← Files Development OSARCHIVED FILE
skills/specialist-reasoning/references/risk-business-domain.md
2.47 KB · Oct 4, 2026 · 12:34 UTC
# Risk, Business, Operations, and Domain Perspectives Load only the functions triggered by the current objective. ## Security engineering Trigger on authentication, authorization, external access, sensitive state, trust boundaries, abuse surface, destructive operations, or consequential integrations. Focus on realistic threats, privilege, attack surface, safe failure, and security architecture. Use current authoritative security evidence where claims depend on changing threats or standards. ## Privacy / trust & safety Trigger on personal data, sharing, public content, moderation, identity, tracking, surveillance implications, or user-to-user abuse. Focus on consent, minimization, visibility, misuse, trust expectations, and recovery. ## Legal / regulatory / compliance Trigger on privacy regimes, payments, contracts, public claims, licensing/IP, regulated domains, children's data, or binding policy. Identify issues and research current authoritative sources; do not present simulated legal reasoning as legal advice or authority. ## Product marketing / growth Trigger on public capabilities, acquisition, onboarding, launches, positioning, distribution, activation, retention, or feature adoption. Focus on why users should care, how value is communicated, and what path leads from discovery to successful use. ## Business / finance / pricing Trigger on paid capability, entitlement, provider cost, pricing, margin, recurring spend, material infrastructure cost, or business-model implications. Focus on economic ownership and sustainability, not generic budgeting ceremony. ## Platform / SRE / operations Trigger on durable/background work, uptime, migrations, queues, incidents, backups, provider reliability, capacity, recovery, or operational toil. Focus on runability, failure containment, observability, rollback, and long-term burden. ## Developer experience / technical writing Trigger on APIs, MCPs, SDKs, CLIs, developer tooling, public schemas, integration docs, error contracts, or technical onboarding. Focus on discoverability, examples, contract clarity, migration, errors, and whether another developer can succeed without hidden context. ## Domain specialist Trigger when generic software/product expertise cannot establish correctness. Examples include games, finance, healthcare, education, media production, hardware, scientific domains, or specialized creator workflows. Use real domain evidence where correctness matters; do not substitute plausible-sounding inference for expertise.
SHA-256: 4bb357e75d9cc234d775dc78eab1a7bd329503a8a08130cbba09d29acbc478db