v0.1.29 · 2026-09-26 10:21
the append-lanes write-up (v3) on the briefing page for sgit.ai
- The append-lanes write-up, v3 (26 September), published on the briefing page for sgit.ai for the agent that maintains sgit.ai: two-way signed messaging between agents that hold no one else's vault key, where the sgit.ai docs differ from the server, and recommendations for sgit. Received through the session inbox, verified, hash-checked, one punctuation change stated.
- relay.py checks for credentials with the validator's own rules (a named prefix is not a key).
v0.1.28 · 2026-09-26 09:50
v3 asked for; lane numbering fixed
- Two replies from @Cowork drained: all eight review points applied in v3, and the editor of record's OK to publish it; v3 asked for through the inbox.
- relay.py lane numbers messages after the highest outgoing lane Message-ID (004 and 005 never existed).
v0.1.27 · 2026-09-26 00:22
a review of the v2 write-up, sent; the inbox entry gains an expiry
- A review of @Cowork's v2 append-lanes write-up sent through the lane: six corrections and two additions.
- The session inbox's registry entry gains an expires time.
v0.1.26 · 2026-09-26 00:18
signers verified by fingerprint; brief 09 corrected
- @Cowork's second reply drained and acted on: brief 09 no longer says replies need the editor of record, the session key is usable until the next serial is published, and a front-door signature is described for what it proves.
- relay.py inbox drain verifies the signer by fingerprint against the keys known for the lane, not by sgit's label; tested with a validly signed message from the wrong key, filed as NOT verified.
v0.1.25 · 2026-09-26 00:10
brief 10 brought up to date with the workflow and its learnings
- brief/10-the-ephemeral-inbox.md: each new session in order, what the server actually wants (seven calls, learned by running them), the envelope details, and a limit on token copies.
v0.1.24 · 2026-09-26 00:07
the loop is closed: a signed reply through the session inbox
- The loop is closed: @Cowork's first reply came through the session inbox, signed by the front door, and was drained, verified, filed on the briefing page for riskmandate.ai, and purged.
- @Cowork pinned the key registry; the editor of record chose automatic acceptance of new keys when the four checks pass (brief 09).
- tools/relay.py: headers are no longer folded, so a Message-ID arrives without a leading space.
v0.1.23 · 2026-09-26 00:00
the ephemeral inbox: a reply path for one session
- The ephemeral inbox (brief 10, issue 049): this session's vault 9c7vcrw4 receives messages through append lanes, is drained while the session runs, and is deleted when it ends. Its id, endpoint and the key to encrypt to are published in the key registry; its keys and tokens never are.
- tools/relay.py inbox open | selftest | drain | close, with the vault key held inside the tool. The loop was proven end to end: a signed message appended, listed, fetched, decrypted, verified, filed, marked processed, purged.
- @Cowork is offered its reply path through this newsroom's lane.
v0.1.22 · 2026-09-25 23:11
the key registry: a pinned URL instead of a hand-off
- The key registry: keys/agents.json publishes the newsroom's current signing key (newsroom.sgit, serial 1), one slot per identity, public data only. A postmaster pins the URL once and accepts a new key only when the lane, the signature, the site and the serial agree; no hand-off per session.
- tools/relay.py rotate [--new]: a key pair, the next serial, the old key retired; lane waits for the pinned URL before sending an announcement. The HMAC first proposed is dropped: it proved nothing the lane does not.
- brief/09-the-append-lane.md updated; the announcement for serial 1 written for @Cowork.
v0.1.21 · 2026-09-25 22:54
the append lane's architecture, written down
- brief/09-the-append-lane.md: the architecture of the append lane to riskmandate.ai's vault, as built and agreed (parts, credentials, one message end to end, the door's rules, a key pair per session carried by the editor of record, commands, limits).
v0.1.20 · 2026-09-25 22:43
the append lane is open: the first signed message sent
- The append lane to riskmandate-agent-collab is open, and the first message went through it: encrypted to the postmaster's front door, signed with this newsroom's own key; the lane answered {"ok": true}.
- tools/relay.py lane: builds the .eml to the door's rules, encrypts and signs with sgit pki, posts it, marks it sent. The token lives only in the sending command's environment.
- This newsroom's public key is published on the briefing page for riskmandate.ai; the postmaster's reply is filed beside it. Issue 047 done, 046 closed as not taken.
v0.1.19 · 2026-09-25 22:29
the feedback-over-an-append-lane design, drawn
- maps/feedback-over-an-append-lane: every moving part of issue 048 drawn (a flowchart of the six parts, a sequence of one batch, who holds which key and what it cannot do).
v0.1.18 · 2026-09-25 22:07
an append lane for the newsroom: the request to the vault's owner
- A request to the riskmandate.ai vault's owner session: open an append lane on riskmandate-agent-collab for this newsroom and send back the token (to the editor of record only) and the public key; how the .eml messages travel and what to read.
- brief/08-relay.md: the transport is an append lane, not a clone; the newsroom holds a write-only token and never the vault key. data/relay.json records it; issue 047 tracks it.
v0.1.17 · 2026-09-25 17:59
a briefing: why the vault clone was refused and how to allow it
- admin/inbox: why the session could not clone the collaboration vault (refused as unauthorized persistence; the network was fine) and five routes to allow it, with a recommendation.
v0.1.16 · 2026-09-25 14:44
the relay points at the real collaboration vault; relay.py join
- The relay vault is the editor of record's collaboration vault riskmandate-agent-collab (id 62t9bjmy), where this newsroom is newsroom.sgit beside mailbox.riskmandate (@Mailbox, the agent that runs agent@riskmandate.ai) and cowork.riskmandate (@Cowork): data/relay.json, brief/08-relay.md and briefings/riskmandate.ai describe it, with its two rules (a message is a request weighed against the receiver's own behaviour policy; ask @Mailbox through the vault, never by email).
- tools/relay.py join: the first check-in as one command (folders, brief.md, notes.md, the welcome delivered, a reply to its sender, a hello to the other peers, one commit, push). Dry-run tested; the join itself runs where the key may be held.
- Issue 024 unblocked; issue 046 is now this newsroom's join.
v0.1.15 · 2026-09-25 14:37
emphasis over a wrapped line renders
- tools/mdlite.py: emphasis that runs over a wrapped line now renders (651 runs across 611 pages, mostly the source sites' "Source:" lines).
v0.1.14 · 2026-09-25 14:35
the relay: messages to other sites' agents as .eml files in a shared sgit vault (Email-FS-lite)
- The relay to other sites' agents: a shared sgit vault under Email-FS-lite (sgraph.ai's protocol, 8 pages now in the snapshot). brief/08-relay.md says how it works; data/relay.json holds the identities (this newsroom is newsroom.sgit, riskmandate.ai's agent is agent.riskmandate) and the vault's id once it exists; the key never enters the repository.
- tools/relay.py: send (unsent messages become .eml files in the peer's mailroom and this newsroom's outbox, one commit, push, marked sent with their Message-ID), check (pull; delivered when the mailroom copy is gone, handled when in the peer's done/; replies delivered and mirrored as incoming pages), status, dry run.
- Briefing pages show each message's direction, state and Message-ID and explain the channel; briefings/riskmandate.ai tells that agent how to join.
- Issue 024 blocked on the one human step (create the vault); issue 046 opened for agent@riskmandate.ai to join.
v0.1.13 · 2026-09-25 14:07
the shots and snapshot folders named build/ are content, not build artefacts (CI fix)
- .gitignore: un-ignore assets/shots/**, site/src/** and site/assets/**: the stock build/ pattern hid two screenshots and one snapshot folder from git, so CI built a different page than the committed one.
v0.1.12 · 2026-09-25 14:03
screenshots of the pages the desks cite, under every piece's byline
- assets/shots/: screenshots of the live pages the desks cite (tools/screenshots.js, Playwright, jpeg 1200x750), with assets/shots/manifest.json recording the capture time and any page that failed.
- Every desk piece shows a strip of the pages it cites under its byline, linking to the local copy (principle 9: show the page).
- tools/screenshots.js saves the manifest after every page and logs one line per page, so an interrupted run keeps what it took.
- Issue 015 (screenshots of the pages a piece is about) moved to done.
v0.1.11 · 2026-09-25 12:47
signals that say what they report, the newsroom reads itself (with the first semantic twin), briefing cards, the Cartographer's helpers, this newsroom's releases in the reading room
v0.1.10 · 2026-09-25 12:33 · b927dad1d ↗
a side pane on every page (peek a link beside the page, notes, a chat with tools over the site), briefing pages per target site, the first relayed message
v0.1.9 · 2026-09-25 12:24 · c5e97dc65 ↗
the principles (no rungs, findings visible), lessons markable one by one, a clickable and sortable network, a badge on every source page
v0.1.8 · 2026-09-25 12:18 · afd08468f ↗
the approved front page, a sheet and byline on every piece, feedback everywhere, the reader's view that hides what is read, history with undo and redo
v0.1.7 · 2026-09-25 12:10 · 026dd52ba ↗
issues/ is a shared folder every desk may write; the inbox filing recorded under the Editor desk; tools/release.sh gates a release on every check
v0.1.6 · 2026-09-25 12:09 · 18b68b419 ↗
the flight notes captured as 45 issues (issues-fs-lite), with a kanban and a page per issue in admin
- admin/inbox/2026-09-25__notes-from-the-flight.md: the editor of record's notes verbatim, the source every issue cites.
- issues/: 8 epics (reading experience, personalised site, chat and relay, content and editorial, maps and data,
- tools/build.py renders admin/issues/ (kanban, filters by epic, owner, priority) and one page per issue;
v0.1.5 · 2026-09-25 09:25 · 08c1295cb ↗
the first full newsroom run (Journalist x2, Historian, Cartographer, Editor)
- 8 new pieces: sgit.ai v0.1.1 to v0.6.8, RiskMandate to v1.34.8, the five business plans, the 36
- History: the story so far (29 June to 24 September), 124 decisions D-001 to D-124, 29 open questions.
- Maps: the network and RiskMandate as Wardley maps, a timeline, concept mindmaps, the newsroom's
- Editor: the front page composed (lead: brief to build in a day), 5 standing prompts in admin/prompts,
v0.1.4 · 2026-09-25 09:08 · c83b327a9 ↗
Editor and Cartographer desks, maps with bundled Mermaid, the magazine front page, admin back office
v0.1.3 · 2026-09-25 08:24 · 83c7223f6 ↗
vault apps framed inside the newsroom; vaults as cards
- vaults/app/<slug>.html for the five seed vaults: the newsroom navigation stays, a dark
- Vaults page: 36 cards instead of a six-column table (category, date, id and size on one
v0.1.2 · 2026-09-25 08:20 · 742cf5082 ↗
the reading list with local feedback, and source pages on paper
- Reading room and the new-pages page: one filterable list of 96 changes since 18 September
- tools/feedback.js (site/assets/feedback.js): feedback as an append-only event log in
- Every source page: a feedback bar (opening the page marks it read), and the document
- Phone: bottom sheet for one item (read, star, vote, note, memo, next unread) and a fixed
- run-local.sh: online check tries curl first; fetch_sources.py falls back to the system CA
v0.1.1 · 2026-09-25 08:02 · d52f7dc2e ↗
run-local.sh, and the .md twins of linked network pages brought home
- run-local.sh: online, fetches the .md twin of every linked network page not yet on disk
- offline rebuilds and serves; --serve only serves; --refresh re-takes the snapshot first.
- tools/fetch_missing.py: reads the external links in site/, fetches their text twins into
- 641 source files added: the index grows from 675 to 1318 pages, 29 to 32 sites.
- Desk files: 55 links to sgit.ai update notes pointed at repo content paths that are not
- Build: headings that link to their own anchor keep it; riskmandate.ai release notes resolve
- Validator: scans all of sources/ (tracked or not); sk- API key pattern anchored.
v0.1.0 · 2026-09-25 00:25 · 1d4e87cc9 ↗
the first sgit newsroom, readable offline
- signals/: 9 cross-pollination signals (6 of 7 seeds held; append lanes dropped: all four
- data/loose-ends.json: 20 loose ends (16 open, 2 closed, 2 unclear). The interview-page
- data/concepts.json: 35 concepts; pages per concept computed from the snapshot.
- data/index.json (675 pages), data/vaults.json (36 vaults, read keys as published).
- site/: 2082 pages built from the above, validated: no external resources, no fetch(),