Outcome
When you finish this checklist, your first Role Assistant pilot has certified integrations, operator Make available, optional channel delivery, and traced user provisioning — with clear ownership between integrator and platform admin.
Prerequisites
- At least one certified external system pair in scope (for example CRM + document library)
- From integrations to Role Assistant phases understood
- Platform admin access for Role Assistants and channels
- Integrator access for validate, upload, and certification commands
Where it happens
| Role | Primary surfaces |
|---|---|
| Integrator | Certification and connected-system readiness |
| Platform admin | Admin portal — Role Assistants, Make available / unavailable, channels |
| End user | Conversation, Work when a richer review is needed |
| Operator | Certification visibility, Assistants evidence review, Why explanations |
Integrator checklist
Complete before asking admin to activate a role:
| Step | Done when |
|---|---|
| Model business information | Business metadata, boundaries, and governed capabilities are ready for the pilot |
| Link records | Foreign keys connect documents to CRM entities where required |
| Validate and test | Green validate, integration test, and E2E for in-scope datasources |
| Publish and certify | Connected-system scope is validated and approved for the pilot |
| AI trust | Business descriptions and trust status support the intended Role Assistant |
| Protection | Required business boundaries are in place |
| Drift control | Current connected-system scope matches the approved pilot |
| Role Assistant package | Settings and Evidence promoted for the pilot environment (upload --env) — Manage Role Assistant packages |
Detailed commands: Certification and Agent metadata and trust.
Admin checklist
Complete before end-user provisioning:
| Step | Done when |
|---|---|
| Review certification | Operations, trust, and governance pillars green for pilot scope |
| Make available | Target Role Assistant is Active (not sticky Draft) — see Role Assistant status and availability |
| Role mapping | Active role boundaries match certified capabilities — no manual capability grants at user layer |
| Channels (if used) | Teams or Slack connected per tenant policy — see Connect assistant channels; integrators use Deliver assistant channels |
| Approver roster | Document approval or other human gates staffed when corpus requires review |
| Pilot comms | Users know assistant name is their only configuration choice after provisioning |
| Conversation and Work | Users begin with a business objective in conversation; Work supports plan review, Ask or Approval tasks, activity, Review Workspace decisions, and the business result when work completes |
| Business result honesty | Completed, failed, denied, expired, waiting, and safely stopped outcomes remain readable in Work and Assistants — see Business value from work steps |
Defaults and examples
| Pilot artifact | Owner | Example evidence |
|---|---|---|
| Certification summary | Integrator | Current certification for the business systems in scope |
| Scoped governance subject | Integrator + security | A business user with the intended role |
| Make available | Admin | Sales Manager assistant Active — users see Sales Assistant |
| Conversation-first work | End user | Business objective begins in a channel; Work opens only for a richer review |
Validate
Admin: Confirm the appropriate Role Assistant appears for a test user and that configured channels satisfy tenant policy.
Operator: Review certification, Assistants evidence, and Why explanations before expanding pilot use.
End user: Start a business objective in conversation. Use Work only when plan review, an Ask or Approval, activity detail, or a Review Workspace decision is needed.
Common mistakes
| Mistake | Fix |
|---|---|
| Admin activates role before certification | Confirm certified scope before Make available |
| Treat LLM provider publish as assistant activation | LLM publish regenerates governed LLM access only — Role Assistant status stays Draft until Make available |
| Users pick capabilities at activation | The active role defines governed scope |
| Treat Work as the daily destination | Begin in conversation; open Work only for focused operational review |
| Treat Ask answers as certified Evidence | Ask supports the current task; Evidence requires capture → validate → certify |
| Treat Approval as integration certification | Approval certifies a proposed business change; integration pillars still prove Connected System readiness |
| Treat skill promotion as more permissions | Skill growth does not expand Operational Trust scope |
| Channel connected but role not activated | Make available first so the Role Assistant is Active |
Limits
Channel behavior and Review Workspace detail vary by deployment generation. Confirm current channel prerequisites with your platform operator before production traffic.
Certification proves declared scope — not unlimited production guarantee. Re-run the ladder when vendor APIs, dimensions, or protection manifests change.