本文へ移動
cccskills
無料GitHub で公開

codexkit-policy-document-writer

Author structured policy documents and Standard Operating Procedures (SOPs) following ISO document control standards. Covers purpose, scope, roles, policy statements, procedures, compliance monitoring, and review schedules. Use when creating corporate policies, operational procedures, or governance documents.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md6.4 KB
  • agents/openai.yaml178 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Policy Document Writer

When to Use

  • When creating a new corporate policy or procedure
  • When formalizing informal processes into official SOPs
  • When audit findings require documented policies
  • When regulatory requirements demand written procedures

Procedure

Step 1 — Document Control Header

FieldValue
Document IDPOL-[Department]-[NNN]
Title[Clear, specific title]
Version1.0
Effective Date[Date]
Review Date[12 months from effective]
Owner[Role/Name]
Approver[Role/Name]
ClassificationInternal / Confidential / Public

Step 2 — Purpose & Scope

Purpose: One paragraph explaining:

  • WHY this policy exists
  • WHAT problem it addresses
  • WHAT compliance requirement it satisfies (if any)

Scope:

  • Who this applies to (roles, departments, locations)
  • What it covers (and explicitly what it does NOT cover)
  • When it takes effect

Step 3 — Definitions

Define key terms to avoid ambiguity:

TermDefinition
PIIPersonally Identifiable Information — any data that can identify an individual
Data ControllerEntity that determines purposes and means of processing personal data

Step 4 — Roles & Responsibilities

RoleResponsibilities
Policy OwnerMaintains, reviews, updates the policy
Department HeadsEnsures team compliance, reports violations
All EmployeesReads, understands, follows the policy
Compliance TeamMonitors adherence, conducts audits

Step 5 — Policy Statements

Write clear, enforceable statements:

Good:

All employees must complete security awareness training within 30 days of hire and annually thereafter.

Bad:

Employees should try to complete training when possible.

Rules for policy statements:

  • Use "must" for requirements, "should" for recommendations
  • Be specific about timeframes, quantities, and thresholds
  • Include consequences for non-compliance
  • Reference related policies by ID

Step 6 — Procedures (SOP)

For each procedure, document step-by-step:

StepActionResponsibleSystemNotes
1Receive request via [channel][Role][System]—
2Verify requester identity[Role][System]Check against directory
3Assess request against policy[Role][Checklist]Use form X-123
4Approve or deny with reason[Role][System]Document decision

Include decision trees for complex procedures:

  • If [condition A] → follow path 1
  • If [condition B] → escalate to [role]

Step 7 — Compliance & Monitoring

CheckMethodFrequencyResponsible
Training completionLMS reportMonthlyHR
Policy acknowledgmente-signatureAnnualCompliance
Incident reviewAudit logQuarterlySecurity

Step 8 — Review Schedule

TriggerAction
Annual review dateFull review by policy owner
Regulatory changeImpact assessment within 30 days
Significant incidentReview and update within 15 days
Organizational changeReview scope and applicability

Inputs

InputRequiredFormat
Policy topicYesWhat the policy covers
Regulatory requirementsRecommendedApplicable laws/standards
Existing informal processesRecommendedCurrent practices to formalize
Approval authorityYesWho approves the policy

Output

# POL-IT-003: Acceptable Use Policy

**Version:** 1.0 | **Effective:** 2024-04-01 | **Review:** 2025-04-01
**Owner:** IT Director | **Approver:** CIO

## 1. Purpose
This policy defines acceptable use of company IT resources to protect
organizational assets and ensure compliance with data protection regulations.

## 2. Scope
Applies to all employees, contractors, and third parties who access
[Company] IT systems, networks, or data.

## 3. Definitions
[Key terms table]

## 4. Roles & Responsibilities
[RACI-style table]

## 5. Policy Statements
5.1 All users MUST use unique credentials...
5.2 Personal devices MUST be enrolled in MDM...

## 6. Procedures
[Step-by-step procedures for common scenarios]

## 7. Compliance Monitoring
[Audit schedule and methods]

## 8. Change Log
| Version | Date | Author | Changes |
|---------|------|--------|---------|
| 1.0 | 2024-04-01 | IT Director | Initial release |

Definition of Done

  • Document control header complete
  • Purpose and scope clearly defined
  • Key terms defined to avoid ambiguity
  • Roles and responsibilities assigned
  • Policy statements use "must" language
  • Procedures are step-by-step with responsible roles
  • Compliance monitoring plan included
  • Review schedule and change log present

Quality Criteria

  • All placeholder sections are filled with domain-specific content
  • Structure follows the relevant industry standard or framework
  • Language matches target audience (technical / executive / legal)
  • Output is ready for review — not a rough draft requiring major rework

Verification (4C)

CheckQuestion
CorrectnessDoes the draft structure follow the stated framework or industry standard?
CompletenessAre all required sections present with substantive (not placeholder) content?
Context-fitDoes tone, detail level, and terminology match the intended audience?
ConsequenceIf sent to the intended recipient without further editing, what would fail?

Edge Cases

  • No existing template for this type — Use the closest available template and document all customizations made.
  • Stakeholder requirements conflict — Flag conflicts explicitly in the draft. Do not silently choose one requirement over another.
  • Output required in multiple formats — Produce the canonical format first, then derive others. Note any formatting limitations.

Changelog

  • v1.0.0 — Initial release

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Design rigorous A/B test plans with hypothesis, sample size calculation, Minimum Detectable Effect (MDE), randomization strategy, and decision rules. Includes guardrail metrics and rollout playbook. Use when planning product experiments, conversion optimization, or data-driven feature decisions.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Review REST and GraphQL API designs for consistency, usability, and best practices. Covers naming conventions, versioning strategy, error format, pagination, authentication patterns, and breaking change detection. Use when reviewing API specs, designing new APIs, or auditing existing endpoints.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Write Architecture Decision Records (ADRs) following the Michael Nygard format. Captures context, options considered, decision rationale, and consequences. Use when making technology choices, framework selections, or any architectural decision that future developers need to understand.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Assess organizational readiness for financial audits (internal or external). Map assertions to account balances, check evidence completeness, score readiness using a Red/Amber/Green framework, and generate a remediation timeline. Aligned with SOX, IFRS, and GAAP audit standards. Use before scheduled audits or when preparing for first-time compliance.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Design safe recurring Codex automations with clear prompts, outputs, schedules, and gating rules.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

Refine Product Backlog Items to meet INVEST criteria. Write User Stories with Acceptance Criteria in Given/When/Then format, estimate with Story Points, and flag dependencies. Use before sprint planning when backlog items need grooming. Do not use to prioritize the backlog — that is the Product Owner's decision.

日本語の概要は準備中です。原文の説明を表示しています。

hoavdc/CodexKit252026年10月11日 更新

hoavdc のスキルをすべて見る

このスキルの問題を報告する