RiskMandate — The insurability layer for agentic AI.
Make your agents insurable.
Carriers are filing to exclude AI from cover, and the way back is evidence an underwriter will accept. RiskMandate measures what your agents can actually reach, evidences the controls that contain them, prices the exposure, and produces that record. Underneath the insurance framing is a risk model: a grant is what a credential technically permits, a mandate is what the holder is authorised and expected to do, and the gap between them is exposure nobody ever accepted. A deployed agent already has access, so a real risk cannot be denied — only accepted, by a named owner, for an interval, with an expiry that brings the decision back. RiskMandate is read-only and never in the request path: it defines the mandate and measures the gap; it does not enforce it. It is built on SG/Vault — zero-knowledge, PKI, provenance, no database — so you hold the keys.
Site version v1.34.8. The version record is at https://riskmandate.ai/versions.html↗ and its index at https://riskmandate.ai/versions/index.json↗.
Core concepts
- The insurability layer: carriers are moving to exclude AI, and affirmative cover now turns on evidence rather than a questionnaire; we produce the record an underwriter will accept.
- The Insurability Index: a 0–100 score over five weighted dimensions, derived from your environment rather than a self-assessment, with six levels from Unmapped to Underwritten.
- The grant is not the mandate: a grant is what a credential technically permits; a mandate is what the holder is authorised to do; the difference is excess authority nobody accepted.
- The signature mechanic: no deny button: a deployed agent already has access, so a real risk cannot be denied — only accepted, by a named owner, for an interval, with an expiry that returns the decision.
- Never in the request path: read-only by design — no runtime decisions, no enforcement point, nothing in line that can slow an agent down or break it.
- Accepted is not acceptable: accepted is an act somebody performs; acceptable is the level at which the business stops funding remediation; they are orthogonal, giving four real states.
- The foundation: SG/Vault: a semantic graph on a zero-knowledge vault — PKI, provenance, no database — that is agentic-native rather than agentic-retrofitted; you hold the keys.
- Positioning: the wedge is agentic risk and the renewal conversation; complementary to GRC, identity and posture tooling rather than a replacement for any of them.
Pages
Each is a plain HTML document at its own URL, with a markdown twin at the same path. Anything a page renders at runtime from data — the demo cards, the library, the scenarios — is in the page, not the twin.
- RiskMandate — Know what your agents can do↗ · md↗: An Agent Behaviour Policy writes down what one AI agent can really reach, what you authorised it to do and the gap between the two.
- RiskMandate — Agent Behaviour Policies, one vault per application↗ · md↗: A directory of behaviour-policy template vaults, one per target application, each read live in the browser from the encrypted vault with a published read key: the four counts, every row with its barrier, the vault’s own app, and the files you hand the agent.
- RiskMandate — the Agent Behaviour Policy↗ · md↗: An Agent Behaviour Policy is a written description, for one agent in one deployment, of everything it can do, what you authorised it to do, the gap between them, and what actually stands in the way. It describes and it does not judge, so it carries no score.
- RiskMandate — How it works: from a prompt to a graph with provenance↗ · md↗: How an Agent Behaviour Policy technically works, in the order it happens: a prompt that shows what the agent can reach, the barriers that separate hope from a control, fitting the policy to the controls you actually have, connectors to whatever you run, the graph to standards and risks, and the vault as provenance.
- Licence to Operate↗ · md↗: The organisation is the authority, the behaviour policy is the instrument, the agent is the licensee. The step between describing an agent and insuring it.
- RiskMandate — Know the risk. Name the owner. Own the mandate.↗ · md↗: Every exception, approval, and agent action becomes a mandate with an owner, a blast radius, and an expiry date. RiskMandate defines the mandate and maps the gap between it and the grant — the excess authority nobody accepted. Never in the request path.
- You run agents today↗ · md↗: You gave an assistant access to a repository, a mailbox, a cloud account. A behaviour policy says what it can actually reach, what you authorised, and the gap.
- You are a founder↗ · md↗: You will be diligenced on your agents before long. A behaviour policy is what diligence finds, written by you first.
- You are a startup↗ · md↗: Your first serious enterprise customer will send a security questionnaire with agent questions on it. A behaviour policy answers them with rows rather than assurances.
- Make your agents insurable↗ · md↗: Insurability is the destination. Cover is being withdrawn, evidence buys it back, and the Insurability Index is the published design for how that evidence is scored.
- RiskMandate — can you insure a software program?↗ · md↗: Can you insure a software program, and has it ever been done? Yes: the maker since the 1980s, one defect in 1997, a smart contract since 2019, a model's output since 2018, an agent in one deployment since February 2026 — dated and sourced — and where an Agent Behaviour Policy sits in it.
- RiskMandate — Who can pull the plug?↗ · md↗: Every board asks it in a sentence: if this agent starts doing something no one intended, who stops it, how fast, and what does stopping it cost? The plug profile is the mandate read backwards — who, blast radius, speed, side effects, and the one dimension money cannot buy back: recoverability.
- RiskMandate — How long will you accept this risk?↗ · md↗: Four situations you'd refuse on instinct — each already accepted the moment an agent runs. The only real question is the interval.
- RiskMandate — RAMM, the Risk Acceptance Maturity Model↗ · md↗: RAMM is a graph-native maturity model for risk acceptance. It models acceptance as a durable decision node linked to evidence, ownership, authority, appetite, and review — so maturity is computed from the graph, not asserted in a questionnaire. Five levels, each a testable path-pattern.
- RiskMandate — business cases, by the risk they change↗ · md↗: The business case for a security product is the difference between the risk register without it and with it, from the operator to the board. Computed from a public model, our own product first, then others in their own words.
- RiskMandate — OWASP, as a graph↗ · md↗: A semantic graph of OWASP: the foundation, its AI and agent projects, the standards and tools an agent deployment touches, the items of eleven lists by title, and the relationships OWASP states between them, joined to the risk model behind the business cases.
- RiskMandate — the business case for Agent Behaviour Policy↗ · md↗: Agent Behaviour Policy (RiskMandate), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for agentgateway↗ · md↗: agentgateway (Linux Foundation (Agentic AI Foundation)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Cedar↗ · md↗: Cedar (CNCF (sandbox)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Cilium network policy↗ · md↗: Cilium network policy (CNCF), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Falco↗ · md↗: Falco (CNCF (graduated)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for gVisor↗ · md↗: gVisor (Google (open source)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Keycloak↗ · md↗: Keycloak (CNCF (incubating)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Langfuse↗ · md↗: Langfuse (ClickHouse (company-maintained)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for LangGraph and LangChain human-in-the-loop↗ · md↗: LangGraph and LangChain human-in-the-loop (LangChain (company-maintained)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for LiteLLM↗ · md↗: LiteLLM (BerriAI (company-maintained)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Open Policy Agent↗ · md↗: Open Policy Agent (CNCF (graduated)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for OpenBao↗ · md↗: OpenBao (OpenSSF (Linux Foundation)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for OpenFGA↗ · md↗: OpenFGA (CNCF), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for OWASP Coraza↗ · md↗: OWASP Coraza (OWASP), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for OWASP Threat Dragon and pytm↗ · md↗: OWASP Threat Dragon and pytm (OWASP), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for PostgreSQL point-in-time recovery↗ · md↗: PostgreSQL point-in-time recovery (PostgreSQL Global Development Group), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Squid↗ · md↗: Squid (Squid Software Foundation), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Unleash↗ · md↗: Unleash (Unleash (company-maintained)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — the business case for Velero↗ · md↗: Velero (CNCF (sandbox)), by the risk it changes: the register for a stated agent deployment without it and with it, computed from a public model, from the operator to the board.
- RiskMandate — Pricing: four levels, £10 to £1,500↗ · md↗: Four levels of one document, an Agent Behaviour Policy for the agent you run: the pack downloaded for £10, a working vault for £50, corrected for your situation for £500 with a prompt you run yourself, or two sessions and a professional's signature for £1,500. The examples are free.
- RiskMandate — the reviewed level: two sessions, and a professional signs it↗ · md↗: What the £1,500 reviewed level of an Agent Behaviour Policy is, in order: two half-hour sessions with your team, a behaviour policy built from the interview, a named professional's correction, and a sign-off file committed with their name and the date.
- RiskMandate — who runs your review↗ · md↗: The people who run the reviewed level of an Agent Behaviour Policy: two sessions with your team and a sign-off with a name and a date. Every line of every record is read off a published page, with the date it was read.
- RiskMandate — Dinis Cruz, who runs the review↗ · md↗: Dinis Cruz runs the reviewed level of an Agent Behaviour Policy: two sessions with your team and a sign-off. Every line on this page is read off a page they publish themselves, with the date it was read.
- RiskMandate — CISO XYZ: the shape of a reviewer page↗ · md↗: A placeholder page, labelled as one: the shape a reviewer profile takes on riskmandate.ai, so that somebody being asked can see exactly what would be published about them.
- RiskMandate — try it: write a behaviour policy for your own agent in twenty minutes↗ · md↗: Four steps, thirteen prompts, pasted into the assistant you have already connected to your mail. Nothing is collected and no account is needed. At the end you have what it can reach, what you meant to authorise, and the gap between the two.
- RiskMandate — articles↗ · md↗: One argument at a time, from the record: what a deployment actually does, the screen or page it was read from, and where the accountability lands. Every claim sourced and dated; nothing tested on anybody else's system; nothing scored.
- RiskMandate — questions we were asked↗ · md↗: Real questions put to us in public, answered here with a date and without naming the asker. Where the answer is that we do not do the thing, that is the first line rather than a caveat at the bottom.
- RiskMandate — privacy: what this site collects, and how to check↗ · md↗: riskmandate.ai runs no analytics, sets no cookies, loads nothing from a third-party CDN and has no account to create. This page says what happens when you read it, when you write to us and when you buy, and what we never ask for.
- RiskMandate — the Lab↗ · md↗: Findings, interface mockups and open proposals, published as they happen. Work in progress rather than product claims — some of it will turn out to be wrong, and the arguing is the point.
- RiskMandate — Live demos↗ · md↗: Three working demonstrations of the RiskMandate approach, each a real encrypted vault opened with a deliberately published read-only key, running natively in this page: the RiskGraph Explorer, Agentic Browser Isolation, and the RiskMandate field demo.
- RiskMandate — Library↗ · md↗: The concepts and the approach behind autonomous risk management.
- RiskMandate — Partners↗ · md↗: RiskMandate is the risk-acceptance and accountability layer for the agent-detection ecosystem. We complement detection and remediation — we don't compete with them.
- UK support, in the open↗ · md↗: Every UK programme, event, scheme and network a London startup could use to get in front of users, read on the official page and dated, with what RiskMandate has done about each one. Written to be forwarded and corrected.
- RiskMandate — Half an hour of your advice, by voice↗ · md↗: This page is for founders and operators who are good at getting into events, at marketing and promotion, at content that spreads, and at making things happen, particularly in the UK. A prompt you copy into your own assistant, which interviews you by voice for about half an hour and writes up a summary you send back. Nothing is sent by this page.
- RiskMandate — Brand guidelines↗ · md↗: The RiskMandate mark, colour tokens, typography and downloadable brand assets. The mark is a seal: it signals counter-signature and provenance to underwriters, risk committees and boards.
- RiskMandate — Give feedback after a demo↗ · md↗: Saw a RiskMandate demo? ChatGPT will interview you by voice while it is fresh, produce an evidence pack you review and control, and you send it back. Not a survey — a conversation that becomes evidence.
- RiskMandate — For Agents↗ · md↗: Machine-readable access to RiskMandate's content: llms.txt, a full-text markdown export, and a structured agent-content manifest. A product about governing agent access, publishing a clean one.
- RiskMandate — Accepted is not acceptable↗ · md↗: Accepted is an act: somebody with standing says they carry the risk. Acceptable is a threshold: the point where the business stops funding remediation. They are orthogonal, not sequential — which gives four real states, each needing a different action. And the EU AI Act mandates the judgement without defining the word.
- Risk Mandate — agents act, and someone has to own the risk↗ · md↗: Risk Mandate begins where security stops — acceptance, funding, and ownership. No risk can be denied, only accepted for an interval and underwritten to the board.
- RiskMandate — The post images↗ · md↗: The 'How long will you accept this risk?' series as static 4:5 artboards, ready to screenshot and post. Same scenarios as the interactive cards, one renderer apart.
- RiskMandate — Licence to Operate, live↗ · md↗: An insurance policy for an agent, simulated: the grant, the mandate, and the delta nothing covers. The homepage argument running as something you can operate, opened read-only with a published key.
- RiskMandate — RiskGraph Explorer, live↗ · md↗: The whole RiskMandate approach in one live vault: answers become facts, facts chain into risks, risks reach the board, and a role accepts what it holds. Seven views over one graph, opened read-only in this page with a published key.
- RiskMandate — Agentic Browser Isolation, live↗ · md↗: A living risk register for one consequential question — does an AI agent browse with your logged-in sessions or an isolated identity? A page per stakeholder altitude and acceptance-gated escalation, live in this page with a published read-only key.
- RiskMandate — the field demo, live↗ · md↗: Eight questions to a risk register, built to be handed to a stranger on an iPad — and an app that uses an LLM without ever holding the API key. Live in this page with a published read-only key.
- RiskMandate — File security, live↗ · md↗: An eleven-step risk-acceptance walk over a file-security estate, running SQLite in the browser. The workflow somebody actually moves through, rather than the model behind it.
- RiskMandate — Agent permission games, live↗ · md↗: Two games about grants and mandates. Five minutes, forty questions, no sign-up: guess what your agent can reach, then find out. The only demo here that sends data — it keeps a leaderboard.
- RiskMandate at Startup Summit Lisbon, 17–18 September 2026↗ · md↗: We are exhibiting at Startup Summit in Lisbon. Bring one agent you already run and we will draft its Agent Behaviour Policy on paper in five minutes — what it can do, what you authorised, and the gap. Plus press boilerplate and every brand asset, free to take.
- RiskMandate — the brief register↗ · md↗: Every document this site was built from, what it produced, and what it did not. Kept with a digest per file so nothing is worked twice and nothing is quietly dropped.
- Working with us — briefs for collaborators and their agents↗ · md↗: Briefs for people collaborating with RiskMandate, written to be read by a person and handed to an agent. Plus the seven hard rules that apply to anything produced on our behalf.
- RiskMandate — after payment: a debrief for the store team↗ · md↗: What riskmandate.ai has for the buyer after the store takes a payment: the four post-sale pages, the link contract per level, what the store has to point at them, what the site guarantees, and what is still open.
- Synthetic users — five people who do not exist, reading this site↗ · md↗: Five invented readers were walked through riskmandate.ai one screenshot at a time and interviewed at the end. Thirty screenshots, eleven unanswered questions, twelve findings, two of them blocking a sale.
- RiskMandate — in this session, the agent holds the union of everything it has ever been allowed to do↗ · md↗: A conversation is not an authorisation boundary. Every session an agent runs carries the union of every scope ever consented and every approval ever clicked — in each vendor's own documented words. What that union is made of, what the help page will not tell you about it, and the one lever a deployer still has.
- RiskMandate — what an Agent Behaviour Policy is, and why one agent needs one↗ · md↗: Somebody will ask what your agent can do, and you need an answer they can check. Four objects — the mandate elicited, the grant measured, the delta derived, the barrier recorded — worked end to end on one real deployment, with every number traceable to the record it came from.
- RiskMandate — an approval prompt is not a human in the loop↗ · md↗: Claude wants to use Add labels to message from Gmail. Which label, on which message, asked for by whom? The screen does not say — and one of its three buttons removes the question for good. What an approval prompt actually is, in the barrier vocabulary, and where the accountability lands.
- The pilot worked. Then somebody asked what else it could do.↗ · md↗: Why so many generative AI and agent pilots never reach production, or are switched off after they do: the business compares what the agent was meant to do with what it can do, at machine speed, and declines to sign for the difference. The data, the cases, and what the data does not show.
- A deleted meeting comes back. An edited one does not.↗ · md↗: Google Calendar keeps a deleted event in a trash for 30 days and documents no way for a user to restore an edited one. What Google keeps after each action, in its own words, why an edit is worse than a delete, where Google's pages disagree, and the draft Calendar rows of an Agent Behaviour Policy.
- Who owns what in AI. And how accountability holds on the way up.↗ · md↗: A LinkedIn infographic maps thirteen roles to what each owns in AI and what it protects. Every company will redraw it. What joins its levels, so that accountability holds on the way up, is risk acceptance with the Agent Behaviour Policy underneath: one agent worked from its nine rows to the board, seven rules, six weeks, and the model in enough detail to build.
- RiskMandate — which Agent Behaviour Policy next?↗ · md↗: The applications and business functions people have asked an Agent Behaviour Policy for, and a form to suggest or vote for the next one.
- RiskMandate — thank you: level 1, what happens now↗ · md↗: After paying for an Agent Behaviour Policy at level 1: what arrives and when, what you do next, how the key reaches you, the definition of done, and who to write to.
- RiskMandate — thank you: level 2, what happens now↗ · md↗: After paying for an Agent Behaviour Policy at level 2: what arrives and when, what you do next, how the key reaches you, the definition of done, and who to write to.
- RiskMandate — thank you: level 3, what happens now↗ · md↗: After paying for an Agent Behaviour Policy at level 3: what arrives and when, what you do next, how the key reaches you, the definition of done, and who to write to.
- RiskMandate — thank you: level 4, what happens now↗ · md↗: After paying for an Agent Behaviour Policy at level 4: what arrives and when, what you do next, how the key reaches you, the definition of done, and who to write to.
- RiskMandate — the behaviour-policy vault for n8n, owner API key↗ · md↗: The template Agent Behaviour Policy vault for n8n, owner API key (n8n/self-hosted/owner-api-key), rendered live from vault l8opgcug: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Dropbox MCP server↗ · md↗: The template Agent Behaviour Policy vault for Dropbox MCP server (dropbox/mcp-server/default), rendered live from vault 9eqa7e4p: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Microsoft 365 connector (Claude)↗ · md↗: The template Agent Behaviour Policy vault for Microsoft 365 connector (Claude) (anthropic/microsoft-365-connector/default), rendered live from vault dgx3nvu4: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Google Drive, read-only scope↗ · md↗: The template Agent Behaviour Policy vault for Google Drive, read-only scope (google/drive/readonly-connector), rendered live from vault vz03p8it: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Claude's Gmail connector↗ · md↗: The template Agent Behaviour Policy vault for Claude's Gmail connector (anthropic/gmail-connector/default), rendered live from vault oc433z3m: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Gmail, read-only scope↗ · md↗: The template Agent Behaviour Policy vault for Gmail, read-only scope (google/gmail/readonly-connector), rendered live from vault l2zlv3ng: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Google Workspace MCP servers↗ · md↗: The template Agent Behaviour Policy vault for Google Workspace MCP servers (google/workspace-mcp/default), rendered live from vault pq7ct02p: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for A scheduled job↗ · md↗: The template Agent Behaviour Policy vault for A scheduled job (generic/scheduled-job/service-account), rendered live from vault kd7zeimj: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for GitHub Actions↗ · md↗: The template Agent Behaviour Policy vault for GitHub Actions (github/actions-runner/ci), rendered live from vault 0hpdpj80: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for A browser extension↗ · md↗: The template Agent Behaviour Policy vault for A browser extension (generic/browser-extension/broad-host-permissions), rendered live from vault exsaxrfr: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for ChatGPT in the browser↗ · md↗: The template Agent Behaviour Policy vault for ChatGPT in the browser (openai/chatgpt-web/default), rendered live from vault dd1teu9n: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Claude in the browser, connectors on↗ · md↗: The template Agent Behaviour Policy vault for Claude in the browser, connectors on (anthropic/claude-web/connectors-on), rendered live from vault wkm5owfl: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Claude Desktop↗ · md↗: The template Agent Behaviour Policy vault for Claude Desktop (anthropic/claude-desktop/default), rendered live from vault ty3axtmo: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Claude Code, confirmations off↗ · md↗: The template Agent Behaviour Policy vault for Claude Code, confirmations off (anthropic/claude-code/local-confirmations-off), rendered live from vault ahly2cho: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Claude Code on your machine↗ · md↗: The template Agent Behaviour Policy vault for Claude Code on your machine (anthropic/claude-code/local-default), rendered live from vault amicdz0h: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- RiskMandate — the behaviour-policy vault for Claude Code on the web↗ · md↗: The template Agent Behaviour Policy vault for Claude Code on the web (anthropic/claude-code-remote/ccr-container), rendered live from vault ruj286tr: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.
- The grant is user-shaped, not data-shaped — RiskMandate Lab 01↗ · md↗: Connect an assistant to your mailbox and the narrowest permission that reads one message reads every message. Four vendors' own documentation, quoted verbatim, and the four places their marketing and their scope lists disagree.
- What buying a behaviour policy would look like — RiskMandate Lab 02↗ · md↗: Twelve stages from a stranger's first question to a recomputing vault with a read key they can hand an underwriter, with five of them drawn as interface mockups. None of it is built yet.
- Changes we are asking of the behaviour-policy site — RiskMandate Lab 03↗ · md↗: Three open requests against abp.sgit.ai: one property for the capability grammar, four connector deployment shapes, and the provenance conventions we would need to render any of it.
- RiskMandate — Lab 04 · the shape collector↗ · md↗: A build specification: the collector that asks somebody what they run, the schema no standard supplies, the write-only lane that cannot correlate — and the arithmetic showing why a twenty-connector question is not anonymous.
- RiskMandate — Lab 05 · the commit author is a free text field↗ · md↗: The author name and address on a commit are free text, the write interface takes them as parameters, and the host attributes the result to whoever owns the address. Exactly one thing prevents it, and it is a repository setting rather than a line in a prompt.
- RiskMandate — Lab 06 · every routable address is in the grant↗ · md↗: Do not attack anyone is the one rule every deployer would sign, and it is the one where the grant cannot be enumerated, the delta cannot be counted, and nothing in the default configuration enforces it.
- What you are actually buying — an Agent Behaviour Policy as a vault — RiskMandate Lab 07↗ · md↗: The first behaviour-policy vault, built and pushed: eight files derived from a measured grant, a starting mandate and a pinned vocabulary, for Claude Code on the web with one repository attached. The files you hand the agent, a Licence to Operate with a referent, a grant check run from inside the shape, and the one-command template that makes the second shape cheap.
- Brief B1 — power user and tester of Agent Behaviour Policies↗ · md↗: The first task for a freelance collaborator: make Agent Behaviour Policies for real deployments, find where the model breaks, and time it. Opens with a prompt written to paste straight into an agent, plus the full reading list across riskmandate.ai, abp.sgit.ai and the rest of the estate.
- RiskMandate — version record↗ · md↗: Every version of the RiskMandate site, what changed in it, and the file that record lives in.
- RiskMandate — Design options (internal)↗ · md↗: The eight logo concepts explored for RiskMandate, preserved as a design record with the reasoning for and against each. Concept E, the Seal, was selected.
- Startup Summit Lisbon 2026 — RiskMandate materials↗ · md↗: Everything Startup Summit needs from RiskMandate in one place: the name, the description at four lengths, every version of the logo, and the booth panel artwork.
Machine-readable
- Full text↗: the entire site as one markdown document
- Content manifest↗: structured JSON
- Version index↗: every release, and the file its notes live in