Agent Governance Review
Review governance as a layered control system: instruction files, repository policy, CI/CD enforcement, identity controls, auditability, and human oversight.
Workflow
- Identify the assistant scope: Codex, Claude Code, or both.
- Read relevant
AGENTS.md,CLAUDE.md, and repository policy files. - Compare the files with
references/governance-review-checklist.md. - Separate soft controls from enforceable controls.
- Report missing or weak controls with severity and concrete remediation.
Required Output
- Scope reviewed.
- Findings ordered by risk.
- Missing required sections.
- Controls that need CI, branch protection, IAM, or scanner enforcement.
- Recommended next changes.
Source: ThisIsCKM-org/ai-agent-governance-kit — distributed by TomeVault.