Skip to content

30-point checklist

Revenue AI data readiness checklist

Revenue AI data is ready for governed action when the organization can name its sources of truth, resolve identities, define required fields, prove freshness, enforce permissions, trace lineage, monitor quality and recover safely. This checklist turns those requirements into evidence a GTM, data and IT team can review before widening agent permissions.

Start working with agents Try the demo

Readiness model

Prove seven foundations before granting action rights

The checklist is a deployment gate, not a generic data-cleaning project. Apply it to one bounded workflow and the exact records, fields and decisions that workflow needs.

NIST organizes AI risk work across govern, map, measure and manage, including documented roles, production monitoring, incident response and recovery. This practical GTM checklist uses the same lifecycle logic without claiming that a completed worksheet proves compliance.

Sources:NIST AI Risk Management FrameworkNIST AI RMF Core

  1. 01

    Source

    Name the authoritative system and accountable owner.

  2. 02

    Resolve

    Match people, accounts, opportunities and activities reliably.

  3. 03

    Define

    Document fields, stages, statuses and required values.

  4. 04

    Protect

    Constrain data and actions by role, policy and purpose.

  5. 05

    Observe

    Measure freshness, completeness, exceptions and evidence.

  6. 06

    Recover

    Stop, reverse or escalate work when a prerequisite fails.

Source map

Start with the records the workflow actually touches

For every input and output, record the system of record, object or table, business owner, technical owner, refresh expectation, permitted use and downstream write. A workflow is not ready when two systems can both be “right” without a documented precedence rule.

Use caseEvidenceOwner questionFailure to test
Source of truthNamed system, object and fieldWho resolves conflicts?Two sources disagree
IdentityMatching key and survivorship ruleWho owns duplicates?One person or account appears twice
DefinitionBusiness meaning and valid valuesWho approves a definition change?Stage or status is used inconsistently
FreshnessExpected latency and last-updated signalWho responds to staleness?The feed stops or arrives late
PermissionAllowed roles, fields and actionsWho grants and reviews access?A restricted field enters context
LineageSource references and transformation recordWho can explain the output?A reviewer challenges the evidence

30 checks

Review the checklist in five evidence groups

Mark each item ready only when an owner and evidence link are present. “Usually true” is not deployment evidence.

  • Sources and identity: authoritative records, identifiers, duplicates, survivorship and relationship rules.
  • Definitions and completeness: field meaning, valid values, required fields, historical coverage and exception handling.
  • Freshness and lineage: update expectations, health signals, transformation history, evidence references and retention.
  • Permissions and governance: least privilege, purpose limits, approval gates, sensitive fields and review cadence.
  • Monitoring and recovery: quality metrics, alerts, fallbacks, rollback, incident ownership and change control.

Scoring rubric

Score evidence, not confidence

Use 0 for missing, 1 for informal or unverified, and 2 for documented and tested. The maximum is 60 points. Treat any failed critical gate—source of truth, permission boundary, approval rule or recovery path—as a stop condition regardless of total score.

Use caseInterpretationNext actionPermission posture
0–29: Not readyFoundations are missing or implicit.Fix ownership and critical gates.No production action rights.
30–47: Pilot-readyEvidence exists but gaps remain.Run read-only or approval-gated tests.Bounded scope with mandatory review.
48–60: Ready to validateMost controls are documented and tested.Validate under production-like conditions.Widen only after measured review.

Next-step plan

Turn the lowest evidence group into a 30-day repair plan

Do not repair the entire data estate before proving one workflow. Prioritize the missing evidence that can change an agent decision or prevent safe recovery.

  1. Days 1–10

    Map and assign

    Confirm sources, definitions, permissions and named owners for the selected workflow.

  2. Days 11–20

    Test and observe

    Run representative records through freshness, completeness, identity and evidence tests.

  3. Days 21–30

    Gate and rehearse

    Test approval, fallback, rollback and incident paths before granting wider action rights.

Downloadable template

Take the checklist into your readiness review.

The downloadable worksheet includes all 30 checks, scoring fields, evidence links, owners, critical-gate markers and a source-map template.

Download the 30-point checklist

Frequently asked questions

No. The score organizes readiness evidence for one workflow. Production safety also depends on testing, evaluation, permission enforcement, human review and ongoing monitoring.
No. Scope the pilot to the records and fields the selected workflow actually needs. Critical inputs and action boundaries must be reliable; unrelated data debt can stay outside the pilot.
Ownership is shared. RevOps defines business meaning and workflow requirements; data and IT own technical reliability and access; security governs risk; the business owner accepts the operating decision.

Make the evidence reviewable.

The goal is not a perfect score. It is an explicit decision about what an agent may do, with which data and under whose control.

Demo

Try the demo.

See agents carry the repeatable work of GTM across sales, marketing, customer success, and RevOps. Every action prepared, reviewed, and recorded. Fictional data, real product.

Explore the demo