1. Rollback trigger
Fields: workflow name, trigger date, reporter, bad output or incident, affected customers/tasks, screenshots/records, and current automation status.
Stop rule: if customer-facing, legal, privacy, pricing, safety, eligibility, or account-access risk is involved, pause automation before asking AI to keep drafting.
2. Last known safe version
Fields: previous prompt/version, model/tool setting, data source, SOP link, reviewer, and what changed since the last safe output.
Guardrail: do not invent rollback history. If nobody knows the last safe version, mark NEEDS OWNER REVIEW.
3. Customer-safe correction
Fields: who must be notified, exact correction, apology/update snippet, support owner, due time, and proof link.
Review: a human must approve any correction involving refunds, discounts, warranty, account access, service scope, legal policy, or personal data.
4. Relaunch test
Fields: new prompt/version, test cases, expected output, reviewer signoff, sampling cadence, kill-switch owner, and next review date.
Stop rule: do not relaunch until the workflow passes edge cases and has a named owner who can pause it again.