Source framework: GRC-PF-001 v1.0 · CL-PHASE-001 v1.0
Policy corpus: Protofire GRC Policy Repository v2026-04-16 (POL-001–017 · STD-101–110 · PR-208–210 · REG-501–513 · PLAN-701–703 · GL-304–305 · DPA-001 · MSA-001)
Phases covered: 1–12 · 42 checklist steps · Track A + Track B
Deployment target: Claude.ai Projects
Integrations: Google Drive · Slack · GitHub/GitLab · ClickUp
Last synced: 2026-07-15 (v2.2 — 2026 H1 threat delta + reviewed PR #1; see kaizen-meta-agent/kaizen-changelog.md)
| Skill | Role | Gate authority | Primary phases |
|---|---|---|---|
am-agent/SKILL.md |
Account Manager | Gate G1-A | 1, 2, 3, 12 |
no-agent/SKILL.md |
Node Owner | G1-A → G8 (all gates) | All |
vciso-agent/SKILL.md |
vCISO | Gate G4 (mandatory) + G7 | 1, 5, 9, 10 |
tl-agent/SKILL.md |
Technical Lead | G4, G5, G6, G7 | 5, 6, 8, 9, 11 |
pm-agent/SKILL.md |
Project Manager | Gate G3 (co-sign) | 4, 6, 7, 10 |
devops-agent/SKILL.md |
DevOps Engineer | Gate G6 (co-sign) | 4, 8, 9, 11 |
qa-agent/SKILL.md |
QA Engineer | Signs audit/test reports | 6, 8, 11 |
fin-agent/SKILL.md |
Finance / Billing | HS-05 hard stop owner | 3 + ongoing |
grc-manager-agent/SKILL.md |
GRC Manager | Programme operations | Ongoing |
dpo-agent/SKILL.md |
Data Protection Officer | G4-A (DPIA input) | 4, 8, 10, ongoing |
kaizen-meta-agent/SKILL.md |
Kaizen Meta-Agent | Improves all 10 above | Post-session |
- Gate G4 — invalid without BOTH TL + vCISO signatures
- Irreversibility Gate Record — invalid without ALL THREE: NO + TL + vCISO
- Phase 4 blocked until Gate G2 signed (HS-02 enforcement)
- vCISO = Aleksey Lekontsev — never substituted
- HS-01 (OFAC) — non-waivable; immediate stop; no further client contact (POL-009 §3)
- HS-05 (arrears >60d) — FIN agent triggers; NO makes stop-work decision
- SoD: NO = PM → DoE co-sign mandatory at all T2+ gates
- Author ≠ reviewer on all smart contract PRs (POL-004 §2.4)
- DPIA mandatory for T2+ engagements with EU personal data (POL-011 §6.1 · CL-409)
- Breach to CISO within 4h; supervisory authority within 72h (POL-011 §8 · PR-208)
- Key Compromise response — PR-210 (separate from breach notification PR-208)
- HS-08 — undecodable/mismatched/stale authorization or unattested/mobile signer endpoint: do not sign; non-waivable except decoded emergency pause path
- HS-09 — unverified high-risk counterparty/token/collateral: block onboarding, listing and limit increase; non-waivable
- High-risk transaction — CL-414 + transaction-intent record + pending-authorization inventory required
- Every session → micro-review (10 min)
- Every 5 sessions → full cycle (30 min)
- Monthly → pattern analysis via
kaizen-meta-agent/kaizen-changelog.md
Four optimization targets: A Triggering · B Decision logic · C Instructions · D Artifact templates
| Domain | Documents |
|---|---|
| Policies | POL-001–017, DAO-001 |
| Standards | STD-101–105, STD-110, S-109, S-115, OPS-001 |
| Procedures | L2-DEL-101, L2-RISK-102, L2-ASSURE-103, L2-INC-201, L2-VULN-202, L2-ACCESS-203, L2-CHANGE-205, PR-208, PR-209, PR-210 |
| Guidelines | GL-304, GL-305, L3-TEST-204 |
| Plans | PLAN-701 (Tabletop IR), PLAN-702 (BCP), PLAN-703 (DR) |
| Checklists | CL-PHASE-001, CL-409, CL-411, CL-414 |
| Registers | REG-501–513 |
| Legal templates | DPA-001, MSA-001 |
| Foundation | L0-1, L0-2, L0-4, L0-5, GRC-MASTER-001, GRC-PF-001, L1-ERM-001, L1-SDLC-003, L1-KEY-005 |