AI SKILL GOVERNANCE

Govern AI skills across teams and AI platforms.

See which AI skills your teams have created, who owns them, which versions are approved, and where they are available.

Commonset helps organizations review, approve, version, distribute, and reconcile reusable AI skills without locking governance to one provider. For a step-by-step operating model, see how to govern AI skills across teams.

01 Discover skills 02 Review + approve 03 Keep versions aligned

COMMONSET / ORGANIZATION OVERVIEW

Your AI work, in view.

Illustrative data
Capabilities inventoried
184
Retrieved in 30 days
62
With approved versions
31

What teams are reusing

MCP retrievals · 30 days
  • Contract ReviewLegal Ops · Approved v2.1.0
    128 retrievals
  • Revenue ForecastFinance · Approved v1.3.0
    96 retrievals
  • Customer ResearchProduct · Approved v1.0.0
    74 retrievals

Where to focus next

Needs attention
14

Open reviewsDecide what is ready to share.

7

Drifted implementationsCheck changes against approved versions.

Illustrative overview, not a live dashboard. Retrievals show access through Commonset MCP, not downstream execution or business outcomes.

AI SKILLS SPREAD FASTER THAN GOVERNANCE

Govern the AI skills your teams are already creating.

Skills get copied through repositories, AI platforms, docs, and individual accounts. Without a shared governance layer, teams cannot easily tell who owns a skill, which version was reviewed, or which copy they should trust.

“The skills are a mess.”

“People are sharing skills through repos, docs, and drives — and nobody knows where to go or what they should be doing.”

“I can’t spend my life modifying the skill repo.”

“Even just knowing what people have created, who owns it, and where versions differ seems useful.”

Find the skills. Review them. Make the trusted versions reusable. Use a governed registry instead of leaving AI skill decisions scattered across provider consoles and repositories. Learn about AI skills registries → · See Commonset →

Anonymous excerpts from early product interviews, lightly edited for clarity. Not customer endorsements.

AI SKILL MANAGEMENT ACROSS TEAMS

Discover, review, approve, and distribute AI skills.

Start with an inventory of the skills your teams already have. Add ownership and provenance, review exact versions, approve what the organization trusts, and make those versions available through supported AI platforms and repositories.

01 / VISIBILITY

Know which AI skills already exist.

Bring skills from connected repositories and supported AI platforms into one inventory. See the owner, source, version history, and review status in one place.

02 / STANDARDIZATION

Agree on what others should use.

Give each capability an owner. Review its content and security findings, approve a specific version, and define who can use it through Commonset.

03 / DISTRIBUTION

Help the next team start ahead.

Make approved work discoverable and available through Commonset MCP and supported integrations. Teams can build on a shared capability instead of starting from scratch.

04 / INTELLIGENCE

See adoption. Decide where to focus.

Follow recorded views, downloads, publishing, and MCP retrievals. Use those signals alongside team feedback to decide what to improve, share more widely, or retire.

GOVERNANCE WITHOUT GRIDLOCK

Experiment locally. Standardize deliberately.

A short path from local experimentation to broader, governed use.

1 Create or import Bring a capability into Commonset from the browser, an integration, or MCP.
2 Check evidence Validate structure and surface security, integrity, and risk signals.
3 Review + approve Apply ownership, policy, separation of duties, and explicit approval.
4 Distribute + understand Make approved versions available through supported runtimes and track lifecycle activity.

KEEP APPROVED AI SKILLS ALIGNED

Govern the skill lifecycle, not just the source file.

Commonset connects ownership, immutable version history, review, access, provider distribution, and drift. When a connected AI skill changes outside the approved flow, compare the exact implementation with the approved baseline and reconcile deliberately.

01
Publish an approved baseline

Distribute an approved Commonset version through a supported integration and record the exact platform version it created.

02
Observe platform state

Sync the connected platform without changing the approved Commonset capability.

03
Detect + alert on drift

If the observed platform version no longer matches the managed baseline, Commonset marks it Drifted and alerts organization administrators once.

04
Compare exact versions

Review the approved Commonset artifact against the exact external source Commonset observed. The comparison is read-only.

05
Reconcile deliberately

Import the external change as a new Draft for review, or republish the approved Commonset version to keep the approved baseline authoritative.

OPENAI API SKILLSContract Review
Drifted
Commonset approvedv3
Managed platform version7
Observed platform version8
VerificationDrifted
SKILL.mdModified
@@ external change @@
+ <!-- Changed outside Commonset -->
REVIEW EXTERNAL CHANGE Import remote as Draft

Preserve platform version 8 as a new Draft. Approved v3 and its managed baseline stay unchanged until normal review and publication.

KEEP COMMONSET AUTHORITATIVE Republish approved v3

Publish the approved Commonset artifact through the existing platform controls, then verify the new platform version on the next sync.

Illustrative product flow. Detection, comparison, reconciliation, and resulting platform changes are explicit and auditable.

CURRENT INTEGRATION DEPTH

Keep your standards as your AI stack changes.

Use supported integrations with Claude, OpenAI, Google, and GitHub. Each platform has its own publishing and access controls; see exactly what Commonset supports below.

Compare integration support
Platform / integration Discover + import Publish Verify + reconcile Access model
Claude API SkillsConnected workspace Skills API SupportedDiscover skills and metadata. Import source when the connected API makes it retrievable. SupportedPublish approved Commonset versions to Claude skills. SupportedTrack exact version identities, detect drift, and compare source when content is retrievable. Workspace-scopedNo Commonset-style per-skill user or group access through this API.
OpenAI API SkillsConnected OpenAI API project SupportedDiscover skills and download version-specific skill bundles into Commonset. SupportedCreate skills or immutable new versions from approved Commonset versions. SupportedDetect exact-version drift, compare the observed source, and reconcile deliberately. Project-scopedThe API does not expose Commonset-style per-skill user or group audiences.
Google Agent RegistryStandalone Skills in a configured project and location SupportedDiscover Skills and import the current default SkillRevision archive. SupportedCreate standalone Skills or immutable SkillRevisions; long-running publishes resume automatically. SupportedCompare the current default revision with the managed revision and exact retrieved source. Platform policyGoogle policy bindings govern platform-side availability.
GitHub / Copilot sourcesConfigured repository sources SupportedDiscover supported packages and import source as Commonset drafts with repository provenance. Supported via PROpen a pull request for approved capabilities linked to a native SKILL.md package. SupportedTrack remote content identity and source commit against the managed baseline and surface drift. Repository / org policyGitHub visibility and Copilot organization or enterprise settings govern availability.
Supported Limited / platform-specific
Current as of August 2026. OpenAI API Skills are supported above; ChatGPT workspace assets are not currently exposed through a supported Commonset integration surface. Platform APIs change, and Commonset keeps integration support explicit as those surfaces evolve. MCP is a Commonset delivery and access path rather than an external inventory API.

MAKE TRUST VISIBLE

Make trust visible before work is shared.

See where a capability came from, what it can do, and which version passed review. Give teams a clear basis for choosing what to use.

  • 01
    Provenance

    Trace the source, parent version, actor, and immutable content digest.

  • 02
    Integrity

    Verify stored artifact bytes still match the approved registry record.

  • 03
    Agent-aware analysis

    Surface network, execution, credential, persistence, and supply-chain capabilities for review.

  • 04
    Policy gates

    Prevent blocked or stale-analysis versions from being approved, downloaded, or published.

Read our security approach
Evidence reportCurrent policy
REVIEW PRIORITYLow
Evidence based
✓

Artifact integrityStored bytes verified

Passed
✓

Provenance bindingDigest matches recorded origin

Passed
!

Outbound networkExternal service access declared

Review
✓

Secret scanNo embedded credentials found

Passed
CAPABILITY FOOTPRINT
NetworkFilesAPI tools

ENCRYPTED BY DESIGN

Protect the capability itself, not just the storage around it.

Commonset encrypts capability files and selected sensitive metadata at the application layer using organization-specific keys. Integration credentials use a separate credential-encryption path.

Read our security approach
CAPABILITY CONTENT Encrypted before storage

Versioned per-organization data keys protect capability files before bytes reach storage.

SENSITIVE METADATA Tenant-bound encryption

Selected fields use authenticated encryption bound to organization, record, and field context.

INTEGRATION CREDENTIALS Stored as ciphertext

External service secrets are decrypted only for authorized integration operations.

ORGANIZATIONAL OWNERSHIP

The capability belongs to your organization.
Not the platform implementing it.

Models and vendors may change. The capability identity, approval history, access, provenance, and version record should endure.

Platform-specific managementCommonset
Governs one AI environmentGoverns the organizational capability
Platform-specific ownershipOrganization-owned source of truth
Platform-specific versionsCanonical version history + provenance
Platform-specific sharingCross-platform access and policy model
Platform status as a proxyVisible evidence + approval

COMMONSET

Turn useful AI work into a shared standard.

Start with what your teams have built. See it clearly, choose what to trust, and make it easier for the next team to reuse.