RiskMandate v1.38.0
OWASP · The tracker

Every step, every submission, every answer.

The state of the move, kept in public. What has been done, what is being done, what waits on whom; what was sent, to whom, through which channel, on which date, and what came back. The people we need to talk to and why. The decisions taken and the questions still open. A line changes when the thing happens, not when somebody means it to.

As at: 8 October 2026. Where it stands: preparing the application; nothing sent to OWASP

The record: project.json. Every table on this page is rendered from it.

01 · The gates

Five approvals, each a named person’s.

G0

Scope

The objectives, and what agents may read and draft.

Who clears it: Dinis Cruz

Done
G1

Contribution rights

The asset manifest: every row's rights checked, nothing confidential left.

Who clears it: The leads, and RiskMandate as a company

To do
G2

Technical scope

Terminology, boundaries and limitations accepted.

Who clears it: The leads, and a reviewer outside RiskMandate

To do
G3

Outreach and application

The exact recipients, the email text and every field of the application.

Who clears it: The leads

Waiting
G4

Publication and migration

The repository target, the licences and the contribution set.

Who clears it: The leads, after OWASP accepts

To do
02 · The steps

The plan, two weeks to an application and a year after it.

The lead’s aim is an OWASP project the two founders lead within a couple of weeks of 8 October. The steps to the application are sized for that; the steps after it are OWASP’s pace, not ours.

Done

4 of 25 steps

Happened, and the record says where.

Doing

0 of 25 steps

Somebody is on it now.

To do

16 of 25 steps

Planned; nobody has started.

Waiting

4 of 25 steps

Ready, and waiting on a named person's approval or answer.

StepGateWhatWhoWhenStatusNotes
S01G0Decide to propose the ABP to OWASP, with RiskMandate as sponsorDinis Cruz, Nimay Parekh2026-10-08DoneVoice note D30 link
S02G0Commission the initiation brief: charter, boundary, inventory, gatesDinis Cruz2026-10-08DoneBrief D31, written with Perplexity link
S03G0Publish this section and the record on the public site and in the public repositorythe website agent2026-10-08DoneThe lead asked for it public: "this should go on the public website the public Git repo"
S04G1Inventory every asset: source, licence, proposed action, couplingthe website agent2026-10-08Done82 rows link
S05G1Check the rights on each contribute and rewrite row, and the licence file of the abp.sgit.ai repositoryDinis CruzTo doA footer is not proof of rights
S06G1Add a CC BY 4.0 licence file to this repository and to the abp.sgit.ai repositoryDinis CruzTo doNone exists; the footers say CC BY 4.0
S07G1RiskMandate, as a company, agrees in writing to contribute the approved assetsNimay ParekhTo doPaid copies name the copyright as RiskMandate's
S08G1Ask the early beta user whose agent measured the n8n vault, and the three people behind the abp.sgit.ai cases, whether their material may moveDinis CruzTo doDeferred until they agree in writing
S09G2Decide the name: Agent Behaviour Policies, as in the brief, or the wording in the voice noteDinis CruzWaitingOpen question Q1
S10G2Decide the home: a standalone project, or an initiative inside the GenAI Security Projectthe leads, after talking to the GenAI project's leadersTo doBoth set out on the application page link
S11G2Find a third leader from outside RiskMandatethe leadsTo doTwo leaders from one company is the pattern the research says to avoid
S12G2Confirm both leaders' OWASP membership is currentDinis Cruz, Nimay ParekhTo doStated by the lead; not checked against OWASP's records
S13G2Find and fix the public pages that describe the delta's storage differentlythe website agentTo doThe brief reports a contradiction; the model says derived, stored with both inputs, never edited
S24G2Read the agent projects OWASP started in 2025 and 2026 (Agent Observability Standard, Agent Skills Security Standard, the MCP projects and others) and write one line on each: what it covers, and whether it records a mandate or a deltathe website agentTo doThe form asks how the project meets a need no existing project meets link
S25G2Settle the name against the committee's vendor-neutrality good practice: RiskMandate sells Agent Behaviour Policies todayDinis Cruz, Nimay ParekhWaitingQ1
S14G3Approve the email to the projects team and the GenAI project, and its recipientsthe leadsWaitingDrafted on the application page link
S15G3Approve every field of the applicationthe leadsWaitingDrafted on the application page link
S16G3Send the email; submit the application through OWASP's channelDinis CruzBlockedBlocked on S14 and S15
S17G4OWASP gives admin access to a new repository in its GitHub organisation and an invitation to manage the project's page on owasp.org; within 30 days the leads create the page (leaders with owasp.org emails, pitch, level, type, licence), add the licence and enable the DCO checkOWASP staff, then the leadsTo doAfter acceptance
S18G4Create the specification repository with README, LICENSE, GOVERNANCE, CONTRIBUTING, SECURITY and the proposed treethe leadsTo doProposed tree on the application page link
S19G4Move the approved assets with their provenance: source, date, committhe leadsTo doNot a find-and-replace
S20G4Point abp.sgit.ai and this site's model pages at the project as the source; nothing taken downthe website agent, with the lead's approvalTo doOnly after the project's repository exists
S21G2Write the JSON Schemas for the grant, the mandate and the deltato be assignedTo doNo schema file exists today
S22G2Run the integration experiment: one synthetic deployment, one restriction (approval before external email), ACS as the enforcement, with positive, negative, bypass and outage teststo be assignedTo doOnly on a system we are entitled to run; no conformance claimed
S23G2Add OWASP mappings to the template vaults: Agentic Top 10 and LLM Top 10 items, by id and titlethe website agentTo doThe vaults map ATT&CK, the EU AI Act and GDPR today, and no OWASP list
03 · Submissions

What we sent, and what came back.

Each row is drafted here before it is sent, and says not sent until it has been. The draft is linked; the answer is quoted in a short phrase and dated when it arrives.

IdWhatToChannelSentStatusAnswer
M01Email introducing the proposal and asking which home fits · the draftOWASP Project Committee (project-committee@owasp.org); co-leads of the GenAI Security Project's Agentic Security Initiativeemailnot sentDrafted—
M02New project application · the draftOWASP FoundationNew Project Request, OWASP service desk (login needed)not sentDrafted—
M03Note to the Agent Control Standard maintainers on the overlap, and the integration experiment · the draftACS maintainersGitHub discussion or the GenAI Slacknot sentDrafted—
04 · Who we talk to

The people and the channels, from OWASP’s own pages.

Names and roles as OWASP’s pages gave them on the date read. Confirmed says whether that is from a page read in full or still to check. Nobody on this list has been contacted.

WhoRoleWhy we talk to themHowConfirmed
OWASP Project CommitteeReviews new-project requests and promotions; meets monthlyThey decide on the request. First recipient of the email (M01)project-committee@owasp.org · Slack #project-new-projectsYes: the committee's page, read 8 Oct 2026
Bjoern KimminichProject Committee chairChairs the reviewthrough the committee's group addressNamed in the committee's leaders file; when it was last edited is unchecked
Jeff Foley, Donnie BrownProject Committee vice chair and secretaryThe committee's officersthrough the committee's group addressAs above
Jason Gillam, Michael Bargury, Jim ManicoProject Committee membersPossible reviewers. Michael Bargury is also a creator of the Agent Control Standard: the overlap is raised by us, in the requestthrough the committee's group addressAs above
Steve SpringettGlobal Board liaison to the Project CommitteeThe board's view, if the home question goes that farthrough the committee's group addressAs above
Starr BrownDirector of Open Source Projects and Programs; staff liaison to the Project CommitteeThe staff side of the request: forms, repository, page, shared resourcesOWASP staff pageYes: the staff page, read 8 Oct 2026
Andrew van der StockExecutive Director; author of the September 2026 project guidesThe guides' author, if a step in them is unclearOWASP staff pageYes: the staff page and the guide, read 8 Oct 2026
John Sotiropoulos, Ron F. Del RosarioCo-leads, Agentic Security Initiative, GenAI Security ProjectThe initiative ACS and the Agentic Top 10 sit in. Second recipient of the email (M01)Slack #team-genai-agentic-security-initiative; open meeting TuesdaysYes: the initiative's page, read 8 Oct 2026
Scott Clinton, Steve WilsonCo-chairs, GenAI Security ProjectIf the home is an initiative inside GenAI, its board and core team vote it inGenAI Security ProjectYes: owasp.org's project record and genai.owasp.org, read 8 Oct 2026
Rock Lambros, Ariel Fogel, Bar Kaduri; Michael Bargury, Ory SegalProject leads and creators, Agent Control StandardThe overlap note and the experiment (M03)the ACS repositoryYes: ACS's GOVERNANCE.md, read 8 Oct 2026
OWASP supportThe general service deskIf a form or a link does not worksupport@owasp.org · contact.owasp.orgYes: owasp.org/contact, read 8 Oct 2026
05 · Where everything lives

Repositories, sites and records, and who manages each.

WhatWhere it livesWho manages itSide
The model, vocabulary and documentation packabp.sgit.ai (v0.12.1)Dinis Cruztoday: sgit, CC BY 4.0; proposed: the OWASP project
The sixteen template ABPs and the delta buildgithub.com/Risk-Mandate/riskmandate.ai, site/vaults/the website agent, for the leadstoday: RiskMandate; proposed: the OWASP project, as examples and the reference tool
This section and its recordriskmandate.ai/owasp/ and site/owasp/project.jsonthe website agent, for the leadsRiskMandate, until the project's repository exists
The OWASP graphriskmandate.ai/owasp-graph.html and business-case/owasp/graph.jsonthe website agentRiskMandate; offered to OWASP
The project pageowasp.org/projects/<slug>, edited in OWASP's admin portal (the new site, September 2026); or a www-project repository, as the draft handbook still describesOWASP staff create it; the leads maintain itOWASP, after acceptance
The specification, schemas, examples and toolsa repository under github.com/OWASP (proposed)the project's leaders and contributorsOWASP, after acceptance
Commercial services, the store, the Index, reviewsriskmandate.ai, store.sgit.aiRiskMandateRiskMandate, always
Customer data and customer vaultsprivate vaults, never in a public repositoryRiskMandateRiskMandate, always
06 · Decisions

What has been decided, by whom.

IdDecidedByDate
K01Propose the Agent Behaviour Policy to OWASP as an open project, with RiskMandate as sponsorDinis Cruz, Nimay Parekh8 October 2026
K02Keep the whole move in public: this section on the public site, the record in the public repositoryDinis Cruz8 October 2026
K03RiskMandate commercialises on the method as anybody else could, and proposes its commercial model as one others can followDinis Cruz8 October 2026
K04Nothing external without approval: every email, form, repository and licence change waits on its gateDinis Cruz (brief D31)8 October 2026
07 · Open questions

What is not decided, and what it holds up.

IdOpen questionWho answersBlocks
Q1The name. Agent Behaviour Policies, or 'application behaviour policies' as the voice note says? And since OWASP's good practices ask that a project's name not be confused with a company's commercial service, does RiskMandate rename what it sells, or does the project take another name?Dinis CruzS15
Q2A standalone project, or an initiative inside the GenAI Security Project?the leads, with the GenAI project's leadersS15
Q3Who is the third leader, from outside RiskMandate?the leads
Q4Documents under CC BY 4.0, as today, or CC BY-SA 4.0, as many OWASP projects use?the leadsS18
Q5Does 'grant' stay the word for measured reach, given that it reads as authorisation in ordinary English?the project, in public
Q6How do the four barrier kinds sit with a richer control model (preventive, approval, detective, corrective; failure behaviour; bypass paths)?the project, in public
Q7Does abp.sgit.ai become the project's reading site under OWASP branding, or does the project read only from its repository?the leads, with OWASPS20
Q8Which three examples will a reviewer outside RiskMandate rebuild from their inputs first?the leads
Q9Which New Project Request form is current? The Project Policy and the September 2026 guide link to different onesOWASP, asked in M01S16
Q10Does a new project get a www-project repository, or only a page in the new admin portal and a code repository?OWASP, asked in M01S17
08 · The log

What happened, newest first.

DateWhat happenedWhere
8 October 2026OWASP's process read: the September 2026 guide, the Project Policy, the committee's page, the staff page, the GenAI project's governance and the ACS repository. The form is behind a login; two OWASP pages link to different formslink
8 October 2026OWASP's Project Policy, twelve OWASP projects and our own published material read; the inventory, the charter and this section publishedlink
8 October 2026The founders decide to propose the Agent Behaviour Policies to OWASP; voice note D30 and initiation brief D31 arrivelink
24 September 2026The lead asks for OWASP first: a semantic graph of OWASP, business cases for its projects, and the intent to move RiskMandate's ideas and standards to OWASP (D17)link
Next

Something here is wrong or out of date?

Say so. A tracker that lags reality is worse than none, and the correction is the point.