Agentic AI UX checklist

Checklist · 28 items · Updated

An agent is an AI feature that does things rather than only saying things: it sends the email, books the meeting, edits the files, makes the purchase. The usability questions change. A wrong answer in a chat costs a reread; a wrong action can cost money, data or a relationship, and some actions can't be taken back.

This checklist covers the controls people need around an agent: what it is allowed to touch, seeing the plan before it runs, approving the risky steps, stopping it, undoing what it did, and reviewing a record afterwards. It draws on Apple's guidance on irreversible actions, Microsoft's principles for agent UX, Microsoft's Guidelines for Human-AI Interaction, and the OWASP Top 10 for LLM applications, where excessive agency and prompt injection are listed risks.

Download the PDF

Agentic AI UX checklist as a print-ready PDF (A4, 133 KB). Everything in it is also free to read on this page.

How to use it

List every action the agent can take, and sort them by how reversible they are and who else they affect (only the user, or other people too). Then check the items below for the riskiest actions first.

Several items are as much engineering as design. Review them with the engineers who implement the agent's tools and permissions.

0 of 28 done

Ticks are saved in this browser only. Nothing you tick here is sent to UX Pickle.

Scope and permissions

  • OWASP's mitigations for excessive agency start with limiting the extensions, functionality and permissions an agent has to the minimum necessary. OWASP LLM06:2025 Excessive Agency

  • Microsoft's agent principles: an agent's knowledge, tools and connections are transparent and customisable. Microsoft Design: UX design for agents

  • People should be able to grant read access to a calendar without granting the power to cancel meetings.

  • OWASP recommends executing actions in the user's context and enforcing authorisation in downstream systems rather than letting the model decide what is allowed. OWASP LLM06:2025 Excessive Agency

  • A limit turns a runaway mistake into a bounded one.

Plan and preview

  • A plan is where a misunderstanding is cheapest to fix. Microsoft's G10 asks systems to scope their actions when in doubt. Microsoft HAX: Guidelines for Human-AI Interaction

  • Microsoft's G16: convey the consequences of user actions. Approving a summary of an action is not the same as approving the action. Microsoft HAX: Guidelines for Human-AI Interaction

  • Microsoft's G10: disambiguate or degrade gracefully when uncertain about the user's goal. Microsoft HAX: Guidelines for Human-AI Interaction

  • Drafts let people check the agent's work at no cost before trusting it with the real action.

Approval steps

  • Apple: avoid automating destructive actions and actions that are hard to undo, such as purchases, and ask for confirmation before a significant action on someone's behalf. OWASP lists human approval of high-impact actions as a core mitigation. Apple HIG: Generative AI

  • If every step asks for confirmation, people stop reading the confirmations. Sort actions by risk and only interrupt for the risky ones.

  • An approval dialog is only a safeguard if it contains the information needed to say no.

  • Mistakes that reach other people are harder to undo and more embarrassing than private ones.

While it runs

  • Microsoft's agent principles: agent status is clearly visible at all times, and background agents have a user-facing way to view and control their actions. Microsoft Design: UX design for agents

  • Microsoft's agent principles put people in control of when the agent is on or off. Microsoft Design: UX design for agents

  • PAIR recommends returning control to people when the AI fails, without making them start again. PAIR: Errors + Graceful Failure

  • A silent partial success is worse than a reported failure.

Undo and recovery

  • Microsoft's G9: make it easy to edit, refine or recover when the AI is wrong. Microsoft HAX: Guidelines for Human-AI Interaction

  • A send delay turns some irreversible actions into reversible ones for a few seconds.

  • An agent that changed fifty files should not need fifty undos.

  • People should never find out an action was permanent after it happened.

Activity log and accountability

  • Microsoft's agent principles call for a way to view and control actions and automations. Microsoft Design: UX design for agents

  • Microsoft's G11: make clear why the system did what it did. Microsoft HAX: Guidelines for Human-AI Interaction

  • Other people deserve to know when they are dealing with an automated action. In the EU, systems that interact directly with people must say they are AI (AI Act Article 50(1)). EU AI Act, Article 50 (EUR-Lex)

  • Background work people never see is work they can't check.

Untrusted content and prompt injection

  • OWASP describes indirect prompt injection: instructions hidden in external content that alter the model's behaviour. Its mitigations include segregating and identifying external content. OWASP LLM01:2025 Prompt Injection

  • OWASP lists requiring human approval for high-risk actions as a prompt-injection mitigation. OWASP LLM01:2025 Prompt Injection

  • OWASP recommends adversarial testing and attack simulations; Apple recommends testing harmful and out-of-scope requests. OWASP LLM01:2025 Prompt Injection

Sources

Checked against these sources on 3 October 2026. Spotted something out of date? Email hi[at]uxpickle.com.