sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

RiskMandate — the brief register

Every document this site was built from, what it produced, and what it did not. Kept with a digest per file so nothing is worked twice and nothing is quietly dropped.

Source: https://riskmandate.ai/briefs.html↗


Everything we were given, and what came of it.

This site is built from briefs written elsewhere. Two things go wrong with that arrangement: the same document gets worked twice, and a document arrives and is never worked at all. Both failures are invisible unless somebody keeps a list — so here is the list, with the digest of every file as it was received and an honest status against each one.

Two failures, one list.

Neither of these is hypothetical. One of the documents below arrived twice, byte-identical, six hours apart — and three Lab entries had already been written from it. Without a digest to compare, the only thing standing between that and a wasted afternoon is somebody's memory of a filename.

StatusWhat it means
ProcessedprocessedRead in full, and something on this site exists because of it
PartlypartlyRead in full; some of it is built and a named part is not
ReceivedreceivedArchived and read, and nothing has been built from it yet
SupersededsupersededLater material replaced it. Kept, because the reasoning is still the record

Ten files, in the order they arrived.

Each one is linked in full, as received, with nothing edited. Where a brief and this site disagree, the brief is what we were given and the site is what we concluded — and where we corrected a brief, the correction is on the page rather than in the file.

The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The Template Vault Is The Product

sha256 1b2dfa45d228be6b0f6eb6a420090da160e979fe0b347048588565441a9f6e38

This is the one that arrived twice. Byte-identical both times, and the second arrival came in the same message as D3 and D4. It was not reprocessed — the three Lab entries below were already written from the first copy. This entry is the reason the register exists.

This Is The Tier One Application Nobody Could Find: The Connector List Alone Is Twenty Bits, So Compute Locally And Submit Banded

sha256 11ff8f5f9eebb9200d30694381ff27c7e53a59417dd92f1a0461bbfe1b65ad89

One correction to this brief is stated on the page it produced, and marked as ours. The brief treats banding as the fix. Worked through, banding is the necessary first move and not the whole answer, because a banded submission still carries roughly the entropy of the fingerprint study the brief benchmarks against. The page shows the assumptions so somebody can check the arithmetic.

The Commit Author Is A Free Text Field: A Prompt Shifts The Odds, And Every Documented Fix Was Architectural

sha256 b54eddae92bc88d8133c1e544c339433972ef6cf8cf8656ac4771b7ffbce7ccd

The finding and the prompt are built; the experiment is not. All six load-bearing quotations were fetched and checked against their sources rather than relayed — which produced two corrections to this brief, both stated on the page it became: the partially verified state additionally requires the author to have enabled vigilant mode, and the claim that the attribution renders a profile picture and a profile link could not be found on the page cited.

The Urgency Is Not A Deadline But A State: You Already Connected It, And A Distributed Skill Cannot Carry A Control

sha256 af73131b6a72bb5f6d8aad1563f124a016040833310df0fb8be717ec44bb0e56

Both of its rulings are now on the site. The entry product says it reduces accidents and does not stop an attacker, in those words, on the page carrying a price — and the behaviour policy is not sold as a skill, because the portable part of that format cannot carry a constraint. The word for the narrowing cover does not appear on the pricing page at all; the authorise question stands in its place.

Startup Summit 2026 — exhibitor booth guide

sha256 d13e3f08729fa8ffaab7f4e1d247535fb0782c5182df67e365ef61d52ca0cf3d

Third-party material, and it corrected three of our own planning assumptions — the banner is not permitted, submissions go through the exhibitor portal rather than by email, and power has to be requested rather than assumed. Kept on a working page rather than a public one; whether it stays fetchable here at all is an open decision.

Every Routable Address Is In The Grant: Do Not Attack Anyone Is The One Rule Everybody Signs, And It Is The One With No Barrier

sha256 b85fdbcb235b352150d5b806e58b4d525414a8c0a7ac11382a697f2f78127eb7

Seven load-bearing quotations were fetched and checked rather than relayed, including the reference container's firewall script. Two departures from the brief are stated on the page it became. It reports observing an agent's two egress paths diverge in one session; in ours they did not — both reached every host tried — so the finding rests on the vendor's own sentences rather than on that observation. And we published a measurement of this machine's own egress instead, which found a raw outbound socket to an arbitrary public address and working name resolution, with no allow list standing in either path.

ABP Graph and Stakeholder Views — the policy is a graph, and every stakeholder gets a projection of it

sha256 d93b0fdc381a166dd0044b024031c9ee60a789533f7efc91ff3dafe4248afa90

A voice memo, transcribed, and the transcriber wrote the acronym as ADP throughout. It is the spoken ABP; the archived bytes are kept exactly as received, which is the rule, and the correction is here rather than in the file. The memo was worked into a brief on the day it was spoken and the file registered when it arrived, with D8.

Use Case Driven ABP Policy Strategy — a policy per use case, and the £500 level is a prompt the customer runs

sha256 8457a6637e212c0b91b2186efda1857836dc660deed3e328e796a267ab9e45ac

The four price points in the memo are the four levels the store put live the same day (store.sgit.ai v0.1.7, 15 September): £5, £50, £500, £1,500. The memo's contribution is what the £500 level actually is — a prompt the customer runs in their own environment, whose output we turn into their policy — and the idea of a policy per use case, with our own Voice Debrief workflows as the first two.

The offer is built and the button is not — each level is the level below plus one thing, and the post-sale page does not exist yet

sha256 99e75be33f0989f6060b5acec058c34a13531b3d6bf54fc53e9cb5e65a23f3ff

The brief's finding is that the four levels are priced and described and nothing happens after the money moves. Its rule for the ladder — each level is the level below plus one thing — was already true of the pricing page and is now said on it. The part this site owns is the page a customer lands on after paying, one per level; the payment links and the store's own product pages are the store's.

Risk Mandate Website Repositioning Strategy

sha256 ab6f9486ecae99de444ff7bfe0aa4c7a95badcdd01fb12b795eec7ec852984eb

The first brief that asked for something to come off the home page rather than go onto it. Its argument is a chain: our job is to make agents insurable; an agent is insurable when the organisation has authorised it in a way that survives examination, which is a licence to operate; a licence to operate needs a behaviour policy to be a licence for anything. So the ABP is sold first — it exists, it is the lowest touch and it can be delivered today — and the insurance thinking is kept in full rather than lost, on a page of its own. One departure while implementing it: the brief names three audiences, and a fourth, investors, is already written up on the Lisbon page, in the store and on the printed sheets. Three pages were built and the fourth is named as missing rather than quietly dropped.

The named professional, and the assignment of the individual who does the £1,500 review

sha256 d376355f1747cc88986a623b91592bee5a5ec3b73f3ac838c43687f7a8fb53eb

The first brief about a person rather than a document. A consultant has agreed to take some of this work, so the top level needs two things written down: what the service actually is — the workflow, the timelines, the expectation on both sides — and who does it, as a page carrying the record, the experience and the declared interests, so that a buyer chooses the individual rather than a logo. The brief asks for the lead’s own page first and the second consultant mapped from it. Built as a generated family from one file per reviewer, because the store reads the same data for its chooser and two sites must not end up saying different things about the same person. The second reviewer is published as a labelled placeholder rather than a name, which is what was asked for: the shape can be read before anybody is asked to fill it in.

How it technically works: prompts first, then hope is not a control, then fit, integrate, graph, and the vault as provenance

sha256 dadd026e61c5653ea7789c5f8e852900cc4d1bef8f852ea9846719bd9ba91791

Prompted by a peer asking, in a chat, “how does it technically work?” The page called How it works answered with an architecture that predates the Agent Behaviour Policy — twins, a RiskGraph, engines, board briefings, an API — none of which is what is sold, and one line of which, twins instead of integrations, said the opposite of the memo. The memo gives the order: start with a prompt because being surprised by the reach is the shift; notice that asking an agent to behave is hope rather than a control; fit the policy to whatever controls actually exist; integrate with whatever the customer runs, connectors built per engagement; connect it all as one graph to risks, standards and internal policies; and keep it in a vault because the vault is the provenance. Rebuilt in that order, with a status chip on each step.

UK support, in the open: consolidate what the UK offers a startup at go-to-market, ask people what is missing, and let other founders use it

sha256 0c528b8c5736930b4a4a87b5e816f38af0758a2cd42eb1ad9df6e0904eceeecc

The product is ready and the challenge is now users. The memo asks for one public page, modelled on the partnership pages on sgit.ai, that consolidates the UK’s support for a London startup at this point: departments, programmes, events, and the kind of government-sponsored travel founders remember. It serves three readers: people the lead knows, asked whether anything is missing; other founders, who can use it; and RiskMandate, which records what happened at each door.

Pilots do not stay in production: the business sees the gap between mandate and reach, at machine speed, and declines to sign for it

sha256 762fd1ea85c2d701f304331d507374b7668ec41bae90788498c2221cd7ac6e53

The real metric is not whether a pilot reached production but whether it stayed there. The memo’s hypothesis: a pilot proves the agent can do the task in a curated world; production asks what else it can do, how many times, how fast, and on whose authority; and when the business models that, it declines to sign. It asks for the data behind it, for examples, and for the answer the site sells: limits in business units, set at design time.

Calendar edits cannot be undone: integrity risk, and why the edit permission is the dangerous one

sha256 0349fc94e7df55c387bd3a2a1e8adb413c0bd742759ff671ad47d7ef7979df84

A finding from drafting Calendar behaviour policies. Google Calendar has a trash for deleted events but no way back from an edit, so an agent that edits many events leaves corruption that looks like a real calendar. The memo asks for the facts to be checked, including the trash period and who can restore; for the calendar-over-email point from early users; and for the conclusion: map each action by whether it can be undone, because an edit with no undo exposes more than a delete with one.

Business cases by risk reduced: the register without a security product and with it, from the operator to the board, starting with our own

sha256 1dabf7f55b1cef3af6cacef62d5fcd0c46d0adb58ea96277cff8e7e79926dade

A section rather than an article, and win-win-win. The business case for a security product is the risk register without it and with it, at every altitude from the operator to the board. Start with RiskMandate’s own product, including what a hope-level instruction to the agent is worth; research the categories of security product for agents; pick targets; publish the cases and use them to start conversations with the vendors. The memo asks whether earlier work already covers the risks and their owners: it does, in the RiskGraph Explorer vault, and the section runs on that model.

OWASP and open source first: a semantic graph of OWASP, business cases for the open-source projects that reduce risk, and the companies built on open source

sha256 3686c72fb430e18cf55612574ae81e302b61475c4f207bec62a2bbd780a42ca8

Start the business cases with open source, and with OWASP in particular. The lead is closely involved with OWASP and wants to bring RiskMandate’s ideas and standards there. The memo asks for a semantic graph of OWASP, which it says does not exist, zoomable from the foundation to one item because every document has its own ontology joined to a wider one; for cases for open-source projects that reduce risk, since free is never free and customising is the work; and for the companies built on open source, to connect with.

A behaviour policy for everybody the lead talks to: a brief and a zip for a new agent, three vaults, and controls so nothing leaks across

sha256 db4b98aef049e05716c3789105ce4a56e4e96fd0939774fd912bea329c8b7624

Users, one conversation at a time. After talking to somebody, the lead gives a new agent a zip, a website and a sentence; the agent researches the organisation’s public pages and builds an Agent Behaviour Policy vault for them, to send as a demo they can correct and try. Three vaults: one for the keys, one for the UI, one per person, with controls so nothing leaks from one person to another, and each person’s vault written so it could be public one day.

An interview page, and a ChatGPT voice prompt to run it: a reusable pattern, and the first page, for a founder who knows UK events and marketing

sha256 c4734574a34364f4e5837a05197a207430ed8429e8fa17bf64332f73219910c4

Expert feedback from people whose knowledge is in their heads. Asking a busy founder to read a site and write feedback rarely works; asking them to talk for twenty minutes usually does. The brief asks for a page that carries a prompt the reader pastes into ChatGPT, which interviews them by voice and writes a structured summary they send back: a reusable pattern of six parts, and the first page on it, for a founder who is good at UK events, marketing and content. The prompt is to be used exactly, changed only where the site states a fact differently.

Ask the ABP questions in the interview, and answer a LinkedIn role map as a stand-alone article: a generic framework, adjusted in every company, with accountability that holds on the way up

sha256 2219d9a051791da925288f494be02fdbcf9a05709b12a70acc42ec4ff565d6ab

Two asks in one note. First, the founder interview should also ask about the Agent Behaviour Policy itself: its name, whether it can be explained, what it adds, whether the market understands it, its value to the people who would use it, and whether it should sell. Second, an article of a kind the lead wants to write more of: take something strong seen on LinkedIn, here a map of who owns what in AI by role, and show our world on top of it. The map is a generic framework, as ours is, and every company adjusts it; what risk acceptance and the ABP add is the connection that keeps accountability intact on the way up. Written as a full document, so the details can be implemented.

Graph visualisations for the role-ownership article: the blast radius as the employee connects and disconnects, the flows played out, the evidence, and the settings a mail scope cannot narrow

sha256 524b59f30d4407f354272061f0e9c10e0ed45d5161d9ef19ad8007324a03bf5f

Show it, not only say it. The article has the ontology and the taxonomy at the bottom, so draw them: a series of visualisations, animated in the page, that show the interconnection, the blast radius growing as an employee connects the assistant to their mail and shrinking when they disconnect it, the flows played out, and the evidence. Include the settings that cannot be prevented: a mail scope grants the whole mailbox, and what the behaviour policy adds is instructions and a mandate narrowed to one business process.

Risks always flow upwards: the roles above carry the aggregate, click a role to see what it holds, list every risk that holds now, and show the level of risk the business already accepts against the gap outside it

sha256 19de617c22e7226307413fbee045912c6af4fe56c453db8010d98209747c31a1

A risk does not stop with its holder. The first figure implied it did: connect the CRM and two risks sat with the CIO and Sales. They reach the CTO, the CEO and the board, and the people at the top get the aggregate; the CEO carries the calendar risk and the mail risk both. So: light the path upward, let each stakeholder be clicked to see the risks they carry, list every risk that holds at any moment, and show that reading the rep’s own mail is a risk the business already accepts, which is different from reading every mailbox the account can open. Drop the roles nothing reaches; keep Legal and the CFO.

Red travels up the path, and a control does not make a risk zero: it leaves a green one. Enough controls, including a proxy in the middle, to make every path green; risks for the CFO and Legal

sha256 d47dbfda7dd3e53314dc72b41922ae0a723cfd13202722bd468488be5ff2560a

Two details, and a scenario the figure could not yet show. The rep’s path was green while the CEO’s and the board’s stayed green above a red risk; if a role carries a red, its path is red. And there was no way to make everything green: add enough controls, such as a proxy in the middle that carries out the actions, and the functionality should be all green, because the green risks are the functionality, accepted once the controls are in. As controls go on, the risks should be seen going down. Risks for the CFO and Legal were missing. Take the controls as working, for now.

And the instructions that arrived as speech or a sentence.

These have no digest to check, which makes them the ones most easily lost — a voice memo that changed the direction of the whole site leaves no artefact at all unless somebody writes it down. So they are recorded here in the same list, with the same two columns.

Put the Agent Behaviour Policy at the centre of the site. The ABP is the fundamental primitive; the grant is calculated from reality via digital twins; RiskMandate drives the sale of ABPs, and those are the first batch of customers; the audiences are corporate users, investors and founders; and a security vendor whose controls reduce the delta has a business case we can make for them.

The Startup Summit exhibitor pack and the event site, for a strategy document and the materials we need to submit.

Hire a freelancer who also works through agents. Give them a page and a first prompt focused on making sales online and at Lisbon, and make their first task being a power user and tester of behaviour policies.

Preserve the Lab's thinking as it changes, and publish it as files that can be sent through a chat app — because by the time a reader follows a link, the page has moved on.

Answer the questions people actually ask in public, with the standing rule that the site never names who asked. Two public comments were supplied as the first two questions, and answers that outgrow a section get their own page.

Build a specific vault for Claude chat connected to a Gmail inbox, capture the connection screens with the address obscured, and map the whole customer workflow — the vault, its home page, the settings, the permissions, the prompts given to Claude — as the purchase workflow. Do not use the agent's name.

Where is the new Claude + Gmail section; publish the vault; give the Gmail workflow brief a page in the admin section, in a way that takes many briefs; and rebuild the admin section to the structure, layout and capabilities of store.sgit.ai/admin/ and the newsroom console at pt.newsroom.sgit.ai/newsroom/.

Make the Gmail-connector vault the first MVP vault, with a solid end-to-end experience and the design template every other vault reuses; global changes to the code vault are fine. Start from the store's V3 marketplace mock-up — the vault panel with its left navigation, the positioning of the vault — and the store's table of what each level gets you, including the dual licence.

The material to add to the Gmail-connector vault. Go back to first principles on the grant and map its side effects: a grant is the union of capabilities, and the reader needs the consequences — each explicit, each tied to the asset that makes it real (secrets in mail, reset links, mail from others). Count the routes out. Authorisation to read is not authorisation to forward. Harvesting, mass send, what makes a platform suspend an account, mass change to the inbox's filing. Realistic scenarios on the mandate; standards as mini-graphs in the vault; the vault navigated as a website with materials per audience.

Check us, rather than trusting us.

The whole point of a digest is that somebody else can compute it. If you produce these documents, you do not have to take this page's word for what arrived — hash what you sent and compare.

Every document is recorded by the SHA-256 of the file exactly as we received it. Hash your copy, look for the digest in the register, and anything that is not there did not reach us — or reached us and was not archived, which is our bug and worth telling us about.

# what did we actually receive?
curl -s https://riskmandate.ai/briefs-register.json \
  | jq -r '.documents[] | "\(.sha256)  \(.status)  \(.title)"'

# is the brief I just sent in there?
sha256sum my-brief.md

A register that only lists what was done is a press release.

Every entry above carries what it asked for and did not get, and on most of the twenty-three that column is the longer one. It is kept that way deliberately: the value of this page is that it can embarrass us, and a version that could not would not be worth fetching.

Register maintained by hand alongside the work, and checked in CI: every document listed must exist at the path given and match its recorded digest, and every file in assets/briefs/ must appear in the register. Last reconciled 16 September 2026.

Twenty-three items. None untouched, and none finished.

Every item now names something it produced and something it did not. Twenty of the twenty-three are marked partly, which is the honest state of almost all real work and the status this register expects to use most. The column that matters is the right-hand one.