<!-- Generated from briefs.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — the brief register

Every document this site was built from, what it produced, and what it did not. Kept with a digest per file so nothing is worked twice and nothing is quietly dropped.

Source: https://riskmandate.ai/briefs.html

---

# Everything we were given, and what came of it.

This site is built from briefs written elsewhere. Two things go wrong with that arrangement: the same document gets worked twice, and a document arrives and is never worked at all. Both failures are invisible unless somebody keeps a list — so here is the list, with the digest of every file as it was received and an honest status against each one.

## Two failures, one list.

Neither of these is hypothetical. One of the documents below arrived twice, byte-identical, six hours apart — and three Lab entries had already been written from it. Without a digest to compare, the only thing standing between that and a wasted afternoon is somebody's memory of a filename.

- **Nothing gets worked twice.** Every file is archived exactly as it arrived and its SHA-256 recorded. An identical file turning up again is recognisable _before_ anybody starts reading it, and the register lists every time it turned up rather than only the first.
- **Nothing gets quietly dropped.** The agent producing these briefs can fetch [briefs-register.json](briefs-register.json), compare it against what it has sent, and name anything that is absent. That is a check somebody else can run against us, which is the only kind worth having.
- **The status is the state of the work, not an intention.** Received means read and archived with nothing built, and Partly — the commonest honest answer — means some of it shipped and a named part did not. Neither is a promise that the rest will follow.
- **And what was _not_ done is recorded beside what was.** A register that lists only outputs flatters the work. Every entry below carries both columns, and the right-hand one is usually longer.

|  | Status | What it means |
| --- | --- | --- |
| Processed | processed | Read in full, and something on this site exists because of it |
| Partly | partly | Read in full; some of it is built and a named part is not |
| Received | received | Archived and read, and nothing has been built from it yet |
| Superseded | superseded | Later material replaced it. Kept, because the reasoning is still the record |

## Five files, in the order they arrived.

Each one is linked in full, as received, with nothing edited. Where a brief and this site disagree, the brief is what we were given and the site is what we concluded — and where we corrected a brief, the correction is on the page rather than in the file.

### The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The Template Vault Is The Product

**sha256** 1b2dfa45d228be6b0f6eb6a420090da160e979fe0b347048588565441a9f6e38

**This is the one that arrived twice.** Byte-identical both times, and the second arrival came in the same message as D3 and D4. It was not reprocessed — the three Lab entries below were already written from the first copy. This entry is the reason the register exists.

- [Lab 01 — the grant is user-shaped, not data-shaped](lab-connector-grants.html), with four vendor quotes verbatim
- [Lab 02 — what buying a behaviour policy would look like](lab-abp-flow.html), including the twelve-stage flow
- [Lab 03 — requests against abp.sgit.ai](lab-abp-requests.html), including the proposed `material` property
- **The five first policies themselves.** Lab 01 documents the grants; no policy document exists for any of the five shapes
- **The template vault and the shape library** — named in the brief as the actual product, and not started
- **The instrumentation table** timing the first five, which the brief calls the only pricing input anybody will have

### This Is The Tier One Application Nobody Could Find: The Connector List Alone Is Twenty Bits, So Compute Locally And Submit Banded

**sha256** 11ff8f5f9eebb9200d30694381ff27c7e53a59417dd92f1a0461bbfe1b65ad89

**One correction to this brief is stated on the page it produced, and marked as ours.** The brief treats banding as the fix. Worked through, banding is the necessary first move and not the whole answer, because a banded submission still carries roughly the entropy of the fingerprint study the brief benchmarks against. The page shows the assumptions so somebody can check the arithmetic.

- [Lab 04 — seven things to build, and one word we have not earned](lab-shape-collector.html)
- **All seven items on Lab 04's own build list.** The page is the specification; none of it is built

### The Commit Author Is A Free Text Field: A Prompt Shifts The Odds, And Every Documented Fix Was Architectural

**sha256** b54eddae92bc88d8133c1e544c339433972ef6cf8cf8656ac4771b7ffbce7ccd

**The finding and the prompt are built; the experiment is not.** All six load-bearing quotations were fetched and checked against their sources rather than relayed — which produced two corrections to this brief, both stated on the page it became: the _partially verified_ state additionally requires the author to have **enabled vigilant mode**, and the claim that the attribution renders a profile picture and a profile link could not be found on the page cited.

- [Lab 05 — your agent can commit as you, and no instruction stops it](lab-commit-author.html), with the eight-line prompt and its _enforced by_ column
- The [free/paid line](pricing.html), which now sends a reader to Lab 05's four free settings before asking them for money
- **The comparison experiment.** Lab 05 specifies it — three arms, twenty runs each, violations counted as repository queries — and no repository has been set up to run it against
- **A signed-commits rule on our own repository.** Lab 05 says in as many words that the argument is demonstrated and not adopted until that is on
- **Provider and connector pages** mapped onto the four layers, and the community incident repository behind them

### The Urgency Is Not A Deadline But A State: You Already Connected It, And A Distributed Skill Cannot Carry A Control

**sha256** af73131b6a72bb5f6d8aad1563f124a016040833310df0fb8be717ec44bb0e56

**Both of its rulings are now on the site.** The entry product says it reduces accidents and does not stop an attacker, in those words, on the page carrying a price — and the behaviour policy is not sold as a skill, because the portable part of that format cannot carry a constraint. The word for the narrowing cover does not appear on the pricing page at all; the authorise question stands in its place.

- The urgency section on [the front page](index.html) — three vendor sentences with dates and no adjective, then the two dated changes of this year
- The [free/paid line](pricing.html), with the honest label and the authorise question
- **The price experiment as redesigned** — charge one price and count, with a certainty question after. The page states the approach; no price is set and nothing is charged
- **The generic prompt as an installable artefact.** The pricing page says it is free and published in the open; the file does not exist yet
- **The early access group** — a dozen people running one of the five shapes, used for objections rather than numbers. No list exists

### Startup Summit 2026 — exhibitor booth guide

**sha256** d13e3f08729fa8ffaab7f4e1d247535fb0782c5182df67e365ef61d52ca0cf3d

**Third-party material, and it corrected three of our own planning assumptions** — the banner is not permitted, submissions go through the exhibitor portal rather than by email, and power has to be requested rather than assumed. Kept on a working page rather than a public one; whether it stays fetchable here at all is an open decision.

- [The booth working page](summit-booth.html), with the guide embedded and the materials to hand over
- Three corrections to [the Lisbon page](summit.html) and the messaging brief behind it
- **Logo and name into the exhibitor portal.** The organisers' own deadline was 15 September
- **The power request**, which goes through the portal and not by email

## And the instructions that arrived as speech or a sentence.

These have no digest to check, which makes them the ones most easily lost — a voice memo that changed the direction of the whole site leaves no artefact at all unless somebody writes it down. So they are recorded here in the same list, with the same two columns.

**Put the Agent Behaviour Policy at the centre of the site.** The ABP is the fundamental primitive; the grant is calculated from reality via digital twins; RiskMandate drives the sale of ABPs, and those are the first batch of customers; the audiences are corporate users, investors and founders; and a security vendor whose controls reduce the delta has a business case we can make for them.

- [The Agent Behaviour Policy page](abp.html)
- The direction brief, in the repository under `docs/briefs/`
- The homepage's second panel, which should become _the grant you did not enumerate_ and still does not
- [Pricing](pricing.html) repointed at the store tiers

**The Startup Summit exhibitor pack and the event site**, for a strategy document and the materials we need to submit.

- [The Lisbon 2026 page](summit.html)
- The messaging and strategy briefs, in the repository under `docs/briefs/`
- Nothing, other than what D5 corrected.

**Hire a freelancer who also works through agents.** Give them a page and a first prompt focused on making sales online and at Lisbon, and make their first task being a power user and tester of behaviour policies.

- [Working with us](work.html)
- [Brief B1 — power user and tester of Agent Behaviour Policies](work-abp-power-user.html)
- Rate, hours, start date, escalation route, publication rules and repository access — deliberately absent because that page is public, and listed on it as owed

**Preserve the Lab's thinking as it changes**, and publish it as files that can be sent through a chat app — because by the time a reader follows a link, the page has moved on.

- Dated PDF editions of every [Lab](lab.html) entry, and the whole Lab as one file
- [The edition register](lab-editions.json), with a digest per file
- Nothing.

## Check us, rather than trusting us.

The whole point of a digest is that somebody else can compute it. If you produce these documents, you do not have to take this page's word for what arrived — hash what you sent and compare.

**Every document is recorded by the SHA-256 of the file exactly as we received it.** Hash your copy, look for the digest in the register, and anything that is not there did not reach us — or reached us and was not archived, which is our bug and worth telling us about.

```
# what did we actually receive?
curl -s https://riskmandate.ai/briefs-register.json \
  | jq -r '.documents[] | "\(.sha256)  \(.status)  \(.title)"'

# is the brief I just sent in there?
sha256sum my-brief.md
```

A register that only lists what was done is a press release.

Every entry above carries what it asked for and did not get, and on most of the nine that column is the longer one. It is kept that way deliberately: the value of this page is that it can embarrass us, and a version that could not would not be worth fetching.

- **The file is the record, not this page.** [briefs-register.json](briefs-register.json) is what a program should read; this page renders it for people. If the two ever disagree, the file is right and the page is stale.
- **Every archived document is byte-identical to what arrived.** Nothing is edited, reformatted or trimmed — including the parts we think are wrong. Where we disagree with a brief, the disagreement is published on the page it produced and marked as ours.
- **Statuses go stale in one direction only.** An item marked _received_ can become _processed_. Nothing moves the other way, and nothing is deleted from the list once it is on it.
- **If something is missing, that is the most useful thing you could tell us.** Use the contact control in the header and name the digest.

Register maintained by hand alongside the work, and checked in CI: every document listed must exist at the path given and match its recorded digest, and every file in `assets/briefs/` must appear in the register. Last reconciled 12 September 2026.

## Nine items. None untouched, and none finished.

Every item now names something it produced and something it did not. Four of the nine are marked _partly_, which is the honest state of almost all real work and the status this register expects to use most. The column that matters is the right-hand one.
