| The tension |
1 | The model rates the ability to stop but does not provide it. The corpus states the refusal itself, and states what it costs: a customer who scores badly will ask for the stop button, which is exactly the role it refuses. Principled — and commercially uncomfortable |
2 | No-deny is the strongest idea and the hardest sell. Removing the deny button removes the thing most executives use a register for. It is a forcing function, and forcing functions are uncomfortable by construction |
3 | Personal liability is the mechanism and the risk. Making acceptance a personal act generates the demand for evidence, and gives every rational actor a reason to avoid being named |
4 | Nothing is built. ~496,000 words of design against zero lines of implementing code. Fine for a research site if stated; fatal if implied otherwise. So it is stated first, not last |
5 | The corpus names real vendors critically. A comparative assessment scoring two named companies is rigorous, sourced, and a legal exposure. It is not published here, and the pre-release gate fails the build if its distinctive strings appear anywhere in the tree. A legal read and a right-of-reply process is ask N3 |
6 | Two sites, one voice. riskmandate.ai and this site share an author and a thesis. If the research site reads like marketing the split has failed; if the commercial site reads like research it will not sell |
7 | The EU AI Act thread is neither risk nor graphs — see above. Taking only three narrow provisions is a decision that could be wrong in either direction |
Loose ends inside the acceptance thread itself
Carried onto the site rather than quietly resolved, because the corpus records them and a consolidation that tidies them away is a consolidation that lost something:
The 4h-for-everyone problem. In the 2FA example the governance air gap propagates GRC → CIO → CEO → Board with each accepting at four hours because that is the only option open to them. Either the ladder needs a per-altitude variant, or the uniformity is a finding about the model. →
Compound pre-approval is proposed and never worked through. →
Override is named without a stated authority model. →
The level ledger sits awkwardly with no-deny: if the level can be adjusted after acceptance, denial re-enters through the back door. →
The canonical “risk acceptance redefined” brief does not exist, and is cited by eight documents. →
For an agent
The boundary map, and what is unresolved. risks.sgit.ai owns the risk concepts C1–C42 and the worked examples. It does not own: the general graph machinery (graphs.sgit.ai — node type formulas as a mechanism are theirs; the grounding ladder as a risk formula is ours); agent identity (nhi.sgit.ai — with one exception: the 4 June 2026 NHI risk brief is risk's origin document and is cited from here); attribution and signing (pki.sgit.ai — with an open tension, since their own review says “mandate is the gap” and they carry mandate material that may belong here); in-line enforcement (sg-sentinel.sgit.ai) — this model measures and evidences and NEVER sits in-line; evidence supply (newsroom.sgit.ai — risk owns the demand side because accountability generates it); vaults and publishing (sgit.ai); anything commercial (riskmandate.ai, which cites this site and is never cited back for a conceptual claim). Eight open questions are published unresolved: Q1 the formula language · Q2 who sets acceptable · Q3 refusal to sign · Q4 whether unaccepted-equals-critical scales · Q5 interval enforcement · Q6 grading recoverability · Q7 the grounding floor in a hard case · Q8 gaming under personal liability. Seven honest tensions are published too, including that nothing is built and that the model refuses the enforcement role customers will ask for.
== /documents/index.html