# RiskMandate — The insurability layer for agentic AI. > Make your agents insurable. Carriers are filing to exclude AI from cover, and the way back is evidence an underwriter will accept. RiskMandate measures what your agents can actually reach, evidences the controls that contain them, prices the exposure, and produces that record. Underneath the insurance framing is a risk model: a grant is what a credential technically permits, a mandate is what the holder is authorised and expected to do, and the gap between them is exposure nobody ever accepted. A deployed agent already has access, so a real risk cannot be denied — only accepted, by a named owner, for an interval, with an expiry that brings the decision back. RiskMandate is read-only and never in the request path: it defines the mandate and measures the gap; it does not enforce it. It is built on SG/Vault — zero-knowledge, PKI, provenance, no database — so you hold the keys. Site version v1.0.0. The version record is at https://riskmandate.ai/versions.html and its index at https://riskmandate.ai/versions/index.json. ## Core concepts - **The insurability layer**: carriers are moving to exclude AI, and affirmative cover now turns on evidence rather than a questionnaire; we produce the record an underwriter will accept. - **The Insurability Index**: a 0–100 score over five weighted dimensions, derived from your environment rather than a self-assessment, with six levels from Unmapped to Underwritten. - **The grant is not the mandate**: a grant is what a credential technically permits; a mandate is what the holder is authorised to do; the difference is excess authority nobody accepted. - **The signature mechanic: no deny button**: a deployed agent already has access, so a real risk cannot be denied — only accepted, by a named owner, for an interval, with an expiry that returns the decision. - **Never in the request path**: read-only by design — no runtime decisions, no enforcement point, nothing in line that can slow an agent down or break it. - **Accepted is not acceptable**: accepted is an act somebody performs; acceptable is the level at which the business stops funding remediation; they are orthogonal, giving four real states. - **The foundation: SG/Vault**: a semantic graph on a zero-knowledge vault — PKI, provenance, no database — that is agentic-native rather than agentic-retrofitted; you hold the keys. - **Positioning**: the wedge is agentic risk and the renewal conversation; complementary to GRC, identity and posture tooling rather than a replacement for any of them. ## Pages Each is a plain HTML document at its own URL, with a markdown twin at the same path. Anything a page renders at runtime from data — the demo cards, the library, the scenarios — is in the page, not the twin. - [RiskMandate — the insurability layer for agentic AI](https://riskmandate.ai/) · [md](https://riskmandate.ai/index.md): Carriers are filing to exclude AI. RiskMandate measures what your agents can actually reach, evidences the controls, prices the exposure, and produces the record an underwriter will accept. Read-only, never in the request path. - [RiskMandate — Who can pull the plug?](https://riskmandate.ai/plug.html) · [md](https://riskmandate.ai/plug.md): Every board asks it in a sentence: if this agent starts doing something no one intended, who stops it, how fast, and what does stopping it cost? The plug profile is the mandate read backwards — who, blast radius, speed, side effects, and the one dimension money cannot buy back: recoverability. - [RiskMandate — Accepted is not acceptable](https://riskmandate.ai/acceptable.html) · [md](https://riskmandate.ai/acceptable.md): Accepted is an act: somebody with standing says they carry the risk. Acceptable is a threshold: the point where the business stops funding remediation. They are orthogonal, not sequential — which gives four real states, each needing a different action. And the EU AI Act mandates the judgement without defining the word. - [Risk Mandate — agents act, and someone has to own the risk](https://riskmandate.ai/acceptance.html) · [md](https://riskmandate.ai/acceptance.md): Risk Mandate begins where security stops — acceptance, funding, and ownership. No risk can be denied, only accepted for an interval and underwritten to the board. - [RiskMandate — Know the risk. Name the owner. Own the mandate.](https://riskmandate.ai/grant-gap.html) · [md](https://riskmandate.ai/grant-gap.md): Every exception, approval, and agent action becomes a mandate with an owner, a blast radius, and an expiry date. RiskMandate defines the mandate and maps the gap between it and the grant — the excess authority nobody accepted. Never in the request path. - [RiskMandate — How it works](https://riskmandate.ai/how-it-works.html) · [md](https://riskmandate.ai/how-it-works.md): Authorisation is whatever the agent can already do — the union of every route to a capability, conferred long before request time. So we model rather than intercept: read-only digital twins instead of integrations, the RiskGraph, and engines that compute the profile. Never in the request path. - [RiskMandate — For Agents](https://riskmandate.ai/agents.html) · [md](https://riskmandate.ai/agents.md): Machine-readable access to RiskMandate's content: llms.txt, a full-text markdown export, and a structured agent-content manifest. A product about governing agent access, publishing a clean one. - [RiskMandate — RAMM, the Risk Acceptance Maturity Model](https://riskmandate.ai/ramm.html) · [md](https://riskmandate.ai/ramm.md): RAMM is a graph-native maturity model for risk acceptance. It models acceptance as a durable decision node linked to evidence, ownership, authority, appetite, and review — so maturity is computed from the graph, not asserted in a questionnaire. Five levels, each a testable path-pattern. - [RiskMandate — How long will you accept this risk?](https://riskmandate.ai/scenarios.html) · [md](https://riskmandate.ai/scenarios.md): Four situations you'd refuse on instinct — each already accepted the moment an agent runs. The only real question is the interval. - [RiskMandate — The post images](https://riskmandate.ai/statics.html) · [md](https://riskmandate.ai/statics.md): The 'How long will you accept this risk?' series as static 4:5 artboards, ready to screenshot and post. Same scenarios as the interactive cards, one renderer apart. - [RiskMandate — Live demos](https://riskmandate.ai/demos.html) · [md](https://riskmandate.ai/demos.md): Three working demonstrations of the RiskMandate approach, each a real encrypted vault opened with a deliberately published read-only key, running natively in this page: the RiskGraph Explorer, Agentic Browser Isolation, and the RiskMandate field demo. - [RiskMandate — Licence to Operate, live](https://riskmandate.ai/demo-licence-to-operate.html) · [md](https://riskmandate.ai/demo-licence-to-operate.md): An insurance policy for an agent, simulated: the grant, the mandate, and the delta nothing covers. The homepage argument running as something you can operate, opened read-only with a published key. - [RiskMandate — RiskGraph Explorer, live](https://riskmandate.ai/demo-risk-graph-explorer.html) · [md](https://riskmandate.ai/demo-risk-graph-explorer.md): The whole RiskMandate approach in one live vault: answers become facts, facts chain into risks, risks reach the board, and a role accepts what it holds. Seven views over one graph, opened read-only in this page with a published key. - [RiskMandate — Agentic Browser Isolation, live](https://riskmandate.ai/demo-agentic-browser-isolation.html) · [md](https://riskmandate.ai/demo-agentic-browser-isolation.md): A living risk register for one consequential question — does an AI agent browse with your logged-in sessions or an isolated identity? A page per stakeholder altitude and acceptance-gated escalation, live in this page with a published read-only key. - [RiskMandate — the field demo, live](https://riskmandate.ai/demo-risk-mandate-field.html) · [md](https://riskmandate.ai/demo-risk-mandate-field.md): Eight questions to a risk register, built to be handed to a stranger on an iPad — and an app that uses an LLM without ever holding the API key. Live in this page with a published read-only key. - [RiskMandate — File security, live](https://riskmandate.ai/demo-file-security.html) · [md](https://riskmandate.ai/demo-file-security.md): An eleven-step risk-acceptance walk over a file-security estate, running SQLite in the browser. The workflow somebody actually moves through, rather than the model behind it. - [RiskMandate — Agent permission games, live](https://riskmandate.ai/demo-agent-permission-games.html) · [md](https://riskmandate.ai/demo-agent-permission-games.md): Two games about grants and mandates. Five minutes, forty questions, no sign-up: guess what your agent can reach, then find out. The only demo here that sends data — it keeps a leaderboard. - [RiskMandate — Pricing](https://riskmandate.ai/pricing.html) · [md](https://riskmandate.ai/pricing.md): Every RiskMandate tier runs the same product on the same zero-knowledge foundation. What changes per tier is how it's operated — maintainability, scalability, and security posture — not which features are gated. - [RiskMandate — Library](https://riskmandate.ai/library.html) · [md](https://riskmandate.ai/library.md): The concepts and the approach behind autonomous risk management. - [RiskMandate — Partners](https://riskmandate.ai/partners.html) · [md](https://riskmandate.ai/partners.md): RiskMandate is the risk-acceptance and accountability layer for the agent-detection ecosystem. We complement detection and remediation — we don't compete with them. - [RiskMandate — Give feedback after a demo](https://riskmandate.ai/feedback.html) · [md](https://riskmandate.ai/feedback.md): Saw a RiskMandate demo? ChatGPT will interview you by voice while it is fresh, produce an evidence pack you review and control, and you send it back. Not a survey — a conversation that becomes evidence. - [RiskMandate — Brand guidelines](https://riskmandate.ai/brand.html) · [md](https://riskmandate.ai/brand.md): The RiskMandate mark, colour tokens, typography and downloadable brand assets. The mark is a seal: it signals counter-signature and provenance to underwriters, risk committees and boards. - [RiskMandate — version record](https://riskmandate.ai/versions.html) · [md](https://riskmandate.ai/versions.md): Every version of the RiskMandate site, what changed in it, and the file that record lives in. - [RiskMandate — Design options (internal)](https://riskmandate.ai/design-options.html) · [md](https://riskmandate.ai/design-options.md): The eight logo concepts explored for RiskMandate, preserved as a design record with the reasoning for and against each. Concept E, the Seal, was selected. ## Machine-readable - [Full text](https://riskmandate.ai/llms-full.txt): the entire site as one markdown document - [Content manifest](https://riskmandate.ai/.well-known/agent-content.json): structured JSON - [Version index](https://riskmandate.ai/versions/index.json): every release, and the file its notes live in