← Devon T.'s track Lesson 04 / 12 · Devon T.

Lesson 04 — A3 Elicitation: Eliciting Claude's Own Read On Rollout Risk

Bloom's: ApplyPBL
● Exhibit 4 of 12 — Devon T.'s track

Standard: — · Bloom's: Apply · Structure: PBL.

Notice the Say-See-Do cycles running on Devon T.'s actual work — not a canned exercise — and that every capability claim is cited to the frozen doc-set. The exit ticket climbs Bloom's to Apply, and the lesson closes by writing to the ledger.

Lesson 04 — A3 Elicitation: Eliciting Claude's Own Read On Rollout Risk

Generation-time decisions (logged)

Decision Value Why
Standard AIHC.1.A3 Lesson 01 found the elicitation step entirely absent from his workflow (draft → review → submit, no "ask Claude" step) — new practice, first exposure
Bloom's Apply this is a brand-new move for Devon (mastery 0.10 baseline) — the target is establishing the habit correctly, not yet judging its limits at Analyze depth
Structure PBL run directly on his now-Manual-mode Grants and Development workflows from Lesson 03
Cycles 4
Scaffold fade exact elicitation prompt given verbatim in Cycle 2, then reused with less framing in Cycles 3–4
Accommodation option-suppression one recommended elicitation prompt given; alternative phrasings noted as available, not listed
Referents (flavor only) competition BBQ circuit (asking the pitmaster who actually cooked the entry what they're least sure of, before the judges taste it — not a courtesy question, a working one)

Learning objective

(Bloom's: Apply) Before finalizing your Manual-mode workflows, ask your Cowork agent what it is least confident about in its own draft or configuration, and use its answer as working input — not a courtesy question you skip because you're already planning to review the output anyway.


SSD cycle 1 — the move itself, and why "I'll review it anyway" isn't the same thing

  • SAY: AIHC.1.A3: ask the AI coworker "for its read, its proposal, or its uncertainty before finalizing an approach, and treat 'what would you do?' as a working question rather than a courtesy." This is not redundant with your Cycle 2–3 Manual-mode decisions (Lesson 03) — Manual review checks what Claude produced; elicitation asks Claude where it thinks it might be wrong, which tells you where to spend your limited review attention first, the same way asking the pitmaster which part of the brisket they're least confident about tells the judge where to cut first — it doesn't replace the judging, it targets it.
  • SEE: A static two-box diagram: "Manual review" (you check everything, evenly) next to "Manual review + elicitation" (you check everything, but Claude's self-flagged areas get checked first) — same total review, different order, informed by a source you haven't been using.
  • DO: Before running the move on your own workflows, write one sentence: what's one thing you are least confident about in your Grants-team spec from Lesson 02 — practicing naming your own uncertainty before asking Claude to name its own.

SSD cycle 2 — running it on the Grants-team workflow

  • SAY: The working question, stated plainly: "Before I finalize this, what are you least confident about in this configuration or draft, and why?" Recommended path: ask it exactly this way, once, before your Manual review(other phrasings are available on request; this one is chosen because it names both the confidence gap and the reason, which is what makes the answer usable).
  • SEE: An illustrative rendering of the kind of answer this question surfaces, consistent with the doc-set's own named Cowork behaviors (§7's content classifiers and safety review; not a claimed live transcript): "I'm not fully certain what your policy means by 'sensitive donor information' — it isn't defined, so I can't tell you confidently whether a donor's giving history falls inside or outside that line. I also can't verify from inside this chat whether your admin console actually offers a configurable retention window — that's a console setting, not something I have visibility into; you'd need to check it directly."
  • DO: Run the exact question on your own Grants-team workflow context. Compare what comes back against your Lesson 01 diagnostic findings: does it independently surface the same gaps you already found (the undefined "sensitive" term, the unverified retention claim), or something new?

SSD cycle 3 — what Claude can, and cannot, tell you about your own console

  • SAY: Cycle 2's illustrative answer makes an important honest move: it flags what it cannot verify — the actual state of your admin console — rather than guessing at it confidently. That is the behavior AIHC.1.A3 wants elicited and credited, not brushed past: an AI coworker naming the edge of its own visibility is exactly the "self-diagnosis" the standard asks you to solicit and use, and confusing "Claude didn't flag it as wrong" with "the console must support it" would undo the whole exercise.
  • SEE: A static callout box: "What Claude can read: the text of your policy draft. What Claude cannot read: your live admin console. Elicitation surfaces the first; it never substitutes for checking the second (that's Lesson 05/06's job)."
  • DO: Write one line distinguishing, for your own rollout, one thing Claude's elicited read can legitimately tell you from one thing it cannot — and where the second one still needs a human console check.

SSD cycle 4 — checking Claude's elicited flags against the doc-set's own named risks

  • SAY: Elicitation is solicited input, not an unaudited final answer — X8 (convergence is not validity) applies to a single elicited response too: an answer that sounds thorough still gets checked against ground truth. Doc-set §7 names Cowork's actual built-in risk surface: content classifiers ("scan all untrusted content entering Claude's context and flag potential injections"), deletion protection ("requires your explicit permission before permanently deleting any files"), and prompt injection generally. Does your Cycle 2 elicited answer cover the risks the doc-set itself names, or only the ones about your own draft language?
  • SEE: A two-column check: doc-set §7's named risks (left) vs. what your elicited answer covered (right) — a gap in the right column (nothing about prompt injection or file deletion) is an expected, honest finding, not a failure of the exercise.
  • DO: Mark which of doc-set §7's named risks your elicited answer did not cover, and write one line on what that means for your review checklist (elicitation adds a source; it doesn't replace reading the doc-set's own risk list).

Independent at-bat

Run the full elicitation move — ask, then check the answer against both your Lesson 01 findings and doc-set §7's named risk list — on the Development-team donor-letter workflow, unscaffolded.

Exit ticket (Bloom's climbs to Apply; graded against doc-set §7 + Devon's own comparisons)

  1. (Remember) What is the exact working question AIHC.1.A3 asks you to put to your AI coworker?
  2. (Understand) Why is "I'll review the output anyway" not the same as running the elicitation step first?
  3. (Apply) Write the elicitation question as you would actually type it into your Cowork session for the Program-team board-summary workflow.
  4. (Apply — objective level) Run the move on the Development-team workflow (your at-bat) and report: what did Claude's elicited answer flag, and did it match, add to, or miss items from your Lesson 01 findings?
  5. (Analyze) Name one thing an elicited answer can never tell you about your own admin console, and what you must do instead to find it out.

Ledger write

ledger_write:
  learner_id: L2-ADMIN-DEVON
  lesson_id: L2-admin-devon-04-a3-elicitation-20260719
  anchors: [AIHC.1.A3]
  exit_ticket: {score: "", bloom_reached: apply}
  auto_mastery: "0.10 -> "
  auto_score: ""
  self_score: ""
  calibration_gap: " — populates when a learner takes this lesson live"
  journal_prompt: >
    The first time you ran the elicitation question for real, did the answer surprise you? If it
    just confirmed what you already suspected, was asking still worth it — why or why not?
  structure_used: PBL
  referents_used: [competition BBQ circuit]
  next_lesson_seed: "Lesson 05 takes the retention claim Claude flagged as unverifiable-from-chat in Cycle 2 and actually verifies it against doc-set section 5, plus verifies the grant-report Outcomes claims against the real export file."

RUBRIC SELF-AUDIT

# Indicator Verdict Evidence
R1 ONE Bloom's-leveled objective, ≥1 named standard PASS single Apply-level objective; AIHC.1.A3 named
R2 Platform claims traced; gaps named PASS §7 (content classifiers, deletion protection) quoted verbatim; retention control's existence explicitly left unverified, not asserted
R3 3–6 SSD cycles complete PASS 4 cycles, SAY/SEE/DO each
R4 SEEs ground-truth-verified PASS Cycle 2's illustrative answer is explicitly labeled illustrative, not a claimed transcript (rubric R5's fictional-labeling clause applied here since no real elicitation session exists in this demo); Cycle 4's risk list quotes §7 exactly
R5 DOs on real artifacts PASS all 4 DOs run on Devon's real workflows/specs from Lessons 01–03
R6 Media doctrine (static) PASS all SEEs static diagrams/callouts/tables
R7 Exit ticket climbing, SSOT-graded PASS 5 Qs Remember→Analyze, graded against doc-set §7 and his own L01 findings
R8 Ledger: standards + both scores + journal PASS present
R9 Band-1 scaffolding with fade; at-bat independent PASS exact question phrasing given in C2, progressively less framing by C4; at-bat runs the full move with no scaffold
R10 Referents elected + flavor-only PASS BBQ pitmaster analogy used once, non-load-bearing
R11 Option-suppression honored PASS Cycle 2 gives one recommended question phrasing; alternates noted as available, not enumerated
R12 Non-replication PASS elicitation targets are Devon's specific spec gaps and workflows from Lessons 01–03
R13 Enforcement gap named PASS Cycle 3 explicitly states Claude cannot verify the admin console from inside chat — the lesson does not let an elicited "no objection" stand in for a verified console state

Escalation check: no load-bearing indicator fails → auto-ships.