Agent skill

Activation Governance Chaos Rollout

by Ali-Marandi in Ali-Marandi/DataSense

Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

MITAuto-check passedDevOps & Cloud

Install Activation Governance Chaos Rollout

skills CLI
$ npx skills add Ali-Marandi/DataSense --skill activation-governance-chaos-rollout -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Ali-Marandi/DataSense activation-governance-chaos-rollout --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Ali-Marandi/DataSense.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/activation-governance-chaos-rollout .claude/skills/activation-governance-chaos-rollout && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
activation-governance-chaos-rollout
GitHub stars
107
Token cost
~1.9k tokens
SKILL.md length
883 words
Files
5 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

  • Works in 6 steps: Establish the evidence baseline → Define the circuit and policy boundary → Build a scenario remediation plan → …
  • Activation triggers
  • SKILL.md covers Use this skill when, Non-negotiable safety rules, Workflow and Required artifacts, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Activation Governance Chaos Rollout is an agent skill from Ali-Marandi/DataSense. Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern. Use for activation triggers, consent and policy gates, transactional Outbox delivery, circuit breakers, kill switches, chaos validation, limited-production rollout gates, on-call runbooks, and security sign-off packages.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/chaos-scenario-matrix.md`, `references/limited-rollout-thresholds.md` and `templates/scenario_evidence_card.md`).

It sits in DevOps & Cloud, covering Deployment, Runbooks and postmortems and Incident response. The repository describes itself as: Advanced Data Analysis and Visualization Platform. The licence is MIT.

When your agent uses it

  • Activation triggers
  • Consent and policy gates
  • Transactional Outbox delivery
  • Circuit breakers

Example prompts

  • “/activation-governance-chaos-rollout”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish the evidence baseline
  2. Define the circuit and policy boundary
  3. Build a scenario remediation plan
  4. Run tests in tiers
  5. Operate Limited Production
  6. Close evidence and decide

What it can do on your machine

Read from SKILL.md and the folder at commit b9a67f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Activation Governance Chaos Rollout loads about 1.9k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 883 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Ali-Marandi/DataSense at commit b9a67f8, republished under its MIT licence (© Ali-Marandi). 883 words, ~1,904 tokens.

Download SKILL.mdSave it as .claude/skills/activation-governance-chaos-rollout/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
activation-governance-chaos-rollout
description
Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern. Use for activation triggers, consent and policy gates, transactional Outbox delivery, circuit breakers, kill switches, chaos validation, limited-production rollout gates, on-call runbooks, and security sign-off packages.

Activation Governance, Chaos, and Rollout

Use this skill when

Use this skill when an automation can create an external customer effect and must be governed by policy, consent, recipient verification, transactional delivery, or production rollout gates. Apply it to systems using an Outbox, retries, DLQ, worker leases, Alertmanager, Kubernetes, or staged releases.

Do not use it to send customer messages, enable a real provider, operate production Kubernetes, or treat a design document as deployment evidence.

Non-negotiable safety rules

  1. Default to fail-closed. Missing policy, unknown circuit state, unavailable consent store, unverified recipient, or invalid channel must produce a bounded suppressed outcome with no external call.
  2. Keep activation event types isolated from audit, security, Quality Gate, and other critical event classes.
  3. Write activation state, audit, suppression, and Outbox enqueue atomically and tenant-scoped. Use a unique execution key to obtain at-most-one external effect.
  4. Re-evaluate policy, consent, recipient, circuit, and channel immediately before external delivery. Do not rely only on enqueue-time approval.
  5. Never redrive stale external notifications automatically. Generate a new trigger only after a fresh eligibility evaluation.
  6. Run chaos only with synthetic data, a fake provider, an explicit non-production acknowledgement, and an allow-listed environment. Do not run destructive or load commands against production.
  7. Never put customer identifiers, payloads, provider URLs, secrets, or raw exception text in metric labels, evidence cards, or incident channels.

Workflow

1. Establish the evidence baseline

Read the implementation, schema, worker, metrics, deployment manifests, existing tests, and release runbooks. Create a scenario register using templates/scenario_evidence_card.md.

Classify each scenario precisely:

StatusMeaning
PASS — modelDeterministic in-memory/unit evidence only.
PARTIALSome implementation or test exists; acceptance criterion is incomplete.
NOT RUNDesign intent exists but no executable evidence.
PASS — stagingIsolated, non-production, integration/staging execution has complete evidence.
FAILAn invariant or acceptance criterion did not hold.

Do not generalize a model PASS to staging or production readiness.

2. Define the circuit and policy boundary

Specify event classes, allowed channels, circuit states, state-transition authority, and expected suppression reason codes. Use the default state model below unless the project has a stricter one:

StateExternal deliveryTransition rule
CLOSEDAllowed only after all gates pass.Critical lag/policy breach/kill condition opens circuit.
OPENForbidden; suppress.May move to Half-Open only with evidence and approval.
HALF_OPENFixed low-rate canary only.Any unexpected failure returns to Open.
MANUAL_KILLForbidden; suppress.Authorized human recovery only after incident review.
UNKNOWNForbidden; suppress.Restore trusted state and obtain approval.

Require a signed or mTLS-protected alert/controller input. Prometheus or an untrusted webhook must not directly gain permission to close a circuit or patch a deployment.

3. Build a scenario remediation plan

For each PARTIAL or NOT RUN scenario, define the missing control, a synthetic fault injection, assertions for external-effect count/final state/audit/metrics, the required environment and reviewer, and the precise artifact required for PASS.

Read references/chaos-scenario-matrix.md for baseline scenario families and references/limited-rollout-thresholds.md for operational gates. Prioritize consent, tenant isolation, policy availability, signed controller input, execution idempotency, and kill-switch behavior before capacity or growth tests.

Show full SKILL.md (384 more words)Show less
4. Run tests in tiers

Run in this order:

  1. Unit/model: state transitions, signature parsing, reason classification, rate cap.
  2. Integration: isolated database/Redis/fake provider; test revocation after enqueue, idempotency, retry/dead, schema rejection, and tenant isolation.
  3. Staging game day: synthetic tenant only; validate Alertmanager/controller, worker crash, flood, rollback, metrics, alert routes, and audit persistence.

Every staging command must require an environment allow-list and an explicit --confirm-nonprod-style acknowledgement. A missing acknowledgement must exit non-zero.

5. Operate Limited Production

Before enabling a cohort, verify kill switch, circuit audit, worker health, dashboard scrape, rollback target, pager routing, current policy version, and named on-call owners. Treat a compliance violation, slow revocation, critical Outbox lag, or worker unavailability as a safety event; pause external delivery before optimizing recovery.

Use the threshold reference only as an initial cohort baseline. Calibrate it after sufficient stable evidence; do not declare a contractual SLO from an initial pilot.

6. Close evidence and decide

Require a scenario evidence card, UTC timing, commit/image/policy/migration version, redacted metrics, fake-provider external-effect count, and reviewer sign-off. A critical failure, unknown circuit behavior, missing tenant isolation evidence, or unexecuted critical scenario blocks broad rollout.

DecisionMinimum condition
Keep internal/stagingCritical scenario has no staging evidence.
Limited ProductionP0 scenarios are staging PASS; alert routing and Security/SRE/Privacy/Engineering/Product sign-offs exist.
Expand cohortStable operating evidence, zero open critical findings, capacity review, and recorded governance approval.
Broad ProductionAll required scenarios staging PASS, rollback drill PASS, calibrated alerts, complete CAPA closure, and formal sign-offs.

Required artifacts

Create or update only the artifacts needed by the project: scenario register/evidence cards, remediation/CAPA plan, security sign-off package, Limited Production on-call runbook, post-incident/validation report, and executive decision briefing.

Keep design status, executable test status, and production status visibly separate in all artifacts.

Resources

  • Read references/chaos-scenario-matrix.md when designing or validating a chaos plan.
  • Read references/limited-rollout-thresholds.md when defining alerts, escalation, or release gates.
  • Copy templates/scenario_evidence_card.md for each test scenario.
  • Copy templates/security_wave_a_signoff.md for security review before activation integration is enabled.

Completion checklist

  • All external effects are policy-gated and re-checked at delivery time.
  • Circuit and kill switch default to suppress under uncertainty.
  • Test environment, synthetic fixtures, and fake provider are explicit.
  • Scenario status is evidence-based and not overstated.
  • Metrics use bounded, low-cardinality labels and no sensitive data.
  • Open/Close/rollback authority and escalation are documented.
  • Sign-offs, CAPA owners, and acceptance evidence are recorded.

© Ali-Marandi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/activation-governance-chaos-rollout of Ali-Marandi/DataSense.

  • SKILL.md
  • references/chaos-scenario-matrix.md
  • references/limited-rollout-thresholds.md
  • templates/scenario_evidence_card.md
  • templates/security_wave_a_signoff.md

Open the folder on GitHubat commit b9a67f8

Compare with similar skills

Activation Governance Chaos Rollout next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Activation Governance Chaos Rollout compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Activation Governance Chaos Rollout this skillAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Vpe Advisoralirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Prd V08 Runbook Creationmattgierhart/PRD-driven-context-engineering180—~4.5kAutomated safety check: NotesMIT
Docs Manualsjh941213/my-cc-harness125—~916Automated safety check: NotesNone
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Protocol Deploymentsablier-labs/evm-monorepo353—~3.8kAutomated safety check: NotesCustom licence

Similar skills

  • Vpe Advisor

    alirezarezvani/claude-skills

    VP of Engineering advisory for startups: delivery throughput (DORA 4 metrics + bottleneck identification), engineering hiring funnel (sourcing → screen → onsite → offer conversion + time-to-fill +…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Prd V08 Runbook Creation

    mattgierhart/PRD-driven-context-engineering

    Create operational playbooks for incident response, deployments, and maintenance during PRD v0.8 Deployment & Ops.

    180 GitHub stars~4.5k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Docs Manuals

    jh941213/my-cc-harness

    Generate user manuals (Diátaxis) and operator manuals (runbooks, deployment guide, configuration reference, incident playbook).

    125 GitHub stars~916 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Protocol Deployment

    sablier-labs/evm-monorepo

    Deploy Sablier protocols to a new EVM chain. An agent skill from sablier-labs/evm-monorepo.

    353 GitHub stars~3.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated today
    DevOps & CloudAuto-check passed

Categories

Questions about Activation Governance Chaos Rollout

What does Activation Governance Chaos Rollout do?

Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern. Activation Governance Chaos Rollout is an agent skill from Ali-Marandi/DataSense. Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

When should I use Activation Governance Chaos Rollout?

Activation Governance Chaos Rollout fits situations like: activation triggers; consent and policy gates; transactional Outbox delivery; circuit breakers.

How do I install Activation Governance Chaos Rollout in Claude Code?

Run `npx skills add Ali-Marandi/DataSense --skill activation-governance-chaos-rollout -a claude-code`. Or copy the skill folder (skills/activation-governance-chaos-rollout in Ali-Marandi/DataSense) into .claude/skills/activation-governance-chaos-rollout in your project. Claude Code loads it when a task matches its description.

How do I install Activation Governance Chaos Rollout in Codex?

Run `npx skills add Ali-Marandi/DataSense --skill activation-governance-chaos-rollout -a codex`. Or copy the skill folder (skills/activation-governance-chaos-rollout in Ali-Marandi/DataSense) into .agents/skills/activation-governance-chaos-rollout in your project. Codex loads it when a task matches its description.

Can I use Activation Governance Chaos Rollout in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Ali-Marandi/DataSense --skill activation-governance-chaos-rollout -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/activation-governance-chaos-rollout, .gemini/skills/activation-governance-chaos-rollout, .github/skills/activation-governance-chaos-rollout and .opencode/skills/activation-governance-chaos-rollout in your project.

What does Activation Governance Chaos Rollout need to run?

SKILL.md names no scripts, command-line tools or credentials: Activation Governance Chaos Rollout is instructions for the agent only.

Does Activation Governance Chaos Rollout access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Activation Governance Chaos Rollout safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Activation Governance Chaos Rollout use?

Activation Governance Chaos Rollout is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Activation Governance Chaos Rollout use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Activation Governance Chaos Rollout?

Skills that share tags, products or a category with Activation Governance Chaos Rollout: Vpe Advisor (alirezarezvani/claude-skills, 28k stars), Prd V08 Runbook Creation (mattgierhart/PRD-driven-context-engineering, 180 stars), Docs Manuals (jh941213/my-cc-harness, 125 stars) and Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Activation Governance Chaos Rollout?

Ali-Marandi (a GitHub user) maintains it in Ali-Marandi/DataSense, which has 107 GitHub stars. The repository was last updated on September 2, 2026.

Source: Ali-Marandi/DataSense on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.