sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

On this page

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

Licence to Operate

The organisation is the authority, the behaviour policy is the instrument, the agent is the licensee. The step between describing an agent and insuring it.

Source: https://riskmandate.ai/licence-to-operate.html↗


A licence to operate.

The organisation is the authority, the behaviour policy is the instrument, and the agent is the licensee. Self-issued, witnessed and dated — which is how most assurance works. Until one is issued, the agent runs on nobody’s say-so, which is the honest description of almost every agent running today.

Four facts, and a date it comes back.

A licence to operate is short on purpose. It is not a control, it is a record of a decision, and the whole value is that somebody’s name is on it and it expires.

The last row is the one that does the work. A condition with nothing enforcing it is an expectation, and three of the four barrier kinds bound nothing at all↗. A licence that does not distinguish them is a document that reads like a control and is not one.

You cannot license what nobody has described.

This is the whole reason the work starts one step down. A licence is an authorisation of specific capabilities; if nobody has enumerated the capabilities, the licence authorises a shape rather than a thing, and it is worth exactly what the enumeration was worth.

Agent Behaviour Policy

What it can reach, what you authorised, the gap, and what stands in the way of each row.

Licence to Operate

A named person authorises that policy, for an interval, with conditions and their enforcers.

Insurable

The record an underwriter will accept, scored and dated, with the residual risk owned.

A file in the pack, not a certificate.

The licence ships as LICENCE-TO-OPERATE.md inside the vault, so the agent can read the terms it runs under and a person can read the same terms without a portal. Every published vault carries one ↗, unissued, with the authority and the interval left blank until somebody fills them in.

Status, stated plainly. The file exists and ships in every published vault today, as a template: unsigned, unissued, with the authority and the interval blank. What does not exist is the countersigned form — a licence somebody outside your organisation would accept as evidence — which is what step three needs and what we have not built. We are not going to describe that as available because the file is.

One thing, at four levels.

A licence needs a behaviour policy underneath it, and that is what the four levels sell. The whole ladder, what each level changes and who does the work is on pricing↗; the catalogue and the checkout are on the store.

The store takes the order and hands you back here: one page per level, and at level one that page is the download — the zip, its size, its sha256 and a check that runs in your own browser. Payment rails are not built yet, and every checkout button on the store says so rather than looking live.

Licence one agent.

Pick an agent you already run, get the behaviour policy for it, and the licence is the short document you write on top. Both are files you keep.