Keep The
Lights OnA DEVELOPMENT PATTERN

A self-check in your browser

Could people keep
this work running?

Pick one capability (one piece of work that depends on an AI service, such as answering customer requests) and answer the questions about its manual path. Calculate a provisional KLOD level and download the list of next actions.

New to KLOD? Learn the pattern. To check a whole code repository instead, use the klod-check skill in your coding assistant.

Answer from current records. Choose “Not sure” where evidence needs checking.

Everything is calculated in your browser. No answers are sent to us. Reloading clears them; download the report to keep it.

Part 1 of 4

The work and its supplier

Assess one business capability, such as answering customer requests. A level belongs to that work, not to the whole product.

Does this work depend on an external AI service during normal operation?

AI used only to write the software is different from an AI service needed to run it.

What is recorded for this capability?

The register is your list of work that depends on AI (specification section 4.1). A complete entry names the supplier, the capability, the declared level (the level you currently claim) and one accountable person.

When was that register last reviewed?

An overdue review is noted separately. It does not lower the level of an otherwise documented capability.

Is L3 currently declared for this capability?

L3 means people already do this work routinely without AI. An existing L3 claim needs a review within the last twelve months confirming that, even if people have since stopped doing the work routinely.

Part 2 of 4

The manual path

Start with a path people can operate without the AI (the manual path). Switching automatically to another AI supplier does not, by itself, establish one.

Is there a documented way for people to do this work without the AI?

People must be able to take responsibility for completing the work, using the tools available to them.

How complete are the instructions?

They should be followable by a competent person who did not write them. L1 does not require a completed drill.

Does any step still need the AI system this procedure replaces?

Include API calls and information the system would have to generate at the time of use.

What can people access without the supplier cooperating?

Consider inputs, previous outputs, reference data and the business knowledge needed to make decisions.

Are the people responsible for the manual path identified by role?

This asks who would do the work. Evidence of their performance comes later.

Does the manual path use a different external AI supplier?

A shared cloud, jurisdiction or access restriction may stop both suppliers. This check concerns a substitute used inside the manual path.

Part 3 of 4

Evidence from practice

Use the records for this capability. A drill is a practice run on real work with the AI genuinely unavailable (specification section 4.4). A tabletop exercise (talking through the procedure) or a rehearsal on sample cases is not a drill. Training, planned exercises and estimates do not establish actual performance. Only relevant follow-up questions appear.

What drill evidence can you rely on for this procedure?

Use the latest drill being relied on, and account for any later failed drill. Extra tabletop or rehearsal exercises do not invalidate an otherwise current drill.

How long ago was that successful drill?

This checks the 90-day L2 schedule. L3 uses a separate routine-performance review, while still requiring current measurements.

Was the replaced AI actually unavailable during that drill?

For example, access was blocked or the integration was disabled for the participants.

What work did participants perform?

Use the actual workload within an authorised, safe scope. A rehearsal can prepare a team but does not satisfy the real-work requirement.

How often are drills unannounced to participants?

The requirement is at least one in every four. You do not need four completed drills before a first assessment.

What does the latest usable drill record contain?

Time to Manual is time to the first correct human result. Capacity records the share of normal work people can sustain and for how long. The record also needs its date and what went wrong.

How many current operators have demonstrated this work without supervision in a drill?

Training records alone do not establish this. Count demonstrated performance of this capability.

Have the people who last performed this work unaided left the organisation?

If they have left, a repeat drill is required before reasserting the level.

Outside drills, do people routinely complete this work independently of AI?

Completing real work counts, including a regular share of the volume. Merely reviewing AI output does not.

When did a review last confirm routine human performance?

This is the L3 review, separate from the register review and from drill dates.

Part 4 of 4

Stopping AI and taking control

Principle 6 (the AI off switch and human takeover) is reviewed separately. Its findings do not change the KLOD level.

Can an authorised person stop AI from taking further actions?

The control must not require the AI being stopped to cooperate. Consider tool access, queued jobs and automatic restarts.

What happens after AI authority is stopped?

For physical or safety-critical systems, use the defined safe state and qualified operating procedure; an improvised manual takeover may be unsafe.

Your result identifies gaps and the evidence needed for your next improvement.

How the result works

The published evidence gates apply to work that depends on an external AI supplier. AI you run yourself gets a human-control review but no KLOD level. Optional AI, or AI used only during development, gets no level.

L1 needs a registered, documented manual path, stated limits, independence from the replaced AI, accessible data and identified operators. L2 and L3 also need current drill measurements and demonstrated staffing. A failed drill prevents either higher level until a successful repeat.

L2 requires a successful drill within 90 days. L3 instead requires routine independent human work and a review within twelve months; it still needs the shared drill and measurement evidence. Existing declarations have separate expiry rules.

A 'Not sure' answer means the affected level cannot be supported; it is listed under 'Evidence to check', separately from confirmed gaps. Follow-up questions that did not apply are listed as not assessed and do not count towards a level. Principle 6 observations and register-review reminders are separate from the level.

For a manual assessment, use these questions with the evidence gates and specification.