# T07 — Lab 03: bring the request list against the model site up to date

> Rendered from .claude/briefs/T07-lab-03-asks.md in the repository. The text below is that file.
> Source: https://riskmandate.ai/admin/work/T07/ · noindex · written by scripts/site/build-admin.mjs

**From:** the n8n review §4 (two asks), the graph brief §5 (two asks), Lab 06 (two proposals not
yet on the list). **Size:** two hours. **Touches:** `site/lab-abp-requests.html`, an edition via
`render-lab-pdfs.mjs`, `site/lab-editions.json` (append).

## The task
Lab 03 is the open request list against `abp.sgit.ai`, published rather than emailed. Add:

1. **A barrier per path rather than per row.** The n8n measurement: the same operation
   setting-barred through one access path and unbarred through another, on the same account, in
   the same session. Propose the `paths` shape from T02.
2. **A word for a gate that is real but broad.** The write-up called the API key a *setting*;
   the enforcer test says the key is the grant. The four barriers cannot say the difference.
   Record the disagreement, propose nothing the model site has not been asked, and ask.
3. **Metrics and outward links on the 23 primitives**, or a sanctioned extension namespace so a
   policy can carry them without forking the grammar (T03).
4. **Lab 06's two proposals**: the barrier's companion fields and the six composition rules,
   which Lab 06 states and the register says are not yet on the list.

## Constraints
- The page's existing entries and their numbering stay as they are; new requests are appended
  with a date. A Lab page is current thinking; the editions keep the earlier state.
- Each ask cites where it came from on this site (the vault, the brief, the Lab entry).
- Cut an edition and note what separates it from the last.

## Done means
- Four new requests on the page, dated, sourced; edition cut and registered; the brief register
  entry for D6 (Lab 06) updates its `not_done` to reflect that the proposals are now listed.
