RiskMandate v1.38.0
OWASP · What moves

Eighty-two assets, each decided on its own row.

The contribution inventory: everything RiskMandate and the sgit sites have published about the Agent Behaviour Policy, where it lives, what licence it says it carries, and whether we propose to contribute it, rewrite it first, defer it, or keep it out. A footer is not proof of rights, so every row is unresolved until somebody has checked it.

As at: 8 October 2026. Where it stands: preparing the application; nothing sent to OWASP

The file: contribution-inventory.csv, the source of the tables below. Read on 8 October 2026 from this repository and from the sgit sites with a plain HTTP fetch.

01 · The count

Four answers, and none of them is final.

contribute

31 of 82 assets

Moves as it is, once its rights are checked.

rewrite

13 of 82 assets

The idea moves; the text is rewritten for a neutral reader first.

defer

11 of 82 assets

Not now: it needs somebody's consent, or it is not the ABP.

exclude

27 of 82 assets

Stays with RiskMandate: commercial, confidential, personal or infrastructure.

02 · What we learned making it

The material to move is mostly on abp.sgit.ai.

  • The model lives at abp.sgit.ai, version 0.12.1. Its vocabulary is one JSON pack at abp.sgit.ai/data/index.json, stated CC BY 4.0: 23 capabilities, 4 barriers, 3 undo classes, 17 profiles, 16 mandates and 18 stored deltas. It has 81 model pages, a seven-part documentation pack including the hard rules and the measuring prompt, five worked examples and 23 version notes. That, not the copies in this repository, is what the project should start from.
  • The vaults here are pinned at 0.3.0, copied on 15 September. They are the sixteen template examples. Every one is at status template; rows are measured on the thing itself in two (claude-gmail-connector, 4 of 6; n8n-owner-api-key, 7 of 8) and observed in two more (claude-code-web, github-actions). The rest are documented from vendor pages or derived.
  • There is no JSON Schema file. abp/profile/v1 and abp/mandate/v1 exist as type values in the data. Writing the schemas is new work, and the first deliverable of the specification.
  • The delta build in scripts/site/build-abp-vault.mjs recomputes the delta from the grant and the mandate and refuses to build if it disagrees with the published one. Its core is the reference tool; the licence assembly and the store and sgit coupling come out first.
  • There is no OWASP mapping in any vault. The standards graphs in the vaults cover ATT&CK, the EU AI Act and GDPR. The OWASP material that exists is on this site: OWASP, as a graph, 181 nodes and 62 edges read from OWASP’s pages on 24 September, already marked as offered to OWASP to take.
  • The “stuff on sgit to move” the lead mentioned is the model, the data, the documentation pack and the examples on abp.sgit.ai. There is no /owasp/ page there (it returns 404). risks.sgit.ai maps to SAMM, ASVS, WSTG and Threat Dragon, but it is a maturity scale with levels, so it stays out of a project that never scores.
03 · Rights, before anything moves

What the licences say, and what they do not prove.

FindingWhat it meansWho decides
Code here is Apache-2.0, in the root LICENSEAcceptable to OWASP as it is—
Pages and template ABPs say CC BY 4.0, in the footer and in each vault’s generated LICENCE.md; abp.sgit.ai, risks.sgit.ai and standards.sgit.ai say the sameAcceptable to OWASP (a Creative Commons licence). But no CC BY licence file exists in the repository; one is added before transferThe leads
Paid copies of a vault carry a commercial licence that names the copyright as RiskMandate’sThe contribution needs the company’s sign-off, not one person’s. The commercial licence text itself stays outRiskMandate, as a company
The n8n measurement was made by an early beta user’s agent; three cases on abp.sgit.ai are real people’s estatesDeferred until those people agree, in writingThe people concerned
The abp.sgit.ai source repository, SGit-AI/SGit-AI__Website__ABP, was not readable from this sessionIts licence file is unchecked. A row from it stays unresolved until somebody reads itThe leads
Vendor marks in logos.json; vendors’ product names throughoutLogos stay out. Names stay, as facts, under rule five: no verdict on a named third party—
Much of the text was drafted by agentsThe brief’s rule: do not assume agent-generated content is free of third-party material. Quotes are short and sourced by design; each moved document is read once more for thatThe reviewer of each asset
OWASP projects often use CC BY-SA 4.0 for documentsCC BY 4.0 is permitted. Moving to BY-SA is a choice, not a requirementThe leads
04 · Every asset

The inventory, by proposed action.

Ids: A abp.sgit.ai and the other sgit sites, R the schemas and vocabulary here, V the vaults, S scripts and tests, D documents, P pages, O OWASP material already here, X what stays with RiskMandate.

Contribute 31

IdAssetWhere it is nowTypeLicence todayCouplingRightsNotes
A01The ABP model (four objects, grammar, barrier, delta, graph rules)https://abp.sgit.ai/model/abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)specificationCC BY 4.0 (page footer; data/index.json)lowunresolvedCanonical source; supersedes repo copies. Repo licence of SGit-AI__Website__ABP not verified (GitHub not attached to session)
A02Published vocabulary pack abp/pack/v1 v0.12.1https://abp.sgit.ai/data/index.json (+ capabilities.json, barriers.json, undo-classes.json, evidence-tiers.json)abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)data/vocabularyCC BY 4.0 (stated in pack)noneunresolvedCore of an OWASP project. Pack says no score anywhere
A03Published profiles, mandates, stored deltas, graph, lexicon, bridgeshttps://abp.sgit.ai/data/{profiles,mandates,deltas,graph,lexicon,bridges,universes,gaps,facts}/abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)dataCC BY 4.0lowunresolvedCheck bridges for third-party standard text (rule 7)
A04RiskMandate-contributed shapes (8 shapes, 42 rows)https://abp.sgit.ai/data/contributed/riskmandate/manifest.jsonabp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)dataCC BY 4.0lowunresolvedSame material as repo vaults; contribute once, from one place
A05Foundation document: What is an Agent Behaviour Policyhttps://abp.sgit.ai/what-is-an-abp/ ; https://abp.sgit.ai/docs/briefs/v0.33.70__foundation__...abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)documentationCC BY 4.0lowunresolvedNatural OWASP project charter text
A06Docs pack (start here, what to build, conventions, model, first examples, hard rules, the prompt)https://abp.sgit.ai/docs/pack/00__START-HERE ... 06__THE-PROMPTabp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)documentationCC BY 4.0lowunresolvedHard rules map to repo CLAUDE.md rules 1-8
A08Worked examples: browser extension, ChatGPT web, Claude Code CLI on/off, GitHub Actionshttps://abp.sgit.ai/examples/ (5 examples)abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)examplesCC BY 4.0lowunresolvedVendor-named; facts and dates only
A09Guided flows: Gmail, cost policy, desktophttps://abp.sgit.ai/gmail/ ; /cost/ ; /desktop/abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)documentationCC BY 4.0lowunresolvedCost flow may lean on pricing language; review
A12Model release historyhttps://abp.sgit.ai/versions/ (23)abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)changelogCC BY 4.0noneunresolvedKeep as provenance of the vocabulary
V01Template ABP vault: browser-extensionsite/vaults/browser-extension/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V02Template ABP vault: chatgpt-website/vaults/chatgpt-web/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V03Template ABP vault: claude-code-clisite/vaults/claude-code-cli/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V04Template ABP vault: claude-code-cli-confirmations-offsite/vaults/claude-code-cli-confirmations-off/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V05Template ABP vault: claude-code-website/vaults/claude-code-web/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V06Template ABP vault: claude-desktopsite/vaults/claude-desktop/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V07Template ABP vault: claude-gmail-connectorsite/vaults/claude-gmail-connector/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip; only vault with a licence block in vault.json (kind cc-by-4.0, points to store ledger)
V08Template ABP vault: claude-m365-connectorsite/vaults/claude-m365-connector/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V09Template ABP vault: claude-web-connectorssite/vaults/claude-web-connectors/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V10Template ABP vault: dropbox-mcpsite/vaults/dropbox-mcp/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V11Template ABP vault: github-actionssite/vaults/github-actions/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V12Template ABP vault: gmail-readonlysite/vaults/gmail-readonly/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V13Template ABP vault: google-drive-readonlysite/vaults/google-drive-readonly/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V14Template ABP vault: google-workspace-mcpsite/vaults/google-workspace-mcp/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V15Template ABP vault: n8n-owner-api-keysite/vaults/n8n-owner-api-key/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip; measured on a sandbox by an early beta user's agent: confirm consent
V16Template ABP vault: scheduled-jobsite/vaults/scheduled-job/Risk-Mandate/riskmandate.aitemplate ABP (vault)CC BY 4.0 (LICENCE.md, generated)lowunresolvedstatus=template; vocabulary v0.3.0; as_at 2026-09-15/16. Contribute data/ (grant, mandate, delta, scenarios, consequences, assets, barrier-holders) + the .md documents; strip LICENCE.md commercial section, app.link.json/read key, dist zip
V17Vault template and MAP-A-GRANT promptsite/vaults/_template/ (MAP-A-GRANT.md, AGENTS.md, SKILL.md, data/assets.json, consequences.json, barrier-holders.json, standards/)Risk-Mandate/riskmandate.aitemplate/promptCC BY 4.0lowunresolvedLICENCE.template.md (commercial licence body) excluded; see R10
D02direction__abp-as-a-graph-and-stakeholder-viewsdocs/briefs/direction__abp-as-a-graph-and-stakeholder-views.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)lowunresolvedBehaviours as nodes, barrier per path, views per audience
D04direction__the-grant-has-storeys-and-the-vault-opens-on-the-audiencedocs/briefs/direction__the-grant-has-storeys-and-the-vault-opens-on-the-audience.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)lowunresolvedGrant storeys: credential/client/etc
D09review__first-measured-abp-n8n-owner-keydocs/briefs/review__first-measured-abp-n8n-owner-key.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)lowunresolvedEvidence tiers worked through on a measured grant
D10research__connector-grants-open-questionsdocs/briefs/research__connector-grants-open-questions.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)lowunresolvedResearch method: read, quote, date vendor pages; never test
O01OWASP, as a graphsite/owasp-graph.html ; site/business-case/owasp/graph.jsonRisk-Mandate/riskmandate.aidata + web pageCC BY 4.0; 'Offered to OWASP: take it'lowunresolvedContribute nodes/edges; the bridge is RiskMandate's reading of the RiskGraph model: rewrite as an ABP-primitive mapping or drop. Items titles only (rule 7 ok)

Rewrite 13

IdAssetWhere it is nowTypeLicence todayCouplingRightsNotes
A07Model design briefshttps://abp.sgit.ai/docs/briefs/ (13 briefs v0.4.0-v0.33.71)abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)documentationCC BY 4.0highunresolvedDev/arch briefs contribute; the 4 strategy briefs (insurer, sell the correction, exclusions, consent) are commercial framing: exclude or rewrite
R02Grant schema in use: abp/profile/v1site/vaults/*/data/grant.json (type abp/profile/v1)Risk-Mandate/riskmandate.aischema (implicit)CC BY 4.0lowunresolvedNo standalone JSON Schema file exists; write one for OWASP
R03Mandate schema in use: abp/mandate/v1site/vaults/*/data/mandate.json (type abp/mandate/v1)Risk-Mandate/riskmandate.aischema (implicit)CC BY 4.0lowunresolvedNo standalone JSON Schema file; write one
V18Standards mini-graphs (ATT&CK, EU AI Act, GDPR)site/vaults/_template/data/standards/{attack,eu-ai-act,gdpr}.jsonRisk-Mandate/riskmandate.aidata/mappingCC BY 4.0 (own work); names belong to MITRE/EUlowunresolvedNo OWASP mini-graph exists in vaults: add LLM Top 10 / Agentic Top 10 as a new mini-graph (gap)
V19The ABP reading app (renderer + loader)site/vaults/_app/ (index.html renderer, loader.html, versions/)Risk-Mandate/riskmandate.aicodeApache-2.0highunresolvedTied to sgit/SG Send vault bridge and Licence to Operate (insurance) tab; make host-agnostic or defer
S01Vault generator: derives delta, writes documentsscripts/site/build-abp-vault.mjs (779 lines)Risk-Mandate/riskmandate.aicodeApache-2.0highunresolvedDelta derivation is the contributable core; licence assembly, store links, sgit paths must be stripped
S05Vault app teststests/site/test_vault_app.mjsRisk-Mandate/riskmandate.aitestsApache-2.0highunresolvedPort the delta and no-score/no-write-credential checks
S06Delta conformance check per vaultpackage.json 'check' loop: build-abp-vault.mjs <slug> --checkRisk-Mandate/riskmandate.aiCIApache-2.0lowunresolvedGood CI pattern for an OWASP repo
D01direction__abp-at-the-centredocs/briefs/direction__abp-at-the-centre.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highunresolvedNaming rules and honest-to-say list are portable; selling content is not
D03direction__consequences-assets-and-the-vault-as-a-websitedocs/briefs/direction__consequences-assets-and-the-vault-as-a-website.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)lowunresolvedConsequence layer; standards as mini-graphs
D14ABP model, condensed.claude/onboarding/02-abp-model.mdRisk-Mandate/riskmandate.aidocumentationApache-2.0 repolowunresolvedGood README seed; stale vs v0.12.1
D15The non-optional rules (no score, ABP naming, never test others' systems, no verdict, no conformity language, no standards text, no manufactured assurance)CLAUDE.md rules 1-8Risk-Mandate/riskmandate.aigovernanceApache-2.0noneunresolvedCore of an OWASP project's contribution guide
P01Explainer pages for the ABPsite/abp.html ; site/article-what-is-an-abp.html ; site/grant-gap.html ; site/how-it-works.htmlRisk-Mandate/riskmandate.aiweb pagesCC BY 4.0 (footer)highunresolvedContent good; mixed with store CTAs

Defer 11

IdAssetWhere it is nowTypeLicence todayCouplingRightsNotes
A10Elicited cases of real users' estateshttps://abp.sgit.ai/cases/ (beta-001, session-001, estate-002)abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)case dataCC BY 4.0 (as published)lowunresolvedReal beta users: needs explicit consent before moving to OWASP
A11ABP model articleshttps://abp.sgit.ai/articles/ (16)abp.sgit.ai (repo SGit-AI/SGit-AI__Website__ABP)articlesCC BY 4.0lowunresolvedUseful as project blog/history; review for RiskMandate promotion
A13What can it do? game + upstream capability maphttps://what-can-it-do.games.sgit.ai/what-can-it-do.games.sgit.aiapp/dataCC BY 4.0 (stated in vocabulary README)lowunresolvedGame has a points score for the player (not the ABP) and a Licence to Operate (insurance) page; upstream map itself could contribute
A14RAMM acceptance maturity model with OWASP crosswalkshttps://risks.sgit.ai/ramm/risks.sgit.aispecificationCC BY 4.0 unless statedhighunresolvedNot ABP; carries levels (a maturity scale) so must stay out of an ABP project (rule 1)
A15Standards as addressable provisions (method)https://standards.sgit.ai/standards.sgit.aimethodCC BY 4.0lowunresolvedPossible method for OWASP list mapping; not ABP itself
S04PDF rendering of a vaultscripts/site/render-abp-vault-pdf.mjsRisk-Mandate/riskmandate.aicodeApache-2.0highunresolved
D05direction__one-rule-a-stranger-can-paste-is-the-way-indocs/briefs/direction__one-rule-a-stranger-can-paste-is-the-way-in.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highunresolvedRule base under site/rules/ not yet built
D08architecture__vaults-in-vaults-for-behaviour-policiesdocs/briefs/architecture__vaults-in-vaults-for-behaviour-policies.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highunresolvedsgit-specific delivery
P03RiskMandate's own agents' behaviour policiessite/team/ (publisher.html, studio.html)Risk-Mandate/riskmandate.aiexample ABPsCC BY 4.0highunresolvedReal internal deployment; good dogfood example if lead agrees
P04Lab editions on ABPsite/lab-abp-requests.html ; lab-connector-grants.html ; lab-shape-collector.htmlRisk-Mandate/riskmandate.aiweb pages/researchCC BY 4.0highunresolvedResearch record; RiskMandate-branded
P05Articles and storiessite/article-*.html (8) ; site/stories/ (9)Risk-Mandate/riskmandate.aiarticlesCC BY 4.0highunresolvedAwareness material; RiskMandate voice and CTAs

Exclude 27

IdAssetWhere it is nowTypeLicence todayCouplingRightsNotes
A16OWASP and the summitshttps://open-source.sgit.ai/owasp/index.htmlopen-source.sgit.aihistory/biographyCC BY 4.0noneexcludedPersonal history; not project material
A17Existing OWASP ties: owasp-sbot org (Issues-FS, osbot-utils, MGraph-DB)https://sgit.ai/articles/ ; graphs.sgit.ai llms.txt ; coding.sgit.ai llms.txtsgit.ai / graphs.sgit.ai / coding.sgit.aireferenceApache-2.0 (code)noneexcludedPrecedent only; already OWASP
A18The store (levels, checkout, ledger, commercial licence wording)https://store.sgit.ai/store.sgit.aicommercialproprietary/commercialhighexcludedCommercial
R01Pinned vocabulary copies (v0.3.0)site/vaults/*/data/vocabulary/ (README, capabilities.json, barriers.json, undo-classes.json, evidence-tiers.json)Risk-Mandate/riskmandate.aidata/vocabularyCC BY 4.0noneexcludedDuplicate of A02 at an older version (v0.3.0 vs v0.12.1); contribute from abp.sgit.ai instead
V20Vault catalogue with public read keys (vid, key, endpoint dev.send.sgraph.ai)site/vaults/index.json ; site/vaults/*/app.link.jsonRisk-Mandate/riskmandate.aiinfrastructure/configApache-2.0highexcludedRead keys are public by design but are RiskMandate/sgit infra
V21Published upstream delta for each shapesite/vaults/*/data/upstream/delta.jsonRisk-Mandate/riskmandate.aidataCC BY 4.0noneexcludedDuplicate of A03
S02Site page builder for vault directory and per-vault pagesscripts/site/build-abp-pages.mjs ; scripts/site/abp/abp-vaults.js, abp.cssRisk-Mandate/riskmandate.aicodeApache-2.0highexcludedSite chrome and store links
S03Vendor marks (Simple Icons, CC0)scripts/site/abp/logos.jsonRisk-Mandate/riskmandate.aiassetsCC0 paths; trademarks of vendorsnoneexcludedTrademark use; do not carry into OWASP
D06direction__use-case-driven-policies-and-the-prompt-workflowdocs/briefs/direction__use-case-driven-policies-and-the-prompt-workflow.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highexcludedPricing/store levels
D07direction__mvp-vault-and-the-reading-appdocs/briefs/direction__mvp-vault-and-the-reading-app.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highexcludedDual licence and paid levels
D11review__vault-pages-vs-the-vaultdocs/briefs/review__vault-pages-vs-the-vault.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highexcludedSite-specific
D12workflow__buying-a-policy-for-claude-on-gmaildocs/briefs/workflow__buying-a-policy-for-claude-on-gmail.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highexcludedPurchase workflow
D13workflow__abp-vaults-for-people-we-knowdocs/briefs/workflow__abp-vaults-for-people-we-know.mdRisk-Mandate/riskmandate.aidesign briefApache-2.0 repo (docs not separately licensed)highexcludedPerson vaults; personal data
D16Lead's spoken brief: OWASP and open source firstsite/assets/briefs/2026-09-24__transcript__owasp-and-open-source-first.txt (brief D17)Risk-Mandate/riskmandate.aiinternal briefApache-2.0/CC BY (site)noneexcludedProvenance for the proposal; internal
P02Vault directory and per-vault pagessite/agent-behaviour-policy.html ; site/abp-vault-*.html (16, generated)Risk-Mandate/riskmandate.aiweb pages (generated)CC BY 4.0highexcludedGenerated + buy links; regenerate from data in OWASP
O02Business case: OWASP Corazasite/business-case-owasp-coraza.html ; site/business-case/cases/owasp-coraza.jsonRisk-Mandate/riskmandate.aiweb page + dataCC BY 4.0highexcludedCommercial/insurance framing; could be offered to the Coraza project separately
O03Business case: OWASP Threat Dragon and pytmsite/business-case-owasp-threat-dragon.html ; site/business-case/cases/owasp-threat-dragon.jsonRisk-Mandate/riskmandate.aiweb page + dataCC BY 4.0highexcludedAs O02
O04Business case builder and open-source companies listscripts/site/build-business-cases.mjs ; site/business-case/companies.jsonRisk-Mandate/riskmandate.aicode/dataApache-2.0highexcludedGraph renderer part could be reused for O01
O05Biographical OWASP mentionssite/uk-support.json ; site/reviewers/dinis-cruz.json ; site/about.htmlRisk-Mandate/riskmandate.aireferenceCC BY 4.0noneexcludedBio only
O06Lisbon summit strategy: OWASP bio placeholderdocs/briefs/summit__lisbon-2026-strategy.md (line 182)Risk-Mandate/riskmandate.aibriefApache-2.0noneexcludedNo substantive OWASP content
X01Pricing and paid-level pagessite/pricing.html ; abp-reviewed.html ; reviewers.html ; paid-t1..t4.html ; after-payment.htmlRisk-Mandate/riskmandate.aicommercialCC BY 4.0highexcludedCommercial
X02Insurance product pages and business casessite/insurance.html ; insure-a-program.html ; licence-to-operate.html ; demo-licence-to-operate.html ; acceptable.html ; acceptance.html ; plug.html ; ramm.html ; scenarios.html ; statics.html ; business-case-*.html (18) ; business-cases.htmlRisk-Mandate/riskmandate.aicommercialCC BY 4.0highexcludedInsurance product; RAMM has levels (scores)
X03Commercial licence body for paid copiessite/vaults/_template/LICENCE.template.md ; LICENCE.md commercial sectionsRisk-Mandate/riskmandate.ailegalproprietary termshighexcludedDual-licence mechanism is RiskMandate's
X04Customer instance of a templatevaults-instances/claude-gmail-connector--customer-draft/Risk-Mandate/riskmandate.aicustomer dataprivatehighexcludedCustomer data
X05Stories vault, admin console, agent work filesstories-vault/ ; site/admin/ ; .claude/work ; .claude/agents ; site/briefs-register.jsonRisk-Mandate/riskmandate.aiinternaln/ahighexcludedInternal
X06ABP vaults for people we know (pack)packs/abp-for-people/ ; packs/dist/abp-for-people-pack.zipRisk-Mandate/riskmandate.aitooling + personal dataApache-2.0highexcludedPersonal data and keys workflow
X07Marketing and sales pagessite/early-access.html ; early-adopters.html ; for-*.html ; partners.html ; work*.html ; summit*.html ; interview-*.htmlRisk-Mandate/riskmandate.aicommercialCC BY 4.0highexcluded
Next

What it plugs into, across OWASP.

The projects a behaviour policy points at, and the ones that point back: as risks, as controls, and as formats.