# Startup Governance

> Govern startup cash, approvals, contracts, records, policy, risk, compliance, and international expansion with evidence-backed controls and explicit human authority. Use when a founder needs a governance decision, register, readiness review, or operating cadence; route legal, tax, accounting, privacy, security, employment, or jurisdiction conclusions to current qualified professionals.

- Skill: `vaibhav0806/startup-governance` (Agent Skill, multi-file: 5 files)
- Install (CLI): `npx skillmds@latest add vaibhav0806/startup-governance`
- Raw SKILL.md: https://api.skillmd.com/api/skills/vaibhav0806/startup-governance/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: vaibhav0806 (https://skillmd.com/u/vaibhav0806)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/vaibhav0806/startup-governance

---


# Startup Governance

Make consequential operating decisions traceable, current, authorized, and reversible where possible. This skill prepares analyses, registers, checklists, agendas, drafts, and decision records; it does not sign, file, pay, approve, communicate an incident, or commit the company.

## Workflow

1. Establish the decision, company/entity, jurisdiction(s), decision owner, intended audience, deadline or evidence trigger, and whether an external side effect is requested. Ask only for missing information that could change the result.
2. Build an evidence register for material inputs: `item | status | actual_or_modelled | source | source_date | as_of | owner | confidence | conflict | refresh_or_expiry`. Use `observed`, `inferred`, `proposed`, `stale`, or `conflicting`; use `unknown` when no evidence exists.
3. Read [finance-approvals.md](references/finance-approvals.md) for cash, budget, close, tax, payments, reserves, scenarios, and finance approval records.
4. Read [legal-board-policy.md](references/legal-board-policy.md) for contracts, entity and cap-table records, authority, board materials, resolutions, conflicts, policies, and action tracking.
5. Read [risk-expansion.md](references/risk-expansion.md) for risk, security, privacy, continuity, vendors, incidents, policy lifecycle, and international readiness.
6. Return the diagnosis, dated evidence and confidence, missing/stale/conflicting inputs, recommendation and alternatives, a finished register/checklist/draft, risks and required approvals, one owner, deadline or trigger, metric, review date, and the smallest useful handoff.

## Decision gates

- Separate reconciled actuals from budgets, forecasts, scenarios, commitments, and proposals. Never invent cash, runway, budget, tax, liability, contract, cap-table, risk, or readiness values.
- No material finance, contract, board, policy, security, privacy, employment, tax, or expansion decision is `ready` while a required input is unknown, stale, or conflicting. Name the reconciliation owner and next gate.
- Use one canonical source per material item. Preserve conflicting values and their dates; do not silently choose the newest, largest, or most convenient value.
- Record every material approval as `decision | rationale | evidence_as_of | approver | authority_basis | date | conditions | owner | next_review | supersedes`.
- Escalate current jurisdiction-specific conclusions to qualified legal, accounting, tax, employment, privacy, security, or other regulated professionals. State the jurisdiction, source date, review date, and limitation.
- Require explicit human authorization immediately before any signature, filing, payment, transfer, board/member action, policy approval, incident communication, vendor commitment, external disclosure, or international expansion commitment.
- Minimize personal, customer, employee, financial, security, legal, and board data. Use approved restricted systems and applicable retention, deletion, legal-hold, and access rules.

## Boundaries and handoffs

- Hand off cash planning, spending decisions, operating priorities, hiring capacity, and review cadence to `founder-operations` with reconciled evidence, assumptions, owner, deadline, metric, and review date.
- Hand off fundraising economics, cap-table disclosure, financing terms, and diligence access to `startup-fundraising` with the exact evidence status and approval gates.
- Hand off worker classification, employment terms, benefits, immigration, tax, or entity questions to qualified advisers and `startup-hiring` or `founder-operations` as appropriate.
- Hand off customer-data, support, incident, vendor, or privacy work to `customer-success` and the appropriate technical/security owner with scope, data role, severity, evidence, and authorization status.
- Direct invocation remains self-contained; do not require `startup-operator` first for a clearly bounded governance request.

## Safe failure

- Missing critical input: state the exact field, why it changes the decision, owner, and evidence request.
- Stale or conflicting evidence: stop the affected conclusion, show the conflict, and define the refresh or reconciliation trigger.
- Unsupported claim: downgrade it to a hypothesis or open gate; never represent a draft policy, forecast, review, or intention as an approved control.
- No meaningful pattern: report the baseline and measurement gap.
- External action requested without authority: prepare the artifact and approval request only.

