## The Lab: findings, interface mockups and open proposals, published as they happen

A new top-level section for work in progress. The rest of the site says only what it can
defend; the Lab is looser about *status* and no looser at all about sourcing, which is
what the four state labels are for.

- **[The Lab](lab.html)** — the index, generated from the entries, plus how to read
  each state. A finding is something quoted from a primary source. A mockup is a drawing
  to be argued with. A proposal is a change we are asking somebody else to make. An open
  question is one we cannot answer and would rather not have rediscovered.
- **[Lab 01 — the grant is user-shaped, not data-shaped](lab-connector-grants.html)**.
  What a connector actually grants when somebody plugs an assistant into their mail or
  their files. Four quotes, verbatim, from the vendors' own documentation, each verified
  against its source page on 12 September 2026: the narrowest Gmail scope that returns a
  message body is described as *view your email messages and settings*; Drive's default
  corpus is defined by Google as *files owned by or shared to the user*; Anthropic's own
  Microsoft 365 connector guide states that *site-specific permissioning is not supported
  because the underlying search is tenant-wide*; and the official Dropbox MCP server
  requests eight scopes including two writes and two sharing scopes. Plus the four places
  a vendor's advertised capability and their granted scope disagree — published unresolved,
  because settling them would mean probing somebody else's service, which is out of bounds.
- **[Lab 02 — what buying a behaviour policy would look like](lab-abp-flow.html)**.
  Twelve stages from a stranger's first question to a recomputing vault with a read key
  they can hand an underwriter, with five drawn as interface mockups: the front-page
  encounter, the five-shape picker, the draft, the correction, and the delivery. None of
  it is built. The draft mockup is the load-bearing one and it carries no score, four
  counts, a barrier per capability and whose material each one touches.
- **[Lab 03 — changes we are asking of the behaviour-policy site](lab-abp-requests.html)**.
  Three open requests against `abp.sgit.ai`, which we render against and do not maintain:
  a `material` property for the capability grammar, four connector deployment shapes, and
  the provenance conventions we would need to render any of it. Published rather than
  emailed, with an argument for moving it to a shared vault if there is a second round.

**Nav.** *Lab* is top-level, between the demos and Lisbon. Its entries are unlisted,
because the index is generated from them and a dropdown of experiments would grow without
bound.

**One defect caught by review, and a test so it cannot recur.** The delivery mockup needed
a read key and got filled in with a real one — the Licence to Operate vault's published
key, paired with an invented vault id. It is a public key and nothing was exposed, but
sample data has to be obviously sample data. It is now a visible placeholder, and a test
asserts that no page in the Lab contains anything shaped like a read key. Tests: 20.
