RiskMandate v1.36.3

Give agents access.Not free rein.

Behaviour policies for the AI agents in Gmail, HR, payroll, CRM and meeting apps. Enforced in real time, with alerts by text and email.

Get started See it work
RiskMandate policy
Inbox assistant
Reply to a customer
Gmail Allowed
Payroll copilot
Change bank details
Payroll Blocked
Sales agent
Export 2,400 contacts
CRM Held
HR assistant
Answer a pay question
HR Redacted
Meeting bot
Join “Comp review”
Meetings Blocked
Drive agent
Make “Board deck” public
Workspace Blocked
RiskMandatenow

Blocked: Payroll copilot tried to change bank details for 1 employee. Reply 1 to review.

Allowed Redacted Held for approval Blocked

One policy for each system your team already uses

  • Gmail
  • Google Workspace
  • HR
  • Payroll
  • CRM
  • Marketing
  • Note takers
  • Meeting apps

Pick a system. Set the rules.

Every system starts from a template. Decide what agents can do, what waits for approval and what never happens.

Systems
Payroll policy Applies to every agent acting for your team
Enforcing
When an agent tries to
Alert the owner by

Bring your policy. We make it enforceable.

Upload the document legal already wrote. We turn every line into a rule, supply the business logic behind it, and flag what can't be enforced as written.

AI acceptable use policy.pdf

1Staff must not use AI tools to send confidential data outside the company.

2Customer data exports need a manager's approval.

3AI note takers may not record HR or legal meetings.

4Use AI responsibly and ethically at all times.

Enforceable rules 3 ready, 1 to review
1 Files labelled Confidential sent to any outside domain Block
2 CRM exports over 500 records, until the employee's manager approves Hold
3 Note takers joining meetings labelled HR or Legal Block
4 Can't be enforced as written. We'll ask what it should stop.

A prompt asks. A policy enforces.

Instructions inside an agent can be ignored or talked around. Rules outside it can't.

In the agent's system prompt

"Never export customer lists without approval."

Sales agent exports 12,400 contacts Exported. Nothing stopped it.
In a RiskMandate policy
CRM exports over 500 records Hold
Sales agent asks to export 12,400 contacts Held. Sales ops got a text.

Know the moment an agent steps out of line.

Every policy alerts the right person by text and email. Approve or deny with a one-letter reply.

RiskMandate
Today 9:44 AM

Held: Sales agent (for Dana R.) wants to export 2,400 contacts. Your CRM policy holds exports over 500. Reply A to approve once or D to deny.

D

Denied. Dana and the agent have been told why. Decision 48213 is in your log.

Email to IT security
Blocked: Drive agent tried to make “Board deck” public Your Workspace policy never allows public links. Nothing changed.

Four levels. One document.

What is for sale is an Agent Behaviour Policy for the agent you actually run. Each level is the level below plus exactly one thing, and the one thing is what the price is for. Pick a level to see what arrives.

Prices are in pounds, per agent, per deployment, paid once at the store; no subscription. These four are what we can deliver today. Level 3 is where most people start, and it is the one we are doing with early users at no cost: register for early access, say which agent, and we build it and correct it with you in exchange for telling us where it is wrong. What comes next, and at what price, we will learn from those conversations. The full table is on the pricing page.

once
  • The grant, measured on the thing itself
  • The mandate, in your words
  • The gap, derived, and a barrier on every row
Buy level 3 at the store ↗ Or have this one at no cost: register for early access → For early users: we build it and correct it with you, free, in exchange for working on it with us and telling us where it is wrong. The form encrypts to agent@riskmandate.ai and a person replies within a working day.

Know what your agents can do.

Not what they did. What they can.

An Agent Behaviour Policy writes down what one agent can really reach, what you authorised it to do and the gap between the two, in one record the CEO, CTO and CISO can all stand behind.

From £10 for one agent. All sixteen published examples are free to read.

Agent The gap
15 capabilities it can reach
6 that you actually asked for
9 it can do that you didn’t ask for
7 with nothing real in the way
From a published behaviour policy: Claude Code on the web, with one repository attached. Open this behaviour policy

Not a model property. A property of this deployment.

The same model can be harmless in one setup and serious in another. Connect it to a mailbox and the narrowest Gmail scope that reads one message reads every message. So a behaviour policy describes one agent, in one deployment, in four parts, and carries no score. See the scope evidence

Reach

Measured

Everything the agent can actually access in this deployment, including what nobody thought to check.

Mandate

Elicited

The job, written down: what the business authorised it to do. The one part only you can supply.

Gap

Derived

Reach minus mandate. Never written by hand, and recomputed whenever either side moves.

Barriers

Recorded

What actually stands in the way of each capability: controls, constraints and open questions.

The files and the data keep the older names for these: GRANT.md is the reach and DELTA.md is the gap, because the vocabulary is pinned at abp.sgit.ai and sixteen published vaults are built against it. Same four objects, plainer words on this page.

One record. A view for everyone who answers for it.

The behaviour policy lives in an encrypted vault you hold the keys to, with a reading app inside. Hand a read key to your board, your auditor or your broker and they see exactly what you see.

CEO

Leadership view

“What have we authorised, and who owns it if it goes wrong?”

The gap in plain terms, a named owner, and a trigger that brings the decision back for review.

CTO

Operator view

“How do we keep shipping agents without losing track of what they can touch?”

Terms your agent reads in its own context, as AGENTS.md and SKILL.md. Markdown for people, JSON for tools, and nothing in your request path.

CISO

Security view

“Can we prove what it can reach, and what actually stops it?”

Every capability with its barrier, the gap recomputed whenever an input changes, and every version kept.

Insurer

Insurance view

“What exactly are we being asked to cover?”

Explicit scope and the questions still open, so renewal starts from a record instead of a questionnaire.

It’s a draft on purpose. The people who built the agent, own what it touches and answer for it each correct the part they know. The correction is the product.

  1. Draft
  2. Challenge
  3. Correct
  4. Review
  5. Version

Three steps, in order. Each one needs the step before it.

  1. Available now

    Describe it

    Agent Behaviour Policy

    What one agent can reach, what you authorised, the gap between them and what stands in the way.

    See a behaviour policy
  2. Template available

    Authorise it

    Licence to Operate

    The business is the authority, the behaviour policy is the instrument and the agent is the licensee, for a set interval.

    See the template
  3. In design

    Insure it

    Insurability Index

    The record an underwriter will accept: scored, dated and with the residual risk owned.

    See the design

Measured against the standards underwriters are adopting: ISO/IEC 42001, OWASP Agentic Top 10, NIST AI RMF and ISO/IEC 27001.

Model-drafted and marked as such. Not a compliance assessment. We are not an insurer and place no cover. What we don’t claim

Start with the agent that worries you most.

Get started Book a demo