For each proposed role, list the outcome it owns, information it requires, tools it may call, actions it may prepare, actions it may execute, and conditions that force escalation. Then identify the source of every permission. Reading an approved supplier record is different from searching an unrestricted mailbox. Preparing a purchase-order change is different from committing it. This matrix prevents a broad tool token from silently becoming permission for every role that can mention the tool.
Define handoff schemas between roles. A supplier-risk finding might include supplier identity, affected item, contractual date, new asserted date, source reference, confidence, exposure window, and unresolved questions. The receiving role should reject a handoff that omits mandatory evidence instead of reconstructing it from free-form prose. Stable schemas also make roles replaceable: a different model or worker can produce the same contract without forcing the whole workflow to reinterpret a conversation transcript.
Add lifecycle ownership for the role itself. Record who can change its instructions, model route, tools, schema, and approval posture, and which tests must pass before the change is used. A role that is safe under read-only access may not remain safe after a new mutation tool is attached. Configuration changes should be reviewed as changes to operating capability, not treated as harmless prompt maintenance.