RiskMandate v1.19.2
Level 3 · Corrected for your situation · £500

Thank you. Here is what happens now.

You bought an Agent Behaviour Policy at level 3: a working vault, plus your situation. Keep the payment receipt; its reference is how you quote this order. The product code is t3.

Your order reference on your payment receipt · product code t3

What arrives, and when

Corrected for your situation. We follow up within 24 hours of the payment landing; the corrected vault follows what the prompt produced.

The vault, with the mandate corrected against your situation rather than against a starting assumption, the delta recomputed with the barrier on every row, and a written note of what was changed and why, committed beside it, so the correction is checkable rather than trusted. A person reviews the note before it is sent.

What this is not. Not a call, and not a signature from a named professional. That is level 4. Nobody interviews you at this level, and nobody needs access to anything of yours: the prompt runs where the agent runs, and what comes back to us is what it wrote.
What you do next

Run the prompt. Send back what it produced.

Nobody interviews you at this level and nobody needs access to anything of yours. The agent that already holds the credential measures its own grant and drafts the mandate in your words; you send us the two files it wrote.

  1. Run the prompt where the agent runs. Every example vault carries it as MAP-A-GRANT.md (the same file in each). Paste it into the session of the agent that holds the credential. It measures what the credential lets it do, in the fixed vocabulary of 23 capabilities and four barriers, and follows seven rules: measure only what you are entitled to run, reversible probes only and clean up, never move a credential, note the door, an error is a symptom not a barrier, say what you did not test, leave the deployment as you found it.
  2. Send us what it wrote. Two files, grant.json and mandate.json, and the session record it kept. Email them to nrparekh@gmail.com with your order reference in the subject. No secret should be in them: the prompt tells the agent to record that it can read a credential, and never to copy one. If one slipped in, remove it before sending; we will ask, not use it.
  3. Then nothing. We build the vault from your files, correct the mandate against your industry, your use case and what you told us, recompute the delta, write the note, and a person reviews it. The key arrives separately; the vault follows.

Where your files go is a mailbox today. A write-only intake link is the intended route and is not yet in use; when it is, this page will say so.

How the key reaches you

Separately. Never on this page.

The vault key arrives out of band — by a separate message to the address you paid with — and never on this page or in any committed file. A read key you may publish; the vault key you may not.

  • The read key is the one you may hand to anybody who asks how you govern the agent. It opens the vault read-only. It is derived one way from the vault key and cannot be turned back into it.
  • The vault key is write access and the whole of your ownership. It arrives by a separate message, it is yours to keep, and nobody at RiskMandate needs it back.
Definition of done

Done is a commit. You can check it.

This level is done when: The corrected mandate and the recomputed delta are committed, and the note of what changed and why is committed beside them.

Checked by: The commit is in the vault's history and the note names every changed row. You do not have to take anybody's word for it.

If it does not arrive

Write to a person. Not a form.

If nobody has followed up within 24 hours, email nrparekh@gmail.com with your order reference and the product code t3. A person reads it.