sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

RiskMandate — Lab 04 · the shape collector

A build specification: the collector that asks somebody what they run, the schema no standard supplies, the write-only lane that cannot correlate — and the arithmetic showing why a twenty-connector question is not anonymous.

Source: https://riskmandate.ai/lab-shape-collector.html↗


Seven things to build, and one word we have not earned.

The first thing anybody will ever use is a page that asks what they run, computes what they granted, and hands them the gap. This is its build specification: three tools, two vaults, two documents — and the arithmetic that says a twenty-connector question is not anonymous, which changes what may leave the browser.

The cheapest product we have, and it asks one thing.

Every other route into what an agent can do requires something to be installed. This one asks. Somebody says which assistants they use, on which surfaces, with which connectors switched on; the page works out what that grants; and it hands back the difference between that and what they would have said they intended. No install, no administrator, no procurement.

The collector asks the shape, computes the grant, and returns the delta.

Everything on this page after that sentence is about one question: what, if anything, is allowed to leave the browser.

A twenty-connector question is not anonymous.

The instinct is that answers like these are harmless in bulk, so they can simply be collected. That instinct is wrong, and it is wrong measurably rather than arguably — which is the good case, because it means the fix is arithmetic rather than judgement.

2²⁰ — about a million distinct answers to one question.

4 bands × 2⁵ category combinations = 128 answers. A reduction of about 8,000×, and the research loses almost nothing — the interesting finding is how many and of what kind, not which brand.

ResponsesCells that could hold a group of fiveRealistic outcome
100at most 20Effectively every respondent unique
500at most 100Effectively every respondent unique
5,000at most 1,000Common shapes reach a group of five. Every interesting shape does not
50,000at most 10,000The head is safe and the tail still singles out

Compute locally in full. Submit banded.

This keeps everything the product needs and gives up nothing the user wants. The full configuration is computed in the browser and never leaves it; what crosses the wire, and only if somebody presses submit, is a banded record.

The full shape, and everything derived from it

Every connector by name, every surface, every assistant. The grant is computed from the full shape, the delta derived, the label and the leaflet rendered. The user sees all of it. It is their configuration.

Bands and categories. Nothing else.

A record with no names in it, no identifier of any kind attached to it, and nothing recorded about the request that carried it.

FieldFull, localSubmitted
connectorsThe named list of twentyA count band — none, 1–2, 3–5, 6+ — plus categories: mail, files, calendar, code, chat
assistantsThe named listA count band and the categories
surfacesEach oneCoarse — desktop, web, editor, command line
roleFree choiceThree or four bands
company sizeExactThree bands
free textShown back to themNever submitted. Free text cannot be anonymised
address, user agent, precise timeNot neededNever recorded — each one independently defeats the banding

A collector that cannot read back cannot correlate.

That is the estate's own enforcer test — a control bounds a grant only if it is enforced by something the grant does not include — applied to our own product. A promise not to correlate is bounded only by something the collector does not have, and here that something is read access. It is a structural claim rather than a policy, which is the only kind worth publishing.

Three tools, two vaults, two documents.

Nothing below exists. Each card says what the thing is, where it runs, what it holds, what it must never do, and what has to be decided before it can be started. The two documents are on this list because without them the product cannot use the word it wants to use.

The shape collector

The page itself: under fifteen questions, one item per screen on a phone, an honest stated duration, a picture that accumulates on the right as the answers come in on the left, one guess screen before the reveal, and a result the user can keep. Everything it computes, it computes locally.

The shape record schema

A closed, controlled vocabulary for a deployed configuration: which assistant, on which surface, with which connectors granted which scopes — and the mapping from that to the capability primitives it grants. Twice this month the answer to "do we need to build this" has been "it already exists". Not this time.

The submitting vault

The lane the browser hands a banded record to. It holds a write credential for V2 and no read key for anything, which is what makes the privacy claim structural instead of promissory.

The collection vault

Where banded records accumulate. Read access sits with us and not with the collector, which is the entire point of splitting it from V1.

The aggregator

The thing that turns a collection vault into something publishable, and the only place the suppression rule can actually be enforced. It is listed separately because a rule that lives in prose is not a rule.

The motivated-intruder assessment

A short written assessment naming who the motivated intruder would be, what they would already know, and what the banded corpus would add to it. The obligation is not to reduce the risk to zero; it is to make a reasoned assessment and record it.

The employer instrument

The same questions, sent by an employer to its own staff, to find out how many agents are in use. It is a real second product and it is not the same product, because the law changes when the employer sends the link. Detail in its own section.

Storing the answers is one thing. Sending them is another.

The analysis splits cleanly, and the design should follow the split rather than cover the whole tool with one consent banner. Three of these four rows need no banner at all. The fourth needs more than a banner.

OperationRegimePosition
storing in-progress answersStorage rules, in scopeStrictly necessary. Assessed from the user's point of view, and somebody who starts a self-assessment plainly wants their answers to persist. No banner
reading them backStorage rules, in scopeSame exception, same reasoning
analytics about the toolStorage rules, in scopeDrop-off point, device class, which question loses people. The statistical-purposes exception fits, with clear information and a simple free means to object — a toggle defaulted on. Browser settings are not sufficient
submitting the answersNot the storage rules. Data protection onlyAn explicit, separate, unticked act. The answers are the content the user produced, not statistics about how the service is used

The statistical exception covers how a service is used. It does not cover what the user told it.

Those are different things and only the first is exempt. The regulator is explicit that the exception is not a broad one covering all analytics — which means the submit screen is a real screen, with its own unticked control, and not a line in a footer.

Do not design it as a game. Design it to finish.

The instinct that the game framing carries over from the teaching work is wrong, and the evidence that applies here is a different literature. This is a data-collection instrument, not a teaching artefact: what matters is completion, and that literature is well developed and mostly contradicts the folklore.

Progress indicatorEffect on dropping out
constant speed — an honest linear barNo significant effect
fast at first, then slowingDrop-off odds multiplied by about 0.80
slow at first, then speeding upDrop-off odds up by 56%
RankLeverEvidence
1Fewer questionsThe only lever with both randomised and large observational support, and the observational data shows a cliff above roughly fifteen
2An honest, short stated durationRandomised and replicated. The announcement is itself a treatment, and an indicator only helped when the task was promised short and actually was
3Works on a phone, one item at a time, no gridsStrong on quality, good on completion. Most responses will be mobile
4A high-value question earlyOne clean experiment, one large observational study. Modest but real
5Showing partial resultsSatisfaction significantly higher, completion roughly unchanged. Treat as an untested hypothesis

The same instrument, circulated inside a company to find out how many agents are actually in use, is a real product and a different one. Three things move, and the third is the one that decides the design.

"One product person on a desktop assistant with mail, files and code connectors" is anonymous to us and a name to them.

So the employer mode never returns an individual row. Only cells above the suppression threshold, only bands, and the product says so on the page the employee sees before they answer.

Nobody else asks. That is the opening and the problem.

A ten-vendor comparison of the discovery market, published 7 September 2026, found that all ten discover through technical telemetry — browser extensions, endpoint agents, network inspection, API integrations, sign-on logs — and none through self-report. One free assessment tool disparages self-report explicitly and recommends usage telemetry instead. Both halves of that matter.

Self-report reaches what telemetry cannot

A personal device, a personal account and a locally run server are all invisible to every method on that list, and all three are where the interesting deployments are. One of the larger vendors implicitly concedes the gap by selling desktop agents to close it.

There is no vocabulary of trust for it

No incumbent treats survey data as a legitimate discovery source, so the burden of explaining why it counts falls entirely on us — and it cannot be met by claiming more than the method delivers.

The honest word, until then, is banded.

One sentence of product copy is doing more damage than any missing feature on this page, and it is the one that says the data is anonymous. It is a claim with a defined test behind it, and we do not currently pass the test.

The word anonymous may not appear in this product until all three of these exist:

Seven things we cannot settle alone.

These are real rather than rhetorical, and four of the seven block a card in the build list above. If you have an opinion on any of them, that is more useful to us today than agreement with the rest of the page.

#QuestionBlocks
1How many questions, exactly? The cliff is around fifteen and the connector question alone could be twenty items if built carelesslyT1
2Is the connector question one multi-select, or a category then a count? The second is the banding made native, and it may lose people who want to see their own tool namedT1
3What does the guess screen ask? One number, or one number per categoryT1
4Who writes the motivated-intruder assessment, and where does it live? It is a short document and it is a precondition for a wordD1
5Does the employer mode need a different instrument, or the same one with a different output? Same instrument is cheaper, and the consent problem does not careT4
6What is the suppression threshold? Five is the cited standard, and a small early sample will suppress nearly everythingT3 · V2
7Does the shape schema become the published vocabulary, or stay internal until the fifth policy? Publishing early invites correction and locks a shape too soonT2

And seven we are choosing to live with.

TensionBoth halves are true
banding the submissionIt is what makes the data lawful to hold, and it throws away the brand-level detail that would be the most interesting thing to publish
computing locallyIt is the strongest privacy position available, and it means we learn nothing at all unless somebody presses submit
not designing it as a gameThe evidence is about completion rather than enjoyment, and the instinct about feel is what will make people start
the guess screenIt is the one mechanic with a published argument behind it, and it adds a screen to an instrument whose main lever is fewer screens
employer modeIt is a real second product, and it carries an impact assessment, a weak lawful basis, and an intruder who is the buyer
self-reportIt reaches what telemetry cannot, and no incumbent treats it as legitimate
building the schemaIt is a genuine gap, and it is the third schema this estate has taken on in a fortnight

Written 12 September 2026 from a dev brief of the same date. Sources, all read 12 September 2026 — completion: the progress-indicator meta-analysis of 19 studies and 32 experiments, Villar, Callegaro and Yang 2013, Social Science Computer Review 31(6); the expectation-matching result, Yan, Conrad, Tourangeau and Couper 2011, IJPOR 23(2); the conversational comparison, Kim, Lee and Gweon 2019, CHI; the 2026 field experiment, Cavusoglu Deveci, Fuchs and Metzler, BMS 169-170(1), 6 March 2026; the item-by-item finding, Revilla, Toninelli and Ochoa 2015; the personalised-feedback trial, Kühne and Kroh 2018, SSCR 36(6); vendor completion claims at typeform.com ↗, treated as marketing with no methodology. Schemas: cyclonedx.org ↗, machine-learning component bill of materials v1.7, standardised as an international specification December 2025; the alternative family's profile at spdx.github.io/spdx-spec ↗. Neither describes a deployed configuration. Identifiability: the regulator on effective anonymisation, the singling-out test, the motivated-intruder test and groups of five, at ico.org.uk ↗; Sweeney on postcode, gender and date of birth; Eckersley 2010 on 470,000 browser samples and 83.6% instantaneous uniqueness. Storage and submission: the guidance on storage and access technologies, published 29 April 2026, at ico.org.uk ↗, including the strictly-necessary test assessed from the user's point of view, the statistical-purposes conditions, the objection mechanism that may not be a browser setting, and the statement that the exception is not a broad one covering all analytics. Employment: the regulator on monitoring workers, October 2023 and last updated 16 June 2026, at ico.org.uk ↗. The market: a ten-vendor comparison published 7 September 2026; nudgesecurity.com ↗ for the one transparent price found; the free seven-question assessment at aona.ai ↗, which recommends telemetry over self-report. Inside the estate: the capability map and its 23 primitives at what-can-it-do.games.sgit.ai↗; the belief-before-answer mechanic at games.sgit.ai↗. The entropy arithmetic in the second section is ours, derived from stated assumptions rather than measured.

The journey, kept as files.

This page holds current thinking, and it will change. Each edition below is a dated, immutable copy of what it said on the day, with its own digest. Nothing is rewritten; the list only grows.

Digests for every edition are in lab-editions.json↗, so a PDF somebody was sent can be checked against this list.

Two vaults are hours. One word is a document.

The write-only lane can be provisioned today and it is what makes the privacy claim structural rather than promissory. The assessment is a short piece of writing and it decides what the product is allowed to say. Neither is the hard part, and both are ahead of the hard part.