Use when producing or updating AI-agent compliance operations runbook for control testing, evidence collection, drills, audit-window operations, and remediation. Use agent-runbook for the neighbouring concern; this skill owns the named document contract and its acceptance evidence.
Use when producing or updating AI-agent compliance operations runbook for control testing, evidence collection, drills, audit-window operations, and remediation. Use agent-runbook for the neighbouring concern; this skill owns the named document contract and its acceptance evidence.
Failures and unavailable checks cannot appear as passes.
Review record
Reviewer, date, disposition, open actions
The consumer can reproduce the acceptance decision.
Capability and Permission Boundaries
Minimum capabilities: read and search the authorised project sources. Execution is optional and limited to non-destructive validation.
Inspection is read-only by default. Create or edit the named project document only when explicitly authorised. Production mutation, publishing, destructive action, spending, external communication, or certification claims require separate explicit authority.
Treat secrets, tenant data, incident evidence, and financial records as least-privilege inputs; expose only the minimum evidence needed for review.
Degraded Mode
If files, execution, network, rendering, environment access, fonts, or current evidence are unavailable, return the narrowest useful draft plus a gap register. Label affected checks not assessed, retain the intended acceptance oracle, and state who must supply or verify the missing evidence. Never convert an unavailable check into a pass.
Decision Rules
Choice
Action
Failure or risk avoided
Evidence is complete and authority is explicit
Choose cadence from control requirement and evidence freshness and produce the full artefact.
Audit-time evidence scrambles or untested controls.
A required source or approval is missing
Stop the affected branch; record the gap, owner, and unblock condition.
Fabricated requirements or unauthorised action.
Evidence conflicts across sources
Preserve both claims, identify the controlling owner, and request a recorded decision.
Silent selection of a convenient but wrong source.
A check cannot run in the available environment
Keep its oracle and mark it not assessed; require later execution evidence.
False assurance from capability limits.
Workflow
Confirm the named deliverable, consumer, scope, environment, authority, and neighbouring-skill boundary.
Inventory required sources and validate provenance, freshness, internal consistency, and missing inputs. Stop the affected branch on a mandatory gap.
Extract traceable requirements, invariants, risks, and measurable acceptance criteria; record conflicts before choosing a design or procedure.
Apply the decision rules and the domain workflow below. For a failed branch, preserve evidence, choose the documented recovery path, or escalate to the named owner.
Draft the artefact, decision register, and evidence record together. Do not defer failure handling, rollback, security, tenancy, accessibility, or operational ownership.
Run available checks, review every result, repair failures, and hand off only when acceptance is observable. If recovery fails or authority is exceeded, stop and escalate without mutation.
Quality Standards
Ground every section in a named project source, decision, measured result, or accountable owner.
Give each requirement or procedure a deterministic oracle that another reviewer can reproduce.
Keep assumptions, exclusions, degraded checks, residual risks, and waivers visible at handoff.
Preserve the domain invariants and more specific controls in the existing workflow below; this contract does not replace them.
Run the repository anti-AI-slop gate: remove filler, verify named standards and dependencies, and retain purposeful domain detail.
Anti-Patterns
Copying a generic template without mapping it to project sources. Fix: attach each section to an approved requirement, configuration, risk, or owner.
Choosing a threshold because it is common practice. Fix: derive it from a requirement, measured baseline, risk decision, or current verified source.
Reporting an inaccessible or unexecuted check as passed. Fix: mark it not assessed, preserve the oracle, and name the verifier.
Mixing the neighbouring agent-runbook concern into this artefact without a boundary. Fix: cross-reference its output and keep ownership explicit.
Omitting failure, rollback, empty-state, security, tenancy, or escalation behaviour. Fix: specify the trigger, safe action, verification, and owner for each applicable case.
Mutating a repository, environment, tenant, ledger, or external system while drafting guidance. Fix: remain read-only until the exact mutation and authority are explicit.
Claiming compliance, certification, readiness, or release from prose alone. Fix: require source-attributed evidence and a named acceptance decision.
Worked Example
Given an approved project source and a conflicting implementation detail, record both with provenance, stop the affected branch, and obtain the accountable owner's decision. Then update the relevant contract, define a reproducible acceptance check, and retain its observed result. The artefact is accepted only when every control activity has an owner, cadence, evidence object, exception path, and closure verification.
References
logic.prompt - load only when its template, logic, or detail is needed.
README.md - load only when its template, logic, or detail is needed.
Overview
The compliance runbook converts the control packs, policy pack, evidence pack spec, and attestation prep spec into a calendar-driven operating procedure: who does what, when, with what artefact. It is the daily / weekly / monthly / quarterly / annual heartbeat that keeps compliance posture continuous.
Quick Reference
Attribute
Value
Inputs
SOC 2 / ISO / HIPAA control packs, Policy Pack, Evidence Pack Spec, Attestation Prep Spec, Agent Runbook, AI Incident Response Runbook
When the auditor walks in (or joins the video call):
Compliance Manager confirms auditor identity; activates portal access for named recipient; logs activation.
Demoer roster confirmed; back-up demoers on standby.
Walkthrough order set with auditor.
Each walkthrough follows the auditor on-the-day playbook (24-ai-agent-attestation-preparation-spec/references/ai-agent-auditor-on-the-day-playbook.md).
Action items recorded as they arise; closure target before auditor leaves where possible.
End of day: portal access reduced to read-only; debrief held.
Step 6: Gap-remediation cadence
Severity
Definition
SLA
Owner
SEV1
Mandatory control without evidence; control failed during the window
7 days
AI Lead + CTO
SEV2
Evidence incomplete; sampling not yet attainable
30 days
AI Lead
SEV3
Documentation polish; cross-link missing
90 days
Compliance Manager
Step 7: Roles
Role
Responsibility
AI Lead
Compliance posture for agent features; evidence custodian; demoer for governance and approval walkthroughs
CTO
Change management sample; system architecture walkthrough
CISO
Kill-switch drill owner; security control walkthroughs