sgit newsroom v0.1.29 · snapshot 2026-09-24
On this page

edition · 2026-09-20

An agent refused to open a mislabelled read key, and sgit.ai changed the label

What changed on 2026-09-20: 18 changes

SiteReleasesNew pages
sgit.ai69
riskmandate.ai30

Computed from the Librarian's changes for the day.

The pages this piece is about

A day about labels. On sgit.ai an agent declined to open vaults whose published read keys called themselves private, and the site agreed with it, relabelled the keys and wrote the rule down↗. The same day sgit.ai took the em-dash out of its prose↗, published the article that introduces Fractal Semantic Graphs↗ and added a thirty-first vault↗. On riskmandate.ai, a new articles section began with a piece on what an approval prompt does not tell the person who clicks it↗.

Lead: An agent refused to open a mislabelled read key, and sgit.ai changed the label

An agent asked to inspect two of sgit.ai's AIUC-1 vaults declined, because their published credentials were labelled private read, and said it would not work around the restriction (version log, v0.2.98↗). The site's own note does not argue with the refusal: "It was right and our label was wrong." (version log↗). Seven published credentials across the two AIUC-1 pages were relabelled to the public read form, with a dated note on each page (the update↗).

The note says the structural fix matters more than the seven strings: the validator now bans both current private prefixes in tracked files, and the credential checker refuses the private read form (version log↗). A new page, Vault credentials↗, sets the rule that classification is by declaration, never by shape, quoting the CLI's own lesson that "guessing from shape is what once misrouted a 64-hex passphrase to a read-only clone." (Vault credentials↗). On the refusal itself, the page is short: "An agent reads the label and acts on it." (Vault credentials↗).

The clean-up went further before midnight. The v0.2.98 note left 99 legacy-prefixed keys across 27 pages as a decision for the author (version log↗). Two releases later, v0.3.0 moved 102 legacy-prefixed and 24 bare published read keys to the public prefix (the update↗). The two counts differ and the notes do not say why. In between, v0.2.99 found that the routine lifting read keys into llms.txt did not know the public prefix, so the relabelled keys were published there without the declaration they had just been given (version log↗). The day closed with vault #31, the first submission to arrive under the public prefix (the update↗).

riskmandate.ai spent the same day on a neighbouring question. Its first article argues that an approval prompt names an action but not its object: "The prompt names a verb. A decision needs the object." (An approval prompt is not a human in the loop↗). Neither site's release notes mention the other.

Also today

The em-dash leaves sgit.ai's prose

sgit.ai removed 3,200 em-dashes from its prose, because a good many readers now find the character off-putting (version log, v0.3.0↗). The note says it was not a find-and-replace: a rewriter classified each occurrence and chose brackets, commas, a colon or a full stop by context, and code was left alone by construction (version log↗). Checking rather than assuming found four bugs, including brackets that opened in one table cell and closed in another, and a try-page script that would have broken its terminal (version log↗). The validator now carries the same exclusions as the rewriter, so the two agree (the update↗).

Vault #31 reaches the same conclusion about fractality

The DSIT AI Risk Toolkit vault is an independent reference edition of the UK government's AI Risk Management Toolkit, and it models the guidance, the official workbook, the risk method and the cited frameworks as separate worlds with named bridges (the update↗). Its ontology states: "containment alone is not fractality. Cross-world edges make the semantic transitions inspectable." (the vault's page↗). The note calls that the same correction the author made to the fractal graphs page on 19 September, reached by a different author in a different vocabulary (version log, v0.3.1↗). The vault labels every edge curated or lexical and publishes six gaps about itself, including a correction of its own formula count from 227 to 208 (the vault's page↗). It describes itself as not an official DSIT service or certification (the vault's page↗).

Fractal Semantic Graphs gets its article, and its origin vault

The article that introduces the term, written for LinkedIn, is now published on sgit.ai as the canonical copy with nine figures LinkedIn cannot carry (the update↗). The article↗ sets out the test at a link, the five-rule grammar and eleven altitudes across seven live vaults, and names what is still modelled rather than imported. Earlier the same day, the Fractal Semantic Graphs page gained a section on where the idea was worked first↗, the VoiceDebrief vault, whose page now records its GitHub mirror↗, checked file for file on 20 September.

riskmandate.ai starts publishing articles

riskmandate.ai opened a Writing section with An approval prompt is not a human in the loop↗, and the release note says two claims were deliberately not made because neither is measured (v1.27.0↗). The same release gave every barrier in its behaviour policies a holder: not_reachable is gone, and the build refuses a blocked entry that does not name what blocks it (v1.27.0↗). A second article, Somebody will ask what your agent can do↗, is the front door to the Agent Behaviour Policy (v1.27.1↗). A third argues that "A conversation is not an authorisation boundary. It only looks like one." (the article↗), and the section was renamed Articles (v1.27.2↗).

Everything else, by site

sgit.ai

riskmandate.ai