Skip to content
Legal
Skill

/internal-investigation

Reference: shared framework for managing internal investigations from intake through final memo — privileged investigation log, document processing with needle-finding, source coverage tracking, Q&A against the log, memo drafting, and audience summaries. Loaded by

BOOST
From plugin
claude-for-legal
9.6k117 skills10 agents17 MCP
Install
$ npx -y skills add anthropics/claude-for-legal --skill internal-investigation --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/internal-investigation

Context preview

The summary Claude sees to decide when to auto-load this skill.

Reference: shared framework for managing internal investigations from intake through final memo — privileged investigation log, document processing with needle-finding, source coverage tracking, Q&A against the log, memo drafting, and audience summaries. Loaded by

SKILL.md

internal-investigation.SKILL.md
name: internal-investigation
description: >
  Reference: shared framework for managing internal investigations from intake
  through final memo — privileged investigation log, document processing with
  needle-finding, source coverage tracking, Q&A against the log, memo drafting,
  and audience summaries. Loaded by /investigation-open, /investigation-add,
  /investigation-query, /investigation-memo, and /investigation-summary; not
  invoked directly.
user-invocable: false

Internal Investigation Skill

Matter context

**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/employment-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/employment-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.

---

Output header

Prepend the work-product header from `~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md` → `## Outputs` (it differs by user role — see `## Who's using this`). Every file, log, memo, and summary produced by this skill opens with that header.

> **Distribution discipline.** Every file this skill creates — log entries, memo drafts, audience summaries, document notes — inherits the privilege and confidentiality status of the underlying investigation. Distribution beyond the privilege circle (forwarding to non-attorneys outside the investigation team, cc'ing HR without scoping, handing to the business side) can waive privilege over the entire investigation. Store these files where privileged materials live, label per the work-product header, and make every distribution decision deliberately.

⚠️ Privilege notice — read before proceeding

**Marking does not create privilege.** The header above reflects the intended protection and is important to include — but it does not itself establish privilege. Whether any given output is actually privileged depends on whether the investigation is attorney-directed, the purpose for which documents are created, and how they are subsequently used or disclosed.

**Before opening a matter, confirm:** Is this investigation attorney-directed? If it is not — if HR is running it with legal in an advisory role, or if it was not initiated at the direction of counsel for the purpose of obtaining legal advice — the privilege analysis changes materially and this skill's default labeling may be misleading. Flag that question to the attorney before creating any log or file.

If there is any doubt about privilege applicability, the attorney should resolve it before investigation files are created. Improperly labeled materials can create problems in discovery if privilege is later challenged.

---

Purpose

Internal investigations fail in two ways: coverage gaps (sources that were never gathered) and synthesis gaps (evidence that was gathered but never connected). This skill handles both — it tracks what has and hasn't been gathered, processes document dumps to surface what matters without burying the attorney, and maintains a structured log that can be turned into a privileged memo at any point.

Privilege note

All files created by this skill carry the privilege marking above. See the notice at the top of this skill for the full caveat on what that marking does and does not do.

Load context

Read `~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md` → escalation table, any investigation protocols noted.

---

Mode 1: Open a new matter

Triggered by `/employment-legal:investigation-open` or "open an investigation" or "start an investigation into".

Step 1 — Intake

Ask the following in a single block:

> To open the investigation log I need a few things: > > **The matter** > - What is the allegation or concern in plain terms? > - Who is the complainant (or what triggered this — complaint, tip, audit, > manager observation)? > - Who is the respondent or subject? > - What is the approximate timeframe the alleged conduct occurred? > - Is this attorney-directed? (If yes: work product protection applies. > If no: flag privilege risk before proceeding.) > > **Investigation type** (helps me suggest the right sources checklist) > - HR: harassment / discrimination / retaliation > - Financial misconduct: expense fraud / procurement irregularities / embezzlement > - Executive misconduct: COI / undisclosed relationships / governance failures > - Whistleblower: retaliation for protected activity > - Other: describe briefly > > **Representation and employer status** (surfaces parallel legal frameworks > that change interview procedure) > - Is the respondent, the complainant, or any anticipated witness represented > by a union or covered by a collective bargaining agreement? (If yes, flag > for Weingarten research — representational rights at investigatory > interviews may apply and change the interview protocol.) > - Is the company a public employer (government entity, public university, > state or municipal agency) or otherwise acting under color of state law? > (If yes, flag for Garrity research — compelled statements in public-sector > investigations have special use-immunity consequences and change how > interviews must be conducted and documented.)

If either flag fires, research the applicable rules (NLRA / state public-sector labor statutes for Weingarten; 5th Amendment and the Garrity line of cases, plus any state analogs) before conducting interviews. Cite primary sources. Verify currency. Do not interview until the protocol is adjusted.

Step 2 — Create the matter directory and files

Cre

Read more
Ships withclaude-for-legal

Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and

Get the whole plugin

Other skills on claude-for-legal.