Does this sit in the request path — can it slow down or break my agents?
No. There are no runtime decisions and no enforcement point. It reads and models; it never intercepts. That is a design property, not a configuration option.
Do I need to integrate it with every system my agents touch?
No. Digital twins model the capability primitives — assets and flows — rather than requiring a live connector to everything underneath. That's what makes broad coverage tractable rather than a multi-year programme.
Who decides what an acceptable plug profile looks like?
You do — and that is the point. The Act requires residual risk to be judged acceptable without ever defining the word, so the threshold is yours to set and yours to evidence. We compute the profile; the line it is measured against is a business decision. See accepted is not acceptable.
How is this different from the risk register we already have?
A register records that a risk exists. A plug profile computes what stopping the agent would cost, attaches a named owner, and expires. The difference shows up the first time someone has to sign one.
What happens to our telemetry?
It's used to test whether our model of your agents is accurate — to find blind spots in the map. It isn't a surveillance layer and it doesn't police traffic.
Can we self-host?
Yes. The core is open source and self-hostable, on a zero-knowledge vault on your own infrastructure — your keys, your data. Enterprise adds sovereign regional deployment.
Where do I read the underlying thinking?
The library has the recorded talks, the full proposition deck, and the long-form pieces — the blast radius, permission granularity, side effects, and risk acceptance. RAMM covers how acceptance maturity is computed, and accepted is not acceptable covers where the line itself comes from.