RiskMandate v1.20.2
Rung two of three

A licence to operate.

The organisation is the authority, the behaviour policy is the instrument, and the agent is the licensee. Self-issued, witnessed and dated — which is how most assurance works. Until one is issued, the agent runs on nobody’s say-so, which is the honest description of almost every agent running today.

What it is

Four facts, and a date it comes back.

A licence to operate is short on purpose. It is not a control, it is a record of a decision, and the whole value is that somebody’s name is on it and it expires.

  • AuthorityThe organisation, through a named accountable owner. Not a team and not a function — accountability that cannot be forwarded
  • LicenseeOne agent in one deployment, identified by its shape and the version of the grant it was licensed against
  • InstrumentThe behaviour policy itself: the mandate, the delta and the vocabulary, each pinned to a version
  • Valid untilAn interval, set when it is issued. A licence with no expiry is not a decision
  • ScopeEach condition beside the thing that actually enforces it — or beside the admission that nothing does

The last row is the one that does the work. A condition with nothing enforcing it is an expectation, and three of the four barrier kinds bound nothing at all. A licence that does not distinguish them is a document that reads like a control and is not one.

Why it needs a policy underneath

You cannot license what nobody has described.

This is the whole reason the work starts one rung down. A licence is an authorisation of specific capabilities; if nobody has enumerated the capabilities, the licence authorises a shape rather than a thing, and it is worth exactly what the enumeration was worth.

Where it lives

A file in the pack, not a certificate.

The licence ships as LICENCE-TO-OPERATE.md inside the vault, so the agent can read the terms it runs under and a person can read the same terms without a portal. Every published vault carries one, unissued, with the authority and the interval left blank until somebody fills them in.

AGENT-BEHAVIOUR-POLICY.mdGRANT.mdDELTA.mdLICENCE-TO-OPERATE.mdAGENTS.mdSKILL.md

Status, stated plainly. The file exists and ships in every published vault today, as a template: unsigned, unissued, with the authority and the interval blank. What does not exist is the countersigned form — a licence somebody outside your organisation would accept as evidence — which is what rung three needs and what we have not built. We are not going to describe that as available because the file is.

How to buy one

One thing, at four levels.

A licence needs a behaviour policy underneath it, and that is what the four levels sell. The whole ladder, what each level changes and who does the work is on pricing; the catalogue and the checkout are on the store.

The store takes the order and hands you back here: one page per level, and at level one that page is the download — the zip, its size, its sha256 and a check that runs in your own browser. Payment rails are not built yet, and every checkout button on the store says so rather than looking live.

Start one rung down

Licence one agent.

Pick an agent you already run, get the behaviour policy for it, and the licence is the short document you write on top. Both are files you keep.