---
title: "What a Build Acceptance List Contains"
description: "Define the files, tests, receipts, permissions, failure cases, and handoff proof required before accepting an AI agent build."
canonical: "https://scalewithsearch.com/articles/what-a-build-acceptance-list-contains"
date: "2026-08-17"
modified: "2026-09-19"
---
## Site navigation

- [Scale With Search](https://scalewithsearch.com/)
- Real estate
  - Real estate
    - [Real estate](https://scalewithsearch.com/for/real-estate)
- Work
  - Start here
    - [Send your brief](https://scalewithsearch.com/work#send-your-brief)
    - [Prepare your six-question brief](https://scalewithsearch.com/work#prepare-your-six-question-brief)
  - Build
    - [Site build, content library with SEO, signal desk](https://scalewithsearch.com/work)
- For your business
  - Trades and home services
    - [Auto body and collision shops](https://scalewithsearch.com/for/auto-body-and-collision-shops)
    - [Foundation and home repair contractors](https://scalewithsearch.com/for/foundation-and-home-repair)
    - [Garage door and fencing contractors](https://scalewithsearch.com/for/garage-door-and-fencing-contractors)
    - [HVAC contractors](https://scalewithsearch.com/for/hvac-contractors)
    - [Janitorial and commercial cleaning companies](https://scalewithsearch.com/for/janitorial-and-commercial-cleaning)
    - [Locksmiths](https://scalewithsearch.com/for/locksmiths)
    - [Moving companies](https://scalewithsearch.com/for/moving-companies)
    - [Pest control companies](https://scalewithsearch.com/for/pest-control-companies)
    - [Plumbing and electrical contractors](https://scalewithsearch.com/for/plumbing-and-electrical-contractors)
    - [Restoration and water or fire damage companies](https://scalewithsearch.com/for/restoration-and-water-fire-damage)
    - [Roofing companies](https://scalewithsearch.com/for/roofing-companies)
    - [Towing companies](https://scalewithsearch.com/for/towing-companies)
    - [Tree services and landscaping companies](https://scalewithsearch.com/for/tree-services-and-landscaping)
    - [Solar installers](https://scalewithsearch.com/for/solar-installation)
    - [General contractors](https://scalewithsearch.com/for/general-contractors-and-construction)
    - [Paving, concrete, and flooring contractors](https://scalewithsearch.com/for/paving)
  - Practices and professional services
    - [Bookkeeping and tax practices](https://scalewithsearch.com/for/bookkeeping-and-tax-practices)
    - [Dental practices](https://scalewithsearch.com/for/dental-practices)
    - [Family and criminal defense law firms](https://scalewithsearch.com/for/family-and-criminal-defense-law-firms)
    - [Med spas and aesthetics practices](https://scalewithsearch.com/for/med-spas-and-aesthetics)
    - [Personal injury law firms](https://scalewithsearch.com/for/personal-injury-law-firms)
    - [Veterinary clinics](https://scalewithsearch.com/for/veterinary-clinics)
    - [Gyms and fitness studios](https://scalewithsearch.com/for/fitness)
    - [Therapy and outpatient health practices](https://scalewithsearch.com/for/therapy-and-outpatient-health)
    - [Medical billing companies](https://scalewithsearch.com/for/medical-billing)
    - [Insurance agencies](https://scalewithsearch.com/for/insurance-agencies)
    - [Financial advisors](https://scalewithsearch.com/for/financial-advisors)
    - [Property management companies](https://scalewithsearch.com/for/property-management)
    - [Recruiting and staffing agencies](https://scalewithsearch.com/for/recruiting-and-staffing)
    - [Architects and interior designers](https://scalewithsearch.com/for/architects-and-interior-designers)
    - [Logistics and supply chain companies](https://scalewithsearch.com/for/logistics-and-supply-chain)
  - Agencies, MSPs, and manufacturing
    - [IT and managed service providers](https://scalewithsearch.com/for/it-and-managed-service-providers)
    - [Machine shops and precision manufacturers](https://scalewithsearch.com/for/machine-shops-and-precision-manufacturing)
    - [Marketing agencies and freelancers](https://scalewithsearch.com/for/marketing-agencies-and-freelancers)
    - [SEO agencies and consultants](https://scalewithsearch.com/for/seo-agencies-and-consultants)
    - [Small manufacturers and fabricators](https://scalewithsearch.com/for/small-manufacturers-and-fabricators)
  - Restaurants, shops, studios, and nonprofits
    - [Restaurants and hospitality businesses](https://scalewithsearch.com/for/restaurants-and-hospitality)
    - [Retail stores and ecommerce sellers](https://scalewithsearch.com/for/retail-and-ecommerce)
    - [Photographers, event planners, and travel agents](https://scalewithsearch.com/for/photographers)
    - [Churches and nonprofits](https://scalewithsearch.com/for/churches-and-nonprofits)
  - [All industries](https://scalewithsearch.com/for/)
- Learn
  - For your office
    - [Office job guides](https://scalewithsearch.com/guides/)
    - [Browser calculators](https://scalewithsearch.com/tools/)
  - Start here
    - [How it works](https://scalewithsearch.com/how-it-works)
    - [Free Starter Kit](https://scalewithsearch.com/kit/business-memory-starter-kit.zip)
    - [Synthetic specimen](https://scalewithsearch.com/specimen/working-session-specimen.zip)
  - Guides
    - [The Complete Guide to Business Memory for AI Agents](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [The Complete Small-Business Guide to AI Agent Governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [The Complete Guide to Leaving Vendor AI Memory](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - Articles by cluster
    - [Business memory](https://scalewithsearch.com/articles/business-memory-for-ai-agents-guide)
    - [Agent governance](https://scalewithsearch.com/articles/ai-agent-governance-guide-small-business)
    - [Migration and ownership](https://scalewithsearch.com/articles/leaving-vendor-ai-memory-guide)
  - For machines
    - [llms.txt](https://scalewithsearch.com/llms.txt)
    - [llms-full.txt](https://scalewithsearch.com/llms-full.txt)
    - [Machine view](https://scalewithsearch.com/?view=machine)
- Company
  - Evidence
    - [Proof](https://scalewithsearch.com/proof)
  - Company
    - [About](https://scalewithsearch.com/about)

# What a Build Acceptance List Contains.

An agent build produces the right answer during a screen share. The builder calls it finished. The next day, the buyer uses a different input and the workflow reads the wrong client folder, skips the approval step, and leaves no record of what happened.

The demo passed. The build did not pass acceptance.

## Acceptance is a written decision

An acceptance list states what must be true before the buyer accepts an outcome. It connects the promised result to files and tests that another authorized person can inspect.

[NIST's AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) is voluntary guidance for managing AI risk across design, development, use, and evaluation. Its resource center includes testing, evaluation, verification, and validation material. A small business build does not need to pretend it earned a certification. It does need a test plan proportionate to what the system can affect.

The inspectable file should be named `acceptance-list.md`. Each item should have:

- an identifier;
- the requirement;
- the test method;
- expected evidence;
- current status;
- reviewer;
- date;
- exception or correction reference.

Avoid requirements such as "works well" or "uses AI safely." They cannot be tested.

## Start with the outcome

The first section repeats the exact outcome purchased.

For example: "Prepare one weekly account brief from these buyer-owned records. Save the draft in this folder. Cite the current source. Stop before sending."

That sentence bounds the build. The acceptance list should not quietly add bulk migration, live publishing, a dashboard, or another department.

Name the required output file and its schema. If the result is `weekly-account-brief.md`, identify the required sections, source references, date, and approval status.

## Check the source path

The list must prove the agent reads the correct material.

Include tests for:

- allowed source folders;
- required context file;
- source freshness or verification date;
- correction record;
- excluded clients, roles, or domains;
- behavior when a required source is absent;
- behavior when sources conflict.

The desired failure is often a stop. If a current price, permission, owner, or customer fact is missing, the system should not fill the gap with a plausible answer.

An evidence file such as `test-source-boundary.md` should name the test input, loaded files, excluded files, output, and result.

## Check the approval boundary

Drafting and acting are different permissions.

The acceptance list should identify every external effect the system can reach: sending email, posting, publishing, booking, spending, deleting, changing a live record, deploying, or granting access.

For each effect, test three conditions:

1. No approval is present.
2. Valid approval is present for the named action and destination.
3. Approval is stale, ambiguous, or for a different action.

The expected result without valid approval is a stop and a clear request. The agent should preserve the draft and record why it did not act.

If the build has no authority to execute external actions, state that directly. Do not add a fake approval test to a read-only workflow.

## Check normal, edge, and denied cases

A single happy-path example is not enough.

Use at least these test classes when they fit the outcome:

- normal input with all required sources;
- missing required source;
- conflicting source records;
- wrong client or role context;
- malformed input;
- duplicate request;
- denied external action;
- provider or tool unavailable;
- correction from a prior failed run;
- repeat run against the same input.

The acceptance list should state the expected behavior for each case. Some should produce an artifact. Others should produce a refusal, exception record, or no-work receipt.

## Check the receipt

Every meaningful run needs an observable result.

The workflow's receipt schema belongs to the operating design. The acceptance list uses the [agent run receipt template](/articles/ai-agent-run-receipt-template) to check whether the promised receipt exists, identifies the run and artifact, records source versions and test results, and shows the correct stopping or approval state.

The acceptance item can say:

```text
ACC-07 requirement:: each test run writes the documented receipt
method:: run normal, blocked, failed, and no-work fixtures
expected_evidence:: four receipts matching schemas/job-receipt.json
read_back:: receipt paths exist and each status matches the fixture expectation
critical:: yes
```

If the job changes an external system, add read-back verification as a separate acceptance item. A successful request is not always proof that the intended state exists.

## Make read-back part of acceptance

Read-back asks the destination what state exists after an approved action.

For a file write, reopen the file and compare its path and hash. For a CRM update, query the intended record and compare the approved fields. For a deployment, read the live version or health endpoint. For a scheduled job, inspect the scheduler state and next-run configuration. For a message, record the provider's stable message identifier when available.

The acceptance list should define four objects:

1. proposed state;
2. approved action;
3. observed resulting state;
4. correction or rollback when they differ.

Use an inspectable item:

```text
ACC-08 requirement:: approved status update appears on the intended test record
fixture:: test account ACCT-1001
approval:: approvals/APR-008.yaml
action:: update status from pending to reviewed
read_back:: query ACCT-1001 after execution
expected:: status equals reviewed, no other field changed
rollback:: restore fixture or reset test account
```

Do not run this acceptance test against production first. Use a sandbox, fixture store, or recorder. If the connected system has no safe test route and the effect matters, keep execution outside the build.

## Record the buyer's acceptance decision

Tests produce evidence. The buyer or named owner makes the acceptance decision.

At the end, each item should be `accepted`, `failed`, `blocked`, or `accepted exception`. The final record names the reviewed build version, evidence paths, unresolved exceptions, correction pass, and support boundary.

Acceptance closes the original build. Any later support is a separate decision and does not replace acceptance for the original build.

## Check ownership and transfer

Acceptance includes handoff.

Require a runbook, repository or canonical file location, environment-variable inventory, ownership map, setup instructions, test command, rollback path, and support boundary.

Then ask an authorized person who did not build the system to follow the runbook from a clean start. Record the result in `transfer-test.md`.

The build is not accepted if it works only on the builder's machine or depends on undocumented access.

## Check model replacement where promised

If the build promises a replaceable model, define what replacement means.

The test might require a second supported provider or local model adapter to read the same task brief and source record, produce the same output schema, honor the same stop rule, and pass the same factual checks. It should not require identical prose.

Record model-specific differences. Tool calling, context limits, structured-output features, and safety behavior can vary. Portability is an interface and test claim, not a claim that models are interchangeable.

## Record exceptions openly

A failed acceptance item does not need to disappear.

Mark it `failed`, `blocked`, or `accepted exception`. State the impact, owner, next action, and buyer decision. An accepted exception should be explicit, especially when it affects privacy, external actions, rollback, or ownership.

When the agreement includes a correction pass, the acceptance list should link the failed item to the correction and rerun receipt.

## The hard stop

The build must stop before production when a critical acceptance item fails. Critical items include source isolation, authorization, secret handling, destructive-action controls, ownership, and rollback where rollback is required.

The system must also ask for approval before activating automation, deploying to production, rotating credentials, sending externally, changing billing, deleting data, or expanding the agreed outcome.

Passing local tests does not authorize those actions.

## Sources

- [NIST: AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)
- [NIST AI Resource Center](https://airc.nist.gov/)
- [GitHub: Actions secrets](https://docs.github.com/en/actions/concepts/security/secrets)


## Questions about What a Build Acceptance List Contains

### How are you testing AI agents before shipping to production?

Write an acceptance list with identifiers, requirements, test methods, expected evidence, statuses, reviewers, dates, and correction references. Test normal, missing-source, conflicting-source, wrong-context, denied-action, duplicate, outage, and recovery cases before production activation.

### How are you catching prompt injection that comes in through retrieved content?

Treat retrieved documents, emails, websites, and tool output as untrusted data. Use a bounded fixture, restricted source path, synthetic marker, tool recorder, and source-to-sink checks to prove that hidden content cannot grant itself authority.

### Are you giving agents direct tool/API access?

The acceptance list should identify every capability and test absent, valid matching, stale, mismatched, or consumed approval. If the workflow is draft-only, keep send credentials out of the runtime and verify that no external action occurred.

## Related: Ownership and Migration

- [What Stops Working When You Stop Paying for the Model?](/articles/what-stops-when-you-stop-paying-for-ai)
- [Run This Test Before You Cancel an AI Subscription](/articles/ai-subscription-shutdown-test)
- [How to Preserve Context From AI Design Sessions: Decisions, Constraints, and Handoff](/articles/preserve-context-ai-design-sessions)

----

```text
                  .|########||.                                       .|########||.                                       .|########||.
               |##||.      .||##|.                                 |##||.      .||##|.                                 |##||.      .||##|.
             |#|.              .|#|.                             |#|.              .|#|.                             |#|.              .|#|.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
        .#.                          .#|                    .#.                          .#|                    .#.                          .#|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
      |#             ......             #|                |#             ......             #|                |#             ......             #|
     .#           ||#########|           #|              .#           ||#########|           #|              .#           ||#########|           #|
    .#.         |######||######|.        .#.            .#.         |######||######|.        .#.            .#.         |######||######|.        .#.
    #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#            #.        .##|###|##|#|######|        .#
   ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||          ||        |##|#||||||||||||#||#|        ||
   #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.         #        |#||||||||||||||||||||#|        #.
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #        #       .#||||||||||||||||||||||||#|       #
 ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||      ||   ....|||#||||||##|#|||#|#||##||||....|. ||
 #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#      #.  .  ....|#  ....#|||   ||| .#|||  ....#. .#
 #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.     #   .  ||||#| .#####||  . .#| .#|||  ||||#   #.
.|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||    .|   |||||  #. |#|||||. ||  #. |#||. .|||||   ||
||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||    ||   |....  #. ....|#.      |. ...|. ....||   ||
#.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#    #.  .||||||##||||||##||####|||||||#||||||#|   .#
#    .||####|###########################|.     #    #    .||####|###########################|.     #    #    .||####|###########################|.     #
#      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #    #      .#||||||.#.|| # |. ..# #| #|||||#|      #
#      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #    #      .#|||||| ..  |# ## |#| ...#|#|||#|      #
#      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #    #      .#|||#|# .# .#| #| ##|.#..#|||||#|      #
#      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #    #      .#||||||############|######|||||#|      #
#   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #    #   |...||#||||||#||||#|#||||||#|||||#||| |.|  #
#. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#    #. .. ||||# .|||##|.  |#| .|| || .|||#. #|  # .#
|| |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||    || |  ...||  ...##| |  #| .|. |. #####  .. .| ||
|| ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||    || ||||| || ||||#|  .  |. |. |#. ||||| |#| || ||
.# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.    .# |.....#|....|#.||||.|||##.|#|....||.#||.#. #.
 #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#      #.|||||||#############################| ||| .#
 ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||      ||       ##||#||#||||||#||#||#||#||##.      ||
  #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #        #       .#|||||||||#||#|||||||||||#|       #
  ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||        ||       |#||||||||||||||||||||||#|       ||
  .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.        .#        |#||||||||||||||||||||#|        #.
   ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||          ||        |#||||||||||||||||||#|        ||
    #.        .######|#|#########|        .#            #.        .######|#|#########|        .#            #.        .######|#|#########|        .#
    .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.            .#.         |#####||||#####|         .#.
     |#           ||########||           #.              |#           ||########||           #.              |#           ||########||           #.
      |#             ......             #|                |#             ......             #|                |#             ......             #|
       |#.                            .#|                  |#.                            .#|                  |#.                            .#|
        |#.                          .#.                    |#.                          .#.                    |#.                          .#.
         .#|                        |#.                      .#|                        |#.                      .#|                        |#.
           |#|                    |#|                          |#|                    |#|                          |#|                    |#|
            .|#|.              .|#|.                            .|#|.              .|#|.                            .|#|.              .|#|.
               |##||.      .||##|                                  |##||.      .||##|                                  |##||.      .||##|
                 .||########||.                                      .||########||.                                      .||########||.

Scale With Search  2026  [scalewithsearch.com](https://scalewithsearch.com)
```
