admin / Briefs written here
Briefs written here
23 documents under docs/, one page each. The direction, the architecture, the reviews and the workflows, written against a named source. The briefs that arrived from outside are a different list.
These were written here, by the agent maintaining the site, in response to the memos and documents that arrived. Each is read against a named source and dated. Add a file under docs/ and rerun build-admin.mjs: it has a page here and a test fails until it does.
Newest first
The store's four levels are a ladder for a customer. The memo asks for the step below the bottom one, whose output is a user:
Seven top-level entries, which is the cap the header can hold at 1100px: Policies (5) · Who it's for (3) · Insurance (8) · Live demos (7) · Lisbon 2026 (1) · Pricing (1) · More (11).
The second reading of riskmandate.ai by the same five invented readers found that the first reading's headline finding is gone and two new ones took its place. This page is the review; the runs, the screenshots and the interviews are in the vault,…
A consequence layer beside the grant: derived where it can be, authored where it must be, evidence-tiered like everything else, and never a score.
oc433z3m becomes the product, and the reading app is rebuilt around itThe store's exploration has three emphases on one shopping model — ABP first, Vault first, Use it — and the vault appears the same way in all three: a panel titled Inside an ABP vault, with a left navigation of eight entries and a reading pane on the right.
Our enforcer test is a control bounds a grant only if it is enforced by something the grant does not include. The vendor's non-exposure passes it: the agent cannot edit Anthropic's connector. So it is a boundary — and treating it as one, without more, is…
A call with a customer. Agreed on the call: the deployment is Claude in the browser with the Gmail connector enabled, on one mailbox, and the customer wants the behaviour policy for it. The same day the lead connected the connector on an account they run…
The renderer never sees which route ran. Its reads for data go through the same bridge or same-origin fetch the loader has, so data/grant.json resolves in this vault, not in the app vault. Booting is: parse the fetched document, move its styles into the…
More of this exists than it looks, because the model site made the primitives into ids on day one:
What the customer does, what we do, and what arrives, so the level-3 page on both sites can say the same thing.
To become useful on this repository, the agent writing this read: the README, the how-the-website-works document, twelve briefs, the markdown twins of the ABP page, the library page, the Lab index, the work page and the agents page, six release notes, the…
Five behaviour-policy vaults for connector shapes, in the directory at abp-vaults.html and each with its own page. None of these shapes is published at abp.sgit.ai; the grants were read from the vendors' own pages on 15 September 2026, quoted rather than…
An agent holding an owner-scoped API key on a self-hosted workflow-automation platform was given the earlier, prose version of the policy and asked to find the edges of what the key could do. It did it the right way: built and ran one real AI-agent…
The Licence to Operate demo page opens with the product itself, twice: the vault's app in App Mode, and beneath it the vault browser with the file tree on the left and the same app running under index.html. Both are the official SG/Vault interface, opened…
The studio has built the delivery end of the flow well and the selling end against the wrong ladder. Its vault — mandate, grant, computed delta, history, and an HTML plus JSON export the buyer keeps — is Lab 02's stage ten drawn properly, and its hero card…
Copy the values. Where a field needs a judgement call rather than a fact, the recommendation is first and the reasoning is one line under it.
The Agent Behaviour Policy is not a new product. It is the primitive the rest of RiskMandate was already made of, now named, published, and — critically — sellable this week at ten pounds.
The previous strategy brief's problem was that the booth had a demo and no transaction: the game qualified people, the Index took an email, and the sale started after the event. That is no longer true. The Agent Behaviour Policy is a named artefact with a…
riskmandate.ai is written for a Head of Risk. Lisbon is founders and investors. If we run the site's messaging at the booth it will land as "enterprise GRC vendor" and founders will walk past.
demos.html embeds three, each with its own page:
Split riskmandate.ai into two planes with different owners, lifecycles, and quality regimes:
Move the interactive Risk Scenarios experience to the decoupled model:
How a page is put together, what happens when the browser loads one, and where each thing lives. Current as of v1.0.0; see the addendum below for what has been added since, and .claude/onboarding/01-map.md for the current map.
Direction
The store's four levels are a ladder for a customer. The memo asks for the step below the bottom one, whose output is a user:
Seven top-level entries, which is the cap the header can hold at 1100px: Policies (5) · Who it's for (3) · Insurance (8) · Live demos (7) · Lisbon 2026 (1) · Pricing (1) · More (11).
A consequence layer beside the grant: derived where it can be, authored where it must be, evidence-tiered like everything else, and never a score.
oc433z3m becomes the product, and the reading app is rebuilt around itThe store's exploration has three emphases on one shopping model — ABP first, Vault first, Use it — and the vault appears the same way in all three: a panel titled Inside an ABP vault, with a left navigation of eight entries and a reading pane on the right.
Our enforcer test is a control bounds a grant only if it is enforced by something the grant does not include. The vendor's non-exposure passes it: the agent cannot edit Anthropic's connector. So it is a boundary — and treating it as one, without more, is…
More of this exists than it looks, because the model site made the primitives into ids on day one:
What the customer does, what we do, and what arrives, so the level-3 page on both sites can say the same thing.
The Agent Behaviour Policy is not a new product. It is the primitive the rest of RiskMandate was already made of, now named, published, and — critically — sellable this week at ten pounds.
Workflows
A call with a customer. Agreed on the call: the deployment is Claude in the browser with the Gmail connector enabled, on one mailbox, and the customer wants the behaviour policy for it. The same day the lead connected the connector on an account they run…
Reviews
The second reading of riskmandate.ai by the same five invented readers found that the first reading's headline finding is gone and two new ones took its place. This page is the review; the runs, the screenshots and the interviews are in the vault,…
An agent holding an owner-scoped API key on a self-hosted workflow-automation platform was given the earlier, prose version of the policy and asked to find the edges of what the key could do. It did it the right way: built and ran one real AI-agent…
The Licence to Operate demo page opens with the product itself, twice: the vault's app in App Mode, and beneath it the vault browser with the file tree on the left and the same app running under index.html. Both are the official SG/Vault interface, opened…
The studio has built the delivery end of the flow well and the selling end against the wrong ladder. Its vault — mandate, grant, computed delta, history, and an HTML plus JSON export the buyer keeps — is Lab 02's stage ten drawn properly, and its hero card…
Research
Five behaviour-policy vaults for connector shapes, in the directory at abp-vaults.html and each with its own page. None of these shapes is published at abp.sgit.ai; the grants were read from the vendors' own pages on 15 September 2026, quoted rather than…
Architecture
The renderer never sees which route ran. Its reads for data go through the same bridge or same-origin fetch the loader has, so data/grant.json resolves in this vault, not in the app vault. Booting is: parse the fetched document, move its styles into the…
Split riskmandate.ai into two planes with different owners, lifecycles, and quality regimes:
Process
To become useful on this repository, the agent writing this read: the README, the how-the-website-works document, twelve briefs, the markdown twins of the ABP page, the library page, the Lab index, the work page and the agents page, six release notes, the…
Vaults
demos.html embeds three, each with its own page:
Summit
The previous strategy brief's problem was that the booth had a demo and no transaction: the game qualified people, the Index took an email, and the sale started after the event. That is no longer true. The Agent Behaviour Policy is a named artefact with a…
riskmandate.ai is written for a Head of Risk. Lisbon is founders and investors. If we run the site's messaging at the booth it will land as "enterprise GRC vendor" and founders will walk past.
Implementation
Move the interactive Risk Scenarios experience to the decoupled model:
Other documents
Copy the values. Where a field needs a judgement call rather than a fact, the recommendation is first and the reasoning is one line under it.
How a page is put together, what happens when the browser loads one, and where each thing lives. Current as of v1.0.0; see the addendum below for what has been added since, and .claude/onboarding/01-map.md for the current map.