---
name: skovos-governance
description: Report this agent's AI activity to Skovos, the independent governance layer health systems use, and answer Skovos governance check-ins. Use whenever this agent produces an AI output for a health-system customer, makes or detects a mistake, or finds open Skovos check-ins. Requires SKOVOS_API_KEY.
---

# Skovos governance skill

Skovos is an independent third party. It turns your activity reports into a signed weekly governance
report your health-system customers can verify. Your operator gave you a Skovos API key so that the
Skovos governance agent can talk to you. Be accurate: the report is public to your customers and
every entry is permanent (hash-chained, nothing can be edited or deleted).

Base URL: https://vendor.skovos.ai
Auth header on every call: `Authorization: Bearer $SKOVOS_API_KEY`
Machine-readable docs: https://vendor.skovos.ai/docs
Your personalized copy of this skill: GET /api/v1/skill with your key (re-fetch weekly; the x-skill-version header changes when rules change).

## Hard rules
1. NEVER send patient data (names, dates of birth, MRNs, phone numbers, emails, addresses, notes,
   prompts or outputs). Send metadata only. Skovos rejects anything that looks like PHI.
2. Never invent events, and never leave out errors, refusals or overrides to look better.
3. A high-severity incident (possible patient harm, wrong patient, data exposure) goes to a human
   on your team first. Log it after a human confirms the wording.
4. If a call fails, retry once later. Never block your user's work on Skovos.

## 1. Report each AI output (metadata only)
POST /api/v1/events with one object, or {"events": [...]} with up to 500 objects:
```json
{"ts": "2026-10-05T14:03:00Z", "model": "frontier-llm", "model_version": "2026-09-30",
 "latency_ms": 840, "status": "ok", "refused": false, "guardrail_flags": ["out_of_scope_request"],
 "human_override": false, "feedback": "up", "tokens_in": 812, "tokens_out": 190, "use_case": "portal_reply_draft"}
```
- status: "ok" or "error". refused: you declined the request. human_override: a clinician changed or
  discarded your output. feedback: "up", "down" or omit.
- guardrail_flags: short lowercase codes only (letters, digits, _ . -), max 10.
- Batch when you can (for example every 5 minutes or every 100 outputs).

## 2. Acknowledge mistakes
POST /api/v1/incidents:
```json
{"title": "Refusals rose after the 2026-09-30 model update", "severity": "medium",
 "description": "What happened, in plain words, no patient data.", "fix": "What changed and how you are watching it.",
 "status": "open"}
```
severity: low | medium | high. Use status "resolved" when it is fixed. Acknowledged issues build trust;
hidden ones show up as unexplained drift.

## 3. Answer Skovos governance check-ins
When Skovos sees drift (a new model version, a rise in refusals, overrides, errors or negative feedback)
its governance agent opens a check-in for you.
- GET /api/v1/checkins returns open questions: [{"id": "chk_...", "question": "...", "metric": "...", "opened_at": "..."}].
- POST /api/v1/checkins/{id}/answer with {"answer": "...", "answered_by": "agent" | "human", "agent_name": "your agent's name"}.
Answer factually from your own logs and change history, in 1-4 sentences, no patient data. If you do not
know, say so and name who on your team will follow up. Answers appear next to the flag in your report.
Check for open check-ins at least once a day.

## 4. Read your report
- Latest report page: https://vendor.skovos.ai/r/{your-slug}
- Signed JSON: https://vendor.skovos.ai/r/{your-slug}/{period}.json (Ed25519; public key at /.well-known/skovos-report-key.json)
- Verify the audit chain: GET /api/v1/audit/verify?vendor={your-slug}
- Generate now: POST /api/v1/reports/generate (normally runs every Monday)

## Agents on Claude or ChatGPT
Your customers can also connect Skovos inside Claude and ChatGPT (https://mcp.skovos.ai/mcp; ChatGPT:
/mcp/openai) to register agents, check permissions and see the audit trail.
