7.5 A first week that is small enough to finish
If the ten ways still feel abstract, use this sequence for one week on one process:
Day 1. Write the outcome in one sentence and the exclusions in five. What must not happen even if the system is clever?
Day 2. Map the current path from request to result. No agents yet — people, systems, delays.
Day 3. Give a system read-only access to inspect or summarize — preferably through an MCP server or equivalent scoped tool, not a shared admin credential in the prompt. Require a written evidence package. No writes.
Day 4. Add one reversible action in a test environment. Define who must approve before anything touches production. If you can, put that deny-by-default in a host policy or ACS-style manifest, not only in a system-prompt paragraph.
Day 5. Run one real case end to end. Save the failure if there is one — as a row in an eval dataset, not only as a Slack link. Change one part of the environment — a SKILL.md, a permission, a test, or a handoff — and run it again.
Day 6–7. Hand the operating notes to somebody else, including the trace_id or workflow id for the successful run.
That is enough to begin with. What follows is the same sequence run once, by one person, on something small enough to finish.