RiskMandate — Know what your agents can do
An Agent Behaviour Policy writes down what one AI agent can really reach, what you authorised it to do and the gap between the two.
Source: https://riskmandate.ai/↗
Know what your agents can do.
Not what they did. What they can.
An Agent Behaviour Policy writes down what one agent can really reach, what you authorised it to do and the gap between the two, in one record the CEO, CTO and CISO can all stand behind.
From £10 for one agent. All sixteen published examples are free to read.
From a published behaviour policy: Claude Code on the web, with one repository attached. Open this behaviour policy↗
- 16 templates, published free↗
- Working vaults you hold the keys to↗
- Mandates corrected by a named professional↗
- Two sessions with your team, then sign-off↗
Measured against the standards underwriters are adopting: ISO/IEC 42001, OWASP Agentic Top 10, NIST AI RMF and ISO/IEC 27001.
Model-drafted and marked as such. Not a compliance assessment. We are not an insurer and place no cover. What we don’t claim↗
Every agent will need a licence to operate.
Insurers are carving AI out of cover, and the business answers for what its agents do. Cover comes back when somebody can evidence what each agent can reach, what it was authorised to do and what actually contains it.
1 January 2026
A generative-AI exclusion took effect in the standard liability forms much of one large insurance market runs on. Several carriers have filed their own, one of them absolute.
9 March 2026
A national consumer regulator said a business is responsible if an agent it uses does something illegal, and should be clear what the agent may do, what data it can access and what constraints apply.
Both dates, with the exclusion’s announcement date and why the figures beside them are stated qualitatively rather than counted: on the insurance page↗. Neither is our observation.
Three steps, in order. Each one needs the step before it.
Describe it
Agent Behaviour Policy
What one agent can reach, what you authorised, the gap between them and what stands in the way.
Authorise it
Licence to Operate
The business is the authority, the behaviour policy is the instrument and the agent is the licensee, for a set interval.
Insure it
Insurability Index
The record an underwriter will accept: scored, dated and with the residual risk owned.
Not a model property. A property of this deployment.
The same model can be harmless in one setup and serious in another. Connect it to a mailbox and the narrowest Gmail scope that reads one message reads every message. So a behaviour policy describes one agent, in one deployment, in four parts, and carries no score. See the scope evidence↗
Reach
Measured
Everything the agent can actually access in this deployment, including what nobody thought to check.
Mandate
Elicited
The job, written down: what the business authorised it to do. The one part only you can supply.
Gap
Derived
Reach minus mandate. Never written by hand, and recomputed whenever either side moves.
Barriers
Recorded
What actually stands in the way of each capability: controls, constraints and open questions.
The files and the data keep the older names for these: GRANT.md is the reach and DELTA.md is the gap, because the vocabulary is pinned at abp.sgit.ai↗ and sixteen published vaults are built against it. Same four objects, plainer words on this page.
One record. A view for everyone who answers for it.
The behaviour policy lives in an encrypted vault you hold the keys to, with a reading app inside. Hand a read key to your board, your auditor or your broker and they see exactly what you see.
CEO
Leadership view
“What have we authorised, and who owns it if it goes wrong?”
The gap in plain terms, a named owner, and a trigger that brings the decision back for review.
CTO
Operator view
“How do we keep shipping agents without losing track of what they can touch?”
Terms your agent reads in its own context, as AGENTS.md and SKILL.md. Markdown for people, JSON for tools, and nothing in your request path.
CISO
Security view
“Can we prove what it can reach, and what actually stops it?”
Every capability with its barrier, the gap recomputed whenever an input changes, and every version kept.
Insurer
Insurance view
“What exactly are we being asked to cover?”
Explicit scope and the questions still open, so renewal starts from a record instead of a questionnaire.
It’s a draft on purpose. The people who built the agent, own what it touches and answer for it each correct the part they know. The correction is the product.
- Draft
- Challenge
- Correct
- Review
- Version
One behaviour policy. Four ways to get it.
The document is the same at every level. What changes is how it arrives and who does the correcting.
Sixteen published shapes to start from, including:
Level 1
ABP Pack
The behaviour policy files for your shape, downloaded and yours to keep.
£10
Level 2
ABP Vault
The same material in a working vault, with your keys and version history.
£50
Level 3
ABP Tailored
A named security professional corrects the mandate for your deployment.
£500
Level 4
ABP Reviewed
Two half-hour sessions with your team and a custom vault, reviewed and signed off.
£1,500
Prices in GBP, read from store.sgit.ai/compare↗ at store v0.3.24 on 17 September 2026; the store holds the cart and the price, so a figure that moves there is detectable here. Paid levels carry a commercial licence to you; the sixteen published templates stay free to read and reuse under CC BY 4.0.
Start with the agent that worries you.
Not the whole estate. One agent, already running, written down as a record you keep, correct and can hand to your insurer before they ask.
The insurability layer for agentic AI. Know the risk. Name the owner. Own the mandate.
Product
Evidence
Open source