sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · risks.sgit.ai · llms-full

Reading room / risks.sgit.ai / llms-full.txt · section 47 of 58

Release history

Every push to dev is a release: CI validates the site, verifies the version bump, tags the commit v{release}.{major}.{minor}, and deploys to GitHub Pages. The version is owned by admin/build/version.txt and must agree with the release commit's subject. How it works.

Version | Date | What shipped |

v0.2.2 | 27 Aug 2026 | The plan that was nearly lost, put back — and the difference between “not destroyed” and “visible”. The proposal for the execution boundary was the vault's index.html for exactly one commit, and the implementation commit overwrote it. Nothing was destroyed — it was still there in the commit history, which is what a versioned store is for. But nobody holding the read key would ever have found it, because a vault reader opens the app entry and sees the current tree. For two commits the plan existed only where nobody looks.

It is restored as proposal.html, a page in its own right, with one change made to it and the change stated rather than implied: a navigation strip inserted after <body>, because a document with no way back out is a document a reader leaves. 18 lines added, 0 removed, 792 bytes. The untouched source travels in the vault as build/proposal-source.html, and the original bytes remain at commit obj-cas-imm-678bd9b6e7cc, so “unedited” is a claim anyone with the read key can check rather than one they have to accept.

The vault's own front page now opens on the choice between the two, which is what makes the pair worth having: the proposal registered five expectations and all five held, and that sounds better than it is, because three were close to tautologies once the data model was fixed. The load-bearing part is that two predicted failures and got them, and that three findings nobody registered turned up during the build and changed the model rather than the code. A plan quietly rewritten to match its outcome can never show any of that. plan.html is now the scorecard rather than the plan, and says so in its first paragraph.

On this site: the example page gains a section naming both documents and what each is, the vault's derived facts move to 36 files · 809 KB · 5 commits · 9 pages behind 1 app entry, and the five-vault totals follow. The vault's credential audit was re-run across the enlarged tree — 36 files, 92 raw hits, all 92 ruled out, up from 77 because the restored proposal arrives with its own inline stylesheet and therefore its own copy of the four CSS declarations that generate the false positive. A rising count with an unchanged ruling is the normal case; a hit that is not a CSS declaration would not be, and there has never been one.

|

v0.2.1 | 27 Aug 2026 | Numbers derived rather than typed, and the verification stated at its real strength. Every published figure about the Execution Boundary vault is now derived from the vault. v0.2.0 described it, and description got two of them wrong: it said “8 app entries” when app.json declares exactly one and the eight are pages behind it, and it said two commits when the log shows four. The vault gained build/facts.py, which reads the tree, the commit log and the manifest and prints the catalogue line; the site now carries what that prints — 34 files · 648 KB · 4 commits · 8 pages behind 1 app entry — and the five-vault totals move with it. The publishing method asks for derived facts and this is why.

What the embed was actually verified to do, said at its real strength. The claim on the page was that the live render was unverified from the build machine, which was true and unhelpfully coarse. Against the real endpoint it is now established that the published read key clones the vault to byte-identical files, that the objects carry access-control-allow-origin: *, and that the exact fetch-and-decrypt sequence the embed performs resolves the ref, walks the commit tree to every file, and decrypts the entry page. The one step still unexercised is the sandboxed iframe booting the app — because the machine this was built on cannot reach the network from a browser, only from the shell. Both halves are on the page, in a row of their own, rather than one implying the other.

The near-miss now travels with the artefact, not just with the site. The vault's PUBLIC.md carries the write-up, because the credential that was nearly published is the vault's and a finding filed only at the far end of a link is a finding that goes missing. Its audit was re-run over the changed tree — 34 files, 77 raw hits, all 77 ruled out, four more than the first run because this file now quotes four CSS declarations as examples of the false positive, which is the scan finding its own worked example. And the illustration in it names no part of the real credential: a truncated write credential is still a piece of a write credential.

|

v0.2.0 | 27 Aug 2026 | The execution boundary — the first thing on this site that computes, and the first vault this site built rather than borrowed. A fourth worked example, and it is not a document. It came out of a LinkedIn exchange in which a correspondent set a specific test: an action authorized on defined conditions, queued, and one material condition changing before execution — “whether, at the execution boundary, the system can establish from the available evidence that the predicates supporting that authorization still hold”. They asked for it small: one decision object, one controlled material change, one consequential execution point. It was built to that constraint and no wider.

Three verdicts, not two, and the third is the contribution. established · not established · cannot establish — no evidence inside a horizon, so nothing says the predicate is false and nothing says it is true. Most systems have an allow state and a deny state and quietly route “I don't know” to the first. That is not-knowing-is-a-fact moved to the moment somebody presses a button, and consistent with C2 the boundary routes rather than blocks: re-establish, escalate, or challenge.

The scenario is deliberately undramatic. A schema migration MIG-114 is authorized at 18:20 for an 02:00 change window, in part because it was reversible — a verified restorable backup existed. The nightly backup-verification job is then suspended for the duration of the change window, which is standard practice. The window that queues the action is the same thing that stops its evidence being refreshed. By 02:00 the last verification is fifty minutes past its 24-hour horizon. Nothing failed, nothing was revoked, the grant is present throughout — and the predicate that expired was the one carrying reversibility.

Two results were pre-registered as unwelcome and arrived that way. Five expectations were written down before any view existed; all five held, and the informative ones are the two that predicted failure. Run D returns a confident, incorrect established — an integrity check finds the backup unrestorable and never reaches the graph, so every predicate reads satisfied and nothing is amber. It ships, so that the claim “the boundary check makes execution safer” arrives with its counter-example attached. And the instrument cannot distinguish “nobody looked” from “somebody looked and did not record it”. A control arm runs the same query against a decision stored as a field rather than a node and terminates at hop 2, which makes C33 a precondition rather than a modelling preference.

The 43rd concept, and the first this site authored rather than consolidated. C43, the persistence hope — hoping the conditions that justified an authorization still hold at execution, and inferring that they do from the grant still being present. It sits beside the two hopes nhi.sgit.ai names, both of which are about the grant; this one is about time. Because a research site that consolidates a corpus and quietly adds to it is no longer reporting the corpus, concepts.json gained an origin field — corpus or authored-here — the concept index gained a provenance pill, and the gate now fails if an entry is missing it.

The vault is embedded, not copied. Eight pages of instrument live in vault r48ncij0 and are decrypted in the reader's browser using sgit.ai's embed technique, carried over verbatim with attribution rather than reimplemented. No copy of the app or its data exists in this repository, so a push to the vault changes the page with no site rebuild. The read key is printed in the open on the page, because read access is the whole credential: sgit_rk1_990d25fd8ecab928ded37c6a8c86a461e7247f6d3838bd43e7468e93cc2e07c4:r48ncij0.

The credential tripwire fired, on this release, on our own page. The vault-viewer link was pasted in exactly as it had been sent — and as sent it was the vault key, in the legacy passphrase:vault_id form that carries write access and has no prefix to announce itself. It appeared three times in one file. The gate refused the build on all three, before the commit, so nothing reached the repository or the site.

It is recorded here rather than quietly corrected, and the check was then widened rather than narrowed: it now recognises a read key by shape and by the published sgit_rk1_ prefix, and the near-miss is written into the source of the rule that caught it. The estate's convention is that an audit finding published beside the artefact is worth more than a clean history nobody can verify — which is easy to hold when the finding is somebody else's.

Also in this release. The vaults page carries a fifth vault and drops a claim that had become false — this site now reproduces a read key, deliberately, and says when that changed and why. /shipped/ gains a row for something that runs, with “and is not an engine” in the status column rather than in a footnote, and a new row under what does not exist: an in-line check that refuses an execution. /examples/, the home page, llms.txt, index.md and the manifest all follow the counts.

|

v0.1.0 | 23 Aug 2026 | The site, first release — pipeline first, then the eight sections the brief sequences first. The pipeline before the content, so that every release from here goes through a gate that already works: validate → auto-tag → deploy, carried over from the sibling sites with the merge-commit anchoring and the SIGPIPE fix those sites had to learn the hard way. Ten checks, three of them written for this site specifically. The over-claim tripwire is the load-bearing one: nothing in this risk corpus is implemented in code, so no page may say the engine is built, shipping or installable — a page may state such a claim only by marking the element data-not-built, which exactly one element on the site does. The do-not-publish tripwire pattern-matches the distinctive strings of the four Tier-3 manifest rows across the whole tree, so a later edit cannot quietly reintroduce a comparative vendor assessment or a contract term. And internal links are checked to the fragment, not just to the file — because this site's promise to an agent is that all 42 concepts have stable anchors, and a promise that is checked is a fact.

/acceptance/ — the founding inversion, five pages. Underwriting rather than prediction, with the temporal move that makes the rest coherent: the risk already exists the moment the permission is provisioned, so the only variable is how long. There is no deny button, including the correction that replaces one button with three moves — accept, escalate, or challenge the fact — because presenting a single button to someone who feels cornered produces resentment rather than compliance. The interval ladder as a six-row table with the operational response and the cost stated per rung, the default at one month set deliberately just above the incident line, and rungs struck off where a remediation is physically impossible. Unaccepted equals critical — escalation without an escalator, aimed at attrition rather than refusal. And the underwriting graph, with override and compound pre-approval published as proposed and unfinished rather than tidied up.

/acceptable/ and /ladder/ — the vocabulary and the machinery. Two orthogonal axes drawn as four quadrants, appetite as a revealed band computed from two signals, and the Article 9(5) gap where the obligation to judge acceptability is imposed and the standard is not supplied. Then the definitional spine: the grounding ladder with each rung defined by its required paths, node type formulas including the honest limit that no formula language exists and nothing executes one, bridges rather than merges with the worked external bridge, and not-knowing-is-a-fact.

/plug/ — moved off the commercial site, with a correction it does not carry. Two symmetric risks, the four-way time intersection, the 12–18 hour detection floor, and the pillar correction that the plug always exists — what older registers recorded as “no plug” was zero recoverability, and restating it that way turns an unassignable blank into an ownable finding. Recoverability gets its own page for the flagship query: show me every accepted risk whose recoverability is zero.

/examples/ — the proof layer, seven pages. The three worked graphs with their real counts (59/75, 51/53, and the Article 26(5) inventory), the four live vaults with the read-keys-yes-write-keys-never rule stated as the pipeline property it is, the ten scenarios, and the seven-row plug register. Two things are stated rather than fudged: the 2FA data file is not mirrored here (task T5) because a reconstructed graph presented as the original would be worse than a missing one, and the browser-isolation graph's counterweight figure is published in both directions rather than in the one that flatters the argument it sits in.

/concepts/ and /agents/ — the commissioned audience. All 42 concepts with a stable anchor each, a one-line definition, maturity stated honestly, canonical source path and the page that argues it — plus the same 42 as structured data with the reading order and the six teaching altitudes. Both are generated from one definition, and the gate re-checks the count, the fields, the version and every anchor at release time, so they cannot drift. llms-full.txt concatenates the prose of every page plus all eleven source documents, because agent fetch tools frequently refuse URLs a search has not returned and a single-file surface is the practical mitigation.

And the parts a research site owes a reader. /shipped/ says the engine is not built, first rather than last, with the grep result quoted. /network/ carries the eight-site boundary map, eight open questions published unresolved and seven honest tensions — including that the model rates the ability to stop and refuses to provide it. /origins/ traces the trajectory from February's “residual risk: acceptable” to June's “there is no deny button”, and names the canonical brief that eight documents cite and nobody can read. /documents/ publishes the eleven sources and, at equal length, what was deliberately excluded and why. /about/participant.html discloses that this site is published by the project that sells the product, and then states five places the model loses.

|

Versioning. v{release}.{major}.{minor}. Every push to dev is a minor release and must bump admin/build/version.txt exactly once, with the same version in the commit subject as site vX.Y.Z: …. CI verifies the two agree and that the bump is the next minor (or a deliberate major), then tags the release commit — HEAD on a direct push, HEAD's parent when a pull request lands as a merge commit. The first run backfills tags for any historical release from the commit subjects.


== briefs/README.md — source document, verbatim