Foundry Academy · AI Workflow Training · Lesson 6 of 6

Exception handling and workflow change control

Operate an AI workflow with visible exceptions, monitoring, rollback, version control, and a manual path when approved conditions are not met.

Start the lesson

Your learning work, on this device

No signup, cloud storage, cross-device sync or verified completion. Saving is optional. This browser profile is shared with anyone who can use it; private mode, browser cleanup or storage limits may remove work. Use only fictional or non-sensitive material. Export a copy before relying on this device.

Not saved. Worksheets, answers and practice notes currently last only in this tab.

Practice markers are self-reported, never credentials.

01 · Explanation

Exception handling and workflow change control

Objective: Operate an AI workflow with visible exceptions, monitoring, rollback, version control, and a manual path when approved conditions are not met.

Define exceptions before launch: unavailable sources, unsupported formats, low-quality scans, conflicting instructions, sensitive data, policy gaps, high-impact requests, unusual volume, model outage, suspected prompt injection, or outputs that fail validation. The system should fail safely by abstaining, preserving the original input, and routing to an authorized person. Users need a clear way to report a wrong or harmful result and continue service without being forced through the same failure. Time-sensitive exceptions require ownership and service targets; a manual path that nobody staffs is not a control.

Every material change should have a request, reason, owner, affected components, risk review, test scope, approval, release record, and rollback plan. Changes include model versions, vendors, prompts, source sets, connectors, thresholds, user groups, and downstream actions. Monitor critical failures, overrides, abstentions, complaints, latency, cost, security events, and data-boundary breaches with thresholds that trigger investigation or pause. Preserve enough evidence to reconstruct an incident without retaining unnecessary sensitive content. Emergency changes still require after-action documentation. If the workflow drifts outside its intended purpose, stop or reclassify it rather than quietly expanding scope.

Before you begin

  • Confirm F05, F06, F11, and F12; record that approved vendor controls, transfer authority, operating roles, monitoring thresholds, rollback package, exception authority, and production approval are absent.
  • STOP. If vendor controls, transfer authority, operating roles, monitoring thresholds, rollback evidence, or exception authority is missing or conflicts with F05/F06/F11/F12, route the runbook to the accountable change authority and authorized specialist reviewers; do not claim production approval or execute a change, exception release, or rollback.

Original overview module anchor →

02 · Compare the artifacts

Supported work. Visible uncertainty.

This is a fictional, sanitized AI-governance training case. All records are fabricated, and the exercise provides no legal, privacy, employment, medical, financial, security, or model-performance guarantee.

Redwood Assist governed intake workflow

Redwood Assist is a fictional services company considering an AI workflow to summarize new client intake and draft a routing recommendation. The current form receives about 420 submissions each month. It includes name, business email, phone, company, project description, budget range, requested timing, and an optional attachment. In a sample of 60 fabricated records, seven attachments contain government identifiers, four contain medical details unrelated to the service, nine include third-party personal information, and 16 lack enough context for reliable routing. The proposed model vendor offers a standard account with model-improvement use enabled by default and a 30-day content retention statement. No security, privacy, contract, data-location, deletion, or subprocessors review has been completed. A pilot prompt tells the model to identify serious founders and reject low-quality leads. The output labels applicants high, medium, or low potential, but neither potential nor serious is defined. In a 40-record test, the model routes 31 correctly according to one manager, while a second manager disagrees on 11 of those decisions. Two Spanish-language submissions are summarized with missing budget conditions. The team proposes automatically rejecting low-rated applicants and sending their attachment to a funding partner. There is no consent for partner disclosure, no human-review standard, no protected exception path, and no versioned evaluation set. Leadership wants the automation live next week to save eight hours of staff time. Learners must classify risk, constrain instructions and sources, establish data boundaries, design meaningful human review, build an evaluation set, and control exceptions and changes. The exercise cannot establish vendor suitability, lawful processing, fairness, or permission to automate decisions.

Supported example — reference only

Step or milestone
Vendor-control gate
Trigger or date
Before any attachment leaves the controlled intake boundary
Evidence and source ID
F05, F06: model-improvement use is enabled; privacy/security/contract controls are unreviewed.
Owner
AI workflow owner with privacy, security, legal, and procurement reviewers
Gate or threshold
All required vendor controls reviewed and approved; evidence currently not supplied.
Dependency or gap
Contract, data-location, deletion, subprocessor, retention, and improvement-use decisions.
Status
Blocked - review not supplied

A well-handled evidence gap

Step or milestone
Rollback validation
Trigger or date
Before any production change or exception release; date not supplied
Evidence and source ID
F12: estimated time saving is provisional and supplies no operational baseline.
Owner
AI operations and change owner
Gate or threshold
Approved rollback package and validation checks; no threshold supplied.
Dependency or gap
Baseline, deployment version, monitoring data, restore evidence, and approval are not supplied.
Status
Open - design review only

Flawed approach — do not copy

Marking this workflow runbook “approved and complete” without the required evidence or reviewer is a flawed submission. Stop production change, exception release, external sharing, or vendor processing when approval, monitoring, rollback, or data controls are absent.

Repair: Rework the workflow runbook as an evidence-backed draft, not an approved result. Define versioned intake, classification, processing, human review, release, monitoring, and record-retention steps. Place vendor privacy/security/contract review before any attachment transfer or model-improvement use. Place consent or other approved-authority review before any partner handoff. Check the revision against this requirement: The runbook covers normal, exception, monitoring, change, and rollback paths. If the required evidence is still absent, keep the decision blocked and identify the missing input or authorized reviewer.

Full case record, ambiguities and all assignments →

03 · Bounded practice

Build the workflow runbook.

Draft monitoring, incident, override, change, rollback, and retirement controls without operating the workflow or executing rollback.

Deliverable: A workflow-runbook draft, exception-log template, change-record template, and rollback-test plan with all execution evidence pending.

Complete a bounded starter and gap analysis using only CB01, F05, F06, F11, F12, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.

Exact supplied inputs for this assignment
  • M06-I01 · F05 — Vendor model-improvement use is enabled by default and content retention is stated as thirty days.
  • M06-I02 · F06 — Security, privacy, contract, data location, deletion, and subprocessors have not been reviewed.
  • M06-I03 · F11 — No consent supports sending attachments to the proposed funding partner.
  • M06-I04 · F12 — Leadership estimates eight staff hours could be saved each month.
  • M06-B01 · CB01 — Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment.
  • M06-S01 · F05, F06, F11, F12 — Build a starter version of “A workflow-runbook draft, exception-log template, change-record template, and rollback-test plan with all execution evidence pending.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it.

Operating procedure

  1. Define versioned intake, classification, processing, human review, release, monitoring, and record-retention steps.
  2. Place vendor privacy/security/contract review before any attachment transfer or model-improvement use.
  3. Place consent or other approved-authority review before any partner handoff.
  4. Define exception intake, risk owner, expiry, compensating control, and reapproval requirements.
  5. Specify monitoring and stop triggers without inventing a baseline or threshold.
  6. Design rollback prerequisites, restoration evidence, and post-rollback validation as pending controls.
  7. Final-QC owners, gates, dependencies, source IDs, exception expiry, change version, and no implied execution.
Field-by-field guidance
Step or milestone
Name one ordered action or decision checkpoint. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Trigger or date
Use a supplied trigger; write date not supplied when absent. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Evidence and source ID
Pair the observation with its exact supplied source ID. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Owner
Name the authorized operating or specialist role. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Gate or threshold
State a measurable provisional gate and who must approve it. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Dependency or gap
Name the evidence, owner, or prerequisite that blocks progression. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Status
Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the runbook to control workflow change, exceptions, monitoring, and rollback before production authorization.
Workflow runbook · learning draft
Step or milestoneTrigger or dateEvidence and source IDOwnerGate or thresholdDependency or gapStatus

Start with 6 rows; the complete workbook specifies 12 stable rows for this artifact. Add rows here or use the full download. No action is saved until you explicitly choose saving above.

Download complete six-module workbook (.md) · Structured case packet (.json)

Keep private client data, unpublished inventions, personal identifiers and credentials out of these public learning tools.

Module 6 · 2-item formative check

Exception handling and workflow change control

Choose an answer and request feedback. Read why each option does or does not fit the evidence. Answers stay in this tab unless you choose device-only saving; they are never submitted.

Question 1 of 2 · MODULE 6 · knowledgeWhat control response should follow a material model, prompt, or source change?
Question 2 of 2 · MODULE 6 · scenarioF05 confirms vendor model-improvement use and thirty-day retention, F06 is unknown for vendor controls, F11 confirms no partner-disclosure consent, and F12 is provisional for estimated staff savings. Which change-control record is traceable?

Answer either question to review its reasoning.

Inspect the artifact, not just your quiz answers

  • The runbook covers normal, exception, monitoring, change, and rollback paths.
  • Vendor and partner gates cite F05/F06/F11.
  • No deployment, exception approval, or rollback result is implied.

Stop: Stop production change, exception release, external sharing, or vendor processing when approval, monitoring, rollback, or data controls are absent.

Go: Proceed only to tabletop review until the full runbook, evidence capture, owners, and rollback test are approved.

Escalate: Escalate privacy/security/vendor exceptions and rollback failure to the accountable change authority and specialist reviewers.

04 · Evidence to keep

Leave with usable work.

Submit the exception queue design, manual service path, monitoring thresholds, change record, regression scope, rollback decision, and after-action review.

Download your artifact CSV and, if wanted, export the learning-work JSON above. Neither export is a reviewed submission or certificate. Device-only saving is optional; you must press Save my work now after edits.

When all six artifacts are ready, compare the full packet against the track rubric. Qualified human review is still required before real-world decisions.

Technology team discussing an AI-assisted workflow and its controls.
Learn the standard. Practice the work.
Professional reviewing an AI-assisted output on a laptop before approval.
Leave with evidence you can inspect.

Sources, scope and review boundaries

Curriculum 2026.10.08-learning-paths-1. External source dates below are record checks, not continuing guarantees. Verify current requirements before consequential use.

nist-ai-rmf · Official guidance

NIST Artificial Intelligence Risk Management Framework

Primary NIST resource for governing, mapping, measuring, and managing AI risk across the lifecycle.

Open reviewed external source ↗

nist-ai-600-1 · Official guidance

NIST AI 600-1: Generative Artificial Intelligence Profile

NIST's cross-sector profile describing generative-AI risks and actions aligned with AI RMF 1.0.

Open reviewed external source ↗

ws-ai-workflow-operating-standard · Academy internal operating standard

Wealth Synergy AI workflow internal operating standard

Academy-selected task classification, prompt, evidence, human-review, evaluation, exception, and change controls. This is an internal operating standard selected by Foundry Academy; it is not law, accreditation, licensure, or an external-standard requirement.

Version 1.0 · reviewed 2026-09-01 · owner: Foundry Academy curriculum owner

A future Wealth Synergy private professional-development certificate would be issued only after its assessment, capstone, identity, reviewer, retention, access, deletion, appeal, and issuance controls pass quality review. No credential is currently issued. Any future certificate would not be an accredited academic qualification, professional license, or government certification.