Risk Mandate — agents act, and someone has to own the risk
Risk Mandate begins where security stops — acceptance, funding, and ownership. No risk can be denied, only accepted for an interval and underwritten to the board.
Source: https://riskmandate.ai/acceptance.html↗
Agents act.You ownthe risk.
Security stops at the vulnerability. Risk Mandate begins where security stops — surfacing each risk so clearly, and routing it so precisely to the person who owns it, that the business funds the fix.
Security stops at the vulnerability. We begin where security stops.
Security tools are very good at finding issues. Then the trail goes cold — because the questions that decide the outcome live in a different world entirely: budgets, ownership, accountability, escalation.
That gap is where the real damage lives. Risk Mandate is the layer for what comes after the finding: acceptance, funding, and ownership.
There is no deny button.
For a deployed system, the agent already has access. You cannot deny a risk that has already materialised — pretending you can is how risk registers quietly drift into fiction. So we removed the deny button.
Accept or deny isn't the decision. How long, who owns it, what's funded.
The interval is the mandate and the priority: sign off for an hour and it's fixed within the hour. In the product it looks like a queue you work — trifecta status, exposure clock, a time-bound decision on every item.
A mandate is the right to act.
Every agent acts on delegated authority — what it may do, who granted it, and for how long. That delegation is a mandate. Agents now read untrusted content, reach the internet, and take actions on their own — the lethal trifecta — while the governance tooling that exists was built for software that does not act.
Governing the right to act — capturing the moment of authorisation, computing the blast radius, binding it to an owner — is the work of the next decade of security.
You hold the keys, not us.
The register is not a spreadsheet. It is a semantic graph — facts only, so everything in it is real — where every change cascades to the top and the picture is never silently stale.
All of it stands on SG/Vault: sovereignty, no lock-in, and a foundation that is agentic-native rather than agentic-retrofitted.
Maturity you compute, not claim.
Every acceptance you make here is a durable graph decision — owned, evidenced, time-boxed, appetite-bound. That's not just good hygiene: it's measurable. RAMM turns the five maturity levels into queries your acceptance graph either satisfies or doesn't, so using Risk Mandate is how you climb them.
Each level is a Node Type Formula — a path-pattern over the acceptance graph, tested by query, not asserted in a questionnaire.
Split by value. Free, consumption, custom.
Every tier runs the same product on the same zero-knowledge foundation. What changes per tier is how it's operated — its maintainability, scalability, and security posture — not which features are gated.
- MAINTAINOpen source, files and folders, no database to operate — no lock-in.
- SCALEAdopt incrementally: as much or as little as fits your stack, at your pace.
- SECUREZero-knowledge vault on your own infrastructure — your keys, your data.
- MAINTAINManaged runtime — versioned, provenance on every change, agent-operable.
- SCALEGrows with usage; pre-approval against risk profiles keeps acceptance scaling without nagging.
- SECURESame zero-knowledge foundation — plaintext never leaves your endpoints.
- MAINTAINSLAs, support, and guided upgrades across the version chain.
- SCALEThe underwriting chain org-wide — acceptance propagated level by level to a board view.
- SECURESovereign deployment: your region, your keys; NIST / ISO / EU AI Act alignment.
Value grows up the ladder; the security model does not change. Sovereignty is the floor, not the premium.
Lower the probability of catastrophic outcomes.
Map your autonomous risk. Accept what exists. Fund what matters. Prove you're getting safer.
Autonomous risk management for systems that act.
PRODUCT
RESOURCES