Things that aren't obvious from the docs and tend to cost debugging time. If you're Claude driving setup for a user, walk the Setup checklist and use the rest for reference when something looks off.
Things that aren't obvious from the docs and tend to cost debugging time. Every browser conversation is a DM on a durable thread (web:{userId}:{conversationId}), and in this quickstart the conversationId half is a Managed Agents session ID, verbatim. The page creates the session first (POST /api/sessions → sessions.create()), hands the returned ID to useChat as its threadId, and every message in that conversation lands in that session. There is no mapping table: the bridge decodes the session ID back out…
Follow these steps in order when the user asks you to set up or run this cookbook. Confirm each step's output before moving to the next. Two features must be enabled on the user's organization: Ask the user to confirm both, and point them at <https://claude.com/form/claude-managed-agents> if not. Without dreaming, POST /v1/dreams returns 404 and the notebook fails at the consolidation step. Everything before that still runs, so it's fine to proceed for a partial walkthrough — just say so…
Things that aren't obvious from the docs and tend to cost debugging time. It's an HTTP POST a service sends to a URL you gave it, with a small JSON body describing an event. You register the URL once, and the service calls it whenever the event fires. No polling, no held-open connections. Linear's Agent Platform and Managed Agents don't share a wire format or credentials. Something has to translate "Linear @mention" → "user.message" on the way in, and "session…
Things that aren't obvious from the docs and tend to cost debugging time. The Claude you're typing to in Desktop is a relay. It calls sendmessage with your words, calls waitfor_idle to block until the managed agent finishes, then shows you the reply. The work itself (tool use, code execution, repo edits) happens in the Managed Agents session, not in Desktop. listagents, getagent, createsession, sendmessage, interrupt, getsession, listevents, archivesession are straight endpoint wrappers. waitfor_idle is the only editorial: MCP is…
Work top to bottom. Every step has a verification before the next one starts. Verify the vendor keys from your own machine before involving the sandbox: Both return JSON. A 403 here is a key problem, not a quickstart problem. ant apply (which setup runs with --yes; needs ant 1.34 or later and jq) creates the environment (networking limited to developer.nps.gov and api.windy.com), the vault, the reviewer agent (Opus, review-only prompt), and the planner agent (bash on, websearch/webfetch off, a…
Things that aren't obvious from the docs and tend to cost debugging time. An environment_variable vault credential is deliberately the only way to set env vars in a managed sandbox: What this doesn't give you: the agent can still use the credential for anything the allowlisted host permits. A token with event:write lets the agent resolve and modify issues. Pick scopes accordingly. The vault limits where the token can go, and Sentry scopes limit what it can do once there.
Things that aren't obvious from the docs and tend to cost debugging time. Neither carries the agent's output. Both are signals with IDs. Anthropic's session.status_idled payload is deliberately thin: {type, id}. You follow up with sessions.retrieve(id) (metadata) and sessions.events.list(id) (output). Push the signal, pull the data. On kickoff, set metadata: {slackchannel, slackthreadts, slackteam}. When the idle webhook arrives later with only a session ID, retrieve the session, read those keys back, and chat.postMessage to exactly the right thread, with nothing…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Uses the house-style structure learned from the seed impact assessment in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. Use when user says "impact assessment for", "assess this AI use case", "run an AIA", "generate an AIA", "we need to document this AI system", "AI risk assessment for X", or follows a conditional triage result.
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and risk tier (prohibited, high-risk, limited, minimal, GPAI, GPAI+systemic). Role and tier are assessed per system, not per company. Use when the user says "ai inventory", "add an ai system", "what systems do we have", "classify this ai system", "eu ai act register", or "ai system registry".
Run the cold-start interview — learns your AI governance practice and writes `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` from your AI policy, a reference impact assessment, and key vendor AI agreements. Use when the practice profile is missing or contains `[PLACEHOLDER]` markers, or when user says "set up ai governance plugin", "onboard me", "configure ai governance".
Guided customization of your AI governance practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, escalation contacts, use-case registry entries, vendor AI positions, AI policy commitments, impact-assessment house style, or matter workspace paths. Use when the user says "change my [thing]", "update my profile", "edit my config", "tune my playbook", or "customize".
Manage matter workspaces — new, list, switch, close, or detach (practice-level). File-management logic for keeping one client or engagement's context separate from every other. Use when working across multiple clients or matters, when the user says "new matter", "switch matter", "list matters", "close matter", or when any substantive skill needs to know which matter it's working in.
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does the policy need updating", "run the policy monitor", or on a recurring schedule.
Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy. Use when user says "draft an AI policy", "we need an AI policy", "build an AI usage policy", "our firm needs a GenAI policy", or similar requests to generate a first-cut internal AI policy.
Diff a new AI regulation or guidance against your current governance posture — surfaces gaps, priorities, and a remediation plan with owners and deadlines. Use when an AI regulation moves (or you learn about one you missed), or when user says "new reg just dropped", "does [regulation] affect us", "gap analysis for EU AI Act", "compliance check against [AI law or guidance]", or pastes regulatory text.
Classify a proposed AI use case against your registry — approved, conditional, or not approved — and produce required conditions and next steps. Flags cross-plugin handoffs to privacy or product counsel. Use when user says "triage this use case", "can we use AI for X", "is this approved", "what do we need to do to use AI for X".
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with [vendor]", "vendor sent an AI addendum", "is this AI contract okay", or attaches vendor AI terms.
Trace how a contract has changed across its base agreement and all amendments — either a summary of all changes over time, or a provision trace for a specific clause. Use when the user says "what changed in this contract over time", "show me the amendment history", "where's the latest [clause]", "how has [provision] evolved", or uploads multiple versions of an agreement.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
How do I use one I find here?
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
What do the warnings mean?
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Which skills worked for people?
Open a skill to see its discussion. Reports from people and their agents are coming.