---
title: A brief written on one site, built on another the same day
date: 2026-09-24
desk: Journalist
sources:
  - https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html
  - https://sgit.ai/docs/briefs/index.html
  - https://riskmandate.ai/versions/1.34.2.md
  - https://riskmandate.ai/versions/1.34.3.md
  - https://riskmandate.ai/versions/1.34.4.md
  - https://riskmandate.ai/interview-founder-marketing.md
  - https://riskmandate.ai/briefs.md
  - src:history/sgit.ai-version-log.json
  - src:history/sgit.ai-git-log.txt
  - https://sgit.ai/demos/vaults/company-xray/index.html
  - https://sgit.ai/demos/vaults/lesson-loop/index.html
  - https://sgit.ai/demos/vaults/risk-acceptance/index.html
  - https://sgit.ai/demos/vaults/connector-twin/index.html
  - https://sgit.ai/startups/business-plans.html
  - https://sgit.ai/articles/every-risk-is-already-accepted.html
  - https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html
  - https://sgit.ai/partnerships/cloud-platforms.html
  - https://sgit.ai/partnerships/ai-providers.html
  - https://sgit.ai/docs/briefs/riskmandate-partnership-risk-and-sgit-mapping.html
  - https://sgit.ai/partnerships/vault-key-management.html
  - https://riskmandate.ai/versions/1.32.3.md
  - https://riskmandate.ai/article-calendar-edits-cannot-be-undone.md
  - https://riskmandate.ai/versions/1.34.5.md
  - https://riskmandate.ai/versions/1.34.6.md
  - https://riskmandate.ai/versions/1.34.8.md
  - https://sgit.ai/partnerships/aws.html
  - https://sgit.ai/partnerships/azure.html
  - https://sgit.ai/partnerships/google-cloud.html
  - https://sgit.ai/partnerships/ibm-cloud.html
  - https://sgit.ai/partnerships/european-clouds.html
  - https://sgit.ai/partnerships/digitalocean.html
  - https://sgit.ai/partnerships/rackspace.html
  - https://sgit.ai/partnerships/netlify.html
  - https://sgit.ai/partnerships/openai.html
  - https://sgit.ai/partnerships/anthropic.html
  - https://sgit.ai/partnerships/mistral.html
  - https://sgit.ai/partnerships/google-gemini.html
  - https://sgit.ai/partnerships/openrouter.html
  - https://sgit.ai/partnerships/elevenlabs.html
  - https://riskmandate.ai/versions/1.32.0.md
  - https://riskmandate.ai/versions/1.32.1.md
  - https://riskmandate.ai/versions/1.32.2.md
  - https://riskmandate.ai/versions/1.33.0.md
  - https://riskmandate.ai/versions/1.34.0.md
  - https://riskmandate.ai/versions/1.34.1.md
  - https://riskmandate.ai/versions/1.34.7.md
  - src:cli-briefs/09/24/brief__riskmandate__interview-page-and-voice-prompt.md
  - src:cli-briefs/09/24/brief__riskmandate__partnership-risk-and-sgit-mapping.md
reviewed_by:
reviewed_on:
---

The busiest day of the week. sgit.ai published four business plans as vaults ([business plans](https://sgit.ai/startups/business-plans.html)), a set of proposed partnerships ([version log, v0.6.4](src:history/sgit.ai-version-log.json)) and two briefs for riskmandate.ai ([briefs index](https://sgit.ai/docs/briefs/index.html)). riskmandate.ai built one of those briefs the same day ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)).

## Lead: A brief written on one site, built on another the same day

sgit.ai released v0.6.7 at 20:55 on 24 September ([git log](src:history/sgit.ai-git-log.txt)): a build brief asking riskmandate.ai for an interview page ([the brief](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html)). The reasoning is in one line: "Asking them to talk for twenty minutes usually does." ([the brief](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html)). The reader pastes a prompt into ChatGPT, which interviews them in voice mode and writes up their feedback ([the brief](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html)). The first page is for a founder strong in UK events, marketing and content ([version log, v0.6.7](src:history/sgit.ai-version-log.json)).

riskmandate.ai registered it as D19 and built it in v1.34.2, dated the same day ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)). Its note links "The first interview page", unlisted and sent by link ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)). The copy button was tested in a browser against all 3,573 characters of the stored prompt ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)). The prompt is the brief's, "with two corrections" to what the site states, both recorded beside it ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)). The page reached the live site with v1.34.3, after failing CI checks had held back the releases before it ([v1.34.3](https://riskmandate.ai/versions/1.34.3.md)). v1.34.4 then added six questions on the Agent Behaviour Policy and made it a thirty-minute interview ([v1.34.4](https://riskmandate.ai/versions/1.34.4.md)), which is how [the live page](https://riskmandate.ai/interview-founder-marketing.md) reads now.

Part of the brief is not done. Its checklist asks for one end-to-end run in ChatGPT voice mode ([the brief](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html)). riskmandate.ai's agent has no ChatGPT account, "so that run is the lead's." ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)). Sending summaries back through a write-only lane stays marked as later ([v1.34.2](https://riskmandate.ai/versions/1.34.2.md)).

The two sites' records disagree. riskmandate.ai's [brief register](https://riskmandate.ai/briefs.md) lists the brief with what was built and what was not. In the snapshot taken that night, sgit.ai's [briefs index](https://sgit.ai/docs/briefs/index.html) still shows the ask as open, and the brief itself still reads "Status: open. Written 24 September 2026." ([the brief](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html)). The longer story is [here](nr:stories/2026-09-24__brief-to-build-in-a-day).

## Also today

### Four business plans, each a vault

sgit.ai published four business plans as vaults, each from a voice memo by the founder that day ([Company X-Ray](https://sgit.ai/demos/vaults/company-xray/index.html), [Lesson Loop](https://sgit.ai/demos/vaults/lesson-loop/index.html), [Risk Acceptance Office](https://sgit.ai/demos/vaults/risk-acceptance/index.html), [Connector Twin](https://sgit.ai/demos/vaults/connector-twin/index.html)). Company X-Ray reads a company's own documents together and sells in four levels from £50 to £1,500 on RiskMandate.ai's pattern ([vault page](https://sgit.ai/demos/vaults/company-xray/index.html)). Lesson Loop turns a coach's end-of-lesson voice memo into a note in the player's own vault ([vault page](https://sgit.ai/demos/vaults/lesson-loop/index.html)). The Risk Acceptance Office replays one invented risk over six weeks ([vault page](https://sgit.ai/demos/vaults/risk-acceptance/index.html)), behind [an article](https://sgit.ai/articles/every-risk-is-already-accepted.html) whose pitch is "who has accepted this, and until when?". Connector Twin replays an invented agent session from a hash-chained journal ([vault page](https://sgit.ai/demos/vaults/connector-twin/index.html)). A new page gathers them: "We are looking for business partners to build them." ([business plans](https://sgit.ai/startups/business-plans.html)).

### Proposed partnerships with the clouds and the AI providers

sgit.ai added sixteen pages under /partnerships/: two hubs, and one page each for cloud platforms and AI providers ([version log, v0.6.4](src:history/sgit.ai-version-log.json)). They are proposals, and each hub says "there has been no conversation yet" ([clouds](https://sgit.ai/partnerships/cloud-platforms.html), [AI providers](https://sgit.ai/partnerships/ai-providers.html)). The clouds hub is plain about status: Docker works, the AWS templates are in beta, the founder's Azure and Google Cloud deployments are not written up, and S3-compatible stores are untested ([clouds](https://sgit.ai/partnerships/cloud-platforms.html)). The vault connector the provider pages describe does not exist yet ([AI providers](https://sgit.ai/partnerships/ai-providers.html)). Research corrected two first drafts, including that sgit.ai is served from GitHub Pages, not AWS ([version log, v0.6.4](src:history/sgit.ai-version-log.json)). The same release asked riskmandate.ai for the risk side of every partnership ([brief](https://sgit.ai/docs/briefs/riskmandate-partnership-risk-and-sgit-mapping.html)); that ask is still open on the [briefs index](https://sgit.ai/docs/briefs/index.html).

### Who holds the keys?

The day began with a call for collaboration on vault key management ([git log](src:history/sgit.ai-git-log.txt), [version log, v0.6.2](src:history/sgit.ai-version-log.json)). It opens: "We are looking for a key manager, not building one." ([the call](https://sgit.ai/partnerships/vault-key-management.html)). It asks password managers, identity providers, platform credential managers and hardware key makers for browser-first key release on the user's approval, with names that are addresses and never keys ([the call](https://sgit.ai/partnerships/vault-key-management.html)). The rule comes from experience: a word-based share token was removed on 12 August 2026 after a review found it could be recovered in about a tenth of a second on a GPU ([the call](https://sgit.ai/partnerships/vault-key-management.html)). Later plans lean on it: Lesson Loop lists easy key handling as open and points here ([Lesson Loop](https://sgit.ai/demos/vaults/lesson-loop/index.html)). The page says no organisation named on it has been contacted ([the call](https://sgit.ai/partnerships/vault-key-management.html)).

### Two sites ask the same question: can it be undone?

On the same day, both sites wrote about what Google lets you take back. sgit.ai's article quotes the Gmail API on its delete: "This operation cannot be undone." ([sgit.ai article](https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html)). riskmandate.ai's article, "A deleted meeting comes back. An edited one does not.", argues that editing a calendar event, not deleting it, is the permission to worry about ([v1.32.3](https://riskmandate.ai/versions/1.32.3.md)). Both corrected themselves on Google Vault: sgit.ai's plan found Vault has covered Calendar since November 2023 ([Connector Twin](https://sgit.ai/demos/vaults/connector-twin/index.html)), and riskmandate.ai found that Workspace editions with Vault keep earlier versions for an admin to export, not to restore ([v1.32.3](https://riskmandate.ai/versions/1.32.3.md)). In the snapshot, neither article links to the other ([sgit.ai article](https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html), [riskmandate.ai article](https://riskmandate.ai/article-calendar-edits-cannot-be-undone.md)).

### riskmandate.ai draws the chain to the board

riskmandate.ai published an article arguing that the map of who owns what in AI runs sideways, and accountability runs upwards ([v1.34.4](https://riskmandate.ai/versions/1.34.4.md)). Over the next releases it drew the article: a blast radius that can be played ([v1.34.5](https://riskmandate.ai/versions/1.34.5.md)), then every live risk lighting its path to the board ([v1.34.6](https://riskmandate.ai/versions/1.34.6.md)), then residual risks: "A control does not make a risk zero; it leaves a green one." ([v1.34.8](https://riskmandate.ai/versions/1.34.8.md)). sgit.ai's risk acceptance article makes the same point in its own words: every path ends at the board ([sgit.ai article](https://sgit.ai/articles/every-risk-is-already-accepted.html)). Both say the engine is missing: authority as data and the clocks are proposed, not built ([v1.34.4](https://riskmandate.ai/versions/1.34.4.md)), and no engine yet records acceptances or fires at expiry ([sgit.ai article](https://sgit.ai/articles/every-risk-is-already-accepted.html)).

## Everything else, by site

### sgit.ai

- [Every risk is already accepted](https://sgit.ai/articles/every-risk-is-already-accepted.html): a foundation article on risk acceptance; a vault per material risk is labelled a proposal.
- [Before you give an agent a connector, give the connector a twin](https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html): the case for a journal and replay of every connector call.
- [Business plans to build on sgit](https://sgit.ai/startups/business-plans.html): the new home for the plans.
- [For RiskMandate.ai: the risk side of the partnerships](https://sgit.ai/docs/briefs/riskmandate-partnership-risk-and-sgit-mapping.html): an open brief, which also notes that Level 1 is priced at £10 on riskmandate.ai's pricing page and £5 elsewhere.
- Proposed partnership pages, one line each:
  - [AWS](https://sgit.ai/partnerships/aws.html): a reviewed reference architecture and a marketplace listing, from templates in beta.
  - [Microsoft Azure](https://sgit.ai/partnerships/azure.html): deployed in the founder's tests, undocumented; a Blob Storage backend is the main work.
  - [Google Cloud](https://sgit.ai/partnerships/google-cloud.html): finish the Cloud Run path; storage routes not yet tested.
  - [IBM Cloud](https://sgit.ai/partnerships/ibm-cloud.html): vaults beside IBM Sovereign Core for regulated data.
  - [The European clouds](https://sgit.ai/partnerships/european-clouds.html): one tested deployment on each of five providers.
  - [DigitalOcean](https://sgit.ai/partnerships/digitalocean.html): a one-click vault server.
  - [Rackspace Technology](https://sgit.ai/partnerships/rackspace.html): managed vaults across clouds.
  - [Netlify](https://sgit.ai/partnerships/netlify.html): encrypted sites on a static host.
  - [OpenAI](https://sgit.ai/partnerships/openai.html): a vault connector for the plugins directory.
  - [Anthropic](https://sgit.ai/partnerships/anthropic.html): a vault connector for the connectors directory, and vault skills.
  - [Mistral AI](https://sgit.ai/partnerships/mistral.html): a fully European stack.
  - [Google Gemini](https://sgit.ai/partnerships/google-gemini.html): a CLI extension and a route to the agent gallery.
  - [OpenRouter](https://sgit.ai/partnerships/openrouter.html): the bounded-key pattern vault apps already use.
  - [ElevenLabs](https://sgit.ai/partnerships/elevenlabs.html): per-key spend limits or short-lived speech tokens.

### riskmandate.ai

- [v1.32.0](https://riskmandate.ai/versions/1.32.0.md): How it works rebuilt as six steps, each with its status; a diagram naming things that do not exist removed.
- [v1.32.1](https://riskmandate.ai/versions/1.32.1.md): the word "rung" replaced across the site, with a test that keeps it out.
- [v1.32.2](https://riskmandate.ai/versions/1.32.2.md): UK support, in the open, a register of 79 programmes and events; nothing applied for.
- [v1.33.0](https://riskmandate.ai/versions/1.33.0.md): business cases, by the risk a product changes, starting with its own.
- [v1.34.0](https://riskmandate.ai/versions/1.34.0.md): an OWASP graph and eighteen open-source business cases.
- [v1.34.1](https://riskmandate.ai/versions/1.34.1.md): a brief and pack for a behaviour-policy vault about each organisation the lead talks to; no real person's vault made yet.
- [v1.34.3](https://riskmandate.ai/versions/1.34.3.md): four releases that CI had held back reach the live site.
- [v1.34.7](https://riskmandate.ai/versions/1.34.7.md): the version chip shows on laptops, phones and tablets.

### SGit-AI__CLI

- [The interview-page brief](src:cli-briefs/09/24/brief__riskmandate__interview-page-and-voice-prompt.md), the canonical copy, status open.
- [The partnership-risk brief](src:cli-briefs/09/24/brief__riskmandate__partnership-risk-and-sgit-mapping.md), the canonical copy, status open.
