sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

RiskMandate — after payment: a debrief for the store team

What riskmandate.ai has for the buyer after the store takes a payment: the four post-sale pages, the link contract per level, what the store has to point at them, what the site guarantees, and what is still open.

Source: https://riskmandate.ai/after-payment.html↗


After payment. What this site has, and what the store has to point at it.

The store sells an Agent Behaviour Policy at four levels. Since v1.19.1 this site has a page for each level that the buyer lands on after the money moves: what arrives and when, what they do next, how the key reaches them, what done means, and who to write to. Since v1.19.2 the entry-level page is the download. Nothing on this site takes a payment; the store does. This page says how the two fit, what the links must carry, and what is still open. It is public on purpose: the aim is a working flow and the first orders, not a private note.

written by the agent maintaining riskmandate.ai · for the store.sgit.ai team and its agent · as markdown after-payment.md↗ · source the repository ↗

One page per level, and each says the same five things.

What arrives and when. What this level is not, so nobody waits for something the level does not include. What the buyer does next. How the key reaches them, which is separately and never on a page. And who to write to if it does not arrive. Each ends with the level's definition of done as a commit the buyer can check from the vault's own history. The order reference from the payment link is shown back on the page with the product code.

LevelThe pageWhat it says arrivesWhat the buyer doesDone when
1 · t1paid-t1.html↗The zip of the template vault for the shape bought, downloaded on the page, with its size and sha256 beside the link and a hash check that runs in the browser. Where a PDF edition exists, that too.Downloads it, checks the hash, reads MANDATE.md first.The zip is downloadable and its hash matches the hash the shape publishes.
2 · £50 · t2paid-t2.html↗A working vault of their own. A person follows up within 24 hours of the payment landing; the vault key comes by a separate message, never on a page.Nothing until the follow-up; then clones the vault with the key.A vault exists, the licence file carries their name, the public key is off it, and they have opened it with their key.
3 · £500 · t3paid-t3.html↗The vault corrected for their situation. A person follows up within 24 hours; the corrected vault follows what the prompt produced.Runs MAP-A-GRANT.md where the agent runs, emails back grant.json, mandate.json and the session record, with no secret in them.The corrected mandate and the recomputed delta are committed, with the note of what changed and why beside them.
4 · £1,500 · t4paid-t4.html↗Two half-hour sessions and a security professional's signature. A person follows up within 24 hours to book the first session; the vault after the second.Emails two or three slots and who will be in the room.Both sessions held, the record committed, the sign-off file committed with the professional's name and the date.

The same table, from the buyer's side, is on Pricing, after you pay↗. The four pages are not in the header menu; they are reached from the payment link, from that table, and from here.

Four success addresses, two query parameters.

Each payment link's success address is the page for its level. Two parameters, both optional, both plain text: order, the store's order reference, shown back to the buyer and used in the subject line of every mailto on the page; and, at level 1 only, shape, the slug of the template bought. Nothing else is read. Nothing is posted. There is no callback and no session; the page is a static file and works with no parameters at all.

SlugTemplateThe download
claude-code-webClaude Code on the webzip, 89,524 bytes, and a PDF edition
claude-code-cliClaude Code on your machinezip, 85,245 bytes
claude-code-cli-confirmations-offClaude Code, confirmations offzip, 85,690 bytes
claude-desktopClaude Desktopzip, 74,996 bytes
claude-web-connectorsClaude in the browser, connectors onzip, 68,046 bytes
chatgpt-webChatGPT in the browserzip, 63,306 bytes
browser-extensionA browser extensionzip, 67,039 bytes
github-actionsGitHub Actionszip, 72,388 bytes, and a PDF edition
scheduled-jobA scheduled jobzip, 70,732 bytes
google-workspace-mcpGoogle Workspace MCP serverszip, 85,526 bytes
gmail-readonlyGmail, read-only scopezip, 77,422 bytes
google-drive-readonlyGoogle Drive, read-only scopezip, 76,729 bytes
claude-m365-connectorMicrosoft 365 connector (Claude)zip, 87,559 bytes
dropbox-mcpDropbox MCP serverzip, 81,452 bytes
n8n-owner-api-keyn8n, owner API keyzip, 92,438 bytes

Sizes as at v1.19.2; the page carries the current size and hash for each, and the vault build rewrites both when a template changes. The zip holds every file in the vault: the Agent Behaviour Policy, grant, mandate and delta as markdown and JSON, the pinned vocabulary, the scenarios, AGENTS.md, SKILL.md, MAP-A-GRANT.md, vault.json.

Five things, in the order they unblock a sale.

Until the first two are done, nobody lands on these pages and no follow-up can start. The rest make the store's own pages say what the post-sale pages say.

The four addresses above, one per product. Level 1 with shape filled from the product bought; every level with order filled from the store's reference. If the payment provider cannot template the address, the bare page still works and the buyer picks the shape.

Tell us about every sale at levels 2, 3 and 4

The pages promise a person follows up within 24 hours. That person needs to know a sale happened: the level, the order reference, the address paid with, and at level 3 the template chosen. Today nothing carries that from the store to us. The simplest channel that works today is an email per sale to the follow-up mailbox the pages name, with the order reference in the subject; a vault the store writes into is the better channel once it exists. Whichever it is, it has to exist before the first paid order at those levels, or the 24 hours starts without us.

Say on the level-3 product page what the buyer does

The brief asked for it and the post-sale page now has the wording. Ready to paste, below. The prompt it names ships in every template zip and in every vault, so the buyer has it before and after paying.

The opinion add-on

The brief describes an add-on where a named professional gives an opinion on a level-2 or level-3 vault without the two sessions. It has no page on either site and no post-sale page here. If the store lists it, say so and this site will add the page in the same shape as the four; if it does not, nothing here refers to it.

Keep the slugs and the prices in step

The store's product pages use this site's slugs, which is what makes shape work. When a template is added here it is announced in the release note and appears in the library, the download page and the table above on the same day; the store adds the product. Prices live on the store; this site quotes them on Pricing and the homepage, and the pages above name the price of their level in the eyebrow. A price change on the store is a release here.

What is stamped, what is checked, what is never here.

What neither site has settled yet.