| MANDATE.md | What the agent is authorised and expected to do — six wanted, three refused, fourteen unstated | you — elicited; the only authored file |
| GRANT.md | Everything the agent can do: fifteen capabilities, each with its barrier, undo class, evidence tier and the tool it goes through. Irreversible rows first | measured from the shape — 13 of 20 rows observed on the thing itself |
| DELTA.md | Nine in the grant that nobody asked for: three refused, six never mentioned, seven with nothing but a setting or a sentence in the way | derived — never authored, recomputed on every build |
| LICENCE-TO-OPERATE.md | The organisation authorises the agent under this behaviour policy, for an interval, on nine conditions — each next to what enforces it | derived from the mandate; a named person signs it when issued |
| AGENT-BEHAVIOUR-POLICY.md | The four objects in one document | derived |
| AGENTS.md | The file you hand the agent: what the others are, what to do with them, and what a file like it cannot do | generic — travels unchanged with every vault |
| SKILL.md | The same, in the portable agent-skill format | generic — travels unchanged |
| README.md | How to read it, how to correct it, how to give it to the agent | derived |
| data/ · history/ | grant.json, mandate.json, delta.json, validity.json, the pinned vocabulary, and one history entry per recompute | the machine-readable half of every row above |