Claude Cursor GitHub Copilot Skill

legal-hr-case-capsule

Use this skill when a Legal or HR agent must hand a matter to another agent and the context, uncertainty, evidence quality, privilege posture, and privacy posture must survive the handoff. It defines the shared legal-hr-case-capsule — a controlled, auditable exchange record with

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_cross-functional_legal-hr-case-capsule-febe32a.zip · 6 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/legal-hr-case-capsule
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

README

📦 Legal-HR Case Capsule

The case capsule is the single, auditable handoff contract for Legal and HR agentic coordination. When a matter crosses a boundary — an HR investigation that needs privileged legal review, or a legal litigation hold that triggers an HR data freeze — the case capsule carries a structured, redacted payload between agents while preserving privilege, minimizing personal data, and recording the escalation path.

What is a case capsule?

A 30-field structured handoff contract that:

  • Carries facts and risk posture, never an authorization or final decision
  • Minimizes personal and sensitive data through explicit redaction rules
  • Preserves legal and HR privilege with mandatory do-not-disclose markers
  • Names one decision owner — the human responsible for the next action
  • Enforces a do-not-do list — irreversible actions that are explicitly forbidden until human sign-off

See SKILL.md for the skill itself, and references/capsule-schema.md for the complete 30-field specification, redaction rules, and a worked example.

Why a case capsule?

Without a case capsule, agents would improvise handoffs — dumping raw case context, leaking personal data, losing track of who said what, and creating audit gaps. The case capsule is the guardrail: it enforces a shape, a payload contract, and a privilege boundary.

Every handoff is auditable: an auditor, a regulator, or opposing counsel can trace exactly what facts moved between agents, why, and who approved the motion.

For Legal agents

When your review reveals an HR issue (wrongful termination exposure, discrimination risk, retaliation red flag), you hand off to HR via a case capsule. The capsule says "here's what I found, here are the privilege markers, here's who owns the next step, here's what we must NOT do without consent."

For HR agents

When your review reveals a legal issue (whistleblower report, conflict of interest, anti-bribery exposure), you hand off to Legal via a case capsule. The capsule carries the HR context without leaking the employee's medical history, protected-characteristic data, or confidential HR files.

Vault principles

  • Redaction is mandatory. Every field has a redaction rule; no field carries unredacted personal data unless explicitly required.
  • Privilege is explicit. Mandatory attorney_client_privilege and work_product_doctrine labels control what can be disclosed downstream.
  • One human owner. Every handoff names a single decision_owner (a real person's title or role) who is accountable for the next irreversible action.
  • Refusal by default. The case capsule carries a do_not_do_list — explicit, non-empty actions that are forbidden until human approval.

Cross-references


The case capsule is part of the vanguard frontier's cross-functional protocol layer. It enables agentic coordination that survives audit and legal scrutiny.

Skill manifest

Legal-HR Case Capsule

Purpose

This skill defines the legal-hr-case-capsule — the single structured record that Legal and HR agents exchange when a matter crosses an agent boundary. The capsule exists so that no agent works in a silo, no context is lost in a handoff, and every cross-domain exchange is auditable. It is a data contract, not a decision: a capsule never approves, denies, or directs an action. It carries facts, uncertainty, risk posture, and an explicit decision owner.

When to use

  • A maestro agent routes a matter to one or more specialist agents.
  • A specialist agent escalates a matter that has crossed into another domain.
  • Any matter touches both Legal and HR risk and must be reviewed in parallel.
  • A matter must be paused and escalated to a human owner.

Core rules

  • Every cross-agent handoff MUST be expressed as a capsule. No free-form agent-to-agent chatter.
  • Every capsule MUST name exactly one decision_owner (an accountable human) and exactly one primary_agent.
  • Every capsule MUST carry a do_not_do_list. An empty list is not acceptable; if nothing is prohibited, the capsule is not ready to send.
  • Every capsule MUST label privilege_sensitivity and privacy_sensitivity.
  • Identifiers MUST be redacted to the minimum necessary. Use role and business-unit references, not names, government IDs, or contact details.
  • A capsule records uncertainty honestly: assumptions, inferences, and missing_evidence are mandatory fields, not optional.
  • A capsule never states "this is legal", "this is compliant", or "this action is approved". risk_rating uses risk language only.
  • High-risk cross-domain capsules MUST set escalation_required: true and recommended_next_action to a pause-and-escalate posture unless documented controls already exist.

Capsule field set

The capsule has 30 required fields. See references/capsule-schema.md for the full field definitions, allowed values, and redaction rules. Summary:

  • Identity and routing: case_id, source_agent, receiving_agent, primary_agent, secondary_agents, matter_type, employee_or_party_identifiers_redacted, jurisdiction_or_location_if_known, business_unit, timeline.
  • Evidence discipline: facts, allegations, assumptions, inferences, missing_evidence, evidence_quality.
  • Risk posture: risk_rating, privilege_sensitivity, privacy_sensitivity, retaliation_risk, discrimination_or_harassment_risk, regulatory_risk, litigation_hold_needed, data_minimization_notes.
  • Ownership and action: decision_owner, human_approval_required, escalation_required, recommended_next_action, do_not_do_list, audit_log_summary.

References

Load only when needed:

Security notes

  • The capsule is a minimum-necessary record. Never widen it to carry medical records, government IDs, credentials, privileged email text, or protected-class data beyond what the matter strictly requires.
  • A capsule that would extend the circulation of privileged or investigation material must be narrowed before it is sent; flag privilege explicitly.
  • The capsule never authorizes action. Any field that reads as a directive to terminate, discipline, settle, file, notify a regulator, or send an employee communication is a defect — rewrite it as a recommendation with a named human owner.
Files (vanguard-frontier-agentic)
  • references
    • capsule-schema.md 5.7 KB
      # Legal-HR Case Capsule — Schema and Redaction Rules
      
      The capsule is the only sanctioned cross-agent handoff record. It has 30
      required fields. A capsule with any field omitted, blank, or set to a
      placeholder is not ready to send.
      
      ## Field definitions
      
      ### Identity and routing
      
      | Field | Type | Rule |
      |---|---|---|
      | `case_id` | string | Stable opaque identifier. No employee name, no email. |
      | `source_agent` | string | Agent id that produced this capsule. |
      | `receiving_agent` | string | Agent id this capsule is handed to. |
      | `primary_agent` | string | The single agent accountable for synthesis. Exactly one. |
      | `secondary_agents` | string[] | Agents running parallel review. May be empty. |
      | `matter_type` | enum | See risk taxonomy `matter_type` values. |
      | `employee_or_party_identifiers_redacted` | string | Role + business unit only, e.g. "IC engineer, BU-West". Never a name or ID. |
      | `jurisdiction_or_location_if_known` | string | Country / state / "Unknown". |
      | `business_unit` | string | Org unit reference, not a person. |
      | `timeline` | string | Dated sequence of events, effective dates, deadlines. |
      
      ### Evidence discipline
      
      | Field | Type | Rule |
      |---|---|---|
      | `facts` | string[] | Confirmed and corroborated only. |
      | `allegations` | string[] | Claims made but unproven; record who made each. |
      | `assumptions` | string[] | Treated as plausible but unverified. |
      | `inferences` | string[] | Conclusions drawn from facts; mark each as inference. |
      | `missing_evidence` | string[] | Materially relevant facts not provided. |
      | `evidence_quality` | enum | `strong` / `mixed` / `weak` / `insufficient`. |
      
      ### Risk posture
      
      | Field | Type | Rule |
      |---|---|---|
      | `risk_rating` | enum | `Critical` / `High` / `Medium` / `Low` / `Unknown`. |
      | `privilege_sensitivity` | enum | `none` / `possible` / `likely-privileged`. |
      | `privacy_sensitivity` | enum | `low` / `moderate` / `high` / `special-category`. |
      | `retaliation_risk` | enum | `none-observed` / `possible` / `elevated` / `unknown`. |
      | `discrimination_or_harassment_risk` | enum | `none-observed` / `possible` / `elevated` / `unknown`. |
      | `regulatory_risk` | enum | `none-observed` / `possible` / `elevated` / `unknown`. |
      | `litigation_hold_needed` | enum | `no` / `recommended` / `yes` / `unknown`. |
      | `data_minimization_notes` | string | What was excluded and why. |
      
      ### Ownership and action
      
      | Field | Type | Rule |
      |---|---|---|
      | `decision_owner` | string | Accountable human role, e.g. "Employment Counsel". Exactly one. |
      | `human_approval_required` | boolean | `true` for any adverse, irreversible, or cross-domain action. |
      | `escalation_required` | boolean | `true` whenever an escalation gate is triggered. |
      | `recommended_next_action` | string | A recommendation, never a directive. |
      | `do_not_do_list` | string[] | Explicit prohibited actions. Must be non-empty. |
      | `audit_log_summary` | string | One-line pointer to the audit-log event for this handoff. |
      
      ## Redaction rules
      
      1. Default to role + business-unit references. A name appears in a capsule only
         when a named human owner role requires it, and never an employee subject.
      2. No government IDs, no contact details, no credentials, no medical detail, no
         protected-class data unless the matter strictly requires it and the
         `privacy_sensitivity` field is set to `special-category` with a documented
         reason in `data_minimization_notes`.
      3. Privileged or investigation text is summarized, never pasted. If a capsule
         would extend circulation of privileged material, set `privilege_sensitivity`
         to `likely-privileged` and narrow the content.
      4. `do_not_do_list` always includes, at minimum, the actions outside agent
         authority: approve, deny, terminate, discipline, settle, file, notify a
         regulator, make a public disclosure, send an employee communication, or
         mutate an HR/legal system.
      
      ## Worked example (sanitized)
      
      ```json
      {
        "case_id": "CAP-2026-0142",
        "source_agent": "hr-maestro-agent",
        "receiving_agent": "hr-termination-readiness-agent",
        "primary_agent": "hr-termination-readiness-agent",
        "secondary_agents": ["legal-employment-law-risk-agent", "hr-employee-relations-agent"],
        "matter_type": "termination-with-retaliation-risk",
        "employee_or_party_identifiers_redacted": "IC engineer, BU-West",
        "jurisdiction_or_location_if_known": "Unknown",
        "business_unit": "BU-West Engineering",
        "timeline": "Complaint filed 2026-04-02; PIP opened 2026-04-09; termination proposed 2026-05-10",
        "facts": ["A PIP was opened", "A complaint was filed before the PIP"],
        "allegations": ["Manager states performance was failing pre-complaint (uncorroborated)"],
        "assumptions": ["PIP criteria were applied consistently with peers"],
        "inferences": ["Timing proximity could be read as retaliatory by a fact-finder"],
        "missing_evidence": ["Contemporaneous performance records predating the complaint", "Comparator data"],
        "evidence_quality": "weak",
        "risk_rating": "High",
        "privilege_sensitivity": "possible",
        "privacy_sensitivity": "moderate",
        "retaliation_risk": "elevated",
        "discrimination_or_harassment_risk": "unknown",
        "regulatory_risk": "possible",
        "litigation_hold_needed": "recommended",
        "data_minimization_notes": "Complaint text excluded; only sequence retained",
        "decision_owner": "Employment Counsel",
        "human_approval_required": true,
        "escalation_required": true,
        "recommended_next_action": "Pause the proposed termination; route to employment counsel for retaliation analysis",
        "do_not_do_list": ["Do not proceed with termination", "Do not backdate or retroactively create performance records", "Do not contact the complainant about the complaint"],
        "audit_log_summary": "EVT-2026-0142-03 capsule handoff hr-maestro -> termination-readiness"
      }
      ```
      
  • metadata.json 1.1 KB
    {
      "id": "legal-hr-case-capsule",
      "name": "Legal-HR Case Capsule",
      "type": "skill",
      "provider": "generic",
      "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"],
      "summary": "Shared, auditable handoff contract for Legal and HR agents — a redacted case capsule carrying facts, uncertainty, evidence quality, risk labels, privilege and privacy posture, a named decision owner, and an explicit do-not-do list. Does not give legal or HR advice.",
      "source_type": "original",
      "official_docs": [
        "https://www.nist.gov/privacy-framework",
        "https://www.eeoc.gov",
        "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
      ],
      "security_notes": "Defines a minimum-necessary handoff record; never carries medical records, government IDs, credentials, privileged email text, or protected-class data beyond what the matter requires. Never authorizes action; flags privilege and privacy posture and routes decisions to a named human owner.",
      "last_verified": "2026-05-18",
      "path": "skills/cross-functional/legal-hr-case-capsule",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • README.md 3.4 KB
    # 📦 Legal-HR Case Capsule
    
    The **case capsule** is the single, auditable handoff contract for Legal and HR agentic coordination. When a matter crosses a boundary — an HR investigation that needs privileged legal review, or a legal litigation hold that triggers an HR data freeze — the case capsule carries a structured, redacted payload between agents while preserving privilege, minimizing personal data, and recording the escalation path.
    
    ## What is a case capsule?
    
    A 30-field structured handoff contract that:
    - **Carries facts and risk posture**, never an authorization or final decision
    - **Minimizes personal and sensitive data** through explicit redaction rules
    - **Preserves legal and HR privilege** with mandatory do-not-disclose markers
    - **Names one decision owner** — the human responsible for the next action
    - **Enforces a do-not-do list** — irreversible actions that are explicitly forbidden until human sign-off
    
    See [`SKILL.md`](SKILL.md) for the skill itself, and [`references/capsule-schema.md`](references/capsule-schema.md) for the complete 30-field specification, redaction rules, and a worked example.
    
    ## Why a case capsule?
    
    Without a case capsule, agents would improvise handoffs — dumping raw case context, leaking personal data, losing track of who said what, and creating audit gaps. The case capsule is the guardrail: it enforces a shape, a payload contract, and a privilege boundary.
    
    Every handoff is auditable: an auditor, a regulator, or opposing counsel can trace exactly what facts moved between agents, why, and who approved the motion.
    
    ## For Legal agents
    
    When your review reveals an HR issue (wrongful termination exposure, discrimination risk, retaliation red flag), you hand off to HR via a case capsule. The capsule says *"here's what I found, here are the privilege markers, here's who owns the next step, here's what we must NOT do without consent."*
    
    ## For HR agents
    
    When your review reveals a legal issue (whistleblower report, conflict of interest, anti-bribery exposure), you hand off to Legal via a case capsule. The capsule carries the HR context without leaking the employee's medical history, protected-characteristic data, or confidential HR files.
    
    ## Vault principles
    
    - **Redaction is mandatory.** Every field has a redaction rule; no field carries unredacted personal data unless explicitly required.
    - **Privilege is explicit.** Mandatory `attorney_client_privilege` and `work_product_doctrine` labels control what can be disclosed downstream.
    - **One human owner.** Every handoff names a single `decision_owner` (a real person's title or role) who is accountable for the next irreversible action.
    - **Refusal by default.** The case capsule carries a `do_not_do_list` — explicit, non-empty actions that are forbidden until human approval.
    
    ## Cross-references
    
    - [`SKILL.md`](SKILL.md) — the skill prompt and scaffold for case-capsule composition
    - [`references/capsule-schema.md`](references/capsule-schema.md) — 30-field specification, redaction rules, worked example, and validation checklist
    - [`docs/architecture/legal-hr-agent-communication.md`](/docs/architecture/legal-hr-agent-communication.md) — cross-functional coordination principles, case capsule as the only channel, audit trail
    
    ---
    
    *The case capsule is part of the vanguard frontier's cross-functional protocol layer. It enables agentic coordination that survives audit and legal scrutiny.*
    
  • SKILL.md 4.2 KB
    ---
    name: legal-hr-case-capsule
    description: Use this skill when a Legal or HR agent must hand a matter to another agent and the context, uncertainty, evidence quality, privilege posture, and privacy posture must survive the handoff. It defines the shared legal-hr-case-capsule — a controlled, auditable exchange record with redacted identifiers, risk labels, privilege and privacy labels, a decision-owner field, and an explicit do-not-do list. It does not give legal or HR advice and does not authorize any action.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-18"
      category: compliance
      lifecycle: experimental
    ---
    
    # Legal-HR Case Capsule
    
    ## Purpose
    This skill defines the **legal-hr-case-capsule** — the single structured record
    that Legal and HR agents exchange when a matter crosses an agent boundary. The
    capsule exists so that no agent works in a silo, no context is lost in a
    handoff, and every cross-domain exchange is auditable. It is a data contract,
    not a decision: a capsule never approves, denies, or directs an action. It
    carries facts, uncertainty, risk posture, and an explicit decision owner.
    
    ## When to use
    - A maestro agent routes a matter to one or more specialist agents.
    - A specialist agent escalates a matter that has crossed into another domain.
    - Any matter touches both Legal and HR risk and must be reviewed in parallel.
    - A matter must be paused and escalated to a human owner.
    
    ## Core rules
    - Every cross-agent handoff MUST be expressed as a capsule. No free-form
      agent-to-agent chatter.
    - Every capsule MUST name exactly one `decision_owner` (an accountable human)
      and exactly one `primary_agent`.
    - Every capsule MUST carry a `do_not_do_list`. An empty list is not acceptable;
      if nothing is prohibited, the capsule is not ready to send.
    - Every capsule MUST label `privilege_sensitivity` and `privacy_sensitivity`.
    - Identifiers MUST be redacted to the minimum necessary. Use role and
      business-unit references, not names, government IDs, or contact details.
    - A capsule records uncertainty honestly: `assumptions`, `inferences`, and
      `missing_evidence` are mandatory fields, not optional.
    - A capsule never states "this is legal", "this is compliant", or "this action
      is approved". `risk_rating` uses risk language only.
    - High-risk cross-domain capsules MUST set `escalation_required: true` and
      `recommended_next_action` to a pause-and-escalate posture unless documented
      controls already exist.
    
    ## Capsule field set
    The capsule has 30 required fields. See
    [references/capsule-schema.md](references/capsule-schema.md) for the full field
    definitions, allowed values, and redaction rules. Summary:
    
    - Identity and routing: `case_id`, `source_agent`, `receiving_agent`,
      `primary_agent`, `secondary_agents`, `matter_type`,
      `employee_or_party_identifiers_redacted`, `jurisdiction_or_location_if_known`,
      `business_unit`, `timeline`.
    - Evidence discipline: `facts`, `allegations`, `assumptions`, `inferences`,
      `missing_evidence`, `evidence_quality`.
    - Risk posture: `risk_rating`, `privilege_sensitivity`, `privacy_sensitivity`,
      `retaliation_risk`, `discrimination_or_harassment_risk`, `regulatory_risk`,
      `litigation_hold_needed`, `data_minimization_notes`.
    - Ownership and action: `decision_owner`, `human_approval_required`,
      `escalation_required`, `recommended_next_action`, `do_not_do_list`,
      `audit_log_summary`.
    
    ## References
    Load only when needed:
    - [Capsule schema and redaction rules](references/capsule-schema.md) — full
      field-by-field contract, allowed values, and worked example.
    
    ## Security notes
    - The capsule is a minimum-necessary record. Never widen it to carry medical
      records, government IDs, credentials, privileged email text, or
      protected-class data beyond what the matter strictly requires.
    - A capsule that would extend the circulation of privileged or investigation
      material must be narrowed before it is sent; flag privilege explicitly.
    - The capsule never authorizes action. Any field that reads as a directive to
      terminate, discipline, settle, file, notify a regulator, or send an employee
      communication is a defect — rewrite it as a recommendation with a named human
      owner.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related