← Files Development OSARCHIVED FILE

skills/specialist-reasoning/references/risk-business-domain.md

2.47 KB · Oct 4, 2026 · 12:34 UTC

↓ Download file

# Risk, Business, Operations, and Domain Perspectives

Load only the functions triggered by the current objective.

## Security engineering
Trigger on authentication, authorization, external access, sensitive state, trust boundaries, abuse surface, destructive operations, or consequential integrations. Focus on realistic threats, privilege, attack surface, safe failure, and security architecture. Use current authoritative security evidence where claims depend on changing threats or standards.

## Privacy / trust & safety
Trigger on personal data, sharing, public content, moderation, identity, tracking, surveillance implications, or user-to-user abuse. Focus on consent, minimization, visibility, misuse, trust expectations, and recovery.

## Legal / regulatory / compliance
Trigger on privacy regimes, payments, contracts, public claims, licensing/IP, regulated domains, children's data, or binding policy. Identify issues and research current authoritative sources; do not present simulated legal reasoning as legal advice or authority.

## Product marketing / growth
Trigger on public capabilities, acquisition, onboarding, launches, positioning, distribution, activation, retention, or feature adoption. Focus on why users should care, how value is communicated, and what path leads from discovery to successful use.

## Business / finance / pricing
Trigger on paid capability, entitlement, provider cost, pricing, margin, recurring spend, material infrastructure cost, or business-model implications. Focus on economic ownership and sustainability, not generic budgeting ceremony.

## Platform / SRE / operations
Trigger on durable/background work, uptime, migrations, queues, incidents, backups, provider reliability, capacity, recovery, or operational toil. Focus on runability, failure containment, observability, rollback, and long-term burden.

## Developer experience / technical writing
Trigger on APIs, MCPs, SDKs, CLIs, developer tooling, public schemas, integration docs, error contracts, or technical onboarding. Focus on discoverability, examples, contract clarity, migration, errors, and whether another developer can succeed without hidden context.

## Domain specialist
Trigger when generic software/product expertise cannot establish correctness. Examples include games, finance, healthcare, education, media production, hardware, scientific domains, or specialized creator workflows. Use real domain evidence where correctness matters; do not substitute plausible-sounding inference for expertise.

SHA-256: 4bb357e75d9cc234d775dc78eab1a7bd329503a8a08130cbba09d29acbc478db