abp.sgit.ai is the site in the sgit network that defines one document, the Agent Behaviour Policy. Its own one-line summary is: what your agent can do, what you authorised it to do, the gap between them, and what actually stands in the way (llms.txt↗). This piece covers what the document is, how the site grew, what it publishes, and how riskmandate.ai uses it.
What an ABP is
The foundation document, dated 11 September 2026, defines an Agent Behaviour Policy as a written description, for one agent in one deployment, of four things (foundation document↗). The grant is everything the agent can do. The mandate is what it was authorised and expected to do. The delta is the difference. The barrier is what stands between the agent and each capability (foundation document↗).
The site's short form of the idea is its heading: "You know what you asked for. You do not know what it can do." (home page↗). The mandate is elicited from the person who deployed the agent, the grant is measured from the deployment, and the barrier is recorded per capability (foundation document↗).
There are four kinds of barrier: nothing, a rule somebody wrote down, a setting the agent's own account could change, and a boundary enforced above it that it cannot reach (foundation document↗). The document's rule is that "Only the fourth kind bounds anything." (foundation document↗). Its worked example is a coding agent profiled twice, with confirmations on and off: the grant, mandate and delta stay the same, and the barrier on every capability in the delta moves one row (foundation document↗).
The ABP carries no score. The foundation document puts it as "A policy cannot be dangerous. A deployment can." (foundation document↗), and the site says there is no score, rating or risk level anywhere on it, including in the data (llms.txt↗).
How it grew
The version table lists 20 releases, from v0.1.0 on 11 September 2026 to v0.11.0 on 22 September 2026 (counted from the versions page↗).
v0.1.0 promoted data that already existed. The capability vocabulary had been published as the data pack a game reads, so the first release gave it a stable address instead of writing a second one, and derived five worked ABPs from it (v0.1.0 record↗). That vocabulary is 23 capability primitives in verb.object.reach form, four barriers, three undo classes, seven evidence tiers, nine deployment shapes and eight starting mandates (v0.1.0 record↗). The article for that release says nothing was renamed (v0.1.0 article↗).
v0.2.0 corrected the site's own rule on the same day. The foundation document said the delta is computed and never stored; the correction is that the delta is derived and never authored, stored with the versions of its inputs and recomputed by the gate (v0.2.0 record↗). The corrected passages were not rewritten: each stands as published, with its correction rendered above it (foundation document↗). The release gate that used to refuse any stored delta now recomputes every stored delta from its pinned inputs (v0.2.0 article↗).
v0.3.0 to v0.4.3 turned words into nodes. v0.3.0 gave read, file and project their own addresses, and a node type became a formula instead of a label; v0.4.0 mapped the ABP onto Fractal Semantic Graphs, and the releases up to v0.4.3 made that map into data the build reads (versions↗).
v0.4.4 took seven shapes from riskmandate.ai. They were fetched as bytes on 20 September 2026, held unchanged with a hash per file, and promoted without renaming anything (v0.4.4 record↗). The record says the intake path "is the same for anybody" (v0.4.4 record↗).
v0.5.0 onwards added one article per release, with screenshots taken from each release's tag (versions↗). Then came three walkthroughs, for a mailbox (v0.6.0), for cost (v0.8.0) and for an assistant on your own machine (v0.10.0), and three cases (v0.7.0 and v0.9.0) (versions↗). v0.11.0 added the Gmail connector as measured by the agent holding it (llms.txt↗).
What it publishes
The snapshot holds 315 files for abp.sgit.ai: 182 markdown, 131 JSON and 2 text (counted from the manifest). Every page has a markdown twin, and the whole site is also served as one file (llms.txt↗). The main parts are:
- The model: the four objects, the capability grammar↗ of 23 primitives, and the barrier↗ (llms.txt↗).
- Walkthroughs a reader runs against their own assistant, each in four steps: the mailbox↗ with thirteen prompts, cost↗ with twelve, and the desktop↗ with ten (llms.txt↗). The fourth step of the mailbox walkthrough says the document written in step three "is an expectation rather than a control" (llms.txt↗).
- Cases: one person's estate of deployments↗, each an ABP "elicited from them rather than authored" (llms.txt↗). One case is the session that built the site's releases v0.4.0 to v0.8.1 (llms.txt↗).
- Articles: one per release↗, 14 in the snapshot (counted from the folders under
articles/). - Docs: the foundation document, the briefs behind it and the build pack, each rendered with a link to its source bytes (llms.txt↗).
How riskmandate.ai uses ABPs
riskmandate.ai describes itself as the insurability layer for agentic AI (riskmandate.ai llms.txt↗). Its ABP page↗ restates the same four objects and four barriers, links to abp.sgit.ai's barrier page and examples, and says the capability vocabulary is "pinned at abp.sgit.ai and shared by every vault" (riskmandate.ai, the ABP↗).
It keeps the no-score rule and places the score elsewhere: "The Insurability Index scores the deployment, never the behaviour policy." (riskmandate.ai, the ABP↗).
What it publishes. A directory of template vaults↗, one per target application, each read live in the browser with a published read key (directory↗). The snapshot holds 16 of these vault pages (counted from the abp-vault-*.md files in the manifest).
What it sells. The reviewed level↗ is priced at £1,500: two half-hour sessions, a behaviour policy built from the interview, and a sign-off file with a named professional's name and the date (reviewed level↗).
What it asked for. On 12 September riskmandate.ai published three requests↗ against abp.sgit.ai: a material property, four connector shapes, and provenance conventions (Lab 03↗). abp.sgit.ai's v0.4.4 answered the second of them, the one riskmandate.ai had marked as unblocking a product (v0.4.4 record↗).
What is still drawn, not built. riskmandate.ai's ABP page says of its graph model: "Half of this is running today and half is drawn" (riskmandate.ai, the ABP↗). Its Lab 02, the flow for buying a behaviour policy, says "None of it is built yet." (riskmandate.ai llms.txt↗).
The line between the two sites
The two sites divide the work. abp.sgit.ai owns the model and the data. Its v0.4.4 record says it does not import riskmandate.ai's vaults for its own shapes, "because they pin this site and importing them would be a loop" (v0.4.4 record↗). riskmandate.ai calls abp.sgit.ai "a separate site with a separate maintainer" and says "We render against it." (Lab 03↗).














