# Loose ends

- [open] The founder's own padel vault, where Lesson Loop's phase one is to be tried first, is not yet published. (waiting on the founder)
- [open] Every partnership page on sgit.ai is a proposal, and none records a contact made: the fourteen cloud and AI provider pages and their two hubs each say there has been no conversation yet. (waiting on sgit.ai)
- [open] sgit.ai's vault server has been deployed on Azure and on Google Cloud by the founder, and neither deployment is documented; storage on S3-compatible stores other than Amazon S3 is untested. (waiting on sgit.ai)
- [open] sgit.ai's brief asking riskmandate.ai for the risk side of every partnership page (two behaviour policies and a delta per provider) and for sgit written up as a control against GDPR has had no response from riskmandate.ai. (waiting on riskmandate.ai)
- [open] sgit.ai's briefs index is stale: it still lists as open two asks that have been answered, the interview page (built by riskmandate.ai in v1.34.2) and the CLI read-key prefix (closed by sgit.ai's own v0.3.0). (waiting on sgit.ai)
- [open] Two parts of the interview-page brief remain after the page was built: a run of the prompt in voice mode to check the summary comes back with every section, and sending the summary back into a vault through a lane that can only be written to. (waiting on riskmandate.ai)
- [open] The price of level 1 disagrees across sites: £10 on riskmandate.ai and on store.sgit.ai's /v1/ page, £5 on store.sgit.ai's /v1/policies/ and /paying/ pages. (waiting on store.sgit.ai)
- [open] standards.sgit.ai says there is no GDPR graph, while sgit.ai publishes a Standards Atlas GDPR vault that models GDPR as a navigable graph. (waiting on standards.sgit.ai)
- [open] riskmandate.ai and sgit.ai describe the same Sovereign AI R&D procurement challenge with different figures (contracts up to £10 million and challenge 3 on one; up to £5 million and challenge area four on the other), and whether to apply is undecided. (waiting on riskmandate.ai)
- [open] Seven riskmandate.ai release notes dated 23 September carry only a title and a placeholder: v1.29.3, v1.29.4, v1.29.5, v1.30.0, v1.30.1, v1.31.0 and v1.31.1. (waiting on riskmandate.ai)
- [open] Which risk acceptance interval ladder is canonical: risks.sgit.ai's six rungs (an hour to six months, a month by default) or the bands on riskmandate.ai's "Accepted is not acceptable" page. (waiting on risks.sgit.ai and riskmandate.ai)
- [open] Seven follow-up questions on append lanes went to the SG/API team, including whether the append endpoints are live on the dev server (every probe returned 404) and whether an append token can be told apart from a read key without harm. (waiting on SG/API team)
- [open] sgit.ai's business plans page describes itself as holding two plans, Connector Twin and Agent as Webmaster, while its table lists five. (waiting on sgit.ai)
- [open] newsroom.sgit.ai still presents pt.newsroom.sgit.ai as a brief and a design ("the site does not exist yet"), while pt.newsroom.sgit.ai is live at v0.23.13. (waiting on newsroom.sgit.ai)
- [open] riskmandate.ai's brief register is headed "Ten files, in the order they arrived" and says it was "Last reconciled 16 September 2026", while it lists 23 briefs, several received on 24 September. (waiting on riskmandate.ai)
- [open] Four older cross-team asks from sgit.ai have no recorded answer: serial transfer mode for sgit under WebAssembly, a history-preserving vault rekey, first-class serialised diffs with ignore support, and the SG/Send API's CORS allow-list missing x-api-key. (waiting on sgit CLI team and SG/Send API team)
- [open] sgit.ai's published vaults page opens with "Thirty-one vaults you can open in your browser right now", and its llms.txt entry for the page says the same, while the page's table lists 36 vaults, numbered 1 to 36. (waiting on sgit.ai)
- [open] The Risk Acceptance Office vault's README says its opening page "replays one invented risk over eight weeks", while sgit.ai's page for the vault says it "replays one invented risk over six weeks", and the replay on that page ends on day 42. (waiting on sgit.ai)
- [open] riskmandate.ai's pricing page marks level 3 (£500, corrected for your situation) "specified, never run", while store.sgit.ai's ledger says of the same level that "that work has been done many times", with six such vaults published. (waiting on riskmandate.ai and store.sgit.ai)
- [open] sgit.ai's interview-page brief of 24 September describes a voice interview prompt as a new, reusable pattern and does not cite riskmandate.ai's feedback page (v0.13.0, 9 September), which has run the same shape since; riskmandate.ai's new interview page (v1.34.2) does not link its own feedback page either. (waiting on sgit.ai and riskmandate.ai)
- [unclear] Two CLI transport bugs found while publishing the Agent as Webmaster vault (a fresh vault's first push flipped to the read-only static transport, and push, pull, fetch, status and delete ignored --transport) are described as fixed in the CLI repository. No source says whether the fixes have reached a released CLI version. (waiting on sgit CLI team)
- [unclear] The counts of old-prefix read keys on sgit.ai do not reconcile: v0.2.98 left 99 published keys across 27 pages on the legacy prefix, and v0.3.0 the same day moved 102 legacy-prefixed and 24 bare keys to the public-read prefix. (waiting on sgit.ai)
- [closed] sgit.ai asked riskmandate.ai for an interview page: a link sent to one person, with a prompt that interviews them by voice and writes up their feedback, the first for a founder strong in UK events and marketing. (waiting on riskmandate.ai)
- [closed] The CLI did not accept the canonical prefixed read-key form that the web loader accepts: given the prefixed key it derived the wrong ref and failed, while the bare form worked. (waiting on sgit CLI team)
