RM Risk Mandate v1.0.0
Autonomous Risk Management

Agents act.
You own
the risk.

Security stops at the vulnerability. Risk Mandate begins where security stops — surfacing each risk so clearly, and routing it so precisely to the person who owns it, that the business funds the fix.

No deny buttonTime-boxed acceptanceUnderwritten to the boardZero-knowledge vault
The problem

Security stops at the vulnerability. We begin where security stops.

Security tools are very good at finding issues. Then the trail goes cold — because the questions that decide the outcome live in a different world entirely: budgets, ownership, accountability, escalation.

01
Who accepts this risk?
02
Who funds the fix?
03
Who owns the consequence?
04
What can it actually reach?

That gap is where the real damage lives. Risk Mandate is the layer for what comes after the finding: acceptance, funding, and ownership.

Signature mechanic

There is no deny button.

For a deployed system, the agent already has access. You cannot deny a risk that has already materialised — pretending you can is how risk registers quietly drift into fiction. So we removed the deny button.

Real vulnerability
A fact that exists — not a hypothetical.
Real risk
Once the vulnerability exists, the risk exists.
Accepted, in a direction
Get more data · reduce · increase · hold.
For an interval
1h · 4h · 1d · 1w · 1m · 6m — set by urgency and cost of fix.
Underwritten
Technical owner + security + GRC. No executive accepts alone.
Up to the board
Propagates level by level into one consolidated view.
Scales without nagging Repeat instances are pre-approved against a risk profile.
The only escape An impossible risk has one exit — the nuclear option: cease the activity.
Risk acceptance

Accept or deny isn't the decision. How long, who owns it, what's funded.

The interval is the mandate and the priority: sign off for an hour and it's fixed within the hour. In the product it looks like a queue you work — trifecta status, exposure clock, a time-bound decision on every item.

Every acceptance creates: attention · accountability · funding pressure · ownership · expiry · escalation
The mandate

A mandate is the right to act.

Every agent acts on delegated authority — what it may do, who granted it, and for how long. That delegation is a mandate. Agents now read untrusted content, reach the internet, and take actions on their own — the lethal trifecta — while the governance tooling that exists was built for software that does not act.

Governing the right to act — capturing the moment of authorisation, computing the blast radius, binding it to an owner — is the work of the next decade of security.

mandatenoun
The right to act, delegated to a system that acts on your behalf.
GRANTED BYa named, accountable owner
SCOPEwhat it may do — and what it may reach
EXPIRYtime-bound, always — never standing
RISKaccepted for an interval, underwritten upward
Foundation

You hold the keys, not us.

The register is not a spreadsheet. It is a semantic graph — facts only, so everything in it is real — where every change cascades to the top and the picture is never silently stale.

All of it stands on SG/Vault: sovereignty, no lock-in, and a foundation that is agentic-native rather than agentic-retrofitted.

Zero-knowledge, client-side encryption — only the endpoints see the data.
PKI for confidentiality, integrity, and attribution.
Provenance on every change — versioned, always.
Folders and files, no database — yet fully queryable.
Agent-operable through the CLI.
Sovereignty and no lock-in — hold the keys, not the storage.
Risk Acceptance Maturity Model

Maturity you compute, not claim.

Every acceptance you make here is a durable graph decision — owned, evidenced, time-boxed, appetite-bound. That's not just good hygiene: it's measurable. RAMM turns the five maturity levels into queries your acceptance graph either satisfies or doesn't, so using Risk Mandate is how you climb them.

1 Ad hoc 2 Repeatable 3 Defined 4 Managed 5 Optimized

Each level is a Node Type Formula — a path-pattern over the acceptance graph, tested by query, not asserted in a questionnaire.

Pricing

Split by value. Free, consumption, custom.

Every tier runs the same product on the same zero-knowledge foundation. What changes per tier is how it's operated — its maintainability, scalability, and security posture — not which features are gated.

Community
Freeopen source
  • MAINTAINOpen source, files and folders, no database to operate — no lock-in.
  • SCALEAdopt incrementally: as much or as little as fits your stack, at your pace.
  • SECUREZero-knowledge vault on your own infrastructure — your keys, your data.
Consumption
Token-basedmetered by usage
  • MAINTAINManaged runtime — versioned, provenance on every change, agent-operable.
  • SCALEGrows with usage; pre-approval against risk profiles keeps acceptance scaling without nagging.
  • SECURESame zero-knowledge foundation — plaintext never leaves your endpoints.
Enterprise
Customtalk to us
  • MAINTAINSLAs, support, and guided upgrades across the version chain.
  • SCALEThe underwriting chain org-wide — acceptance propagated level by level to a board view.
  • SECURESovereign deployment: your region, your keys; NIST / ISO / EU AI Act alignment.

Value grows up the ladder; the security model does not change. Sovereignty is the floor, not the premium.

Risk register live

Lower the probability of catastrophic outcomes.

Map your autonomous risk. Accept what exists. Fund what matters. Prove you're getting safer.