How to Deploy and Operate Robo Claw in Local Governments
When rolling out tasks verified in the Pilot to production, this organizes the operational framework including execution environment, authentication, least privilege, trust boundaries for information systems, resident information systems, and core systems, access control for contractors, monitoring, and exceptional operations during disasters.
In production operations, in addition to the normal and abnormal behaviors confirmed in the Pilot, it is fundamental to establish a system for continuous monitoring, alerts, and incident response. In particular, pre-defining the stop conditions and exceptional operations during disasters, the procedure for switching to manual operations in case of failure, and the re-verification process during system changes will determine the initial actions that prevent incorrect reflection or misdelivery of resident information. The design should not assume that judgments affecting administrative penalties, eligibility for benefits, examinations, or residents’ rights can be executed without approval, and separation from electronic approval should also be maintained.
Who This Is For
Who This Is For
This is intended for the information systems department, responsible department heads, and information security officers when rolling out tasks verified in the Pilot to production.
What You'll Decide
What You'll Decide in This Step
In Deploy & Operate, the authentication, permissions, and monitoring system in the production environment are finalized, and stop conditions and recovery procedures in case of failure, exceptional operations during disasters, and methods for maintaining continuous operations across multiple departments are decided.
Industry Challenges
Challenges unique to local governments
Operating Hours within the Office / Continuity Response During Disasters
The operational structure required during normal times differs from that during disasters, and a monitoring and alert system capable of handling both is required.
Incident Response Across Multiple Departments and Contractors
If system configurations differ for each department or contractor, it takes time to isolate issues when incidents occur.
Following Changes on Resident Information Systems
When there are specification changes in resident information or core systems, changes management and re-verification for the integrated parts are necessary.
Immediate Halt When an Incident Occurs
In cases of mishandling of personal information, it is necessary to have a system that can immediately stop the related automated processes.
Method
Implementation Steps
1. Prepare the Execution Environment
Prepare the production environment and confirm the differences from the Pilot environment.
2. Determine authentication and minimum privileges
Determine the authentication method for production users and agents, as well as the minimum permissions by department and position.
3. Design Trust Boundaries for Information Systems, Resident Information Systems, and Core Systems
Establish trust boundaries between the office information network and resident information/core systems, limiting the execution scope of AI agents to information systems.
4. Establish Secret Management
Set up a system that can safely manage and rotate confidential information such as system API keys and tokens.
5. Design Separation from Electronic Approval and Administrative Decisions
The output of AI agents shall be limited to drafts and candidates, and official approvals and administrative decisions are clearly excluded from the scope of agent execution.
6. Establish access control, logging, and audit systems for contractors
Control the access scope of contractors, define the storage location and retention period of operational logs, and establish methods for reference during audits.
7. Define monitoring, alerts, and stop conditions
Monitor the operation status of agents, execution failures, and signs of abnormal misdelivery, and define automatic stop conditions when anomalies are detected.
8. Define exceptional operations and incident response during disasters
Define exceptional operations in case of disasters, automatic processing stops in case of accidental disclosure of personal information, escalation routes to legal, personal information protection, and information security officers, and procedures for switching to manual operation.
Data & Systems
Data and Systems Used
Human-in-the-loop
Where Human Approval Is Required
- Final approval for migration to the production environment
- Approval for issuing and rotating secrets and authentication information
- Approval of skill and tool updates and re-verification due to specifications changes in connected systems
- Approval for execution of recovery and restart procedures in case of incident occurrence
Measurement
KPI
Operating rate
Operating rate of Agents/Skills in production
Time from failure detection to recovery
Time taken from detecting an anomaly to recovery
Alert response time
Time from alert issuance to first response
Pitfalls
Common Pitfalls
Leaving it entirely to monitoring after introduction
If you operate without deciding the monitoring system after going live, detection of failures will be delayed.
Do not provide stop procedures in case of incident occurrence
If there are no procedures to immediately stop related processes when an incident occurs, the risk of impact expansion increases.
Omit re-verification after system changes
If operations continue without re-verification after a specification change of the connected system, the risk of unexpected malfunctions increases.
Checklist
Production Operation Checklist
- Authentication and least privileges in the production environment are confirmed
- Trust boundaries for information systems, resident information systems, and core systems are designed.
- Procedures for secret management and rotation are established
- Electronic approvals and administrative decisions are excluded from the scope of Agent execution.
- The access range of contractors is controlled.
- The storage location and retention period for operation logs and input/output records are determined.
- The monitoring and alert targets and notification destinations are set.
- Conditions for stopping in abnormal situations and recovery procedures are documented.
- Procedures for switching to manual operation and exceptional operation during disasters are prepared.
- A process for re-verification when connected systems, etc., are changed is defined.
FAQ
Frequently Asked Questions
Who is responsible for monitoring during production operation?
The Information Systems Department usually takes the lead, and depending on the business content, coordinates with the responsible department and information security personnel. Specific role assignments are designed individually.
Can administrative actions or approval/rejection of benefits be executed automatically without permission?
No. Operations that affect residents’ rights or interests, such as administrative actions, approval/rejection of benefits, subsidies, support, and examinations, are fundamentally designed on the premise of human approval.
What happens if an incident such as the erroneous transmission of personal information occurs?
It is recommended to prepare in advance a route to immediately stop related automated processes and escalate to legal, personal information protection, and information security personnel. The specifics of the procedure will be designed individually.
Shall we organize the production configuration and operation together?
The production operation configuration, including authentication, connection to resident information and core systems, monitoring, incident response, and multi-department operations, can be concretized through consultation with the official LP.