All skills
permission-boundary-modeling
FoundationJIT onlyanalysis-agent/task-agent/review-agent: use for tenant isolation, privilege-escalation, subject-resource-action policy, or enforcement changes; skip authentication-only work.
- Group
- Domain modeling
- Supported roles
- MainAnalysisTaskReview
- Source
- SKILL.md
Use when
Trigger signals that make this skill the right owner
- model subject resource action conditions object tenant scope privilege transitions and enforcement
Do not use when
Anti-triggers — as binding as the triggers above
- no task-local permission policy or enforcement decision is required
Required inputs
What must be supplied before this skill can decide anything
- current task contract
- selected primary Professional Skill
- task-local trigger evidence
Output contract
What this skill owes the next role
- permission contract with authoritative decision inputs, subject-resource-action conditions, object and tenant scope, reachable enforcement, collection and bulk semantics, denial disclosure, delegated entitlement, negative proof, and residual owners
Escalation signals
When this skill must hand the decision back
- Permission authority, scope, enforcement, denial, or residual ownership remains ambiguous
Loaded by
This skill never owns a task. These professionals may pull it in as Layer 3.
Targeted references
Each reference carries its own load condition. None of them enter context by default.
| Reference | Load when | Do not load when | Required by |
|---|---|---|---|
| benchmarks-and-patterns.mdbenchmark-pattern | competing object relationship context collection bulk delegation denial or placement patterns remain viable | current policy and enforcement path resolve the changed permission decision | AnalysisTaskReview |
| checklist.mddecision-checklist | several permission matrix enforcement collection bulk denial delegation or rollout decisions must close together | one bounded permission decision is already complete from the root contract | AnalysisTaskReview |
| evidence-patterns.mdevidence-pattern | authority scope enforcement collection bulk denial delegation rollout or negative-path claims need fresh proof | current source and selected fixtures prove the bounded permission claims | AnalysisTaskReview |