What is argued, and what runs
The sibling sites all publish a page separating what exists from what is designed. This site inherits that convention with an unusually empty column, and the honest sentence is short: this is a research site. The concepts are argued, the worked examples are real graphs, five vaults are live and browsable, and one worked example computes rather than argues. The engine is not built.
That last clause changed at v0.2.0 and it is the sort of change this page exists to police. The execution boundary is a vault app that evaluates a formula against data and returns a verdict — so something on this site now runs. It is still not an engine: it holds one invented scenario, it observes rather than gates, and it stops nothing. A worked example that recomputes is not a product, and the row below says so in the status column rather than in a footnote.
the measurement Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository's Python return zero matches. Not few. Zero.
The project's own reality file is equally direct, and it is quoted here rather than paraphrased: “All items below are PROPOSED. None have been code-verified. Do not describe any of these as existing features.” — team/roles/librarian/reality/ai-agents/proposed/risk-mandate.md
That is the whole of it. There is no partial implementation, no prototype behind a flag, and no internal build that the public documents are lagging behind.
What exists
Artefact | What it is | Status |
Five published vaults | 504 files and 116 commits between them, browsable in a browser with no account. The Risk Graph Explorer runs seven views with permissions: {}; Agentic Browser Isolation runs acceptance-gated escalation across five altitudes; the Risk Mandate vault carries 98 commits of the method applied to its own build; the Regulation Graph carries the EU AI Act as 1,523 nodes; and the Execution Boundary is the first this site built rather than borrowed | published |
The execution boundary | The one thing on this site that computes. A vault app that evaluates AdmissibleForExecution against one invented scenario at a chosen moment and returns one of three verdicts. Four runs, eight pages, read key published. It is a worked example that recomputes, not a system: one scenario, no storage, no integrations, and it emits a verdict rather than blocking anything. Run D returns a confident wrong answer on purpose | runs — and is not an engine |
Three worked risk graphs | 59/75, 51/53 and a full node-and-edge inventory for the Article 26(5) instance. Counted from the sources rather than estimated | written |
The ten scenarios | Hook, reveal, punchline — the corpus's only audience-tested artefact, and the content behind riskmandate.ai's scenario product | shipped |
riskmandate.ai | A vault-powered static site. Real, public, and the commercial half of this split | published |
This site | 43 concepts — 42 consolidated from ~496,000 words across ~185 documents and one authored here — with a definitions endpoint that says which is which, and a gate that enforces the honesty constraint on every release | you are reading it |
What does not exist
What the model describes | What exists |
An engine that records acceptances, tracks intervals and fires at expiry | nothing — how the interval is enforced is open question Q5 |
Storage, a schema or an API for a risk register | nothing |
A check that sits in-line and refuses an execution when the authorization can no longer be established | observed only — the execution boundary emits a verdict and gates nothing, and the model refuses the enforcement role on purpose |
Roll-up, propagation, or the unaccepted-equals-critical mechanic running automatically | demonstrated on data in one vault, hand-built, not computed |
Node type formulas as executable queries | no formula language exists — Q1. Every formula in the corpus is English prose describing a path pattern |
Relevance fade, or the register replayed as a narrative | described, not specified |
RAMM as a testable model | one of five levels has a stated predicate — the other four are named only |
Air-gap detection | acknowledged open problem |
Override authority, or compound pre-approval | proposed and never worked through |
Why this page exists, and why it leads rather than hides
Three reasons, in order of how much they matter.
1
Because over-claiming here would poison the network
Eight sites share a domain, a voice and an author. A single page on one of them describing a design as a shipped feature makes every claim on the other seven negotiable. The cost of one over-claim is not local.
2
Because it is what makes the split from riskmandate.ai work
A commercial site has to talk about what its product does. A research site has to talk about what is true, which includes the absence of a product. Those are genuinely different jobs, and trying to do both on one property is what left nine concept pieces described and unpublished on the commercial site.
3
Because the framing is not a weakness
“~496,000 words of design and no implementing code” reads badly only if the site was pretending to be a product. As a description of a research property it is unremarkable — and the five live vaults mean it is not vapour either. The engine is the missing piece; the argument, the worked examples and the artefacts are not.
How the honesty constraint is kept
Not by remembering it. The pre-release gate pattern-matches implementation claims across every page in the tree, and a page saying the engine is built, shipping or installable fails the build. A page may state such a claim only by marking the element data-not-built — which is exactly what the quoted reality-file sentence at the top of this page does, and the only such marking on the site.
The same gate refuses to publish four categories of Tier-3 source material, refuses anything that looks like a vault key, and requires every page to carry an agent block. All ten checks →
The build order, published unresolved
The brief set a ten-step order. This release covers the first eight; the rest is stated rather than quietly dropped.