Skip to content
Legal
Skill

/policy-monitor

Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does

BOOST
From plugin
claude-for-legal
9.6k117 skills10 agents17 MCP
Install
$ npx -y skills add anthropics/claude-for-legal --skill policy-monitor --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/policy-monitor

Context preview

The summary Claude sees to decide when to auto-load this skill.

Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does

SKILL.md

policy-monitor.SKILL.md
name: policy-monitor
description: >
  Keep the AI policy current with practice — weekly sweep of saved AIAs, triage
  results, and vendor reviews to find policy drift, or direct query for a proposed
  new AI practice. Use when user says "policy sweep", "does our AI policy cover
  this", "we want to start doing X — does the policy need updating", "run the
  policy monitor", or on a recurring schedule.
argument-hint: "[describe a proposed new AI practice — or omit / use --sweep for crawl mode]"

/policy-monitor

**Sweep mode** (no argument or `--sweep`): 1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → outputs folder path, AI policy document, last sweep date. 2. Use the framework below. Scan outputs folder for files since last sweep. 3. For each output: extract approved practices → diff against current policy commitments and use case registry. 4. Classify gaps: REQUIRED (policy misrepresents current practice) vs ADVISABLE (policy silent). 5. For each gap: quote current policy, describe gap, draft suggested language. 6. Flag any use cases in outputs not yet added to the `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` registry. 7. Present results to the human. Only after acknowledgment, update `Last policy sweep` and `gaps_found` in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`.

**Direct query mode** (with description argument): 1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → current policy commitments, use case registry, actual policy document. 2. Parse proposed practice. Diff against policy: use case coverage, automation level, affected parties, disclosure, vendor data use, oversight. 3. Output: covered / missing / conflicting + suggested language for each gap + registry entry if needed + timing recommendation.

**Recurring runs:** Set up a recurring reminder in your own scheduler to run `/ai-governance-legal:policy-monitor` weekly. Scheduled execution requires a scheduled-tasks integration, which is not bundled with this plugin.

/ai-governance-legal:policy-monitor
/ai-governance-legal:policy-monitor "We want to use AI to automatically flag expense reports for review"

---

Purpose

AI policies drift from practice faster than almost any other policy document — the field moves quickly, use cases multiply, and each approved AIA or triage result represents a new commitment the policy may not have caught up with. An AIA approves a new AI use case with a human-oversight condition. A vendor AI agreement permits data processing the policy doesn't mention. A triage result marks a new category of deployment as conditional with a disclosure requirement. The policy sits there unchanged.

This skill catches the drift — either by crawling the outputs folder weekly, or by answering the direct question: "we're about to start doing X, what does that mean for our AI policy?"

The output is always the same: here's the gap, here's the suggested language.

---

Load current state

Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`:

  • `## AI policy commitments` — commitments extracted from the published policy
  • `## Use case registry` — approved, conditional, and never use cases
  • `## Outputs` — outputs folder path, AI policy document location, last sweep date

If `## Outputs` contains `[PLACEHOLDER]`: > "Outputs aren't configured yet. I can still run a direct-query check — describe > what you're planning to do and I'll diff it against your current AI policy. To > enable the crawl sweep, run `/ai-governance-legal:cold-start-interview` and provide the outputs > folder path."

Read the actual AI or acceptable use policy document from the path in `## Outputs` → **AI policy document**. The commitments in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` are a summary; the actual document is authoritative for suggesting edits.

---

Mode detection

**Sweep mode:** No argument, `--sweep`, or triggered by schedule. → Scan the outputs folder. Diff all outputs since last sweep against current policy.

**Direct query mode:** User provides a description of a proposed new AI practice. → Diff that practice against current policy and use case registry. Suggest updates.

---

Mode 1: Sweep

Determine scope

Read `## Outputs` → **Last policy sweep** date. Scan for output files in the outputs folder dated after that date. If no date is recorded, scan all files and note: "First sweep — scanning all outputs."

If the outputs folder is empty or has no new files since the last sweep: > "No new outputs since [last sweep date]. AI policy appears current with recent > practice. Next scheduled sweep: [date]."

**Do not update `Last policy sweep` or `gaps_found` automatically.** After the sweep results are presented, wait for the human to acknowledge them ("sweep acknowledged," "results reviewed," or equivalent). Only then update `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`:

  • `Last policy sweep: [date of acknowledgment]`
  • `gaps_found: [N]` (number of REQUIRED + ADVISABLE gaps found in that sweep)

Updating the stamp before acknowledgment would let an unreviewed sweep silently roll forward and suppress the next sweep's attention to the same gaps.

What to read in each output type

**AIAs (AI Impact Assessments):**

  • Extract: use case approved, AI system description, deployment mode (assistive /

augmentative / automated), conditions imposed, affected parties, vendor used, any disclosure requirements to affected individuals

  • Flag: use cases not in the registry, use cases approved with conditions not

reflected in policy, vendor added that policy doesn't cover, automated decision deployed where policy implies human oversight

**Triage results (CONDITIONAL / APPROVED outcomes):**

  • Extract: use case classified, tier assigned, conditions imposed
  • Flag: new use case categories not in regis
Read more
Ships withclaude-for-legal

Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and

Get the whole plugin

Other skills on claude-for-legal.