Inside the institution
Employee tools, internal agents, approved uses, information access, reviewers and escalation.
The question: Which work is delegated and who remains accountable?
Agent Readiness · Scoped engagement
A customer can bring an assistant. A vendor can add AI to an existing product. An employee can use a new tool. Review the institution’s responsibilities across all three surfaces.
Public discovery, identity and permission are separate design questions.
Three surfaces. Named responsibilities.
Employee tools, internal agents, approved uses, information access, reviewers and escalation.
The question: Which work is delegated and who remains accountable?
Embedded AI features, subcontractors, model changes, data rights and the evidence your agreement requires.
The question: How does a vendor’s AI change the service or risk you accepted?
Assistants acting for customers or members, explicit delegated scopes, limits, verification and revocation.
The question: What establishes the customer’s intent and authority for this action?
Public information discovery
Use clear public pages, descriptive links, current facts and consistent service information. Check crawl access, canonical URLs, structured content and the sitemap.
Define a review owner for product terms and public updates. Test a set of discovery questions and keep the answers’ sources visible.
Google’s published guidance retains established SEO practices for AI search. No special AI markup guarantees inclusion or ranking. Read the official guidance ↗
A public page can help an assistant understand the institution. Account access, personal data retrieval and transactions require separate identity, consent, permissions and controls.
A machine-readable description or agent identifier does not replace those controls.
NIST AI risk framework ↗Deliverables to agree
Inventory relevant internal tools, vendor capabilities and proposed delegated interactions.
Distinguish reading public information, accessing private data and changing an account or transaction.
Name the principal, permissions, duration, limits, review, revocation and escalation.
Define attributable events and the evidence needed for ownership, review and response.
Before we begin
Login evidence alone may not establish who initiated a later action or what was delegated. A design must capture the relevant principal, authority and attributable events rather than infer permission from a browser or identifier.
An interface can expose capabilities. Authentication, authorization, data handling, human review and operational ownership still need an explicit design. Protocol choice follows the use case.
Evaluate specific interactions, existing obligations and measurable outcomes. The review can identify changes to public information, vendor questions or bounded capabilities while retaining the institution’s current services.
Vendor Compare is a working browser tool. The other service pages describe scoped engagements. Live Conversation Companion and Idle Cash Opportunity remain development concepts in our product planning until implementation is verified.
One owner. One useful outcome.
Describe the internal tool, vendor feature or customer interaction. We will define the questions, owners and evidence for a useful review.
Scope, fee, delivery, hosting and data permissions are agreed before work begins. Use your first inquiry to describe the need; agree an authorized route before sharing confidential material.