/cs:caio-review — CAIO Forcing Questions
Command: /cs:caio-review <plan>
The eval-demanding CAIO pressure-tests any plan that involves AI. Six questions before any AI feature ships, any multi-year vendor commitment, or any AI team expansion.
When to Run
- Before shipping any new AI-powered feature
- Before signing a multi-year AI vendor contract (API or self-hosted infra)
- Before EU launch of any AI feature
- Before a major AI team hire (especially ML engineer or research scientist)
- Before a fine-tuning project commitment
- Before adopting AI in a regulated domain (employment, credit, healthcare, education, etc.)
- When the founder uses the word "AI" near "competitive advantage" or "moat"
The Six CAIO Questions
1. What does this AI need to be good at, and how would you measure it?
No eval set = no ship. Before any AI feature deploys, define the eval criteria.
- 50-100 representative inputs minimum
- Expected outputs OR rubric for grading
- Edge cases: ambiguous, adversarial, format-edge
- If you can't write down what "good" looks like, you don't have a feature; you have a vibe.
2. What's the SLO on hallucination / error rate, and what's the fallback?
Every AI feature has a failure mode. Plan for it.
- Quantified SLO: "<5% hallucination on factual queries"
- Detection mechanism: monitoring, sampling, customer feedback loop
- Fallback: human-in-loop review, lower-risk default response, refuse-to-answer
- Blast radius if SLO breached: how many users affected, what is the cost?
3. What's the risk tier under EU AI Act, and is conformity assessment required?
Run ai_risk_classifier.py if any EU residents are affected OR domain is regulated.
- PROHIBITED → cannot launch in EU; re-scope
- HIGH → conformity assessment + EU DB registration + 10 Articles of obligations (3-12 months, $50-200K)
- LIMITED → transparency obligations (chatbot disclosure, AI-generated content marking)
- MINIMAL → no specific obligations; NIST AI RMF voluntary
4. API, fine-tune, or build?
Run model_buildvsbuy_calculator.py for the specific use case.
- 80% of B2B SaaS use cases: API
- 15%: fine-tune (when domain-specific behavior + labeled data + ML team + high volume)
- <1%: build from scratch
- Decision must consider economic breakeven AND practical feasibility (data, team, compliance)
5. What's the 12-month cost trajectory at expected scale?
Run ai_cost_economics.py for the workload.
- API: variable, scales linearly
- Self-hosted: mostly fixed, breakeven typically 1-10B tokens/month for 70B-class
- Hidden costs of self-hosted: ops, monitoring, model updates, capacity, failover, security
- Hidden costs of API: vendor lock-in, capability drift, rate limits, data residency
- Prompt caching is the most underrated lever; check provider support
6. What role unblocks this — and have we hired prerequisites first?
Map AI capability to specific role. Founders confuse AI engineer / ML engineer / research scientist.
- AI engineer: applied + full-stack + prompts + evals + deployment (most startups need this)
- ML engineer: fine-tuning + retraining infra (only after platform engineer + labeled data)
- Research scientist: model invention (only if model IS the product)
- Don't hire research scientist as first AI hire — they need infrastructure to be productive
Workflow
# 1. Model selection check
python ../../../skills/chief-ai-officer-advisor/scripts/model_buildvsbuy_calculator.py use_case.json
# 2. Regulatory classification
python ../../../skills/chief-ai-officer-advisor/scripts/ai_risk_classifier.py use_case.json
# 3. Cost projection
python ../../../skills/chief-ai-officer-advisor/scripts/ai_cost_economics.py workload.json
Output Format
# CAIO Review: <plan>
**Date:** YYYY-MM-DD
## The Decision Being Made
[one sentence — which CAIO decision: model selection | risk classification | economics | next hire]
## Eval Discipline
- Eval set committed: yes/no
- SLO defined: <metric> < <threshold>
- Fallback behavior: <one line>
## Model Selection (if applicable)
- Recommended: API / FINE_TUNE / BUILD
- 3-year TCO: $X (chosen path) vs $Y (alternatives)
- Breakeven: <volume>
## Risk Classification (if applicable)
- EU AI Act tier: PROHIBITED / HIGH / LIMITED / MINIMAL
- Conformity assessment required: yes/no
- US state triggers: [list]
- Required controls open: N
## Cost Economics (if applicable)
- Monthly cost at current volume: $X
- Breakeven for self-hosted migration: <volume>
- Migration cost if applicable: $X (3-6 months)
## Org (if applicable)
- Next hire: <role>
- Why this, not the alternative: <one line>
- Prerequisite hires in place: yes/no
## Verdict
🟢 SHIP | 🟡 SHARPEN | 🔴 BLOCK
## Next Steps
[3 concrete actions]
Routing
/cs:cdo-review — for any training-data implications
/cs:gc-review — for AI vendor contracts, output liability, training-data licensing
/cs:ciso-review — for prompt injection / jailbreak / training-data poisoning threat model
/cs:cfo-review — for multi-year vendor or GPU commitment TCO
cs-chro-advisor agent — for AI team hires (comp, ladder, leveling)
/cs:decide — log the verdict
/cs:freeze 60 — on multi-year AI commitments
Related
Version: 1.0.0
Source: alirezarezvani/claude-skills → c-level-advisor/c-level-agents/skills/caio-review/SKILL.md
1---2name: caio-review3description: Caio Review4---5
6
7# /cs:caio-review — CAIO Forcing Questions
8
9**Command:** `/cs:caio-review <plan>`
10
11The eval-demanding CAIO pressure-tests any plan that involves AI. Six questions before any AI feature ships, any multi-year vendor commitment, or any AI team expansion.
12
13## When to Run
14
15- Before shipping any new AI-powered feature
16- Before signing a multi-year AI vendor contract (API or self-hosted infra)
17- Before EU launch of any AI feature
18- Before a major AI team hire (especially ML engineer or research scientist)
19- Before a fine-tuning project commitment
20- Before adopting AI in a regulated domain (employment, credit, healthcare, education, etc.)
21- When the founder uses the word "AI" near "competitive advantage" or "moat"
22
23## The Six CAIO Questions
24
25### 1. What does this AI need to be good at, and how would you measure it?
26**No eval set = no ship.** Before any AI feature deploys, define the eval criteria.
27- 50-100 representative inputs minimum
28- Expected outputs OR rubric for grading
29- Edge cases: ambiguous, adversarial, format-edge
30- If you can't write down what "good" looks like, you don't have a feature; you have a vibe.
31
32### 2. What's the SLO on hallucination / error rate, and what's the fallback?
33**Every AI feature has a failure mode. Plan for it.**
34- Quantified SLO: "<5% hallucination on factual queries"
35- Detection mechanism: monitoring, sampling, customer feedback loop
36- Fallback: human-in-loop review, lower-risk default response, refuse-to-answer
37- Blast radius if SLO breached: how many users affected, what is the cost?
38
39### 3. What's the risk tier under EU AI Act, and is conformity assessment required?
40**Run `ai_risk_classifier.py` if any EU residents are affected OR domain is regulated.**
41- PROHIBITED → cannot launch in EU; re-scope
42- HIGH → conformity assessment + EU DB registration + 10 Articles of obligations (3-12 months, $50-200K)
43- LIMITED → transparency obligations (chatbot disclosure, AI-generated content marking)
44- MINIMAL → no specific obligations; NIST AI RMF voluntary
45
46### 4. API, fine-tune, or build?
47**Run `model_buildvsbuy_calculator.py` for the specific use case.**
48- 80% of B2B SaaS use cases: API
49- 15%: fine-tune (when domain-specific behavior + labeled data + ML team + high volume)
50- <1%: build from scratch
51- Decision must consider economic breakeven AND practical feasibility (data, team, compliance)
52
53### 5. What's the 12-month cost trajectory at expected scale?
54**Run `ai_cost_economics.py` for the workload.**
55- API: variable, scales linearly
56- Self-hosted: mostly fixed, breakeven typically 1-10B tokens/month for 70B-class
57- Hidden costs of self-hosted: ops, monitoring, model updates, capacity, failover, security
58- Hidden costs of API: vendor lock-in, capability drift, rate limits, data residency
59- Prompt caching is the most underrated lever; check provider support
60
61### 6. What role unblocks this — and have we hired prerequisites first?
62**Map AI capability to specific role. Founders confuse AI engineer / ML engineer / research scientist.**
63- AI engineer: applied + full-stack + prompts + evals + deployment (most startups need this)
64- ML engineer: fine-tuning + retraining infra (only after platform engineer + labeled data)
65- Research scientist: model invention (only if model IS the product)
66- Don't hire research scientist as first AI hire — they need infrastructure to be productive
67
68## Workflow
69
70```bash
71# 1. Model selection check
72python ../../../skills/chief-ai-officer-advisor/scripts/model_buildvsbuy_calculator.py use_case.json
73
74# 2. Regulatory classification
75python ../../../skills/chief-ai-officer-advisor/scripts/ai_risk_classifier.py use_case.json
76
77# 3. Cost projection
78python ../../../skills/chief-ai-officer-advisor/scripts/ai_cost_economics.py workload.json
79```
80
81## Output Format
82
83```markdown
84# CAIO Review: <plan>
85**Date:** YYYY-MM-DD
86
87## The Decision Being Made
88[one sentence — which CAIO decision: model selection | risk classification | economics | next hire]
89
90## Eval Discipline
91- Eval set committed: yes/no
92- SLO defined: <metric> < <threshold>
93- Fallback behavior: <one line>
94
95## Model Selection (if applicable)
96- Recommended: API / FINE_TUNE / BUILD
97- 3-year TCO: $X (chosen path) vs $Y (alternatives)
98- Breakeven: <volume>
99
100## Risk Classification (if applicable)
101- EU AI Act tier: PROHIBITED / HIGH / LIMITED / MINIMAL
102- Conformity assessment required: yes/no
103- US state triggers: [list]
104- Required controls open: N
105
106## Cost Economics (if applicable)
107- Monthly cost at current volume: $X
108- Breakeven for self-hosted migration: <volume>
109- Migration cost if applicable: $X (3-6 months)
110
111## Org (if applicable)
112- Next hire: <role>
113- Why this, not the alternative: <one line>
114- Prerequisite hires in place: yes/no
115
116## Verdict
117🟢 SHIP | 🟡 SHARPEN | 🔴 BLOCK
118
119## Next Steps
120[3 concrete actions]
121```
122
123## Routing
124
125- `/cs:cdo-review` — for any training-data implications
126- `/cs:gc-review` — for AI vendor contracts, output liability, training-data licensing
127- `/cs:ciso-review` — for prompt injection / jailbreak / training-data poisoning threat model
128- `/cs:cfo-review` — for multi-year vendor or GPU commitment TCO
129- `cs-chro-advisor` agent — for AI team hires (comp, ladder, leveling)
130- `/cs:decide` — log the verdict
131- `/cs:freeze 60` — on multi-year AI commitments
132
133## Related
134
135- Agent: [`cs-caio-advisor`](../../agents/cs-caio-advisor.md)
136- Skill: [`chief-ai-officer-advisor`](../../../skills/chief-ai-officer-advisor/SKILL.md)
137- Adjacent: `../../../skills/chief-data-officer-advisor/` (training data rights, data strategy)
138
139---
140
141**Version:** 1.0.0
142
143---
144
145**Source:** [`alirezarezvani/claude-skills`](https://github.com/alirezarezvani/claude-skills) → `c-level-advisor/c-level-agents/skills/caio-review/SKILL.md`