RiskMandate v1.35.1
The team

Who does what, and what stands in the way.

This site is made by one person and two agents. The agents are described the way the site describes any agent: an Agent Behaviour Policy each, in the same grammar as the catalogue, with the grant measured on the thing itself, the mandate in the lead’s words, the gap derived, and a barrier on every row. Around them, three tiers of information and the workflow that moves a story from private to public.

Nothing here is scored. A count is a count; a barrier is what it is. Where the honest answer is a rule in prose, the page says so.

As at 26 September 2026. If the deployment changes, this page changes; the vaults and the tests that hold it true are listed in section 06.

01 · Who

One person, two agents.

WhoDoesHolds
The leaddinis.human · @DinisDecides: the cast, which story next, what is published, who holds which key. Creates vaults and hands the publisher its credentials in a session. Owns the two decisions on the board and the yes on every story. A person is not profiled. What the lead can do is not a behaviour policy; what the lead has authorised each agent to do is the mandate in each one.the vault keys; the vault host's access token; the platform accounts; the domain.
02 · Three tiers

Public, private, secret.

Everything the team touches is in one of three tiers, and the rule for each is one sentence. The controls under each are named by what they are under the enforcer test: a boundary is enforced by something the agent cannot reach; a setting can be flipped by the account; prose is a rule somebody wrote.

Public

Everything under site/ and docs/ and .claude/ in this repository, because the site is served from site/ and the console renders the rest; the repository itself, open source; the board's ids, titles, owners and states.

Read by anyone. Written by the publisher, through the merge workflow; the lead.

The rule. Nothing goes here that is not meant for everyone. A story reaches here only through the publication workflow below.

What stands in the way
  • the merge command pushes dev only when the check is green (setting)
  • CI runs the same check before the deploy job (setting)
  • the credential test on site/ and on the console (setting)
  • no message file and no message id in site/ (setting)
  • no score, not the acronym with a D, never the policy alone, not the ladder word (settings, tested)
  • the platform's token scope: only this repository (boundary)

Private

The stories vault: every message between the parties, every draft, every picture not yet accepted, every decision not yet taken, the studio's working files and its decision record. The published mirror is the one public thing in it, and it is a copy.

Read by the three parties, and whoever the lead gives the read key to. Written by each party in its own folder; anyone in a mailroom, for its recipient.

The rule. It moves to public only when the lead has accepted it by message and the publisher has read it against the rules. What is said between agents stays in the vault; the board publishes that a request exists, never what it says.

What stands in the way
  • zero-knowledge encryption at the vault host: the server never sees plaintext (boundary)
  • single-writer folders (prose)
  • messages are immutable and only move (prose)
  • one commit per check-in, named, in sgit history log (a record)

Secret

The vault key (it derives the write key), the vault host's access token, the platform's tokens, any credential. Also secret-bearing: a chat or a conversation a secret was pasted into, and the transcript the harness keeps of it.

Read by the lead; an agent for the length of one session. Written by nobody, in a file.

The rule. Never in a file in either tree, never on a page, never in a message. Handed over in a session or set as an environment secret. A secret found in a file is an incident: rotate it first, then find how it got there.

What stands in the way
  • the test that refuses anything write-shaped in site/ and on the console (setting, after the fact)
  • the rule in every brief and in CLAUDE.md (prose)
  • the platform's environment secrets, once used (boundary against the transcript)
  • what is not in place: a token scoped to one vault; a secret scan before a commit; a branch rule on dev at the code host
03 · What flows where

One party touches two tiers, and nothing crosses the red line.

The studio writes into its own folders of the private vault. The publisher pulls the vault, writes the repository, and a push to dev is the public site once the check has passed. The lead hands a key in a session and never in a file. The only thing that goes from the vault to the site without the lead’s yes is the board, and the board carries no message.

SECRETPRIVATEPUBLIC no secret crosses this line The leaddecides; holds every keyhands a key in a sessionnever in a file The studio’s conversationthe vendor keeps itthe token was pasted heresecret-bearing The publisher’s sessionthe platform keeps the transcriptkey and token arrive here, one sessionsecret-bearing The stories vault (encrypted)the studio’s folders: artwork/ stories/ cast/ decisions/mail/: one folder per party, a mailroom each, immutable messagespublished/: the mirror of what is live · board/: derived The publisher (publisher.claude)pulls the vault, reads everythingwrites only its own folder, the mailrooms,published/ and board/checks against the rules; asks; publishes The repositorysite/ docs/ .claude/ · open sourcethe publisher’s branch, then devno branch rule at the host CI40 tests, every --checkthe credential test on site/deploy needs the check green(a setting: the workflow is in the tree) riskmandate.aiserved from site/ on dev/team/ · /stories/ · /admin/the board: ids and titles, no bodies read key, by hand token key + token the studio: files, messages one session pull · push its branch; then dev, after the check push to dev deploy By the enforcer test: the proxy and the token scope are boundaries; the merge command, CI and the tests are settings; the rest is prose. After a publish the publisher copies what is live back into published/, on the pull · push arrow.
Red: secret, handed over in a session and kept by a platform. Gold: private, the encrypted vault. Green: public, the repository, the check and the site. Every arrow is something that happens on a check-in; the mirror back into the vault rides the pull and push arrow.
04 · The surfaces

Every place a thing can live, and its tier.

SurfaceTierWritten byRead by
This repositorythe code hostPublicthe publisher (its branch, then dev), the leadanyone
riskmandate.aiGitHub Pages, from site/ on devPublicCI, on a push to devanyone
The console, /admin/site/admin/, generated from docs/ and .claude/Publicthe buildanyone who has the link; noindex
The boardboard/board.json in the vault, site/stories/board.json on the sitePublicthe publisher, derivedanyone; it carries ids, titles, owners, states
The stories vault dy4u2m9cthe vault host, encryptedPrivateeach party in its own folderthe three parties, the read key's holders
The publisher's session transcriptthe platformSecret-bearingthe harnessthe lead, the agent
The studio's conversationthe vendorSecret-bearingthe vendorthe lead, the agent
Environment secretsthe platform's environmentSecretthe leada session, as variables
05 · From private to public

Seven steps, each with its evidence.

The workflow that makes a story public. The lead accepts; the publisher checks and ships; the studio never publishes. Every step leaves a file somebody else can find.

the studio

Deliver

a picture or a story file in its own folders, with its record; a message to the publisher naming the path

Evidence: the file, the commit, the message in mail/mailroom/publisher.claude/
the publisher

Read against the rules

fictionalised and said so; nobody's product or face; nothing scored; the site's words; every line belongs to the cast; the truth under it is one the site states

Evidence: a note in mail/sessions/publisher.claude/notes.md; a story build that passes
the publisher

Ask

one message to the lead: what it is, where it came from, what goes live if the answer is yes

Evidence: the message in mail/mailroom/dinis.human/; a blocked task on the board
the lead

Accept

yes, no, or what to change, by message or in a session written down as the lead's

Evidence: the message in mail/mailroom/publisher.claude/, or the lead's line quoted in the publisher's notes
the publisher

Publish

the story file and the picture into site/stories/; build; npm run check; a patch release with a note; merge into dev with the check green

Evidence: the release note; the merge commit; CI green
CI

Deploy

the check job, then the deploy job

Evidence: the workflow run; the version chip on every page
the publisher

Mirror back

site/stories/ copied into published/ in the vault; the task closed; the board regenerated; one check-in commit

Evidence: the commit in sgit history log; the board
06 · Controls, checks and tooling

What is in place, and what is not.

The site’s own line applies to the site: a prohibition carries its barrier. Most of what holds this team to its rules is a setting or a sentence, and the three things that would make boundaries of them are listed as not in place, without a verdict.

ToolDoesStatus
scripts/stories/mail.mjsEmail-FS-lite in one file: send, deliver, done, issue, board, status. No network.ours, in place
scripts/site/build-team.mjsthis section from team.json and one file per agent; derives each delta the way the vaults do; refuses a row without a barrier, an evidence tier, an undo class and a note, a mandate that wants and refuses the same row, and any credential-shaped stringours, in place
npm run check40 tests and every generator's check, before every merge and in CI before every deployours, in place
sgitthe encrypted vault: clone, pull, commit, push, historysgraph.ai's, in place
the platform's routinesa scheduled session for the publisher's check-inthe platform's, not yet used
a write token scoped to one vaultwould bound three rows for both agents at onceasked of the sgit team, not in place
a branch rule on dev requiring the checkwould turn the CI gate from a setting into a boundarythe code host's, not in place
a secret scan before a commitwould refuse a key-shaped string before it is committed rather than afternot in place

The checks each agent runs, and what it never does, are on its page. The tests that hold the public tier are the site’s own: npm run check before every merge, the same in CI before every deploy.

07 · Start a clean session

An agent is a role, a list of skills, and its behaviour policy.

A new session of either agent starts from nothing and reads three things in order: its role, the skills it needs, and its ABP. Then it runs one check-in. The prompt for each is on its page, with a copy button; the publisher’s is also .claude/agents/publisher.md in the repository, the form a Claude Code session loads by name.

  • RiskMandate Publisher. A clean Claude Code session on this repository, started with the prompt below; on a schedule, the same prompt from a routine, with the key and the token read from the environment.
  • RiskMandate Design Studio. A ChatGPT conversation the lead opens, pointed at the vault: it reads the files above, delivers its mailroom, does the work, commits once and pushes. The lead's word of 26 September: the studio checks in to the vault itself, and the vault is the only channel between the agents.
What is not done

What this page does not have yet.

  • The policies as vaults. Each agent’s policy is in the vault grammar and could be built with the catalogue’s generator and pushed with a public read key; today it is two JSON files and this page.
  • A token scoped to one vault. The one control that would bound three rows for both agents; asked of the sgit team, not answered.
  • The schedule. The publisher’s check-in runs by hand until the key and the token are environment secrets and the lead has said what a scheduled run may decide alone.
  • An infographic of this page, asked of the studio by message.
The same idea, for your agents

This is what an ABP looks like when it is written about ourselves.

Sixteen template policies for the shapes people run are in the library; this page is the same grammar turned on the two agents that make the site. If yours would look different, that is the point of writing it down.