# AI Production Checklist
By Alexandr Rich · alexandrrich.com

AI made it easy to start software. It did not make it easy to finish it.
Use this list between "the demo works" and "people can rely on it."
Tick an item only when you can point at the evidence.

## 1. Architecture
- [ ] You can explain the system in one diagram: user, app, data, model, external services.
- [ ] Each AI step has a defined input, a defined output and a schema that is validated.
- [ ] Business rules live in code, not only in a prompt.
- [ ] Model and provider can be swapped without rewriting the app.
- [ ] There is one clear place where state is stored, and you know what happens if it is lost.

## 2. Context
- [ ] The project has a written brief the agent reads first (see the Agent Project Brief).
- [ ] A short, maintained project memory records decisions, conventions and known traps.
- [ ] The agent is given the files it needs, not the whole repository by default.
- [ ] Every generated change is small enough for a person to review in one sitting.

## 3. Testing and QA
- [ ] The main user workflow has an automated end-to-end test.
- [ ] Sharp edges have tests: auth, payments, permissions, data deletion, anything irreversible.
- [ ] AI outputs are checked against a fixed evaluation set, with a recorded baseline.
- [ ] Tests were written or reviewed by someone other than the agent that wrote the code.
- [ ] You have run the app as a new user, from a clean account, on a phone.

## 4. Security
- [ ] Secrets are server-side, outside source control and outside browser bundles.
- [ ] Every data query is scoped to the signed-in user or organisation in code.
- [ ] User-supplied text cannot change what the agent or model is allowed to do.
- [ ] Dependencies were installed on purpose, and none were invented by the model.
- [ ] Rate limits and spending caps exist on every paid API.

## 5. Deployment
- [ ] A clean environment can build and run the app from the README.
- [ ] Deploys are automatic from one branch, and you check that each deploy actually succeeded.
- [ ] Database changes are applied by the deploy, not by hand.
- [ ] Rollback has been tried at least once.

## 6. Maintenance
- [ ] Errors reach you before a user reports them.
- [ ] Logs identify failures without storing sensitive text you don't need.
- [ ] Monthly cost per active user is known.
- [ ] Someone other than the original agent session could pick up the code tomorrow.

## 7. Actual users
- [ ] At least one real person outside the project has used it without help.
- [ ] You wrote down what confused them.
- [ ] There is a way for users to report a problem, and someone reads it.

## Ready?
Everyone is showing what AI can build in 20 minutes.
This list is about what happens 20 days later.
If a section is mostly unticked, that is the next thing to build.
