{"slug":"legal-hr-risk-taxonomy","title":"legal-hr-risk-taxonomy","summary":"Use this skill to assign consistent risk labels to a Legal or HR matter — severity ratings, privilege and privacy sensitivity labels, retaliation and discrimination risk labels, matter-type classes, escalation-gate triggers, and the audit-log schema. It standardizes the vocabular","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-10-05T21:52:01.692635Z","repo":{"url":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","stars":24,"forks":3,"license":"Apache-2.0","updatedAt":"2026-10-05T13:00:24Z"},"bodyHtml":"<h1>\uD83C\uDFF7️ Legal-HR Risk Taxonomy</h1>\n<p>The <strong>risk taxonomy</strong> defines the shared vocabulary for legal and HR risk assessment — severity scales, sensitivity labels, escalation-grade matter types, escalation gates, and minimum-necessary audit-log schema. It enables agents to speak the same language and escalate with precision.</p>\n<h2>What is the risk taxonomy?</h2>\n<p>A structured reference that specifies:</p>\n<ul>\n<li><strong>5-level severity scale</strong> (Critical → High → Medium → Low → Informational) with clear business-impact definitions</li>\n<li><strong>Privilege, privacy, and retaliation sensitivity labels</strong> — data classification to control what can be disclosed, who can view case context, and when escalation is mandatory</li>\n<li><strong>Escalation-grade matter types</strong> — a list of matters (retaliation allegations, data breaches, whistleblower reports, executive misconduct, securities violations) that trigger automatic counsel/board escalation</li>\n<li><strong>Escalation gates</strong> — thresholds and decision rules that mandate senior human involvement</li>\n<li><strong>Minimum-necessary audit-log schema</strong> — structured fields every Legal and HR agent must emit to the audit trail</li>\n</ul>\n<p>See <a href=\"references/risk-labels.md\"><code>references/risk-labels.md</code></a> for the complete specification, enumeration of matter types, label definitions, and the audit-log schema.</p>\n<h2>The severity scale</h2>\n<table>\n<thead>\n<tr>\n<th>Level</th>\n<th>Definition</th>\n<th>Legal example</th>\n<th>HR example</th>\n<th>Next action</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>Critical</strong></td>\n<td>Board-level incident; regulatory exposure; imminent legal jeopardy</td>\n<td>Patent infringement by key competitor entering market; major data breach affecting thousands of customers</td>\n<td>Executive misconduct allegation; whistleblower report of systemic discrimination; mass layoff with retaliation risk</td>\n<td>Immediate counsel + board escalation</td>\n</tr>\n<tr>\n<td><strong>High</strong></td>\n<td>Material legal or HR risk; requires counsel or senior HR review; potential litigation or regulatory investigation</td>\n<td>Wrongful-termination exposure; contract breach by vendor; regulatory licensing gap</td>\n<td>Wrongful termination exposure; retaliation risk in termination; high-risk accommodation denial</td>\n<td>Escalate to employment counsel or CHRO within 24 hours</td>\n</tr>\n<tr>\n<td><strong>Medium</strong></td>\n<td>Process improvement needed; no immediate jeopardy; senior review recommended</td>\n<td>Contract clause ambiguity; IP assignment gap in contractor agreement</td>\n<td>Pay-equity anomaly; performance-plan defensibility concern</td>\n<td>Escalate to counsel/senior HR; schedule review within a week</td>\n</tr>\n<tr>\n<td><strong>Low</strong></td>\n<td>Informational; no immediate action required; routine guidance</td>\n<td>Routine contract renewal; standard vendor audit</td>\n<td>Routine scheduling conflict; policy-interpretation question</td>\n<td>Route to the right specialist; no escalation required</td>\n</tr>\n<tr>\n<td><strong>Informational</strong></td>\n<td>Informational only; logged for completeness</td>\n<td>Regulatory guidance update; industry trend</td>\n<td>Engagement survey result; policy reminder</td>\n<td>Log and distribute</td>\n</tr>\n</tbody>\n</table>\n<h2>Sensitivity labels</h2>\n<p>Every Legal and HR matter is labeled with one or more sensitivity markers that control disclosure:</p>\n<ul>\n<li><strong>attorney-client-privilege</strong> — information protected from disclosure under legal privilege; must not be shared downstream without counsel approval</li>\n<li><strong>work-product-doctrine</strong> — analysis, strategy, or litigation advice; protected under work-product doctrine</li>\n<li><strong>medical-information</strong> — employee medical records, disability status, medical leave reason; must be minimized and access-controlled</li>\n<li><strong>protected-characteristic-data</strong> — age, race, gender, religion, national origin, disability, genetic information; must be minimized and access-controlled</li>\n<li><strong>whistleblower-report</strong> — information from a whistleblower; mandatory confidentiality and retaliation-risk escalation</li>\n<li><strong>retaliation-risk</strong> — an action that, if taken without review, could trigger retaliation claims; automatic escalation</li>\n<li><strong>data-breach-material</strong> — involves a data breach or loss of regulated data; automatic regulatory and counsel escalation</li>\n<li><strong>executive-misconduct</strong> — conduct by executives or board members; automatic board and counsel escalation</li>\n</ul>\n<h2>Escalation-grade matter types</h2>\n<p>The following matter types <strong>automatically trigger escalation</strong> (counsel, CHRO, CFO, or board as appropriate):</p>\n<ul>\n<li>Retaliation allegations or risk</li>\n<li>Discrimination or harassment allegations</li>\n<li>Whistleblower reports</li>\n<li>Executive or board-member misconduct</li>\n<li>Data breaches or regulatory notifications</li>\n<li>Litigation holds or subpoena response</li>\n<li>Securities-law materiality (IPO, acquisitions, public disclosures)</li>\n<li>Mass layoffs or restructurings with adverse-impact risk</li>\n<li>Third-party claims (breach of contract, IP infringement, product liability)</li>\n<li>Regulatory agency contact or investigation</li>\n</ul>\n<h2>Escalation gates</h2>\n<p>Escalation gates are decision thresholds. When a matter hits a gate, human approval is mandatory:</p>\n<ol>\n<li><strong>Severity ≥ High</strong> → escalate to counsel (legal) or CHRO (HR)</li>\n<li><strong>Any sensitivity label</strong> → escalate to the gate owner (e.g., whistleblower → board; executive misconduct → CEO + board)</li>\n<li><strong>Matter type is escalation-grade</strong> → escalate automatically</li>\n<li><strong>Time-critical or irreversible action</strong> → escalate before execution</li>\n<li><strong>Cross-domain matter</strong> → escalate to maestro router; both domains approve</li>\n<li><strong>Disagreement between specialists</strong> → escalate to counsel + CHRO</li>\n<li><strong>Regulatory or board trigger</strong> → escalate to general counsel + CFO + board</li>\n</ol>\n<h2>Audit-log schema</h2>\n<p>Every Legal and HR agent must emit the following minimum-necessary audit-log entry:</p>\n<pre><code>{\n  \"agent_id\": \"legal-privacy-data-protection-agent\",\n  \"matter_id\": \"MTR-2025-00041\",\n  \"timestamp\": \"2025-05-19T14:23:45Z\",\n  \"severity\": \"High\",\n  \"sensitivity_labels\": [\"attorney-client-privilege\", \"data-breach-material\"],\n  \"decision\": \"Flag DPIA gap; escalate to counsel before proceeding with cross-border transfer\",\n  \"evidence_level\": \"Strong\",\n  \"open_questions\": [\"Scope of DPIA if only metadata is transferred\", \"Adequacy decision status in target jurisdiction\"],\n  \"safe_next_actions\": [\"Retain outside DPA counsel\", \"Schedule adequacy-decision research\"],\n  \"decision_owner\": \"Chief Privacy Officer\",\n  \"do_not_do_list\": [\"Do not proceed with cross-border transfer without adequate decision\", \"Do not disclose PII without DPIA completion\"]\n}\n</code></pre>\n<p>See <a href=\"references/risk-labels.md\"><code>references/risk-labels.md</code></a> for the complete schema and worked examples.</p>\n<h2>Cross-references</h2>\n<ul>\n<li><a href=\"SKILL.md\"><code>SKILL.md</code></a> — the skill prompt for risk assessment and taxonomy application</li>\n<li><a href=\"references/risk-labels.md\"><code>references/risk-labels.md</code></a> — complete specification, matter-type enumeration, label definitions, audit-log examples</li>\n<li><a href=\"/docs/architecture/legal-hr-agent-routing.md\"><code>docs/architecture/legal-hr-agent-routing.md</code></a> — how escalation gates feed into routing decisions</li>\n<li><a href=\"/skills/cross-functional/legal-hr-case-capsule/\"><code>skills/cross-functional/legal-hr-case-capsule</code></a> — case capsule carries severity and sensitivity labels</li>\n</ul>\n<hr>\n<p><em>The risk taxonomy is part of the vanguard frontier's cross-functional protocol layer. It ensures Legal and HR agents rate risk in the same language and escalate with precision.</em></p>\n","files":[{"path":"metadata.json","sizeBytes":1156,"isText":true},{"path":"README.md","sizeBytes":7096,"isText":true},{"path":"references/risk-labels.md","sizeBytes":3747,"isText":true},{"path":"SKILL.md","sizeBytes":4564,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-10-05T21:56:27.935033Z","sha256":"5B4D4D555C7D6E01CFF3B0F7CFA07BA98B434AEB55FC6C2A611BF4B9609E7298","sizeBytes":7506},"review":null,"source":{"repositoryUrl":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","path":"skills/cross-functional/legal-hr-risk-taxonomy","license":"Apache-2.0","commit":"febe32a08e78fd06b1e466187410d673f1958d87","subtreeSha":"932303049BBE59FBC4EDF9D851F5384DF235F78A487EB5EED1FE4654008A1517","lastSyncedAt":"2026-10-05T21:51:58.639905Z"},"reviewedAt":"2026-10-05T22:05:57.580483Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/legal-hr-risk-taxonomy"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart"},{"target":"git","command":"git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git"}]}