sgit newsroom v0.1.29 · snapshot 2026-09-24

signal · 2026-09-24

The key management call names one business plan; two more depend on it

sgit.ai's key management call cites one business plan, Agent as Webmaster, as its case that keys are multiplying; two more plans published on sgit.ai the same day, Lesson Loop and Company X-Ray, depend on easy key handover, and the call does not mention either.

sgit.ai → sgit.ai new

Suggested action: give the authors of sgit.ai's key management call the Lesson Loop and Company X-Ray pages as evidence of demand, and give the X-Ray plan the call's link

The pages this piece is about

sgit.ai's key management call cites one business plan, Agent as Webmaster, as its case that keys are multiplying; two more plans published on sgit.ai the same day, Lesson Loop and Company X-Ray, depend on easy key handover, and the call does not mention either.

Lesson Loop says so and links the call; Company X-Ray relies on it without linking it.

Side A: the call

Who holds the keys?↗, published on 24 September 2026 in sgit.ai v0.6.2, says "We are looking for a key manager, not building one." Its evidence that keys are multiplying includes agents that hand work over as vaults. It names Agent as Webmaster, "a business plan built on exactly that. Every one of those hand-overs is a key that has to go to a person, safely".

It asks for a way to "share a vault with someone else by sending a short name in plain words rather than the key", and for revocation.

Side B: two plans that need it

Lesson Loop (sgit.ai v0.6.6, vault page↗). Its architecture file, 03-architecture.md, has a section called "The one hard part":

"Key management. A player has to keep a vault key safe, hand out read keys to coaches, and take them back. That is the problem sgit.ai's call for collaboration with password managers and identity providers exists to solve."

Its table of what exists today lists "Easy key handling for players and coaches" as "Open", with the call's address.

Company X-Ray (sgit.ai v0.6.8, vault page↗). Its architecture file hands keys out at two points: after delivery, "The customer can copy the content into a fresh vault whose key only they hold", and read-only keys "let the customer give their accountant or chair a view without giving them the ability to change anything." It does not mention the key management call.

What we checked