<!-- Generated from reviewers.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — who runs your review

The people who run the reviewed level of an Agent Behaviour Policy: two sessions with your team and a sign-off with a name and a date. Every line of every record is read off a published page, with the date it was read.

Source: https://riskmandate.ai/reviewers.html

---

# Who runs your review.

The reviewed level is somebody's time rather than a pipeline: two half-hour sessions with your team, a behaviour policy built from what they hear, and a sign-off file committed with their name and the date. This is who does it, what they have done, and where every line of that comes from.

## One name today, and the list is built for more.

Choosing the reviewer is part of buying the reviewed level, and the choice is made on facts rather than on a rating. Nobody here is scored, ranked or starred: what is published is what each of them has done, where they write, what languages they can hold the sessions in, and what they want you to know about their own interests before you weigh what they say.

### Dinis Cruz

Founder of RiskMandate.ai and the sgit.ai network; former OWASP Board member and organiser of the OWASP Summits; creator of the O2 Platform.

### CISO XYZ

One sentence, in the person's own published words where there are any: the role, the organisation and the thing they are known for.

## Nothing on a reviewer's page is written by us.

Every row of every record names the page it was read off and the date it was read, and a reviewer with no published page gets no rows. There are no testimonials on this site yet, because there is no real one to publish: a quote we composed, beside a £1,500 price, would cost more than it could ever earn. When there is one, it will carry a name, a date and permission.

- **What gets published:** what the person has published themselves, cited and dated; and anything they write for us and sign off, marked as theirs.
- **What does not:** a biography we composed, a score, a ranking, a star rating, a queue position, or a claim about somebody else's work.
- **How somebody joins:** they send the page they already publish, the sentence they want at the top in their own words, the languages they can run a session in, and their declaration of interests. We build the page, they correct it, and it goes up when they say so — which is what the placeholder entry on this list is for.

This list is the source of truth for the person who does the work. [reviewers.json](reviewers.json) publishes the same data as a manifest, so the store can build its chooser from it rather than keeping a second copy of a real person's biography. Generated from `site/reviewers/<slug>.json` by `scripts/site/build-reviewer-pages.mjs`.

## Would you put your name on one of these?

The work is two half-hours and a review: an hour with a team that is trying to write down what one agent can actually reach, and your signature on what comes back. If that is a thing you would do, the page above is exactly what would be published about you.
