Librarian
Concepts
The ideas that recur across the network: 35 concepts. The pages under each are computed by searching the snapshot for the concept's terms, so they are complete for the snapshot, and noisy at the edges.
Acceptance intervals
The ladder of durations a risk can be accepted for, from an hour to six months with a month as the default, where the chosen interval sets both the severity and the response. where it is defined
13 pages on 3 sites
- riskmandate.ai (4): Who owns what in AI. And how accountability holds on the way up., RiskMandate — questions we were asked, RiskMandate — How long will you accept this risk?, 0.9.2.md
- risks.sgit.ai (3): risks.sgit.ai — Brief Pack, risks.sgit.ai — you cannot deny a risk, only say how long you accept it, risks.sgit.ai llms.txt
- sgit.ai (6): Every risk is already accepted. The only question is by whom, and for how long., Articles, Risk Acceptance Office, a business plan with one risk replayed, published as a v, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, The sgit.ai network, sibling sites
Agent Behaviour Policy
A written record, for one agent in one deployment, of everything it can do, what it was authorised to do, the gap between the two, and what actually stands in the way; it describes and carries no score. where it is defined
403 pages on 4 sites
- abp.sgit.ai (180): v0.9.0: Two more cases: this site's own session as a ledger, and three surfaces , v0.2.0: A rule this site published in the morning was wrong by the afternoon, an, v0.4.0: An ABP is a junction object, which is what Fractal Semantic Graphs is fo, v0.1.0: The ontology already existed, so the first release promoted it instead o, v0.10.0: The desktop walkthrough: on your own machine, host means your machine, , v0.8.0: The cost ABP: every ABP so far bounded what, and this one bounds how muc, The articles, v0.4.1: The map became files, pages and a gate check, and the walk is rebuilt on, v0.5.0: The releases get one article each, and the screenshots come from the tag, v0.7.0: The first case: one person's estate, the mandates elicited line by line,, v0.4.4: Seven deployment shapes somebody else measured, promoted with their prov, v0.4.3: The home page has argued about one setting since v0.1.0, and now the bui, v0.4.2: The fact diff was named as a blocker on four consecutive days, and it re, v0.6.0: Thirteen prompts a reader runs against their own mailbox, and the fourth, v0.3.0: read.file.project was a string with a gloss beside it, which is schema-f, Case beta-001: ChatGPT with the Google Calendar connector, allow all, Case beta-001: ChatGPT with the Google Drive connector, allow all, Case beta-001: ChatGPT with the Gmail connector, allow all, Case beta-001: ChatGPT with a meeting note taker connected, Case beta-001: The inbox scout: the same Gmail grant, running with nobody presen, Case beta-001: Claude with the Slack connector, Case beta-001: One person, two assistants, six deployments, one shared account, Case estate-002: Claude Code, in a container with a repository attached, Case estate-002: Claude Cowork, on the desktop, Case estate-002: Claude in the browser, with connectors possibly still on, Case estate-002: One person, three surfaces of one product, one account holding , Cases, Case session-001: Claude Code on the web, one repository attached: the session t, Case session-001: The session that built this site's last twelve releases, as a , The cost ABP: how much, not just what, Step 4: what a clause over a count cannot do, Step 1: what it has already spent, Step 2: what you actually paid for, Step 3: write the cost policy, GRANT.md — Reach, The data, An assistant on your own machine, Step 4: what a switch is, and is not, Step 1: what it can reach on your machine, Step 2: what matters, and what does not, Step 3: write the rules, The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has , The Delta Is Derived And Never Authored: Storing It Is The Point, And The Histor, Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know W, The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Se, The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, No Gmail Scope Lets An Agent Draft Without Letting It Send: The Drafts Have To L, The Behaviour Policy Is Already A Fractal And The Overlay Is Already Published: , The Split Does Not Break The Trifecta, The Schema Does: A Closed Vocabulary At T, The Transition Demotes An Imperative To A Proposition: The Ontology Bounds The S, The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, Marking Everything Read Destroys This User And Breaks Nothing: The Grant Cannot , The Consent Dialog Is An Accountability Transfer Rather Than A Decision: The Use, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Docs, Start Here, What To Build, The Conventions, The ABP Model, The First Examples, The Hard Rules, The Prompt, An External Review Of Fractal Semantic Graphs Against The Prior Work: Distribute, A browser extension with broad host permissions, Chat in the browser, nothing connected, The same coding agent, confirmations off, A coding agent on your own machine, confirmations on, A CI job on a hosted runner, under a service account, Five worked examples, Your mailbox, and what you gave it, The measured deployment: what the agent that holds the connector found, Step 4: what a prompt cannot do, Step 1: what it can already do, Step 2: what you actually asked for, Step 3: write the behaviour policy, Agent Behaviour Policy, abp.sgit.ai llms.txt, The barrier, authenticate-as.credential.signing, authenticate-as.credential.tenant, create.record.world, create.schedule.host, create.schedule.tenant, delete.file.host, execute.process.host, execute.process.self, grant.credential.self, The capability grammar, read.credential.host, read.file.host, read.file.project, read.message.tenant, read.record.browsing, read.record.history, send.endpoint.allowed, send.endpoint.world, send.message.world, write.budget.tenant, write.file.host, write.file.project, write.repository.project, write.repository.tenant, The delta, The edge vocabulary, The node type formulas, The graph, The three layers, The model, browser (family), code (family), communication (family), filesystem (family), identity (family), money (family), network (family), process (family), schedule (family), The lexicon, budget (object), credential (object), file (object), message (object), network-endpoint (object), process (object), record (object), repository (object), schedule (object), host (reach), project (reach), self (reach), tenant (reach), world (reach), authenticate-as (verb), create (verb), delete (verb), execute (verb), grant (verb), read (verb), receive (verb), revoke (verb), send (verb), write (verb), The schema, The undo class, The universes, U0: The source bytes, U1: The grammar, U10: The obligations, U11: The runtime, U12: The estate of agents, U2: The deployment shape, U3: The grant and its evidence, U4: The enforcement, U5: The deployer, U6: The derivation, U7: The projections, U8: The licence, the acceptance and the risk, U9: The estate and the twin, Versions, v0.1.0: the ontology is promoted out of a game and the five examples are derived, v0.10.0: the desktop walkthrough: an assistant on your own machine, the map of w, v0.10.1: the desktop walkthrough gets its article, with six figures captured fro, v0.11.0: the Gmail connector measured end to end by the agent that holds it, rea, v0.2.0: the delta is derived and never authored, so it is stored with its inputs, v0.3.0: read, file and project become nodes with their own addresses, and a node, v0.4.0: the ABP is mapped onto Fractal Semantic Graphs: one row crosses nine uni, v0.4.1: the universes become data with a page each, the walk of one row is built, v0.4.2: the fact set is data, the fact diff runs over every published page, and , v0.4.3: the product, the tool and the setting become nodes, derived from data al, v0.4.4: seven shapes contributed by riskmandate.ai are promoted with their prove, v0.5.0: the releases get one article each, with the screenshots taken from the t, v0.5.1: the articles run newest first, carry their version in the title, and lin, v0.6.0: a walkthrough for somebody who has connected an assistant to their own m, v0.6.1: the mailbox walkthrough gets its article, with six figures captured from, v0.7.0: the first case: one person's estate of six deployments, the mandates eli, v0.7.1: the first case gets its article, with six figures captured from the v0.7, v0.8.0: the cost ABP: a walkthrough over how much an agent may spend rather than, v0.8.1: the cost ABP gets its article, with six figures captured from the v0.8.0, v0.9.0: two more cases: the session that built this site, as a ledger with a mea, What is an Agent Behaviour Policy
- riskmandate.ai (171): RiskMandate — the reviewed level: two sessions, and a professional signs it, RiskMandate — the behaviour-policy vault for A browser extension, RiskMandate — the behaviour-policy vault for ChatGPT in the browser, RiskMandate — the behaviour-policy vault for Claude Code, confirmations off, RiskMandate — the behaviour-policy vault for Claude Code on your machine, RiskMandate — the behaviour-policy vault for Claude Code on the web, RiskMandate — the behaviour-policy vault for Claude Desktop, RiskMandate — the behaviour-policy vault for Claude's Gmail connector, RiskMandate — the behaviour-policy vault for Microsoft 365 connector (Claude), RiskMandate — the behaviour-policy vault for Claude in the browser, connectors o, RiskMandate — the behaviour-policy vault for Dropbox MCP server, RiskMandate — the behaviour-policy vault for GitHub Actions, RiskMandate — the behaviour-policy vault for Gmail, read-only scope, RiskMandate — the behaviour-policy vault for Google Drive, read-only scope, RiskMandate — the behaviour-policy vault for Google Workspace MCP servers, RiskMandate — the behaviour-policy vault for n8n, owner API key, RiskMandate — the behaviour-policy vault for A scheduled job, RiskMandate — the Agent Behaviour Policy, Start here, The map, The Agent Behaviour Policy, condensed, Where we are, and what is next, Rules of engagement for agents working in parallel, Workflows, riskmandate.ai — read this first, brief-from-debrief, merge-to-dev, new-page, new-vault, onboard, research-vault, The agents' front door, Vaults in vaults: the application vault is data, the renderer lives once, The policy is a graph, and every stakeholder gets a projection of it, Direction change — the Agent Behaviour Policy becomes the primitive, A grant is a union of capabilities; what the reader needs is the consequences — , The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, The grant has storeys: what the credential permits, what the client exposes, wha, The menu after the ABP turn: five entries, one product first, and eleven pages o, Nobody buys a policy until they have made a small one, so the next phase is user, A policy per use case, and the £500 level is a prompt the customer runs, How riskmandate.ai actually works, Briefs written here, LinkedIn company page — every field, ready to paste, The agents' front door: onboard in ten minutes, and work in parallel without und, Connector grants: the open questions, written to be handed to an agent, The Design Studio MVPs, read against the workflow that sells a behaviour policy, The first measured behaviour policy: an owner API key on a self-hosted n8n, read, Five synthetic users read the new home page: the word is fixed, the vocabulary i, The vault pages, read against the vault: show the thing, and stop copying it, Lisbon messaging — we now have something to sell in the room, Startup Summit Lisbon 2026 — strategy, materials, and the build list, A behaviour policy for everybody the lead talks to, made by an agent from a zip, Buying a behaviour policy for Claude on one Gmail mailbox: the workflow, run onc, The reviewer manifest: one source for who does the work, addressed to the store , The memo queue, Tooling and the gate, The vaults, T01 — One page per behaviour, T02 — The grant as edges, one per path, T03 — Metrics and outward links on the 23 behaviours, T04 — Views per audience, and projections regenerated from a shipped prompt, T07 — Lab 03: bring the request list against the model site up to date, T08 — Bring docs/how-the-website-works.md to the current site, T09 — Stop deploying the vault: inputs in the repository, the product in the vau, T10 — The two Voice Debrief use-case vaults, and a use-case axis on the library, T11 — Consequences and assets: what follows when a capability meets what is in t, T12 — The standards mini-graphs inside the vault: GDPR, the EU AI Act and ATT&CK, Task briefs — written to be picked up by one agent each, The board, RiskMandate — after payment: a debrief for the store team, RiskMandate — which Agent Behaviour Policy next?, RiskMandate — Agent Behaviour Policies, one vault per application, RiskMandate — an approval prompt is not a human in the loop, A deleted meeting comes back. An edited one does not., The pilot worked. Then somebody asked what else it could do., One agent, and every desk it reaches. How to read the risk propagation visualise, RiskMandate — in this session, the agent holds the union of everything it has ev, RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one, Who owns what in AI. And how accountability holds on the way up., RiskMandate — articles, Every Routable Address Is In The Grant: Do Not Attack Anyone Is The One Rule Eve, The Commit Author Is A Free Text Field: A Prompt Shifts The Odds, And Every Docu, The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The, The Urgency Is Not A Deadline But A State: You Already Connected It, And A Distr, The Offer Is Built And The Button Is Not: Each Level Is The Level Below Plus One, RiskMandate — the brief register, RiskMandate — the business case for Agent Behaviour Policy, RiskMandate — business cases, by the risk they change, RiskMandate — How it works: from a prompt to a graph with provenance, RiskMandate — Know what your agents can do, Make your agents insurable, RiskMandate — can you insure a software program?, RiskMandate — Half an hour of your advice, by voice, What buying a behaviour policy would look like — RiskMandate Lab 02, Changes we are asking of the behaviour-policy site — RiskMandate Lab 03, RiskMandate — Lab 05 · the commit author is a free text field, The grant is user-shaped, not data-shaped — RiskMandate Lab 01, RiskMandate — Lab 06 · every routable address is in the grant, RiskMandate — Lab 04 · the shape collector, What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandat, Licence to Operate, riskmandate.ai llms.txt, RiskMandate — OWASP, as a graph, RiskMandate — thank you: level 1, what happens now, RiskMandate — thank you: level 2, what happens now, RiskMandate — thank you: level 3, what happens now, RiskMandate — thank you: level 4, what happens now, RiskMandate — Pricing: four levels, £10 to £1,500, RiskMandate — privacy: what this site collects, and how to check, RiskMandate — questions we were asked, RiskMandate — Dinis Cruz, who runs the review, RiskMandate — who runs your review, Startup Summit Lisbon 2026 — RiskMandate materials, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, Synthetic users — five people who do not exist, reading this site, RiskMandate — try it: write a behaviour policy for your own agent in twenty minu, UK support, in the open, AGENT BEHAVIOUR POLICY — Claude Code on the web, with one repository attached, AGENTS.md — how to treat the behaviour policy files beside this one, DELTA — what it can do that you did not ask for, GRANT — everything the agent can do, LICENCE TO OPERATE — the organisation authorises the agent, under this behaviour, MANDATE — what the agent is authorised and expected to do, Claude Code on the web, with one repository attached — an Agent Behaviour Policy, Agent Behaviour Policy — skill, The vocabulary this vault was computed against, Grant check — 15 September 2026, from inside the shape, MAP-A-GRANT.md — a prompt for an agent that holds a connector or a credential, RiskMandate — version record, 1.1.0.md, 1.11.0.md, 1.12.0.md, 1.13.0.md, 1.14.0.md, 1.15.0.md, 1.16.0.md, 1.17.0.md, 1.19.0.md, 1.19.2.md, 1.2.0.md, 1.20.0.md, 1.20.1.md, 1.21.0.md, 1.22.0.md, 1.22.1.md, 1.23.0.md, 1.24.0.md, 1.25.0.md, 1.25.2.md, 1.25.4.md, 1.26.0.md, 1.27.0.md, 1.27.1.md, 1.27.3.md, 1.28.0.md, 1.29.0.md, 1.29.2.md, 1.32.0.md, 1.32.1.md, 1.33.0.md, 1.34.1.md, 1.34.3.md, 1.34.4.md, 1.34.5.md, 1.34.8.md, 1.4.0.md, 1.5.0.md, 1.8.0.md, Brief B1 — power user and tester of Agent Behaviour Policies, Working with us — briefs for collaborators and their agents
- sgit.ai (15): Release history, Before you give an agent a connector, give the connector a twin, Fractal Semantic Graphs: everything connects to everything, and nobody has to sh, Fractal Semantic Graphs, Company X-Ray, a business plan with one company X-rayed, published as a vault, Synthetic users, second run, five people who do not exist, reading riskmandate.a, Cross-team briefs, For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit.ai llms.txt, sgit.ai llms.txt, Models do the work, vaults hold it: proposed partnerships with the AI providers, A proposed partnership between sgit.ai and Anthropic, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Updates (sgit.ai)
- store.sgit.ai (37): Design brief — store.sgit.ai, Never leave the site — and write down who owns what, The homepage sells — and the work has been done before, /next/ — the next store, Stripe, A partner walked the whole store and wrote it up, What happened to each memo, index.md, The work, Take money at all, The homepage sells, Who owns what, You have to answer for it, You are a founder, You own the register, You are backing a company, You do this for a living, Who is this for?, index.md, index.md, Your order, Tier 3 — Can you correct it for my situation?, index.md, Agent Behaviour Policies for the agents you already run, Everything this store says, and how it knows, store.sgit.ai llms.txt, Gmail, read-only scope, Something not on this list, What lands, and when, Which agent do you run?, The product page — the next store, index.md, index.md, index.md, index.md, Dinis Cruz, Who does the work
Append lanes
A write-only channel into a vault: the writer holds a token that can only append, gets back a blind acknowledgement, and entries sit outside the commit tree until the vault owner processes them. where it is defined
47 pages on 6 sites
- abp.sgit.ai (1): No Gmail Scope Lets An Agent Draft Without Letting It Send: The Drafts Have To L
- games.sgit.ai (4): Building a game as a vault, The catalogue, games.sgit.ai llms.txt, What our games send
- pki.sgit.ai (2): pki.sgit.ai llms.txt, pki.sgit.ai llms.txt
- riskmandate.ai (3): The memo queue, RiskMandate — Lab 04 · the shape collector, riskmandate.ai llms.txt
- sgit.ai (35): Release history, API: append lanes (sgit.ai), API authentication, The HTTP API, sgit.ai llms.txt, API: transfers, one encrypted handover, one link, API: vault objects, Before you give an agent a connector, give the connector a twin, Articles, Performance, cost, and running everywhere, Fractal Semantic Graphs, Two games about agent permissions (a published vault), Lesson Loop, a business plan for coaches with one player's record, published as , Cross-team briefs, For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it, Publishing a vault’s decks onto a website, build brief, Telemetry from a published vault, a build brief, Working on a vault: start here, guidance, sgit.ai llms.txt, Documentation, sgit, sgit.ai llms.txt, Keys, signatures and encrypting to someone else, Sending messages between vaults, The window.sg bridge, SG/Vault, Static hosting on GitHub Pages, SG/Vault, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, nhi.sgit.ai, Agents you run, agents you rent, and the identity gap, pki.sgit.ai, A key registry for agents, designed from a documented failure, Models do the work, vaults hold it: proposed partnerships with the AI providers, sgit runs on every cloud: proposed partnerships with the cloud platforms, Building HTML Apps That Live Inside an SG/Vault, Skills for AI agents, sgit, The board, open work on sgit.ai, as a kanban of files, Cartographer, an agentic role on sgit.ai, Updates (sgit.ai)
- what-can-it-do.games.sgit.ai (2): what-can-it-do.games.sgit.ai llms.txt, Contribute
Blast radius
How far the harm from a grant, a risk or a control reaches: which systems, people and roles it touches, recorded beside the owner and the expiry of each mandate. where it is defined
60 pages on 11 sites
- abp.sgit.ai (16): v0.6.0: Thirteen prompts a reader runs against their own mailbox, and the fourth, Case beta-001: ChatGPT with the Google Calendar connector, allow all, Case beta-001: ChatGPT with the Google Drive connector, allow all, Case beta-001: ChatGPT with the Gmail connector, allow all, Case beta-001: ChatGPT with a meeting note taker connected, Case beta-001: The inbox scout: the same Gmail grant, running with nobody presen, Case beta-001: Claude with the Slack connector, Case estate-002: Claude Code, in a container with a repository attached, Case estate-002: Claude Cowork, on the desktop, Case estate-002: Claude in the browser, with connectors possibly still on, Case estate-002: One person, three surfaces of one product, one account holding , GRANT.md — Reach, MANDATE.md — What the business authorised, The Consent Dialog Is An Accountability Transfer Rather Than A Decision: The Use, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Step 1: what it can already do
- elevenlabs.providers.sgit.ai (4): index.md, index.md, index.md, index.md
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- llms.sgit.ai (2): The provider layer, The security model, and the gap in it
- nhi.sgit.ai (2): Shared Drives For Agents: Everything Available Runs On Your Identity, Granularit, nhi.sgit.ai llms.txt
- pki.sgit.ai (2): pki.sgit.ai — good public key repositories existed, and were destroyed, pki.sgit.ai llms.txt
- providers.sgit.ai (2): index.md, index.md
- riskmandate.ai (19): Risk Mandate — agents act, and someone has to own the risk, Where we are, and what is next, The policy is a graph, and every stakeholder gets a projection of it, Nobody buys a policy until they have made a small one, so the next phase is user, Startup Summit Lisbon 2026 — strategy, materials, and the build list, The memo queue, RiskMandate — in this session, the agent holds the union of everything it has ev, RiskMandate — the brief register, RiskMandate — Know the risk. Name the owner. Own the mandate., Make your agents insurable, riskmandate.ai llms.txt, RiskMandate — Who can pull the plug?, RiskMandate — questions we were asked, 0.11.0.md, 0.4.3.md, 0.9.1.md, 1.34.5.md, 1.34.6.md, 1.34.8.md
- risks.sgit.ai (2): risks.sgit.ai — Brief Pack, risks.sgit.ai llms.txt
- sgit.ai (9): Release history, Git for things you cannot put on GitHub, Case studies, AI vs. AI, Black Hat Europe 2025, a published vault, Seven shorts on the licence to operate, the author's walkthroughs, The author’s walkthroughs, Risk Graph Explorer, Lessons learned, the rules and the incidents behind them, Updates (sgit.ai), Findings about your own weaknesses, sgit use cases
- ungovr.providers.sgit.ai (1): index.md
Brand assets
The logos, marks, colour tokens and boilerplate descriptions of set lengths that a site publishes for others to reuse, such as event forms and printers. where it is defined
10 pages on 2 sites
- riskmandate.ai (9): RiskMandate — Brand guidelines, riskmandate.ai llms.txt, Startup Summit Lisbon 2026 — RiskMandate materials, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, RiskMandate — version record, 0.13.0.md, 1.1.0.md, 1.29.1.md, 1.29.2.md
- ungovr.providers.sgit.ai (1): 02 — The Model: Nodes, Edges, Addressing, Provenance
Briefs
Documents one team writes for another: cross-team asks that carry a status and close when answered, and build briefs written for an agent to execute, tracked in public indexes and registers. where it is defined
145 pages on 4 sites
- abp.sgit.ai (40): The data, The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has , The Delta Is Derived And Never Authored: Storing It Is The Point, And The Histor, Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know W, The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Se, The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, No Gmail Scope Lets An Agent Draft Without Letting It Send: The Drafts Have To L, The Behaviour Policy Is Already A Fractal And The Overlay Is Already Published: , The Split Does Not Break The Trifecta, The Schema Does: A Closed Vocabulary At T, The Transition Demotes An Imperative To A Proposition: The Ontology Bounds The S, The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, Marking Everything Read Destroys This User And Breaks Nothing: The Grant Cannot , The Consent Dialog Is An Accountability Transfer Rather Than A Decision: The Use, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Docs, What To Build, Step 4: what a prompt cannot do, Step 2: what you actually asked for, Step 3: write the behaviour policy, abp.sgit.ai llms.txt, The delta, The graph, The universes, U0: The source bytes, U1: The grammar, U10: The obligations, U11: The runtime, U12: The estate of agents, U2: The deployment shape, U3: The grant and its evidence, U4: The enforcement, U5: The deployer, U6: The derivation, U7: The projections, U8: The licence, the acceptance and the risk, U9: The estate and the twin, v0.2.0: the delta is derived and never authored, so it is stored with its inputs, v0.4.0: the ABP is mapped onto Fractal Semantic Graphs: one row crosses nine uni, v0.6.0: a walkthrough for somebody who has connected an assistant to their own m, What is an Agent Behaviour Policy
- llms.sgit.ai (2): Site Architecture, The documents
- riskmandate.ai (67): Start here, The map, The Agent Behaviour Policy, condensed, Where we are, and what is next, Rules of engagement for agents working in parallel, Workflows, riskmandate.ai — read this first, brief-from-debrief, research-vault, The agents' front door, Architecture Brief — Decoupling site structure from content, Vaults in vaults: the application vault is data, the renderer lives once, The policy is a graph, and every stakeholder gets a projection of it, Direction change — the Agent Behaviour Policy becomes the primitive, A grant is a union of capabilities; what the reader needs is the consequences — , The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, The grant has storeys: what the credential permits, what the client exposes, wha, The menu after the ABP turn: five entries, one product first, and eleven pages o, Nobody buys a policy until they have made a small one, so the next phase is user, A policy per use case, and the £500 level is a prompt the customer runs, How riskmandate.ai actually works, Implementation Brief — Scenarios pilot (first decoupled content area), The agents' front door: onboard in ten minutes, and work in parallel without und, Connector grants: the open questions, written to be handed to an agent, The Design Studio MVPs, read against the workflow that sells a behaviour policy, The first measured behaviour policy: an owner API key on a self-hosted n8n, read, Five synthetic users read the new home page: the word is fixed, the vocabulary i, The vault pages, read against the vault: show the thing, and stop copying it, Lisbon messaging — we now have something to sell in the room, Startup Summit Lisbon 2026 — strategy, materials, and the build list, A behaviour policy for everybody the lead talks to, made by an agent from a zip, Buying a behaviour policy for Claude on one Gmail mailbox: the workflow, run onc, The reviewer manifest: one source for who does the work, addressed to the store , The console, The memo queue, The records, T01 — One page per behaviour, T02 — The grant as edges, one per path, T04 — Views per audience, and projections regenerated from a shipped prompt, T05 — Settle the open questions in the five connector vaults, T07 — Lab 03: bring the request list against the model site up to date, T08 — Bring docs/how-the-website-works.md to the current site, T09 — Stop deploying the vault: inputs in the repository, the product in the vau, T10 — The two Voice Debrief use-case vaults, and a use-case axis on the library, T11 — Consequences and assets: what follows when a capability meets what is in t, T12 — The standards mini-graphs inside the vault: GDPR, the EU AI Act and ATT&CK, RiskMandate — the brief register, RiskMandate — Lab 05 · the commit author is a free text field, RiskMandate — Lab 06 · every routable address is in the grant, riskmandate.ai llms.txt, Grant check — 15 September 2026, from inside the shape, 1.13.0.md, 1.14.0.md, 1.15.0.md, 1.16.0.md, 1.18.0.md, 1.19.0.md, 1.22.1.md, 1.23.0.md, 1.25.3.md, 1.25.4.md, 1.26.0.md, 1.32.1.md, 1.34.2.md, 1.6.0.md, 1.8.0.md, 1.9.0.md
- sgit.ai (36): Release history, API: append lanes (sgit.ai), The proof moved up, the homepage after the rebuild, next to the before pictures, The day we leaked our own vault key (sgit.ai case study), Case studies, Demos, The Strategy in Seven Maps, a real document republished from a vault, sgit.ai de, A vault app, live inside this page, sgit.ai demos, Two games about agent permissions (a published vault), Start with an AI decision, then trace it back to the guidance: the DSIT AI Risk , Brief: first-class serialised diffs, and ignore-file support, Briefing: embedding the Vault App iframe inside sgit.ai pages, reusing your code, For graphs.sgit.ai: Fractal Semantic Graphs, and what to change, Cross-team briefs, Markdown and file viewers in a vault: what not to build (build brief), For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, Reading a vault from a .sgit.ai site page, build brief, Publishing a vault’s decks onto a website, build brief, An infographic of the published vaults, build brief, Telemetry from a published vault, a build brief, Working on a vault: start here, guidance, sgit.ai llms.txt, Documentation, sgit, sgit.ai llms.txt, Content authoring, SG/Vault, Reading one file out of a vault, SG/Vault, sgit (the encrypted git for humans and AI agents), sgit.ai, for investors, published in the open, sgit.ai llms.txt, Models do the work, vaults hold it: proposed partnerships with the AI providers, Starting prompts for the regular work (sgit.ai team), Updates (sgit.ai), Agent state that isn't the vendor's to read, sgit use cases, The serialised pull request, sgit use cases, Why does this exist?
Business plans
Businesses sgit.ai thinks should exist on top of sgit, each published as a vault with the plan, sourced facts, numbers marked as hypotheses and prototypes, for someone else to take and run. where it is defined
14 pages on 1 sites
- sgit.ai (14): Release history, Before you give an agent a connector, give the connector a twin, Every risk is already accepted. The only question is by whom, and for how long., Agent as Webmaster, a business plan published as a vault, Company X-Ray, a business plan with one company X-rayed, published as a vault, Connector Twin, a business plan with a working replay, published as a vault, Published vaults, Lesson Loop, a business plan for coaches with one player's record, published as , sgit.ai llms.txt, Risk Acceptance Office, a business plan with one risk replayed, published as a v, sgit.ai llms.txt, Who holds the keys? A call for collaboration on vault key management, Business plans to build on sgit, Build your startup on sgit vaults
Client-side encryption
Content is encrypted on the owner's device before it is stored, so the host holds only ciphertext and cannot read it; the zero-knowledge model behind every vault. where it is defined
55 pages on 10 sites
- abp.sgit.ai (1): The Hard Rules
- nhi.sgit.ai (1): nhi.sgit.ai llms.txt
- open-source.sgit.ai (1): 01 — Concepts Index
- riskmandate.ai (9): Risk Mandate — agents act, and someone has to own the risk, LinkedIn company page — every field, ready to paste, Startup Summit Lisbon 2026 — strategy, materials, and the build list, RiskMandate — Know the risk. Name the owner. Own the mandate., riskmandate.ai llms.txt, RiskMandate — Who can pull the plug?, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, 0.5.0.md, 0.5.1.md
- sg-sentinel.sgit.ai (1): sg-sentinel.sgit.ai llms.txt
- sgit.ai (34): Release history, API: transfers, one encrypted handover, one link, Before you give an agent a connector, give the connector a twin, Articles, The proof is two clicks behind the claim, what the homepage gets wrong, and the , Git for things you cannot put on GitHub, One working tree, two version control systems, and why we stopped, sgit.ai case , Company X-Ray, a business plan with one company X-rayed, published as a vault, Lesson Loop, a business plan for coaches with one player's record, published as , RiskMandate: File security, a published vault, VoiceDebrief, a published vault, Run your own SG/Send server (sgit.ai), For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, When NOT to use sgit, Docs, sgit.ai llms.txt, Git repos inside vaults, SG/Vault, SG/Vault & the vault platform, sgit.ai llms.txt, Static hosting on GitHub Pages, SG/Vault, Sub-vaults, SG/Vault, What is sgit, Docs, sgit (the encrypted git for humans and AI agents), sgit.ai, for investors, published in the open, sgit.ai llms.txt, graphs.sgit.ai, A node is just a node, meaning lives in the edges, A proposed partnership between sgit.ai and Mistral AI, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Who holds the keys? A call for collaboration on vault key management, Security model, sgit, SKILL: Create Vault Content for SG/Send Browse, SKILL: sgit — Zero-Knowledge Encrypted Vault Operations, Updates (sgit.ai), Data that changes what is permissible, sgit use cases, Why does this exist?
- store.sgit.ai (2): index.md, Everything this store says, and how it knows
- subscriptions.sgit.ai (2): subscriptions.sgit.ai — a subscription is a discount, not rent, subscriptions.sgit.ai llms.txt
- teams.sgit.ai (3): Appsec, Architect, Journalist
- what-can-it-do.games.sgit.ai (1): Above the ceiling
Em-dashes and style
The network's writing rules, most visibly the removal of the em-dash from prose on sgit.ai on 20 September 2026, rewritten by context rather than replaced, with a validator guard. where it is defined
17 pages on 6 sites
- abp.sgit.ai (6): v0.2.0: A rule this site published in the morning was wrong by the afternoon, an, The data, The Conventions, The Hard Rules, v0.1.0: the ontology is promoted out of a game and the five examples are derived, v0.11.0: the Gmail connector measured end to end by the agent that holds it, rea
- coding.sgit.ai (1): coding.sgit.ai llms.txt
- llms.sgit.ai (1): 07 — Boundaries and licensing
- open-source.sgit.ai (1): 01 — Concepts Index
- riskmandate.ai (5): riskmandate.ai — read this first, brief-from-debrief, release, Direction change — the Agent Behaviour Policy becomes the primitive, The agents' front door: onboard in ten minutes, and work in parallel without und
- sgit.ai (3): Release history, For graphs.sgit.ai: Fractal Semantic Graphs, and what to change, Updates (sgit.ai)
EU AI Act
Regulation (EU) 2024/1689, the one instrument standards.sgit.ai models, cited across the network for duties such as judging residual risk acceptable without a definition of acceptable. where it is defined
52 pages on 7 sites
- graphs.sgit.ai (2): graphs.sgit.ai llms.txt, graphs.sgit.ai — a node is just a node; meaning lives in the edges
- newsroom.sgit.ai (1): newsroom.sgit.ai llms.txt
- riskmandate.ai (15): RiskMandate — Accepted is not acceptable, Risk Mandate — agents act, and someone has to own the risk, Direction change — the Agent Behaviour Policy becomes the primitive, A grant is a union of capabilities; what the reader needs is the consequences — , LinkedIn company page — every field, ready to paste, Lisbon messaging — we now have something to sell in the room, T12 — The standards mini-graphs inside the vault: GDPR, the EU AI Act and ATT&CK, Task briefs — written to be picked up by one agent each, The board, RiskMandate — How it works: from a prompt to a graph with provenance, riskmandate.ai llms.txt, RiskMandate — OWASP, as a graph, 0.12.2.md, 1.24.0.md, 1.32.0.md
- risks.sgit.ai (2): risks.sgit.ai — Brief Pack, risks.sgit.ai llms.txt
- sgit.ai (19): Release history, Every risk is already accepted. The only question is by whom, and for how long., The future of news is the story vault, not the paywall, Articles, Fractal Semantic Graphs: everything connects to everything, and nobody has to sh, Git for things you cannot put on GitHub, Fractal Semantic Graphs, Performance, cost, and running everywhere, Fractal Semantic Graphs, Provenance is not conformance, a published vault, Published vaults, sgit.ai llms.txt, Regulation Graph, a published vault, The author’s walkthroughs, Risk Graph Explorer, VoiceDebrief, a published vault, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, The sgit.ai network, sibling sites, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Updates (sgit.ai)
- standards.sgit.ai (2): standards.sgit.ai — point at the provision, or you are asserting, standards.sgit.ai llms.txt
- ungovr.providers.sgit.ai (11): 00 — README: The Government Graph Pack, 01 — What Exists: The Assembly Inventory, 03 — The Worked Example: One County, One Law, One Acceptance, 06 — Verification: Acceptance Tests, Claim States, Blockers, 01 — The Anchor-Node Thesis, 03 — The Standards Map, 04 — The Worked Example, 05 — Integration, 06 — Verification, The Security-Standards Graph — a dev pack, index.md
Fractal semantic graphs
Graphs where each node can open into a graph of its own with its own ontology, joined by a shared grammar rather than a shared schema, so the same rules hold at every altitude. where it is defined
39 pages on 4 sites
- abp.sgit.ai (18): v0.4.0: An ABP is a junction object, which is what Fractal Semantic Graphs is fo, The articles, v0.4.1: The map became files, pages and a gate check, and the walk is rebuilt on, v0.3.0: read.file.project was a string with a gloss beside it, which is schema-f, The Behaviour Policy Is Already A Fractal And The Overlay Is Already Published: , The Transition Demotes An Imperative To A Proposition: The Ontology Bounds The S, The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Docs, An External Review Of Fractal Semantic Graphs Against The Prior Work: Distribute, abp.sgit.ai llms.txt, The graph, The model, The universes, Versions, v0.4.0: the ABP is mapped onto Fractal Semantic Graphs: one row crosses nine uni, v0.4.1: the universes become data with a page each, the walk of one row is built, v0.7.0: the first case: one person's estate of six deployments, the mandates eli
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- sg-sentinel.sgit.ai (1): sg-sentinel.sgit.ai llms.txt
- sgit.ai (19): About the author, Dinis Cruz, Release history, Every risk is already accepted. The only question is by whom, and for how long., The future of news is the story vault, not the paywall, Articles, Fractal Semantic Graphs: everything connects to everything, and nobody has to sh, The SaaS apocalypse will be decided by inertia, not by AI, Fractal Semantic Graphs, Performance, cost, and running everywhere, Fractal Semantic Graphs, Demos, Start with an AI decision, then trace it back to the guidance: the DSIT AI Risk , VoiceDebrief, a published vault, For graphs.sgit.ai: Fractal Semantic Graphs, and what to change, Cross-team briefs, sgit.ai llms.txt, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Updates (sgit.ai)
Frozen, hashed sources
Every source page fetched, frozen to a dated snapshot and hashed with SHA-256, so claims are read from the frozen copy and can be checked later. where it is defined
5 pages on 5 sites
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- newsroom.sgit.ai (1): newsroom.sgit.ai llms.txt
- pt.newsroom.sgit.ai (1): pt.newsroom.sgit.ai llms.txt
- riskmandate.ai (1): 1.0.0.md
- sgit.ai (1): The future of news is the story vault, not the paywall
GDPR
The EU data protection regulation, published by sgit.ai as a navigable graph vault and cited by articles in the partnership and risk work, while one sibling site still says no GDPR graph exists. where it is defined
42 pages on 7 sites
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- open-source.sgit.ai (1): 07 — Site architecture, licensing and boundaries
- riskmandate.ai (15): The Agent Behaviour Policy, condensed, Where we are, and what is next, The policy is a graph, and every stakeholder gets a projection of it, A grant is a union of capabilities; what the reader needs is the consequences — , The memo queue, T03 — Metrics and outward links on the 23 behaviours, T12 — The standards mini-graphs inside the vault: GDPR, the EU AI Act and ATT&CK, Task briefs — written to be picked up by one agent each, The board, This Is The Tier One Application Nobody Could Find: The Connector List Alone Is , RiskMandate — the brief register, RiskMandate — How it works: from a prompt to a graph with provenance, RiskMandate — Lab 04 · the shape collector, 1.24.0.md, 1.32.0.md
- sgit.ai (16): Release history, Fractal Semantic Graphs: everything connects to everything, and nobody has to sh, Fractal Semantic Graphs, Published vaults, sgit.ai llms.txt, The author’s walkthroughs, Risk Graph Explorer, Standards Atlas: GDPR, a published vault, For graphs.sgit.ai: Fractal Semantic Graphs, and what to change, Cross-team briefs, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit.ai llms.txt, sgit.ai llms.txt, The sgit.ai network, sibling sites, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Updates (sgit.ai), Data that changes what is permissible, sgit use cases
- standards.sgit.ai (2): standards.sgit.ai — point at the provision, or you are asserting, standards.sgit.ai llms.txt
- teams.sgit.ai (1): Dpo
- ungovr.providers.sgit.ai (6): 00 — README: The Government Graph Pack, 01 — What Exists: The Assembly Inventory, 03 — The Worked Example: One County, One Law, One Acceptance, 04 — The Vault: Team, Viewers, Settings, Releases, 00 — Start Here: The Security-Standards Graph, 03 — The Standards Map
Grants and mandates
The grant is what an agent can actually reach; the mandate is what someone with authority allowed it to do; the delta between them is the excess authority nobody accepted. where it is defined
164 pages on 9 sites
- abp.sgit.ai (43): v0.2.0: A rule this site published in the morning was wrong by the afternoon, an, v0.1.0: The ontology already existed, so the first release promoted it instead o, v0.5.0: The releases get one article each, and the screenshots come from the tag, v0.7.0: The first case: one person's estate, the mandates elicited line by line,, v0.4.4: Seven deployment shapes somebody else measured, promoted with their prov, v0.4.3: The home page has argued about one setting since v0.1.0, and now the bui, v0.4.2: The fact diff was named as a blocker on four consecutive days, and it re, The data, The Delta Is Derived And Never Authored: Storing It Is The Point, And The Histor, Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know W, The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Se, The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, The Behaviour Policy Is Already A Fractal And The Overlay Is Already Published: , The Transition Demotes An Imperative To A Proposition: The Ontology Bounds The S, The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , What To Build, The ABP Model, The Prompt, A browser extension with broad host permissions, Chat in the browser, nothing connected, The same coding agent, confirmations off, A coding agent on your own machine, confirmations on, A CI job on a hosted runner, under a service account, Five worked examples, The measured deployment: what the agent that holds the connector found, Step 2: what you actually asked for, Step 3: write the behaviour policy, Agent Behaviour Policy, abp.sgit.ai llms.txt, The delta, The edge vocabulary, The graph, The model, The universes, U6: The derivation, U8: The licence, the acceptance and the risk, v0.1.0: the ontology is promoted out of a game and the five examples are derived, v0.11.0: the Gmail connector measured end to end by the agent that holds it, rea, v0.2.0: the delta is derived and never authored, so it is stored with its inputs, v0.4.4: seven shapes contributed by riskmandate.ai are promoted with their prove, v0.7.1: the first case gets its article, with six figures captured from the v0.7, What is an Agent Behaviour Policy
- elevenlabs.providers.sgit.ai (1): 01: What The Site Has Today, And What Is Missing
- games.sgit.ai (5): games.sgit.ai — a game makes you say what you think, before you are told, games.sgit.ai llms.txt, Grant vs. mandate, The method — four claims, The network
- pki.sgit.ai (2): pki.sgit.ai llms.txt, pki.sgit.ai llms.txt
- riskmandate.ai (72): RiskMandate — the behaviour-policy vault for A browser extension, RiskMandate — the behaviour-policy vault for ChatGPT in the browser, RiskMandate — the behaviour-policy vault for Claude Code, confirmations off, RiskMandate — the behaviour-policy vault for Claude Code on your machine, RiskMandate — the behaviour-policy vault for Claude Code on the web, RiskMandate — the behaviour-policy vault for Claude Desktop, RiskMandate — the behaviour-policy vault for Claude's Gmail connector, RiskMandate — the behaviour-policy vault for Microsoft 365 connector (Claude), RiskMandate — the behaviour-policy vault for Claude in the browser, connectors o, RiskMandate — the behaviour-policy vault for Dropbox MCP server, RiskMandate — the behaviour-policy vault for GitHub Actions, RiskMandate — the behaviour-policy vault for Gmail, read-only scope, RiskMandate — the behaviour-policy vault for Google Drive, read-only scope, RiskMandate — the behaviour-policy vault for Google Workspace MCP servers, RiskMandate — the behaviour-policy vault for n8n, owner API key, RiskMandate — the behaviour-policy vault for A scheduled job, RiskMandate — the Agent Behaviour Policy, The map, The Agent Behaviour Policy, condensed, Where we are, and what is next, riskmandate.ai — read this first, Vaults in vaults: the application vault is data, the renderer lives once, The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, The menu after the ABP turn: five entries, one product first, and eleven pages o, Nobody buys a policy until they have made a small one, so the next phase is user, A policy per use case, and the £500 level is a prompt the customer runs, LinkedIn company page — every field, ready to paste, The first measured behaviour policy: an owner API key on a self-hosted n8n, read, The vault pages, read against the vault: show the thing, and stop copying it, Startup Summit Lisbon 2026 — strategy, materials, and the build list, A behaviour policy for everybody the lead talks to, made by an agent from a zip, Buying a behaviour policy for Claude on one Gmail mailbox: the workflow, run onc, RiskMandate — after payment: a debrief for the store team, RiskMandate — an approval prompt is not a human in the loop, One agent, and every desk it reaches. How to read the risk propagation visualise, RiskMandate — in this session, the agent holds the union of everything it has ev, Who owns what in AI. And how accountability holds on the way up., Every Routable Address Is In The Grant: Do Not Attack Anyone Is The One Rule Eve, The Commit Author Is A Free Text Field: A Prompt Shifts The Odds, And Every Docu, The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The, The Urgency Is Not A Deadline But A State: You Already Connected It, And A Distr, The Offer Is Built And The Button Is Not: Each Level Is The Level Below Plus One, RiskMandate — Agent permission games, live, RiskMandate — Licence to Operate, live, RiskMandate — Know the risk. Name the owner. Own the mandate., What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandat, RiskMandate — the Lab, riskmandate.ai llms.txt, RiskMandate — thank you: level 1, what happens now, RiskMandate — thank you: level 3, what happens now, RiskMandate — thank you: level 4, what happens now, RiskMandate — Pricing: four levels, £10 to £1,500, RiskMandate — questions we were asked, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, AGENT BEHAVIOUR POLICY — Claude Code on the web, with one repository attached, DELTA — what it can do that you did not ask for, GRANT — everything the agent can do, LICENCE TO OPERATE — the organisation authorises the agent, under this behaviour, MANDATE — what the agent is authorised and expected to do, Claude Code on the web, with one repository attached — an Agent Behaviour Policy, MAP-A-GRANT.md — a prompt for an agent that holds a connector or a credential, RiskMandate — version record, 0.11.0.md, 0.11.2.md, 0.12.0.md, 0.12.2.md, 0.14.0.md, 1.13.0.md, 1.16.0.md, 1.17.0.md, 1.24.2.md, 1.26.0.md
- sgit.ai (18): Release history, Fractal Semantic Graphs, Two games about agent permissions (a published vault), The AIUC-1 conformance layer decks, How RiskMandate.ai's insurance model works with AIUC-1, AIUC-1 conformance layer, Published vaults, The Licence to Operate decks, The insurance model, Licence to Operate decks, The map (Licence to Operate decks), The problem (Licence to Operate decks), Licence to Operate (an insurance policy for an agent, simulated) a published vau, Seven shorts on the licence to operate, the author's walkthroughs, sgit.ai llms.txt, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Updates (sgit.ai)
- store.sgit.ai (17): Make a product page feel like a product page, A partner walked the whole store and wrote it up, You are a founder, What arrives, at every level, Tier 1 — Can I just have the pack?, Tier 4 — Can somebody go through it with my team?, Describe your agent, Agent Behaviour Policies for the agents you already run, Describe your agent — the canvas, Describe your agent — one at a time, index.md, Everything this store says, and how it knows, store.sgit.ai llms.txt, What lands, and when, You bought: Corrected for your situation, The product page — the next store, Who does the work
- ungovr.providers.sgit.ai (1): 05 — Integration
- what-can-it-do.games.sgit.ai (5): Licence to Operate — the delta, priced, what-can-it-do.games.sgit.ai llms.txt, Claude Code — web container, GitHub Actions — hosted runner, What to do next
Insurability
The argument that agents become insurable when someone can evidence what they can reach and what contains them, which is what a behaviour policy and a licence to operate produce. where it is defined
55 pages on 5 sites
- abp.sgit.ai (2): The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, The capability grammar
- riskmandate.ai (33): RiskMandate — the Agent Behaviour Policy, The Agent Behaviour Policy, condensed, riskmandate.ai — read this first, Direction change — the Agent Behaviour Policy becomes the primitive, The grant has storeys: what the credential permits, what the client exposes, wha, The menu after the ABP turn: five entries, one product first, and eleven pages o, How riskmandate.ai actually works, LinkedIn company page — every field, ready to paste, Lisbon messaging — we now have something to sell in the room, Startup Summit Lisbon 2026 — strategy, materials, and the build list, The memo queue, RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one, RiskMandate — the brief register, RiskMandate — Give feedback after a demo, RiskMandate — Know what your agents can do, Make your agents insurable, RiskMandate — can you insure a software program?, What buying a behaviour policy would look like — RiskMandate Lab 02, Licence to Operate, riskmandate.ai llms.txt, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, Synthetic users — five people who do not exist, reading this site, UK support, in the open, RiskMandate — version record, 0.12.0.md, 0.12.2.md, 1.12.0.md, 1.20.0.md, 1.20.2.md, 1.22.0.md, 1.25.4.md, 1.26.0.md, Brief B1 — power user and tester of Agent Behaviour Policies
- sgit.ai (16): Release history, Every risk is already accepted. The only question is by whom, and for how long., The proof is two clicks behind the claim, what the homepage gets wrong, and the , Provenance is not conformance, a published vault, AIUC-1, as a graph you can cite, a published vault, Published vaults, Licence to Operate (an insurance policy for an agent, simulated) a published vau, Seven shorts on the licence to operate, the author's walkthroughs, sgit.ai llms.txt, Risk Acceptance Office, a business plan with one risk replayed, published as a v, Synthetic users, second run, five people who do not exist, reading riskmandate.a, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Updates (sgit.ai)
- ungovr.providers.sgit.ai (3): 01 — What Exists: The Assembly Inventory, 03 — The Standards Map, 05 — Integration
- what-can-it-do.games.sgit.ai (1): The capabilities
Interview pages
A page sent to one person that carries a prompt they paste into a chat assistant, which interviews them by voice and writes up their feedback for them to send back. where it is defined
16 pages on 2 sites
- riskmandate.ai (11): The map, Workflows, The memo queue, RiskMandate — the brief register, RiskMandate — Half an hour of your advice, by voice, riskmandate.ai llms.txt, RiskMandate — version record, 0.12.2.md, 1.34.2.md, 1.34.3.md, 1.34.4.md
- sgit.ai (5): Release history, Cross-team briefs, For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it, sgit.ai llms.txt, sgit.ai llms.txt
Lessons learned
Rules recorded with the event that produced them, so each correction says what went wrong and how it was caught. where it is defined
22 pages on 7 sites
- elevenlabs.providers.sgit.ai (5): Brief — make narrated videos for elevenlabs.providers.sgit.ai, narrated by Eleve, 02: The Two Axes, The Audiences, The Page Contract, And Eleven Decisions, index.md, index.md, index.md
- influences.sgit.ai (1): OWASP & the security community
- providers.sgit.ai (1): index.md
- riskmandate.ai (1): Brief B1 — power user and tester of Agent Behaviour Policies
- sgit.ai (12): About the author, Dinis Cruz, Release history, The day we leaked our own vault key (sgit.ai case study), Published vaults, Vault App Mode, a published vault, Cross-team briefs, sgit.ai, for investors, published in the open, Lessons learned, the rules and the incidents behind them, sgit.ai llms.txt, How the site is run, the agentic team behind sgit.ai, Historian, an agentic role on sgit.ai, Updates (sgit.ai)
- teams.sgit.ai (1): teams.sgit.ai — roles are boundaries
- ungovr.providers.sgit.ai (1): index.md
Licence to operate
A self-issued, witnessed and dated licence in which the organisation is the authority, the behaviour policy the instrument and the agent the licensee: the step between describing an agent and insuring it. where it is defined
119 pages on 8 sites
- abp.sgit.ai (11): The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has , The Delta Is Derived And Never Authored: Storing It Is The Point, And The Histor, The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Se, The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Start Here, The Hard Rules, The delta, U11: The runtime, U5: The deployer, v0.8.0: the cost ABP: a walkthrough over how much an agent may spend rather than
- games.sgit.ai (3): The catalogue, games.sgit.ai llms.txt, Grant vs. mandate
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- riskmandate.ai (61): RiskMandate — the behaviour-policy vault for A browser extension, RiskMandate — the behaviour-policy vault for ChatGPT in the browser, RiskMandate — the behaviour-policy vault for Claude Code, confirmations off, RiskMandate — the behaviour-policy vault for Claude Code on your machine, RiskMandate — the behaviour-policy vault for Claude Code on the web, RiskMandate — the behaviour-policy vault for Claude Desktop, RiskMandate — the behaviour-policy vault for Claude's Gmail connector, RiskMandate — the behaviour-policy vault for Microsoft 365 connector (Claude), RiskMandate — the behaviour-policy vault for Claude in the browser, connectors o, RiskMandate — the behaviour-policy vault for Dropbox MCP server, RiskMandate — the behaviour-policy vault for GitHub Actions, RiskMandate — the behaviour-policy vault for Gmail, read-only scope, RiskMandate — the behaviour-policy vault for Google Drive, read-only scope, RiskMandate — the behaviour-policy vault for Google Workspace MCP servers, RiskMandate — the behaviour-policy vault for n8n, owner API key, RiskMandate — the behaviour-policy vault for A scheduled job, RiskMandate — the Agent Behaviour Policy, The Agent Behaviour Policy, condensed, Where we are, and what is next, riskmandate.ai — read this first, Direction change — the Agent Behaviour Policy becomes the primitive, A grant is a union of capabilities; what the reader needs is the consequences — , The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, The grant has storeys: what the credential permits, what the client exposes, wha, The menu after the ABP turn: five entries, one product first, and eleven pages o, Briefs written here, LinkedIn company page — every field, ready to paste, The Design Studio MVPs, read against the workflow that sells a behaviour policy, The vault pages, read against the vault: show the thing, and stop copying it, Lisbon messaging — we now have something to sell in the room, Startup Summit Lisbon 2026 — strategy, materials, and the build list, The console, The memo queue, The board, The pilot worked. Then somebody asked what else it could do., RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one, The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The, The Offer Is Built And The Button Is Not: Each Level Is The Level Below Plus One, RiskMandate — the brief register, RiskMandate — business cases, by the risk they change, RiskMandate — Licence to Operate, live, RiskMandate — Know what your agents can do, Make your agents insurable, RiskMandate — can you insure a software program?, RiskMandate — Half an hour of your advice, by voice, What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandat, RiskMandate — the Lab, Licence to Operate, riskmandate.ai llms.txt, RiskMandate — questions we were asked, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, LICENCE TO OPERATE — the organisation authorises the agent, under this behaviour, 0.14.0.md, 1.2.0.md, 1.20.0.md, 1.20.1.md, 1.22.0.md, 1.25.0.md, 1.26.0.md, 1.32.1.md, Working with us — briefs for collaborators and their agents
- sgit.ai (27): Release history, Before you give an agent a connector, give the connector a twin, Fractal Semantic Graphs, Provenance is not conformance, a published vault, Published vaults, Who says yes, Licence to Operate decks, Bounding it, Licence to Operate decks, The Licence to Operate decks, The insurance model, Licence to Operate decks, The map (Licence to Operate decks), The problem (Licence to Operate decks), Licence to Operate (an insurance policy for an agent, simulated) a published vau, Seven shorts on the licence to operate, the author's walkthroughs, sgit.ai llms.txt, Synthetic users, second run, five people who do not exist, reading riskmandate.a, For graphs.sgit.ai: Fractal Semantic Graphs, and what to change, For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, Reading one file out of a vault, SG/Vault, sgit.ai llms.txt, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Corporate users, services available now, Founders, open source technology that works today, Investors (how does your firm share data with its portfolio?), The board, open work on sgit.ai, as a kanban of files, Journalist, an agentic role on sgit.ai, Updates (sgit.ai)
- store.sgit.ai (10): The homepage concepts, reviewed, Design brief — store.sgit.ai, A partner walked the whole store and wrote it up, The work, You are a founder, index.md, Everything this store says, and how it knows, store.sgit.ai llms.txt, index.md, Dinis Cruz
- ungovr.providers.sgit.ai (4): 00 — Start Here: The Security-Standards Graph, 05 — Integration, The Security-Standards Graph — a dev pack, index.md
- what-can-it-do.games.sgit.ai (2): Licence to Operate — the delta, priced, what-can-it-do.games.sgit.ai llms.txt
Open source
Open source treated as a strategy rather than a charity: the network publishes its code under Apache-2.0 and argues that the technology was never the moat. where it is defined
94 pages on 15 sites
- abp.sgit.ai (1): No Gmail Scope Lets An Agent Draft Without Letting It Send: The Drafts Have To L
- coding.sgit.ai (2): coding.sgit.ai — the style guide that measured itself, coding.sgit.ai llms.txt
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- issues-fs.sgit.ai (2): issues-fs.sgit.ai — the issues are files and the files are a graph, issues-fs.sgit.ai llms.txt
- llms.sgit.ai (8): Participant disclosure, and where we lose, 07 — Boundaries and licensing, Licence, The code samples, Boundaries And Licensing, The documents, The Pack Licence, llms.sgit.ai llms.txt
- newsroom.sgit.ai (1): newsroom.sgit.ai llms.txt
- open-source.sgit.ai (18): Dinis Cruz, Comms: tasks & requests, Release history, 00 — The Brief: open-source.sgit.ai, 01 — Concepts Index, 02 — How he actually uses open source, 07 — Site architecture, licensing and boundaries, 08 — Gaps, open questions and honest tensions, Licence, open-source.sgit.ai — brief pack, The History of Open Source and Its Major Success Stories, Owning the code, or opening it, Open source is a strategy. It is not a charity., open-source.sgit.ai llms.txt, Why Apache-2.0 rather than MIT, Three licences, three layers, and one nobody had noticed, Publish the source next to the render, We run the test on our own estate
- riskmandate.ai (18): The memo queue, RiskMandate — the brief register, RiskMandate — the business case for agentgateway, RiskMandate — the business case for Cedar, RiskMandate — the business case for Cilium network policy, RiskMandate — the business case for Falco, RiskMandate — the business case for gVisor, RiskMandate — the business case for Keycloak, RiskMandate — the business case for Open Policy Agent, RiskMandate — the business case for OpenFGA, RiskMandate — the business case for OWASP Coraza, RiskMandate — the business case for OWASP Threat Dragon and pytm, RiskMandate — the business case for Unleash, RiskMandate — the business case for Velero, RiskMandate — Dinis Cruz, who runs the review, RiskMandate — version record, 1.16.0.md, 1.34.0.md
- risks.sgit.ai (1): risks.sgit.ai llms.txt
- sg-compute.sgit.ai (2): sg-compute.sgit.ai — ephemeral environments in AWS, one command away, sg-compute.sgit.ai llms.txt
- sgit.ai (35): About the author, Dinis Cruz, Release history, Articles, For a startup, the most important question is whether they miss it, Git for things you cannot put on GitHub, The same pack, written for an archetype instead of a company, fractional CISO pa, An application for a job, as a vault, interim CISO pack, VoiceDebrief, a published vault, What is sgit, Docs, sgit (the encrypted git for humans and AI agents), sgit.ai, for investors, published in the open, sgit.ai llms.txt, The sgit.ai network, sibling sites, Models do the work, vaults hold it: proposed partnerships with the AI providers, A proposed partnership between sgit.ai and Anthropic, A proposed partnership between sgit.ai and AWS, A proposed partnership between sgit.ai and Microsoft Azure, sgit runs on every cloud: proposed partnerships with the cloud platforms, A proposed partnership between sgit.ai and DigitalOcean, A proposed partnership between sgit.ai and ElevenLabs, A proposed partnership between sgit.ai and the European clouds, A proposed partnership between sgit.ai and Google Cloud, A proposed partnership between sgit.ai and Google Gemini, A proposed partnership between sgit.ai and IBM Cloud, A proposed partnership between sgit.ai and Mistral AI, A proposed partnership between sgit.ai and Netlify, A proposed partnership between sgit.ai and OpenAI, A proposed partnership between sgit.ai and OpenRouter, A proposed partnership between sgit.ai and Rackspace Technology, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Who holds the keys? A call for collaboration on vault key management, Security model, sgit, Build your startup on sgit vaults, The board, open work on sgit.ai, as a kanban of files, Why does this exist?
- skills.sgit.ai (1): skills.sgit.ai llms.txt
- store.sgit.ai (2): Dinis Cruz, Who does the work
- twins.sgit.ai (1): twins.sgit.ai llms.txt
- ungovr.providers.sgit.ai (1): index.md
Partnerships
Proposals for work with named organisations, written from public material only so each page can be forwarded, stating the fit, where it is partial and a first piece of work; none records a conversation yet. where it is defined
29 pages on 2 sites
- riskmandate.ai (2): RiskMandate — the brief register, 1.32.2.md
- sgit.ai (27): About the author, Dinis Cruz, Release history, Before you give an agent a connector, give the connector a twin, Lesson Loop, a business plan for coaches with one player's record, published as , Cross-team briefs, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit.ai llms.txt, sgit.ai llms.txt, Models do the work, vaults hold it: proposed partnerships with the AI providers, A proposed partnership between sgit.ai and Anthropic, A proposed partnership between sgit.ai and AWS, A proposed partnership between sgit.ai and Microsoft Azure, sgit runs on every cloud: proposed partnerships with the cloud platforms, A proposed partnership between sgit.ai and DigitalOcean, A proposed partnership between sgit.ai and ElevenLabs, A proposed partnership between sgit.ai and the European clouds, A proposed partnership between sgit.ai and Google Cloud, A proposed partnership between sgit.ai and Google Gemini, A proposed partnership between sgit.ai and IBM Cloud, Partnerships, argued in the open, A proposed partnership between sgit.ai and Mistral AI, A proposed partnership between sgit.ai and Netlify, A proposed partnership between sgit.ai and OpenAI, A proposed partnership between sgit.ai and OpenRouter, A proposed partnership between sgit.ai and Rackspace Technology, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Who holds the keys? A call for collaboration on vault key management
Performance and cost
The measured speed and running cost of reading vaults and fractal graphs straight from object storage, with no live database and nothing running between questions. where it is defined
PKI
Public key infrastructure for vaults and agents: keypairs from the CLI for encryption and signing, sealing messages to a recipient, and the registry rules pki.sgit.ai draws from the history of key servers. where it is defined
50 pages on 10 sites
- games.sgit.ai (2): Admin & engineering, What our games send
- llms.sgit.ai (4): How this site is built · llms.sgit.ai, 07 — Boundaries and licensing, Licence, The network, and what this site does not own
- nfrs.sgit.ai (1): nfrs.sgit.ai llms.txt
- nhi.sgit.ai (3): Shared Drives For Agents: Everything Available Runs On Your Identity, Granularit, pki.sgit.ai: The Public Key Registry Has A Documented Failure To Learn From, And, nhi.sgit.ai llms.txt
- open-source.sgit.ai (1): 07 — Site architecture, licensing and boundaries
- pki.sgit.ai (4): pki.sgit.ai: The Public Key Registry Has A Documented Failure To Learn From, And, pki.sgit.ai llms.txt, pki.sgit.ai llms.txt, pki.sgit.ai llms.txt
- riskmandate.ai (4): riskmandate.ai llms.txt, RiskMandate — RAMM, the Risk Acceptance Maturity Model, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, 0.5.0.md
- sgit.ai (24): Release history, API: append lanes (sgit.ai), The HTTP API, API: vault objects, Two games about agent permissions (a published vault), Provenance is not conformance, a published vault, Cross-team briefs, Telemetry from a published vault, a build brief, Vault credentials: what each one can do, and what its prefix declares, Documentation, sgit, When NOT to use sgit, Docs, sgit.ai llms.txt, Keys, signatures and encrypting to someone else, Sending messages between vaults, sgit.ai llms.txt, The sgit.ai network, sibling sites, pki.sgit.ai, A key registry for agents, designed from a documented failure, sg-sentinel.sgit.ai, An app-coupled edge guard, Layer 1 decides, Layer 2 acts, Security model, sgit, Skills for AI agents, sgit, SKILL: sgit — Zero-Knowledge Encrypted Vault Operations, Updates (sgit.ai), Use cases, sgit, Why does this exist?
- twins.sgit.ai (1): twins.sgit.ai llms.txt
- wardley-maps.sgit.ai (6): 00 — The Brief: wardley-maps.sgit.ai, wardley-maps.sgit.ai — brief pack, 04 — Job B: the industry resources, and how to build a page for each, 06 — Site Architecture, 07 — Boundaries, licensing and house style, 08 — Gaps, open questions and honest tensions
Pricing ladders
Four levels where each is the level below plus exactly one thing, from a downloaded pack to a signed review, sold through standing payment links; RiskMandate's ladder is reused by other plans. where it is defined
110 pages on 4 sites
- elevenlabs.providers.sgit.ai (2): index.md, index.md
- riskmandate.ai (59): RiskMandate — the reviewed level: two sessions, and a professional signs it, RiskMandate — the behaviour-policy vault for A browser extension, RiskMandate — the behaviour-policy vault for ChatGPT in the browser, RiskMandate — the behaviour-policy vault for Claude Code, confirmations off, RiskMandate — the behaviour-policy vault for Claude Code on your machine, RiskMandate — the behaviour-policy vault for Claude Code on the web, RiskMandate — the behaviour-policy vault for Claude Desktop, RiskMandate — the behaviour-policy vault for Claude's Gmail connector, RiskMandate — the behaviour-policy vault for Microsoft 365 connector (Claude), RiskMandate — the behaviour-policy vault for Claude in the browser, connectors o, RiskMandate — the behaviour-policy vault for Dropbox MCP server, RiskMandate — the behaviour-policy vault for GitHub Actions, RiskMandate — the behaviour-policy vault for Gmail, read-only scope, RiskMandate — the behaviour-policy vault for Google Drive, read-only scope, RiskMandate — the behaviour-policy vault for Google Workspace MCP servers, RiskMandate — the behaviour-policy vault for n8n, owner API key, RiskMandate — the behaviour-policy vault for A scheduled job, The map, Where we are, and what is next, Workflows, The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, Nobody buys a policy until they have made a small one, so the next phase is user, A policy per use case, and the £500 level is a prompt the customer runs, Briefs written here, Five synthetic users read the new home page: the word is fixed, the vocabulary i, Buying a behaviour policy for Claude on one Gmail mailbox: the workflow, run onc, The memo queue, RiskMandate — after payment: a debrief for the store team, RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one, Every Routable Address Is In The Grant: Do Not Attack Anyone Is The One Rule Eve, The Offer Is Built And The Button Is Not: Each Level Is The Level Below Plus One, RiskMandate — the brief register, You run agents today, You are a founder, You are a startup, RiskMandate — Know what your agents can do, RiskMandate — can you insure a software program?, RiskMandate — Half an hour of your advice, by voice, RiskMandate — Lab 04 · the shape collector, Licence to Operate, riskmandate.ai llms.txt, RiskMandate — Pricing: four levels, £10 to £1,500, RiskMandate — questions we were asked, RiskMandate — CISO XYZ: the shape of a reviewer page, RiskMandate — who runs your review, Synthetic users — five people who do not exist, reading this site, RiskMandate — try it: write a behaviour policy for your own agent in twenty minu, UK support, in the open, RiskMandate — version record, 0.6.0 — Pages-only nav, a Pricing page, and RAMM, 0.9.1.md, 1.19.0.md, 1.19.1.md, 1.20.1.md, 1.22.0.md, 1.25.2.md, 1.29.0.md, 1.34.7.md, 1.7.0.md
- sgit.ai (7): Release history, Provenance is not conformance, a published vault, Company X-Ray, a business plan with one company X-rayed, published as a vault, Synthetic users, second run, five people who do not exist, reading riskmandate.a, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit.ai llms.txt, Business plans to build on sgit
- store.sgit.ai (42): The homepage concepts, reviewed, Design brief — store.sgit.ai, Stripe end to end, with their SKUs — and a customer even at 100% off, £10, a commercial licence, and a name on the review, One table, five columns, and the free one first, The homepage sells — and the work has been done before, The memo queue, /next/ — the next store, Stripe, A partner walked the whole store and wrote it up, Five readers walked the new store from the front page to the till. Four of them , What happened to each memo, index.md, The work, Take money at all, The comparison table, Who runs the review, You have to answer for it, You are a founder, You own the register, You are backing a company, You do this for a living, Who is this for?, index.md, Your order, Tier 4 — Can somebody go through it with my team?, You are backing a company, and want somebody to look, You are a startup, and diligence is coming, Agent Behaviour Policies for the agents you already run, Everything this store says, and how it knows, store.sgit.ai llms.txt, Gmail, read-only scope, Something not on this list, You bought: Two sessions and a custom vault, index.md, Which agent do you run?, The product page — the next store, Your order, index.md, index.md, Dinis Cruz, Who does the work
Provenance
The visible record on each page of where its material came from: original date, link, authors including any AI co-authorship, and how it was curated. where it is defined
18 pages on 6 sites
- abp.sgit.ai (8): v0.1.0: The ontology already existed, so the first release promoted it instead o, v0.4.4: Seven deployment shapes somebody else measured, promoted with their prov, The data, The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , The schema, U0: The source bytes, v0.4.4: seven shapes contributed by riskmandate.ai are promoted with their prove
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- newsroom.sgit.ai (1): newsroom.sgit.ai llms.txt
- pt.newsroom.sgit.ai (1): pt.newsroom.sgit.ai llms.txt
- sgit.ai (4): Fractal Semantic Graphs: everything connects to everything, and nobody has to sh, Fractal Semantic Graphs, Regulation Graph, a published vault, Standards Atlas: GDPR, a published vault
- ungovr.providers.sgit.ai (3): Start Here: The UnGovr Vault MVP And Its Provider Site, 01 — What Exists: The Assembly Inventory, 06 — Verification: Acceptance Tests, Claim States, Blockers
Read keys
A key derived one way from the vault key that can read a vault and never write to it; a site publishes one on purpose, with the public-read prefix, when it wants anyone to open the vault. where it is defined
268 pages on 15 sites
- abp.sgit.ai (6): Case session-001: The session that built this site's last twelve releases, as a , The Split Does Not Break The Trifecta, The Schema Does: A Closed Vocabulary At T, Docs, The Conventions, The measured deployment: what the agent that holds the connector found, v0.11.0: the Gmail connector measured end to end by the agent that holds it, rea
- elevenlabs.providers.sgit.ai (2): index.md, index.md
- games.sgit.ai (8): Admin & engineering, Building a game as a vault, The catalogue, What Can It Do? — the scoreboard, Which Agent Is It? — the floor plan, games.sgit.ai — a game makes you say what you think, before you are told, games.sgit.ai llms.txt, What our games send
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- llms.sgit.ai (12): Participant disclosure, and where we lose, Comms: tasks & requests, 03 — The security model, and the gap in it, 04 — Websites vs vaults: what changes when there is no host, 06 — Site Architecture, 07 — Boundaries and licensing, 08 — Gaps, open questions and honest tensions, Licence, Adding an LLM chat pane, The security model, and the gap in it, What is shipped, and what is not, Websites vs vaults
- nhi.sgit.ai (1): nhi.sgit.ai llms.txt
- open-source.sgit.ai (5): 01 — Concepts Index, 02 — How he actually uses open source, 07 — Site architecture, licensing and boundaries, The documents, Publish the source next to the render
- riskmandate.ai (74): RiskMandate — the reviewed level: two sessions, and a professional signs it, RiskMandate — the behaviour-policy vault for A browser extension, RiskMandate — the behaviour-policy vault for ChatGPT in the browser, RiskMandate — the behaviour-policy vault for Claude Code, confirmations off, RiskMandate — the behaviour-policy vault for Claude Code on your machine, RiskMandate — the behaviour-policy vault for Claude Code on the web, RiskMandate — the behaviour-policy vault for Claude Desktop, RiskMandate — the behaviour-policy vault for Claude's Gmail connector, RiskMandate — the behaviour-policy vault for Microsoft 365 connector (Claude), RiskMandate — the behaviour-policy vault for Claude in the browser, connectors o, RiskMandate — the behaviour-policy vault for Dropbox MCP server, RiskMandate — the behaviour-policy vault for GitHub Actions, RiskMandate — the behaviour-policy vault for Gmail, read-only scope, RiskMandate — the behaviour-policy vault for Google Drive, read-only scope, RiskMandate — the behaviour-policy vault for Google Workspace MCP servers, RiskMandate — the behaviour-policy vault for n8n, owner API key, RiskMandate — the behaviour-policy vault for A scheduled job, The map, The Agent Behaviour Policy, condensed, Workflows, riskmandate.ai — read this first, Architecture Brief — Decoupling site structure from content, Vaults in vaults: the application vault is data, the renderer lives once, The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, How riskmandate.ai actually works, Implementation Brief — Scenarios pilot (first decoupled content area), LinkedIn company page — every field, ready to paste, Five synthetic users read the new home page: the word is fixed, the vocabulary i, Startup Summit Lisbon 2026 — strategy, materials, and the build list, A behaviour policy for everybody the lead talks to, made by an agent from a zip, Buying a behaviour policy for Claude on one Gmail mailbox: the workflow, run onc, The console, The memo queue, The records, Tooling and the gate, The vaults, RiskMandate — after payment: a debrief for the store team, RiskMandate — Agent Behaviour Policies, one vault per application, RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one, The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The, The Urgency Is Not A Deadline But A State: You Already Connected It, And A Distr, The Offer Is Built And The Button Is Not: Each Level Is The Level Below Plus One, RiskMandate — the brief register, Where this model comes from, RiskMandate — Know what your agents can do, RiskMandate — can you insure a software program?, What buying a behaviour policy would look like — RiskMandate Lab 02, Changes we are asking of the behaviour-policy site — RiskMandate Lab 03, RiskMandate — Lab 04 · the shape collector, What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandat, RiskMandate — the Lab, riskmandate.ai llms.txt, RiskMandate — thank you: level 2, what happens now, RiskMandate — thank you: level 3, what happens now, RiskMandate — thank you: level 4, what happens now, RiskMandate — Pricing: four levels, £10 to £1,500, RiskMandate — privacy: what this site collects, and how to check, RiskMandate — Dinis Cruz, who runs the review, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, Synthetic users — five people who do not exist, reading this site, RiskMandate — try it: write a behaviour policy for your own agent in twenty minu, UK support, in the open, 0.11.1.md, 0.11.2.md, 0.14.0.md, 1.0.0.md, 1.13.0.md, 1.15.0.md, 1.2.0.md, 1.22.0.md, 1.23.0.md, 1.24.0.md, Brief B1 — power user and tester of Agent Behaviour Policies, Working with us — briefs for collaborators and their agents
- risks.sgit.ai (3): risks.sgit.ai — Brief Pack, risks.sgit.ai — you cannot deny a risk, only say how long you accept it, risks.sgit.ai llms.txt
- sgit.ai (126): About the author, Dinis Cruz, Plan: the Why reframe, three end-to-end demo vaults, and the component registry, Release history, API: append lanes (sgit.ai), API authentication, API: transfers, one encrypted handover, one link, API: vault objects, Before you give an agent a connector, give the connector a twin, Every risk is already accepted. The only question is by whom, and for how long., The future of news is the story vault, not the paywall, Fractal Semantic Graphs: everything connects to everything, and nobody has to sh, The proof is two clicks behind the claim, what the homepage gets wrong, and the , Seven vaults, one method, For a startup, the most important question is whether they miss it, Git for things you cannot put on GitHub, A live site whose host cannot read it, sgit.ai case study, One working tree, two version control systems, and why we stopped, sgit.ai case , The vault catalogue, Comparisons, as tests you can re-run, Fractal Semantic Graphs, Performance, cost, and running everywhere, Fractal Semantic Graphs, Demos, sgit, on a Wardley Map (sgit.ai demos), The Strategy in Seven Maps, a real document republished from a vault, sgit.ai de, A vault app, live inside this page, sgit.ai demos, Two games about agent permissions (a published vault), Agent as Webmaster, a business plan published as a vault, Agentic Browser Isolation, a published vault, What AIUC-1 is, AIUC-1 conformance layer decks, Zoom in: D003 (one control, to the byte, measured, and run) AIUC-1 conformance l, The AIUC-1 conformance layer decks, How RiskMandate.ai's insurance model works with AIUC-1, AIUC-1 conformance layer, The vault: files, graphs, and the query (AIUC-1 conformance layer decks), Provenance is not conformance, a published vault, AIUC-1, as a graph you can cite, a published vault, Algarve · May 2026, a published vault, AI vs. AI, Black Hat Europe 2025, a published vault, The sgit.ai board, a published vault, The Vault Catalogue (a published vault), SG Commercialisation, a published vault, Company X-Ray, a business plan with one company X-rayed, published as a vault, Connector Twin, a business plan with a working replay, published as a vault, Content-Transformation Proxy, a published vault, Deploy Docs, a published vault, Start with an AI decision, then trace it back to the guidance: the DSIT AI Risk , Field Notes, a published vault, The same pack, written for an archetype instead of a company, fractional CISO pa, Private Health Score, a published vault, Published vaults, An application for a job, as a vault, interim CISO pack, Lesson Loop, a business plan for coaches with one player's record, published as , Who says yes, Licence to Operate decks, Bounding it, Licence to Operate decks, The Licence to Operate decks, The insurance model, Licence to Operate decks, The map (Licence to Operate decks), The problem (Licence to Operate decks), Licence to Operate (an insurance policy for an agent, simulated) a published vau, Seven shorts on the licence to operate, the author's walkthroughs, sgit.ai llms.txt, SG/Payments Brief Pack, a published vault, Penetration Test Report, a published vault, Publishing a vault: the method, Regulation Graph, a published vault, Risk Acceptance Office, a business plan with one risk replayed, published as a v, Risk Graph Explorer, a published vault, The author’s walkthroughs, Risk Graph Explorer, The seven views, explained (Risk Graph Explorer), Risk Mandate, a published vault, RiskMandate: File security, a published vault, Standards Atlas: GDPR, a published vault, Strategy Maps (a published vault), Supplement Stack, a published vault, Synthetic users, second run, five people who do not exist, reading riskmandate.a, Synthetic users, five people who do not exist, shopping, Scaling Threat Modeling with Semantic Knowledge Graphs, a published vault, Vault App Mode, a published vault, VoiceDebrief, a published vault, A three-minute pitch, delivered from a vault, a published vault, Briefing: embedding the Vault App iframe inside sgit.ai pages, reusing your code, For graphs.sgit.ai: Fractal Semantic Graphs, and what to change, Cross-team briefs, Markdown and file viewers in a vault: what not to build (build brief), For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, Reading a vault from a .sgit.ai site page, build brief, Publishing a vault’s decks onto a website, build brief, An infographic of the published vaults, build brief, Telemetry from a published vault, a build brief, Vault credentials: what each one can do, and what its prefix declares, Working on a vault: start here, guidance, sgit.ai llms.txt, Documentation, sgit, sgit.ai llms.txt, Three surfaces: which one are you building for?, sgit.ai llms.txt, Reading one file out of a vault, SG/Vault, Sub-vaults, SG/Vault, sgit (the encrypted git for humans and AI agents), sgit.ai, for investors, published in the open, Lessons learned, the rules and the incidents behind them, sgit.ai llms.txt, nhi.sgit.ai, Agents you run, agents you rent, and the identity gap, Models do the work, vaults hold it: proposed partnerships with the AI providers, sgit runs on every cloud: proposed partnerships with the cloud platforms, Partnerships, argued in the open, A proposed partnership between sgit.ai and Netlify, A proposed partnership between sgit.ai and OpenAI, A proposed partnership between sgit.ai, RiskMandate.ai and UK Sovereign AI, Who holds the keys? A call for collaboration on vault key management, Security model, sgit, SKILL: sgit — Zero-Knowledge Encrypted Vault Operations, Business plans to build on sgit, Build your startup on sgit vaults, The board, open work on sgit.ai, as a kanban of files, How the site is run, the agentic team behind sgit.ai, Starting prompts for the regular work (sgit.ai team), Auditor, an agentic role on sgit.ai, Publisher, an agentic role on sgit.ai, Updates (sgit.ai), Agent state that isn't the vendor's to read, sgit use cases, Data that changes what is permissible, sgit use cases, Use cases, sgit, Working documents with clients, sgit use cases, Findings about your own weaknesses, sgit use cases, The serialised pull request, sgit use cases, Why does this exist?
- standards.sgit.ai (2): standards.sgit.ai — point at the provision, or you are asserting, standards.sgit.ai llms.txt
- store.sgit.ai (18): Design brief — store.sgit.ai, Never leave the site — and write down who owns what, The homepage sells — and the work has been done before, Stripe, A partner walked the whole store and wrote it up, Describe your agent, The work, What arrives, at every level, Tier 1 — Can I just have the pack?, Tier 2 — Can I have a vault I hold the keys to?, index.md, Everything this store says, and how it knows, Gmail, read-only scope, The product page — the next store, index.md, index.md, index.md, index.md
- ungovr.providers.sgit.ai (5): Start Here: The UnGovr Vault MVP And Its Provider Site, 04 — The Vault: Team, Viewers, Settings, Releases, index.md, index.md, 04 — The Worked Example
- wardley-maps.sgit.ai (3): 01 — Concepts Index, 06 — Site Architecture, Licence
- what-can-it-do.games.sgit.ai (2): How this site is built, Contribute
Risk acceptance
A risk exists as soon as the exposure does, so the question is who has accepted it and until when: there is no deny button, only accept for a stated interval, fund the work, or fix it. where it is defined
56 pages on 8 sites
- abp.sgit.ai (4): The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , The ABP Model, U8: The licence, the acceptance and the risk
- games.sgit.ai (3): games.sgit.ai llms.txt, Grant vs. mandate, The network
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- pki.sgit.ai (1): pki.sgit.ai llms.txt
- riskmandate.ai (22): RiskMandate — Accepted is not acceptable, Risk Mandate — agents act, and someone has to own the risk, The Agent Behaviour Policy, condensed, Direction change — the Agent Behaviour Policy becomes the primitive, The menu after the ABP turn: five entries, one product first, and eleven pages o, LinkedIn company page — every field, ready to paste, Startup Summit Lisbon 2026 — strategy, materials, and the build list, Who owns what in AI. And how accountability holds on the way up., RiskMandate — the brief register, Make your agents insurable, riskmandate.ai llms.txt, RiskMandate — Who can pull the plug?, RiskMandate — RAMM, the Risk Acceptance Maturity Model, RiskMandate at Startup Summit Lisbon, 17–18 September 2026, RiskMandate — version record, 0.1.0.md, 0.10.0.md, 0.10.1.md, 0.4.3.md, 0.5.0.md, 0.6.0 — Pages-only nav, a Pricing page, and RAMM, 0.9.2.md
- risks.sgit.ai (3): risks.sgit.ai — Brief Pack, risks.sgit.ai — you cannot deny a risk, only say how long you accept it, risks.sgit.ai llms.txt
- sgit.ai (21): Release history, Every risk is already accepted. The only question is by whom, and for how long., Articles, Fractal Semantic Graphs, Agentic Browser Isolation, a published vault, Company X-Ray, a business plan with one company X-rayed, published as a vault, Published vaults, Who says yes, Licence to Operate decks, The Licence to Operate decks, Seven shorts on the licence to operate, the author's walkthroughs, sgit.ai llms.txt, Risk Acceptance Office, a business plan with one risk replayed, published as a v, The seven views, explained (Risk Graph Explorer), RiskMandate: File security, a published vault, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, The sgit.ai network, sibling sites, Business plans to build on sgit, Build your startup on sgit vaults, Startups. It is open source, and it is built to be built on, Updates (sgit.ai)
- what-can-it-do.games.sgit.ai (1): What to do next
Security audits
Checks published beside the work: every vault audited from a read-key clone before its key is published, and reviews whose findings are stated even when they did not survive checking. where it is defined
64 pages on 10 sites
- abp.sgit.ai (31): Case beta-001: ChatGPT with the Google Calendar connector, allow all, Case beta-001: ChatGPT with the Google Drive connector, allow all, Case beta-001: ChatGPT with the Gmail connector, allow all, Case beta-001: ChatGPT with a meeting note taker connected, Case beta-001: The inbox scout: the same Gmail grant, running with nobody presen, Case beta-001: Claude with the Slack connector, Case beta-001: One person, two assistants, six deployments, one shared account, Case estate-002: Claude Code, in a container with a repository attached, Case estate-002: Claude Cowork, on the desktop, Case estate-002: Claude in the browser, with connectors possibly still on, Case estate-002: One person, three surfaces of one product, one account holding , Cases, Case session-001: Claude Code on the web, one repository attached: the session t, Case session-001: The session that built this site's last twelve releases, as a , The cost ABP: how much, not just what, Step 4: what a clause over a count cannot do, An assistant on your own machine, Step 4: what a switch is, and is not, Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know W, The Split Does Not Break The Trifecta, The Schema Does: A Closed Vocabulary At T, The Hard Rules, A browser extension with broad host permissions, Chat in the browser, nothing connected, The same coding agent, confirmations off, A coding agent on your own machine, confirmations on, A CI job on a hosted runner, under a service account, Five worked examples, Your mailbox, and what you gave it, The measured deployment: what the agent that holds the connector found, Agent Behaviour Policy, What is an Agent Behaviour Policy
- open-source.sgit.ai (10): 00 — The Brief: open-source.sgit.ai, 02 — How he actually uses open source, 03 — The history, and how to use it, 08 — Gaps, open questions and honest tensions, The History of Open Source and Its Major Success Stories, Owning the code, or opening it, Six corrections, Open source is a strategy. It is not a charity., Publish the source next to the render, We run the test on our own estate
- riskmandate.ai (9): LinkedIn company page — every field, ready to paste, The Design Studio MVPs, read against the workflow that sells a behaviour policy, Lisbon messaging — we now have something to sell in the room, Startup Summit Lisbon 2026 — strategy, materials, and the build list, RiskMandate — Know the risk. Name the owner. Own the mandate., RiskMandate — How it works: from a prompt to a graph with provenance, RiskMandate — Half an hour of your advice, by voice, RiskMandate — questions we were asked, Claude Code on the web, with one repository attached — an Agent Behaviour Policy
- sgit.ai (6): Release history, Lessons learned, the rules and the incidents behind them, sgit.ai llms.txt, Who holds the keys? A call for collaboration on vault key management, Security model, sgit, Investors (how does your firm share data with its portfolio?)
- skills.sgit.ai (1): skills.sgit.ai llms.txt
- standards.sgit.ai (1): standards.sgit.ai llms.txt
- store.sgit.ai (3): £10, a commercial licence, and a name on the review, The work, Who runs the review
- teams.sgit.ai (1): Conductor
- threat-modeling.sgit.ai (1): threat-modeling.sgit.ai — a threat model is a claim you can check
- what-can-it-do.games.sgit.ai (1): About the game
Startups
sgit.ai's operating model for founders: ship something usable, give it away briefly, take it away and see whether anybody misses it; be profitable before raising; open source everything. where it is defined
20 pages on 3 sites
- riskmandate.ai (1): UK support, in the open
- sgit.ai (16): About the author, Dinis Cruz, Release history, Before you give an agent a connector, give the connector a twin, Every risk is already accepted. The only question is by whom, and for how long., Articles, For a startup, the most important question is whether they miss it, Agent as Webmaster, a business plan published as a vault, Company X-Ray, a business plan with one company X-rayed, published as a vault, Connector Twin, a business plan with a working replay, published as a vault, Lesson Loop, a business plan for coaches with one player's record, published as , Risk Acceptance Office, a business plan with one risk replayed, published as a v, sgit.ai llms.txt, A proposed partnership between sgit.ai and AWS, A proposed partnership between sgit.ai and OpenAI, Business plans to build on sgit, Build your startup on sgit vaults
- store.sgit.ai (3): index.md, store.sgit.ai llms.txt, index.md
Synthetic users
Invented readers walked through a site one screenshot at a time and interviewed at the end, to find where real readers would get lost. where it is defined
19 pages on 3 sites
- riskmandate.ai (9): The menu after the ABP turn: five entries, one product first, and eleven pages o, Briefs written here, Five synthetic users read the new home page: the word is fixed, the vocabulary i, The records, riskmandate.ai llms.txt, Synthetic users — five people who do not exist, reading this site, RiskMandate — version record, 1.21.0.md, 1.25.2.md
- sgit.ai (7): Release history, Published vaults, sgit.ai llms.txt, Synthetic users, second run, five people who do not exist, reading riskmandate.a, Synthetic users, five people who do not exist, shopping, sgit.ai llms.txt, Updates (sgit.ai)
- store.sgit.ai (3): Five audiences, decoupled views, and the version the board can read, Reviews, The work
Telemetry
Anonymous usage reported from a published vault back to its author through an append lane, the one credential that stays safe when published inside a public vault. where it is defined
54 pages on 8 sites
- abp.sgit.ai (3): The Delta Is Derived And Never Authored: Storing It Is The Point, And The Histor, The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, The delta
- games.sgit.ai (8): Admin & engineering, Building a game as a vault, Ideas & feedback — the reply channel, The catalogue, games.sgit.ai — a game makes you say what you think, before you are told, games.sgit.ai llms.txt, The maturity ladder, What our games send
- nhi.sgit.ai (1): pki.sgit.ai: The Public Key Registry Has A Documented Failure To Learn From, And
- open-source.sgit.ai (3): Comms: tasks & requests, The History of Open Source and Its Major Success Stories, The numbers, and the ones we refuse to publish
- pki.sgit.ai (2): pki.sgit.ai: The Public Key Registry Has A Documented Failure To Learn From, And, pki.sgit.ai llms.txt
- riskmandate.ai (13): Every Routable Address Is In The Grant: Do Not Attack Anyone Is The One Rule Eve, This Is The Tier One Application Nobody Could Find: The Connector List Alone Is , You run agents today, RiskMandate — Know the risk. Name the owner. Own the mandate., Make your agents insurable, RiskMandate — Lab 06 · every routable address is in the grant, RiskMandate — Lab 04 · the shape collector, RiskMandate — OWASP, as a graph, RiskMandate — Who can pull the plug?, RiskMandate — questions we were asked, 1.10.0.md, 1.12.0.md, 1.32.0.md
- sgit.ai (20): Release history, API: append lanes (sgit.ai), The proof is two clicks behind the claim, what the homepage gets wrong, and the , The proof moved up, the homepage after the rebuild, next to the before pictures, Performance, cost, and running everywhere, Fractal Semantic Graphs, Two games about agent permissions (a published vault), VoiceDebrief, a published vault, Cross-team briefs, For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it, Publishing a vault’s decks onto a website, build brief, Telemetry from a published vault, a build brief, Working on a vault: start here, guidance, sgit.ai llms.txt, sgit.ai llms.txt, sgit (the encrypted git for humans and AI agents), sgit.ai, for investors, published in the open, sgit.ai llms.txt, The board, open work on sgit.ai, as a kanban of files, Publisher, an agentic role on sgit.ai, Updates (sgit.ai)
- what-can-it-do.games.sgit.ai (4): How this site is built, what-can-it-do.games.sgit.ai llms.txt, The Mavs PoC — a draft pack, What we learn from you
Twins
A twin here is an interface to reality rather than a simulation of it: a system with properties, behaviours and inputs and outputs, such as a connector twin that journals and replays every call an agent makes. where it is defined
36 pages on 6 sites
- abp.sgit.ai (11): The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has , The Prohibitions Are The Exclusions: Your Own Demo Says No Policy Covers The Del, The Behaviour Policy Is Already A Fractal And The Overlay Is Already Published: , The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Docs, What To Build, abp.sgit.ai llms.txt, The delta, The universes, U9: The estate and the twin
- nfrs.sgit.ai (1): nfrs.sgit.ai llms.txt
- pki.sgit.ai (1): pki.sgit.ai llms.txt
- riskmandate.ai (6): Direction change — the Agent Behaviour Policy becomes the primitive, The memo queue, RiskMandate — the brief register, RiskMandate — Know the risk. Name the owner. Own the mandate., RiskMandate — Who can pull the plug?, 0.10.0.md
- sgit.ai (15): Release history, Before you give an agent a connector, give the connector a twin, Every risk is already accepted. The only question is by whom, and for how long., Articles, Connector Twin, a business plan with a working replay, published as a vault, Published vaults, sgit.ai llms.txt, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt, graphs.sgit.ai, A node is just a node, meaning lives in the edges, The sgit.ai network, sibling sites, A proposed partnership between sgit.ai and AWS, sgit runs on every cloud: proposed partnerships with the cloud platforms, Business plans to build on sgit, Build your startup on sgit vaults
- twins.sgit.ai (2): twins.sgit.ai — an interface to reality, not a simulation of it, twins.sgit.ai llms.txt
Undo classes
Whether an action can be reversed: undone with no loss, recoverable with effort, or not at all; recorded per capability or risk and used to order what matters first. where it is defined
135 pages on 10 sites
- abp.sgit.ai (63): v0.1.0: The ontology already existed, so the first release promoted it instead o, v0.10.0: The desktop walkthrough: on your own machine, host means your machine, , v0.7.0: The first case: one person's estate, the mandates elicited line by line,, v0.4.4: Seven deployment shapes somebody else measured, promoted with their prov, v0.4.2: The fact diff was named as a blocker on four consecutive days, and it re, The data, Agent Behaviour Policy (ABP): You Know What You Asked For, And You Do Not Know W, The Behaviour Policy Is The Document The Only Agent Insurer Already Requires: Se, The Behaviour Policy Is Already A Fractal And The Overlay Is Already Published: , The Twin Of The Interface Is The Grant In Machine Readable Form: Three Twins Are, Marking Everything Read Destroys This User And Breaks Nothing: The Grant Cannot , The Consent Dialog Is An Accountability Transfer Rather Than A Decision: The Use, The ABP Is A Fractal Semantic Graph: One Row Crosses Nine Universes, Each Keeps , Docs, Start Here, What To Build, The ABP Model, The First Examples, The Hard Rules, The Prompt, A browser extension with broad host permissions, Chat in the browser, nothing connected, The same coding agent, confirmations off, A coding agent on your own machine, confirmations on, A CI job on a hosted runner, under a service account, Step 1: what it can already do, Agent Behaviour Policy, abp.sgit.ai llms.txt, authenticate-as.credential.signing, authenticate-as.credential.tenant, create.record.world, create.schedule.host, create.schedule.tenant, delete.file.host, execute.process.host, execute.process.self, grant.credential.self, The capability grammar, read.credential.host, read.file.host, read.file.project, read.message.tenant, read.record.browsing, read.record.history, send.endpoint.allowed, send.endpoint.world, send.message.world, write.budget.tenant, write.file.host, write.file.project, write.repository.project, write.repository.tenant, The edge vocabulary, The graph, The model, The lexicon, The schema, The undo class, U1: The grammar, U7: The projections, v0.1.0: the ontology is promoted out of a game and the five examples are derived, v0.4.2: the fact set is data, the fact diff runs over every published page, and , What is an Agent Behaviour Policy
- elevenlabs.providers.sgit.ai (5): 01: What The Site Has Today, And What Is Missing, 02: The Two Axes, The Audiences, The Page Contract, And Eleven Decisions, 03: The Sequence, index.md, index.md
- open-source.sgit.ai (2): 02 — How he actually uses open source, Publish the source next to the render
- pki.sgit.ai (1): pki.sgit.ai llms.txt
- providers.sgit.ai (1): index.md
- riskmandate.ai (25): The Agent Behaviour Policy, condensed, The policy is a graph, and every stakeholder gets a projection of it, Direction change — the Agent Behaviour Policy becomes the primitive, A grant is a union of capabilities; what the reader needs is the consequences — , The memo queue, T01 — One page per behaviour, T11 — Consequences and assets: what follows when a capability meets what is in t, A deleted meeting comes back. An edited one does not., One agent, and every desk it reaches. How to read the risk propagation visualise, RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one, Who owns what in AI. And how accountability holds on the way up., RiskMandate — the brief register, RiskMandate — the business case for PostgreSQL point-in-time recovery, RiskMandate — the business case for Velero, Changes we are asking of the behaviour-policy site — RiskMandate Lab 03, The grant is user-shaped, not data-shaped — RiskMandate Lab 01, What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandat, GRANT — everything the agent can do, Claude Code on the web, with one repository attached — an Agent Behaviour Policy, The vocabulary this vault was computed against, MAP-A-GRANT.md — a prompt for an agent that holds a connector or a credential, RiskMandate — version record, 1.17.0.md, 1.32.3.md, Brief B1 — power user and tester of Agent Behaviour Policies
- risks.sgit.ai (2): risks.sgit.ai — Brief Pack, risks.sgit.ai llms.txt
- sgit.ai (7): Release history, Before you give an agent a connector, give the connector a twin, Articles, Connector Twin, a business plan with a working replay, published as a vault, For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, sgit (the encrypted git for humans and AI agents), sgit.ai llms.txt
- ungovr.providers.sgit.ai (1): index.md
- what-can-it-do.games.sgit.ai (28): The data pack, what-can-it-do.games.sgit.ai llms.txt, Sign commits with the key it holds, Act in accounts with the credentials it holds, Publish packages, images or pages under the name it holds, Delete files anywhere the account can reach, The capabilities, Read credentials stored where it runs, Read any file the account can reach, Read mail or chat it is connected to, Read every page you visit, Read a retained record: shell history, past sessions, Reach a permitted list of hosts, Reach any host on the internet, Send a message to anyone, Spend money or tokens against an account it holds, The deltas, Claude Code — web container, Claude Code — local · confirm off, Claude Code — local · confirm on, Claude Desktop — local tools, Claude.ai — connectors on, Browser extension — all sites, Scheduled job — service account, GitHub Actions — hosted runner, The products, ChatGPT — no connectors, The map — what each agent can reach
Vault apps
Self-contained HTML applications that live inside a vault and open from its index.html in a sandboxed frame, reaching the host through a permissioned bridge, including model calls without holding an API key. where it is defined
120 pages on 12 sites
- abp.sgit.ai (4): The Split Does Not Break The Trifecta, The Schema Does: A Closed Vocabulary At T, Docs, The Conventions, abp.sgit.ai llms.txt
- elevenlabs.providers.sgit.ai (5): index.md, index.md, index.md, index.md, index.md
- games.sgit.ai (3): Admin & engineering, Building a game as a vault, The network
- llms.sgit.ai (28): Participant disclosure, and where we lose, Comms: tasks & requests, Release history · llms.sgit.ai, Pages that models read, The sg.llm. reference, The traps, 00 — The Brief: llms.sgit.ai, llms.sgit.ai — brief pack, 01 — The chat pane: three surfaces, 02 — The sg.llm. API, 03 — The security model, and the gap in it, 06 — Site Architecture, 07 — Boundaries and licensing, 08 — Gaps, open questions and honest tensions, Licence, Code samples — adding an LLM chat pane, Adding an LLM chat pane, The code samples, The sg.llm. API, Site Architecture, The documents, Code Samples: Adding An LLM Chat Pane, llms.sgit.ai — your app calls a language model without ever holding an API key, llms.sgit.ai llms.txt, The network, and what this site does not own, The security model, and the gap in it, What is shipped, and what is not, AUTHORINGcalling-an-llm.md
- pki.sgit.ai (2): pki.sgit.ai llms.txt, pki.sgit.ai llms.txt
- providers.sgit.ai (1): index.md
- riskmandate.ai (12): The map, Vaults in vaults: the application vault is data, the renderer lives once, The first MVP vault: oc433z3m becomes the product, and the reading app is rebuil, Briefs written here, A behaviour policy for everybody the lead talks to, made by an agent from a zip, T04 — Views per audience, and projections regenerated from a shipped prompt, RiskMandate — the brief register, What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandat, 0.1.0.md, 0.5.4.md, 1.13.0.md, 1.20.0.md
- risks.sgit.ai (1): risks.sgit.ai llms.txt
- sgit.ai (61): sgit.ai, the website, served from a vault, Brief for Claude Code, sgit.ai design improvements, Admin & engineering, Plan: the Why reframe, three end-to-end demo vaults, and the component registry, Release history, API: append lanes (sgit.ai), The HTTP API, A chat box on a site with no server, the plan, and the trade it makes, Before you give an agent a connector, give the connector a twin, Comparisons, as tests you can re-run, Fractal Semantic Graphs, Demos, sgit, on a Wardley Map (sgit.ai demos), A vault app, live inside this page, sgit.ai demos, Two games about agent permissions (a published vault), Agent as Webmaster, a business plan published as a vault, Provenance is not conformance, a published vault, AI vs. AI, Black Hat Europe 2025, a published vault, Company X-Ray, a business plan with one company X-rayed, published as a vault, Connector Twin, a business plan with a working replay, published as a vault, Field Notes, a published vault, Published vaults, Lesson Loop, a business plan for coaches with one player's record, published as , sgit.ai llms.txt, Risk Acceptance Office, a business plan with one risk replayed, published as a v, Vault App Mode, a published vault, Briefing: embedding the Vault App iframe inside sgit.ai pages, reusing your code, Cross-team briefs, Markdown and file viewers in a vault: what not to build (build brief), Reading a vault from a .sgit.ai site page, build brief, An infographic of the published vaults, build brief, Telemetry from a published vault, a build brief, Working on a vault: start here, guidance, sgit.ai llms.txt, Documentation, sgit, sgit.ai llms.txt, Three surfaces: which one are you building for?, Sending messages between vaults, Content authoring, SG/Vault, Git repos inside vaults, SG/Vault, SG/Vault & the vault platform, sgit.ai llms.txt, The window.sg bridge, SG/Vault, Static hosting on GitHub Pages, SG/Vault, Sub-vaults, SG/Vault, Building vault apps, SG/Vault, sgit.ai, for investors, published in the open, sgit.ai llms.txt, The sgit.ai network, sibling sites, Models do the work, vaults hold it: proposed partnerships with the AI providers, A proposed partnership between sgit.ai and Anthropic, A proposed partnership between sgit.ai and ElevenLabs, A proposed partnership between sgit.ai and Google Gemini, A proposed partnership between sgit.ai and Mistral AI, A proposed partnership between sgit.ai and OpenAI, A proposed partnership between sgit.ai and OpenRouter, Building HTML Apps That Live Inside an SG/Vault, Skills for AI agents, sgit, The board, open work on sgit.ai, as a kanban of files, Designer, an agentic role on sgit.ai, Updates (sgit.ai)
- skills.sgit.ai (1): skills.sgit.ai llms.txt
- store.sgit.ai (1): Design brief — store.sgit.ai
- ungovr.providers.sgit.ai (1): 04 — The Vault: Team, Viewers, Settings, Releases
Vault key management
How people and agents store, share and take back vault keys, which today travel by copy and paste; sgit.ai's open call asks password managers and identity providers to solve it rather than build it alone. where it is defined
11 pages on 1 sites
- sgit.ai (11): Release history, Before you give an agent a connector, give the connector a twin, Lesson Loop, a business plan for coaches with one player's record, published as , For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sg, When NOT to use sgit, Docs, sgit.ai llms.txt, Partnerships, argued in the open, Who holds the keys? A call for collaboration on vault key management, Data that changes what is permissible, sgit use cases, Working documents with clients, sgit use cases, Why does this exist?
Wardley maps
Maps that place each component on an evolution axis, treated across the network as arguable claims rather than pictures, with a research site of their own. where it is defined
40 pages on 8 sites
- games.sgit.ai (1): Admin & engineering
- graphs.sgit.ai (1): graphs.sgit.ai llms.txt
- influences.sgit.ai (5): An influence is a claim you can check, influences.sgit.ai — the influence register of Dinis Cruz, Karl Popper & falsifiability, Team Topologies & Cynefin, Simon Wardley & Wardley Maps
- open-source.sgit.ai (3): 02 — How he actually uses open source, 08 — Gaps, open questions and honest tensions, Three licences, three layers, and one nobody had noticed
- pki.sgit.ai (2): pki.sgit.ai — good public key repositories existed, and were destroyed, pki.sgit.ai llms.txt
- riskmandate.ai (2): The pilot worked. Then somebody asked what else it could do., 0.4.3.md
- sgit.ai (13): Release history, The SaaS apocalypse will be decided by inertia, not by AI, sgit, on a Wardley Map (sgit.ai demos), The Strategy in Seven Maps, a real document republished from a vault, sgit.ai de, Published vaults, sgit.ai llms.txt, Strategy Maps (a published vault), Scaling Threat Modeling with Semantic Knowledge Graphs, a published vault, sgit.ai llms.txt, graphs.sgit.ai, A node is just a node, meaning lives in the edges, The sgit.ai network, sibling sites, Updates (sgit.ai), Why does this exist?
- wardley-maps.sgit.ai (13): 00 — The Brief: wardley-maps.sgit.ai, wardley-maps.sgit.ai — brief pack, 01 — Concepts Index, 02 — Explorer / Villager / Town Planner: PST as three literal agent teams, 03 — Job A: everything Dinis Cruz has published on Wardley Maps, 04 — Job B: the industry resources, and how to build a page for each, 05 — Maps, rendering, and two things this session established by testing, 06 — Site Architecture, 07 — Boundaries, licensing and house style, 08 — Gaps, open questions and honest tensions, Licence, Maps are claims, not pictures, wardley-maps.sgit.ai llms.txt