* feat: add gap-analysis methodology skill Signed-off-by: Magnus Hedemark <magnus919@pm.me> * fix: satisfy gap-analysis trigger validation Signed-off-by: Magnus Hedemark <magnus919@pm.me> * chore: refresh generated marketplace metadata Signed-off-by: Magnus Hedemark <magnus919@pm.me> * chore: refresh llms catalog Signed-off-by: Magnus Hedemark <magnus919@pm.me> --------- Signed-off-by: Magnus Hedemark <magnus919@pm.me>
3.1 KiB
Context Variants
Use the generic method, then adapt the target and evidence to the context. Never import a framework's scale or threshold without its authority and fit.
Capability and maturity
Assess capabilities as observable behaviors, not labels. Define levels with anchors such as intent, repeatability, measurement, integration, and adaptation only when those levels serve the decision. Evidence can include operating records, demonstrations, outcomes, ownership, and review cadence. Report capability-by-capability rather than one blended maturity number. A maturity model can show progression; it cannot prove business value by itself.
Artifact: capability statement, level anchors, current evidence, desired level rationale, dependency map, and staged roadmap.
Process and operating model
Map the actual flow, handoffs, decision rights, queues, controls, and outcomes. Compare the flow to the required or desired flow. Look for wait states, rework, missing inputs, conflicting incentives, and unowned exceptions. Validate with records and people who perform the work, not only the process owner.
Artifact: process step matrix with owner, input, output, control, measure, failure mode, current evidence, target behavior, and change action.
Compliance and readiness
Start with an authoritative requirement or release criterion and preserve its wording and applicability. Map each requirement to implementation status, evidence, owner, and residual uncertainty. Distinguish “not implemented,” “implemented but unproven,” “not applicable with rationale,” and “evidence unavailable.” Do not declare legal compliance, certification, or audit readiness from a self-assessment. Route interpretation to qualified legal, compliance, audit, security, quality, or regulatory owners.
Artifact: requirement-to-evidence matrix plus exceptions, remediation plan, acceptance authority, and re-test plan.
Research and evidence gaps
Define the decision question and the population/intervention/comparison/outcome/setting as applicable. Describe what the evidence does and does not establish, then classify why it falls short: insufficient/imprecise, biased, inconsistent/unknown, or not the right information. A research gap becomes a research need only when filling it would help a real decision-maker. Specify the study or evidence needed, not just “more research.”
Artifact: question/evidence matrix, gap reason, decision consequence, priority criteria, and proposed evidence design.
Readiness and transition
Define the go/no-go condition, date, operating boundary, dependencies, rehearsal evidence, rollback or fallback, and owner. Readiness is not the same as activity completion. Mark each criterion as demonstrated, partially demonstrated, untested, blocked, or not applicable with rationale. Use a decision gate with explicit residual risks and authority.
Selecting a variant
If a request mixes contexts, split the analysis into linked registers. For example, a compliance gap can expose a capability gap and a readiness dependency, but one row should not silently carry three different standards. Maintain a stable gap ID and link related rows.