AI Use-Case Intake & Risk Tiering
Use this intake to decide what to build/ship — and what controls are required before a use case can move from idea → pilot → production. Your risk tier and required actions update as you answer.
Status: Not scored
Coverage: 0%
Score: —
Risk tier: —
Decision: —
Your score
0
out of 45
Answered 0/15
Risk tier
—
Answer the questions to see your risk tier and required controls.
Section A — Use Case & Impact
1) What’s the impact if the system is wrong?
Low Minor inconvenience; no material consequences.
Moderate Operational cost/time; reversible decisions.
High Financial/legal/customer harm likely.
Critical Safety, rights, eligibility, or regulated outcomes.
2) How close is the system to a final decision?
Informational only No decisions; clear disclaimers.
Decision support Human decides; system provides options.
Strong recommendation Humans likely follow the output by default.
Automated action / gatekeeper System triggers actions or approvals.
3) Who is exposed to the output?
Small internal team Controlled access; trained users.
Broad internal Many employees, varying expertise.
Partners / contractors External parties rely on outputs.
Public / customers External users; brand/legal exposure.
4) Is the use case regulated or high-stakes by policy (e.g., finance, health, employment, legal, eligibility)?
No Not in a regulated/high-stakes category.
Adjacent Could influence regulated decisions indirectly.
Yes — controlled Regulated/high-stakes; clear constraints exist.
Yes — direct impact Directly affects regulated outcomes/rights.
5) Is there a clear “do not do” scope boundary for this use case?
No Scope is ambiguous; likely to expand.
Partial Some boundaries, not enforced.
Mostly Boundaries documented and communicated.
Enforced Boundaries enforced in UX/policy/system.
Section B — Data, Privacy & Access
6) What data types will be used or exposed?
Public / non-sensitive No personal or confidential data.
Internal confidential Business confidential, low personal data.
Personal data PII/employee/customer data may appear.
Sensitive personal Health, biometric, minors, legal, etc.
7) Are data sources mapped with ownership, freshness, and access rights?
No Unknown sources/rights; ad-hoc access.
Partial Some sources known; gaps remain.
Mostly Sources mapped; owners identified.
Enforced Access governed; freshness and rights tracked.
8) Are outputs grounded with evidence (citations, document IDs, timestamps) when making factual claims?
No No consistent citations or traceability.
Manual Occasional citations; not enforced.
Mostly Traceability exists for key claims.
Enforced Evidence trails are required and logged.
9) Are permissions least-privilege with periodic review (tools, actions, data access)?
No Broad access; no review cycle.
Partial Some controls; inconsistent reviews.
Mostly Roles defined; access is reviewed sometimes.
Enforced Least-privilege + scheduled reviews + logging.
10) Do you have a retention policy and audit-ready logs (inputs, retrieval, outputs, versions)?
No Cannot reconstruct what happened.
Partial Some logs, incomplete coverage.
Mostly Good logs; exportability varies.
Enforced Structured, exportable logs with retention policy.
Section C — Controls & Shipping Gates
11) Is there a “safe to ship” definition (quality threshold, refusal behaviour, escalation for high-stakes)?
No No thresholds or escalation paths.
Partial Informal expectations; not tested.
Mostly Documented thresholds exist.
Enforced Documented + tested + monitored gates.
12) Are failure paths tested (missing evidence, contradictions, prompt injection, tool failure)?
No No structured negative testing.
Partial Occasional checks; not a suite.
Mostly Common failures tested before ship.
Enforced Regression suite + repeatable evaluation.
13) Is monitoring in place with owners (quality/drift, refusal, latency/cost) and alerting?
No No monitoring or on-call ownership.
Partial Some monitoring; unclear thresholds/owners.
Mostly Monitoring exists; alerting is limited.
Enforced SLOs + alerting + named response owners.
14) Is incident response defined for this use case (triage, rollback/kill, comms, learning loop)?
No No playbook; no authority to pause.
Partial Informal; not rehearsed.
Mostly Documented with escalation paths.
Enforced Practiced; measurable; post-incident reviews.
15) Are change logs and approvals required (prompts, models, tools, data access) before shipping changes?
No Changes are ad-hoc; no approvals.
Partial Some tracking; inconsistent approvals.
Mostly Consistent logs; approvals for major changes.
Enforced Logged + approved + auditable change control.
Tip: Use this before every new use case. If the tier is High/Critical, treat “controls” as prerequisites — not post-launch fixes.
Calculate Results
Copy Results
Email Results
Reset
Required actions (controls before ship)
(function(){
function init(){
const root = document.getElementById(‘oyez-intake-risk’);
if(!root) return false;
if(root.__oyezInit) return true;
root.__oyezInit = true;
const MAX=45, TOTAL=15;
const bar = root.querySelector(‘#oyezIntakeBar’);
const statusEl = root.querySelector(‘#oyezIntakeStatus’);
const coverageEl = root.querySelector(‘#oyezIntakeCoverage’);
const scorePillEl = root.querySelector(‘#oyezIntakeScorePill’);
const tierPillEl = root.querySelector(‘#oyezIntakeTierPill’);
const decisionPillEl = root.querySelector(‘#oyezIntakeDecisionPill’);
const scoreBigEl = root.querySelector(‘#oyezIntakeScoreBig’);
const answeredEl = root.querySelector(‘#oyezIntakeAnswered’);
const tierTopEl = root.querySelector(‘#oyezIntakeTier’);
const tierTopNoteEl = root.querySelector(‘#oyezIntakeTierNote’);
const useCaseEl = root.querySelector(‘#oyezIntakeUseCase’);
const ownerEl = root.querySelector(‘#oyezIntakeOwner’);
const usersEl = root.querySelector(‘#oyezIntakeUsers’);
const jurisEl = root.querySelector(‘#oyezIntakeJurisdiction’);
const calcBtn = root.querySelector(‘#oyezIntakeCalc’);
const copyBtn = root.querySelector(‘#oyezIntakeCopy’);
const emailBtn = root.querySelector(‘#oyezIntakeEmail’);
const resetBtn = root.querySelector(‘#oyezIntakeReset’);
const results = root.querySelector(‘#oyezIntakeResults’);
const tierOut = root.querySelector(‘#oyezIntakeTierOut’);
const tierNoteOut = root.querySelector(‘#oyezIntakeTierNoteOut’);
const decisionOut = root.querySelector(‘#oyezIntakeDecisionOut’);
const decisionDesc = root.querySelector(‘#oyezIntakeDecisionDesc’);
const actionsEl = root.querySelector(‘#oyezIntakeActions’);
function updateSelected(){
root.querySelectorAll(‘.opt’).forEach(opt=>{
const r = opt.querySelector(‘input[type=”radio”]’);
opt.classList.toggle(‘selected’, !!(r && r.checked));
});
}
function answeredCount(){
let n=0;
for(let i=1;i<=TOTAL;i++){
if(root.querySelector(`input[name="q${i}i"]:checked`)) n++;
}
return n;
}
function score(){
let s=0;
for(let i=1;i<=TOTAL;i++){
const picked = root.querySelector(`input[name="q${i}i"]:checked`);
if(picked) s += parseInt(picked.value,10);
}
return s;
}
function riskTierFromScore(s){
// Higher score = better controls / lower risk
if(s <= 15) return 'Critical';
if(s <= 27) return 'High concern';
if(s <= 36) return 'Moderate';
return 'Low';
}
function pack(tier){
const packs = {
'Low': {
note: 'Well-scoped and controlled. Risk is manageable with routine monitoring and change control.',
decision: 'Ship with standard controls',
decisionDesc: 'Proceed to production if you keep evidence trails, monitoring, and change approvals in place.',
actions: [
'Confirm scope boundaries and user training remain current.',
'Keep evidence trails (sources/IDs/timestamps) exportable by default.',
'Monitor drift/refusal/latency with named owners.',
'Require change logs + approvals for prompts/models/tools/data access.'
]
},
'Moderate': {
note: 'Promising, but gaps could produce silent failures or compliance exposure if shipped too fast.',
decision: 'Ship only with mitigations',
decisionDesc: 'You can proceed, but treat the missing controls as prerequisites — not “phase 2”.',
actions: [
'Tighten scope: add explicit “do not do” boundaries and enforce them.',
'Map data sources with ownership, rights, and freshness requirements.',
'Define “safe to ship” thresholds and escalation for high-stakes cases.',
'Add structured, exportable logging (inputs, retrieval, outputs, versions).',
'Run failure-path tests before launch and before major changes.'
]
},
'High concern': {
note: 'High likelihood of material harm, audit failure, or uncontrolled scaling without stronger gates.',
decision: 'Pilot only (no scale)',
decisionDesc: 'Limit access, reduce exposure, and do not scale until ownership, evidence, and incident readiness exist.',
actions: [
'Restrict to a small trained group; avoid external/public exposure.',
'Implement evidence-first grounding: citations/IDs/timestamps on factual claims.',
'Enforce least-privilege access and schedule permission reviews.',
'Create a system-specific incident playbook with authority to pause/rollback.',
'Add monitoring with alerting and named on-call/response owners.',
'Establish change approvals and regression tests for failure paths.'
]
},
'Critical': {
note: 'Not safe to ship in current form. The combination of impact + insufficient controls is unacceptable.',
decision: 'Do not ship (re-design or add strong controls)',
decisionDesc: 'Treat this as a redesign: narrow scope, add enforceable controls, and re-run intake before any rollout.',
actions: [
'Redesign to reduce impact: make it informational-only or require human decision.',
'Remove/avoid sensitive personal data until privacy, rights, and retention are governed.',
'Add enforceable ship gates: refusal behaviour, escalation, and evidence requirements.',
'Implement full audit logging and retention for event reconstruction.',
'Build a repeatable evaluation suite (incl. injection/tool failure/contradictions).',
'Require governance sign-off for regulated/high-stakes categories.'
]
}
};
return packs[tier];
}
function compute(){
updateSelected();
const ans = answeredCount();
const cov = Math.round((ans/TOTAL)*100);
const s = score();
bar.style.width = cov + '%';
statusEl.textContent = ans===0 ? 'Not scored' : (ans{ const li=document.createElement(‘li’); li.textContent=x; actionsEl.appendChild(li); });
results.style.display=’block’;
copyBtn.disabled=false; emailBtn.disabled=false;
return {
ans,cov,s,tier,pack:p,
useCase: (useCaseEl.value||’—’),
owner: (ownerEl.value||’—’),
users: (usersEl.value||’—’),
jurisdiction: (jurisEl.value||’—’)
};
}
function summaryText(state){
const lines=[];
lines.push(‘OYEZ — AI Use-Case Intake & Risk Tiering’);
lines.push(‘————————————–‘);
lines.push(`Use case: ${state.useCase}`);
lines.push(`Business owner: ${state.owner}`);
lines.push(`Users: ${state.users}`);
lines.push(`Jurisdiction: ${state.jurisdiction}`);
lines.push(”);
lines.push(`Status: ${state.ans===TOTAL ? ‘Completed’ : ‘In progress’}`);
lines.push(`Coverage: ${state.cov}% (${state.ans}/${TOTAL})`);
lines.push(`Score: ${state.s}/45`);
lines.push(`Risk tier: ${state.tier}`);
lines.push(`Decision: ${state.pack.decision}`);
lines.push(”);
lines.push(state.pack.note);
lines.push(”);
lines.push(‘Required actions (controls before ship):’);
state.pack.actions.forEach((a,i)=>lines.push(`${i+1}. ${a}`));
return lines.join(‘\n’);
}
root.addEventListener(‘change’, (e)=>{
if(e.target && e.target.matches(‘input[type=”radio”]’)) compute();
});
calcBtn.addEventListener(‘click’, (e)=>{ e.preventDefault(); compute(); });
copyBtn.addEventListener(‘click’, async (e)=>{
e.preventDefault();
const state = compute();
if(!state) return;
const text = summaryText(state);
try{
await navigator.clipboard.writeText(text);
copyBtn.textContent=’Copied’;
setTimeout(()=>copyBtn.textContent=’Copy Results’, 900);
}catch(err){
const ta=document.createElement(‘textarea’);
ta.value=text; document.body.appendChild(ta);
ta.select(); document.execCommand(‘copy’);
document.body.removeChild(ta);
copyBtn.textContent=’Copied’;
setTimeout(()=>copyBtn.textContent=’Copy Results’, 900);
}
});
emailBtn.addEventListener(‘click’, (e)=>{
e.preventDefault();
const state = compute();
if(!state) return;
const subject = encodeURIComponent(`Oyez — Use-Case Intake (${state.tier}, ${state.s}/45)`);
const body = encodeURIComponent(summaryText(state));
window.location.href = `mailto:?subject=${subject}&body=${body}`;
});
resetBtn.addEventListener(‘click’, (e)=>{
e.preventDefault();
root.querySelectorAll(‘input[type=”radio”]’).forEach(r=>r.checked=false);
useCaseEl.value=”; ownerEl.value=”; usersEl.value=”; jurisEl.value=”;
compute();
root.scrollIntoView({behavior:’smooth’, block:’start’});
});
compute();
return true;
}
if(!init()){
let tries=0;
const t=setInterval(()=>{
tries++;
if(init() || tries>=50) clearInterval(t);
}, 100);
}
})();