# Changes, 2026-09-24

- sgit.ai: [Company X-Ray: a business plan, with one company X-rayed](https://sgit.ai/demos/vaults/company-xray/index.html): Publishes the Company X-Ray vault and adds it to the business plans page: a service that reads a company's own documents together, with an invented company X-rayed end to end and four levels from £50 to £1,500 on RiskMandate.ai's pricing pattern; published vaults reach thirty-six.
- sgit.ai: [A brief for RiskMandate: interview pages, and a ChatGPT voice prompt](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html): Adds a build brief and an open cross-team ask for riskmandate.ai: a reusable interview page whose prompt runs a twenty-minute voice interview and returns a structured summary, the first for a founder strong in UK events and marketing, with a later step proposing a write-only append lane.
- sgit.ai: [Lesson Loop: a business plan for coaches](https://sgit.ai/demos/vaults/lesson-loop/index.html): Publishes the thirty-fifth vault, a business plan for padel coaches and any teacher with students: an end-of-lesson voice memo becomes a note in the player's own vault, with a write-only lane per coach and pay-on-demand credits instead of a subscription.
- sgit.ai: [Every risk is already accepted, and a company to run the loop](https://sgit.ai/articles/every-risk-is-already-accepted.html): Publishes a foundation article on risk acceptance (no deny button; accept, fund or fix; the interval as the decision; accepted versus acceptable under the EU AI Act's Article 9(5)) and the thirty-fourth vault, the Risk Acceptance Office business plan, which replays one invented risk over six weeks.
- sgit.ai: [Partnerships with the clouds and the AI providers, and a brief for RiskMandate](https://sgit.ai/partnerships/cloud-platforms.html): Adds sixteen pages under /partnerships/ (a hub for the cloud platforms, a hub for the AI providers and fourteen proposed partnership pages) plus a brief asking riskmandate.ai for the risk side of every partnership and a GDPR mapping for sgit; research corrected two first drafts.
- sgit.ai: [Before you give an agent a connector, give the connector a twin; business plans get their own page](https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html): Publishes an article arguing that a journal and replay of every connector call is the minimum for deploying an agent, the thirty-third vault (Connector Twin, a working replay of an invented Gmail and Calendar session) and a new /startups/business-plans.html page.
- sgit.ai: [A call for collaboration on vault key management](https://sgit.ai/partnerships/vault-key-management.html): Adds an open call to password managers, identity providers and platform credential managers to hold sgit vault keys, with requirements, a share-by-name sketch, and why the word-based share token was removed in August.
- sgit.ai: [Company X-Ray, a business plan with one company X-rayed, published as a vault](https://sgit.ai/demos/vaults/company-xray/index.html): Vault page for a service that X-rays a company's documents in five working days: an invented company, fourteen findings labelled read, computed or inferred, a script that re-runs all 46 figures, and a published read key.
- sgit.ai: [For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it](https://sgit.ai/docs/briefs/riskmandate-interview-page-and-voice-prompt.html): Build brief, status open: a six-part interview page pattern, the first page for a founder who knows UK events and marketing, the full prompt ready to send, and a checklist that includes one end-to-end run in voice mode.
- sgit.ai: [Lesson Loop, a business plan for coaches with one player's record, published as a vault](https://sgit.ai/demos/vaults/lesson-loop/index.html): Vault page replaying one invented player's record across four lessons with three coaches in two cities; notes that easy key handling is open and that the founder's own padel vault, where phase one will be tried, is not yet published.
- sgit.ai: [Every risk is already accepted. The only question is by whom, and for how long.](https://sgit.ai/articles/every-risk-is-already-accepted.html): Foundation article: three doors (accept for an interval, fund, fix), the risks.sgit.ai interval ladder, fractal risk registers, a vault per material risk (labelled a proposal), and twins as designs not yet built.
- sgit.ai: [Risk Acceptance Office, a business plan with one risk replayed, published as a vault](https://sgit.ai/demos/vaults/risk-acceptance/index.html): Vault page for a governance service priced per material risk; replays one invented risk over six weeks with a hash-chained decision record, and records four places where the published method disagrees with itself.
- sgit.ai: [For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sgit](https://sgit.ai/docs/briefs/riskmandate-partnership-risk-and-sgit-mapping.html): Build brief, status open: asks riskmandate.ai for one page per partner organisation as two behaviour policies and a delta, and for sgit written up as a control against GDPR Articles 32, 25, 34(3)(a), 28 and 17; notes two inconsistencies, including a Level 1 price of £10 on one site and £5 on another.
- sgit.ai: [Models do the work, vaults hold it: proposed partnerships with the AI providers, sgit.ai](https://sgit.ai/partnerships/ai-providers.html): Hub for six proposed provider partnerships: three meeting points (agents read and write vaults, vault apps call models without a key, vaults carry agent work); states that the vault connector does not exist yet.
- sgit.ai: [A proposed partnership between sgit.ai and Anthropic](https://sgit.ai/partnerships/anthropic.html): Proposes a vault connector in the provider's connectors directory, vault skills and a partner-network place, starting from this site already being built by agent sessions that share state through a vault.
- sgit.ai: [A proposed partnership between sgit.ai and AWS](https://sgit.ai/partnerships/aws.html): Proposes a reviewed reference architecture and a marketplace listing, building on beta CloudFormation templates and the vault service's Amazon S3 storage; notes the European Sovereign Cloud.
- sgit.ai: [A proposed partnership between sgit.ai and Microsoft Azure](https://sgit.ai/partnerships/azure.html): Says sgit runs on Azure in the founder's tests but is undocumented, and that a native Blob Storage backend is the main engineering a partnership would need.
- sgit.ai: [sgit runs on every cloud: proposed partnerships with the cloud platforms, sgit.ai](https://sgit.ai/partnerships/cloud-platforms.html): Hub for eight cloud pages: sgit needs mostly storage and a little compute; Docker works, AWS templates are in beta, Azure and Google Cloud deployments are not documented, and S3-compatible stores are untested.
- sgit.ai: [A proposed partnership between sgit.ai and DigitalOcean](https://sgit.ai/partnerships/digitalocean.html): Proposes a one-click vault server on App Platform with Spaces storage, and help with a tested deployment.
- sgit.ai: [A proposed partnership between sgit.ai and ElevenLabs](https://sgit.ai/partnerships/elevenlabs.html): Builds on the site's published independent report and asks for per-key spend limits or short-lived text-to-speech tokens so a vault app can hold a credential safely.
- sgit.ai: [A proposed partnership between sgit.ai and the European clouds](https://sgit.ai/partnerships/european-clouds.html): Proposes one tested deployment on each of OVHcloud, Scaleway, Hetzner, IONOS and STACKIT, with sovereignty as the argument.
- sgit.ai: [A proposed partnership between sgit.ai and Google Cloud](https://sgit.ai/partnerships/google-cloud.html): Proposes finishing the Cloud Run path with native Cloud Storage support, a reviewed guide and a Marketplace listing; neither storage route is tested yet.
- sgit.ai: [A proposed partnership between sgit.ai and Google Gemini](https://sgit.ai/partnerships/google-gemini.html): Proposes a Gemini CLI extension, which can be listed self-service, and a route to the enterprise agent gallery through the Google Cloud partnership.
- sgit.ai: [A proposed partnership between sgit.ai and IBM Cloud](https://sgit.ai/partnerships/ibm-cloud.html): Proposes vaults beside IBM Sovereign Core for regulated enterprise data, with IBM Cloud Object Storage and Code Engine.
- sgit.ai: [A proposed partnership between sgit.ai and Mistral AI](https://sgit.ai/partnerships/mistral.html): Proposes a fully European stack: EU-hosted models, a vault connector for Vibe and a joint reference with a European cloud.
- sgit.ai: [A proposed partnership between sgit.ai and Netlify](https://sgit.ai/partnerships/netlify.html): Proposes a documented pattern for encrypted sites served from a static host and decrypted in the reader's browser.
- sgit.ai: [A proposed partnership between sgit.ai and OpenAI](https://sgit.ai/partnerships/openai.html): Proposes a vault connector for the plugins directory shared by ChatGPT and Codex, with read and append tools that need nothing destructive.
- sgit.ai: [A proposed partnership between sgit.ai and OpenRouter](https://sgit.ai/partnerships/openrouter.html): Proposes documenting the bounded-key pattern (a spend limit and a reset) that vault apps on this site already use to reach models.
- sgit.ai: [A proposed partnership between sgit.ai and Rackspace Technology](https://sgit.ai/partnerships/rackspace.html): Proposes Rackspace offering managed vaults across clouds, including its UK sovereign clouds.
- sgit.ai: [Before you give an agent a connector, give the connector a twin](https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html): Article: what Gmail and Calendar can and cannot undo, from Google's own pages; the twin as journal plus replay on a write-only lane; undo as a graded list; how a twin changes the agent's behaviour policy.
- sgit.ai: [Connector Twin, a business plan with a working replay, published as a vault](https://sgit.ai/demos/vaults/connector-twin/index.html): Vault page: an invented seventeen-call Gmail and Calendar session rebuilt from a hash-chained journal, before and after for every write, a graded revert plan, and per-agent pricing as hypotheses.
- sgit.ai: [Business plans to build on sgit, sgit.ai](https://sgit.ai/startups/business-plans.html): New home for the business plans, each a vault: Company X-Ray, Lesson Loop, Risk Acceptance Office, Connector Twin and Agent as Webmaster, with how to take one and an invitation to build them with partners.
- sgit.ai: [Who holds the keys? A call for collaboration on vault key management, sgit.ai](https://sgit.ai/partnerships/vault-key-management.html): Open call to key managers: browser-first release on the user's approval, key kinds kept apart, names that are addresses and never keys, scoped keys for agents; lists what exists and what does not.
- riskmandate.ai: [A control leaves a green risk](https://riskmandate.ai/versions/1.34.8.md): The blast-radius figure now shows red travelling up the path while anything below is unaccepted, gives every control a residual risk of its own, and adds controls that can make every path green.
- riskmandate.ai: [The version, on every screen](https://riskmandate.ai/versions/1.34.7.md): The header's version chip, hidden on most screens, now shows on laptops and appears as the first drawer entry on phones and tablets.
- riskmandate.ai: [Risks flow upwards](https://riskmandate.ai/versions/1.34.6.md): Every live risk in the article's figure now lights the path from its holder to the board, with counts per role and a list of every risk that holds at that moment.
- riskmandate.ai: [The article, drawn](https://riskmandate.ai/versions/1.34.5.md): Adds three figures drawn from the article's own data: a playable blast radius, the six weeks as a strip, and the ontology.
- riskmandate.ai: [Who owns what in AI, and the ABP in the interview](https://riskmandate.ai/versions/1.34.4.md): Adds an article that puts a role-ownership map under accountability that runs upwards, and extends the founder interview with six questions on the Agent Behaviour Policy, to thirty minutes and sixteen summary sections.
- riskmandate.ai: [Four releases, delivered](https://riskmandate.ai/versions/1.34.3.md): Fixes the CI failures that had kept v1.32.2 to v1.34.2 off the live site, so the UK support page, the two articles, the business cases, the OWASP graph and the interview page reach riskmandate.ai for the first time.
- riskmandate.ai: [Twenty minutes of your advice, by voice](https://riskmandate.ai/versions/1.34.2.md): Builds sgit.ai's interview-page brief (registered D19): the first interview page, unlisted and sent by link, a copy button tested against the stored prompt, two recorded corrections, and a template; the voice-mode run is left to the lead.
- riskmandate.ai: [A behaviour policy for everybody the lead talks to](https://riskmandate.ai/versions/1.34.1.md): Adds a brief and a repository pack for building a behaviour-policy vault about each organisation the lead talks to, with a leak gate proved against six planted leaks; no keys vault or real person's vault exists yet.
- riskmandate.ai: [OWASP and open source first](https://riskmandate.ai/versions/1.34.0.md): Adds an OWASP graph (52 projects and documents, 110 numbered items) published as data, eighteen open-source business cases and eighteen companies built on open source.
- riskmandate.ai: [Business cases, by the risk they change](https://riskmandate.ai/versions/1.33.0.md): Adds a business-cases section that computes the risk register for an agent deployment with and without a product, starting with RiskMandate's own case and twelve product categories.
- riskmandate.ai: [Two articles: pilots that do not stay, and edits that cannot be undone](https://riskmandate.ai/versions/1.32.3.md): Adds two articles: why agent pilots may not reach or stay in production, and why a Google Calendar edit, unlike a delete, documents no way for a user to restore it.
- riskmandate.ai: [UK support, in the open](https://riskmandate.ai/versions/1.32.2.md): Adds a public register of 79 UK programmes, events, schemes and networks, each read on its official page, with nothing applied for.
- riskmandate.ai: [The ladder has steps](https://riskmandate.ai/versions/1.32.1.md): Replaces the word 'rung' with 'step' (or 'interval', 'tier', 'level') across the site, with a test that fails the build if it returns.
- riskmandate.ai: [How it works, in the order it happens](https://riskmandate.ai/versions/1.32.0.md): Rebuilds How it works as six steps in the order they happen, each with its status, and removes an architecture diagram that named things that do not exist.
- SGit-AI__CLI: [For RiskMandate.ai: an interview page, and a ChatGPT voice prompt to run it](src:cli-briefs/09/24/brief__riskmandate__interview-page-and-voice-prompt.md): The canonical markdown copy of the interview-page brief, status open, written 24 September 2026, with the prompt to hand the builder agent.
- SGit-AI__CLI: [For RiskMandate.ai: the risk side of the partnerships, and a risk mapping for sgit](src:cli-briefs/09/24/brief__riskmandate__partnership-risk-and-sgit-mapping.md): The canonical markdown copy of the partnership-risk brief, status open: fourteen risk pages as two behaviour policies and a delta each, and sgit mapped as a control, including residual risks such as no revocation and no recovery.
