legal-hr-risk-taxonomy
Use this skill to assign consistent risk labels to a Legal or HR matter — severity ratings, privilege and privacy sensitivity labels, retaliation and discrimination risk labels, matter-type classes, escalation-gate triggers, and the audit-log schema. It standardizes the vocabular
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/legal-hr-risk-taxonomy
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
README
🏷️ Legal-HR Risk Taxonomy
The risk taxonomy defines the shared vocabulary for legal and HR risk assessment — severity scales, sensitivity labels, escalation-grade matter types, escalation gates, and minimum-necessary audit-log schema. It enables agents to speak the same language and escalate with precision.
What is the risk taxonomy?
A structured reference that specifies:
- 5-level severity scale (Critical → High → Medium → Low → Informational) with clear business-impact definitions
- Privilege, privacy, and retaliation sensitivity labels — data classification to control what can be disclosed, who can view case context, and when escalation is mandatory
- Escalation-grade matter types — a list of matters (retaliation allegations, data breaches, whistleblower reports, executive misconduct, securities violations) that trigger automatic counsel/board escalation
- Escalation gates — thresholds and decision rules that mandate senior human involvement
- Minimum-necessary audit-log schema — structured fields every Legal and HR agent must emit to the audit trail
See references/risk-labels.md for the complete specification, enumeration of matter types, label definitions, and the audit-log schema.
The severity scale
| Level | Definition | Legal example | HR example | Next action |
|---|---|---|---|---|
| Critical | Board-level incident; regulatory exposure; imminent legal jeopardy | Patent infringement by key competitor entering market; major data breach affecting thousands of customers | Executive misconduct allegation; whistleblower report of systemic discrimination; mass layoff with retaliation risk | Immediate counsel + board escalation |
| High | Material legal or HR risk; requires counsel or senior HR review; potential litigation or regulatory investigation | Wrongful-termination exposure; contract breach by vendor; regulatory licensing gap | Wrongful termination exposure; retaliation risk in termination; high-risk accommodation denial | Escalate to employment counsel or CHRO within 24 hours |
| Medium | Process improvement needed; no immediate jeopardy; senior review recommended | Contract clause ambiguity; IP assignment gap in contractor agreement | Pay-equity anomaly; performance-plan defensibility concern | Escalate to counsel/senior HR; schedule review within a week |
| Low | Informational; no immediate action required; routine guidance | Routine contract renewal; standard vendor audit | Routine scheduling conflict; policy-interpretation question | Route to the right specialist; no escalation required |
| Informational | Informational only; logged for completeness | Regulatory guidance update; industry trend | Engagement survey result; policy reminder | Log and distribute |
Sensitivity labels
Every Legal and HR matter is labeled with one or more sensitivity markers that control disclosure:
- attorney-client-privilege — information protected from disclosure under legal privilege; must not be shared downstream without counsel approval
- work-product-doctrine — analysis, strategy, or litigation advice; protected under work-product doctrine
- medical-information — employee medical records, disability status, medical leave reason; must be minimized and access-controlled
- protected-characteristic-data — age, race, gender, religion, national origin, disability, genetic information; must be minimized and access-controlled
- whistleblower-report — information from a whistleblower; mandatory confidentiality and retaliation-risk escalation
- retaliation-risk — an action that, if taken without review, could trigger retaliation claims; automatic escalation
- data-breach-material — involves a data breach or loss of regulated data; automatic regulatory and counsel escalation
- executive-misconduct — conduct by executives or board members; automatic board and counsel escalation
Escalation-grade matter types
The following matter types automatically trigger escalation (counsel, CHRO, CFO, or board as appropriate):
- Retaliation allegations or risk
- Discrimination or harassment allegations
- Whistleblower reports
- Executive or board-member misconduct
- Data breaches or regulatory notifications
- Litigation holds or subpoena response
- Securities-law materiality (IPO, acquisitions, public disclosures)
- Mass layoffs or restructurings with adverse-impact risk
- Third-party claims (breach of contract, IP infringement, product liability)
- Regulatory agency contact or investigation
Escalation gates
Escalation gates are decision thresholds. When a matter hits a gate, human approval is mandatory:
- Severity ≥ High → escalate to counsel (legal) or CHRO (HR)
- Any sensitivity label → escalate to the gate owner (e.g., whistleblower → board; executive misconduct → CEO + board)
- Matter type is escalation-grade → escalate automatically
- Time-critical or irreversible action → escalate before execution
- Cross-domain matter → escalate to maestro router; both domains approve
- Disagreement between specialists → escalate to counsel + CHRO
- Regulatory or board trigger → escalate to general counsel + CFO + board
Audit-log schema
Every Legal and HR agent must emit the following minimum-necessary audit-log entry:
{
"agent_id": "legal-privacy-data-protection-agent",
"matter_id": "MTR-2025-00041",
"timestamp": "2025-05-19T14:23:45Z",
"severity": "High",
"sensitivity_labels": ["attorney-client-privilege", "data-breach-material"],
"decision": "Flag DPIA gap; escalate to counsel before proceeding with cross-border transfer",
"evidence_level": "Strong",
"open_questions": ["Scope of DPIA if only metadata is transferred", "Adequacy decision status in target jurisdiction"],
"safe_next_actions": ["Retain outside DPA counsel", "Schedule adequacy-decision research"],
"decision_owner": "Chief Privacy Officer",
"do_not_do_list": ["Do not proceed with cross-border transfer without adequate decision", "Do not disclose PII without DPIA completion"]
}
See references/risk-labels.md for the complete schema and worked examples.
Cross-references
SKILL.md— the skill prompt for risk assessment and taxonomy applicationreferences/risk-labels.md— complete specification, matter-type enumeration, label definitions, audit-log examplesdocs/architecture/legal-hr-agent-routing.md— how escalation gates feed into routing decisionsskills/cross-functional/legal-hr-case-capsule— case capsule carries severity and sensitivity labels
The risk taxonomy is part of the vanguard frontier's cross-functional protocol layer. It ensures Legal and HR agents rate risk in the same language and escalate with precision.
Skill manifest
Legal-HR Risk Taxonomy
Purpose
This skill is the shared risk vocabulary for the Legal and HR agent ecosystem. It defines the severity scale, sensitivity labels, matter-type classes, escalation-gate triggers, and the audit-log schema, so every agent and every case capsule rates and labels risk the same way. It does not give legal or HR advice and never concludes that a matter is safe, compliant, or approved.
When to use
- An agent must assign a
risk_ratingor sensitivity label to a matter. - An agent must decide whether an escalation gate is triggered.
- A capsule or audit-log entry must be filled in with consistent labels.
Severity scale
| Rating | Meaning |
|---|---|
| Critical | Immediate legal or regulatory exposure; do not proceed without counsel sign-off. |
| High | Material litigation, regulatory, or financial exposure; escalation strongly indicated. |
| Medium | Manageable with documented controls; monitor and document. |
| Low | Limited exposure on current evidence; note and monitor. |
| Unknown | Jurisdiction or material facts missing; cannot rate. Mandatory when documentation is incomplete. |
Unknown is mandatory, not a fallback. An agent never upgrades a matter to a
ratable severity to avoid an escalation.
Sensitivity labels
privilege_sensitivity:none/possible/likely-privileged.privacy_sensitivity:low/moderate/high/special-category.retaliation_risk,discrimination_or_harassment_risk,regulatory_risk:none-observed/possible/elevated/unknown.litigation_hold_needed:no/recommended/yes/unknown.
Escalation-grade matter types
The following are escalation-grade by default — they always reach a qualified human owner regardless of severity rating: harassment, discrimination, retaliation, whistleblower, workplace safety, wage/hour, worker classification, union/labor, immigration, medical leave, disability accommodation, pay equity, executive misconduct, mass layoff or reorganization, employee data breach, and litigation-hold or discovery matters.
Escalation gates
A matter must be paused and escalated when any gate is true:
- The matter is an escalation-grade matter type (above).
- A claim, complaint, charge, grievance, or subpoena has been filed or threatened.
- Protected activity, protected characteristics, or whistleblower status are in play.
- Attorney-client privilege or work-product protection may be implicated.
- Financial or reputational exposure is material.
- A board, audit-committee, or regulatory-reporting trigger may apply.
- The matter crosses Legal and HR and no documented controls exist.
- Legal and HR agents disagree.
See references/risk-labels.md for the full
matter_type value list and the audit-log schema.
Audit-log schema
Every handoff and escalation produces one audit-log event with the minimum
necessary fields: event_id, case_id, timestamp, initiating_agent,
receiving_agent, human_owner, matter_type, risk_rating,
escalation_status, data_sensitivity, privilege_sensitivity,
action_recommended, action_prohibited, evidence_summary,
open_questions, decision_status, retention_category. Field rules are in
the reference file.
References
- Risk labels and audit-log schema — full
matter_typeenumeration, label definitions, and audit-log field contract.
Security notes
- A rating is an opinion on exposure, never a clearance. Never record "this is compliant" or "safe to proceed"; use the severity scale only.
- The audit log is minimum-necessary. It carries labels and summaries, never raw medical, privileged, credential, or protected-class content.
- When facts are missing, rate
Unknownand trigger the escalation gate rather than guessing a lower severity.
Files (vanguard-frontier-agentic)
-
references
-
risk-labels.md 3.7 KB
# Legal-HR Risk Labels and Audit-Log Schema ## matter_type values The `matter_type` field on a case capsule uses one of these classes. Classes marked **E** are escalation-grade by default. | Value | Domain | E | |---|---|---| | `contract-review` | Legal | | | `privacy-data-protection` | Legal | | | `litigation-hold-discovery` | Legal | E | | `regulatory-compliance` | Legal | | | `ip-open-source` | Legal | | | `vendor-procurement-risk` | Legal | | | `ethics-investigation` | Legal | E | | `policy-governance` | Legal | | | `public-disclosure` | Legal | E | | `employee-relations` | HR | | | `workplace-investigation` | HR | E | | `performance-management` | HR | | | `termination-readiness` | HR | | | `termination-with-retaliation-risk` | HR + Legal | E | | `leave-accommodation` | HR | E | | `recruiting-selection` | HR | | | `compensation-equity` | HR | E | | `benefits-payroll` | HR | | | `workforce-reduction` | HR + Legal | E | | `worker-classification` | HR + Legal | E | | `harassment-discrimination` | HR + Legal | E | | `retaliation` | HR + Legal | E | | `whistleblower` | Legal + HR | E | | `executive-misconduct` | Legal + HR | E | | `union-labor` | HR + Legal | E | | `employee-data-breach` | Legal + HR | E | | `people-data-analytics` | HR | | | `hris-process-controls` | HR | | | `unclassified` | maestro | | ## Label definitions - `evidence_quality` - `strong` — corroborated, contemporaneous, consistent. - `mixed` — some corroboration, some gaps. - `weak` — largely uncorroborated or single-source. - `insufficient` — cannot assess; treat conclusions as Unknown. - `privilege_sensitivity` - `none` — no privileged material implicated. - `possible` — privilege may attach; flag and narrow circulation. - `likely-privileged` — route through counsel; do not widen distribution. - `privacy_sensitivity` - `low` — no personal data beyond role references. - `moderate` — ordinary employee data. - `high` — sensitive employee data (performance, discipline). - `special-category` — medical, disability, immigration, protected-class, or similar; documented justification required. ## Audit-log schema One event per handoff or escalation. Minimum necessary fields only. | Field | Rule | |---|---| | `event_id` | Stable opaque event identifier. | | `case_id` | The capsule this event belongs to. | | `timestamp` | ISO 8601. | | `initiating_agent` | Agent id that raised the event. | | `receiving_agent` | Agent id or human owner role receiving it. | | `human_owner` | Accountable human role. | | `matter_type` | A value from the table above. | | `risk_rating` | Critical / High / Medium / Low / Unknown. | | `escalation_status` | `none` / `recommended` / `escalated` / `paused`. | | `data_sensitivity` | The `privacy_sensitivity` label. | | `privilege_sensitivity` | The `privilege_sensitivity` label. | | `action_recommended` | One-line recommendation, never a directive. | | `action_prohibited` | The capsule `do_not_do_list` summary. | | `evidence_summary` | One line; no raw sensitive content. | | `open_questions` | Material questions still unanswered. | | `decision_status` | `pending-human-approval` / `approved-by-owner` / `not-required`. | | `retention_category` | Records-retention class for the event. | ## Rules 1. The audit log carries labels and summaries only. Never raw medical, privileged, credential, or protected-class content. 2. `decision_status` is never `approved` unless a named `human_owner` approved it. Agents never self-approve. 3. When facts are missing, `risk_rating` is `Unknown` and `escalation_status` is at least `recommended`. 4. An escalation-grade `matter_type` forces `escalation_status` to `escalated` or `paused`, never `none`.
-
-
metadata.json 1.1 KB
{ "id": "legal-hr-risk-taxonomy", "name": "Legal-HR Risk Taxonomy", "type": "skill", "provider": "generic", "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"], "summary": "Shared risk vocabulary for the Legal and HR agent ecosystem — severity ratings, privilege and privacy sensitivity labels, matter-type classes, escalation-gate triggers, and the audit-log schema. Does not give legal or HR advice and never concludes a matter is safe or compliant.", "source_type": "original", "official_docs": [ "https://www.nist.gov/privacy-framework", "https://www.eeoc.gov", "https://eur-lex.europa.eu/eli/reg/2016/679/oj" ], "security_notes": "A risk rating is an opinion on exposure, never a clearance; never records a matter as compliant or safe. The audit-log schema is minimum-necessary and carries labels and summaries, never raw medical, privileged, credential, or protected-class content. Rates Unknown and escalates when facts are missing.", "last_verified": "2026-05-18", "path": "skills/cross-functional/legal-hr-risk-taxonomy", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
README.md 6.9 KB
# 🏷️ Legal-HR Risk Taxonomy The **risk taxonomy** defines the shared vocabulary for legal and HR risk assessment — severity scales, sensitivity labels, escalation-grade matter types, escalation gates, and minimum-necessary audit-log schema. It enables agents to speak the same language and escalate with precision. ## What is the risk taxonomy? A structured reference that specifies: - **5-level severity scale** (Critical → High → Medium → Low → Informational) with clear business-impact definitions - **Privilege, privacy, and retaliation sensitivity labels** — data classification to control what can be disclosed, who can view case context, and when escalation is mandatory - **Escalation-grade matter types** — a list of matters (retaliation allegations, data breaches, whistleblower reports, executive misconduct, securities violations) that trigger automatic counsel/board escalation - **Escalation gates** — thresholds and decision rules that mandate senior human involvement - **Minimum-necessary audit-log schema** — structured fields every Legal and HR agent must emit to the audit trail See [`references/risk-labels.md`](references/risk-labels.md) for the complete specification, enumeration of matter types, label definitions, and the audit-log schema. ## The severity scale | Level | Definition | Legal example | HR example | Next action | | ----- | ---------- | ------------- | ---------- | ----------- | | **Critical** | Board-level incident; regulatory exposure; imminent legal jeopardy | Patent infringement by key competitor entering market; major data breach affecting thousands of customers | Executive misconduct allegation; whistleblower report of systemic discrimination; mass layoff with retaliation risk | Immediate counsel + board escalation | | **High** | Material legal or HR risk; requires counsel or senior HR review; potential litigation or regulatory investigation | Wrongful-termination exposure; contract breach by vendor; regulatory licensing gap | Wrongful termination exposure; retaliation risk in termination; high-risk accommodation denial | Escalate to employment counsel or CHRO within 24 hours | | **Medium** | Process improvement needed; no immediate jeopardy; senior review recommended | Contract clause ambiguity; IP assignment gap in contractor agreement | Pay-equity anomaly; performance-plan defensibility concern | Escalate to counsel/senior HR; schedule review within a week | | **Low** | Informational; no immediate action required; routine guidance | Routine contract renewal; standard vendor audit | Routine scheduling conflict; policy-interpretation question | Route to the right specialist; no escalation required | | **Informational** | Informational only; logged for completeness | Regulatory guidance update; industry trend | Engagement survey result; policy reminder | Log and distribute | ## Sensitivity labels Every Legal and HR matter is labeled with one or more sensitivity markers that control disclosure: - **attorney-client-privilege** — information protected from disclosure under legal privilege; must not be shared downstream without counsel approval - **work-product-doctrine** — analysis, strategy, or litigation advice; protected under work-product doctrine - **medical-information** — employee medical records, disability status, medical leave reason; must be minimized and access-controlled - **protected-characteristic-data** — age, race, gender, religion, national origin, disability, genetic information; must be minimized and access-controlled - **whistleblower-report** — information from a whistleblower; mandatory confidentiality and retaliation-risk escalation - **retaliation-risk** — an action that, if taken without review, could trigger retaliation claims; automatic escalation - **data-breach-material** — involves a data breach or loss of regulated data; automatic regulatory and counsel escalation - **executive-misconduct** — conduct by executives or board members; automatic board and counsel escalation ## Escalation-grade matter types The following matter types **automatically trigger escalation** (counsel, CHRO, CFO, or board as appropriate): - Retaliation allegations or risk - Discrimination or harassment allegations - Whistleblower reports - Executive or board-member misconduct - Data breaches or regulatory notifications - Litigation holds or subpoena response - Securities-law materiality (IPO, acquisitions, public disclosures) - Mass layoffs or restructurings with adverse-impact risk - Third-party claims (breach of contract, IP infringement, product liability) - Regulatory agency contact or investigation ## Escalation gates Escalation gates are decision thresholds. When a matter hits a gate, human approval is mandatory: 1. **Severity ≥ High** → escalate to counsel (legal) or CHRO (HR) 2. **Any sensitivity label** → escalate to the gate owner (e.g., whistleblower → board; executive misconduct → CEO + board) 3. **Matter type is escalation-grade** → escalate automatically 4. **Time-critical or irreversible action** → escalate before execution 5. **Cross-domain matter** → escalate to maestro router; both domains approve 6. **Disagreement between specialists** → escalate to counsel + CHRO 7. **Regulatory or board trigger** → escalate to general counsel + CFO + board ## Audit-log schema Every Legal and HR agent must emit the following minimum-necessary audit-log entry: ```json { "agent_id": "legal-privacy-data-protection-agent", "matter_id": "MTR-2025-00041", "timestamp": "2025-05-19T14:23:45Z", "severity": "High", "sensitivity_labels": ["attorney-client-privilege", "data-breach-material"], "decision": "Flag DPIA gap; escalate to counsel before proceeding with cross-border transfer", "evidence_level": "Strong", "open_questions": ["Scope of DPIA if only metadata is transferred", "Adequacy decision status in target jurisdiction"], "safe_next_actions": ["Retain outside DPA counsel", "Schedule adequacy-decision research"], "decision_owner": "Chief Privacy Officer", "do_not_do_list": ["Do not proceed with cross-border transfer without adequate decision", "Do not disclose PII without DPIA completion"] } ``` See [`references/risk-labels.md`](references/risk-labels.md) for the complete schema and worked examples. ## Cross-references - [`SKILL.md`](SKILL.md) — the skill prompt for risk assessment and taxonomy application - [`references/risk-labels.md`](references/risk-labels.md) — complete specification, matter-type enumeration, label definitions, audit-log examples - [`docs/architecture/legal-hr-agent-routing.md`](/docs/architecture/legal-hr-agent-routing.md) — how escalation gates feed into routing decisions - [`skills/cross-functional/legal-hr-case-capsule`](/skills/cross-functional/legal-hr-case-capsule/) — case capsule carries severity and sensitivity labels --- *The risk taxonomy is part of the vanguard frontier's cross-functional protocol layer. It ensures Legal and HR agents rate risk in the same language and escalate with precision.* -
SKILL.md 4.5 KB
--- name: legal-hr-risk-taxonomy description: Use this skill to assign consistent risk labels to a Legal or HR matter — severity ratings, privilege and privacy sensitivity labels, retaliation and discrimination risk labels, matter-type classes, escalation-gate triggers, and the audit-log schema. It standardizes the vocabulary every Legal and HR agent and case capsule uses so risk is rated the same way across the ecosystem. It does not give legal or HR advice and never concludes that a matter is safe or compliant. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-18" category: compliance lifecycle: experimental --- # Legal-HR Risk Taxonomy ## Purpose This skill is the shared risk vocabulary for the Legal and HR agent ecosystem. It defines the severity scale, sensitivity labels, matter-type classes, escalation-gate triggers, and the audit-log schema, so every agent and every case capsule rates and labels risk the same way. It does not give legal or HR advice and never concludes that a matter is safe, compliant, or approved. ## When to use - An agent must assign a `risk_rating` or sensitivity label to a matter. - An agent must decide whether an escalation gate is triggered. - A capsule or audit-log entry must be filled in with consistent labels. ## Severity scale | Rating | Meaning | |---|---| | Critical | Immediate legal or regulatory exposure; do not proceed without counsel sign-off. | | High | Material litigation, regulatory, or financial exposure; escalation strongly indicated. | | Medium | Manageable with documented controls; monitor and document. | | Low | Limited exposure on current evidence; note and monitor. | | Unknown | Jurisdiction or material facts missing; cannot rate. Mandatory when documentation is incomplete. | `Unknown` is mandatory, not a fallback. An agent never upgrades a matter to a ratable severity to avoid an escalation. ## Sensitivity labels - `privilege_sensitivity`: `none` / `possible` / `likely-privileged`. - `privacy_sensitivity`: `low` / `moderate` / `high` / `special-category`. - `retaliation_risk`, `discrimination_or_harassment_risk`, `regulatory_risk`: `none-observed` / `possible` / `elevated` / `unknown`. - `litigation_hold_needed`: `no` / `recommended` / `yes` / `unknown`. ## Escalation-grade matter types The following are escalation-grade by default — they always reach a qualified human owner regardless of severity rating: harassment, discrimination, retaliation, whistleblower, workplace safety, wage/hour, worker classification, union/labor, immigration, medical leave, disability accommodation, pay equity, executive misconduct, mass layoff or reorganization, employee data breach, and litigation-hold or discovery matters. ## Escalation gates A matter must be paused and escalated when any gate is true: - The matter is an escalation-grade matter type (above). - A claim, complaint, charge, grievance, or subpoena has been filed or threatened. - Protected activity, protected characteristics, or whistleblower status are in play. - Attorney-client privilege or work-product protection may be implicated. - Financial or reputational exposure is material. - A board, audit-committee, or regulatory-reporting trigger may apply. - The matter crosses Legal and HR and no documented controls exist. - Legal and HR agents disagree. See [references/risk-labels.md](references/risk-labels.md) for the full `matter_type` value list and the audit-log schema. ## Audit-log schema Every handoff and escalation produces one audit-log event with the minimum necessary fields: `event_id`, `case_id`, `timestamp`, `initiating_agent`, `receiving_agent`, `human_owner`, `matter_type`, `risk_rating`, `escalation_status`, `data_sensitivity`, `privilege_sensitivity`, `action_recommended`, `action_prohibited`, `evidence_summary`, `open_questions`, `decision_status`, `retention_category`. Field rules are in the reference file. ## References - [Risk labels and audit-log schema](references/risk-labels.md) — full `matter_type` enumeration, label definitions, and audit-log field contract. ## Security notes - A rating is an opinion on exposure, never a clearance. Never record "this is compliant" or "safe to proceed"; use the severity scale only. - The audit log is minimum-necessary. It carries labels and summaries, never raw medical, privileged, credential, or protected-class content. - When facts are missing, rate `Unknown` and trigger the escalation gate rather than guessing a lower severity.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.