<!-- Generated from paid-t2.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — thank you: level 2, what happens now

After paying for an Agent Behaviour Policy at level 2: what arrives and when, what you do next, how the key reaches you, the definition of done, and who to write to.

Source: https://riskmandate.ai/paid-t2.html

---

# Thank you. Here is what happens now.

You bought an Agent Behaviour Policy at level 2: the pack, plus **keys and history**. Keep the payment receipt; its reference is how you quote this order. The product code is `t2`.

Your order reference **on your payment receipt** · product code **t2**

## A working vault. We follow up within 24 hours of the payment landing.

A vault of the shape you picked, with the same files as the pack and, on top of them, its history, its own app, and a licence file carrying your name and no public key. You hold the keys: clone it, change the mandate, commit, and every version is kept. Hand anybody who asks how you govern the agent a read key; keep the vault key.

## Nothing. It is on its way.

Nothing until the key arrives. Then open the vault once with it — that first open is how you and we both know it is yours — and read `MANDATE.md`. Correcting the mandate is yours to do at this level; the vault recomputes the delta when you commit.

## Separately. Never on this page.

The vault key arrives out of band — by a separate message to the address you paid with — and never on this page. This page is a committed file, and a vault key is never committed to anything, by rule. A read key you may publish; the vault key you may not.

- **The read key** is the one you may hand to anybody who asks how you govern the agent. It opens the vault read-only. It is derived one way from the vault key and cannot be turned back into it.
- **The vault key** is write access and the whole of your ownership. It arrives by a separate message, it is yours to keep, and nobody at RiskMandate needs it back.

## Done is a commit. You can check it.

**This level is done when:** A vault exists, the licence file in it carries your name, the public key is off it, and you have opened it with your key.

**Checked by:** Your first clone: the licence file is in the tree with your name on it, and the history starts with the commit that put it there. You do not have to take anybody's word for it.

## Write to a person. Not a form.

If nobody has followed up within 24 hours, email [nrparekh@gmail.com](mailto:nrparekh@gmail.com?subject=Level%202%20%C2%B7%20order%20%5Byour%20reference%5D%20%C2%B7%20nothing%20arrived) with your order reference and the product code `t2`. A person reads it.
