skills/agent-authority-charter-builder-arkadiy-miteiko/SKILL.md
Creates an Agent Authority Charter for enterprise or regulated AI agents before deployment. Use this Skill when a user needs to define what an AI agent is allowed to do, who delegated authority to it, what actions are permitted or prohibited, when human approval is required, what evidence must be preserved, and how the agent can be suspended, revoked, or escalated.
npx skillsauth add lawvable/awesome-legal-skills agent-authority-charter-builder-arkadiy-miteikoInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This Skill helps legal, compliance, risk, product, operations, and AI governance teams create an Agent Authority Charter before an AI agent is deployed into an enterprise or regulated workflow.
The purpose is not to decide whether an AI system is generally ethical, safe, or compliant. The purpose is narrower and more operational:
Define what institutional authority the agent has before it acts.
The Skill converts a proposed AI agent use case into a structured, reviewable governance artifact covering:
The final output should be suitable for review by legal, compliance, risk, security, business, audit, and technical stakeholders.
An AI agent should not be governed only by what it can technically do.
It must be governed by what the institution has authorized it to do.
The charter must answer:
Use this Skill when the user asks to:
Use this Skill even if the user phrases the request informally, such as:
Do not use this Skill to:
If the user asks for legal conclusions, state that the output is a governance drafting aid and should be reviewed by qualified counsel and the appropriate institutional authority.
Collect as many of the following inputs as possible. If the user does not provide enough information, proceed with reasonable assumptions but mark missing items as “To be confirmed.”
Possible agent types include:
Identify who or what delegates authority to the agent.
Authority may come from:
If the source of authority is unclear, mark the charter as not deployment-ready.
Identify:
Define what the agent may do:
Examples of permitted actions:
Define what the agent may not do.
Examples of prohibited actions:
Classify each agent action into one of the following authority tiers.
The agent may read, summarize, classify, or flag information. It may not alter records, trigger workflows, make decisions, communicate externally, or create business consequences.
The agent may draft, structure, recommend, or queue actions for human review. It may not execute the action without human approval.
The agent may perform low-risk internal actions within clearly defined thresholds. The action must be logged and reversible where possible.
The agent may prepare or initiate consequential actions only after explicit human approval. The approval must be preserved as part of the evidence record.
The agent may not perform these actions. They require human, legal, compliance, board, regulator, or other institutional authority.
Follow this process when creating the charter.
Determine whether the agent is assisting a human or exercising delegated authority.
Ask:
Classify the agent as:
The charter should never say “the agent is authorized” without identifying who or what authorized it.
Document:
If authority is unclear, state:
“Not ready — authority source not established.”
The agent may be technically capable of many actions. Only some actions are institutionally authorized.
Create a table with three columns:
| Technical Capability | Authorized Use | Required Control | |---|---|---|
Example:
| Technical Capability | Authorized Use | Required Control | |---|---|---| | Send email | Draft only, no autonomous send | Human approval required | | Update CRM | Add internal note only | Log entry required | | Approve refund | Up to approved threshold only | Evidence pack required | | Deny claim | Not authorized unless specifically approved | Human decision required |
Classify each action into Tier 0 through Tier 4.
Use conservative classification when the facts are unclear.
Any action involving legal, financial, medical, employment, credit, insurance, public-sector, customer-harm, or external commitment consequence should default to Tier 3 or Tier 4 unless the user provides a specific approved threshold and authority source.
For each action requiring human approval, define:
The charter must specify when the agent must stop and escalate.
Escalation triggers may include:
Write escalation rules in operational language.
Good example:
“The agent must escalate if the requested refund exceeds the approved threshold, if the customer account has an open dispute, or if the agent cannot identify a policy basis for the action.”
Weak example:
“The agent should escalate when the matter is risky.”
For each action tier, define minimum evidence.
Suggested baseline:
| Tier | Minimum Evidence | |---|---| | Tier 0 | Timestamp, request, source records, generated output | | Tier 1 | Timestamp, request, source records, draft or recommendation, reviewer identity | | Tier 2 | Timestamp, authority source, constraints applied, action taken, affected record, audit log | | Tier 3 | Tier 2 evidence plus human approval, approval rationale, escalation history | | Tier 4 | Prohibited action log, denial reason, escalation record |
Evidence should include:
The charter must define when the agent’s authority must be suspended or revoked.
Examples:
Define:
Choose one readiness status:
Use the conservative status when facts are incomplete.
When using this Skill, produce the following artifact.
Status options:
Classify the agent as one of:
Explain why.
Describe the workflow in which the agent may operate.
Include:
| Technical Capability | Authorized Use | Required Control | |---|---|---|
| Action | Authority Tier | Human Approval Required? | Conditions | Evidence Required | |---|---:|---|---|---|
| Prohibited Action | Reason | Required Escalation | |---|---|---|
Define:
| Trigger | Required Agent Behavior | Escalation Recipient | Evidence to Preserve | |---|---|---|---|
Define:
Define:
| Issue | Risk Level | Owner | Required Resolution | |---|---|---|---|
Risk levels:
Choose one:
Include a short rationale.
Provide a short summary of the main authority risks, including:
List all important missing information as “To be confirmed.”
List any issues that prevent deployment.
If none are identified, state:
“No deployment blockers were identified based on the information provided, but this does not constitute legal, compliance, risk, or security approval.”
Recommend which stakeholders should review the charter:
Add this notice at the end of every charter:
“This Agent Authority Charter is a governance drafting aid. It does not constitute legal advice, regulatory approval, or final institutional authorization. Deployment should be reviewed by the appropriate legal, compliance, risk, security, technical, and business authorities.”
The output must be:
Avoid vague language such as:
Replace vague language with specific authority, threshold, evidence, and escalation rules.
If the agent can create legal, financial, operational, customer, employee, patient, citizen, market, public-sector, or external consequence, and the user has not identified a clear authority source, mark the charter:
“Not ready — authority source not established.”
If information is incomplete, choose the more restrictive authority tier.
If a proposed action could bind the organization, affect a person’s rights, change money movement, alter legal status, affect regulated records, or create external reliance, classify it as Tier 3 or Tier 4 unless the user provides a clear authority source and approved threshold.
When returning the charter, include:
Do not overstate certainty. Do not state that the agent is approved unless the user has provided an actual approval source.
“We are deploying an AI agent to review customer refund requests. It can read support tickets, check order history, recommend a refund decision, and update the CRM. It should approve small refunds automatically but escalate larger ones.”
The assistant should produce an Agent Authority Charter that:
development
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
development
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
tools
Build a client instruction schedule — a plain-English, Scott Schedule-style Word table that gathers a struggling client's evidence and instructions issue by issue, with a one-page covering note. Use whenever the user asks for a "client instruction schedule", "instruction schedule", "client questionnaire", "schedule of questions for the client", "get instructions from the client on the papers", or says the client is overwhelmed and needs the case broken into manageable questions. Also trigger when asked to turn case papers into a structured request for client input. Do NOT use for court-facing Scott Schedules, pleadings, witness statements, or advice letters — this skill produces a client-facing working document only. Output is always a .docx draft for solicitor review, never a final document.
tools
Turn complex legal analysis into clear, commercially useful client-facing advice. Use this whenever the user has dense legal material — drafting, internal analysis, counsel notes, research memos, pleadings, a case update, or correspondence — and wants it converted into something a client can actually understand and act on. Trigger on phrases like 'explain this to the client', 'put this in plain English', 'translate this for a non-lawyer', 'turn this into client-facing advice', 'make this client-ready', 'draft a client update', or when the user shares legal analysis and asks 'what does this mean for them'. Also trigger when the user wants a board summary, litigation risk update, or call script derived from legal material. The skill preserves legal nuance, uncertainty, and risk rather than oversimplifying — it makes advice usable, not just simpler.