# isWebMCP enterprise pilot worksheet

Status: proposed pilot; no results collected. Complete and retain privately.

## Owner approval
- Application owner and technical reviewer:
- Approved public URL (no secrets in path or query):
- One workflow and known expected result:
- Data-processing approval, including hosted sanitized URL/outcome retention of 90 days, with deletion during subsequent writes:
- Confirmation that no access controls will change for this pilot:
- Allowed request budget, review window, and stop contact:

## Evidence files (owned by the adopting team)
- Baseline artifact location and access policy:
- Current artifact location:
- Comparison artifact location:
- Artifact retention and deletion owner:
- Matching final URL, model version, input fingerprint, complete collection/inventory:

## Human review
- Finding and supporting evidence:
- Relevant recipe, or reason neither current recipe applies:
- Authorized local change and deployment reference:
- Is the finding actionable, a false alarm, or unresolved? Reviewer and rationale:
- Did the same reported issue change? Missing evidence is not proof of a fix:

## Measures to collect, not promised results
- Setup minutes and integration effort:
- Number of reviewed findings, actionable findings, false alarms, and unresolved items:
- Comparable / inconclusive check counts and reasons:
- New or worsened source findings after changes:
- Whether the team voluntarily retained and reused the check:
- Browser task success / latency / interventions: NOT MEASURED unless a separate authorized trial exists:

## Stop / continue
- Stop on sensitive inputs, incomplete evidence, unapproved requests, or no useful source visibility.
- Continue only after a reviewer confirms concrete utility and accepts the operating limits.
- Company name, quotation, logo, and result publication each require explicit written permission.
- No security certification, WebMCP conformance, market-adoption claim, or ROI is inferred from these checks.
