RiskMandate — Pricing: four levels, £10 to £1,500
Four levels of one document, an Agent Behaviour Policy for the agent you run: the pack downloaded for £10, a working vault for £50, corrected for your situation for £500 with a prompt you run yourself, or two sessions and a professional's signature for £1,500. The examples are free.
Source: https://riskmandate.ai/pricing.html↗
Four levels. One document.
What is for sale is an Agent Behaviour Policy for the agent you actually run: everything it can do, what you authorised, the gap, and what stands in the way of each thing. Every level is the same document. What changes is the form it arrives in and who does the correcting — from a pack downloaded for £10 to two sessions and a security professional's signature for £1,500. The examples are free, on this site, with their keys published. Read one before buying anything.
Pick the application closest to yours, and the level you want it at.
Fifteen applications are in the library↗: Claude Code on a machine and in CI, Claude Desktop, ChatGPT in the browser, a browser extension, GitHub Actions, a scheduled job, Gmail and Drive at read-only scope, the Microsoft 365 connector, Dropbox, n8n, and the rest. Something not on the list starts at the third level, because the first two deliver an existing template and for yours there is not one yet.
| Level | Price | What it is | Who does it | ||
|---|---|---|---|---|---|
| 1 | The pack, downloadedYou want the material and you do not want to run anything. | £10 | Every file in the vault, sent to you: the behaviour policy, the grant, the mandate and the delta as markdown and JSON, the pinned vocabulary, the prompts, and the two files you hand the agent. Yours to use, keep and hand over. Not a vault: no history, no app, no read key to give anybody. | automatedexists and runs | Buy ↗↗ |
| 2 | A working vaultYou want the thing itself rather than a copy of its contents. | £50 | The same material as a vault you hold the keys to: clone it, change it, version it, and hand anyone a read key. It recomputes the delta when the mandate or the grant moves, and keeps every version. The mandate in it is still the starting one; correcting it is yours to do. | automatedexists and runs | Buy ↗↗ |
| 3 | Corrected for your situationYour deployment is not the template, and you would rather not do the correcting. | £500 | You run a prompt in your own environment and send us what it finds. We build the vault from that, correct the mandate against your industry, your use case and the details you gave, recompute the delta, and send it back yours — with a written note of what changed and why, so the correction is checkable rather than trusted. How the prompt step works ↓ | agents, a person reviewsspecified, never run | Buy ↗↗ |
| 4 | Two sessions, and a professional signs itThe answer has to survive somebody else asking about it. | £1,500 | Half an hour with your team to find out what is actually running, and half an hour to deliver it: reviewed and signed off by a security professional, with the licence carrying a name. The line between this level and the one below it is the line between a thing agents do and a thing a person signs. | a personspecified, never run | Buy ↗↗ |
Each level is the level below plus exactly one thing, and the one thing is what the price is for. The pack is the files. The vault is the files with keys and history. Corrected is the vault against your situation. The fourth is corrected with a person in the room. The price steps are ten, ten and three; the third step is smaller because what is added is an hour of a person rather than a new kind of object.
Prices are in pounds and each level is one price, so each has a standing payment link at store.sgit.ai↗, where the paying happens on the payment provider's own pages. The store's own ledger says which levels have run for a paying buyer and which have not; the states above are copied from it on 15 September 2026, and two of the four have never been sold once. Every level says what does not arrive as well as what does.
You run a prompt. We turn what it finds into your policy.
Nobody interviews you at this level, and nobody needs access to anything. The agent that already holds the credential measures its own grant, drafts the mandate in your words, and you send us the two files it wrote. The prompt is public and travels in every vault as MAP-A-GRANT.md; the rules it follows are the ones the first measured policy on this site was produced under.
Buy level 3 for the application closest to yours
Or something not on the list, which starts here because no template exists for it yet. You get an order reference.
Run the prompt where the agent runs
Paste MAP-A-GRANT.md into the session of the agent that holds the credential. It measures what the credential lets it do rather than what the documentation says, in the fixed vocabulary of 23 capabilities and four barriers, and it follows seven rules: measure only what you are entitled to run, reversible probes only and clean up, never move a credential, note the door, an error is a symptom not a barrier, say what you did not test, leave the deployment as you found it.
Send us what it wrote
Two JSON files, grant.json and mandate.json, and the session record. No secrets: the prompt tells the agent to record that it can read a credential, and never to copy one.
We build, correct and recompute
The vault is built from your files. The mandate is corrected against the industry, the use case and the details you gave; the delta is recomputed; where the vendor's pages and your measurement disagree, the disagreement is recorded unresolved rather than settled by guessing. A person reviews the note of what changed and why.
Your vault comes back
Private, no public key, a name on the licence, the note beside it. It recomputes when the grant moves, and it is yours to hand to whoever asks what you authorised.
Done is a commit. You can check it from the vault's own history.
The payment link's success address is a page per level that says what happens now: what arrives and when, what you do next, how the key reaches you (separately, never on a page), and who to write to if it does not arrive. Each level is done when its commit is in your vault's history, and you do not have to take anybody's word for it.
| Level | Done when | Checked by | The page |
|---|---|---|---|
| 1 | The zip for the shape bought is downloadable from the page and its content hash matches the hash the shape publishes | Compare the hash on the page with the hash of what you downloaded; the page checks it in the browser | Level 1 →↗ |
| 2 | A vault exists, the licence file in it carries your name, the public key is off it, and you have opened it with your key | Your first clone: the licence file is in the tree | Level 2 →↗ |
| 3 | The corrected mandate and the recomputed delta are committed, and the note of what changed and why is committed beside them | The commit is in the history and the note names every changed row | Level 3 →↗ |
| 4 | Both sessions held, the record of what was asked and answered committed, and the sign-off file committed with the professional's name and the date | Three files in the tree, and the sessions dated in the record | Level 4 →↗ |
Level 1 is downloaded on the page, with the hash beside the link. Levels 2, 3 and 4 are a follow-up from a person within 24 hours of the payment landing: the key, the prompt step, the first session. If the record says we cannot keep that, the number moves here first. How the store's payment links reach those pages is written down for the store team on the after-payment debrief↗.
The library is the argument. The instance is yours.
Everything describing a_ deployment is free, and the document describing _your deployment is not. The templates are public with published read keys because a policy nobody can check is a policy asking to be trusted, and the whole point of this document is that it can be checked.
- The free draft is the top of the sales motion rather than a giveaway. Correcting our draft is how you tell us what you actually intended, and the intent is the one input we cannot derive. So the free tier and the elicitation are the same step, and that is by design.
- The prompt is free on purpose, and it is not sold as a skill. The portable part of the agent-skill format carries instructions and cannot carry a constraint, so the document that bounds nothing is the free one. What is paid for is independence: at every level more of the result is yours and less of it depends on us still being here.
- A behaviour policy reduces accidents. It does not stop an attacker. A rule somebody wrote down shapes what an agent tends to do, not what it can do. What bounds a grant is a setting, a scope or a gateway, and Lab 05↗ works one case through — including four free settings you should turn on before paying us anything.
The question you will be asked is what you did authorise. That document is the thing on the paid side of the line.
Read one first. Then buy yours.
Fifteen example policies, read live from their vaults with published keys, cost nothing and need no account. When you want the one that says what you authorised, it is four levels at the store.