Staging first
Use a demo, sandbox, or staging environment whenever it can reproduce the relevant workflow and system behavior.
Security & data handling
Every evaluation starts by reducing exposure: narrow the workflow, prefer non-production environments, limit the access window, and agree how artifacts are handled before testing begins.

Default posture
Use a demo, sandbox, or staging environment whenever it can reproduce the relevant workflow and system behavior.
Request only the interface, role, and time window required for the agreed evaluation scope.
Prefer fictional, masked, or purpose-built records unless representative data is essential and separately agreed.
Keep engagement evidence bounded to the evaluation and avoid mixing it with unrelated customer or operating data.
Engagement controls
Confirm which system is in scope, whether it is isolated from production, and what actions the evaluation account may perform.
Identify prohibited data, acceptable fixtures, necessary redactions, and what may appear in captured evidence.
Define approved users, credential method, permissions, access period, and the process for revocation.
Agree what is captured, where it is delivered, who may receive it, and when working materials should be removed.
What to prepare
The exact questions depend on the agent, tools, and workflow. These are the minimum topics a design partner should expect to resolve.
The agent surface, tools it can call, authoritative systems, and the environment available for testing.
A named person who can provision, constrain, rotate, and revoke access during the engagement.
Which data classifications may be used, what must be sanitized, and what must never be shared.
Security review
Include your environment, data restrictions, and review requirements in the application so feasibility can be assessed early.