RiskMandate v1.28.0
Behaviour-policy vault · Template · Read live from vault oc433z3m with the key printed on this page. All applications · How the first one was built
Agent Behaviour Policy · anthropic/gmail-connector/default

Claude, with the Gmail connector on one inbox.

The Gmail connector in Claude's directory: "MADE BY Google", connector URL https://gmailmcp.googleapis.com/mcp/v1, "ADDED March 2026", category Communication, sign-in required. It is one of three Google Workspace connectors (Gmail, Calendar, Drive) that Anthropic's help article says are "available for all users on Claude and Claude Desktop", toggled individually — so a deployment can run Gmail alone, which is this shape. This is the template vault for that shape: the grant read from the vendor's own pages on 2026-09-16 and quoted, with 6 open questions it could not settle, the starting mandate written here to be argued with, and everything else derived. Every number on this page is decrypted from the vault as you read it.

See the levels at the store ↗
01 · See it live

Open the vault. See what you get.

Reading app · files · keys · history. Two frames, both the official SG/Vault interface opened read-only with the key printed at the bottom of this page, both reading the vault and not this site. The first is the vault's own app, which is what whoever is handed the policy sees. The second is the vault browser: every file in the tree, its history, and the same app one click away. Between them is what you are buying at every level — the app is the reading, the tree is the record.

The app

Opens on Start here. A left navigation: the record it can do, what you do with it, and what you hold — the mandate to correct, the consequences that follow, your keys, and the licence.

The vault

The tree on the left is the whole product: the markdown for people, the JSON for machines, the pinned vocabulary, the scenarios, the consequence layer, the history of every recompute. Click a file to read it; the same app is under index.html.

Your keys. A working copy you control; hand the read key on and the reader sees what you see.
Multiple formats. Markdown for people, JSON for machines, the whole thing as a zip with its sha256.
Version history. Every recompute keeps the basis of the revision, and the vault keeps every commit.

The read key travels to the host over a same-page handshake, never in a URL. Nothing you do in either frame touches the vault: it is opened read-only, and the write key is not published. Not loading? Open it in its own tab ↗.

02 · The card

Six it can do. One you asked for. Four nothing bounds.

Four counts and no score. The bar splits the excess by what stands in the way of each row: nothing, a rule in prose, a setting the agent's own account can flip, or a boundary enforced above it. Only the last is a control. 4 of 6 rows were measured; every row was read from a vendor page on a date, and the open questions are the rows a page could not settle.

03 · The mandate

What you asked it to do, and what you did not.

Elicited, and the only authored file in the vault. This is the draft asserting a conservative mandate so that the correction goes upward: most people authorised less than they think, and never mentioned the rest.

04 · The grant

Everything the agent can do, irreversible rows first.

Measured from the shape, not from your account and not by you. Each row says how it is known (✓ marks a row observed on the thing itself), what stands in the way, and whether the effect can be undone. What host, tenant and world mean in this shape is stated on the vault's Grant view, because for an agent in a vendor's container the host is the container and not your machine.

The grant above is what it can do after the blocks.

A capability the credential authorises and something else withholds is not a grant row, and it is not out of reach either: it is blocked, and the record names the blocker. Some of these are the credential's own ceiling. Some are a vendor choosing not to ship a tool the credential would authorise — which moves in a release, with no consent screen and nothing for anyone to click. Under one heading those two look alike; they are not.

Who holds each barrier, in answers that need no adjective.

The barrier column says what stands in the way. These say who holds it, whether it can move without you, whether you would be told, and what would remove it — each a fact with a source, and none of them a rating. How much a barrier is worth depends on the deployment, which is the same reason nothing on this site is scored.

A control bounds a grant only if it is enforced by something the grant does not include. A setting the agent's own account could change is not a control, because the grant includes the ability to remove the bound. A boundary enforced above it is one, because it does not. One of the five excess rows here sit behind a boundary; the other four are only asked.
05 · The delta

What it can do that nobody asked for.

Derived from the grant and the mandate, never authored, stored with both inputs pinned. Split three ways: the part you refused, the part you never mentioned, and the part with no boundary in the way — which is the only list a real control shortens.

06 · Licence to Operate

The organisation authorises the agent, for an interval, on conditions.

The organisation is the authority, the behaviour policy is the instrument, the agent is the licensee. A template is unsigned and unissued; a corrected vault carries a name, a date and an interval — and each condition sits next to what enforces it, so the person signing knows what they are accepting with their eyes open.

07 · The files

The bytes themselves, listed from the live tree.

Markdown for people, JSON for machines, the pinned vocabulary, the history, and the two files you hand the agent — AGENTS.md for a CLAUDE.md, a ROLE.md or a skill, and SKILL.md in the portable skill format. The list is read from the vault's live tree; the vault browser above opens any of them from the vault itself, and each link here opens the copy this site keeps for the build.

08 · The read key

Published on purpose. Read, and nothing else.

Derived one-way from the vault's write key, which is not published and never will be. With the key below anyone can clone this vault, open it in the vault browser, or read it from their own page — and check every number above against the bytes it came from. That is what makes a template free: the library is the argument, and it is public. A buyer's corrected vault has no public key.

sgit prints the same key with a prefix that declares its intent; the public form is the one shown. This page reads the vault at dev.send.sgraph.ai over plain cross-origin GETs and decrypts in your browser; the site never proxies it and holds no credential beyond the key you can see.

Behaviour-policy vault

Run this? Buy the one for your deployment.

This template is free and public, and you are reading it with the key printed above. Yours is this vault with the mandate corrected, a name on the licence, and no public key on it — and it recomputes when the grant moves. Four levels at the store: the pack as a download, a working vault you hold the keys to, that vault corrected for your situation by a named professional, or the same with two sessions and their signature. The store owns the prices, the cart and the order; this page holds none of them. This shape is new here, so the store has not built its page yet — the link goes to its list of shapes until it does.