A business plan, with one risk replayed
Published on sgit.ai for somebody else to build. The organisation, people and risk below are invented. The method is the one published on risks.sgit.ai, RiskMandate.ai and in the Risk Graph Explorer vault.
The method, in principles
Every risk is already accepted. The question is by whom, and until when.
| Principle | What it means in practice |
|---|
One risk, replayed
The interval is the decision
The acceptance ladder
| Rung | What it means |
|---|
The business
A service that runs the acceptance loop, in the gaps of the GRC platform
What you sell
The numbers, as a calculator
monthly recurring revenue
annual run rate
delivery cost a month
gross margin
material risks per consultant
capacity check
Assumptions, not measurements.
In this vault
Everything needed to start
| Path | What it is |
|---|---|
plan/00-START-HERE.md to plan/10-open-questions.md | The plan as documents: the idea, the method, the operating model, working in the gaps of the GRC platform, services and pricing, go-to-market, the first ninety days, investors, risks, and what is still open. |
risk/ | The invented risk replayed above: its facts, controls, holders and a hash-chained decision record. The shape of "a vault per risk". |
spec/ | The acceptance record and the risk vault layout: the contract a tool or a GRC integration writes to. |
prototypes/ | The acceptance-audit script, the workshop agenda, and the GRC integration outline. |
diagrams/ | The acceptance loop and the board-to-bytes view, as SVG and WebP. |
tools/ | The content builder and the chain verifier. |