| S01 | G0 | Decide to propose the ABP to OWASP, with RiskMandate as sponsor | Dinis Cruz, Nimay Parekh | 2026-10-08 | Done | Voice note D30 link |
| S02 | G0 | Commission the initiation brief: charter, boundary, inventory, gates | Dinis Cruz | 2026-10-08 | Done | Brief D31, written with Perplexity link |
| S03 | G0 | Publish this section and the record on the public site and in the public repository | the website agent | 2026-10-08 | Done | The lead asked for it public: "this should go on the public website the public Git repo" |
| S04 | G1 | Inventory every asset: source, licence, proposed action, coupling | the website agent | 2026-10-08 | Done | 82 rows link |
| S05 | G1 | Check the rights on each contribute and rewrite row, and the licence file of the abp.sgit.ai repository | Dinis Cruz | | To do | A footer is not proof of rights |
| S06 | G1 | Add a CC BY 4.0 licence file to this repository and to the abp.sgit.ai repository | Dinis Cruz | | To do | None exists; the footers say CC BY 4.0 |
| S07 | G1 | RiskMandate, as a company, agrees in writing to contribute the approved assets | Nimay Parekh | | To do | Paid copies name the copyright as RiskMandate's |
| S08 | G1 | Ask the early beta user whose agent measured the n8n vault, and the three people behind the abp.sgit.ai cases, whether their material may move | Dinis Cruz | | To do | Deferred until they agree in writing |
| S09 | G2 | Decide the name: Agent Behaviour Policies, as in the brief, or the wording in the voice note | Dinis Cruz | | Waiting | Open question Q1 |
| S10 | G2 | Decide the home: a standalone project, or an initiative inside the GenAI Security Project | the leads, after talking to the GenAI project's leaders | | To do | Both set out on the application page link |
| S11 | G2 | Find a third leader from outside RiskMandate | the leads | | To do | Two leaders from one company is the pattern the research says to avoid |
| S12 | G2 | Confirm both leaders' OWASP membership is current | Dinis Cruz, Nimay Parekh | | To do | Stated by the lead; not checked against OWASP's records |
| S13 | G2 | Find and fix the public pages that describe the delta's storage differently | the website agent | | To do | The brief reports a contradiction; the model says derived, stored with both inputs, never edited |
| S24 | G2 | Read the agent projects OWASP started in 2025 and 2026 (Agent Observability Standard, Agent Skills Security Standard, the MCP projects and others) and write one line on each: what it covers, and whether it records a mandate or a delta | the website agent | | To do | The form asks how the project meets a need no existing project meets link |
| S25 | G2 | Settle the name against the committee's vendor-neutrality good practice: RiskMandate sells Agent Behaviour Policies today | Dinis Cruz, Nimay Parekh | | Waiting | Q1 |
| S14 | G3 | Approve the email to the projects team and the GenAI project, and its recipients | the leads | | Waiting | Drafted on the application page link |
| S15 | G3 | Approve every field of the application | the leads | | Waiting | Drafted on the application page link |
| S16 | G3 | Send the email; submit the application through OWASP's channel | Dinis Cruz | | Blocked | Blocked on S14 and S15 |
| S17 | G4 | OWASP gives admin access to a new repository in its GitHub organisation and an invitation to manage the project's page on owasp.org; within 30 days the leads create the page (leaders with owasp.org emails, pitch, level, type, licence), add the licence and enable the DCO check | OWASP staff, then the leads | | To do | After acceptance |
| S18 | G4 | Create the specification repository with README, LICENSE, GOVERNANCE, CONTRIBUTING, SECURITY and the proposed tree | the leads | | To do | Proposed tree on the application page link |
| S19 | G4 | Move the approved assets with their provenance: source, date, commit | the leads | | To do | Not a find-and-replace |
| S20 | G4 | Point abp.sgit.ai and this site's model pages at the project as the source; nothing taken down | the website agent, with the lead's approval | | To do | Only after the project's repository exists |
| S21 | G2 | Write the JSON Schemas for the grant, the mandate and the delta | to be assigned | | To do | No schema file exists today |
| S22 | G2 | Run the integration experiment: one synthetic deployment, one restriction (approval before external email), ACS as the enforcement, with positive, negative, bypass and outage tests | to be assigned | | To do | Only on a system we are entitled to run; no conformance claimed |
| S23 | G2 | Add OWASP mappings to the template vaults: Agentic Top 10 and LLM Top 10 items, by id and title | the website agent | | To do | The vaults map ATT&CK, the EU AI Act and GDPR today, and no OWASP list |