This checklist serves as a guide for evaluating the containment of agent workflows to ensure safe production use, particularly in environments with sensitive systems and regulated records. It outlines specific criteria that teams should consider when determining whether an agent can operate outside of a pilot environment. The checklist includes points such as ensuring that agents run in controlled environments rather than on unmanaged devices, implementing technical controls to prevent unauthorized execution, and restricting network access to only necessary applications. It also addresses the importance of credential management and the principle of least privilege by default. Additionally, the checklist emphasizes the need for fast revocation capabilities, asset inventory, and proper change management practices. By following these guidelines, teams can minimize risks associated with agent operations and enhance overall security in their workflows.