Claude Cursor GitHub Copilot Skill

legal-hr-risk-taxonomy

Use this skill to assign consistent risk labels to a Legal or HR matter — severity ratings, privilege and privacy sensitivity labels, retaliation and discrimination risk labels, matter-type classes, escalation-gate triggers, and the audit-log schema. It standardizes the vocabular

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_cross-functional_legal-hr-risk-taxonomy-febe32a.zip · 7 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/cross-functional/legal-hr-risk-taxonomy
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

README

🏷️ Legal-HR Risk Taxonomy

The risk taxonomy defines the shared vocabulary for legal and HR risk assessment — severity scales, sensitivity labels, escalation-grade matter types, escalation gates, and minimum-necessary audit-log schema. It enables agents to speak the same language and escalate with precision.

What is the risk taxonomy?

A structured reference that specifies:

  • 5-level severity scale (Critical → High → Medium → Low → Informational) with clear business-impact definitions
  • Privilege, privacy, and retaliation sensitivity labels — data classification to control what can be disclosed, who can view case context, and when escalation is mandatory
  • Escalation-grade matter types — a list of matters (retaliation allegations, data breaches, whistleblower reports, executive misconduct, securities violations) that trigger automatic counsel/board escalation
  • Escalation gates — thresholds and decision rules that mandate senior human involvement
  • Minimum-necessary audit-log schema — structured fields every Legal and HR agent must emit to the audit trail

See references/risk-labels.md for the complete specification, enumeration of matter types, label definitions, and the audit-log schema.

The severity scale

Level Definition Legal example HR example Next action
Critical Board-level incident; regulatory exposure; imminent legal jeopardy Patent infringement by key competitor entering market; major data breach affecting thousands of customers Executive misconduct allegation; whistleblower report of systemic discrimination; mass layoff with retaliation risk Immediate counsel + board escalation
High Material legal or HR risk; requires counsel or senior HR review; potential litigation or regulatory investigation Wrongful-termination exposure; contract breach by vendor; regulatory licensing gap Wrongful termination exposure; retaliation risk in termination; high-risk accommodation denial Escalate to employment counsel or CHRO within 24 hours
Medium Process improvement needed; no immediate jeopardy; senior review recommended Contract clause ambiguity; IP assignment gap in contractor agreement Pay-equity anomaly; performance-plan defensibility concern Escalate to counsel/senior HR; schedule review within a week
Low Informational; no immediate action required; routine guidance Routine contract renewal; standard vendor audit Routine scheduling conflict; policy-interpretation question Route to the right specialist; no escalation required
Informational Informational only; logged for completeness Regulatory guidance update; industry trend Engagement survey result; policy reminder Log and distribute

Sensitivity labels

Every Legal and HR matter is labeled with one or more sensitivity markers that control disclosure:

  • attorney-client-privilege — information protected from disclosure under legal privilege; must not be shared downstream without counsel approval
  • work-product-doctrine — analysis, strategy, or litigation advice; protected under work-product doctrine
  • medical-information — employee medical records, disability status, medical leave reason; must be minimized and access-controlled
  • protected-characteristic-data — age, race, gender, religion, national origin, disability, genetic information; must be minimized and access-controlled
  • whistleblower-report — information from a whistleblower; mandatory confidentiality and retaliation-risk escalation
  • retaliation-risk — an action that, if taken without review, could trigger retaliation claims; automatic escalation
  • data-breach-material — involves a data breach or loss of regulated data; automatic regulatory and counsel escalation
  • executive-misconduct — conduct by executives or board members; automatic board and counsel escalation

Escalation-grade matter types

The following matter types automatically trigger escalation (counsel, CHRO, CFO, or board as appropriate):

  • Retaliation allegations or risk
  • Discrimination or harassment allegations
  • Whistleblower reports
  • Executive or board-member misconduct
  • Data breaches or regulatory notifications
  • Litigation holds or subpoena response
  • Securities-law materiality (IPO, acquisitions, public disclosures)
  • Mass layoffs or restructurings with adverse-impact risk
  • Third-party claims (breach of contract, IP infringement, product liability)
  • Regulatory agency contact or investigation

Escalation gates

Escalation gates are decision thresholds. When a matter hits a gate, human approval is mandatory:

  1. Severity ≥ High → escalate to counsel (legal) or CHRO (HR)
  2. Any sensitivity label → escalate to the gate owner (e.g., whistleblower → board; executive misconduct → CEO + board)
  3. Matter type is escalation-grade → escalate automatically
  4. Time-critical or irreversible action → escalate before execution
  5. Cross-domain matter → escalate to maestro router; both domains approve
  6. Disagreement between specialists → escalate to counsel + CHRO
  7. Regulatory or board trigger → escalate to general counsel + CFO + board

Audit-log schema

Every Legal and HR agent must emit the following minimum-necessary audit-log entry:

{
  "agent_id": "legal-privacy-data-protection-agent",
  "matter_id": "MTR-2025-00041",
  "timestamp": "2025-05-19T14:23:45Z",
  "severity": "High",
  "sensitivity_labels": ["attorney-client-privilege", "data-breach-material"],
  "decision": "Flag DPIA gap; escalate to counsel before proceeding with cross-border transfer",
  "evidence_level": "Strong",
  "open_questions": ["Scope of DPIA if only metadata is transferred", "Adequacy decision status in target jurisdiction"],
  "safe_next_actions": ["Retain outside DPA counsel", "Schedule adequacy-decision research"],
  "decision_owner": "Chief Privacy Officer",
  "do_not_do_list": ["Do not proceed with cross-border transfer without adequate decision", "Do not disclose PII without DPIA completion"]
}

See references/risk-labels.md for the complete schema and worked examples.

Cross-references


The risk taxonomy is part of the vanguard frontier's cross-functional protocol layer. It ensures Legal and HR agents rate risk in the same language and escalate with precision.

Skill manifest

Legal-HR Risk Taxonomy

Purpose

This skill is the shared risk vocabulary for the Legal and HR agent ecosystem. It defines the severity scale, sensitivity labels, matter-type classes, escalation-gate triggers, and the audit-log schema, so every agent and every case capsule rates and labels risk the same way. It does not give legal or HR advice and never concludes that a matter is safe, compliant, or approved.

When to use

  • An agent must assign a risk_rating or sensitivity label to a matter.
  • An agent must decide whether an escalation gate is triggered.
  • A capsule or audit-log entry must be filled in with consistent labels.

Severity scale

Rating Meaning
Critical Immediate legal or regulatory exposure; do not proceed without counsel sign-off.
High Material litigation, regulatory, or financial exposure; escalation strongly indicated.
Medium Manageable with documented controls; monitor and document.
Low Limited exposure on current evidence; note and monitor.
Unknown Jurisdiction or material facts missing; cannot rate. Mandatory when documentation is incomplete.

Unknown is mandatory, not a fallback. An agent never upgrades a matter to a ratable severity to avoid an escalation.

Sensitivity labels

  • privilege_sensitivity: none / possible / likely-privileged.
  • privacy_sensitivity: low / moderate / high / special-category.
  • retaliation_risk, discrimination_or_harassment_risk, regulatory_risk: none-observed / possible / elevated / unknown.
  • litigation_hold_needed: no / recommended / yes / unknown.

Escalation-grade matter types

The following are escalation-grade by default — they always reach a qualified human owner regardless of severity rating: harassment, discrimination, retaliation, whistleblower, workplace safety, wage/hour, worker classification, union/labor, immigration, medical leave, disability accommodation, pay equity, executive misconduct, mass layoff or reorganization, employee data breach, and litigation-hold or discovery matters.

Escalation gates

A matter must be paused and escalated when any gate is true:

  • The matter is an escalation-grade matter type (above).
  • A claim, complaint, charge, grievance, or subpoena has been filed or threatened.
  • Protected activity, protected characteristics, or whistleblower status are in play.
  • Attorney-client privilege or work-product protection may be implicated.
  • Financial or reputational exposure is material.
  • A board, audit-committee, or regulatory-reporting trigger may apply.
  • The matter crosses Legal and HR and no documented controls exist.
  • Legal and HR agents disagree.

See references/risk-labels.md for the full matter_type value list and the audit-log schema.

Audit-log schema

Every handoff and escalation produces one audit-log event with the minimum necessary fields: event_id, case_id, timestamp, initiating_agent, receiving_agent, human_owner, matter_type, risk_rating, escalation_status, data_sensitivity, privilege_sensitivity, action_recommended, action_prohibited, evidence_summary, open_questions, decision_status, retention_category. Field rules are in the reference file.

References

Security notes

  • A rating is an opinion on exposure, never a clearance. Never record "this is compliant" or "safe to proceed"; use the severity scale only.
  • The audit log is minimum-necessary. It carries labels and summaries, never raw medical, privileged, credential, or protected-class content.
  • When facts are missing, rate Unknown and trigger the escalation gate rather than guessing a lower severity.
Files (vanguard-frontier-agentic)
  • references
    • risk-labels.md 3.7 KB
      # Legal-HR Risk Labels and Audit-Log Schema
      
      ## matter_type values
      
      The `matter_type` field on a case capsule uses one of these classes. Classes
      marked **E** are escalation-grade by default.
      
      | Value | Domain | E |
      |---|---|---|
      | `contract-review` | Legal | |
      | `privacy-data-protection` | Legal | |
      | `litigation-hold-discovery` | Legal | E |
      | `regulatory-compliance` | Legal | |
      | `ip-open-source` | Legal | |
      | `vendor-procurement-risk` | Legal | |
      | `ethics-investigation` | Legal | E |
      | `policy-governance` | Legal | |
      | `public-disclosure` | Legal | E |
      | `employee-relations` | HR | |
      | `workplace-investigation` | HR | E |
      | `performance-management` | HR | |
      | `termination-readiness` | HR | |
      | `termination-with-retaliation-risk` | HR + Legal | E |
      | `leave-accommodation` | HR | E |
      | `recruiting-selection` | HR | |
      | `compensation-equity` | HR | E |
      | `benefits-payroll` | HR | |
      | `workforce-reduction` | HR + Legal | E |
      | `worker-classification` | HR + Legal | E |
      | `harassment-discrimination` | HR + Legal | E |
      | `retaliation` | HR + Legal | E |
      | `whistleblower` | Legal + HR | E |
      | `executive-misconduct` | Legal + HR | E |
      | `union-labor` | HR + Legal | E |
      | `employee-data-breach` | Legal + HR | E |
      | `people-data-analytics` | HR | |
      | `hris-process-controls` | HR | |
      | `unclassified` | maestro | |
      
      ## Label definitions
      
      - `evidence_quality`
        - `strong` — corroborated, contemporaneous, consistent.
        - `mixed` — some corroboration, some gaps.
        - `weak` — largely uncorroborated or single-source.
        - `insufficient` — cannot assess; treat conclusions as Unknown.
      - `privilege_sensitivity`
        - `none` — no privileged material implicated.
        - `possible` — privilege may attach; flag and narrow circulation.
        - `likely-privileged` — route through counsel; do not widen distribution.
      - `privacy_sensitivity`
        - `low` — no personal data beyond role references.
        - `moderate` — ordinary employee data.
        - `high` — sensitive employee data (performance, discipline).
        - `special-category` — medical, disability, immigration, protected-class, or
          similar; documented justification required.
      
      ## Audit-log schema
      
      One event per handoff or escalation. Minimum necessary fields only.
      
      | Field | Rule |
      |---|---|
      | `event_id` | Stable opaque event identifier. |
      | `case_id` | The capsule this event belongs to. |
      | `timestamp` | ISO 8601. |
      | `initiating_agent` | Agent id that raised the event. |
      | `receiving_agent` | Agent id or human owner role receiving it. |
      | `human_owner` | Accountable human role. |
      | `matter_type` | A value from the table above. |
      | `risk_rating` | Critical / High / Medium / Low / Unknown. |
      | `escalation_status` | `none` / `recommended` / `escalated` / `paused`. |
      | `data_sensitivity` | The `privacy_sensitivity` label. |
      | `privilege_sensitivity` | The `privilege_sensitivity` label. |
      | `action_recommended` | One-line recommendation, never a directive. |
      | `action_prohibited` | The capsule `do_not_do_list` summary. |
      | `evidence_summary` | One line; no raw sensitive content. |
      | `open_questions` | Material questions still unanswered. |
      | `decision_status` | `pending-human-approval` / `approved-by-owner` / `not-required`. |
      | `retention_category` | Records-retention class for the event. |
      
      ## Rules
      
      1. The audit log carries labels and summaries only. Never raw medical,
         privileged, credential, or protected-class content.
      2. `decision_status` is never `approved` unless a named `human_owner` approved
         it. Agents never self-approve.
      3. When facts are missing, `risk_rating` is `Unknown` and `escalation_status`
         is at least `recommended`.
      4. An escalation-grade `matter_type` forces `escalation_status` to `escalated`
         or `paused`, never `none`.
      
  • metadata.json 1.1 KB
    {
      "id": "legal-hr-risk-taxonomy",
      "name": "Legal-HR Risk Taxonomy",
      "type": "skill",
      "provider": "generic",
      "harnesses": ["codex", "claude-code", "cursor", "gemini", "kiro", "other"],
      "summary": "Shared risk vocabulary for the Legal and HR agent ecosystem — severity ratings, privilege and privacy sensitivity labels, matter-type classes, escalation-gate triggers, and the audit-log schema. Does not give legal or HR advice and never concludes a matter is safe or compliant.",
      "source_type": "original",
      "official_docs": [
        "https://www.nist.gov/privacy-framework",
        "https://www.eeoc.gov",
        "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
      ],
      "security_notes": "A risk rating is an opinion on exposure, never a clearance; never records a matter as compliant or safe. The audit-log schema is minimum-necessary and carries labels and summaries, never raw medical, privileged, credential, or protected-class content. Rates Unknown and escalates when facts are missing.",
      "last_verified": "2026-05-18",
      "path": "skills/cross-functional/legal-hr-risk-taxonomy",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • README.md 6.9 KB
    # 🏷️ Legal-HR Risk Taxonomy
    
    The **risk taxonomy** defines the shared vocabulary for legal and HR risk assessment — severity scales, sensitivity labels, escalation-grade matter types, escalation gates, and minimum-necessary audit-log schema. It enables agents to speak the same language and escalate with precision.
    
    ## What is the risk taxonomy?
    
    A structured reference that specifies:
    - **5-level severity scale** (Critical → High → Medium → Low → Informational) with clear business-impact definitions
    - **Privilege, privacy, and retaliation sensitivity labels** — data classification to control what can be disclosed, who can view case context, and when escalation is mandatory
    - **Escalation-grade matter types** — a list of matters (retaliation allegations, data breaches, whistleblower reports, executive misconduct, securities violations) that trigger automatic counsel/board escalation
    - **Escalation gates** — thresholds and decision rules that mandate senior human involvement
    - **Minimum-necessary audit-log schema** — structured fields every Legal and HR agent must emit to the audit trail
    
    See [`references/risk-labels.md`](references/risk-labels.md) for the complete specification, enumeration of matter types, label definitions, and the audit-log schema.
    
    ## The severity scale
    
    | Level | Definition | Legal example | HR example | Next action |
    | ----- | ---------- | ------------- | ---------- | ----------- |
    | **Critical** | Board-level incident; regulatory exposure; imminent legal jeopardy | Patent infringement by key competitor entering market; major data breach affecting thousands of customers | Executive misconduct allegation; whistleblower report of systemic discrimination; mass layoff with retaliation risk | Immediate counsel + board escalation |
    | **High** | Material legal or HR risk; requires counsel or senior HR review; potential litigation or regulatory investigation | Wrongful-termination exposure; contract breach by vendor; regulatory licensing gap | Wrongful termination exposure; retaliation risk in termination; high-risk accommodation denial | Escalate to employment counsel or CHRO within 24 hours |
    | **Medium** | Process improvement needed; no immediate jeopardy; senior review recommended | Contract clause ambiguity; IP assignment gap in contractor agreement | Pay-equity anomaly; performance-plan defensibility concern | Escalate to counsel/senior HR; schedule review within a week |
    | **Low** | Informational; no immediate action required; routine guidance | Routine contract renewal; standard vendor audit | Routine scheduling conflict; policy-interpretation question | Route to the right specialist; no escalation required |
    | **Informational** | Informational only; logged for completeness | Regulatory guidance update; industry trend | Engagement survey result; policy reminder | Log and distribute |
    
    ## Sensitivity labels
    
    Every Legal and HR matter is labeled with one or more sensitivity markers that control disclosure:
    
    - **attorney-client-privilege** — information protected from disclosure under legal privilege; must not be shared downstream without counsel approval
    - **work-product-doctrine** — analysis, strategy, or litigation advice; protected under work-product doctrine
    - **medical-information** — employee medical records, disability status, medical leave reason; must be minimized and access-controlled
    - **protected-characteristic-data** — age, race, gender, religion, national origin, disability, genetic information; must be minimized and access-controlled
    - **whistleblower-report** — information from a whistleblower; mandatory confidentiality and retaliation-risk escalation
    - **retaliation-risk** — an action that, if taken without review, could trigger retaliation claims; automatic escalation
    - **data-breach-material** — involves a data breach or loss of regulated data; automatic regulatory and counsel escalation
    - **executive-misconduct** — conduct by executives or board members; automatic board and counsel escalation
    
    ## Escalation-grade matter types
    
    The following matter types **automatically trigger escalation** (counsel, CHRO, CFO, or board as appropriate):
    
    - Retaliation allegations or risk
    - Discrimination or harassment allegations
    - Whistleblower reports
    - Executive or board-member misconduct
    - Data breaches or regulatory notifications
    - Litigation holds or subpoena response
    - Securities-law materiality (IPO, acquisitions, public disclosures)
    - Mass layoffs or restructurings with adverse-impact risk
    - Third-party claims (breach of contract, IP infringement, product liability)
    - Regulatory agency contact or investigation
    
    ## Escalation gates
    
    Escalation gates are decision thresholds. When a matter hits a gate, human approval is mandatory:
    
    1. **Severity ≥ High** → escalate to counsel (legal) or CHRO (HR)
    2. **Any sensitivity label** → escalate to the gate owner (e.g., whistleblower → board; executive misconduct → CEO + board)
    3. **Matter type is escalation-grade** → escalate automatically
    4. **Time-critical or irreversible action** → escalate before execution
    5. **Cross-domain matter** → escalate to maestro router; both domains approve
    6. **Disagreement between specialists** → escalate to counsel + CHRO
    7. **Regulatory or board trigger** → escalate to general counsel + CFO + board
    
    ## Audit-log schema
    
    Every Legal and HR agent must emit the following minimum-necessary audit-log entry:
    
    ```json
    {
      "agent_id": "legal-privacy-data-protection-agent",
      "matter_id": "MTR-2025-00041",
      "timestamp": "2025-05-19T14:23:45Z",
      "severity": "High",
      "sensitivity_labels": ["attorney-client-privilege", "data-breach-material"],
      "decision": "Flag DPIA gap; escalate to counsel before proceeding with cross-border transfer",
      "evidence_level": "Strong",
      "open_questions": ["Scope of DPIA if only metadata is transferred", "Adequacy decision status in target jurisdiction"],
      "safe_next_actions": ["Retain outside DPA counsel", "Schedule adequacy-decision research"],
      "decision_owner": "Chief Privacy Officer",
      "do_not_do_list": ["Do not proceed with cross-border transfer without adequate decision", "Do not disclose PII without DPIA completion"]
    }
    ```
    
    See [`references/risk-labels.md`](references/risk-labels.md) for the complete schema and worked examples.
    
    ## Cross-references
    
    - [`SKILL.md`](SKILL.md) — the skill prompt for risk assessment and taxonomy application
    - [`references/risk-labels.md`](references/risk-labels.md) — complete specification, matter-type enumeration, label definitions, audit-log examples
    - [`docs/architecture/legal-hr-agent-routing.md`](/docs/architecture/legal-hr-agent-routing.md) — how escalation gates feed into routing decisions
    - [`skills/cross-functional/legal-hr-case-capsule`](/skills/cross-functional/legal-hr-case-capsule/) — case capsule carries severity and sensitivity labels
    
    ---
    
    *The risk taxonomy is part of the vanguard frontier's cross-functional protocol layer. It ensures Legal and HR agents rate risk in the same language and escalate with precision.*
    
  • SKILL.md 4.5 KB
    ---
    name: legal-hr-risk-taxonomy
    description: Use this skill to assign consistent risk labels to a Legal or HR matter — severity ratings, privilege and privacy sensitivity labels, retaliation and discrimination risk labels, matter-type classes, escalation-gate triggers, and the audit-log schema. It standardizes the vocabulary every Legal and HR agent and case capsule uses so risk is rated the same way across the ecosystem. It does not give legal or HR advice and never concludes that a matter is safe or compliant.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-18"
      category: compliance
      lifecycle: experimental
    ---
    
    # Legal-HR Risk Taxonomy
    
    ## Purpose
    This skill is the shared risk vocabulary for the Legal and HR agent ecosystem.
    It defines the severity scale, sensitivity labels, matter-type classes,
    escalation-gate triggers, and the audit-log schema, so every agent and every
    case capsule rates and labels risk the same way. It does not give legal or HR
    advice and never concludes that a matter is safe, compliant, or approved.
    
    ## When to use
    - An agent must assign a `risk_rating` or sensitivity label to a matter.
    - An agent must decide whether an escalation gate is triggered.
    - A capsule or audit-log entry must be filled in with consistent labels.
    
    ## Severity scale
    | Rating | Meaning |
    |---|---|
    | Critical | Immediate legal or regulatory exposure; do not proceed without counsel sign-off. |
    | High | Material litigation, regulatory, or financial exposure; escalation strongly indicated. |
    | Medium | Manageable with documented controls; monitor and document. |
    | Low | Limited exposure on current evidence; note and monitor. |
    | Unknown | Jurisdiction or material facts missing; cannot rate. Mandatory when documentation is incomplete. |
    
    `Unknown` is mandatory, not a fallback. An agent never upgrades a matter to a
    ratable severity to avoid an escalation.
    
    ## Sensitivity labels
    - `privilege_sensitivity`: `none` / `possible` / `likely-privileged`.
    - `privacy_sensitivity`: `low` / `moderate` / `high` / `special-category`.
    - `retaliation_risk`, `discrimination_or_harassment_risk`, `regulatory_risk`:
      `none-observed` / `possible` / `elevated` / `unknown`.
    - `litigation_hold_needed`: `no` / `recommended` / `yes` / `unknown`.
    
    ## Escalation-grade matter types
    The following are escalation-grade by default — they always reach a qualified
    human owner regardless of severity rating: harassment, discrimination,
    retaliation, whistleblower, workplace safety, wage/hour, worker classification,
    union/labor, immigration, medical leave, disability accommodation, pay equity,
    executive misconduct, mass layoff or reorganization, employee data breach, and
    litigation-hold or discovery matters.
    
    ## Escalation gates
    A matter must be paused and escalated when any gate is true:
    - The matter is an escalation-grade matter type (above).
    - A claim, complaint, charge, grievance, or subpoena has been filed or
      threatened.
    - Protected activity, protected characteristics, or whistleblower status are in
      play.
    - Attorney-client privilege or work-product protection may be implicated.
    - Financial or reputational exposure is material.
    - A board, audit-committee, or regulatory-reporting trigger may apply.
    - The matter crosses Legal and HR and no documented controls exist.
    - Legal and HR agents disagree.
    
    See [references/risk-labels.md](references/risk-labels.md) for the full
    `matter_type` value list and the audit-log schema.
    
    ## Audit-log schema
    Every handoff and escalation produces one audit-log event with the minimum
    necessary fields: `event_id`, `case_id`, `timestamp`, `initiating_agent`,
    `receiving_agent`, `human_owner`, `matter_type`, `risk_rating`,
    `escalation_status`, `data_sensitivity`, `privilege_sensitivity`,
    `action_recommended`, `action_prohibited`, `evidence_summary`,
    `open_questions`, `decision_status`, `retention_category`. Field rules are in
    the reference file.
    
    ## References
    - [Risk labels and audit-log schema](references/risk-labels.md) — full
      `matter_type` enumeration, label definitions, and audit-log field contract.
    
    ## Security notes
    - A rating is an opinion on exposure, never a clearance. Never record "this is
      compliant" or "safe to proceed"; use the severity scale only.
    - The audit log is minimum-necessary. It carries labels and summaries, never
      raw medical, privileged, credential, or protected-class content.
    - When facts are missing, rate `Unknown` and trigger the escalation gate rather
      than guessing a lower severity.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related