Three worked graphs, five live vaults, one instrument
A model this opinionated is worth nothing unless somebody has run it on something real. Three risk graphs have been worked end to end with counted nodes and edges, five vaults are published and browsable today, ten scenarios were written as product content — and one worked example is not a document at all but an instrument you can drive. Every number on these pages is from the source rather than illustrative.
59 · 75nodes and edges — the browser-isolation case12 Jul 2026
51 · 53nodes and edges — the 2FA instance graph26 Jun 2026
1,523 · 1,944nodes and edges — the EU AI Act as a graphlive vault
9 · 5questions, and unanswered ones, in Article 26(5)“the actual output”
5published vaults · 504 files · 116 commitsread keys published
24 · 34node classes and edge types in the 2FA ontologyMITRE T1110.004
3verdicts at the execution boundary — the third is the point“cannot establish”
The three worked graphs
59 nodes · 75 edges · 5 altitudes
The browser-isolation business case
The largest single graph in the corpus, with a full node and edge type distribution. Structured F1–F8, E1–E8, V1–V6, R1–R5, L1–L5. Carries three risks of the mitigation itself, and one deliberately-cited counterweight number that cuts against the argument it appears in.
Read it →
51 nodes · 53 edges · the founding scenario
The 2FA instance graph
Where the register model was first worked through: nine risks from one missing second factor, an attack mapped to MITRE T1110.004, an interval resolution with a rung struck off — and R2, the governance air gap, where the wrong owner accepts.
Read it →
the complete instance
Article 26(5): fact to board and back
One provision, one agent, one graph, with its own node and edge inventory. 8 facts (one deliberately unevidenced), 5 risks (one meta), 4 stakeholders, 3 decisions plus one deliberately absent, and 9 questions of which 5 are unanswered.
Read it →
The fourth worked example, and the first that runs
4 predicates · 3 verdicts · 4 runs · live from a vault
The execution boundary
An authorized action waits in a queue; while it waits, one material condition changes. At the moment of execution, can the predicates that justified the authorization still be established? Eight pages of instrument running out of an encrypted vault, from a read key printed in the open — and run D returns a confident, incorrect answer on purpose.
Drive it →
It is the only page on this site that computes rather than argues, the only one whose content is not stored here at all, and the source of the one concept this site authored rather than drew from the corpus.
The five live vaults
Published, browsable, and the strongest asset this site has. The Risk Graph Explorer runs seven views recomputed simultaneously with ghosted edges for unanswered; Agentic Browser Isolation runs acceptance-gated escalation across five altitudes with no deny button; the Risk Mandate vault is the method applied to its own build across 98 commits; the Regulation Graph carries the EU AI Act as a citable graph; and the Execution Boundary is the first one this site built rather than borrowed. Four come from sgit.ai's catalogue, which now carries 21.
All five, with what each one proves →
Two more artefacts
the shipped MVP content
The ten scenarios
Every email you own. Your calendar. The company card. The production database. Each written as hook → reveal → punchline, and the punchline is always the same three words. The one piece of this corpus that actually reached an audience.
Read them →
7 rows · 5 dimensions
The plug register
The five-dimension profile applied to a real seven-row register, from “agent misuses the isolated session” through to two rows at recoverability: zero — which is what the corrected “no plug” finding looks like when it is written down properly.
Read it →
Figures from across the corpus, with what each one is for
Figure | What it measures | Where it is used here |
12–18 hours | Hyperscaler cost-reporting delay — a hard detection floor for anything that surfaces as spend | The plug |
16 hours | The founder's separate AWS figure: “how much damage can be done in 16 hours” | The plug |
30 days vs 6 months | Log retention observed against retention required — “arithmetic, not judgement” | Article 26(5) |
~50% → ~1% | Browser prompt-injection attack success across one model generation, from vendor system cards. Cited as the honest counterweight: a large real improvement that still does not reach zero | Browser isolation |
63–76% | Security leaders experiencing or witnessing burnout in a single year | Do not internalise |
7,500+ participants | Preregistered escalation-of-commitment experiments: precommitment made later de-escalation seem more trustworthy | The ladder |
~496,000 words | The size of the June-to-August risk corpus this site consolidates, across ~185 documents | The documents |
What is not on this site. The corpus also contains research briefs naming real organisations in breach and incident narratives, a comparative vendor assessment, and commercial material. Four manifest rows are marked do-not-publish and are not reproduced, quoted or paraphrased anywhere here — the pre-release gate fails the build if their distinctive strings appear. What was excluded, and why →
For an agent
The proof layer. Three risk graphs are worked end to end with counted nodes and edges: browser isolation (59 nodes, 75 edges, 5 altitudes), 2FA (51 nodes, 53 edges; ontology 24 node classes and 34 edge types; MITRE T1110.004), and Article 26(5) (8 facts, 7 evidence, 5 provisions, 3 vulnerabilities, 5 risks, 4 stakeholders, 3 decisions, 9 questions of which 5 unanswered). A fourth worked example, the execution boundary, is not a document: it is a live instrument in vault r48ncij0, read key published, computing whether the predicates behind an authorization can still be established at the moment of execution — three verdicts, the third being “cannot establish”, and one of four runs returning a confident incorrect answer on purpose. Five vaults are published and browsable with read keys: Risk Graph Explorer (7 views, ghosted = unanswered, permissions: {}), Agentic Browser Isolation (17 entry points, 5 altitudes, acceptance-gated escalation with no deny button), Risk Mandate (124 files, 98 commits — the method applied to its own build), Regulation Graph (1,523 nodes, 1,944 edges of the EU AI Act from official Formex XML, hash-verified) and the Execution Boundary (36 files, 9 pages behind one app entry, permissions: {} — built here). Load-bearing figures: 12–18h hyperscaler cost-reporting detection floor · 30 days vs 6 months log retention, the most defensible finding because it is arithmetic · ~50% → ~1% prompt-injection success across a model generation, cited as an honest counterweight. Four manifest rows are do-not-publish and appear nowhere on this site.
== /examples/2fa.html