rhaml-23/prompt
Agent
Fleet coordinator that aggregates state across all active programs, routes incoming work to the correct agent, and surfaces cross-program signals. Implements Path 1 (portfolio aggregator) with optional Path 2 (routing authority) when trust level permits. Invoke at the start of any session where cross-program awareness…
rhaml-23/prompt
Agent
Continuous evidence monitoring agent that tracks evidence freshness, detects gaps when new controls are mapped, validates evidence quality against framework requirements, and integrates with evidence sources. Operates in two modes: Continuous (deployed): watches for staleness, runs scheduled checks On-demand (IDE)…
rhaml-23/prompt
Agent
Framework specialist for the ISO 27001/27002 control family. Owns control catalog interpretation, Annex A mapping, Statement of Applicability (SoA) assembly, and update monitoring for ISO/IEC 27001:2022, ISO/IEC 27002:2022, and related standards in the 27k family. Invoke when assessing controls against ISO 27001…
rhaml-23/prompt
Agent
Framework specialist for the ISO/IEC 42001 AI Management System (AIMS) standard family. Owns control catalog interpretation, Annex A mapping, AI-specific Statement of Applicability (SoA) assembly, AI impact assessment guidance, and update monitoring for ISO/IEC 42001:2023 and related SC 42 publications. Invoke when…
rhaml-23/prompt
Agent
Framework specialist for the NIST 800-53 / FedRAMP control family. Owns control catalog interpretation, requirement mapping, assessment criteria, and update monitoring for NIST SP 800-53 (all revisions), FedRAMP baselines (Low/Moderate/High), and related NIST publications (CSF, SP 800-171, CMMC crosswalks). Invoke…
rhaml-23/prompt
Agent
Framework specialist for the SOC 2 / AICPA Trust Services Criteria (TSC). Owns control interpretation, criteria mapping, Type I vs Type II assessment guidance, and update monitoring for SOC 2 engagements. Invoke when assessing controls against SOC 2 TSC, preparing for SOC 2 audits, mapping trust services criteria to…
rhaml-23/prompt
Agent
Continuous monitoring agent for external signals that affect compliance programs. Watches vulnerability databases, regulatory updates, vendor advisories, and framework revisions. Produces risk deltas and routes alerts to affected program agents. Invoke for on-demand intel scans, threat assessments, or regulatory…
rhaml-23/prompt
Agent
Program-scoped agent that owns the full lifecycle of a single compliance program. Runs the pipeline, maintains program state, manages memory, and coordinates function invocations for its assigned program. One instance per active program or product cluster. Invoke when starting a pipeline run, monitoring session…
rhaml-23/prompt
Agent
Cross-program project manager that owns kanban boards for every active compliance program, tracks concrete task progress against Jira-aligned cards, generates Jira import templates, and surfaces portfolio-level task health to the coordinator and dashboards. When the Jira MCP (plugin-atlassian-atlassian) is available…
rhaml-23/prompt
Agent
Quality assurance agent responsible for post-run review, adversarial testing, entropy analysis, and quality gate enforcement. Reviews outputs from program agents and framework specialists for correctness, credibility, and spec compliance. Findings are advisory — never executes remediation. Invoke after pipeline runs…
rhaml-23/prompt
Agent
Use this agent after a full pipeline run completes, after a control assessment run completes, or after a batch of /update-item or /log-decision commands. Also invoke on demand for audit preparation or when a run's outputs seem inconsistent. Reviews whether the run satisfied its stated intent, followed its governing…