An AI demonstration can work with one user, a handful of documents, and a permissive connection. An enterprise service has to work across teams, changing permissions, busy systems, and questions nobody anticipated. Scaling begins with that difference.

Start with the task, not the entire system

Avoid treating AI readiness as unrestricted access to every database and application. Define a useful task first: retrieve an approved policy, summarise an account's open cases, or prepare an operational briefing. Then identify the smallest set of data and operations needed.

This keeps tool interfaces understandable. A focused operation with clear inputs and a predictable result is easier to test than an unrestricted interface that accepts arbitrary instructions.

Separate knowledge retrieval from actions

Knowledge retrieval helps a model answer a question. A business action changes something in the world: submitting a request, editing a record, or triggering a workflow. These deserve different permission scopes and approval rules.

Use read-only access where that is sufficient. For write operations, validate inputs, define retry behaviour, and guard against duplicate execution. An interrupted conversation should not result in the same consequential action being performed twice.

Carry identity across every boundary

The receiving system should know who or what is asking, which authority the request carries, and what operation is allowed. Shared credentials can make a prototype convenient while obscuring the boundaries required in production.

Protocols such as the Model Context Protocol can provide a common way for AI applications to interact with tools and resources. Its authorisation specification addresses access to protected servers. Adopting a protocol still leaves organisations responsible for configuring permissions, validating tool behaviour, and governing their underlying systems.

Design for partial failure

Sources can be slow, rate-limited, or unavailable. Permissions can change between requests. A production experience needs timeouts, bounded retries, useful failure messages, and a clear indication when an answer is incomplete.

Set a freshness requirement for each task. A quarterly planning question and a question about today's open incidents do not have the same tolerance for cached information. Preserve source timestamps and avoid blending old and new evidence without explanation.

Scale the evidence before scaling the rollout

Build an evaluation set from real work, with permission to use the underlying examples. Include ordinary questions, ambiguous requests, empty results, restricted content, and attempted actions outside the user's authority. Review the results with the people accountable for the workflow.

Monitor successful task completion, groundedness, latency, cost, and access-control failures. Expand to more teams only when the operating team can understand failures and improve the service. This is the practical foundation for bringing enterprise knowledge to humans and AI agents through platforms such as Cognx.

Enterprise AI readiness is a combination of usable interfaces, bounded authority, and a service that remains understandable when things go wrong.
Further reading: Model Context Protocol: Authorisation specification
Explore more insightsExplore Cognx with your team