Skip to the content.

The 5-person-team adoption path. Three playbooks, two templates, four weekends. Reach Maturity Level 1 (Aware) in week 1, Level 2 (Containable) in week 4. The full framework is comprehensive; you do not have to adopt all of it on day one.

Part of the AI IR Overlay™ framework. See CONTENT_MAP.md for the full repository map and QUICKSTART.md for the standard 30-day adoption path.


Startup QUICKSTART: Minimum Viable Adoption

Who this is for

This artifact is for security teams of 5 or fewer who need to defensibly respond to AI agent incidents but cannot adopt the full 24-playbook framework in their first month. The standard QUICKSTART.md assumes well-resourced security teams with full platform control; this artifact assumes the opposite.

You should still read this if any of these apply to your situation:

If you are at a 50-person-plus security team with full platform control, use QUICKSTART.md instead. It targets a deeper adoption path that this artifact deliberately defers.

The startup-minimum subset

The full framework has 24 playbooks, 4 framework foundation docs, 2 templates, 5 schemas, 3 crosswalks, and a validator. The startup-minimum subset is 3 playbooks + 2 templates + 1 triage card:

Artifact Why it is in the minimum subset
Playbook 02: Evidence Lives in New Places The conceptual foundation. Three Realities of AI Evidence. If your team does not internalize these, every other discipline is at risk. Read first.
Playbook 01: The Agent Is a Privileged Identity The operational keystone. Six Triage Questions. First-Hour Actions. Materiality and Disclosure call convening. This is the playbook your on-call responder works through during an incident.
Playbook 18: Post-Incident Hardening The 5-business-day closure SLA. Turns lessons into permanent guardrails. Without this, the same incident recurs.
AI-BOM template The inventory artifact. Per-agent record of identity, tools, write targets, retrieval, memory, kill-switch status. Exportable in 5 minutes.
Agent Privilege Matrix The tool-tier classification. T0/T1/T2 per tool, with approval gates and reversibility. The substrate for Kill-Switch Mode M3 Tool Tiering.
Six Triage Questions card The print-and-keep-at-the-desk artifact. Q1 through Q6 plus the Mental Model and Kill-Switch ladder on one page. The most useful single artifact under operational pressure.

That is the minimum subset. Six files. Everything else (the other 21 playbooks, the crosswalks, the schemas, the validator) is the depth that supports specific incident classes and maturity progression beyond Level 2.

The 4-week adoption path

The path below assumes three Week-0 preconditions are met. If any of these is not met before you start Week 1, add 1-3 weeks for discovery work and document the constraint. The Week-0 checklist exists because the most common reason small-team adoptions slip from 4 weeks to 8-12 weeks is hitting these preconditions mid-project.

Week 0: Pre-Adoption Readiness Check (do not skip)

Goal: confirm the structural preconditions are met before committing to the 4-week timeline. Each check is ~30-90 minutes; the full Week 0 sweep is ~1 day for a single security person.

Pre-check What to confirm If not met
Vendor-copilot evidence SLA For each vendor-managed agent (Copilot for Microsoft 365, Salesforce Einstein, ChatGPT Enterprise, custom vendor copilots): document the contracted evidence-export SLA (target: ≤ 60 minutes), the named escalation contact, the proof-of-M3-availability (can the vendor disable individual tools, or is M4 the only granularity?), and the vendor’s audit-log retention window for your tenant. If any vendor copilot you depend on cannot meet the customer-side 60-minute evidence target, the Level 3 maturity claim is structurally bounded for those agents Read Playbook 10 (Vendor Copilots) (the deferred-but-conditional playbook this Week 0 acknowledges). Document the vendor constraint in the AI-BOM notes field. Plan for separate maturity tracks per agent class (customer-managed vs vendor-managed).
Tool reversibility audit For each AI agent’s high-impact tools: confirm what “reversibility” actually means in your stack. “via audit log” is passive (you can see what happened but cannot undo it); “via blue-green rollback” or “draft-mode preferred” is active. Audit your top 5 T2-class tools per agent for reversibility category. If 30%+ of your tools are passive-reversibility (cross-tenant email sends, immutable CRM records, public posts without recall), Week 2 will surface this as a structural blocker Defer the affected tools to vendor or platform-team work. Re-classify passive-reversibility T2 tools as approval-required-and-audit-only with explicit risk acceptance per Playbook 24 C4. The 4-week path continues with the tools that have active reversibility
Identity coordination Confirm you (or one named person on the security team) has IdP admin access to inspect OAuth grants, service accounts, and scope assignments. The AI-BOM Day 3 step requires this; for a startup with engineering managing IdP separately, plan a Day 0.5 IdP-team walkthrough Schedule the IdP-team walkthrough before Week 1 Day 3. If IdP access is not available within 7 days, defer the affected agents (continue Week 1 with the agents whose identity can be inspected)
Multi-agent sequencing If you have 2-3 agents, decide upfront: run Week 1 on all agents in parallel (1-2 weeks for inventory), then continue weeks 2-4 sequentially. If you have 1 agent, the 4-week path applies as-written For 4+ agents, run the QUICKSTART-startup path on the top 2 highest-risk agents first; defer the others to the standard QUICKSTART progression
Regulated-data scope If any agent touches regulated data (PII, PHI, payment card, FERPA, GDPR personal data, sectoral regulated data): your retention and logging discipline is audit-relevant immediately, not “deferred until Level 3” Include Playbook 15 (Records and Retention) and Playbook 23 (Logging and Privacy) in your Week 0 reading. Plan for retention-and-redaction design in Week 1 alongside the AI-BOM
RAG enabled If any agent has retrieval-augmented generation (knowledge base, vector search, document corpora): your retrieval forensics discipline is load-bearing for any output-leakage or context-poisoning incident Include Playbook 03 (RAG Forensics) in your Week 0 reading. The 7-component pipeline forensics from PB03 informs your evidence-instrumentation choices in Week 1

Week 0 deliverable: a one-page Pre-Adoption Readiness Report with each of the six pre-checks answered. The report becomes the Week 1 input; the 4-week timeline is calibrated against the confirmed-met preconditions.

Voice note for solo founders and single-security-person startups: the QUICKSTART-startup path is written for “the security team” but recognizes that in many 5-person organizations the security team is one person (often combining engineering, security, and IT roles). For solo operators, the Week 0 checks are particularly important: each unmet precondition compounds with the cognitive load of running the 4-week path on top of regular operations. The most common solo-operator failure pattern is committing to the 4-week timeline before validating the Week 0 preconditions, then absorbing the slip silently. The framework’s discipline is to make the slip visible and named: a 6-week or 8-week path that completes Week 0 honestly is materially better than a 4-week path that creates false-confidence about maturity.

Week 1: Inventory (Maturity Level 1: Aware)

Goal: know what AI agents you run.

Day Action Effort Owner
Day 1 Read Playbook 02 (Three Realities). Internalize the mental shifts. Read Playbook 01 (The Agent Is a Privileged Identity) for the operational lens. ~2 hours One person
Day 2 List every AI agent in production. Vendor copilots count. Shadow AI counts (per Playbook 21 if curious). ~1 hour One person
Day 3-5 For each agent: copy templates/ai-bom.yaml, rename to per-agent (e.g., ai-bom-customer-support-copilot.yaml), fill in: agent name, business owner, identity, model, tools, write targets, retrieval corpora, memory configuration. Set kill_switches.maturity_target: "level_1_aware" for week 1 (you are not yet at Level 2). ~30-60 min per agent One person, coordinating with IT for identity scopes
Day 7 Validate. Run the validator against each AI-BOM. Output should be OK. If failures: read the errors, fix the AI-BOM, re-run. ~15 min One person

End of Week 1 deliverable: one AI-BOM per agent, validated against schema, with maturity_target: level_1_aware set explicitly. Your organization can now answer “what AI agents do we run?” in under 5 minutes.

Week 2: Tool tiering (preparation for Level 2)

Goal: know what each agent can do.

Day Action Effort Owner
Day 8 Read Playbook 04 (Tool Design Is Containment). Focus on the T0/T1/T2 vocabulary. ~1 hour One person
Day 9-12 Copy templates/agent-privilege-matrix.csv. For each tool of each agent: classify as T0 (read-only), T1 (bounded writes), or T2 (systems of record). When unsure, default to T2. Specify approval_required, cap_per_run, reversible, write_targets, allowlist. ~1-2 hours per agent One person, coordinating with business owner for reversibility
Day 14 Validate. Run the validator against the matrix. Output should be OK. ~15 min One person

End of Week 2 deliverable: Privilege Matrix populated for every agent, with at least one T2 tool per agent showing approval_required=yes. You now have the substrate for Mode M3 Tool Tiering.

Week 3: Tabletop the kill-switches (Maturity Level 2: Containable)

Goal: prove you can stop harm.

Day Action Effort Owner
Day 15 Read Kill-Switch Modes. Understand M0-M5 and the M3 variants. ~1 hour Whole team
Day 16 For each agent, identify how to activate each of M1 (Read-Only), M2 (Approvals Required), M3 (Tool Tiering), M4 (Full Disable). For vendor copilots: document where M3 and M4 require vendor coordination (per Playbook 10). ~2-4 hours per agent One person + business owner
Day 17-19 Tabletop each mode. Walk through what activating each mode looks like in practice. Measure TTA (Time-to-Activate) in minutes. Update the AI-BOM’s kill_switches.mX.tested_at to today’s date and tta_minutes to the measured time. ~1-2 hours per mode per agent Whole team
Day 19 end Update each AI-BOM: change maturity_target to level_2_containable. Re-run validator. ~15 min One person
Day 21 Print the Six Triage Questions card. Distribute to the on-call team. ~5 min One person

End of Week 3 deliverable: every agent has all four kill-switch modes tabletop-tested within the past 7 days. Your organization is at Maturity Level 2 (Containable) by the framework’s discipline.

Week 4: Post-incident readiness and trigger the first drill

Goal: be ready to respond.

Day Action Effort Owner
Day 22 Read Playbook 18 (Post-Incident Hardening). Understand the 5-business-day SLA. ~1 hour One person
Day 23-24 Document who is the on-call responder for each agent and who approves T2 actions. Add to the AI-BOM agent.business_owner and agent.technical_owner fields. If your team is too small for separation: document the contingency (vendor support contact, mutual-aid agreement, board-level escalation path). ~30 min per agent Whole team
Day 26 Run a synthetic incident drill. Pick one agent. Simulate the scenario: anomalous tool-call spike, suspicious agent output, or customer complaint. Walk through the Six Triage Questions card. Activate Mode M3 Tool Tiering. Document the response timeline. ~2 hours Whole team
Day 28-30 Retrospective. What worked. What did not. What hardening item is on the 5-business-day list for next week. Update the runbook. Commit to the next monthly drill. ~2 hours Whole team

End of Week 4 deliverable: one drill complete, one retrospective documented, one hardening item committed. You are operationally ready for your first real AI incident.

What you are deliberately deferring

This 4-week path deliberately defers the following from the full framework. Several of the deferrals are conditional rather than absolute: the Week 0 readiness check should flag the conditions that override the deferral, and you should include the affected playbook in your Week 0 reading and Week 1 planning.

Conditional deferrals (override if condition applies)

Absolute deferrals (defer until growth conditions are met)

The framework’s discipline is “adopt only what you can sustainably operate”. A 5-person team operating PB01 + PB02 + PB18 well plus the conditional playbooks their Week 0 check identified is materially better than a 5-person team gesturing at all 24 playbooks badly.

Limits and honest acknowledgments

This QUICKSTART has limits you should be aware of:

  1. The 30-day path slips for vendor-copilot-heavy environments. If your AI agents are exclusively vendor copilots (you cannot modify the runtime), some kill-switch modes will be vendor-coordinated and slower than 10 minutes. Document the constraint; do not pretend you have something you do not.
  2. The Level 2 (Containable) claim depends on the customer actually tabletop-testing all four kill-switch modes. A team that only practices M1 (Read-Only) and M4 (Full Disable) is at Level 1.5; it is honest to claim that explicitly per framework/03-maturity-roadmap.md.
  3. Evidence export (Type A through F per evidence/minimum-evidence-set.md) is NOT included in the startup-minimum subset for Level 2. It is required for Level 3 (Provable). For Level 2 you only need to be able to contain harm; for Level 3 you need to be able to prove what happened. The framework’s discipline is honest about the difference.
  4. You will encounter gaps the QUICKSTART does not address. When you do, the CONTENT_MAP.md is the navigation artifact. Read the relevant playbook on-demand rather than trying to memorize the whole framework.

When you are ready for more

Two natural progression points:


Source: AI IR Overlay framework, by Jacob Ideji. Startup-minimum adoption path released in v0.26.0 to close the adoption-friction gap identified in the v0.24.0 holistic critique.

https://www.linkedin.com/in/jacobideji/