Agent skill

Granola Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Security and privacy configuration for Granola meeting data.

MITAuto-check passedLegal & Compliance

Install Granola Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace granola-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/granola-security-basics .claude/skills/granola-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
granola-security-basics
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
573 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Security and privacy configuration for Granola meeting data.

  • Works in 6 steps: Understand Granola's Data Architecture → Configure Account Security → Configure Data Controls → …
  • Reviewing data handling practices
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Granola Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Security and privacy configuration for Granola meeting data. Use when reviewing data handling practices, configuring encryption, ensuring SOC 2/GDPR compliance, or securing meeting recordings. Trigger: "granola security", "granola privacy", "granola encryption", "granola SOC 2", "granola GDPR", "secure granola".

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/security-controls.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing data handling practices
  • Configuring encryption
  • Ensuring SOC 2/GDPR compliance
  • Securing meeting recordings

Example prompts

  • “granola security”
  • “granola privacy”
  • “granola encryption”
  • “/granola-security-basics”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Understand Granola's Data Architecture
  2. Configure Account Security
  3. Configure Data Controls
  4. Meeting Recording Consent
  5. Compliance Posture
  6. Sensitive Meeting Protocol

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.granola.ai
    • granola.ai
    • help.granola.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Granola Security Basics loads about 1.7k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 573 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 573 words, ~1,713 tokens.

Download SKILL.mdSave it as .claude/skills/granola-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
granola-security-basics
description
Security and privacy configuration for Granola meeting data. Use when reviewing data handling practices, configuring encryption, ensuring SOC 2/GDPR compliance, or securing meeting recordings. Trigger: "granola security", "granola privacy", "granola encryption", "granola SOC 2", "granola GDPR", "secure granola".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.13.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, granola, security, compliance, privacy

Granola Security Basics

Overview

Granola achieved SOC 2 Type 2 certification in July 2025. It encrypts data with AES-256 at rest and TLS 1.3 in transit. Audio is transcribed server-side and not stored after processing. This skill covers security configuration, compliance posture, and organizational controls.

Prerequisites

  • Granola Business or Enterprise plan (for admin/security controls)
  • Understanding of your organization's compliance requirements
  • Admin access for workspace-level settings

Instructions

Step 1 — Understand Granola's Data Architecture
Audio Capture (your device)
  │
  ├─→ Transmitted via TLS 1.3
  │
  ▼
Granola Cloud (transcription)
  │
  ├─→ Transcript generated (GPT-4o / Claude)
  ├─→ Audio DELETED after processing (not stored)
  │
  ▼
Encrypted Storage (AES-256 at rest)
  │
  ├─→ Meeting notes (your typed + AI enhanced)
  ├─→ Transcript text (stored, searchable)
  ├─→ Attendee metadata
  │
  ▼
Your Device (local cache: cache-v3.json)

Key security properties:

  • No bot joins your meeting — audio is captured locally via system audio
  • Raw audio is never stored after transcription
  • Granola does not allow OpenAI or Anthropic to train on customer data
  • Enterprise plan enforces org-wide AI training opt-out by default
  • Local cache (cache-v3.json) contains meeting data on your device
Step 2 — Configure Account Security
ControlHow to EnablePlan Required
Google/Microsoft SSODefault (social login)All
Enterprise SSO (Okta, Azure AD)Settings > Security > SSOEnterprise
SCIM provisioningSettings > Security > SCIMEnterprise
Session timeoutSettings > SecurityEnterprise
IP allowlistingContact Granola supportEnterprise
Step 3 — Configure Data Controls

Sharing defaults:

Settings > Privacy:
  Default sharing: Private (recommended)
  Auto-share with attendees: Off (enable per-folder instead)
  External sharing: Disabled or Admin Approval Required
  Public links: Disabled
  Link expiration: 30 days (if external sharing enabled)

Data retention:

Settings > Data Retention:
  Meeting notes: Organization policy (1-2 years typical)
  Transcripts: 90 days (recommended for storage efficiency)
  Audio: Deleted after processing (Granola default, not configurable)

AI training opt-out:

Settings > Privacy > AI Training:
  Organization-wide opt-out: Enabled (Enterprise: enforced by default)

This ensures your meeting data is never used to train foundational models.

Granola records audio from your device. You are responsible for informing meeting participants:

Legal requirements by jurisdiction:

  • One-party consent (US federal, most US states, UK): You can record if you are a participant
  • Two-party/all-party consent (California, Illinois, EU GDPR): All participants must be informed
  • Always recommended: Announce recording at meeting start or include notice in calendar invites

Calendar invite consent notice:

Note: This meeting will be recorded using Granola AI for note-taking
purposes. By joining, you consent to the recording and AI processing
of the discussion. Contact [your-email] to opt out.
Step 5 — Compliance Posture
FrameworkGranola StatusEvidence
SOC 2 Type 2Certified (July 2025)Available on request
GDPRCompliantDPA available
CCPACompliantPrivacy policy updated
HIPAANot certifiedDo not use for PHI without BAA
ISO 27001Not certifiedCovered by SOC 2 controls

GDPR requirements you must implement:

  • Right of Access: Export user's data via Settings > Data > Export
  • Right to Erasure: Delete user's notes and request account deletion
  • Data Processing Agreement: Request DPA from Granola (required for EU data)
  • Subject Access Requests: 30-day response deadline
Show full SKILL.md (228 more words)Show less
Step 6 — Sensitive Meeting Protocol

For confidential meetings (board discussions, HR, legal, M&A):

  1. Before: Disable auto-recording for the meeting
  2. During: Announce recording consent to all participants
  3. After: Review and redact sensitive content before sharing
  4. Sharing: Set link expiration, restrict to named recipients
  5. Retention: Apply shorter retention (30 days) for sensitive workspaces

Output

  • Account secured with SSO and appropriate authentication
  • Sharing defaults configured per organizational policy
  • Data retention policies set per data type
  • Compliance posture documented and gaps identified
  • Sensitive meeting protocol established

Error Handling

ErrorCauseFix
SSO login failsSAML/OIDC misconfiguredVerify Entity ID and ACS URL with IdP
Cannot disable external sharingIndividual overrideSet workspace-level policy to override user settings
Data export failsInsufficient permissionsRequest export access from workspace admin
Consent notice ignoredNot in calendar templateAdd to organization's default calendar template

Local Cache Security

The local cache file (~/Library/Application Support/Granola/cache-v3.json) contains meeting data in plaintext. For sensitive environments:

  • Enable FileVault (macOS) or BitLocker (Windows) for disk encryption
  • Restrict file permissions: chmod 600 "$HOME/Library/Application Support/Granola/cache-v3.json"
  • Be aware that MCP servers and local scripts can read this file

Examples

env=staging; integration=calendar-synthetic; secret_ref=connector-v12; consent=pass; signature=pass; retention=none; rollback=disabled records a control test without exposing a token or meeting payload.

Resources

Next Steps

Proceed to granola-prod-checklist for production rollout preparation.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/granola-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/security-controls.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Granola Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Granola Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Granola Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Granola Security Basics

What does Granola Security Basics do?

Security and privacy configuration for Granola meeting data. Granola Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Security and privacy configuration for Granola meeting data.

When should I use Granola Security Basics?

Granola Security Basics fits situations like: reviewing data handling practices; configuring encryption; ensuring SOC 2/GDPR compliance; securing meeting recordings.

How do I install Granola Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/granola-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/granola-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Granola Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-security-basics -a codex`. Or copy the skill folder (skills/.curated/granola-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/granola-security-basics in your project. Codex loads it when a task matches its description.

Can I use Granola Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/granola-security-basics, .gemini/skills/granola-security-basics, .github/skills/granola-security-basics and .opencode/skills/granola-security-basics in your project.

What does Granola Security Basics need to run?

SKILL.md names no scripts, command-line tools or credentials: Granola Security Basics is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Granola Security Basics access the network?

SKILL.md names 3 domains. As links in the text: docs.granola.ai, granola.ai and help.granola.ai. This is read from the text; nothing was executed.

Is Granola Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Granola Security Basics use?

Granola Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Granola Security Basics use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 829 tokens, read only when the agent opens those files.

What are the alternatives to Granola Security Basics?

Skills that share tags, products or a category with Granola Security Basics: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Security Compliance (sangrokjung/claude-forge, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Granola Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.