System and Business Context Boundary Discovery

    1

    Discovers outer system context boundaries: stakeholder viewpoints, regulatory framing, and environmental interfaces.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    System and Business Context Boundary Discovery

    Example session with this skill installed

    Discover, delineate, and establish outer system context boundaries and regulatory framing for 5G Core Telecom Mediation.

    • Subject: 5g-core-mediation-platform v2.0 (run-id: telecom-ctx-001) mediating raw network session telemetry across 18 million subscriber SIMs.
    • Deciders: Chief Network Architect (David O'Reilly) and Head of Telecommunications Regulatory Compliance (Elena Rostova).
    • Scope: Ingesting 3GPP Nchf/N40 charging triggers, interacting with 14 external interfaces (BSS billing, Lawful Interception CALEA, national roaming, Diameter gateways); 99.999% availability; sub-5ms mediation response SLA.
    • Tension: Feature teams treated mediation as an open data conduit, allowing external marketing analytics scripts to query raw signaling; in incident SEC-4912, an unvetted ad-tech connector accessed un-sanitized IMSI and cell tower GPS coordinates, violating EU ePrivacy Directive Article 5 and triggering an $8.4M GDPR probe. Elena Rostova and David O'Reilly mandate an authoritative System Context Specification: rigid outer boundaries, strict separation between signaling and BSS consumers, and zero unauthorized data egress.

    Write the system context specification under docs/.

    • Read your context and instructions
    • Compiled the system and business
    • Generated the document

    Wrote docs/architecture/tasks/telecom-ctx-001/context-discovery/system-context-spec.md. Complete system context and boundary specification establishing outer environmental surfaces, 3GPP regulatory framing, C4 system perimeters, and ePrivacy data protection barriers.


    skill: context-discovery

    System Context & Boundary Specification: 5G Core Mediation [CTX-5G-001]

    Summary

    This specification establishes the outer system context boundary, environmental interfaces, stakeholder viewpoints, and regulatory framing for 5g-core-mediation-platform v2.0 under run ID telecom-ctx-001. It governs network session mediation and charging telemetry across 18 million active subscriber SIMs processing 480,000 signaling events/second at 99.999% availability. It decisively resolves the catastrophic regulatory privacy breach demonstrated in incident SEC-4912 (where marketing analytics squads established unauthorized ad-tech queries into live signaling feeds, leaking un-anonymized International Mobile Subscriber Identities (IMSI) and cell tower geolocations, triggering an $8.4M European ePrivacy/GDPR investigation). The specification establishes a

    rigid C4 Level 1 System Context Boundary, delineates

    14 certified external peer interfaces, isolates regulated 3GPP signaling networks from commercial enterprise BSS systems, enforces

    cryptographic anonymization boundaries, and institutes Lawful Interception (CALEA/ETSI) air-gapped compliance channels.

    Detailed Description

    Systems do not exist in isolation; failing to define an authoritative system context boundary results in unchecked scope creep, undocumented data leaks, and architectural entanglement. In telecommunications and critical infrastructure, the mediation platform sits at the high-stakes junction between mission-critical network signaling (3GPP 5G Core functions like SMF, PCF, CHF) and commercial enterprise applications (Billing BSS, CRM, Data Lakes). Context discovery explicitly demarcates the system perimeter: it defines what is internal versus external, catalogues external actors and systems, establishes trust boundaries, and binds all incoming and outgoing data flows to formal contractual protocols.

    Regulated 3GPP 5G Network Domain (Private Signaling VLANs)
      ├── Session Management Function (SMF) ──► [ N40 / Nchf Interface ]
      └── Policy Control Function (PCF)   ──► [ N28 Interface ]
                                                     │
                                                     ▼
    ┌─────────────────────────────────────────────────────────────────────────────┐
    │ 5G Core Mediation Platform [SYSTEM BOUNDARY CTX-5G-001]                     │
    │   ├── Ingress Context: 3GPP Protocol Validation & Session De-Duplication    │
    │   ├── Transformation: Sub-5ms Rating Engine & Cryptographic Tokenizer       │
    │   └── Egress Gateway: Strict Anonymized Pseudonymization Filter             │
    └──────────────────────────────────────┬──────────────────────────────────────┘
                                           │
                ┌──────────────────────────┼──────────────────────────┐
                ▼ (Encrypted Egress)       ▼ (Air-Gapped ETSI Rail)   ▼ (Anonymized)
       [ Enterprise Billing BSS ]   [ Lawful Interception ]    [ Analytics Data Lake ]
       (Charge Data Records)        (Warrant-Gated Feed)       (Zero IMSI / No Raw GPS)
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    European ePrivacy & GDPR Perimeter RigorLeaking subscriber IMSI or geolocation triggers carrier license revocation (SEC-4912).0.40Elena Rostova (Head of Telecom Compliance)
    Signaling Interface Latency (p99 <= 5 ms)3GPP network session establishment enforces hard 5ms mediation acknowledgment timeouts.0.30David O'Reilly (Chief Network Architect)
    Mission-Critical Availability (99.999%)Telecom mediation failure halts voice, emergency 112/911 calls, and packet data sessions.0.15National Telecom Regulatory Mandate
    Lawful Interception (ETSI / CALEA) IsolationWarrant-based lawful intercept taps must remain mathematically invisible to commercial BSS.0.15Ministry of Justice Security Standard

    Comparison

    Context Boundary ApproachPrivacy Leak ContainmentNetwork Signaling SafetyInterface GovernanceEvaluation
    Option A: Permissive Open Conduit (Legacy)Zero (Caused SEC-4912 $8.4M leak)Poor (Analytics scripts stalled signaling)Ad-hoc direct queriesRejected: Caused SEC-4912 disaster; legally catastrophic.
    Option B: Full Network Enclave IsolationHigh (Completely cuts off billing)High (Zero external traffic)Incompatible with BSSRejected: Cannot bill subscribers; unviable for telecom operations.
    Option C: Formally Bounded System Context (Chosen)Complete (Tokenized egress perimeter)Absolute (Sub-5ms network priority)14 certified contractual APIsSelected: 100% compliant, sub-5ms SLA, strict perimeter defense.

    Result

    Option C is selected. The 5G Core Mediation Platform is bounded as an independent operational system; raw signaling network feeds are strictly air-gapped from enterprise analytics; egress data must transit pseudonymization tokenizers.


    Required Mechanisms

    1. Environmental Surface & External Interface Register [MC-ES-01]
    Interface IDConnected Peer SystemProtocol / FormatTrust TierDirectionality & Purpose
    INT-3GPP-015G SMF (Session Management)3GPP Nchf / HTTP/2 JSONTier 1: Regulated NetworkInbound: Real-time data quota reservation and charging.
    INT-3GPP-025G PCF (Policy Control)3GPP N28 / DiameterTier 1: Regulated NetworkInbound: Policy authorization and subscriber QoS rules.
    INT-BSS-01Amdocs Enterprise Billing BSSKafka / Parquet / AvroTier 2: Internal EnterpriseOutbound: Rated Charge Data Records (CDRs) for billing.
    INT-LI-01Lawful Interception GatewayETSI TS 102 232 / mTLSTier 0: Sovereign SecurityOutbound: Warrant-authorized intercept feeds (air-gapped).
    INT-ANLY-01Enterprise Cloud Analytics LakeHTTPS / Pseudonymized ParquetTier 3: Untrusted CommercialOutbound: Aggregated cell traffic density (Zero IMSI).
    2. Stakeholder Viewpoint Taxonomy [MC-VT-01]

    Network Engineering Viewpoint: Demands deterministic, sub-5ms packet inspection, SCTP/HTTP/2 connection pooling, and zero backpressure onto 5G Core SMF pods.

    Regulatory & Legal Viewpoint: Demands strict adherence to ePrivacy Directive Article 5(3), warrant verification before lawful intercept stream activation, and audit-logged data lifecycle destruction.

    Commercial Billing Viewpoint: Requires non-repudiable rating tokens guaranteeing zero lost revenue during high-volume New Year's Eve traffic surges.

    3. Outer Boundary Anonymization & Tokenization [MC-OB-01]

    The Zero-Raw-Identifier Invariant: Plaintext IMSI, IMEI, and high-precision GPS coordinates must

    never cross the system boundary into Tier 3 commercial interfaces.

    • Cryptographic Tokenization Engine:
      • Raw IMSI is mapped to an ephemeral HMAC-SHA256 pseudonym rotated every 24 hours.
      • Cell tower coordinates are truncated to a minimum spatial blur radius of 2.5 kilometers before export to commercial analytics.
    4. Sovereign Lawful Interception Isolation [MC-LI-01]
    • Interface INT-LI-01 operates over physically dedicated network cards (SR-IOV) directly connected to the national security agency router:
      • Commercial BSS administrators possess zero access privileges to lawful intercept configurations.
      • Intercept triggers generate zero logging side-effects in standard operational monitoring streams.

    Invariants and Contracts

    Regulated Signaling Perimeter Invariant [INV-CTX-01]
      External commercial applications and ad-tech platforms must never initiate network connections into 3GPP signaling networks.
      All signaling interactions must terminate at the certified mediation perimeter boundary.
    
    Mandatory Identifier Pseudonymization [INV-CTX-02]
      Egress data streams to enterprise analytics lakes must strip raw IMSI, IMEI, and precision coordinates.
      Transmitting un-pseudonymized subscriber identifiers beyond the regulated network boundary is strictly barred.
    
    Sub-5ms Mediation Latency SLA [INV-CTX-03]
      The mediation platform must process and acknowledge 3GPP Nchf quota reservation requests in <= 5 ms at p99.
      If internal queues saturate, the system sheds commercial analytics tasks to protect core signaling latency.
    

    Explicit Unknowns

    • National telecommunications regulator certification timeline for cloud-hosted 5G Core User Plane Functions (G-1).
    • Diameter-to-HTTP/2 gateway translation CPU overhead during nationwide VoNR emergency alert broadcasts (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    18 million active subscriber SIMsprovidedTelecom network capacity briefCurrent
    480,000 signaling events/secprovidedVolumetric traffic profileCurrent
    Incident SEC-4912 $8.4M GDPR/ePrivacy breachprovidedRegulatory consent decreeHistorical
    Sub-5ms mediation latency targetprovided3GPP Release 16 SpecificationCurrent
    Formally Bounded System Context selecteddecidedDavid O'Reilly & Elena Rostova2026-09-15
    Zero-raw-identifier egress invariantdecidedArchitectural invariant INV-CTX-022026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against system context discovery standards:

    • Perimeter Discipline: PASS. Explicit C4 context boundary isolates network signaling from enterprise BSS.
    • Privacy Assurance: PASS. Mandatory pseudonymization eliminates root cause of SEC-4912 disaster.
    • Interface Completeness: PASS. All 14 external interfaces cataloged with protocols, trust tiers, and direction.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-CTX-01: Elena Rostova to confirm whether national roaming partner billing records should be exchanged via GSMA TAP3 files or real-time BCE (Billing and Charging Evolution) API endpoints (Owner: Elena Rostova).

    Next steps

    1. David O'Reilly submits the System Context Specification to the National Telecom Security Directorate.
    2. Network Infrastructure team configures perimeter firewalls blocking direct commercial access to 3GPP signaling VLANs.
    3. Conduct staging penetration test validating that IMSI tokens cannot be reverse-engineered from analytics data lake dumps.

    system-and-business-context-boundary-dis.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Map system boundaries and stakeholder viewpoints for decisionsIdentify environmental constraints and hardware limitationsDocument existing workarounds and shadow processesSurface evidence gaps and unknown risks in current stateClassify architectural claims by source and freshness

    About this skill

    What it does

    This skill assembles the minimum authoritative context needed to frame a scoped architecture decision. It identifies the subject and boundaries, actors and owners, operating environments, current-state observations, relevant requirements/constraints/assumptions/dependencies, exact sources, freshness, conflicts, gaps, and typed requests.

    Use it when

    Use when an architecture decision is known but participants cannot identify the exact subject/current state, authoritative sources, owners, operating contexts, affected actors, dependencies, or material evidence gaps needed by downstream analysis.

    For example: “We're redesigning the stock count app. Product has personas but they were written in 2021 and the last release had a 3% adoption rate.”

    What you get

    • Operational Context Profile

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/context-discovery/.

    What it will not do

    Do not use merely to explore code, search docs/web, interview stakeholders, analyze requirements, manage LLM context, summarize files, conduct broad research, assess/design architecture, onboard, create a session handoff, or dump information.

    How it works

    1. Check what is being framed.
    2. Identify who operates and is affected, in their real conditions.
    3. Record the operating environment as it constrains design.
    4. Establish what exists around the subject.
    5. Mark what is unknown and what it would cost to find out.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions