Operating, Changing and Retiring a Workflow
Running What Works: Handoff and Operations · 5 min read
Launch is the start of the operating life of a workflow. The model can change underneath it, the policy it supports can be rewritten, the data can shift and the staff who understand it can leave. This lesson covers how to keep a workflow healthy after handoff, how to handle change, and where leaders most often go wrong.
Change control for four levers
Four things alter how an AI workflow behaves: the prompt or instructions, the model, the data it draws on, and the policy it is meant to follow. Each needs a record of who proposed a change, who approved it, what was tested, and when it reached users. Consider Corrin Credit Union, an invented lender whose member-correspondence assistant was handed to a second branch network. The second network's supervisors fixed an awkward sentence in the instructions locally, planning to ask for approval later. Within a month two networks were sending different wording about fees. Local edits followed by retrospective approval look pragmatic and produce divergence. The better pattern is a fast, lightweight request route to the maintainer, with a short turnaround, so that people have no reason to work around it.
Review triggers, not only calendars
A fixed review date catches slow drift. Triggers catch sudden change. Agree in advance the events that force a review of the workflow: a change in the policy or regulation it relies on, a run of repeated errors of the same kind, a vendor model change, a new type of user or input, and any incident. A vendor that updates a model without asking can change outputs on a Tuesday while your last validation dates from March. Treat vendor changes arriving by update as a trigger to re-run your agreed checks before trusting the new behaviour, and ask the vendor how it announces changes. Periodic re-validation on a set schedule then sits behind the triggers as a backstop.
Keep measuring, and say who reads it
Metrics that justified the pilot often lapse once attention moves on. Decide before handoff which few measures continue, who reads them, how often, and what they do when a figure moves. A dashboard nobody is named to read is decoration. Choose measures of outcome, such as error rate in sampled outputs, escalations and rework, over measures of activity such as number of prompts sent. Include cost: usage-based pricing can grow quietly as more teams adopt a workflow, and a rise in spend with no matching rise in benefit is a finding that belongs with the owner.
Logs and records
Keep the logs that let you reconstruct what the system did. Where the EU AI Act applies to a high-risk system, providers must retain automatically generated logs for at least six months under Art. 19, and deployers have the same duty under Art. 26(6). Many systems in a leadership portfolio are not high-risk and are not covered by that duty, so retention there is a business and data-protection decision, not a legal minimum. Either way, someone must be named to decide how long logs are kept and who may read them.
People and knowledge
New joiners should be onboarded to the workflow, not left to copy a colleague: what it is for, what it must not be used for, how to verify output, how to raise an exception. Documentation must survive the original team leaving, which means it is held where the maintainer can edit it, is dated, and records the reasons for decisions as well as the steps. Incidents should feed back: each one should end with a decision on whether the instructions, checks or training change, and the change should go through control.
Expand, consolidate, or retire
When a second team succeeds, the temptation is to add a third. Consolidate first. Confirm the second team runs without the creator, the metrics hold, and the exception route has been used. Widening a workflow that is held together by one person multiplies the dependency. Eventually a workflow may end. Retire it deliberately: stop use, switch off access, and keep the record, meaning decisions, instructions as they stood, test results and relevant logs for the period you have decided or are required to keep. Switching off should not erase the evidence of what was done.
Sustaining the value story
Benefits fade if nobody checks them. Return to the value case at set intervals and ask whether the measured outcome still matches what was claimed, whether the work has changed, and whether the cost has moved. Where the evidence no longer supports the original claim, say so to the sponsor and propose a decision: continue, adjust, or stop. Under Art. 72, providers of high-risk systems must run post-market monitoring across the lifetime of the system; for everyone else, the same discipline is good practice.
As of 24 September 2026.
You can read every lesson without an account. Signing in keeps your place and unlocks the assessment.