sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · risks.sgit.ai · llms-full

On this page

Reading room / risks.sgit.ai / llms-full.txt · section 55 of 58

06 — Boundaries, Redaction and House Style


1. The seven-site boundary map

risks.sgit.ai is the eighth property in the estate and the second to be carved out of an existing site rather than built from a gap. Getting the boundaries right on day one is what stops eight sites becoming eight competing copies of the same argument.

Genuinely risk's own (risks.sgit.ai)

Everything in §1 concepts C1–C42, specifically: risk acceptance as underwriting; no-deny; the interval ladder; unaccepted-equals-critical; accepted-vs-acceptable; the grounding ladder; node type formulas and ontologies-of-ontologies as applied to risk; the register as a graph of graphs; fractal registers and relevance fade; technical vs business owner; Confirmed/Validated/Accepted; the underwriting graph and propagation; cascade and air gaps; not-knowing-is-a-fact; CIA blast-radius expansion; the plug question, plug profile and recoverability; altitude; appetite as a revealed band; the psychology of the physical act; the level ledger; register density; residuals; meta-risks; register health and gaming; three moves; decision-as-node; question-is-not-a-risk; do-not-internalise; the evidence economy's acceptor/certifier split; confidence bands; the two underwritings; observability as a risk dimension; five whys as a domain translator; RAMM; AOMM; the plug-pull maturity model; the harm taxonomy; the agentic incident taxonomy; and every worked example in §4.

Belongs to graphs.sgit.ai (with risks.sgit.ai citing, not owning)

The general graph machinery, independent of risk: directed edges with named inverses and query paths that prevent node explosion (06/26/semantic-graph-and-query-paths/v0.33.35__arch-brief__...directed-edges...md); path properties read as language and multi-graph creation paths (.../v0.33.35__arch-brief__...path-properties...md); fractal semantic graphs as an agentic operating layer (07/12/architecture/v0.33.48__arch-brief__...fractal-semantic-graphs...md); browser-local query engines — Oxigraph/Kuzu/DuckDB WASM (07/28/regulation-graph-and-acceptability/v0.33.53__arch-brief__...customised-standard...md); the graph canvas REPL and "never render the whole graph" (08/02/vault-as-substrate/v0.33.55__arch-brief__...graph-canvas-repl...md); the 08/09 graphing-text cluster (enrichment and shared anchors, Wikidata as the concept layer, evidence packs attach-never-mutate, index-is-not-a-source, refactoring meaning); and digital twins in their general form (06/26/digital-twins-and-world-models/, 4 docs). The boundary rule: node type formulas as a mechanism are graphs.sgit.ai's; the grounding ladder as a risk formula is risks.sgit.ai's, and should cite the mechanism rather than restate it.

Belongs to nhi.sgit.ai

The entire 06/04/nhi-2.0/ series (17 documents, ~50,000 words): agent identity as a startup thesis, cloud permissions per API, living off the land, multiple identities working together, permission granularity, PKI foundations, semantic knowledge graphs of identity, skills-come-with-identity, temporal permissions and time travel, web of trust and agent trust scores, plus the NHI commercial/moat/open-source briefs. Also the agent-mandate ontology's identity half (Principal, Agent, AgentTwin, CapabilityCertificate) and the 08/19 service-twin and agent-enrolment briefs. The one exception: 06/04/nhi-2.0/v0.32.3__strategy-brief__sg-send-nhi-2.0-risk-management-acceptance-underwriting-roi.md is risk's origin document and should be cited by risks.sgit.ai as the first appearance of "the risk already exists", while living on nhi.sgit.ai.

Belongs to pki.sgit.ai

Attribution, non-repudiation, signing and key topology: team/roles/appsec/reviews/02/21/v0.5.0__review__pki-architecture-security*.md; 08/19/briefs/v0.33.60__cross-team-brief__pki-site-review-mandate-is-the-gap-registry-is-the-missing-half.md; 08/19/briefs/v0.33.60__arch-brief__agent-enrolment-without-borrowed-authority-append-lane-is-the-narrow-door.md; the vault-authorisation cluster (08/06/vault-authorisation/, 6 docs — statecharts, kernel reference monitor, plugins-are-capability-grants, ambient authority as the injection root cause). Note the tension: the 19 Aug PKI-site review says "mandate is the gap, registry is the missing half" — meaning pki.sgit.ai currently carries mandate material that arguably belongs with risk. Worth a coordinated split.

Belongs to sg-sentinel.sgit.ai

Anything that is in-line enforcement, which the risk corpus explicitly refuses. 05/24/sg-sentinel-batch2/v0.27.60__arch-brief__sg-sentinel-agent-governance.md (reverse-proxy agent governance, controlling what agents do in dev and prod) is the clean case. The risk corpus's own stated boundary, from 07/23/posture-and-core-primitives/v0.33.50__strategy-brief__...never-in-line...md and the honest-tension table in 07/24/.../v0.33.51__strategy-brief__...ability-to-stop...md: "The model rates the ability to stop but does not provide it; a customer who scores badly will ask us to supply the stop button, which is exactly the enforcement role the corpus refuses." risks.sgit.ai should state this boundary explicitly — it measures and evidences; sg-sentinel enforces.

Belongs to newsroom.sgit.ai

The evidence-economy supply side: news-backed evidence vaults run as an editorial mini news organisation, news stories as Evidence on the grounding ladder, author micropayments as a consumption-event billing primitive, MyFeeds and Trust-as-a-Service, evidence packs as a service, and paying-the-fact-creator. Files: 07/05/evidence-economy/ (3 docs), 07/31/projects-budgets-and-evidence/v0.33.54__strategy-brief__...paying-the-fact-creator...md, 05/17/v0.27.55__strategy-brief__myfeeds-*, 05/17/v0.27.55__arch-brief__myfeeds-website-rebuild-three-primitives.md, 05/17/v0.27.55__dev-brief__articles-as-vaults-publishing-workflow.md. The split: the demand side — force of proof, the risk-acceptor/fact-certifier split, the two prices, and confidence bands driving evidence purchases — is risk's own, because it is generated by accountability. The supply side — how evidence is produced, certified, priced and paid for — is the newsroom's.

Additional boundaries worth naming (not in the brief but present in the corpus)



2. Redaction watch-list

This corpus has the highest redaction load of any pack so far. It names real vendors critically, contains a live contract draft, and carries investor figures. Run these checks before any bulk publication.

9.1 Named real companies assessed critically — highest risk

9.2 Codenames that may map to real entities

9.3 Pricing, commercial terms, and investor material

9.4 Named individuals

9.5 Live secrets and operational detail (pre-history)

9.6 Documents already carrying their own disclaimers (good precedent to preserve)

Many of the best risk documents already model the right posture and their disclaimers should be carried across verbatim to risks.sgit.ai rather than stripped: "Legal points are factual and not legal advice"; "The organisation is invented; every invented element is marked"; "Generic to the secure-browser and browser-isolation category. No vendor is named"; "The scenario is a product deployment example, shortened and illustrative, not any customer's register"; "Offered to be built on and challenged"; and the CC BY 4.0 release line at the foot of nearly every brief — which is what makes public republication straightforward in the first place.


3. House style, inherited

Full treatment in the graphs pack 06__house-style-and-conventions.md. Essentials, with the risk-specific emphasis:

Vault rules: publish read keys, never write keys · escrow the write key before publishing, or the vault is frozen · audit before publish and adopt the PUBLIC.md convention · no metered capability behind a published read key — the Risk Graph Explorer's permissions: {} is the model.

Licence: CC BY 4.0 per the 21 August decision. docs.diniscruz.ai prior art is CC0 at source — state the source licence per page.


4. Two demonstrations to build in

  1. Run the site's own risk register in the open. The corpus argues that a register is a graph, that unaccepted equals critical, and that the register maintains itself because accountability manufactures demand for evidence. A research site that publishes its own register — its open questions as unaccepted risks, with intervals — demonstrates all three at zero cost.
  2. Ship the definitions endpoint. 42 concepts as JSON: name, one-line definition, canonical source, maturity, related concepts. It is the single highest-value artefact for the commissioned audience, nothing else in the estate has one, and it is a day's work from 01__concepts-index.md.

5. Provenance for moved and republished pages

Two classes of source, two rules.

From riskmandate.ai — the page moved rather than being copied, so record the move:

moved_from:      https://riskmandate.ai/acceptable.html
moved_on:        2026-08-22
leave_behind:    stub published at source, linking here
curation:        edited            # commercial framing removed

From docs.diniscruz.ai — the full provenance contract from the newsroom pack applies: first_published is the original date, original URL, original co-authors, honest curation label, source_licence: CC0-1.0, and rel="canonical" for verbatim republication. Never redirect the source.

From the __Send repo — never published, so the version tag is the address:

source_repo:      https://github.com/the-cyber-boardroom/SGraph-AI__App__Send
source_repo_path: team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__...
source_version:   v0.33.36
first_written:    2026-06-28
source_licence:   CC BY 4.0

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).


== briefs/07__gaps-and-open-questions.md — source document, verbatim