# The Urgency Is Not A Deadline But A State: You Already Connected It, And A Distributed Skill Cannot Carry A Control

**version** v0.33.70
**date** 12 September 2026
**from** Human (project lead)
**to** Whoever writes the urgency section, whoever runs the early access group, and whoever decides what the free tier gives away

**type** Strategy brief (why somebody buys today, what the free thing is, and how to find the price without a survey)

*First of 12 September. Both the corpus and the outside were searched. The outside search was aimed at two things, being how to discover a price from a handful of people and whether a policy can ship as an agent skill, and both came back with answers that change the plan. The pricing research says do not run the survey the memo proposes, because the method it would use is below every published sample floor and is at its worst on exactly this kind of product, and because a certainty filter reproduces real purchase rates almost exactly while the standard mitigation does nothing. The skills research says the format is now a cross vendor standard carried by around forty six products, which is better distribution than expected, and that the frontmatter fields which would constrain an agent do not survive external distribution, which is the barrier argument proved mechanically rather than argued. Limitations: no price is recommended; one marketplace contradicts itself on its own revenue split; and several adoption counts in this area are crawl artefacts rather than measurements, and are treated as such.*

---

## What This Is

The answer to why anybody buys a behaviour policy today, the design of the experiment that finds the price, and the ruling on what ships as a skill: **the memo asks the question that decides whether any of this sells, being why somebody would spend a pound or ten or fifty today rather than finding the idea interesting and moving on, and proposes an answer, which is that what they need is a prompt they can give their agent now to stop it going off piste, deliverable as a skill, with a generic version free and a customised version and a vault as the paid tiers; it proposes an urgency section on the site, an early access token for a group who can run the whole flow without paying and then be asked whether it was worth ten pounds, and an experiment to find the sweet spot between one pound and a hundred; and it asks what value the site gives away for nothing, on the reasoning that somebody who gets value free is more inclined to buy; the first finding is that there is no deadline and inventing one would break the estate's own rule against the verdict, but there is something better, which is that the exposure predates the purchase, because the connector was enabled last month and the grant it created exists right now and has never been enumerated, so the honest page states what that connector grants in the vendor's own words and lets the reader draw their own conclusion; the second finding is that two dated things did change this year, being that the standard liability forms most of the market runs on acquired a generative artificial intelligence exclusion effective 1 January 2026 while the affirmative market replacing it prices on a description of what the agent may do, and that a national regulator wrote on 9 March 2026 that a business using an agent is responsible for what it does and should be clear what tasks it is allowed to perform; the third finding is the one that must be said out loud on the product page, which is that a prompt is the second barrier row and therefore stops mistakes rather than attacks, and that this is defensible because most off piste behaviour is not adversarial and because the model provider's own words are that model layer controls shape what an agent tends to do rather than what it is capable of; the fourth finding is mechanical and settles the question rather than arguing it, because the skill format's portable frontmatter carries six fields and the ones that would constrain an agent are not among them, so a distributed skill literally cannot carry an enforcement mechanism; the fifth is that the format sets the price far more than the content does, since packaged skills sell between five and fifteen dollars with a median earning under fifty dollars a month while a document template pack of governance material sells for ninety nine and a toolkit for two thousand one hundred and ninety nine, and one marketplace is selling nineteen thousand crawled skills for four dollars; and the sixth is that the price experiment the memo describes cannot work as described, because at fifteen to thirty people the method is below every published floor, stated willingness to pay overstates real by a factor between one point two and three, and the thing that reproduced a real purchase rate almost exactly in a controlled field experiment was a certainty filter rather than the standard mitigation.** New contributions: **the three honest answers to why now and the one that is a state rather than a deadline; the mistakes not attacks positioning with its supporting quotation; the mechanical proof that a distributed skill cannot carry a control; the free and paid ladder; the finding that format sets price; and a replacement experiment that charges money instead of asking about it.**

## There Is No Deadline, And That Is Fine

**Nobody is fined next month for not having a behaviour policy.** Manufacturing a deadline would be the verdict style the estate ruled out on 20 August, and a buyer who checks would find nothing behind it.

**But the memo is reaching for something real, and it is better than a deadline. It is a state.**

**You already connected it.** The mailbox connector was enabled last month, or the drive, or the shared folder. **The grant it created exists right now.** Nobody enumerated it then and nobody has since. The thing a buyer would be protecting against is not coming; it arrived when they clicked authorise.

**So the urgency section does not warn. It states, and it sources.** From the previous brief's research, all from the vendors' own pages:

> The only scope that lets anything read a message reads every message in the mailbox. There is no scope that filters by sender, by label or by date.

> The default file search corpus is defined by its publisher as files owned by **or shared to** the user.

> Site specific permissioning is not supported because the underlying search is tenant wide.

**No adjective. No claim about risk. Three sentences from three vendor pages, with dates.** The reader supplies the alarm, and because they supplied it, it is theirs.

**That is the whole urgency mechanic, and it obeys the rule: publish the record, never the verdict.**

## Two Things Genuinely Did Change This Year

**If somebody asks why this year rather than last, there are two dated answers and neither is ours.**

**The cover narrowed.** The standard general liability forms that underpin most of one large market acquired a generative artificial intelligence exclusion announced 21 October 2025 and effective **1 January 2026**, and several large carriers have filed their own exclusions, one of them absolute and naming inadequate policies and training among the things it excludes. Meanwhile the affirmative market replacing it prices on a description of what the agent is permitted to do. **Something a business thought it had is being withdrawn on a date, and the thing replacing it asks a question they cannot currently answer.**

**Responsibility was assigned in March.** A national consumer regulator published on **9 March 2026** that if an agent a business uses does something illegal, the business is responsible, and that businesses should be clear about what tasks an agent is allowed to perform, what data it can access and what constraints apply. **That is a regulator describing this document without naming it**, it is current, and it is domestic.

**One wording rule for the page.** The word for the first of those may not appear on any page carrying a price. The version that works is: **if your agent does something you did not authorise, the question you will be asked is what you did authorise.**

## The Prompt Stops Mistakes, Not Attacks, And The Page Says So

**This is the tension at the centre of the memo and it must not be ducked.** For three days every document in this corpus has said that a rule somebody wrote down is the second barrier row and does not bound a grant. The memo now proposes selling exactly that as the entry product.

**The resolution is to sell it and say precisely what it is.**

**A prompt does not bound the grant. It changes what the agent tends to do.** The model provider's own words, from 25 May 2026:

> Model layer controls shape only what the agent tends to do, not what it is theoretically capable of doing.

**Read that as a product claim rather than a warning and it is a good one.** Shaping tendency is worth money **when the failure mode is tendency**, and most off piste behaviour is not an attack. It is an agent doing something reasonable that nobody wanted, because nobody told it. **The barrier argument is about adversarial bypass. The everyday failure is not adversarial.**

**So the honest label, and it goes on the product page in these words or better:**

> This reduces accidents. It does not stop an attacker. Here is what would.

**Three things that buys.**

**It makes the mandate explicit, probably for the first time.** Writing down what you want the agent to do is the elicitation, and the estate has been arguing for a week that the mandate is the scarce input.

**It reduces the common failure.** No number is claimed, because none exists, and the page should not invent one.

**It is the input that compiles into a real control later.** The same mandate, expressed as rules at a gateway, is the thing that stops an attacker, and that is the uplift rather than a different product.

**And it turns the weakness into the ladder.** A buyer who understands why the prompt is not a control understands why the next tier exists. **Nobody else selling a packaged prompt explains this, because explaining it makes the thing they are selling sound smaller.**

## A Distributed Skill Cannot Carry A Control, And That Is A Field List Rather Than An Opinion

**The skill format is better distribution than the memo assumes and weaker enforcement than anybody assumes, and both are checkable.**

**On distribution, the news is good.** The format is no longer one vendor's. It is an open standard with its own specification and governance, and the showcase lists **around forty six products** supporting it, including the other two large model providers' coding agents, a large code host's assistant, and several editors and frameworks. **A skill written once is portable across that set without modification**, provided it stays inside the portable field list. Distribution is decentralised: anybody can host a catalogue on a git host and users add it with one command. **There is no central gatekeeper and no approval queue.**

**On enforcement, the news settles an argument.** The portable frontmatter carries six fields: name, description, licence, compatibility, metadata, and one for pre approved tools that is **marked experimental**. The fields that would actually constrain an agent, meaning the ones that disallow tools, attach hooks or restrict paths, **exist in one client's own implementation and do not survive external distribution.**

**So a skill distributed to somebody else can carry instructions and cannot carry a constraint.** That is not the barrier argument as an opinion. **It is the format's field list.** And it means the honest positioning above is not a concession we chose, it is the only positioning the delivery mechanism permits.

**Two operational notes.** There is **no payment rail anywhere in that stack**, so charging means gating outside it, with a private repository and an ordinary payment provider. And skills **do not sync across a provider's own surfaces**, so a skill uploaded in one place is not available in another, which matters for what the customer is told they are buying.

**One risk worth naming.** The same provider's guidance says to use skills only from trusted sources, because a skill can direct an agent to invoke tools in ways that do not match its stated purpose. **We would be asking people to install an instruction set from a company they have just met.** That argues for publishing the skill in the open, in full, readable before installation, which we would do anyway.

## The Format Sets The Price More Than The Content Does

**This is the most useful pricing finding and it is not about the number.**

| Format | Observed market price |
|---|---|
| A packaged skill on the one marketplace with a payment rail | **Five to fifteen dollars**, a few to twenty five, **median earnings under fifty dollars a month** |
| Skills on a general craft marketplace | **Nineteen thousand skills for four dollars.** Two thousand for nine |
| Prompts on the incumbent prompt marketplace | About three to seven dollars, median around six |
| A governance template pack, as documents | **Ninety nine dollars** for sixty templates |
| An agent governance toolkit, as documents | **Two thousand one hundred and ninety nine dollars** |

**The same argument is worth four dollars as a skill, ninety nine as a document pack and two thousand as a toolkit.** Nothing about the content explains that spread. **The container does.**

**Two consequences.**

**Do not sell the ABP as a skill.** Sell the skill as the free thing, and sell the vault. A skill that costs money sits in a market where nineteen thousand of them go for four dollars, and no amount of quality escapes that comparison, because the buyer cannot see quality before purchase.

**And note what the gap says.** Between a free hobbyist constraint skill and a gateway product at twenty dollars per seat per month, **there is nothing.** That emptiness is the opportunity and the warning in the same fact: nobody has made this work yet, and nobody has tried and failed publicly either.

## What The Site Gives Away, And What Is Left To Sell

**The memo asks the right question. If the free thing is not genuinely useful nobody comes, and if it is too useful nobody pays.**

| Free, on the site | Paid |
|---|---|
| The five example policies, in full, with their provenance | **Yours, not a shape's.** Derived from the deployment you actually run |
| The capability map and its data | **A vault you can hand to somebody** with a read key |
| A draft for your shape, instantly, no account | **It recomputes** when the grant or the mandate moves, and keeps the history |
| The generic skill, published in the open | **Somebody looked at it**, and at the higher tier signed something |

**The line is clean: the library is the argument and the instance is yours.** That is the 26 August ruling and it holds here without adjustment.

**And the free tier is the top of the sales motion rather than a giveaway**, because the draft and correction flow is both the free thing and the elicitation. **Somebody who corrects our draft has told us their mandate, which is the input we would otherwise have to buy their time to get.**

## The Price Experiment, Redesigned

**The memo proposes giving an early access group the full flow and then asking whether it was worth ten pounds. The research says that specific design will produce a number that is confidently wrong.**

**Four findings that kill it.**

**The sample is below every published floor.** The standard method for this has no authoritative minimum, and practitioner guidance runs from fifty to four hundred, with fifty described as directional only. **At fifteen to thirty people you are below all of them.** Worse, the main open source implementation's own demonstration dataset discards forty three per cent of respondents for giving answers that are not internally consistent. **Twenty people may be eleven.**

**The method is at its worst on exactly this product.** Its documented weakness is new products for which respondents have no reference price. That is this.

**Stated willingness to pay overstates real.** Meta analyses put the gap between one point two and three times, with about twenty one per cent average bias for consumer goods specifically.

**And showing a price first contaminates the answer badly.** The classic result found stated values fifty seven to over a hundred per cent higher among people anchored on the last two digits of an identification number. **The meta analytic correlation between an arbitrary anchor and the elicited value is around 0.27.** So asking *would this be worth ten pounds* does not measure whether it is worth ten pounds. It measures the effect of having said ten pounds.

**Three findings that give a better design.**

**Certainty filtering works and the standard mitigation does not.** In a field experiment with two hundred and sixty seven participants buying a real product at three price points, hypothetical intent ran at forty five per cent against a real purchase rate of twenty six. A cheap talk script left it at forty five. **Counting only the people who said they were definitely sure gave twenty four per cent against a real twenty six.** One extra question, essentially exact.

**A real offer predicts as well as anything fancier.** A field study of over a thousand households found a plain take it or leave it price predicted behaviour about as well as a formal incentive compatible mechanism. **Three real sales at a price beat thirty stated willingness to pay.**

**And anchoring largely disappears when money is real.** Three experiments with eighteen hundred participants found substantial anchor effects under hypothetical questioning and **no significant effect under real payment**. That is the strongest argument for charging rather than asking.

**So the redesign.**

| Instead of | Do this |
|---|---|
| Ask twenty people what they would pay | **Charge a price and count.** Even three purchases is evidence; thirty opinions are not |
| Show a price then ask | **Never show a price before any question about price** |
| A cheap talk preamble | **A certainty question after**: how sure are you, and count only definitely |
| One price across everybody | **One price at a time.** A split test at this size cannot detect any realistic difference: at fifteen per arm the other arm must more than triple conversion to register |
| Treat a few sales as a conversion rate | **Treat a zero as the finding.** Nobody buying out of thirty puts the true rate under about ten per cent, which is informative. Three out of thirty tells you almost nothing, with a confidence interval from four to twenty six per cent |

**And use the small group for what small groups are actually good for.** Twelve interviews reach thematic saturation in the published work on the subject, which means **a dozen good conversations will surface essentially every reason somebody does not buy.** That is the real yield of an early access group: the objections, the words that landed, and which of the four paid properties they reached for first. **Not the number.**

**One extra variable worth testing, given the format finding above: test the container, not just the price.** The same policy offered as a skill, as a document and as a vault with a read key will not command the same price, and the spread between four dollars and ninety nine in the observed market suggests the container is the bigger lever.

## What This Does Not Try To Be

- **A price.** None is recommended. The floor of ten pounds set on 10 September stands on card fee arithmetic and nothing here changes it.
- **A claim that the prompt works.** No effectiveness number is given because none was found. The positioning is that it addresses mistakes rather than attacks, and that claim rests on a provider's own description of what model layer controls do.
- **A skill.** The format, the portable fields and the distribution mechanism are established. Nothing is written.
- **A marketing plan.** The urgency mechanic is specified as three sourced sentences. The page is not written.
- **A verified adoption picture for skills.** The counts published in that ecosystem are crawl artefacts, one marketplace contradicts itself on its own revenue split, and star counts could not be checked from this session.

## Honest Tensions

| Tension | Note |
|---|---|
| No deadline | It is honest and it is a harder sale than a deadline would be |
| The state framing | The exposure genuinely predates the purchase, and stating it is one short step from selling fear |
| Mistakes not attacks | It is true, it is the only thing the format permits, and it caps what the entry product can claim |
| Selling a prompt at all | It is the fastest thing to ship, and every other document in this corpus says that layer bounds nothing |
| Giving the skill away | It is the top of the funnel and it is also the thing most people will take and never return |
| Charging instead of asking | It is the only design that yields a real signal, and it means asking strangers for money before the product is finished |
| The empty gap in the market | Nobody occupies the space between a free skill and a gateway subscription, and nobody has publicly failed there either |

## Open Questions

1. **What is the first price?** The research says pick one and charge it. Nobody has picked.
2. **Does the generic skill cannibalise the paid vault, or advertise it?** The four paid properties suggest it advertises, and that is an assumption nobody has tested.
3. **Who is in the early access group?** A dozen people who run one of the five shapes is the right composition and no list exists.
4. **What does the certainty question ask, exactly?** It is one sentence and it is the only part of the survey the evidence supports.
5. **Does the skill get published in a catalogue, or only from our own site?** Decentralised distribution is available and it puts an instruction set from us on other people's machines.
6. **How is the free draft rate limited?** It is the elicitation and the funnel, and it is also a thing somebody can take a thousand of.
7. **What happens when a vendor changes a scope?** The urgency section quotes three vendor pages, and a quoted page that changes turns an accurate claim into a wrong one overnight.

## Relationship To Previous Briefs

**From the end to end brief of yesterday**, it takes the three sourced sentences about what a connector grants, and turns them into the urgency mechanic.

**From the foundation document**, it takes the four barriers, and accepts the consequence that the entry product sits at the second one and must say so.

**From the second brief of 11 September**, it takes the provider statements about prompts, and reads one of them as a product claim rather than only as a warning.

**From the third brief of 11 September**, it takes the market changes of this year, and uses the narrowing of one thing and the arrival of another as the only dated answers to why now.

**From the ladder ruling of 3 September**, it takes the prohibition on the word, and supplies the version of the argument that survives on a page carrying a price.

**From the ruling of 20 August**, it takes publish the record and never the verdict, and applies it to the hardest case, which is a page whose job is to create urgency.

**From the toolkit brief of 10 September**, it takes the finding that games help as a supplement and not as a replacement, and notes the same shape here: the prompt is a supplement to a control and is worse than useless if sold as a replacement for one.

## Key Claims

| # | Claim |
|---|-------|
| 1 | There is no deadline, and inventing one would break the rule against publishing a verdict |
| 2 | The urgency is a state rather than a deadline, because the exposure was created when the connector was enabled and has never been enumerated |
| 3 | So the urgency section quotes three vendor pages with dates and attaches no adjective, and the reader supplies the conclusion |
| 4 | Two dated things changed this year: a standard liability exclusion effective 1 January 2026, and a regulator assigning responsibility on 9 March 2026 |
| 5 | A prompt is the second barrier row, so the entry product stops mistakes rather than attacks and the page must say so |
| 6 | That is defensible because the provider's own words are that model layer controls shape what an agent tends to do rather than what it can do |
| 7 | A distributed skill cannot carry a control, because the constraining frontmatter fields do not survive external distribution |
| 8 | The skill format is a cross vendor open standard carried by around forty six products, so distribution is better than expected and enforcement is impossible |
| 9 | The format sets the price more than the content does, from four dollars as a bundled skill to two thousand as a document toolkit |
| 10 | So the skill is the free thing and the vault is the paid thing |
| 11 | The proposed price survey cannot work, because the sample is below every published floor, the method is worst on new products, and showing a price first contaminates the answer |
| 12 | Charge a price and count, filter by certainty rather than by a cheap talk script, and use the dozen conversations for objections because twelve reach saturation |

---

## Sources

All read 12 September 2026.

**Inside the estate.** The foundation document and the briefs of 11 September. The capability map at https://what-can-it-do.games.sgit.ai/map/index.html. The connector scope research in the end to end brief of 11 September, drawn from vendor documentation at https://developers.google.com/workspace/gmail/api/auth/scopes, https://developers.google.com/workspace/drive/api/reference/rest/v3/files/list and https://support.claude.com/en/articles/12684923-microsoft-365-connector-security-guide.

**What changed this year.** The standard form exclusion announced 21 October 2025 and effective 1 January 2026 at https://www.independentagent.com/vu_resource/verisk-to-roll-out-new-general-liability-exclusions-for-generative-ai-exposures/, and the absolute exclusion reported at https://www.hunton.com/hunton-insurance-recovery-blog/the-continued-proliferation-of-ai-exclusions. The consumer guidance of 9 March 2026 at https://www.gov.uk/government/publications/complying-with-consumer-law-when-using-ai-agents.

**What a prompt does and does not do.** The statement that model layer controls shape tendency rather than capability, 25 May 2026, at https://www.anthropic.com/engineering/how-we-contain-claude.

**The skill format.** The specification and its governance at https://agentskills.io/specification, and the client showcase listing around forty six products. Distribution via decentralised catalogues at https://docs.claude.com/en/docs/claude-code/plugin-marketplaces. The portable field list, the absence of a payment rail, the non syncing of skills across surfaces, and the guidance to install only from trusted sources, from the same documentation set. Cross vendor adoption confirmed at OpenAI's Codex skills documentation and the Gemini command line documentation, both of which name the standard.

**What packaged prompts and skills sell for.** Marketplace listings and the platform's own pricing guidance at https://agensi.io, including the statement that individual skills sell for five to fifteen dollars and that median earnings are under fifty dollars a month, with its revenue split stated inconsistently across two of its own pages. Bundled listings at a general craft marketplace, including nineteen thousand skills for four dollars, read today. Prompt prices at https://promptbase.com. The governance template pack at ninety nine dollars at https://governancedocs.com. The toolkit at two thousand one hundred and ninety nine dollars at https://agentguru.co.

**Price discovery method.** The price sensitivity meter, its four intersections and the absence of any authoritative minimum sample, with practitioner floors from fifty to four hundred, summarised at https://en.wikipedia.org/wiki/Van_Westendorp%27s_Price_Sensitivity_Meter and https://sawtoothsoftware.com. The critique that it has no theoretical foundation and fails on products with no reference price, at https://www.relevantinsights.com. The intransitive response discard rate from the reference implementation's own demonstration dataset.

**Stated against real willingness to pay.** The consumer goods meta analysis reporting twenty one per cent average bias, Schmidt and Bijmolt 2020, Journal of the Academy of Marketing Science 48(3). The earlier meta analysis reporting a median ratio of 1.35, Murphy and others 2005. The field experiment with two hundred and sixty seven participants showing hypothetical at forty five per cent against real at twenty six, cheap talk at forty five, and certainty filtering at twenty four, Blumenschein and others 2008, The Economic Journal. The comparison of a plain offer against an incentive compatible mechanism, Berry, Fischer and Guiteras 2019.

**Anchoring.** The coherent arbitrariness experiment, Ariely, Loewenstein and Prelec 2003, Quarterly Journal of Economics 118(1). The meta analysis reporting a correlation around 0.27, Li, Maniadis and Sedikides 2021. The finding that anchoring is substantial under hypothetical questioning and not significant under real payment, Brzozowicz and Krawczyk 2022, PLOS ONE 17(1).

**Small samples.** The saturation finding that twelve interviews surface essentially all themes, Guest, Bunce and Johnson 2006, Field Methods 18(1). Confidence interval and power figures computed for this brief and checkable with any statistics package.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
