Access to context
Define the identities and roles that need access to each source, record and model input. Test both permitted access and denied requests.

Put access, authority and accountability at the center of an operational design.
Before connecting a source or enabling an action, define who can see the information, who can change it and how a decision will be reviewed.
Define the identities and roles that need access to each source, record and model input. Test both permitted access and denied requests.
Identify which changes require approval and who can authorize them. Define how actions are scoped, acknowledged, retried and stopped.
Connect source information, evaluation, operator decisions and system responses. Set requirements for retention and inspection.
Define who needs which information, for what task and for how long. Consider how access changes when roles or responsibilities change.
Keep the source and age of information visible when evaluating a decision. Distinguish observations from assumptions and derived conclusions.
Separate the ability to inspect information from authority to approve or execute a change. Define ownership and escalation before enabling an action.