1---2name: box-migration-assistant3description: Use when tasks require box migration assistant with credential-aware preflight, deterministic execution, validation gates, and handoff-ready artifacts.4---56# Box Migration Assistant78## Quick Reference9| Field | Value |10| --- | --- |11| Skill ID | `180` |12| Provider | `Box` |13| Operation | `Migration Assistant` |14| Domain | `Productivity and file platforms` |15| Runtime archetype | `migration-engine` |16| Core method | `staged migration planning and cutover` |17| Primary artifact | `box-migration-cutover-plan` |18| Routing tag | `box:migration-assistant` |19| Mutating | `yes` |20| Release cycles | `3` |2122## Why This Skill Exists23We need this skill because Box workflows degrade when state changes are hard to undo once they begin. This specific skill turns Box Migration Assistant into a deterministic, auth-checked workflow for plans and executes safe migrations to or from box..2425## Trigger Checklist26- [ ] The task explicitly requires `Box Migration Assistant` rather than generic brainstorming.27- [ ] The provider tenant, workspace, or environment is known before execution begins.28- [ ] Credential reuse has been checked before asking for new secrets.29- [ ] Success criteria, side effects, and handoff owner are clear.30- [ ] If the run mutates provider state, the relevant approval gates are available.3132## Auth & Access Profile33| Field | Value |34| --- | --- |35| External auth required | `yes` |36| API key likely required | `no` |37| Protocols | `HTTPS/REST`, `provider SDK` |38| Mutating | `yes` |39| Webhook capable | `no` |4041| Auth Mode | Kind | Env Hints | Validation |42| --- | --- | --- | --- |43| OAuth client or delegated session | `oauth2` | `BOX_CLIENT_ID`, `BOX_CLIENT_SECRET` | Reuse an active delegated session or validate the client credentials with a lightweight identity call. |4445## Inputs (contract)46| Input | Type | Required | Source |47| --- | --- | --- | --- |48| source inventory | signal | yes | operator or upstream tool |49| target mapping | signal | yes | operator or upstream tool |50| rollback plan | signal | yes | operator or upstream tool |5152## Outputs (contract)53| Output | Type | Guaranteed | Consumer |54| --- | --- | --- | --- |55| box-migration-cutover-plan | structured-artifact | yes | next workflow or operator |56| box-migration-cutover-plan-scorecard | scorecard | yes | reviewer |57| box-migration-cutover-plan-handoff | handoff-packet | yes | downstream owner |5859## Step-by-Step Implementation Guide601. Define the source inventory, target mapping, cutover window, and rollback checkpoint for Box Migration Assistant before any Box rehearsal is approved.612. Validate credential reuse, export baselines, and the human approval chain for every irreversible migration step.623. Implement plans and executes safe migrations to or from box. as staged rehearsal, checkpoint, and cutover workflows that preserve a deterministic revert path.634. Capture migration inventories, mapping diffs, checkpoint identifiers, and partial-failure evidence in the cutover plan.645. Run simulation and regression suites that cover missing inventory, rollback weakness, and partial cutover outcomes.656. Publish a migration cutover plan with rehearsal status, rollback readiness, and the exact approval still required for production execution.6667## Operational Runbook68### Preflight69- Validate the full source inventory, target mapping, cutover window, and rollback checkpoint before rehearsal begins.70- Require an explicit human approval path for every irreversible step in the migration.7172### Execution73- Rehearse the migration with deterministic checkpoints before the production cutover is allowed.74- Pause on any unapproved mapping gap or rollback weakness rather than proceeding optimistically.7576### Recovery77- Abort cutover immediately when checkpoints or rollback evidence fail validation.78- Revert to the last stable platform state and capture every partially migrated object for review.7980### Handoff81- Return the migration cutover plan, rehearsal results, and rollback status.82- State clearly whether the migration is ready, blocked, partially rolled back, or awaiting approval.8384## Validation Gates & Test Matrix85| Gate | Purpose | On Fail |86| --- | --- | --- |87| auth-preflight | Validate credential presence, scope, and environment before work begins. | block execution |88| schema-contract-check | Ensure required signals and payload shapes remain valid. | quarantine and request correction |89| policy-approval-check | Verify the declared approval gates before mutating or publishing state. | pause or route to human review |90| reliability-check | Confirm retries, rollback, and checkpoint readiness. | rollback or fail closed |9192- Required validation suites: `unit`, `integration`, `simulation`, `regression-baseline`9394## Failure Modes & Recovery Playbook95| Code | Trigger | Action |96| --- | --- | --- |97| `E_INVENTORY_GAP` | The source inventory is incomplete or inconsistent with the target mapping. | Block rehearsal and request a corrected inventory or mapping diff. |98| `E_ROLLBACK_WEAKNESS` | Rollback checkpoints are missing or cannot restore all affected entities. | Fail closed and prohibit cutover approval. |99| `E_PARTIAL_CUTOVER` | The cutover succeeds for only a subset of the planned assets. | Abort the migration and revert to the last stable platform state. |100101## Tool Call Implementation102- Reuse existing credentials first. Check environment variables, secure stores, and active sessions before prompting.103- Start with the smallest authenticated read or validation call that proves identity and scope.104- Preserve request, response, and approval traces in `box-migration-cutover-plan` so downstream owners do not need to rediscover context.105- If any auth, contract, or approval gate fails, halt execution and attach remediation guidance instead of guessing.106107## Credential Reuse Policy108- Reuse valid provider credentials by default and prefer tenant-scoped sessions over newly created secrets.109- Prompt for credentials only when they are missing, invalid, expired, or point at the wrong environment.110- For webhook flows, validate the signing secret against a known sample before accepting live traffic.111112## Guardrails113- safety: Do not permit cutover without a rehearsed rollback checkpoint and explicit approval. (`rollback-readiness-check`)114- quality: Require inventory-to-mapping reconciliation before rehearsal and again before cutover. (`inventory-reconcile`)115- reliability: Abort immediately on partial cutover and revert to the last stable platform state. (`cutover-abort-and-revert`)116117## Acceptance Checklist118- [ ] Credential preflight and scope validation completed successfully.119- [ ] Required validation suites ran and all fail-closed gates passed.120- [ ] box-migration-cutover-plan, scorecard, and handoff packet were produced.121- [ ] Any mutations, approvals, or rollbacks are reflected in the artifact bundle.122123## Anti-Patterns124- Do not ask for new credentials before checking reusable auth context.125- Do not skip the read-only or dry-run validation step for mutating work.126- Do not proceed when approval gates, signing secrets, or rollback checkpoints are missing.127- Do not hand off partial or ambiguous provider state as complete.128129## Handoff Contract130- **Produces:** `box-migration-cutover-plan`, execution scorecard, approval trace, and next actions.131- **Consumes:** `source inventory`, `target mapping`, `rollback plan`.132- **Readiness rule:** release only after auth, contract, approval, and reliability gates all pass.133- **Downstream hint:** route to `box:migration-assistant` consumers with approval and credential context attached.134135## Observability & Continuous Improvement136- SLO: >=99.9% successful runs per 7-day window137- Error budget: <=0.1% critical failures per 7-day window138- Alert triggers:139- credential validation failures exceed baseline140- schema or contract regressions persist for two consecutive runs141- critical posture or rollback events exceed tolerance142- Primary outcome metric: `migration completeness`143- Secondary metrics: `cutover risk`, `rollback success rate`144- Review cadence: `daily`