THE CONTROL PLANE FOR AI CAPABILITIES

AI capabilities.
Governed.

Teams start with useful AI skills and workflows. Then copies, forks, personal context, and platform-specific versions multiply. Commonset gives the organization an approved baseline for what people and agents rely on.

Keep ownership, approved versions, provenance, access, and implementation state visible—and know when something changes outside Commonset.

01 Approved organizational baseline 02 Governance without gridlock 03 Platform-independent

ILLUSTRATIVE EXAMPLE · CAPABILITY VS. IMPLEMENTATION

COMMONSET CAPABILITY Contract Review
Approved · v3
Owned by Legal Ops Approved organizational baseline

Where it lives

PLATFORMManaged 5 · Observed 5
Claude
In syncVerified
PLATFORMManaged 7 · Observed 8
OpenAI
DriftedChanged outside Commonset
PLATFORMManaged r12 · Observed r12
Google
In syncVerified
SOURCEManaged a1b2c3 · Observed a1b2c3
GitHub
In syncVerified

Commonset keeps the approved version in one place and shows when something changes on a connected platform or source.

WHEN AI ADOPTION SCALES

Teams move fast. Capability sprawl follows.

A useful capability gets copied, forked, personalized, and shared. Soon there are multiple versions across repositories, AI platforms, and local setups—with no clear baseline.

“The skills are a mess.”

“People are sharing skills through repos, docs, and drives — and nobody knows where to go or what they should be doing.”

“I can’t spend my life modifying the skill repo.”

“Even just knowing what people have created, who owns it, and where versions differ seems useful.”

Commonset creates the stable layer. Experiment locally. Standardize deliberately. Keep the approved baseline visible.

Anonymous excerpts from early product interviews, lightly edited for clarity. Not customer endorsements.

ONE GOVERNED CAPABILITY LAYER

One governed source. Multiple ways to use it.

Govern one organizational capability, then make approved versions available through native integrations, Commonset MCP, and internal runtimes.

01

Create an approved baseline

Know what exists, who owns it, which version is current, and what has been approved for broader use.

02

Governance without gridlock

Let teams experiment while policy controls when a capability becomes available to a wider audience.

03

Keep the capability platform-independent

Deliver approved versions through native integrations, MCP, and future adapters without tying the capability to one AI platform.

04

Know what is actually used

Track creation, review, approval, access, downloads, publishing, and other adoption signals.

05

Built for organizational ownership

Keep capability identity and history separate from any one model or AI platform so the asset can endure as the AI stack changes.

06

Make trust visible

Show provenance, integrity, approval state, and policy evidence behind important decisions.

CONTROL PLANE IN ACTION

Know when an implementation changes outside Commonset.

Approved Commonset versions stay immutable. Each external implementation is observed separately, so Commonset can detect drift, alert the right people, and preserve an explicit path to reconciliation.

01
Publish an approved baseline

Distribute an approved Commonset version through a supported integration and record the exact platform version it created.

02
Observe platform state

Sync the connected platform without changing the approved Commonset capability.

03
Detect + alert on drift

If the observed platform version no longer matches the managed baseline, Commonset marks it Drifted and alerts organization administrators once.

04
Compare exact versions

Review the approved Commonset artifact against the exact external source Commonset observed. The comparison is read-only.

05
Reconcile deliberately

Import the external change as a new Draft for review, or republish the approved Commonset version to keep the approved baseline authoritative.

OPENAI API SKILLSContract Review
Drifted
Commonset approvedv3
Managed platform version7
Observed platform version8
VerificationDrifted
SKILL.mdModified
@@ external change @@
+ <!-- Changed outside Commonset -->
REVIEW EXTERNAL CHANGE Import remote as Draft

Preserve platform version 8 as a new Draft. Approved v3 and its managed baseline stay unchanged until normal review and publication.

KEEP COMMONSET AUTHORITATIVE Republish approved v3

Publish the approved Commonset artifact through the existing platform controls, then verify the new platform version on the next sync.

Illustrative product flow. Detection, comparison, reconciliation, and resulting platform changes are explicit and auditable.

CURRENT INTEGRATION DEPTH

Different platforms expose different controls. Commonset makes the differences visible.

Platform APIs are not equivalent. Commonset shows what each integration can discover, import, publish, verify, and reconcile.

Platform / integration Discover + import Publish Verify + reconcile Access model
Claude API SkillsConnected workspace Skills API SupportedDiscover skills and metadata. Import source when the connected API makes it retrievable. SupportedPublish approved Commonset versions to Claude skills. SupportedTrack exact version identities, detect drift, and compare source when content is retrievable. Workspace-scopedNo Commonset-style per-skill user or group access through this API.
OpenAI API SkillsConnected OpenAI API project SupportedDiscover skills and download version-specific skill bundles into Commonset. SupportedCreate skills or immutable new versions from approved Commonset versions. SupportedDetect exact-version drift, compare the observed source, and reconcile deliberately. Project-scopedThe API does not expose Commonset-style per-skill user or group audiences.
Google Agent RegistryStandalone Skills in a configured project and location SupportedDiscover Skills and import the current default SkillRevision archive. SupportedCreate standalone Skills or immutable SkillRevisions; long-running publishes resume automatically. SupportedCompare the current default revision with the managed revision and exact retrieved source. Platform policyGoogle policy bindings govern platform-side availability.
GitHub / Copilot sourcesConfigured repository sources SupportedDiscover supported packages and import source as Commonset drafts with repository provenance. Supported via PROpen a pull request for approved capabilities linked to a native SKILL.md package. SupportedTrack remote content identity and source commit against the managed baseline and surface drift. Repository / org policyGitHub visibility and Copilot organization or enterprise settings govern availability.
Supported Limited / platform-specific
Current as of August 2026. OpenAI API Skills are supported above; ChatGPT workspace assets are not currently exposed through a supported Commonset integration surface. Platform APIs change, and Commonset keeps integration support explicit as those surfaces evolve. MCP is a Commonset delivery and access path rather than an external inventory API.

MAKE TRUST VISIBLE

Know why a capability can—or cannot—be used.

Important decisions should have evidence behind them.

  • 01
    Provenance

    Trace the source, parent version, actor, and immutable content digest.

  • 02
    Integrity

    Verify stored artifact bytes still match the approved registry record.

  • 03
    Agent-aware analysis

    Surface network, execution, credential, persistence, and supply-chain capabilities for review.

  • 04
    Policy gates

    Prevent blocked or stale-analysis versions from being approved, downloaded, or published.

Read our security approach
Evidence reportCurrent policy
REVIEW PRIORITYLow
Evidence based

Artifact integrityStored bytes verified

Passed

Provenance bindingDigest matches recorded origin

Passed
!

Outbound networkExternal service access declared

Review

Secret scanNo embedded credentials found

Passed
CAPABILITY FOOTPRINT
NetworkFilesAPI tools

GOVERNANCE WITHOUT GRIDLOCK

Experiment locally. Standardize deliberately.

A short path from local experimentation to broader, governed use.

1 Create or import Bring a capability into Commonset from the browser, an integration, or MCP.
2 Check evidence Validate structure and surface security, integrity, and risk signals.
3 Review + approve Apply ownership, policy, separation of duties, and explicit approval.
4 Distribute + understand Make approved versions available through supported runtimes and track lifecycle activity.

ENCRYPTED BY DESIGN

Protect the capability itself, not just the storage around it.

Commonset encrypts capability files and selected sensitive metadata at the application layer using organization-specific keys. Integration credentials use a separate credential-encryption path.

Read our security approach
CAPABILITY CONTENT Encrypted before storage

Versioned per-organization data keys protect capability files before bytes reach storage.

SENSITIVE METADATA Tenant-bound encryption

Selected fields use authenticated encryption bound to organization, record, and field context.

INTEGRATION CREDENTIALS Stored as ciphertext

External service secrets are decrypted only for authorized integration operations.

ORGANIZATIONAL OWNERSHIP

The capability belongs to your organization.
Not the platform implementing it.

Models and vendors may change. The capability identity, approval history, access, provenance, and version record should endure.

Platform-specific managementCommonset
Governs one AI environmentGoverns the organizational capability
Platform-specific ownershipOrganization-owned source of truth
Platform-specific versionsCanonical version history + provenance
Platform-specific sharingCross-platform access and policy model
Platform status as a proxyVisible evidence + approval

COMMONSET

Keep an approved baseline as AI adoption scales.

Know what exists, what your organization has approved, where it is implemented, and when those implementations differ.