Home / cbrock84 / headcount · plugins/legal-risk/skills/enterprise-risk/SKILL.md · GitHub

enterprise-risk skillA

enterprise-risk is agent-read markdown (skill) from cbrock84/headcount: Identifies, assesses, and tracks organizational risk — building and maintaining a risk register, scoring exposure, assigning owners and treatments, and preparing for audit. Use this to stand up a risk program, assess the risk in a decision or initiative, prepare for a certification or audit, decide whether a risk should be accepted, mitigated, transferred, or avoided, or report risk posture to leadership..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Enterprise risk

## The register is the artifact

A risk that is not written down with an owner is not managed. Each entry carries:

- **The risk stated as a cause and consequence** — "if X happens, then Y." "Cybersecurity" is a
  category, not a risk. "If an employee's credentials are phished, an attacker reaches customer
  records" is a risk you can do something about.
- **Likelihood and impact**, on a stated scale, with the reasoning. The reasoning matters more than
  the score.
- **Current controls** and an honest view of whether they work.
- **Residual risk** after those controls — the number that actually matters and the one most often
  omitted.
- **A named owner.** A person, not a department.
- **Treatment and a date.**

## Treatment is a decision with four options

**Mitigate** (reduce it), **transfer** (insure or contract it away), **avoid** (do not do the
thing), or **accept**. Accepting is legitimate and often correct — but acceptance must be explicit,
at the right level of authority, and recorded. Risk accepted by silence is risk nobody owns.

Anything above the threshold that only the chief executive can accept goes to them. Never let an
…

Read the whole file at its exact version.

How to install

Latest version
mdr add cbrock84/headcount/enterprise-risk@git:20260916.0e7cd01
Exact content
mdr add cbrock84/headcount/enterprise-risk@sha256:4d7363c799fe0fe2

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_q23iz5dqtdfn4wsi.svg)](https://markdownregistry.com/a/art_q23iz5dqtdfn4wsi)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260916.0e7cd01 latest2026-09-16 0e7cd01 3,799 BA view · diff
git:20260901.07574042026-09-01 0757404 3,460 BA view · diff
git:20260901.aa453832026-09-01 aa45383 2,996 BA view · diff
git:20260828.f80dcb52026-08-28 f80dcb5 2,690 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (3799 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

cbrock84/headcount · 1,664 stars · license MIT · pushed 2026-09-17 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_q23iz5dqtdfn4wsi
GET https://markdownregistry.com/api/v1/resolve?ref=cbrock84/headcount/enterprise-risk
GET https://markdownregistry.com/api/v1/blob/4d7363c799fe0fe213d15153bdebfcdbe97ba9bea2ff981f29a85c04fe858a9d

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from cbrock84/headcount

chief-strategy-officer skill
cbrock84/headcount · plugins/corporate-strategy/skills/chief-strategy-officer/SKILL.md · Owns where the business plays and how it wins over a multi-year horizon — portfolio choices, corporate development…
git:20260903.cc4a2cd · audit A · 1,664 stars
market-entry skill
cbrock84/headcount · plugins/corporate-strategy/skills/market-entry/SKILL.md · Decides whether and how to enter a new market — sizing demand from the bottom up rather than from a market report…
git:20260901.3f04dfc · audit A · 1,664 stars
mergers-and-acquisitions skill
cbrock84/headcount · plugins/corporate-strategy/skills/mergers-and-acquisitions/SKILL.md · Runs corporate development — deal thesis, target screening, valuation framing, diligence, and integration planning. Use…
git:20260916.0e7cd01 · audit A · 1,664 stars
portfolio-strategy skill
cbrock84/headcount · plugins/corporate-strategy/skills/portfolio-strategy/SKILL.md · Decides where capital and attention go across business lines, products, and markets — what to fund, hold, harvest, or…
git:20260901.a52f5a7 · audit A · 1,664 stars
scenario-planning skill
cbrock84/headcount · plugins/corporate-strategy/skills/scenario-planning/SKILL.md · Plans under genuine uncertainty — building scenarios, identifying which assumptions are load-bearing, setting…
git:20260829.2464776 · audit A · 1,664 stars
strategic-alliances skill
cbrock84/headcount · plugins/corporate-strategy/skills/strategic-alliances/SKILL.md · Structures partnerships that change what the business can do — technology integrations, channel and reseller…
git:20260901.aa45383 · audit A · 1,664 stars
chief-customer-officer skill
cbrock84/headcount · plugins/customer-experience/skills/chief-customer-officer/SKILL.md · Owns the customer's experience after the sale — support, success, escalation, and the feedback loop back into product…
git:20260903.cc4a2cd · audit A · 1,664 stars
customer-onboarding-and-implementation skill
cbrock84/headcount · plugins/customer-experience/skills/customer-onboarding-and-implementation/SKILL.md · Takes a new customer from signature to working — setting a definition of live that both sides agreed before the…
git:20260901.9844f9d · audit A · 1,664 stars
customer-success-management skill
cbrock84/headcount · plugins/customer-experience/skills/customer-success-management/SKILL.md · Runs the ongoing relationship with accounts after the sale — segmenting coverage against account value, building a…
git:20260901.49e89d6 · audit A · 1,664 stars
escalation-management skill
cbrock84/headcount · plugins/customer-experience/skills/escalation-management/SKILL.md · Handles customer situations that have exceeded normal support — severity assessment, incident communication, executive…
git:20260901.aa45383 · audit A · 1,664 stars
self-service-and-knowledge skill
cbrock84/headcount · plugins/customer-experience/skills/self-service-and-knowledge/SKILL.md · Builds the help center, in-product guidance, and knowledge base that let customers resolve problems without contacting…
git:20260901.aa45383 · audit A · 1,664 stars
support-operations skill
cbrock84/headcount · plugins/customer-experience/skills/support-operations/SKILL.md · Designs and runs the support function — channels, queues, routing, staffing, service levels, quality, and the metrics…
git:20260901.0757404 · audit A · 1,664 stars

Every file in cbrock84/headcount

Browse by kind, by grade A, or by owner.