policy-monitor

Detect drift between AI policy and approved or proposed practices.

109|20|Updated Mar 7, 2025
One-click install
npx skills add https://github.com/stakwork/stakgraph --skill policy-monitor-stakwork
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: policy-monitor
Source: https://github.com/stakwork/stakgraph/tree/main/mcp/skills/ai-governance-legal/policy-monitor
Command: npx skills add https://github.com/stakwork/stakgraph --skill policy-monitor-stakwork

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill detects when an organization's AI policy has drifted from its approved use cases, impact assessments, vendor reviews, and operational practices.

Core Features & Use Cases

  • Policy Drift Detection: Compare saved AI impact assessments, triage results, and vendor reviews against current policy commitments.
  • Direct Policy Checks: Evaluate proposed AI practices for coverage, conflicts, oversight, disclosure, automation, and vendor data-use concerns.
  • Human-Reviewed Updates: Classify gaps as required or advisable, draft policy language, identify registry changes, and defer state updates until acknowledgment.
  • Use Case: When a team proposes using AI to flag expense reports, run a direct policy check to determine whether the practice is covered, what safeguards are missing, and whether the policy or use case registry needs updating.

Quick Start

Run the policy monitor with a description of the proposed AI practice, or omit the description to perform a sweep of saved governance outputs.

Frequently Asked Questions about policy-monitor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect AI policy drift against approved use cases and impact assessments?

AI policy drift is detected by comparing saved impact assessments, triage results, vendor reviews, and use case registries against current policy commitments during weekly sweeps. The monitor evaluates coverage, conflicts, oversight, disclosure, automation, and vendor data-use concerns to identify misalignments.

What is AI policy monitoring and when do I need to run a governance sweep?

AI policy monitoring is the process of checking whether operational AI practices align with governance documents. You need to run a sweep weekly to review saved governance outputs, or run a direct check whenever a team proposes a new AI deployment or practice.

How do I check if a proposed AI deployment conflicts with our existing governance policy?

To check a proposed AI deployment, run a direct policy check with a description of the intended practice. The monitor evaluates the practice for coverage, missing safeguards, and conflicts, then classifies gaps as required or advisable before drafting policy language updates.

Can I automate policy registry updates without human acknowledgment of the sweep results?

No, governance state updates are deferred until human acknowledgment is received. The monitor classifies gaps, drafts policy language, and identifies necessary registry changes, but requires manual review before recording sweep results or updating the state file.

What files and access do I need to run an AI policy compliance check?

You need access to the configured AI policy document, the governance state file, and the outputs directory containing saved impact assessments and vendor reviews. These inputs allow the monitor to compare approved practices against current policy commitments.

Why does my AI use case registry show policy gaps after a vendor review?

Policy gaps appear after a vendor review because the monitor detects drift between the vendor's data-use practices and your current policy commitments. It identifies missing safeguards and classifies whether updating the use case registry or policy language is required or advisable.