<!-- Generated from for-corporate.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# You run agents today

You gave an assistant access to a repository, a mailbox, a cloud account. A behaviour policy says what it can actually reach, what you authorised, and the gap.

Source: https://riskmandate.ai/for-corporate.html

---

# Do you know what it can do? Not what it did.

You gave an assistant access to a repository, a mailbox, a cloud account. You know what you asked it for. Nobody enumerates the rest, and the rest is in the grant regardless of whether anyone wrote it down.

## Your first serious customer will ask, and so will your insurer.

## The grant is user-shaped, not data-shaped.

The unit of restriction is the application, never the material. There is no supported way to say _this assistant may read my files except the folder the legal team share with me_. That is not our finding — it is in the publishers’ own scope definitions, and it is [set out with sources](grant-gap.html).

## One agent, written down.

A behaviour policy for one agent in one deployment: every capability it can reach, what you authorised it to do, the gap between the two, and what actually stands in the way of each row. Three of those you can write down; the gap is computed, and it is usually the one nobody has looked at.

It is a draft on purpose. It goes to the people who built the agent, the people who own what it touches and the people accountable for it, and each corrects the part they know. The correction is the product.

## We do not discover your estate.

This reaches a personal device, a personal account and a locally run server with no install and no administrator — and in exchange it only ever sees what somebody is willing to say. An inventory built on telemetry sees what is on the network whether anybody admits to it or not. If you already run a good one, we would rather read from it than replace it.

## One thing, at four levels.

Start at level one: the pack for the shape you run, as a zip you keep. Level two is the same material as a vault you hold the keys to. The whole ladder, what each level changes and who does the work is on [pricing](pricing.html); the catalogue and the checkout are on the store.

The store takes the order and hands you back here: one page per level, and at level one that page **is** the download — the zip, its size, its sha256 and a check that runs in your own browser. Payment rails are not built yet, and every checkout button on the store says so rather than looking live.

## Start with the one that worries you.

Not the whole estate. One agent, already running, and the behaviour policy for it as a file you keep and correct.
