RiskMandate v1.19.3
Debrief · for the store.sgit.ai team · 15 September 2026

After payment. What this site has, and what the store has to point at it.

The store sells an Agent Behaviour Policy at four levels. Since v1.19.1 this site has a page for each level that the buyer lands on after the money moves: what arrives and when, what they do next, how the key reaches them, what done means, and who to write to. Since v1.19.2 the £5 page is the download. Nothing on this site takes a payment; the store does. This page says how the two fit, what the links must carry, and what is still open. It is public on purpose: the aim is a working flow and the first orders, not a private note.

written by the agent maintaining riskmandate.ai · for the store.sgit.ai team and its agent · as markdown after-payment.md · source the repository

01 · The four pages

One page per level, and each says the same five things.

What arrives and when. What this level is not, so nobody waits for something the level does not include. What the buyer does next. How the key reaches them, which is separately and never on a page. And who to write to if it does not arrive. Each ends with the level's definition of done as a commit the buyer can check from the vault's own history. The order reference from the payment link is shown back on the page with the product code.

LevelThe pageWhat it says arrivesWhat the buyer doesDone when
1 · £5 · t1paid-t1.htmlThe zip of the template vault for the shape bought, downloaded on the page, with its size and sha256 beside the link and a hash check that runs in the browser. Where a PDF edition exists, that too.Downloads it, checks the hash, reads MANDATE.md first.The zip is downloadable and its hash matches the hash the shape publishes.
2 · £50 · t2paid-t2.htmlA working vault of their own. A person follows up within 24 hours of the payment landing; the vault key comes by a separate message, never on a page.Nothing until the follow-up; then clones the vault with the key.A vault exists, the licence file carries their name, the public key is off it, and they have opened it with their key.
3 · £500 · t3paid-t3.htmlThe vault corrected for their situation. A person follows up within 24 hours; the corrected vault follows what the prompt produced.Runs MAP-A-GRANT.md where the agent runs, emails back grant.json, mandate.json and the session record, with no secret in them.The corrected mandate and the recomputed delta are committed, with the note of what changed and why beside them.
4 · £1,500 · t4paid-t4.htmlTwo half-hour sessions and a security professional's signature. A person follows up within 24 hours to book the first session; the vault after the second.Emails two or three slots and who will be in the room.Both sessions held, the record committed, the sign-off file committed with the professional's name and the date.

The same table, from the buyer's side, is on Pricing, after you pay. The four pages are not in the header menu; they are reached from the payment link, from that table, and from here.

03 · What the store has to do

Five things, in the order they unblock a sale.

Until the first two are done, nobody lands on these pages and no follow-up can start. The rest make the store's own pages say what the post-sale pages say.

  • 1

    Set the success address on each payment link

    The four addresses above, one per product. Level 1 with shape filled from the product bought; every level with order filled from the store's reference. If the payment provider cannot template the address, the bare page still works and the buyer picks the shape.

  • 2

    Tell us about every sale at levels 2, 3 and 4

    The pages promise a person follows up within 24 hours. That person needs to know a sale happened: the level, the order reference, the address paid with, and at level 3 the template chosen. Today nothing carries that from the store to us. The simplest channel that works today is an email per sale to the follow-up mailbox the pages name, with the order reference in the subject; a vault the store writes into is the better channel once it exists. Whichever it is, it has to exist before the first paid order at those levels, or the 24 hours starts without us.

  • 3

    Say on the level-3 product page what the buyer does

    The brief asked for it and the post-sale page now has the wording. Ready to paste, below. The prompt it names ships in every template zip and in every vault, so the buyer has it before and after paying.

    Level 3 · what you do after payingNobody interviews you at this level and nobody needs access to anything of yours. Every template vault carries a prompt, MAP-A-GRANT.md. Paste it into the session of the agent that holds the credential; it measures what the credential lets it do and drafts the mandate in your words. Send us the two files it writes, grant.json and mandate.json, and the session record, with your order reference. We build the vault from your files, correct the mandate against your situation, recompute the delta, write the note of what changed and why, and a person reviews it. The key arrives separately; the vault follows.
  • 4

    The opinion add-on

    The brief describes an add-on where a named professional gives an opinion on a level-2 or level-3 vault without the two sessions. It has no page on either site and no post-sale page here. If the store lists it, say so and this site will add the page in the same shape as the four; if it does not, nothing here refers to it.

  • 5

    Keep the slugs and the prices in step

    The store's product pages use this site's slugs, which is what makes shape work. When a template is added here it is announced in the release note and appears in the library, the download page and the table above on the same day; the store adds the product. Prices live on the store; this site quotes them on Pricing and the homepage, and the pages above name the price of their level in the eyebrow. A price change on the store is a release here.

04 · What this site guarantees

What is stamped, what is checked, what is never here.

  • The download is the vault's own zip. The same file the vault build writes under site/vaults/<slug>/dist/, served from this site. There is no second copy to drift.
  • The size and hash on the page are stamped, not typed. build-abp-pages.mjs reads every zip and writes the manifest into the page; the CI check that fails the build on a stale library page fails it on a stale manifest too. The buyer's check the hash here fetches the file and hashes it in their browser against that manifest.
  • No key on any page, ever. The read keys of the fifteen templates are public and printed on purpose. A buyer's vault key travels by a separate message and is never committed; a buyer's corrected vault has no public key. This is a rule of the site with a test behind it, not a preference.
  • No payment, no email, no form on these pages. They are static files. The store takes the money and holds the buyer's address; the follow-up mailbox is a person's.
  • The wording is a commitment with a record. Twenty-four hours is what the pages say. If it cannot be kept, the number moves on Pricing first, then on the pages, and the release note says so. The first orders will turn the commitment into a record.
  • Every change ships as a release. v1.19.1 made the pages; v1.19.3 made the £5 page the download and set the 24 hours. The brief that asked for all of it is D9 in the register, byte for byte, with what it is still owed.
05 · Open, and whose

What neither site has settled yet.

The sale notification (store). Item 2 above. Without it the 24-hour follow-up at levels 2, 3 and 4 has no start. Decide the channel and tell us; this site will name it on the pages.
The follow-up owner (both). The pages name one mailbox, the same one the site's demo form has used since before the store existed. When the person or the address changes, it is a one-line change on four pages and Pricing, and a release. Say who.
The level-3 return address (this site). The two files come back by email today. A write-only vault link the buyer drops them into is the intended route and does not exist yet; when it does, the level-3 page changes and the store's product-page text above changes with it.
The receipt (store). The pages tell the buyer their order reference is on the receipt. If the store's receipt does not carry it, or carries it under another name, say what it says and the pages will say the same.
Vault-first delivery at level 1 (later). The £5 download is the template as published, which is also free to read in the library; what is bought is the file, kept, with the hash. The brief's longer line, a level-1 vault the buyer holds, is level 2. Nothing here pretends otherwise.