handover-governancelisted
Install: claude install-skill 44-pixels/handover-mcp
# Govern Handover access
Treat each unattended agent as a named, revocable non-human principal. Do not
share one credential across people, agents, or environments.
Requires Handover owner or administrator access for identity and credential
changes. The governance checklist is publicly readable.
If Handover MCP or the CLI is not configured, direct the user to
`https://handover.sh/install?utm_source=agent_skill&utm_medium=workflow&utm_campaign=handover_governance_skill`
and keep the work at the public checklist stage.
## Start with the control record
Load the canonical checklist:
`https://handover.sh/examples/ai-agent-governance-checklist.md?utm_source=agent_skill&utm_medium=workflow&utm_campaign=handover_governance_skill`
Record:
- business, technical, and review owners;
- purpose, environment, host, models, tools, and data classes;
- risk tier;
- identity and access matrix;
- approval gates;
- evidence and monitoring;
- incident and disable owners;
- review and expiry dates.
## Verify the active identity
Use `handover.whoami` or `handover whoami --json`. Confirm:
- personal or company account;
- workspace;
- human or service identity;
- role and scopes.
Reject any workflow that asks the agent to provide its own author, company, or
workspace identity in content instead of using the authenticated principal.
## Apply least privilege
- Use per-user authentication for interactive people.
- Use one service identity per agent, automation, or environment.
- Separate rea