use-case-triage

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

/use-case-triage

/use-case-triage

  1. Read
    ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
    . Confirm registry is populated — if not, stop and direct to setup.
  2. Use the framework below. Clarify the use case if vague.
  3. Registry lookup → red line check → classify.
  4. Output: classification, reasoning, conditions table (if conditional), governance tier, cross-plugin handoffs.
  5. Propose registry update if use case wasn't already in the registry.
/ai-governance-legal:use-case-triage "Sales team wants to score leads with AI automatically"

  1. 读取
    ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
    文件。确认注册表已填充——若未填充,请停止操作并引导用户完成设置。
  2. 使用下方框架。若用例描述模糊,请先澄清。
  3. 注册表查询→红线检查→分类。
  4. 输出内容:分类结果、推理过程、条件表格(若为有条件批准)、治理层级、跨插件交接提示。
  5. 若用例未在注册表中,建议更新注册表。
/ai-governance-legal:use-case-triage "Sales team wants to score leads with AI automatically"

Matter context

事项上下文

Matter context. Check
## Matter workspaces
in the practice-level CLAUDE.md. If
Enabled
is
(the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run
/ai-governance-legal:matter-workspace switch <slug>
or say
practice-level
." Load the active matter's
matter.md
for matter-specific context and overrides. Write outputs to the matter folder at
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/
. Never read another matter's files unless
Cross-matter context
is
on
.

事项上下文。查看实践层面CLAUDE.md中的
## Matter workspaces
部分。如果
Enabled
(内部用户默认设置),则跳过本段剩余内容——技能将使用实践层面的上下文,事项机制不可见。如果已启用且没有活跃事项,请询问:“这是针对哪个事项的?运行
/ai-governance-legal:matter-workspace switch <slug>
或说明
practice-level
。”加载活跃事项的
matter.md
文件以获取特定于事项的上下文和覆盖规则。将输出写入事项文件夹
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/
。除非
Cross-matter context
on
,否则切勿读取其他事项的文件。

Purpose

目的

Stop the conversation that happens in a hallway and starts as "can we just use AI for this?" Give a fast, calibrated answer from the registry — and if the answer is conditional, make the conditions concrete and the next step obvious.
The triage skill is a gateway, not a destination. Its job is to classify, flag what's required, and route. The aia-generation skill does the deep work.
终结始于走廊的这类对话:“我们能不能直接把AI用在这个场景上?”基于注册表给出快速、精准的答案——若答案为有条件批准,则明确具体条件和下一步操作。
筛选技能是入口而非终点。其职责是分类、标记所需要求并转介。AI影响评估(AIA)生成技能负责深入工作。

Read
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
first

先读取
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件

Before triaging, always read
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
. The use case registry and red lines there are authoritative. Generic AI ethics reasoning is not a substitute for what this company has actually decided.
If
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
contains
[PLACEHOLDER]
, surface this bounce:
I notice you haven't configured your practice profile yet — that's how I tailor the use case registry, red lines, and governance tiers to your practice.
Two choices:
  • Run
    /ai-governance-legal:cold-start-interview
    (2 minutes) to configure your profile, then I'll triage tailored to YOUR practice.
  • Say "provisional" and I'll triage against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output
    [PROVISIONAL — configure your profile for tailored output]
    so you can see what I do before committing.
在进行筛选前,务必读取
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件。其中的用例注册表和红线规则具有权威性。通用AI伦理推理不能替代公司实际做出的决策。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件包含
[PLACEHOLDER]
,请提示以下内容:
我注意您尚未配置实践档案——这是我为您定制用例注册表、红线规则和治理层级的依据。
两种选择:
  • 运行
    /ai-governance-legal:cold-start-interview
    (耗时2分钟)配置档案,之后我将根据您的实践情况进行筛选。
  • 回复“临时模式”,我将基于通用默认规则进行筛选——美国管辖区域、中等风险偏好、律师角色、无操作手册——并在所有输出中标注
    [PROVISIONAL — configure your profile for tailored output]
    ,以便您在确认前了解我的操作结果。

Provisional mode

临时模式

If the user says "provisional," run triage normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no registry (classify by general AI governance principles rather than matching to a registered entry). Tag the reviewer note and every finding block with
[PROVISIONAL]
. At the end of the output, append:
"That was a generic run against default assumptions. Run
/ai-governance-legal:cold-start-interview
to get output calibrated to YOUR practice — your registry, your jurisdiction, your risk appetite. 2 minutes."
Jurisdictional scope. Triage applies the registry, red lines, and governance tiers configured for the regulatory footprint in
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
. AI rules vary materially by jurisdiction — an APPROVED classification in one footprint may be CONDITIONAL or prohibited in another. If deployment touches a jurisdiction not in the footprint, surface that and re-triage rather than extending by analogy.

若用户回复“临时模式”,请使用以下通用默认规则正常运行筛选:中等风险偏好、律师角色、美国管辖区域、无注册表(根据通用AI治理原则分类,而非匹配已注册条目)。在评审说明和每个结果块中标注
[PROVISIONAL]
。在输出末尾添加:
“这是基于默认假设的通用运行结果。运行
/ai-governance-legal:cold-start-interview
可根据您的实践情况——您的注册表、管辖区域、风险偏好——生成校准后的输出,仅需2分钟。”
管辖范围。筛选将应用
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件中针对监管覆盖范围配置的注册表、红线规则和治理层级。AI规则因管辖区域差异显著——在某一覆盖范围内获批的分类,在另一区域可能为有条件批准或被禁止。若部署涉及未纳入覆盖范围的管辖区域,请提示并重新进行筛选,而非类推适用。

Triage process

筛选流程

Step 1: Understand the use case

步骤1:理解用例

Before classifying, make sure you understand what's actually being proposed. If the description is vague, ask:
  • "What is the AI doing, exactly — generating content, making a decision, surfacing recommendations, automating a task?"
  • "Who or what is the AI acting on — employees, customers, third parties, internal data only?"
  • "Is a human reviewing the AI output before anything happens, or is it automated?"
  • "Which vendor or tool is being proposed?"
  • "Is this internal-only, or does it touch customers or other external parties?"
Don't let "we want to use AI for [vague thing]" go untriaged. Get specific enough to classify accurately.

在分类前,确保准确理解拟议的内容。若描述模糊,请询问:
  • “AI具体执行什么操作——生成内容、做出决策、提供建议、自动化任务?”
  • “AI作用于谁或什么对象——员工、客户、第三方、仅内部数据?”
  • “在执行任何操作前,是否有人类审核AI输出,还是完全自动化?”
  • “拟议使用哪个供应商或工具?”
  • “这仅用于内部,还是会涉及客户或其他外部方?”
切勿对“我们想把AI用于[模糊场景]”这类表述直接进行筛选。需获取足够具体的信息以确保分类准确。

Step 2: Registry lookup

步骤2:注册表查询

Check the use case registry in
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
for a direct or close match.
Direct match: If the registry has a directly matching entry, apply it.
Near match: If the use case is similar to a registry entry but not identical, flag this: "This looks like [registered use case] — I'm applying that classification, but if the scope is meaningfully different, it may need its own assessment."
No match: If the use case isn't in the registry, default to CONDITIONAL pending an AI impact assessment. Surface the preliminary read on risk and route to the AIA.
"This use case isn't in your registry yet. Defaulting to CONDITIONAL pending an AI impact assessment. Here's my preliminary read on risk: [preliminary read]. Next step: run the impact assessment, and I'll add the use case to the registry once classification is settled."

~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件的用例注册表中查找直接或近似匹配的条目。
直接匹配:若注册表中有完全匹配的条目,直接应用该分类。
近似匹配:若用例与注册表条目相似但不完全相同,请提示:“这看起来与[已注册用例]类似——我将应用该分类,但如果范围存在显著差异,可能需要单独评估。”
无匹配:若用例未在注册表中,默认归类为有条件批准,待完成AI影响评估后确认。提示初步风险判断并转介至AIA生成技能。
“该用例尚未纳入您的注册表。默认归类为有条件批准,待完成AI影响评估后确认。以下是我的初步风险判断:[初步判断内容]。下一步:运行影响评估,分类确定后我会将该用例添加至注册表。”

Source attribution (applies whenever the triage cites regulation)

来源归因(当筛选引用法规时适用)

Triage typically stays high-level, but if the classification depends on citing a regulation, statute, rule, directive, standard, or guidance — tag the citation. Do not output untagged regulatory citations in the triage reasoning, the red-line explanation, or the conditions list. A triage that says "Art. 22(1)" without a tag is exactly where a fabricated pinpoint slips past the reader.
Source attribution tiering. For model-knowledge citations, use one of three tiers:
  • [settled]
    — stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 22 as a concept, the existence of Regulation (EU) 2024/1689 as the EU AI Act). Still verify before certifying, but lower priority.
  • [verify]
    — model-knowledge citations that are real but should be verified: specific delegated / implementing acts, regulator guidance, standards, effective dates, thresholds, post-2023 amendments.
  • [verify-pinpoint]
    — pinpoint citations (specific article numbers, annex references, subsection letters, paragraph numbers) carry the highest fabrication risk and should ALWAYS be verified against a primary source. EU AI Act article numbers in particular shifted during consolidation; every pinpoint cite to the Act should be verified against the Official Journal text.
Other sources keep their own tags:
[registry]
when drawn from the practice profile's use case registry;
[Westlaw]
,
[EUR-Lex]
,
[regulator site]
, or the MCP tool name when retrieved from a connected legal research tool;
[web search — verify]
for web-search citations;
[user provided]
for user-supplied citations. The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.
For non-lawyer users, uncertain dates and thresholds go in a confirm-list, not inline. A
[verify]
tag on "effective February 1, 2026" reads as "effective February 1, 2026" to someone who doesn't know what the tag means. Read
## Who's using this
in
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
. If Role is Non-lawyer and an effective date, phase-in, threshold, or deadline is uncertain (would carry
[verify]
or
[verify-pinpoint]
if inline), replace the inline assertion with "effective date: confirm with counsel" (or "threshold: confirm with counsel") and collect all uncertain assertions in a final triage section titled: "Things I'm not certain about — ask your attorney to confirm before relying on this:" with each item listed (what I said, what's uncertain, why it matters). Lawyer-role users keep the inline
[verify]
treatment.

筛选通常保持较高层面,但如果分类依赖引用法规、法令、规则、指令、标准或指南,请为引用添加标签。在筛选推理、红线解释或条件列表中,不得输出未标记的法规引用。若筛选中仅提及“第22(1)条”而未添加标签,极易导致伪造的精准引用被读者忽略。
来源归因层级。对于模型知识库中的引用,使用以下三个层级之一:
  • [settled]
    ——稳定、知名的法规引用,不太可能发生变化(例如,GDPR第22条的概念,欧盟《AI法案》(Regulation (EU) 2024/1689)的存在)。仍需在认证前验证,但优先级较低。
  • [verify]
    ——模型知识库中的引用真实存在,但需验证:具体的授权/实施法案、监管指南、标准、生效日期、阈值、2023年后的修订内容。
  • [verify-pinpoint]
    ——精准引用(具体条款编号、附件引用、子款字母、段落编号)存在最高的伪造风险,必须对照原始来源进行验证。尤其是欧盟《AI法案》的条款编号在整合过程中发生过变动,对该法案的每一处精准引用都应对照官方公报文本进行验证。
其他来源使用各自的标签:从实践档案的用例注册表中提取的内容标记为
[registry]
;从关联法律研究工具获取的内容标记为
[Westlaw]
[EUR-Lex]
[regulator site]
或MCP工具名称;网络搜索获取的引用标记为
[web search — verify]
;用户提供的引用标记为
[user provided]
。层级划分明确了实际的验证工作——读者若验证所有内容,等于未进行有效验证。切勿移除或合并标签。
针对非律师用户,不确定的日期和阈值应放入确认列表,而非直接内联。对于不了解标签含义的用户,带有
[verify]
标签的“2026年2月1日生效”会被直接理解为“2026年2月1日生效”。查看
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件中的
## Who's using this
部分。若角色为非律师,且生效日期、分阶段实施、阈值或截止日期不确定(若内联会带有
[verify]
[verify-pinpoint]
标签),请将内联断言替换为“生效日期:请咨询法律顾问确认”(或“阈值:请咨询法律顾问确认”),并在筛选末尾添加标题为“我无法确定的事项——依赖前请咨询您的律师确认:”的部分,列出各项内容(我所说的内容、不确定的点、为何重要)。律师角色用户保留内联
[verify]
处理方式。

Step 3: Red line check

步骤3:红线检查

Before going further, check the red lines in
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
.
If the use case triggers a red line — even partially, even in a charitable reading — say so immediately.
"This use case touches [red line]. Your red lines treat this as an automatic no. If there's something different about this situation, that's a conversation for legal sign-off — not a triage call."
Do not soften red line outcomes. If it's a no, it's a no.

Jurisdictional scope. Ask: "Who's affected, and where are they? (Employees / customers / the general public / specific groups.) Which jurisdictions? (Not just where your company is — where the affected people are.)"
Then check the use case against EVERY regime in the practice profile's
## Regulatory footprint
, not just the primary one. Flag conflicts:
  • "APPROVED under US law, but triggers EU AI Act Article 27 FRIA if EU residents are affected — confirm whether any affected individuals are in the EU."
  • "Standard tier under your governance framework, but NYC LL144 requires a bias audit if used for hiring decisions affecting NYC residents."
  • "Low risk under Australian AI Ethics Framework, but may be high-risk under the Colorado AI Act if Colorado residents are affected."
A use case that crosses jurisdictions gets the strictest applicable treatment, not the most convenient one.

在继续操作前,检查
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件中的红线规则。
若用例触发红线——即使是部分触发,即使从善意角度解读——请立即告知用户。
“该用例涉及[红线内容]。您的红线规则将此视为直接禁止项。若此场景存在特殊情况,需与法律团队沟通确认——而非通过筛选流程决定。”
不得弱化红线规则的结果。若为禁止项,则直接判定为不批准。

管辖范围。询问:“哪些对象会受到影响,他们位于何处?(员工/客户/公众/特定群体)涉及哪些管辖区域?(不仅是您公司所在区域,还包括受影响对象所在区域)”
然后对照实践档案
## Regulatory footprint
中的所有制度检查用例,而非仅主要制度。标记冲突:
  • “根据美国法律获批,但如果涉及欧盟居民,将触发欧盟《AI法案》第27条FRIA要求——请确认是否有受影响的个人位于欧盟。”
  • “根据您的治理框架属于标准层级,但如果用于影响纽约居民的招聘决策,NYC LL144要求进行偏见审计。”
  • “根据澳大利亚AI伦理框架属于低风险,但如果涉及科罗拉多居民,可能根据科罗拉多AI法案被列为高风险。”
跨管辖区域的用例应适用最严格的规则,而非最便利的规则。

Step 4: Classification and output

步骤4:分类与输出

The APPROVED / CONDITIONAL / NOT APPROVED buckets, the red-line definitions, and the CONDITIONAL required-controls list all come from
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
## AI use case triage criteria
and
## Use case registry
. If the playbook doesn't define a criterion the use case turns on, ask the user: "Your playbook doesn't cover [specific question]. What's your default position? I'll add it to
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
so the next triage is consistent."
Before issuing an APPROVED classification (approving an AI use case for deployment): Read
## Who's using this
in
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
. If the Role is Non-lawyer:
Approving this use case for deployment has legal consequences. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:
[Generate a 1-page summary: the use case and its scope, how it maps to the registry, what policies or red lines it touches, what could go wrong in deployment, what to ask the attorney before green-lighting.]
If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Do not proceed past this gate without an explicit yes. CONDITIONAL outputs do not require the gate.
Before issuing a NOT APPROVED classification that cuts off a proposed use case: Read
## Who's using this
in
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
. If the Role is Non-lawyer, a symmetric gate applies — wrongly rejecting a use case is also a consequential error, and the business will push back regardless of the triage call:
This is a full stop for a business ask. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:
[Generate a 1-page summary: the use case and its scope, the specific red line or registry entry that blocks it, what a narrower version could look like that might clear elevated tier (if anything), what the business will likely ask the attorney for, and the three questions to ask the attorney before accepting the no.]
If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Do not proceed past this gate without an explicit yes. A non-lawyer issuing a hard no on the AI plugin's behalf, without an attorney in the loop, is the mirror failure of a non-lawyer issuing a hard yes.
Format for each triage output:

[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see
## Who's using this
]
USE CASE: [State the use case as you understand it]
CLASSIFICATION: [APPROVED / CONDITIONAL / NOT APPROVED]
Registry match: [Direct match / Near match — [name] / No match]
Reasoning: [1-3 sentences on why this classification. If approved, what makes it safe. If conditional, what creates the risk that conditions are managing. If not approved, what red line or policy position applies.]
Red lines triggered: [None / List any that apply]

If CONDITIONAL — required before proceeding:
RequirementOwnerDone?
[e.g., AI impact assessment][AI governance counsel]
[e.g., Privacy review / PIA][Privacy counsel]
[e.g., Human-in-the-loop requirement — no automated decisions][Product]
[e.g., Disclosure to affected parties][Product / Legal]
[e.g., Specific vendor only — [approved vendor name]][Procurement]
[e.g., Legal sign-off][GC]
Governance tier: [Standard / Elevated / High — per
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
]
Approval path: [Who needs to sign off, per tier]
Next step — offer to continue:
After presenting a CONDITIONAL result, always end with:
"Want me to start the impact assessment now? I can run the intake questions and produce the assessment document without you needing to run a separate command."
If they say yes, load the
aia-generation
skill and continue in the same conversation — no need to restart. Pass the use case description and governance tier already determined.
If they say no (or don't respond), the triage result stands as a standalone output. The AIA can be run any time with:
/ai-governance-legal:aia-generation [use case]

If NOT APPROVED:
Reason: [Specific red line, policy prohibition, or registry entry]
If there's a version of this that could work: [Optional — "A narrower version that keeps a human in the loop for every adverse decision might clear the elevated tier. That would require..."] Only include if genuinely true. Don't offer a workaround for every no.

批准/有条件批准/不批准的分类标准、红线定义及有条件批准所需的控制措施列表,均来自
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件中的
## AI use case triage criteria
## Use case registry
部分。若操作手册未定义用例涉及的某项标准,请询问用户:“您的操作手册未涵盖[具体问题]。您的默认立场是什么?我会将其添加至
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件,以便后续筛选保持一致。”
在发布批准分类(批准AI用例部署)前:查看
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件中的
## Who's using this
部分。若角色为非律师:
批准该用例部署会产生法律后果。您是否已与律师审核过此内容?若是,请继续。若否,请将以下摘要提交给律师:
[生成1页摘要:用例及其范围、与注册表的匹配情况、涉及的政策或红线规则、部署中可能出现的问题、批准前需向律师咨询的问题。]
若您需要寻找律师、法务顾问或其他授权法律专业人士:您所在地区的专业监管机构推荐服务是最快的起点(美国为州律师协会,英格兰及威尔士为SRA/律师标准委员会,苏格兰/北爱尔兰/爱尔兰/加拿大/澳大利亚为律师协会,或您所在管辖区域的对应机构)。
未获得明确的肯定答复前,不得继续操作。有条件批准的输出无需此环节。
在发布不批准分类(否决拟议用例)前:查看
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件中的
## Who's using this
部分。若角色为非律师,需执行对称环节——错误否决用例同样会产生重大后果,业务部门无论筛选结果如何都会提出异议:
这是对业务需求的直接否决。您是否已与律师审核过此内容?若是,请继续。若否,请将以下摘要提交给律师:
[生成1页摘要:用例及其范围、阻止该用例的具体红线规则或注册表条目、可能通过高层级审核的简化版本(若存在)、业务部门可能向律师提出的问题、接受否决前需向律师咨询的三个问题。]
若您需要寻找律师、法务顾问或其他授权法律专业人士:您所在地区的专业监管机构推荐服务是最快的起点(美国为州律师协会,英格兰及威尔士为SRA/律师标准委员会,苏格兰/北爱尔兰/爱尔兰/加拿大/澳大利亚为律师协会,或您所在管辖区域的对应机构)。
未获得明确的肯定答复前,不得继续操作。非律师代表AI插件直接做出否决决定,且未让律师参与,与直接做出批准决定的错误性质相同。
每次筛选输出的格式

[工作产品标题——根据插件配置
## Outputs
,因角色而异;查看
## Who's using this
部分]
用例: [说明您理解的用例内容]
分类: [批准/有条件批准/不批准]
注册表匹配情况: [直接匹配/近似匹配——[名称]/无匹配]
推理过程: [1-3句话说明分类原因。若为批准,说明安全依据;若为有条件批准,说明需要通过条件管控的风险;若为不批准,说明适用的红线规则或政策立场。]
触发的红线规则: [无/列出适用的规则]

若为有条件批准——继续前需满足:
要求负责人是否已完成?
[例如:AI影响评估][AI治理法律顾问]
[例如:隐私审查/PIA][隐私法律顾问]
[例如:人工介入要求——禁止自动化决策][产品团队]
[例如:向受影响方披露信息][产品团队/法律团队]
[例如:仅使用特定供应商——[获批供应商名称]][采购团队]
[例如:法律签署同意][总法律顾问]
治理层级: [标准/高级/高——根据
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件]
审批路径: [根据层级确定需要签署同意的人员]
下一步——提供后续操作选项:
在展示有条件批准结果后,务必以以下内容结尾:
“需要我现在启动影响评估吗?我可以直接运行 intake 问题并生成评估文档,无需您单独执行命令。”
若用户同意,加载
aia-generation
技能并在同一对话中继续——无需重启。传递已确定的用例描述和治理层级。
若用户拒绝(或未回复),筛选结果作为独立输出生效。可随时通过以下命令运行AIA:
/ai-governance-legal:aia-generation [use case]

若为不批准:
原因: [具体红线规则、政策禁令或注册表条目]
是否存在可行的替代版本: [可选——“若在每个不利决策中保留人工介入环节,简化版本可能通过高层级审核。这需要……”]仅在真实可行时添加。无需为每个否决项提供变通方案。

Step 5: Cross-plugin handoffs

步骤5:跨插件交接

Privacy handoff: If the use case involves personal data — employee data, customer data, behavioral data — flag it:
"This use case involves personal data. A PIA is likely required in addition to an AI impact assessment. Use
/privacy-legal:pia-generation [use case]
, if the plugin is installed, to run that in parallel."
Product counsel handoff: If this is a new product feature involving AI:
"If this use case is part of a product launch, loop in product counsel. Use
/product-legal:launch-review
, if the plugin is installed — it will detect the AI component and route to this plugin."
Only flag handoffs that are actually relevant. Don't append both as boilerplate to every triage.

隐私交接: 若用例涉及个人数据——员工数据、客户数据、行为数据——请提示:
“该用例涉及个人数据。除AI影响评估外,可能还需要进行PIA。若已安装插件,可使用
/privacy-legal:pia-generation [use case]
并行运行该流程。”
产品法律顾问交接: 若这是涉及AI的新产品功能:
“若该用例属于产品发布的一部分,请联系产品法律顾问。若已安装插件,使用
/product-legal:launch-review
——该插件会检测AI组件并转介至本插件。”
仅标记实际相关的交接提示。切勿将两者作为模板附加到所有筛选结果中。

Step 6: Registry update suggestion

步骤6:注册表更新建议

If this triage resulted in a classification that isn't in the registry yet — either a no-match or a near-match that revealed a gap:
"I'd suggest adding this to your use case registry. Proposed entry:"
| [Use case description] | [Approved/Conditional/Never] | [Conditions if any] | [Reason if Never] |
"Add to
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
→ Use case registry. This means next time the same request comes up, the answer is documented and consistent."

若本次筛选的分类结果未纳入注册表——无论是无匹配项还是近似匹配项暴露出的空白:
“我建议将该用例添加至您的注册表。拟议条目:”
| [用例描述] | [批准/有条件批准/禁止] | [条件(若有)] | [禁止原因(若有)] |
“添加至
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
文件→用例注册表。这样下次出现相同请求时,答案已记录在案且保持一致。”

Batch triage

批量筛选

If the user presents multiple use cases at once — a list, a backlog, a product roadmap — run through each one and output a summary table first, then expand each conditional or not-approved entry:
#Use caseClassificationKey condition / blocker
1[use case]🟢 Approved
2[use case]🟡 ConditionalImpact assessment required
3[use case]🔴 Not approvedAutomated adverse decision — red line
Then expand each row that isn't a clean approved.

若用户同时提交多个用例——列表、待办事项、产品路线图——请逐一处理并先输出汇总表格,再展开每个有条件批准或不批准的条目:
#用例分类关键条件/障碍
1[用例]🟢 批准
2[用例]🟡 有条件批准需要进行影响评估
3[用例]🔴 不批准自动化不利决策——触发红线规则
然后展开每个未直接批准的条目。

Edge cases and failure modes

边缘情况与失败模式

"We're already doing this" triage: If someone is asking for retroactive triage — the use case is already deployed — say so plainly, and before classifying from scratch, search the registry for an existing entry covering the deployed version. Retroactive triages often surface a superseded registry entry whose conditions have drifted from current practice; updating that entry is usually the right follow-up rather than adding a new row.
"This looks like retroactive triage. If this is already running without an assessment, that's a gap to document, not to wave through. I'm searching the registry for any existing entry covering this deployment before running the triage fresh. Here's the classification: [run normal triage]. If it's conditional, those conditions should be confirmed in place now, not assumed. If the registry has an existing entry and the deployed version has drifted, the right follow-up is updating that entry rather than adding a new one."
"It's just internal" doesn't change the analysis: Internal AI use affecting employees (screening, monitoring, evaluation) is often higher-risk than customer-facing AI. Flag this if the user implies internal scope reduces risk.
"The vendor says it's safe": Vendor representations don't substitute for your own impact assessment. Flag it:
"The vendor's position doesn't substitute for your own assessment — especially for anything in the elevated or high tier."
"We're just piloting": A pilot that touches real employee or customer data is not exempt from triage or impact assessment. Apply the same classification; if conditions include an impact assessment, the pilot should have one too.
“我们已经在使用了”的回溯筛选: 若用户要求回溯筛选——用例已部署——请明确告知,在重新分类前,先在注册表中查找涵盖已部署版本的现有条目。回溯筛选通常会发现已过时的注册表条目,其条件与当前实践存在偏差;此时正确的后续操作通常是更新该条目,而非添加新行。
“这看起来是回溯筛选。若该用例已部署但未进行评估,这是需要记录的空白,而非直接通过。我将先在注册表中查找涵盖该部署的现有条目,再重新进行筛选。以下是分类结果:[运行正常筛选流程]。若为有条件批准,需确认这些条件当前已落实,而非假设已完成。若注册表中有现有条目且已部署版本存在偏差,正确的后续操作是更新该条目,而非添加新行。”
“仅用于内部”不改变分析结果: 影响员工的内部AI使用(筛选、监控、评估)通常比面向客户的AI风险更高。若用户暗示内部范围可降低风险,请提示此点。
“供应商说这是安全的”: 供应商的声明不能替代您自己的影响评估。请提示:
“供应商的立场不能替代您的评估——尤其是针对高级或高风险层级的用例。”
“我们只是试点”: 涉及真实员工或客户数据的试点项目不能豁免筛选或影响评估。应用相同分类;若条件包含影响评估,试点项目也需完成该评估。

Close with the next-steps decision tree

以下一步决策树结尾

End with the next-steps decision tree per CLAUDE.md
## Outputs
. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
根据CLAUDE.md文件
## Outputs
部分的内容,以下一步决策树结尾。根据本技能生成的结果自定义选项——五个默认分支(起草X、升级、获取更多事实、观察等待、其他)为起点,而非固定选项。决策树为输出内容,由律师选择后续操作。