# Concepts

- **Append lanes**: A write-only channel into a vault: the writer holds a token that can only append, gets back a blind acknowledgement, and entries sit outside the commit tree until the vault owner processes them. (47 pages)
- **Read keys**: A key derived one way from the vault key that can read a vault and never write to it; a site publishes one on purpose, with the public-read prefix, when it wants anyone to open the vault. (268 pages)
- **Vault key management**: How people and agents store, share and take back vault keys, which today travel by copy and paste; sgit.ai's open call asks password managers and identity providers to solve it rather than build it alone. (11 pages)
- **Risk acceptance**: A risk exists as soon as the exposure does, so the question is who has accepted it and until when: there is no deny button, only accept for a stated interval, fund the work, or fix it. (56 pages)
- **Acceptance intervals**: The ladder of durations a risk can be accepted for, from an hour to six months with a month as the default, where the chosen interval sets both the severity and the response. (13 pages)
- **Agent Behaviour Policy**: A written record, for one agent in one deployment, of everything it can do, what it was authorised to do, the gap between the two, and what actually stands in the way; it describes and carries no score. (403 pages)
- **Grants and mandates**: The grant is what an agent can actually reach; the mandate is what someone with authority allowed it to do; the delta between them is the excess authority nobody accepted. (164 pages)
- **Licence to operate**: A self-issued, witnessed and dated licence in which the organisation is the authority, the behaviour policy the instrument and the agent the licensee: the step between describing an agent and insuring it. (119 pages)
- **Insurability**: The argument that agents become insurable when someone can evidence what they can reach and what contains them, which is what a behaviour policy and a licence to operate produce. (55 pages)
- **Blast radius**: How far the harm from a grant, a risk or a control reaches: which systems, people and roles it touches, recorded beside the owner and the expiry of each mandate. (60 pages)
- **Fractal semantic graphs**: Graphs where each node can open into a graph of its own with its own ontology, joined by a shared grammar rather than a shared schema, so the same rules hold at every altitude. (39 pages)
- **Twins**: A twin here is an interface to reality rather than a simulation of it: a system with properties, behaviours and inputs and outputs, such as a connector twin that journals and replays every call an agent makes. (36 pages)
- **Business plans**: Businesses sgit.ai thinks should exist on top of sgit, each published as a vault with the plan, sourced facts, numbers marked as hypotheses and prototypes, for someone else to take and run. (14 pages)
- **Partnerships**: Proposals for work with named organisations, written from public material only so each page can be forwarded, stating the fit, where it is partial and a first piece of work; none records a conversation yet. (29 pages)
- **Briefs**: Documents one team writes for another: cross-team asks that carry a status and close when answered, and build briefs written for an agent to execute, tracked in public indexes and registers. (145 pages)
- **Provenance**: The visible record on each page of where its material came from: original date, link, authors including any AI co-authorship, and how it was curated. (18 pages)
- **Frozen, hashed sources**: Every source page fetched, frozen to a dated snapshot and hashed with SHA-256, so claims are read from the frozen copy and can be checked later. (5 pages)
- **Pricing ladders**: Four levels where each is the level below plus exactly one thing, from a downloaded pack to a signed review, sold through standing payment links; RiskMandate's ladder is reused by other plans. (110 pages)
- **Interview pages**: A page sent to one person that carries a prompt they paste into a chat assistant, which interviews them by voice and writes up their feedback for them to send back. (16 pages)
- **Telemetry**: Anonymous usage reported from a published vault back to its author through an append lane, the one credential that stays safe when published inside a public vault. (54 pages)
- **Open source**: Open source treated as a strategy rather than a charity: the network publishes its code under Apache-2.0 and argues that the technology was never the moat. (94 pages)
- **EU AI Act**: Regulation (EU) 2024/1689, the one instrument standards.sgit.ai models, cited across the network for duties such as judging residual risk acceptable without a definition of acceptable. (52 pages)
- **GDPR**: The EU data protection regulation, published by sgit.ai as a navigable graph vault and cited by articles in the partnership and risk work, while one sibling site still says no GDPR graph exists. (42 pages)
- **Vault apps**: Self-contained HTML applications that live inside a vault and open from its index.html in a sandboxed frame, reaching the host through a permissioned bridge, including model calls without holding an API key. (120 pages)
- **Lessons learned**: Rules recorded with the event that produced them, so each correction says what went wrong and how it was caught. (22 pages)
- **Em-dashes and style**: The network's writing rules, most visibly the removal of the em-dash from prose on sgit.ai on 20 September 2026, rewritten by context rather than replaced, with a validator guard. (17 pages)
- **Security audits**: Checks published beside the work: every vault audited from a read-key clone before its key is published, and reviews whose findings are stated even when they did not survive checking. (64 pages)
- **Client-side encryption**: Content is encrypted on the owner's device before it is stored, so the host holds only ciphertext and cannot read it; the zero-knowledge model behind every vault. (55 pages)
- **PKI**: Public key infrastructure for vaults and agents: keypairs from the CLI for encryption and signing, sealing messages to a recipient, and the registry rules pki.sgit.ai draws from the history of key servers. (50 pages)
- **Synthetic users**: Invented readers walked through a site one screenshot at a time and interviewed at the end, to find where real readers would get lost. (19 pages)
- **Brand assets**: The logos, marks, colour tokens and boilerplate descriptions of set lengths that a site publishes for others to reuse, such as event forms and printers. (10 pages)
- **Performance and cost**: The measured speed and running cost of reading vaults and fractal graphs straight from object storage, with no live database and nothing running between questions. (7 pages)
- **Startups**: sgit.ai's operating model for founders: ship something usable, give it away briefly, take it away and see whether anybody misses it; be profitable before raising; open source everything. (20 pages)
- **Wardley maps**: Maps that place each component on an evolution axis, treated across the network as arguable claims rather than pictures, with a research site of their own. (40 pages)
- **Undo classes**: Whether an action can be reversed: undone with no loss, recoverable with effort, or not at all; recorded per capability or risk and used to order what matters first. (135 pages)
