<!-- Generated from acceptance.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# Risk Mandate — agents act, and someone has to own the risk

Risk Mandate begins where security stops — acceptance, funding, and ownership. No risk can be denied, only accepted for an interval and underwritten to the board.

Source: https://riskmandate.ai/acceptance.html

---

# Agents act.You ownthe risk.

Security stops at the vulnerability. Risk Mandate begins where security stops — surfacing each risk so clearly, and routing it so precisely to the person who owns it, that the business funds the fix.

## Security stops at the vulnerability. We begin where security stops.

Security tools are very good at finding issues. Then the trail goes cold — because the questions that decide the outcome live in a different world entirely: budgets, ownership, accountability, escalation.

That gap is where the real damage lives. Risk Mandate is the layer for what comes after the finding: **acceptance, funding, and ownership.**

## There is no deny button.

For a deployed system, the agent already has access. You cannot deny a risk that has already materialised — pretending you can is how risk registers quietly drift into fiction. So we removed the deny button.

## Accept or deny isn't the decision. How long, who owns it, what's funded.

The interval is the mandate and the priority: sign off for an hour and it's fixed within the hour. In the product it looks like a queue you work — trifecta status, exposure clock, a time-bound decision on every item.

## A mandate is the right to act.

Every agent acts on delegated authority — what it may do, who granted it, and for how long. That delegation is a mandate. Agents now read untrusted content, reach the internet, and take actions on their own — the lethal trifecta — while the governance tooling that exists was built for software that does not act.

Governing the right to act — capturing the moment of authorisation, computing the blast radius, binding it to an owner — is the work of the next decade of security.

## You hold the keys, not us.

The register is not a spreadsheet. It is a semantic graph — facts only, so everything in it is real — where every change cascades to the top and the picture is never silently stale.

All of it stands on SG/Vault: sovereignty, no lock-in, and a foundation that is agentic-native rather than agentic-retrofitted.

## Maturity you compute, not claim.

Every acceptance you make here is a durable graph decision — owned, evidenced, time-boxed, appetite-bound. That's not just good hygiene: it's measurable. RAMM turns the five maturity levels into queries your acceptance graph either satisfies or doesn't, so using Risk Mandate is how you climb them.

Each level is a Node Type Formula — a path-pattern over the acceptance graph, tested by query, not asserted in a questionnaire.

## Split by value. Free, consumption, custom.

Every tier runs the same product on the same zero-knowledge foundation. What changes per tier is how it's operated — its maintainability, scalability, and security posture — not which features are gated.

- MAINTAINOpen source, files and folders, no database to operate — no lock-in.
- SCALEAdopt incrementally: as much or as little as fits your stack, at your pace.
- SECUREZero-knowledge vault on your own infrastructure — your keys, your data.
- MAINTAINManaged runtime — versioned, provenance on every change, agent-operable.
- SCALEGrows with usage; pre-approval against risk profiles keeps acceptance scaling without nagging.
- SECURESame zero-knowledge foundation — plaintext never leaves your endpoints.
- MAINTAINSLAs, support, and guided upgrades across the version chain.
- SCALEThe underwriting chain org-wide — acceptance propagated level by level to a board view.
- SECURESovereign deployment: your region, your keys; NIST / ISO / EU AI Act alignment.

Value grows up the ladder; the security model does not change. Sovereignty is the floor, not the premium.

## Lower the probability of catastrophic outcomes.

Map your autonomous risk. Accept what exists. Fund what matters. Prove you're getting safer.

Autonomous risk management for systems that act.

PRODUCT

RESOURCES
