RiskMandate v1.15.0
Behaviour-policy vault · Template · Read live from vault vz03p8it with the key printed on this page. All applications · How the first one was built
Agent Behaviour Policy · google/drive/readonly-connector

An assistant on a personal Google Drive.

Any assistant a person connects to their own Drive with the read-only scope. Google classes drive.readonly as a restricted scope — "View and download all your Drive files" — and the per-file alternative, drive.file, reaches only files the user opened with the app. This is the template vault for that shape: the grant read from the vendor's own pages on 2026-09-15 and quoted, with 3 open questions it could not settle, the starting mandate written here to be argued with, and everything else derived. Every number on this page is decrypted from the vault as you read it.

01 · The card

Three it can do. One you asked for. One nothing bounds.

Four counts and no score. The bar splits the excess by what stands in the way of each row: nothing, a rule in prose, a setting the agent's own account can flip, or a boundary enforced above it. Only the last is a control. 0 of 3 rows were measured; every row was read from a vendor page on a date, and the open questions are the rows a page could not settle.

02 · The mandate

What you asked it to do, and what you did not.

Elicited, and the only authored file in the vault. This is the draft asserting a conservative mandate so that the correction goes upward: most people authorised less than they think, and never mentioned the rest.

02 · The grant

Everything the agent can do, irreversible rows first.

Measured from the shape, not from your account and not by you. Each row says how it is known (✓ marks a row observed on the thing itself), what stands in the way, and whether the effect can be undone. What host, tenant and world mean in this shape is stated on the vault's Grant view, because for an agent in a vendor's container the host is the container and not your machine.

A control bounds a grant only if it is enforced by something the grant does not include. A setting the agent's own account could change is not a control, because the grant includes the ability to remove the bound. A boundary enforced above it is one, because it does not. One of the two excess rows here sit behind a boundary; the other one are only asked.
02 · The delta

What it can do that nobody asked for.

Derived from the grant and the mandate, never authored, stored with both inputs pinned. Split three ways: the part you refused, the part you never mentioned, and the part with no boundary in the way — which is the only list a real control shortens.

02 · Licence to Operate

The organisation authorises the agent, for an interval, on conditions.

The organisation is the authority, the behaviour policy is the instrument, the agent is the licensee. A template is unsigned and unissued; a corrected vault carries a name, a date and an interval — and each condition sits next to what enforces it, so the person signing knows what they are accepting with their eyes open.

03 · The app

The vault's own interface, running here from the vault.

The vault carries a single self-contained page that renders itself from the files beside it, and opens on Start here: what this is, where the pieces go, what we want the agent to do beside what we do not, and three ways to hand it over. Below it is booted inside a sandboxed frame with an opaque origin and served its reads by this page over a message channel — the app never sees a key, and this page never runs the app's code in its own origin.

On a phone, open it in its own window: the frame below is the same app, sandboxed, and small. The vault browser is the whole product — files, history and the app — and the button carries the public read key, so it opens read-only without a paste. The copy this site serves at vaults/google-drive-readonly/index.html says in its top bar which route it loaded the app by.

04 · The files

The bytes themselves, listed from the live tree.

Markdown for people, JSON for machines, the pinned vocabulary, the history, and the two files you hand the agent — AGENTS.md for a CLAUDE.md, a ROLE.md or a skill, and SKILL.md in the portable skill format. The list is the vault's; each link opens the copy this site serves.

The read key

Published on purpose. Read, and nothing else.

Derived one-way from the vault's write key, which is not published and never will be. With the key below anyone can clone this vault, open it in the vault browser, or read it from their own page — and check every number above against the bytes it came from. That is what makes a template free: the library is the argument, and it is public. A buyer's corrected vault has no public key.

sgit prints the same key with a prefix that declares its intent; the public form is the one shown. This page reads the vault at dev.send.sgraph.ai over plain cross-origin GETs and decrypts in your browser; the site never proxies it and holds no credential beyond the key you can see.

Behaviour-policy vault

Run this? Correct the mandate.

Open the app above, move the rows that are wrong, and send us the export. Your vault is this one with the mandate corrected, a name on the licence, and no public key — and it recomputes when the grant moves.