blog/tests-that-catch-ai-code-mistakes
- Input preparation: https://www.opentechnologyblog.com/blog/minimize-data-for-ai-writing
- Proposal handoff: https://www.opentechnologyblog.com/blog/verified-findings-to-ai-proposals

Send only a case's input to an approved tool. Keep expected/criticalFailures for the reviewer. These are synthetic exercises, not recorded model results. Record exact input, tool/version, output, reviewer, pass/fail/blocked/not-run and critical failures separately. Chat-only scope tests do not verify server authorization.
