<!-- Generated from paid-t4.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — thank you: level 4, what happens now

After paying for an Agent Behaviour Policy at level 4: what arrives and when, what you do next, how the key reaches you, the definition of done, and who to write to.

Source: https://riskmandate.ai/paid-t4.html

---

# Thank you. Here is what happens now.

You bought an Agent Behaviour Policy at level 4: corrected for your situation, plus **a person**. Keep the payment receipt; its reference is how you quote this order. The product code is `t4`.

Your order reference **on your payment receipt** · product code **t4**

## Two sessions, and a professional signs it. We follow up within 24 hours of the payment landing to book the first session; the vault after the second.

Everything level 3 delivers, built from two half-hour sessions with your team rather than from a form: one to find out what is actually running, one to deliver. The Agent Behaviour Policy is reviewed and signed off by a security professional, the licence carries a name, and the record of what was asked and answered is committed with it.

## Book the first session. Bring the people who know.

The Agent Behaviour Policy at this level is built from the interview rather than from a form, so the first session is where it starts.

- **Book the first session.** Email [nrparekh@gmail.com](mailto:nrparekh@gmail.com?subject=Level%204%20%C2%B7%20book%20the%20first%20session%20%C2%B7%20order%20%5Byour%20reference%5D) with your order reference, two or three half-hour slots that suit your team, and who will be in the room: the people who built the agent, the people who own what it touches, and whoever is accountable for it. We confirm one slot by reply.
- **The first session: what is actually running.** Half an hour. Which agent, where it runs, what it holds, what it was asked to do. We take the record; you correct it as we go.
- **The second session: delivery.** Half an hour, after the vault is built and reviewed. What the grant is, what the mandate says, where the delta sits, what the sign-off covers and what it does not.

## Separately. Never on this page.

The vault key arrives out of band — by a separate message to the address you paid with — and never on this page or in any committed file. A read key you may publish; the vault key you may not.

- **The read key** is the one you may hand to anybody who asks how you govern the agent. It opens the vault read-only. It is derived one way from the vault key and cannot be turned back into it.
- **The vault key** is write access and the whole of your ownership. It arrives by a separate message, it is yours to keep, and nobody at RiskMandate needs it back.

## Done is a commit. You can check it.

**This level is done when:** Both sessions have been held, the record of what was asked and answered is committed, and the sign-off file is committed with the professional's name and the date.

**Checked by:** Three files in the tree, and the sessions dated in the record. You do not have to take anybody's word for it.

## Write to a person. Not a form.

If nobody has followed up within 24 hours, email [nrparekh@gmail.com](mailto:nrparekh@gmail.com?subject=Level%204%20%C2%B7%20order%20%5Byour%20reference%5D%20%C2%B7%20nothing%20arrived) with your order reference and the product code `t4`. A person reads it.
