How NGOs can deploy and operate Robo Claw in production
Based on the results verified in the pilot, we establish a small-scale execution environment, authentication and least privilege, separation of production and testing, trust boundaries among headquarters, local offices, contractors, and volunteers, secret management, read and write control, control of personal and sensitive information, control of images, videos, and testimonial information, control of external transmission and external publication, logging and audit trails, monitoring and cost limits, stop conditions, exception operations in case of disasters, conflicts, accidents, or information leaks, incident response, change management, manual operation switching, and design of responsible personnel and duty rosters that can be maintained with a small number of people. Direct execution of donations, transfers, expenses, or SNS postings from Robo Claw is initially excluded.
Who This Is For
Who This Is For
This is aimed at business managers, staff responsible for both IT systems, and data protection officers who have completed the pilot and are considering production deployment.
What You'll Decide
What You'll Decide in This Step
In the Deploy & Operate STEP, we establish a production operation system that can be sustained with limited personnel, monitoring and stop conditions, and exception operations (in case of disasters, conflicts, accidents, or information leaks).
Industry Challenges
Challenges Commonly Faced in Production Operation
Unable to assign dedicated operation staff
It is necessary to build a system where only dual-role staff can continue with monitoring and incident response.
Emergency response procedures are not yet established
Even if there are procedures for normal operations, there may not be procedures prepared for how to handle Agents in case of disasters, conflicts, accidents, or information leaks.
Management of secrets and authentication information tends to become person-dependent.
When staff members or volunteers in concurrent positions change, there may be omissions in transferring system authentication information.
It is difficult to notice cost overruns.
Without setting limits on API usage or SaaS fees, it may take time to notice unexpected increases in costs.
Method
Implementation Steps
1. Set minimum permissions and trust boundaries.
Set the access range for Agents, staff, and volunteers to the minimum necessary.
2. Design separation between headquarters, local sites, and contractors.
Separate access ranges between headquarters, local offices, and contractors.
3. Manage secrets and authentication information.
Store API keys and authentication information securely and establish handover procedures when personnel or volunteers change.
4. Control read/write operations, personal/sensitive information, and external transmission.
Based on the Tool Policy, control read/write ranges, the use of personal/sensitive information, and external recipients.
5. Maintain logs and audit trails.
Inquiry classification, draft creation, and sending history are recorded so that they can be checked later.
6. Define monitoring and stop conditions
Establish conditions for automatically or manually stopping when abnormal behavior or an increase in error rate is detected.
7. Define exceptional operations in case of disaster, conflict, accident, or information leakage
If an emergency contact is received, define the operation to stop confirmed processing and immediately escalate to the safety management officer and relevant organizations.
8. Define failure response, change management, cost limits, and manual operation switching
Prepare procedures for responding to failures, procedures for confirmation when changing tools, skills, or models, setting cost limits, and procedures for switching to manual operation.
Exception Operations
Exceptional operations in case of disaster, conflict, accident, or information leakage
Separate from normal operations, in the following situations, it is mandatory to immediately stop confirmed processing and switch to human response. Direct execution of donations, transfers, expenditures, SNS postings, etc., from Robo Claw is initially excluded, regardless of these exceptional operations.
In the event of disaster, conflict, or emergency
Stop automatic sending or automatic publication in the relevant region or business and immediately contact the safety management officer, local responsible officer, and relevant organizations. Final decisions regarding evacuation and safety are not entrusted to AI.
If there is suspicion of information leakage or an accident
Temporarily suspend the operation of the relevant Agent/Tool and immediately report to the Personal Information Protection Officer, Legal Department, and Board of Directors. The investigation of the cause and determination of the response policy will be carried out by humans.
Data & Systems
Data and Systems Used
Human-in-the-loop
Where Human Approval Is Required
- Decision to start or stop production operation
- Operational switching decision in case of disaster, conflict, accident, or information leakage
- Application of changes to Tool / Skill / model
- Decision on whether to continue when cost limit is exceeded
Measurement
KPI
Time from activation of stop conditions to completion of response
Time from abnormality detection / stop to completion of responsible person's response
Compliance rate with cost limit
Proportion of time operated within set cost limit
Success rate of manual operational switching
Proportion of times manual operation switching could be carried out without issue during switching training / actual operation
Pitfalls
Common Pitfalls
End monitoring only in the initial phase of implementation
Continuous monitoring and alert response is necessary after production operation, but sometimes the system becomes superficial with only initial responses.
Do not conduct training for exceptional operations
If you only document procedures for disasters and accidents but do not conduct training, they may not function properly when they actually occur.
Omit change management
Updating tools, skills, or models without verification carries the risk of unexpected behavior changes occurring in the production environment.
Checklist
Production Operation Checklist
- Minimum privileges, trust boundaries, and separation between headquarters/local sites/contractors are designed and implemented.
- Methods for managing secrets and authentication information, and handover procedures, are defined.
- Read/write controls, personal and sensitive information controls, and external communication/publication controls are functioning.
- Logs and audit trails are stored and can be verified.
- Monitoring systems and stop conditions are defined, and alerts are functioning.
- Exceptional operation procedures for disasters, conflicts, accidents, and information leaks are defined and trained.
- Robo Claw is designed not to directly execute donations, remittances, expenses, or SNS postings.
- Failure response procedures are in place.
- Change management processes for tools, skills, and models are defined.
- Cost limits are set, and responses to exceedances are defined.
- The procedure for switching to manual operation has been established and training has been completed.
FAQ
Frequently Asked Questions
Does Robo Claw directly make donations or transfers?
No. Direct execution of donations, transfers, expenditures, or SNS postings is initially excluded. Robo Claw supports information organization and draft creation, while execution is performed by humans.
Can production operation be carried out without a dedicated operator?
If limited to one project, one region, or one language, it is assumed that operation can continue through a rotation system and checklist management by part-time operators.
What happens to Agents in the event of a disaster or conflict?
It is mandatory to design the system to stop automatic sending and publishing for the relevant regions and projects, and immediately escalate to the safety management officer and local officer. Decisions regarding evacuation and safety are not entrusted to AI.
What should be done if there is a suspicion of information leakage?
It is recommended to pre-establish procedures to temporarily suspend the operation of the relevant Agent or Tool and immediately report to the data protection officer, legal team, and board of directors.
Shall we organize the design of the production operation system together?
You can review authority design, monitoring/stopping conditions, and exception operation procedures, and discuss the configuration for production operation officially with LP.