AI tools · Skills · Internal apps · Education
Your AI playbook, available where your team works.
Which AI tools are allowed, what your team has built, the skills it has
worked out, and the lessons that teach all three — written down once, with
an owner's name against every one of them, and read back by the agents your
people already work in.
The four registries
Bought, written, built, taught.
01 — Bought
AI tools
The catalogue of what you pay for. Each tool carries its status, the data
it is cleared to hold, whether the vendor trains on what you send, and
whether a DPA is signed. Where nobody knows yet, it says so — a blank
sends someone to find the answer, a guess does not.
02 — Written
Skills
The way your team has worked out how to do something, in the
Agent Skills format.
Import a folder or a zip, review it, publish it — and anyone can download
the package and hand it straight to an agent.
03 — Built
Internal apps
The dashboards, forms and small sites your own people generated in an
afternoon. The person who built it writes what it does; an admin writes
what it is permitted to hold. Deploys arrive from GitHub, so the registry
cannot quietly drift away from what is actually running.
04 — Taught
Education
A video, a write-up, or both, attached to the tool, skill or app it is
about — and it plays on that record's page, where the question gets
asked. Embeds are rebuilt from an allowlist of hosts, never from whatever
somebody pasted.
How the governance works
Reading is never gated
Everyone can look up whether a tool is allowed. Changing what a record
claims is an admin's job, because that claim is what other people rely
on. A person who cannot find the answer signs up for the tool anyway.
One name, no fallback
Every record has one owner, and that owner decides its access requests —
not "the owner or any admin". When somebody leaves, an admin reassigns
the record in the open, rather than a second approver appearing quietly.
"No" stays on the shelf
Prohibited and retired are statuses, not deletions. A refusal only works
if the next person can find it, with the reason attached and the date it
was last looked at.
Start with the tools you already have.
Invite your team, list what is in use, and put a name against each one. The
rest of it — the skills, the apps, the training — follows from there.