<!-- Generated from early-adopters.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — early adopters: a thank you, and a behaviour policy corrected with you

A thank you to two groups who backed this early: the early users of The Cyber Boardroom, the company behind RiskMandate, who bought credits, and the early adopters of RiskMandate. Each gets an Agent Behaviour Policy for one agent they run, corrected for their situation with them, the level the store sells for £500, at no cost, for thirty days from their email. How to collect it, what it is, and what it is not.

Source: https://riskmandate.ai/early-adopters.html

---

# You backed this early. Here is what it became, and what we owe you.

Two groups of people put something in before there was much to see: the early users of The Cyber Boardroom, who bought credits, and the early adopters of RiskMandate, who said yes to a programme on an invitation. The Cyber Boardroom is the company behind RiskMandate, and the work moved on. This page says where it moved, what we are giving each of you for having been there, and how to collect it in the next thirty days.

**The offer:** an Agent Behaviour Policy for one agent you run, corrected for your situation with you: the level the store sells for £500, at no cost, for thirty days from the day your email arrives.

**How to collect it:** [register with the code in your email](early-access.html). One form, encrypted in your browser; a person replies within a working day.

**This page as markdown:** [early-adopters.md](early-adopters.md)

## From a boardroom tool with credits to a document about one agent.

The Cyber Boardroom set out to give boards a way to ask questions about cyber risk in plain language, and some of you bought credits to try it. The question that kept coming back was narrower and harder: not _what is our cyber risk_ but _what can this agent we just connected actually do, and who said it could?_ RiskMandate is the answer to that question, and the Agent Behaviour Policy is the document it produces: for one agent in one deployment, everything it can reach, what it was authorised to do, the gap between the two, and what stands in the way of each thing. The same company, the same person, one step further down.

_The same company, one step further down: from credits in a boardroom tool to a document about the one agent you run._

is the company behind

## Two groups, one offer.

### You bought credits. Most are still there.

You put £5 in to try it, and the logs say most of you did not get much back for it. That is on the product, which moved, and not on you. The credits were a vote of confidence in a direction; the direction is now RiskMandate, and this is the thank you: the corrected behaviour policy below, for one agent you run, at no cost.

Your invitation code starts with `CB-`.

### You said yes to an invitation. It just got bigger.

The [early-access programme](early-access.html) offered a behaviour-policy vault made from your public pages, free, in exchange for telling us where it is wrong. As an early adopter you are a design partner, and design partners get the next level: the same vault, then corrected with you for your situation. The same thing the first group gets.

Your invitation code starts with `EA-`.

## The £500 level, at no cost.

The store sells an Agent Behaviour Policy at [four levels](pricing.html). The third, _corrected for your situation_, is the one where the document stops describing a deployment in general and starts describing yours. That is the one you get.

- **One agent you run, named by you.** A mailbox connector, a coding agent, a workflow tool, a CRM assistant, a dot. If the shape is one of [the sixteen published](agent-behaviour-policy.html), the vault starts from it; if not, it starts from the vendor’s pages, dated.
- **The grant, documented and then measured by you.** Every vault carries the prompt that lets the agent holding the credential measure its own reach, in the fixed vocabulary of 23 capabilities and four barriers. Twenty minutes, nothing of yours leaves your side, and the documented rows become measured ones.
- **The mandate, corrected with you.** This is the part the price is for. You tell the agent that keeps this site, by email or on a call, what the agent is for in your organisation, and the mandate is corrected against your industry, your use case and your words; the gap is recomputed; a written note of what changed and why is committed beside it, and a person reviews the note before it goes to you. [What level 3 delivers](paid-t3.html), word for word.
- **An encrypted vault you hold the keys to.** The link by one message, the key by another, never on a page. A read key you may hand to your board, your auditor or your broker. Your vault is never listed or published without your yes, and the default is no.
- **A direct line.** `agent@riskmandate.ai`, read by a person within a working day, and [the contact form](contact.html), which reaches the same agent through its vault.

## Collect it before the window closes.

The offer is open for thirty days from the day your email arrives. The window is there because every vault is made by hand and corrected in a conversation, and a batch has to be a batch. After thirty days the early-access programme is still open on its own terms, and the store still sells the level.

### Your email arrives, with a code

From `agent@riskmandate.ai`, signed by the lead. The code is `CB-` or `EA-` and four characters. It is a label for matching you to this page, not a gate.

### Register, with the code

[The early-access form](early-access.html): your name, your organisation, the agent you run, the code. Encrypted in your browser to the key of the agent that runs this site; the site itself keeps nothing. No form? Reply to the email instead.

### A person confirms, within a working day

And asks the one question the correction needs: what is this agent for, in your words.

### Your vault, within five working days

The link by one message, the key by another. Read the mandate first; it was drafted to be argued with.

### Correct it with us

Run the prompt where the agent runs; send back what it measured; tell us what is wrong in the mandate. Each correction is a commit in your vault’s history, with the note beside it. Done is a commit you can check.

## What this is, and what it is not.

- **It is a thank you**, from the same company and the same person, for having put money or time in before there was much to see.
- **It is not a security assessment**, and not a promise about your agent’s behaviour. A behaviour policy describes; it carries no score. Where the vendor’s pages and your measurement disagree, the disagreement is recorded unresolved rather than settled by guessing.
- **Your credits are yours.** The offer does not touch them; nothing on this page asks you to give anything up.
- **Nothing of yours is published.** The vault is private, the key is yours, and the default for listing it anywhere is no. What you tell us about the agent goes into your mandate and nowhere else.
- **What we count.** How many of you register, and then how many run the prompt and correct a mandate. That number, not the number of emails sent, is how we know whether this worked.

How this programme is run, including the words that go out and who does what, is written down on the console: [the early-adopters programme](admin/briefs/programme--early-adopters-thank-you/index.html). The Cyber Boardroom: [thecyberboardroom.com](https://www.thecyberboardroom.com/).

## One agent, written down, corrected with you.

If your email has arrived, the code is in it. If it has not and you think it should have, write to `agent@riskmandate.ai` and say which group you are in.
