Compliance Workshop

Applied Claude Enterprise Session — 2 Hours, Remote (Zoom)

Session Objectives

Agenda

Time Block Details
0:00–0:20
1. Projects & Skills Overview
  • What are Projects? Knowledge files + custom instructions = persistent workspace
  • What are Skills? Portable, distributable procedures anyone can run
  • How they work together: the compliance project + the compliance skill
  • Your AI Policy is the foundation — we're building on what you already wrote
0:20–0:40
2. Build Your Project
  • Create the "Compliance" project in Claude Desktop
  • Upload knowledge: AI Policy, risk matrix, compliance manual sections
  • Write project instructions (role, rules, output format)
  • Test: ask Claude a compliance question using your uploaded docs
0:40–1:10
3. Build the Compliance Skill
  • Download the pre-built skill template from the workshop site
  • Walk through SKILL.md structure: metadata, triggers, procedure, output format
  • Customize for your firm: add your specific policy rules, risk categories
  • Upload and test: "Check this marketing deck for compliance issues"
  • Review the generated report together
1:10–1:30
4. Research & Update Exercise
  • Install the Compliance Research skill
  • Live research: "Find the latest SEC guidance on AI in advisory firms"
  • Claude searches the web and (if connected) your SharePoint for relevant sources
  • Review the research brief: what changed, what requires action, what to monitor
  • Feed findings into the compliance skill: compare against your current risk matrix
  • Claude drafts specific row updates (new risks, changed severity, control gaps)
  • The full cycle: research → assess → update → review
1:30–1:45
5. “What Can Claude See?”
  • Install the Access & Visibility Audit skill
  • Run it live: map connectors, SharePoint reach, permissions, add-in status
  • Review findings: is sensitive data exposed? Any permission gaps?
  • Mark false positives: add approved exceptions to the project — the skill remembers and won't re-flag them (with optional expiry dates)
  • Key outcome: you now have a documented, repeatable answer to “what is Claude's access surface at this firm”
1:45–1:55
6. Sharing, Automation & Daily Monitoring
  • Share the project with Karl (view vs. edit access)
  • Provision skills org-wide: Organization Settings → Skills
  • Install the Daily Compliance Monitor skill
  • Set up a scheduled task: runs every weekday morning, generates a 2-minute compliance brief, saves a draft email to your inbox
  • Versioning: how to update skills when rules change
  • Governance note: scheduled tasks need “Cowork in the cloud” enabled — you turned it off (for good reason); discuss whether to re-enable for this specific use case
1:55–2:00
7. Wrap-Up & Next Steps
  • Download reference materials from the workshop site
  • Install the bonus maintenance skills (see below)
  • Homework: upload your email review lexicon to the project
  • Homework: run the compliance skill against one real document this week
  • Schedule follow-up check-in

Optional Modules (if time allows or for follow-up)

These can fill extra time or become homework. Each takes 10–15 minutes. Available as skill downloads on the workshop site.

Time Module Details
~15 min
A. Project Health Check
  • Install the Project Health Check skill
  • Run it against the compliance project we just built
  • Review the report: staleness flags, conflict detection, organization score
  • Discuss the quarterly rhythm — run this after every major doc update
  • Key lesson: stale documents actively mislead Claude; a project that was great in September is wrong by December if not maintained
~10 min
B. Knowledge Refresh
  • Install the Knowledge Refresh skill
  • Scenario: your AI Policy was just revised — upload the new version
  • The skill compares old vs. new, flags cascade impacts on other project docs
  • Key lesson: never just swap a file — one changed date in a policy can make three other documents wrong
~10 min
C. Compliance Calendar
  • Install the Compliance Calendar skill
  • Run it: "What's due this quarter?" — see the calendar with your obligations mapped
  • Customize the calendar with your firm's specific dates and deadlines
  • Key lesson: pair this with the risk matrix — every quarterly review updates both
~15 min
D. Email Review Lexicon
  • Upload your email review word list to the compliance project
  • Show how Claude uses it as project knowledge for email reviews
  • Test: "Using my lexicon, what should I search for in this quarter's email review?"
  • Key lesson: the lexicon that "can't be saved in the tools" is perfectly stored as project knowledge
~15 min
E. Project Maintenance Discipline
  • Install the Project Maintenance skill
  • Run a pre-flight check on the compliance project we just built
  • Walk through the three hallucination risks: contradictions, stale data, overload
  • Practice: add a document "the right way" (date it, check overlaps, test after)
  • Set up the monthly maintenance checklist as a recurring habit
  • Key lesson: a project that was accurate in September gives wrong answers by December unless actively maintained — fix the knowledge, not the prompt
Please bring to the session:
1. Your current risk matrix (Excel file)
2. Your compliance manual (or the sections you update most frequently)
3. Your email review lexicon (the word list for quarterly email reviews)

We'll upload these directly into your project during the workshop. If you'd prefer, you can send them ahead of time and we'll have them ready.

Materials

All session materials are available at:
workshop.abraxasintegrations.com