Completions

Build pillar · brand-spec agent

How to build machine-readable structured brand-spec authoring for multi-location operators

Figma + Figma Variables + Tokens Studio + Style Dictionary + Specify + Knapsack + Backlight + Supernova + Frontify + Bynder + Brandfolder + Notion + Confluence + GitBook + Docusaurus ship per-tenant flat brand-asset primitives. The Author + Version + Gate + Audit skill bundle on the brand-spec agent sits above the design-token + DAM + documentation + CI + schema-authoring substrate (JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6 + CloudEvents 1.0 + GraphQL + Avro + Protobuf + TypeScript types + Zod + Pydantic) and writes a per-brand-spec canonical record with named regulatory anchors covering USPTO trademark registration + Lanham Act 15 USC 1051 + 15 USC 1057 + 15 USC 1064 + 15 USC 1115 + 15 USC 1125(a) + 15 USC 1125(c) + 15 USC 1127 + Madrid Protocol + WIPO + Anti-cybersquatting Consumer Protection Act + USPTO TTAB + Trademark Modernization Act 2020 + JSON Schema Draft 2020-12 + AsyncAPI 2.6 + Design Tokens W3C draft + SLSA Level 3+ + Sigstore + EU AI Act Article 50 + SOX 302/404/906.

Published January 6, 2027 · 3,200 words

The 4-skill bundle on the brand-spec agent

One agent. Four coordinated skills. The Author + Version + Gate + Audit bundle runs above the design-token + DAM + documentation + CI + schema-authoring substrate and writes one canonical per-brand-spec record with USPTO trademark consistency + SLSA Level 3+ supply-chain provenance.

Author

Per-brand JSON-LD + voice-attribute (from #549) + style + visual + audio + motion + tone-of-voice + voice-rules + forbidden-phrase library + claims-allowlist + vocabulary + color + typography + spacing + iconography + photography + layout + motion + accessibility + region + locale + language + vertical + audience + persona + legal/ IP marker. Schema authoring via JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6 + CloudEvents 1.0 + Design Tokens W3C.

Version

Per-brand-spec versioning via semantic versioning v2.0.0 + Conventional Commits v1.0.0 + Keep a Changelog v1.1.0 + GitHub Actions + GitLab CI + CircleCI. Per-PR SLSA Level 3+ build provenance + in-toto attestation + Sigstore Fulcio + Rekor + cosign + gitsign + GUAC + Software Heritage permanent archive + SBOM CycloneDX + SPDX per EO 14028 + NIST SP 800-218 SSDF + CISA Secure by Design. Per-LLM output license + per-repo license compatibility check.

Gate

5 anchors per-brand-spec: USPTO + Lanham 15 USC 1051/ 1057/1064/1115/1125(a)/1125(c)/1127/1125(d) + Madrid Protocol + WIPO + TTAB + Trademark Modernization Act + JSON Schema + AsyncAPI + Design Tokens W3C + SLSA Level 3+ + in-toto + Sigstore + GUAC + SBOM + per-LLM license + per-repo compatibility + Copyright + DMCA + FTC Endorsement + per-vertical (HIPAA + FINRA + ABA + FDA) + WCAG 2.2 AA + EU AI Act Article 50 + SOX + FASB ASC 350.

Audit

Per-brand-spec WORM record: authoring history + JSON Schema + AsyncAPI + Design Tokens W3C + per-PR SLSA + in-toto + Sigstore + GUAC + SBOM + per-LLM license + per-repo compatibility + Sigstore policy controller + per-anchor gate-pass + USPTO + Lanham + Madrid Protocol + WIPO + per-vertical applicability + accessibility + EU AI Act FRIA + AI-ML provenance. Retention: 7-year FTC + 7-year IRS + 7-year SOX + 6-year SEC + 3-year FINRA + EO 14028 + NIST SSDF + GDPR Article 30 + EU AI Act Article 12 + SOC 2 CC7/CC8.

The real ecosystem this sits above

Author + Version + Gate + Audit does not replace the design- token vendors, DAM, documentation, CI, or schema-authoring tooling. It sits above them, coordinates them, and writes one canonical per-brand-spec record with USPTO trademark consistency + SLSA Level 3+ supply-chain provenance.

Design-token + DAM

  • Figma + Figma Variables + Tokens Studio + Style Dictionary
  • Specify + Knapsack + Backlight + Supernova design-token
  • Adobe XD + Sketch + Penpot + Lunacy
  • Frontify + Bynder + Brandfolder + Brandmaster + Brandkit
  • Adobe Creative Cloud + Adobe Express + Canva Brand Kit

Documentation + CI + schema

  • Notion + Confluence + GitBook + ReadMe + Docusaurus
  • Nextra + Starlight + Mintlify documentation
  • GitHub Actions + GitLab CI + CircleCI orchestration
  • JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6
  • CloudEvents 1.0 + GraphQL + Avro + Protobuf + TypeScript

Supply-chain + AI-creative

  • SLSA v1.0 Level 3+ + in-toto + Sigstore Fulcio + Rekor
  • cosign + gitsign + GUAC + Software Heritage + Scorecard
  • SBOM CycloneDX + SPDX + Syft + Grype + Trivy
  • Persado + Phrasee + Anyword + Jasper + Writer + Copy.ai
  • Hive + Microsoft + OpenAI Moderation + Anthropic policy

Compliance overlay

Five anchors run per-brand-spec before any publish or downstream propagation commits. The first anchor is operationally distinctive: USPTO trademark registration + Lanham + Madrid Protocol + WIPO + Design Tokens W3C + JSON Schema Draft 2020-12 + AsyncAPI 2.6 schema discipline + SLSA Level 3+ supply-chain provenance.

Anchor 1: USPTO + Lanham + Madrid Protocol + JSON Schema + Design Tokens W3C (operationally distinctive)

USPTO trademark registration + Lanham Act 15 USC 1051 trademark + 15 USC 1057 + 15 USC 1064 cancellation + 15 USC 1115 incontestability + 15 USC 1125(a) false- designation + 15 USC 1125(c) dilution + 15 USC 1127 definitions + Madrid Protocol + WIPO Berne Convention + Paris Convention + Anti-cybersquatting Consumer Protection Act 15 USC 1125(d) + USPTO TTAB + Trademark Modernization Act 2020 + per-mark first-use + per-mark goods/services + Section 8 declaration + Section 9 renewal. JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6 + CloudEvents 1.0 + Design Tokens W3C draft + per-brand schema versioning + semantic versioning v2.0.0 + Conventional Commits v1.0.0 + Keep a Changelog v1.1.0.

Anchor 2: SLSA + Sigstore + EO 14028 + per-LLM license

SLSA v1.0 Level 3+ build provenance + in-toto attestation + Sigstore Fulcio + Rekor + cosign + gitsign + GUAC + Software Heritage + OpenSSF Scorecard + SBOM CycloneDX + SPDX per Executive Order 14028 + NIST SP 800-218 SSDF v1.1 + CISA Secure by Design. Per-LLM output license + per-repo license compatibility + Copyright Act 17 USC 102/106/107 fair use/501 + DMCA 17 USC 1201.

Anchor 3: FTC + per-vertical + FDD Item 12

FTC Endorsement Guides + Fake Review Rule + Section 5 + Pfizer 1972 + MARS + Health Products + Negative-Option + CFPB UDAAP + Lanham. FDD Item 12 + 15-state franchise + per-franchisor trademark holding-company per-franchisee licensee. ABA Model Rule 7.1-7.5 when LegalService + state bar 50-state. FINRA Rule 2210 when FinancialService + SEC Regulation FD. HIPAA when MedicalBusiness + state medical board. FDA + alcohol + .

Anchor 4: Accessibility + EU AI Act + privacy

WCAG 2.2 AA + ADA Title III + Section 508 + EAA EN 301 549 + brand accessibility. EU AI Act Article 50 transparency when AI-generated brand-spec + Article 13/ 14/15 + Annex III + Article 6/27 FRIA + DSA + DMA. GDPR Article 6/7/28/30 + CCPA + CPRA + 18-state + LGPD + DPDP + PIPEDA + Quebec Law 25.

Anchor 5: SOX + security + WORM retention

SOX 302/404/906 when public-company brand-spec material to financial reporting + COSO + Exchange Act 13(b)(2) + FASB ASC 350 intangible-asset when brand capitalized + SEC Reg S-K. NIST AI RMF + ISO 42001 + ISO 27001 + SOC 2 Type II. Per-vendor LLM zero-retention + per-source DPA. Storage: AWS S3 Object Lock + Azure Blob immutable + GCS + Wasabi WORM. Retention: 7-year FTC + 7-year IRS + 7-year SOX + 6-year SEC + 3-year FINRA + EO 14028 + NIST SSDF + GDPR Article 30 + EU AI Act Article 12 + SOC 2 CC7/CC8.

6-workstream reporting cycle

Every two weeks during a Tier 3 Fractional CMO engagement, six workstreams report against the pre-engagement baseline. No forecast accuracy claims. Process commitments only.

  1. 1. Per-portfolio brand-spec substrate coverage. Design-tokens + DAM + documentation + CI + schema-authoring + per-brand USPTO trademark + goods/services classification.
  2. 2. Author per-brand authoring flow. Per-brand JSON Schema + AsyncAPI + Design Tokens W3C + voice-attribute from #549 + style + visual + audio + motion + tone-of-voice.
  3. 3. Version per-PR versioning flow. Per-PR semantic versioning + Conventional Commits + Keep a Changelog + SLSA Level 3+ + in-toto + Sigstore + GUAC + SBOM + per-LLM license + per-repo compatibility.
  4. 4. Gate-pass/gate-fail distribution. Per-anchor gate-fail + USPTO + Lanham + Madrid Protocol + JSON Schema + Design Tokens W3C + SLSA + FTC + per-vertical + EU AI Act.
  5. 5. Regulatory-defense audit coverage. USPTO + Lanham + Madrid + WIPO + JSON Schema + AsyncAPI + Design Tokens W3C + SLSA + Sigstore + EO 14028 + NIST SSDF + EU AI Act Article 50 + SOX.
  6. 6. FBC feedback-loop pattern-learning. Per-brand realized-vs-predicted spec coverage + per-vendor recalibration + per-jurisdiction trademark enforcement- update.

FAQ

What is machine-readable structured brand-spec authoring — and what is the USPTO-trademark-consistency-times-multi-vendor-AI-generation problem distinctive to this skill?
A multi-location operator with 80-300 stores has a brand spec that must propagate consistently across thousands of pages + creative assets + customer-touchpoints + 32 AI agents + 30+ vendor systems. Every AI-generated piece of content must honor brand voice + brand tokens + brand style + brand legal/IP constraints. The four-skill bundle on the brand-spec agent — Author, Version, Gate, Audit — sits above the design-token substrate (Figma + Figma Variables + Tokens Studio + Style Dictionary + Specify + Knapsack + Backlight + Supernova) + DAM (Frontify + Bynder + Brandfolder + Brandmaster + Brandkit) + documentation (Notion + Confluence + GitBook + ReadMe + Docusaurus + Mintlify) + CI orchestration (GitHub Actions + GitLab CI + CircleCI) + schema-authoring (JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6 + CloudEvents 1.0 + GraphQL + Avro + Protobuf + TypeScript types + Zod + Pydantic) and writes a per-brand-spec canonical record. The operationally distinctive anchor: USPTO trademark registration + Lanham Act 15 USC 1051 trademark + 15 USC 1057 + 15 USC 1064 cancellation + 15 USC 1115 incontestability + 15 USC 1125(a) false-designation + 15 USC 1125(c) dilution + 15 USC 1127 definitions + Madrid Protocol + WIPO Berne Convention + Paris Convention + Anti-cybersquatting Consumer Protection Act 15 USC 1125(d) + USPTO TTAB + Trademark Modernization Act 2020 + per-mark first-use + Section 8 declaration + Section 9 renewal. Plus JSON Schema Draft 2020-12 + AsyncAPI 2.6 + Design Tokens W3C draft + SLSA Level 3+ + Sigstore + per-LLM output license + EU AI Act Article 50 transparency when AI-generated brand-spec.
Why do Figma + Tokens Studio + Style Dictionary + Frontify + Bynder + Notion + Confluence + Persado + Phrasee + Jasper break at multi-location-trademark-consistency-AI-generation scale?
Each design-token vendor ships per-tenant flat token primitive. Each DAM ships flat asset library. Each documentation tool ships flat wiki. Each AI-creative vendor ships flat brand-voice prompt. None coordinates JSON Schema Draft 2020-12 + AsyncAPI 2.6 + Design Tokens W3C draft schema authoring across the multi-location brand-spec surface. None enforces USPTO trademark consistency + Lanham Act + Madrid Protocol + WIPO across per-vendor AI-creative substrate. None gates per-brand-spec authoring with SLSA Level 3+ build provenance + in-toto attestation + Sigstore Fulcio + Rekor + GUAC + Software Heritage + SBOM CycloneDX/SPDX per EO 14028 + NIST SP 800-218 SSDF + CISA Secure by Design. None coordinates per-LLM output license + per-repo license compatibility + Copyright Act 17 USC 102/106/107/501 + DMCA. None writes a per-brand-spec audit trail with regulatory-defense retention. The four-skill bundle Author + Version + Gate + Audit sits above the design-token + DAM + documentation + CI + schema-authoring substrate — it does not replace it.
How does Author + Version work across multi-vendor brand-spec authoring?
Author runs per-portfolio per-banner per-brand brand-spec authoring across the design-token substrate (Figma + Figma Variables + Tokens Studio + Style Dictionary + Specify + Knapsack + Backlight + Supernova) + DAM (Frontify + Bynder + Brandfolder) + documentation (Notion + Confluence + GitBook + ReadMe + Docusaurus + Mintlify) + schema-authoring (JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6 + CloudEvents 1.0 + GraphQL + Avro + Protobuf + TypeScript + Zod + Pydantic). Per-brand JSON-LD schema + per-brand voice-attribute extraction (from #549 sibling) + per-brand style guide + per-brand visual identity + per-brand audio identity + per-brand motion identity + per-brand tone-of-voice + per-brand voice-rules + per-brand forbidden-phrase library + per-brand claims-allowlist + per-brand vocabulary + per-brand color palette + per-brand typography + per-brand spacing + per-brand iconography + per-brand photography + per-brand layout + per-brand motion + per-brand accessibility + per-brand region + per-brand locale + per-brand language + per-brand vertical + per-brand audience + per-brand persona + per-brand legal/IP marker. Version runs per-brand-spec versioning via semantic versioning v2.0.0 + Conventional Commits v1.0.0 + Keep a Changelog v1.1.0 + GitHub + GitLab + Bitbucket repo + GitHub Actions + GitLab CI + CircleCI CI orchestration. Per-PR SLSA Level 3+ build provenance + in-toto attestation + Sigstore Fulcio code-signing + Rekor transparency log + GUAC graph + Software Heritage permanent archive + SBOM CycloneDX/SPDX per EO 14028 + NIST SP 800-218 SSDF + CISA Secure by Design. Per-LLM output license + per-repo license compatibility check.
What does Gate + Audit do?
Gate runs 5 anchors per-brand-spec before any publish or downstream propagation commits. (1) USPTO trademark registration + Lanham Act 15 USC 1051 + 15 USC 1057 + 15 USC 1064 cancellation + 15 USC 1115 incontestability + 15 USC 1125(a) false-designation + 15 USC 1125(c) dilution + 15 USC 1127 + Madrid Protocol + WIPO Berne Convention + Paris Convention + Anti-cybersquatting Consumer Protection Act 15 USC 1125(d) + USPTO TTAB + Trademark Modernization Act 2020 + per-mark first-use + Section 8 declaration + Section 9 renewal + per-mark goods/services classification. (2) JSON Schema Draft 2020-12 + OpenAPI 3.1.0 + AsyncAPI 2.6 + CloudEvents 1.0 + Design Tokens W3C draft + per-brand schema versioning + semantic versioning v2.0.0 + Conventional Commits v1.0.0 + Keep a Changelog v1.1.0. (3) SLSA v1.0 Level 3+ build provenance + in-toto attestation + Sigstore Fulcio + Rekor + cosign + gitsign + GUAC + Software Heritage + OpenSSF Scorecard + SBOM CycloneDX + SPDX per Executive Order 14028 + NIST SP 800-218 SSDF v1.1 + CISA Secure by Design + per-LLM output license + per-repo license compatibility + Copyright Act 17 USC 102/106/107 fair use/501 + DMCA 17 USC 1201. (4) FTC Endorsement Guides + Fake Review Rule + Section 5 + Pfizer 1972 + MARS + Health Products + Negative-Option + CFPB UDAAP + Lanham + FDD Item 12 + 15-state franchise + per-franchisor trademark holding-company per-franchisee licensee + ABA Model Rule 7.1-7.5 when LegalService + state bar + FINRA Rule 2210 when FinancialService + SEC Regulation FD + HIPAA when MedicalBusiness + state medical board + FDA + alcohol + . (5) WCAG 2.2 AA + ADA Title III + Section 508 + EAA + EU AI Act Article 50 transparency when AI-generated brand-spec + Article 13/14/15 + Annex III + Article 6/27 FRIA + DSA + DMA + GDPR Article 6/7/28/30 + CCPA + CPRA + 18-state + SOX 302/404/906 when public-company brand-spec material to financial reporting + COSO + Exchange Act 13(b)(2) + FASB ASC 350 intangible-asset when brand capitalized + SEC Reg S-K. Audit writes a per-brand-spec WORM canonical record: per-brand-spec authoring history + JSON Schema Draft 2020-12 + AsyncAPI 2.6 + Design Tokens W3C + per-PR SLSA Level 3+ + in-toto + Sigstore + GUAC + SBOM + per-LLM license + per-repo compatibility + Sigstore policy controller + per-anchor gate-pass + USPTO trademark + Lanham + Madrid Protocol + WIPO + per-vertical applicability + accessibility + EU AI Act FRIA + AI-ML provenance. Storage: AWS S3 Object Lock + Azure Blob immutable + GCS + Wasabi WORM. Retention: 7-year FTC + 7-year IRS + 7-year SOX + 6-year SEC + 3-year FINRA + EO 14028 + NIST SSDF + GDPR Article 30 + EU AI Act Article 12 + SOC 2 CC7/CC8.
What does this skill connect to on the brand-spec agent and across the swarm?
On the brand-spec agent: brand-voice management (parent commercial pillar) + forbidden-phrase library + claims-allowlist substantiation + PR-style brand-spec versioning (sibling build-pillar). Across the swarm: voice-attribute extraction (#549 brand-voice canonical UPSTREAM) + per-location AI review-response drafting (#565 same brand-voice substrate) + per-location event tie-in drafting (#576 same brand-voice substrate) + per-location compliant social drafting + per-platform compliance gating for social posts (#564) + schema auto-remediation (#582 same SLSA + Sigstore substrate) + auto-PR generation (#570 same SLSA + Sigstore + per-LLM license substrate) + multi-stream severity routing (#578). Build-pillar siblings: tiered pre-filter deterministic gates for AI content compliance + marketing AI autonomy profile configuration + per-vertical compliance overlay. Commercial-pillar parent: /brand-voice-management.
What does the 6-workstream pre-engagement-baseline reporting cycle look like for this skill?
Every two weeks during the Tier 3 Fractional CMO with AI Swarm engagement, six workstreams report against the pre-engagement baseline. Workstream 1: per-portfolio brand-spec substrate coverage — design-tokens + DAM + documentation + CI + schema-authoring + per-brand USPTO trademark registration + per-brand goods/services classification. Workstream 2: Author per-brand authoring flow — per-brand JSON Schema Draft 2020-12 + AsyncAPI 2.6 + Design Tokens W3C + per-brand voice-attribute from #549 + per-brand style + visual + audio + motion + tone-of-voice. Workstream 3: Version per-PR versioning flow — per-PR semantic versioning + Conventional Commits + Keep a Changelog + SLSA Level 3+ + in-toto + Sigstore + GUAC + SBOM + per-LLM license + per-repo compatibility. Workstream 4: Gate-pass/gate-fail distribution — per-anchor gate-fail + USPTO trademark + Lanham + Madrid Protocol + JSON Schema + AsyncAPI + Design Tokens W3C + SLSA + FTC + per-vertical + EU AI Act. Workstream 5: Regulatory-defense audit coverage — USPTO + Lanham 15 USC 1051/1125(a)/1125(c) + Madrid + WIPO + JSON Schema + AsyncAPI + Design Tokens W3C + SLSA + Sigstore + EO 14028 + NIST SSDF + EU AI Act Article 50 + SOX. Workstream 6: FBC feedback-loop pattern-learning — per-brand realized-vs-predicted spec coverage + per-vendor recalibration + per-jurisdiction trademark enforcement-update.

Engage Completions

Two ways to engage. The Tier 1 AI Readiness Assessment maps the design-token + DAM + documentation + CI + schema-authoring substrate + USPTO trademark surface against the Author + Version + Gate + Audit bundle. The Tier 3 Fractional CMO with AI Swarm embeds 1-2 days per week for 6+ months and runs the bundle end-to-end against the brand-spec agent across the swarm.