Skills

Your best way of working, on everyone's agent.

A tool lets an agent act. A Skill tells it how your company does the work. Palma distributes both down the same governed connection — so people get the capability and the know-how together.

See the MCP & Skill Gateway
A catalogue of governed, versioned Skills ready to be distributed to entitled agents

What a Skill is

The part that decides whether an agent is useful.

Give an agent a hundred tools and it will still guess at your process. The knowledge of how you work is the thing that turns capability into completed work.

  • A tool is a verb. A Skill is the playbook.

    The tool can create a ticket. The Skill knows which queue, what the title should say, and when to escalate instead. One is capability, the other is how your company actually works.

  • Written by the people who know

    Your best operator already does month-end close correctly. A Skill is that knowledge captured once, instead of living in their head and a document nobody opens.

  • The same knowledge on everyone’s agent

    Once it is published, every entitled person gets it — not just the team that happened to write it down.

Lifecycle

From someone's head to everyone's agent.

Four steps, one of which can stop the rest. That gate is the difference between distributing knowledge and distributing a liability.

  1. Author

    Someone writes down what works

    A domain expert captures the way the job is actually done. No engineering ticket, no schema to learn.

  2. Scan

    Secrets out, threats blocked

    Redaction runs before storage. Rules for injection, exfiltration and privilege escalation decide whether the version may be served at all.

  3. Publish

    An immutable version

    The version is frozen. Nothing about it can change later, so nothing shifts under an agent already using it.

  4. Resolve

    It appears where it is entitled

    Connected clients pick it up on their next session, scoped to the spaces and identities allowed to see it.

Distribution

Published once. Everywhere that should have it.

Skills reach every assistant through the connection your people already use, entitled by the groups your directory already maintains.

  • Nothing to install

    Point an MCP-capable client at a Palma space and the Skills that identity is entitled to are simply there. No plugin, no marketplace step, no per-machine setup.

  • One channel, every client

    Skills travel over the open standard as SEP-2640 resources, with a meta-tool path for the clients that have not adopted it yet. One distribution channel either way, instead of an adapter per assistant vendor.

  • Updates land on next session

    Publish a version and connected clients pick it up when they next start. There is no fleet to chase and no stale copies to reconcile.

  • Scoped by the same rules as tools

    A Skill is scoped to a space by exactly the machinery that scopes tools. No second permission model, and no gap between the two for something to slip through.

Scoped per space

Governed exactly like everything else.

A Skill is attached to a space and resolved against the same entitlements that decide which tools an identity can see. The governance surface is one surface, not two.

  • Attached to a space, or bundled into a Pack with the tools it needs
  • Active policies visible alongside the capabilities they govern
  • Every resolution recorded with the rest of the activity
A Palma space showing active policies and governance alongside its tools and capabilities

The catalogue

Every playbook, with its provenance attached.

A Skill is not a file someone emails around. It has an owner, a version, a scan result and a visibility tier — and the one that failed its scan is not being served to anybody.

Skills 4 of 27 All spaces
  • month-end-close-checklist Finance Operations v4 Private Scan passed Pack-only · requires 3 tools
  • incident-triage-runbook IT Operations v11 Private Scan passed Attached to 4 spaces
  • customer-refund-policy Customer Support v2 Shared Scan passed Shared with 2 tenants
  • vendor-onboarding-draft Procurement v1 Private Blocked Secret detected · exception pending

Safety

A playbook is executable text. Treat it that way.

A Skill can tell an agent to do something it should not. That makes distribution a security question, which is why scanning and versioning sit in front of it rather than beside it.

  • Secrets stripped before storage

    Redaction runs before a version is ever written, so a key pasted into a playbook does not become a key sitting in a database.

  • Scanned, and blocked if it fails

    Deterministic rules for prompt injection, exfiltration, privilege escalation and supply-chain patterns gate every version. A blocked version is never served to an agent — the resolver simply omits it.

  • A second opinion on intent

    Beyond the rules, a semantic judge assesses what a Skill is actually trying to do, and machine-learning models flag PII in the bundle for review.

  • Exceptions go to a human

    When a team believes a block is wrong, they file a justification with an optional expiry and it routes to the approval queue. Overriding is a decision someone owns, not a config flag.

  • Versions never change underneath you

    Every publish is an immutable snapshot. Nothing shifts mid-flight for a running agent, and rolling back is choosing an earlier version.

  • Private, shared, or open

    Keep a Skill inside your tenant, share it with named partners, or publish it broadly. The resolver enforces the tier on every request.

Palma gave our agents governed superpowers. We are an investor and a customer because Palma solves one of the hardest problems in AI right now. Agent governance at scale.
Patrick D11Z
Patrick, D11Z

Book a demo

See what governed AI agents look like.

A 20-minute demo on your stack. We'll show Palma working with the agents, tools and identity provider you already run.

  • Enterprise security
  • Role-based access
  • Instant integration

Latest Blog Posts

Stay up-to-date with the latest in enterprise AI, MCP servers, and secure integration strategies.

Common Questions

Quick answers about Palma.ai's enterprise MCP platform