What problem does it solve? Organizations adopting AI coding agents lack deterministic governance: agents act with inherited human privileges, vendor-level controls change silently, and compliance teams cannot audit agent actions. This Skill produces a concrete control design covering provisioning, policy, audit, proxy, and boundary enforcement for platforms where humans and agents ship code side by side. ## Core Features & Use Cases - Control architecture design: Audits existing platforms against five control responsibilities and five privilege-separation patterns, mapped to a four-level autonomy ladder (L1 human-in-the-loop through L4 autonomous agents). - Regulatory mapping: Verifies agent workflows against SOX, GDPR, FedRAMP, ITAR, IL4-IL6, NIS2, and DORA, including a sovereignty overlay with provider validation questions and exit-by-design GitOps patterns. - Vulnerability management rollout: Implements shift-down security with hardened signed base images, policy-as-code enforcement (OPA, Kyverno, Conftest), and a seven-step roadmap with owners and cadences. - Use Case: A platform team at a regulated enterprise asks whether agents can safely ship code under SOX; the Skill scores their autonomy level, maps mandatory controls, and delivers a phased governance roadmap with metrics. ## Quick Start Use the platform-security-playbook to audit our platform against the five control responsibilities and produce a governance roadmap for our compliance regimes.