Governed Workflows: The Eight Stages That Make a Method Repeatable
Many AI policies read as if risk enters when an employee opens a tool. It enters when an output moves to the next stage of work.
A summary becomes a recommendation. A draft becomes a client communication. A classification changes how someone is treated. A prompt library cannot carry an operating model. It records an instruction, not which source was approved, what the output must contain, how failure is detected, or who may change the method.
This post takes the governance decision from the operating model and makes it concrete: the eight stages that turn a private technique into a workflow the organisation can inspect, reproduce, challenge and stop.
The eight stages
A governed workflow is a sequence, not a policy. Each stage does a specific job, and each one can be tested on its own.
- Trigger. When the process starts, defined explicitly, so informal use is not the default route.
- Approved inputs. Which documents, data classes and versions may be used.
- AI task. Narrow enough to test. A broad instruction cannot be evaluated; a specific one can.
- Deterministic checks. The requirements that must never vary, encoded as rules rather than left to the model.
- Human review. Resolves ambiguity, judges quality, and owns the decision.
- Final output. Released through the normal channel, never straight from the model.
- Measurement. Captures the full effect, including correction and review, not just the headline time saved.
- Review cycle. Asks whether the source, model, control or workflow needs to change.
Boards and approval forums are weakest when the work they govern is invisible. If every user combines different inputs, prompts and review habits, central oversight receives a description of the use case rather than evidence of how it operates. Governance has to alter the sequence before it produces an output.
A prompt can standardise an instruction. Only a workflow can standardise responsibility.
Controls follow consequence
Controls are engineered to the consequence of the output, not copied from a checklist. The same eight stages carry different weight depending on what the output can do.
- Internal ideation. Approved tool, non-sensitive inputs, and a clear rule that nothing is published without review.
- Recurring content workflow. Documented sources, a maintained instruction, named reviewers, version control, and sampled output quality.
- Client treatment, personal data, significant decisions. Formal testing against the process it replaces, traceable approvals, monitoring, escalation and a viable manual fallback. Where automated evaluation has significant effects, the impact assessment is a living document, not a one-off sign-off.
The checklist scales with what the output can do. A low-consequence task carries light controls precisely because a poor suggestion is discarded on the spot. A consequential task carries heavy controls because the efficiency would otherwise rest on removing the very thing that made it acceptable.
Security is engineered into the sequence
Hallucination, prompt injection, data leakage and manipulated inputs are not managed by user awareness. They are managed by the workflow: input filtering, access restrictions, response validation and incident routes, engineered in rather than trained around.
This matters because an intelligent interface can conceal an ordinary operational failure. The cross-government Copilot trial found the tool inherited each user's permissions and exposed underlying access and knowledge-management weaknesses. AI does not make untidy information more reliable. If access is wrong before the model arrives, it is wrong after. Building the controls into the sequence, rather than relying on people to remember them, is what closes that gap.
Two worked examples
The stages are easier to see in practice. Both of these use AI. Their controls differ because the outputs carry different consequences.
Content repurposing. The approved input is the signed-off source. AI produces channel drafts. Rules check that mandatory statements and links survived. A marketer verifies meaning, tone and fit. Corrections feed back into the workflow when the same failure recurs.
Pre-checking a client communication. AI compares a draft with guidance and flags passages, citing the source and separating rule from interpretation. Uncertainty routes to a qualified reviewer. The absence of a flag never implies approval.
The common requirement is ownership. Someone can explain the purpose, inputs, method, reviewers, failure routes and current version. That is the practical difference between a workflow the organisation owns and a technique that lives in one person's chat history.
Why the sequence is the point
A governed workflow is one the organisation can inspect, reproduce, challenge and stop. Those four verbs are not achievable through a policy binder. They are properties of a sequence where approved inputs, checks, a reviewer with authority and an escalation route are in place before the output has consequences.
This is also what makes a method transferable. When the workflow holds the responsibility rather than the individual, a second team can run it, a new starter can learn it, and the team can update it when tools or requirements change. That is the move from personal productivity to something the organisation owns, which we set out in activity is not capability. Choosing which tasks deserve this treatment in the first place is covered in where AI earns its place.
To see the full set of stages and worked examples, download the full field note. If you have a workflow you want governed before it scales, send us the use case and we will tell you plainly whether it is ready.