Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Patterns for synthesizing findings across multiple frameworks into one readable portfolio view. Use when a /report:* command is pulling from more than one framework plugin and needs to avoid drowning the reader in control IDs.
.claude/skills/grcengclub-program-portfolio-composition/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -40% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 21% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -58% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -37% | 0% |
Most GRC programs run 3 to 8 frameworks. Presenting each one in full is how leadership reports get ignored. The job is to show the portfolio, not every control.
Most "different" controls across frameworks map back to the same SCF control. SCF IAC-01 shows up as SOC 2 CC6.1, NIST AC-2, ISO A.9.2, CMMC AC.L2-3.1.1, and more. When you report the portfolio, collapse down to SCF first, then expand back to frameworks for the appendix.
A 15-framework program is usually a 400 SCF control program. That's the denominator that matters.
1. Coverage table (one row per framework)
| Framework | Coverage | 30-day delta | Top gap | Owner | | --- | --- | --- | --- | --- | | SOC 2 | 82% | +3 pp | Access reviews | IAM |
Five columns. Never more. If you need more, split into a second table with a clear break (e.g., "priority frameworks" vs "monitored frameworks").
2. Leverage list (cross-framework patterns)
Controls that fail in 3+ frameworks. Fix one, close many. This is the board-friendly version of "we are investing in the right things."
Example: "SCF IAC-15 (account-recertification) fails in SOC 2, FedRAMP, and ISO 27001. One automation project closes all three. Scoped for Q2."
3. Watch list (at-risk items)
Controls or frameworks trending down. Specifically name what could slip, why, and what prevents it.
If the portfolio view is more than 2 pages, it has become the detailed report.
If the leverage list is empty, either you haven't mapped through SCF yet, or the program has no compounding work in flight. The first is a tooling fix. The second is a program problem worth naming.
If every framework shows identical coverage week over week, the pipeline isn't producing fresh findings. Flag this in the report rather than reporting stale numbers as if they were current.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 31,245 | 31,309 | +0% | 1 | 1 | 0% | 4,961 | 2,974 | -40% | 0 | 0 | — |
case-02 | fail→pass | 15,684 | 14,505 | -8% | 1 | 1 | 0% | 2,420 | 2,935 | +21% | 0 | 0 | — |
case-03 | fail→pass | 36,878 | 12,815 | -65% | 1 | 1 | 0% | 6,181 | 2,624 | -58% | 0 | 0 | — |
case-04 | pass→pass | 13,016 | 12,722 | -2% | 1 | 1 | 0% | 2,131 | 2,434 | +14% | 0 | 0 | — |
case-05 | pass→pass | 15,125 | 13,334 | -12% | 1 | 1 | 0% | 2,252 | 2,524 | +12% | 0 | 0 | — |
case-06 | pass→pass | 15,801 | 11,971 | -24% | 1 | 1 | 0% | 2,226 | 2,392 | +7% | 0 | 0 | — |
case-07 | fail→pass | 13,518 | 11,208 | -17% | 1 | 1 | 0% | 2,098 | 2,326 | +11% | 0 | 0 | — |
case-08 | pass→pass | 12,737 | 10,034 | -21% | 1 | 1 | 0% | 1,889 | 2,187 | +16% | 0 | 0 | — |
case-09 | fail→pass | 22,590 | 5,030 | -78% | 1 | 1 | 0% | 2,187 | 1,371 | -37% | 0 | 0 | — |
case-10 | fail→pass | 12,948 | 12,414 | -4% | 1 | 1 | 0% | 1,949 | 2,518 | +29% | 0 | 0 | — |
case-11 | fail→pass | 14,792 | 7,658 | -48% | 1 | 1 | 0% | 2,154 | 1,798 | -17% | 0 | 0 | — |
case-12 | fail→pass | 10,988 | 7,529 | -31% | 1 | 1 | 0% | 1,569 | 1,722 | +10% | 0 | 0 | — |
case-13 | fail→pass | 14,717 | 11,553 | -21% | 1 | 1 | 0% | 1,996 | 2,270 | +14% | 0 | 0 | — |
case-14 | pass→pass | 10,710 | 8,938 | -17% | 1 | 1 | 0% | 1,627 | 1,987 | +22% | 0 | 0 | — |
case-15 | fail→pass | 13,908 | 8,910 | -36% | 1 | 1 | 0% | 2,131 | 1,819 | -15% | 0 | 0 | — |
case-16 | fail→pass | 15,487 | 5,722 | -63% | 1 | 1 | 0% | 2,640 | 1,632 | -38% | 0 | 0 | — |
case-17 | fail→pass | 12,762 | 12,356 | -3% | 1 | 1 | 0% | 1,994 | 2,564 | +29% | 0 | 0 | — |
case-18 | fail→pass | 14,828 | 14,594 | -2% | 1 | 1 | 0% | 2,184 | 2,984 | +37% | 0 | 0 | — |
case-19 | pass→pass | 14,019 | 15,199 | +8% | 1 | 1 | 0% | 2,084 | 2,718 | +30% | 0 | 0 | — |
case-20 | fail→pass | 12,545 | 2,412 | -81% | 1 | 1 | 0% | 1,012 | 957 | -5% | 0 | 0 | — |
case-21 | pass→pass | 13,510 | 9,283 | -31% | 1 | 1 | 0% | 1,809 | 1,912 | +6% | 0 | 0 | — |
case-22 | fail→pass | 14,265 | 8,920 | -37% | 1 | 1 | 0% | 2,149 | 1,933 | -10% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +68 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.