Create an approved baseline
Know what exists, who owns it, which version is current, and what has been approved for broader use.
THE CONTROL PLANE FOR AI CAPABILITIES
Teams start with useful AI skills and workflows. Then copies, forks, personal context, and platform-specific versions multiply. Commonset gives the organization an approved baseline for what people and agents rely on.
Keep ownership, approved versions, provenance, access, and implementation state visible—and know when something changes outside Commonset.
WHEN AI ADOPTION SCALES
A useful capability gets copied, forked, personalized, and shared. Soon there are multiple versions across repositories, AI platforms, and local setups—with no clear baseline.
“The skills are a mess.”
“People are sharing skills through repos, docs, and drives — and nobody knows where to go or what they should be doing.”
“I can’t spend my life modifying the skill repo.”
“Even just knowing what people have created, who owns it, and where versions differ seems useful.”
Anonymous excerpts from early product interviews, lightly edited for clarity. Not customer endorsements.
ONE GOVERNED CAPABILITY LAYER
Govern one organizational capability, then make approved versions available through native integrations, Commonset MCP, and internal runtimes.
Know what exists, who owns it, which version is current, and what has been approved for broader use.
Let teams experiment while policy controls when a capability becomes available to a wider audience.
Deliver approved versions through native integrations, MCP, and future adapters without tying the capability to one AI platform.
Track creation, review, approval, access, downloads, publishing, and other adoption signals.
Keep capability identity and history separate from any one model or AI platform so the asset can endure as the AI stack changes.
Show provenance, integrity, approval state, and policy evidence behind important decisions.
CONTROL PLANE IN ACTION
Approved Commonset versions stay immutable. Each external implementation is observed separately, so Commonset can detect drift, alert the right people, and preserve an explicit path to reconciliation.
Distribute an approved Commonset version through a supported integration and record the exact platform version it created.
Sync the connected platform without changing the approved Commonset capability.
If the observed platform version no longer matches the managed baseline, Commonset marks it Drifted and alerts organization administrators once.
Review the approved Commonset artifact against the exact external source Commonset observed. The comparison is read-only.
Import the external change as a new Draft for review, or republish the approved Commonset version to keep the approved baseline authoritative.
@@ external change @@
+ <!-- Changed outside Commonset -->
Preserve platform version 8 as a new Draft. Approved v3 and its managed baseline stay unchanged until normal review and publication.
Publish the approved Commonset artifact through the existing platform controls, then verify the new platform version on the next sync.
Illustrative product flow. Detection, comparison, reconciliation, and resulting platform changes are explicit and auditable.
CURRENT INTEGRATION DEPTH
Platform APIs are not equivalent. Commonset shows what each integration can discover, import, publish, verify, and reconcile.
| Platform / integration | Discover + import | Publish | Verify + reconcile | Access model |
|---|---|---|---|---|
| Claude API SkillsConnected workspace Skills API | SupportedDiscover skills and metadata. Import source when the connected API makes it retrievable. | SupportedPublish approved Commonset versions to Claude skills. | SupportedTrack exact version identities, detect drift, and compare source when content is retrievable. | Workspace-scopedNo Commonset-style per-skill user or group access through this API. |
| OpenAI API SkillsConnected OpenAI API project | SupportedDiscover skills and download version-specific skill bundles into Commonset. | SupportedCreate skills or immutable new versions from approved Commonset versions. | SupportedDetect exact-version drift, compare the observed source, and reconcile deliberately. | Project-scopedThe API does not expose Commonset-style per-skill user or group audiences. |
| Google Agent RegistryStandalone Skills in a configured project and location | SupportedDiscover Skills and import the current default SkillRevision archive. | SupportedCreate standalone Skills or immutable SkillRevisions; long-running publishes resume automatically. | SupportedCompare the current default revision with the managed revision and exact retrieved source. | Platform policyGoogle policy bindings govern platform-side availability. |
| GitHub / Copilot sourcesConfigured repository sources | SupportedDiscover supported packages and import source as Commonset drafts with repository provenance. | Supported via PROpen a pull request for approved capabilities linked to a native SKILL.md package. | SupportedTrack remote content identity and source commit against the managed baseline and surface drift. | Repository / org policyGitHub visibility and Copilot organization or enterprise settings govern availability. |
MAKE TRUST VISIBLE
Important decisions should have evidence behind them.
Trace the source, parent version, actor, and immutable content digest.
Verify stored artifact bytes still match the approved registry record.
Surface network, execution, credential, persistence, and supply-chain capabilities for review.
Prevent blocked or stale-analysis versions from being approved, downloaded, or published.
Artifact integrityStored bytes verified
PassedProvenance bindingDigest matches recorded origin
PassedOutbound networkExternal service access declared
ReviewSecret scanNo embedded credentials found
PassedGOVERNANCE WITHOUT GRIDLOCK
A short path from local experimentation to broader, governed use.
ENCRYPTED BY DESIGN
Commonset encrypts capability files and selected sensitive metadata at the application layer using organization-specific keys. Integration credentials use a separate credential-encryption path.
Read our security approachVersioned per-organization data keys protect capability files before bytes reach storage.
Selected fields use authenticated encryption bound to organization, record, and field context.
External service secrets are decrypted only for authorized integration operations.
ORGANIZATIONAL OWNERSHIP
Models and vendors may change. The capability identity, approval history, access, provenance, and version record should endure.
COMMONSET
Know what exists, what your organization has approved, where it is implemented, and when those implementations differ.