CtrlK
BlogDocsLog inGet started
Tessl Logo

granola-enterprise-rbac

Configure enterprise role-based access control for Granola workspaces. Use when defining user roles, setting sharing permissions, configuring SSO group mappings, or implementing least-privilege access for meeting data. Trigger: "granola roles", "granola permissions", "granola access control", "granola RBAC", "granola admin roles".

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/saas-packs/granola-pack/skills/granola-enterprise-rbac/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is well-structured and actionable for configuring Granola RBAC, with concrete UI paths and mapping tables. Its main weaknesses are an orphaned, unreferenced implementation.md bundle file, duplicated role/permission detail, and missing verification checkpoints in the access-change workflows.

Suggestions

Reference references/implementation.md from the body (e.g., a "## Implementation details" section linking to it) and move the duplicated permission matrix and role definitions out of SKILL.md into that file.

Add explicit verification checkpoints to the role-change and offboarding workflows (e.g., "confirm the user's access is revoked in Settings > Team" before proceeding).

Trim the redundant "Output" section and any detail duplicated with implementation.md to tighten token usage.

DimensionReasoningScore

Conciseness

The body is mostly relevant Granola-specific detail without over-explaining concepts Claude knows, but at ~200 lines it is long and the "Output" section plus duplicated permission/role data that also appears in references/implementation.md could be trimmed.

3 / 5

Actionability

Gives concrete, actionable guidance for an instruction-only skill — exact UI paths ("Organization Settings > Security > SSO > Group Mapping"), specific sharing settings, and named SSO group-to-role mappings — with only minor gaps.

4 / 5

Workflow Clarity

The seven steps are clearly sequenced and a quarterly checklist exists, but role-change/offboarding workflows lack explicit verification checkpoints that access was actually revoked, and the destructive/batch-access nature caps this at 3 per the rubric.

3 / 5

Progressive Disclosure

A bundle file references/implementation.md exists with detailed role definitions and permission matrices, but the body never links or signals it; instead the body inlines duplicate role/permission/SSO content that clearly belongs in that separate file.

2 / 5

Total

12

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is well-formed: it states a concrete capability, gives an explicit Use-when trigger clause, and lists natural product-prefixed trigger phrases. Its only weakness is that the capability verbs are somewhat high-level and a few natural trigger synonyms are missing.

DimensionReasoningScore

Specificity

Lists several concrete actions — "defining user roles, setting sharing permissions, configuring SSO group mappings, or implementing least-privilege access" — covering the main RBAC tasks, though the actions remain slightly high-level rather than fully comprehensive.

4 / 5

Completeness

Explicitly answers both what ("Configure enterprise role-based access control for Granola workspaces") and when (a "Use when..." clause plus a dedicated "Trigger:" line with concrete phrases).

5 / 5

Trigger Term Quality

Provides good natural-phrase coverage with "granola roles", "granola permissions", "granola access control", "granola RBAC", and "granola admin roles", but omits common variations like SSO or sharing triggers.

4 / 5

Distinctiveness Conflict Risk

Targets a clear niche (Granola enterprise RBAC) with product-prefixed triggers, giving it minimal overlap or conflict risk with other skills.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
jeremylongshore/claude-code-plugins-plus-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.