Maya Workforce AI/Evaluation checklist

The Questions to Ask Any AI Agent Vendor Before You Hand It Credentials

An AI agent with write access to your systems of record is not a chatbot procurement decision. It is closer to hiring a contractor and giving them a badge. These twelve questions are the ones that separate a system designed for failure from one that has only been demonstrated succeeding.

The questions are below in full. Answer two fields and the page also shows you what a real answer sounds like, what a rehearsed one sounds like, and the follow-up that tells them apart.

1

What happens when an access token expires in the middle of a task?

This is the single most common production failure for anything holding credentials, and the answer tells you whether recovery was designed or improvised.

2

If the same event is delivered twice, do I get the action twice?

Webhook redelivery is normal, not exceptional. Duplicate sends and duplicate payments are how automation loses trust in week one.

3

What does it do when it cannot uniquely identify a record?

Two employees with the same name, two vendors with the same DBA. Guessing here is how an agent does the right action to the wrong person.

4

Which actions can never be automated, regardless of configuration?

Every vendor says there is a human in the loop. The real question is which gates you are not allowed to turn off.

5

If a ticket or email tells the agent to ignore its instructions, what happens?

Any agent that reads inbound content has an attack surface made of that content. This is not theoretical for anything touching a shared mailbox or a public queue.

6

Can the agent resolve its own authentication problems?

If it can, then "your session expired, sign in here" is a working attack. If it cannot, that entire class of attack has nothing to act on.

7

Where does our data live, and what do you see?

This determines the length of your security review more than any other answer.

8

What stops it from reaching a system it was not granted?

Scope enforced by convention drifts. Scope enforced at the network does not.

9

What gates a release, and what is in that gate?

Everyone has tests. The question is whether the tests break things on purpose.

10

When it makes a mistake and we correct it, what stops the mistake from recurring?

This separates a system that improves from a system that is described as improving.

11

What happens to our data when we ask you to delete a person from it?

A right-to-be-forgotten request is a real operational event, and the storage design decides whether you can honor it.

12

What is in the retainer, and what is a new agreement?

Ambiguous scope is what turns a working deployment into a slow argument.

See what a real answer sounds like

For each question: the answer that means they built it, the answer that means they have a slide about it, and the follow-up that separates the two.

Unlocks on this page. Nothing to download.

Want to see these answered live?

This list is the one we built our own product against, which is why we are comfortable handing it to you before you have talked to us. Bring it to every vendor you evaluate, including this one.

Request a demo