sgit newsroom v0.1.29 · snapshot 2026-09-24

All desks

Loose ends

What was said and not done: 24 recorded, 20 open. Every desk adds to this list.

Open (20)

WhatSaid onWaiting onWhereDesk
sgit.ai's interview-page brief of 24 September describes a voice interview prompt as a new, reusable pattern and does not cite riskmandate.ai's feedback page (v0.13.0, 9 September), which has run the same shape since; riskmandate.ai's new interview page (v1.34.2) does not link its own feedback page either.
The feedback page is on riskmandate.ai (in the snapshot at sources/sites/riskmandate.ai/feedback.md) and the signal quotes it; what is missing is a link from sgit.ai's brief to it, and from riskmandate.ai's interview page to it. Recorded by the Architect from the voice-feedback signal (issue 033).
2026-09-24sgit.ai and riskmandate.aisource↗, source↗, source↗, source↗Architect
riskmandate.ai's pricing page marks level 3 (£500, corrected for your situation) "specified, never run", while store.sgit.ai's ledger says of the same level that "that work has been done many times", with six such vaults published.
The pricing page says its states were copied from the store's ledger on 15 September 2026; the store changed its wording on 16 September (its memo The homepage sells), separating work done from a sale through the store. The two pages now disagree on what the state means. Found by the Cartographer (maps/riskmandate-wardley), checked against the snapshot by the Editor.
2026-09-24riskmandate.ai and store.sgit.aisource↗, source↗, source↗Editor
The Risk Acceptance Office vault's README says its opening page "replays one invented risk over eight weeks", while sgit.ai's page for the vault says it "replays one invented risk over six weeks", and the replay on that page ends on day 42.
sgit.ai's version log (v0.6.5, 24 September) and its article Every risk is already accepted also say six weeks; only the README inside the vault says eight. Found by the Journalist (back catalogue A), checked against the snapshot by the Editor.
2026-09-24sgit.aisource, source↗, source↗Editor
sgit.ai's published vaults page opens with "Thirty-one vaults you can open in your browser right now", and its llms.txt entry for the page says the same, while the page's table lists 36 vaults, numbered 1 to 36.
The table's newest rows are the five business plans of 23 and 24 September (Company X-Ray is number 36). The summary line, which is what llms.txt and link previews carry, was not updated as the count grew. Found by the Journalist (back catalogue A), checked against the snapshot by the Editor.
2026-09-24sgit.aisource↗, source↗Editor
riskmandate.ai's brief register is headed "Ten files, in the order they arrived" and says it was "Last reconciled 16 September 2026", while it lists 23 briefs, several received on 24 September.
The register's own later heading, "Twenty-three items. None untouched, and none finished.", has the right count. The register is how sites check whether a brief was received, so its header matters.
2026-09-24riskmandate.aisource↗Librarian
sgit.ai's business plans page describes itself as holding two plans, Connector Twin and Agent as Webmaster, while its table lists five.
The page's description, which is what llms.txt and link previews show, names only Connector Twin and Agent as Webmaster. The table below it adds Company X-Ray, Lesson Loop and Risk Acceptance Office, all dated 24 September.
2026-09-24sgit.aisource↗Librarian
Which risk acceptance interval ladder is canonical: risks.sgit.ai's six rungs (an hour to six months, a month by default) or the bands on riskmandate.ai's "Accepted is not acceptable" page.
The Risk Acceptance Office plan lists "Which ladder?" as its first open question and uses risks.sgit.ai's for now. Nothing on riskmandate.ai refers to the question. See the signal on two ladders.
2026-09-24risks.sgit.ai and riskmandate.aisource, source, source↗Architect
riskmandate.ai and sgit.ai describe the same Sovereign AI R&D procurement challenge with different figures (contracts up to £10 million and challenge 3 on one; up to £5 million and challenge area four on the other), and whether to apply is undecided.
The two pages cite different official pages and do not link each other. On applying, riskmandate.ai says "We have not applied yet. Whether to is the lead’s decision, and this row will say what it was." Its dates list shows an expression of interest by about 17 November for the 1 December batch.
2026-09-24riskmandate.aisource↗, source↗Cartographer
standards.sgit.ai says there is no GDPR graph, while sgit.ai publishes a Standards Atlas GDPR vault that models GDPR as a navigable graph.
standards.sgit.ai (v0.1.4, 24 August 2026) says "There is no GDPR graph" and "THERE IS NO GDPR VAULT AND NO GDPR GRAPH". sgit.ai's published-vaults list dates the GDPR vault 25 August 2026, a day later. sgit.ai's partnership-risk brief flagged it on 24 September: "One of them needs updating".
2026-09-24standards.sgit.aisource↗, source↗, source↗, source↗Cartographer
The price of level 1 disagrees across sites: £10 on riskmandate.ai and on store.sgit.ai's /v1/ page, £5 on store.sgit.ai's /v1/policies/ and /paying/ pages.
riskmandate.ai corrected its own £5s to £10 in v1.22.0 and keeps one on purpose as a dated record. sgit.ai's partnership-risk brief noticed the disagreement but addressed it to riskmandate.ai; the pages that still say £5 are store.sgit.ai's.
2026-09-24store.sgit.aisource↗, source↗, source↗, source↗Cartographer
Two parts of the interview-page brief remain after the page was built: a run of the prompt in voice mode to check the summary comes back with every section, and sending the summary back into a vault through a lane that can only be written to.
riskmandate.ai says its agent has no account with the chat assistant, "so that run is the lead's", and that sending the summary into a vault "is marked in the brief as later". v1.34.4 lengthened the prompt; the register records a run of the longer prompt as the lead's too.
2026-09-24riskmandate.aisource↗, source↗Developer
sgit.ai's briefs index is stale: it still lists as open two asks that have been answered, the interview page (built by riskmandate.ai in v1.34.2) and the CLI read-key prefix (closed by sgit.ai's own v0.3.0).
Both entries read "Status: open" in the index built at site v0.6.8. The index's own convention for an answered ask is "acted on" with the release that did it.
2026-09-24sgit.aisource↗Cartographer
sgit.ai's brief asking riskmandate.ai for the risk side of every partnership page (two behaviour policies and a delta per provider) and for sgit written up as a control against GDPR has had no response from riskmandate.ai.
riskmandate.ai's brief register lists 23 briefs with their digests, and this one is not among them. Its releases v1.34.3 to v1.34.8 on 24 September answer other asks (the interview page, the role-ownership article and its figures). The brief was written the same day, so the silence is hours old at snapshot time; the interview-page brief of the same day was answered.
2026-09-24riskmandate.aisource↗, source↗, sourceCartographer
sgit.ai's vault server has been deployed on Azure and on Google Cloud by the founder, and neither deployment is documented; storage on S3-compatible stores other than Amazon S3 is untested.
The hub says "The founder has deployed it on Azure and on Google Cloud, but neither is documented yet" and that other clouds' S3-compatible stores are "the next step, not yet tested". The Azure page calls it "the clearest case of something that works and is not yet written down". The hub's one-line summary still says "Google Cloud planned", which refers to the guide, while its body says the founder has deployed there.
2026-09-24sgit.aisource↗, source↗, source↗Architect
Every partnership page on sgit.ai is a proposal, and none records a contact made: the fourteen cloud and AI provider pages and their two hubs each say there has been no conversation yet.
Each provider page and both hubs carry the sentence "there has been no conversation yet". The Sovereign AI page (23 September) says "There has been no conversation with the fund", and the key management call says "there has been no conversation with any organisation named on it". Nothing in the snapshot records a contact since.
2026-09-24sgit.aisource↗, source↗, source↗, source↗, source↗Cartographer
The founder's own padel vault, where Lesson Loop's phase one is to be tried first, is not yet published.
The vault page says "The founder already has a padel vault of their own, not yet published, where phase one will be tried first." The plan's table marks "A trial with real coaches and players" as "Next". sgit.ai's list of 36 published vaults has no padel vault.
2026-09-24the foundersource↗, sourceLibrarian
Seven riskmandate.ai release notes dated 23 September carry only a title and a placeholder: v1.29.3, v1.29.4, v1.29.5, v1.30.0, v1.30.1, v1.31.0 and v1.31.1.
Each note's body is "TODO: what changed, and why. One bullet per change, the reason first." followed by an empty bullet. These are the only notes in the snapshot with that placeholder; the notes either side (v1.29.2, v1.32.0) are written out.
2026-09-23riskmandate.aisource↗, source↗, source↗, source↗, source↗, source↗, source↗, source↗Librarian
newsroom.sgit.ai still presents pt.newsroom.sgit.ai as a brief and a design ("the site does not exist yet"), while pt.newsroom.sgit.ai is live at v0.23.13.
newsroom.sgit.ai's front page lists "pt.newsroom.sgit.ai (a brief for the next agent)". Its memo 14, in the same file, was written after reading pt.newsroom.sgit.ai's repository and live site on 14 September. See the signal on frozen, hashed sources.
2026-09-13newsroom.sgit.aisource↗, source↗Cartographer
Seven follow-up questions on append lanes went to the SG/API team, including whether the append endpoints are live on the dev server (every probe returned 404) and whether an append token can be told apart from a read key without harm.
sgit.ai's updates page says "Seven questions went back". No later source in the snapshot records an answer; sgit.ai's version log after 7 September does not return to them.
2026-09-07SG/API teamsource, source↗Developer
Four older cross-team asks from sgit.ai have no recorded answer: serial transfer mode for sgit under WebAssembly, a history-preserving vault rekey, first-class serialised diffs with ignore support, and the SG/Send API's CORS allow-list missing x-api-key.
The first three are marked "Status: open" on the briefs index; the CORS finding has no status line and the site works around it by dropping the header client-side (sgit.ai v0.1.11, 11 August). Given that the read-key ask was closed without the index noticing, some of these may also be answered; the snapshot does not show it.
2026-08-11sgit CLI team and SG/Send API teamsource↗, source↗Developer

Unclear (2)

WhatSaid onWaiting onWhereDesk
Two CLI transport bugs found while publishing the Agent as Webmaster vault (a fresh vault's first push flipped to the read-only static transport, and push, pull, fetch, status and delete ignored --transport) are described as fixed in the CLI repository. No source says whether the fixes have reached a released CLI version.
sgit.ai's v0.6.0 note says both were "fixed in the CLI repository with a pinning test", and the vault page says "Two fixes went into the CLI repository from this session". The seed's lead, that the fix sits on a local branch not yet landed, is not stated in any source we read, and the CLI branch log in the seed holds only brief commits. No source names a CLI release that carries the fixes.
2026-09-23sgit CLI teamsource↗, source↗, sourceDeveloper
The counts of old-prefix read keys on sgit.ai do not reconcile: v0.2.98 left 99 published keys across 27 pages on the legacy prefix, and v0.3.0 the same day moved 102 legacy-prefixed and 24 bare keys to the public-read prefix.
v0.2.98: "99 published keys across 27 pages still carry the legacy rk1 prefix". v0.3.0: "102 published read keys under sgit_rk1_ and 24 bare ones now carry sgit_public_read_". Neither note explains the difference of three; it may be counting (keys against occurrences) or pages added between the releases, and the notes do not say.
2026-09-20sgit.aisource↗Librarian

Closed (2)

WhatSaid onWaiting onWhereDesk
sgit.ai asked riskmandate.ai for an interview page: a link sent to one person, with a prompt that interviews them by voice and writes up their feedback, the first for a founder strong in UK events and marketing.
Built the same day. riskmandate.ai v1.34.2 calls interview-founder-marketing "The first interview page", with the brief's six parts in order and the pattern as a template; v1.34.3 put it on the live site. Two named parts remain with riskmandate.ai's lead (see the follow-up loose end). The ask is closed; sgit.ai's index does not yet say so.
2026-09-24riskmandate.aisource↗, source↗, source
closed by↗, closed by↗, closed by↗
Cartographer
The CLI did not accept the canonical prefixed read-key form that the web loader accepts: given the prefixed key it derived the wrong ref and failed, while the bare form worked.
Found on v0.14.27 and confirmed on v0.15.0 on 17 August. sgit.ai's v0.3.0 note (20 September) says re-running the comparison suite "closed it, all six checks pass on sgit-ai v0.16.2 including prefixed clone succeeded". The briefs index still shows the ask as open.
2026-08-17sgit CLI teamsource↗, source↗
closed by↗, closed by↗
Developer