| name | u0612-security-human-approval-router |
| description | Build and operate the "Security Human Approval Router" capability for Security and Privacy. Trigger when this exact capability is needed in mission execution. |
Security Human Approval Router
Why This Skill Exists
We need this skill because production autonomy must default to least privilege and strong privacy. This specific skill directs high-risk decisions to the right humans quickly.
When To Use
Use this skill when the request explicitly needs "Security Human Approval Router" outcomes in the Security and Privacy domain.
Step-by-Step Implementation Guide
- Define the scope and success metrics for
Security Human Approval Router, including at least three measurable KPIs tied to breach, exfiltration, and over-privileged actions.
- Design and version the input/output contract for permissions, sensitive data flows, and threat events, then add schema validation and failure-mode handling.
- Implement the core capability using reviewer routing policies, and produce priority approval queues with deterministic scoring.
- Integrate the skill into swarm orchestration: task routing, approval gates, retry strategy, and rollback controls.
- Add unit, integration, and simulation tests that explicitly cover breach, exfiltration, and over-privileged actions, then run regression baselines.
- Deploy behind a feature flag, monitor telemetry/alerts for two release cycles, and iterate thresholds based on observed outcomes.
Required Deliverables
- Capability contract: input schema, deterministic scoring, output schema, and failure modes.
- Runtime profile: planning-router using reviewer routing policies to produce priority approval queues.
- Orchestration integration: security-and-privacy:planning-router routing, approval gates, retries, and rollback controls.
- Validation evidence: unit, integration, simulation, regression-baseline suites and rollout telemetry.
Operational Runbook
Preflight
- Confirm the Security Human Approval Router request scope, source evidence, and measurable success criteria before execution.
- Verify feature flag skill_0612_security-human-approval-router, approval gates, and rollback owner before autonomous use.
Execution
- Execute reviewer routing policies with deterministic scoring and reproducible trace capture.
- Produce priority approval queues plus scorecard, assumptions, and unresolved-risk notes.
Recovery
- Fail closed when required signals, evidence, or approval gates are missing.
- Rollback to the last stable baseline when posture is critical or validation fails.
Handoff
- Publish priority approval queues, validation evidence, and telemetry links to downstream owners.
- Queue follow-up tasks for unresolved risks, threshold tuning, or approval review.
Guardrails
- [quality] Require deterministic scoring and validation evidence before promotion.
- [reliability] Preserve retries, rollback controls, and failure-mode evidence for every run.
- [safety] Route critical posture or missing approval gates to human review before autonomous action.