sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

The Agent Behaviour Policy library, wider and readable: the label, the lethal trifecta, the diagram, a resizable panel, and a page for what is next

The library page, one release on, corrected against the project lead's reading of it.

It says Agent Behaviour Policy, every time. The key thing a stranger has to learn on this page is that this is a behaviour policy for an agent, so the words are used in full — in the menu (Agent Behaviour Policies), in the hero, on every section. The hero now says what an Agent Behaviour Policy is in one paragraph, says these are the examples and that for most people they will be the first they have seen, and has one link, to the model. The two buttons that scrolled down and jumped to one vault are gone.

Wider, and the panel is yours to size. Most people reading this have a wide screen, so the library uses it: four tiles across at a typical desktop width, with the preview panel on the right. A vertical bar between the two drags the panel wider or narrower, remembers the width on your device, and double-clicks back to the default. The panel scrolls on its own now; before, a long policy could not be scrolled past the fold.

The label. The punchline is the numbers, so the panel now draws them: one cell per capability in the grant, green where the mandate wanted it, amber where it was not asked for and nothing stands in the way, outlined where a boundary does, a red mark under any row the mandate told the agent not to, and dashed cells outside the grant for what was wanted and not granted. Under it, a box in the shape of the list of ingredients on a packet: what this agent could do to you — the counts, then the side effects in plain words (could delete files anywhere the account can reach · could send data to any host on the internet · could create thousands of scheduled entries), each with its capability id and whether it can be undone; then what the agent was told not to do and only told; then the lethal trifecta — private data, untrusted content, a way out — with each leg marked present, present but behind a boundary, or absent, and the sentence that follows: all three with an unbounded way out is the shape that leaks, and the mandate cannot change that; only a barrier on one leg does.

"Refused" was the wrong word. A row the mandate refuses is still one the grant permits, and refused read as if the agent could not do it. It now says told not to, on the library, on the vault pages and in the panel's legend, with the meaning spelled out on hover.

A box opens the policy too. Clicking a tile or a row previews it in the panel; the title and an Open the policy → link on every tile, and the arrow on every row, go straight to the policy's page. Before, only the panel's button did.

Filters inside the policy. The row list in the panel filters to wanted, told not to, unstated, unbounded, behind a boundary, or cannot be undone, and counts what it shows.

What is next has its own page. The five connectors not yet researched and the three business functions moved to Which Agent Behaviour Policy next?↗, with a suggestion form that opens a message in your mail client, a vote for one already listed, and a vote button marked coming soon on every tile. The library page ends where the library ends; the sections that used to follow it — the queue, the reading mechanism — were losing the reader after the part that mattered.

Nothing in any vault changed in this release.