ai-governancelisted
Install: claude install-skill guerrilla2799/ops-and-scale-os
# AI Governance
The policy layer. Written before the rollout, because the alternative is a policy written after an incident, and those policies are always worse.
## When to use
- Before AI reaches a GTM team at any scale
- Somebody discovers reps pasting customer data into a consumer chatbot
- Legal, security, or a works council asks what the policy is
- Adoption is being blocked by fear rather than by capability
- Procurement or a customer security review asks about AI use
## Inputs
- Needs from user: which tools people are already using (ask without consequence, or you get a false answer), what customer data exists, contractual and regulatory obligations, and whether any staff are represented
- Reads: `workspace/agents/context/guardrails.md`
## Workflow
### 1. Survey the shadow AI first, and make it safe to answer
People are already using AI. A policy written as though they are not is a policy about an imaginary company.
Ask what tools are in use, for what, with what data, and state explicitly that the answer carries no consequence. An amnesty gets you the truth. A compliance-framed question gets you silence and the behavior continues unobserved.
The findings are usually: a consumer chatbot with customer names in it, a meeting recorder nobody approved, an unvetted writing tool with a browser extension, and one person running something genuinely useful that should be sanctioned and shared.
### 2. Draw the data boundary as three tiers
The most-used part of the polic