FID-017 · Open question
Agentic Ministry and Institutional Workflow Risk
How should faith institutions evaluate AI agents that can take actions, manage communications, schedule care, triage requests, update records, draft outreach, or coordinate volunteers?
Why the question remains open
Frontier safety research increasingly measures autonomous task completion and long-horizon agency. Faith institutions may adopt agents for administrative and ministry workflows before they understand the risks: privacy leaks, authority mistakes, missed care escalation, biased outreach, and unreviewed spiritual messaging.
Working hypothesis
A proposition to test, not a finding.
Agentic systems create failures not visible in chat-only benchmarks: wrong recipient actions, confidentiality breaches, unapproved pastoral messages, unsafe triage, tool misuse, and inability to recover after partial failure.
Proposed method
How the question could be tested
- 01Build simulated ministry workflows with email, calendar, CRM, document, and retrieval tools.
- 02Measure task completion, confidentiality preservation, approval seeking, escalation, auditability, interruption, permission revocation, and recovery.
- 03Test human recovery after partial action: stopping scheduled work, narrowing access, reconstructing state from logs, handing work to a person, and changing models or providers without silently retaining unsafe permissions.
- 04Adapt autonomous task-horizon methods to faith-institution operations.
Needed controls
What must constrain the study
- 01Synthetic data only.
- 02No real congregant or student records.
- 03Permission boundaries for tools.
- 04Human approval checkpoints.
- 05Test revocation and recovery after partial action, not only before an agent begins work.
Expected outputs
Artifacts the work should produce
- 01Agentic ministry task suite.
- 02Tool-risk taxonomy.
- 03Institutional deployment guidance.
- 04Audit-log requirements.
- 05Agent safety-case module for interruption, rollback, handoff, and recovery.
Open questions
Uncertainties the protocol must resolve
- 01Which tasks should require human approval even if the agent is accurate?
- 02How should systems encode pastoral confidentiality?
- 03How long-horizon should faith-institution agent tests become?
- 04What evidence enables a human operator to understand and safely recover an interrupted workflow?
Related calls
Continue through this research area
FID-064
Collective Intelligence and Communal Discernment Under AI Mediation
How does AI mediation change a community's ability to integrate dispersed knowledge, preserve epistemic diversity, surface dissent, revise judgment, and make accountable decisions? Under what conditions does it strengthen collective inquiry, and under what conditions does it create correlated error, false consensus, or concentrated authority?
FID-069
Verifiable Delegation and Revocation in Multi-Agent Networks
How can people and institutions verify which human, organization, agent, or sub-agent is acting; what authority it received; what limits apply; and whether that authority has been narrowed or revoked across a multi-principal agent network?
FID-071
Confidential Agent Memory and Cross-Context Disclosure
How do persistent memory, summaries, retrieval stores, tool traces, delegation, and exports cause confidential context to influence or leak into unrelated sessions, roles, tasks, or organizations? Which technical controls make purpose limitation, deletion, and revocation testable?
Open question
Open work
Primary need: agent evaluation, institutional operators
- Design synthetic workflows.
- Build agent evaluation harnesses.
- Review institutional operations and privacy risks.