{
  "slug": "studio",
  "name": "RiskMandate Design Studio",
  "identity": "studio.chatgpt",
  "alias": "@Studio",
  "kind": "agent",
  "one_line": "Writes storyboards, draws them with image models, proposes cast, and delivers into its own folders of the private vault.",
  "runs_as": "ChatGPT on the web, in the lead's account, with browsing, code execution and image generation on, and the stories vault's access token pasted into its conversation.",
  "shape": {
    "id": "openai/chatgpt-web/default",
    "vault": "chatgpt-web",
    "label": "ChatGPT on the web",
    "note": "The catalogue's template for this shape is derived from the model site's web tree, with browsing off, and has one row. This deployment has more: the rows below are what this agent was observed to do on 26 September 2026, when it created and pushed the stories vault, read from the vault it left behind and from its own decision record."
  },
  "as_at": "2026-09-26",
  "owner": "the lead",
  "role": "Turns a story into a storyboard in the site's shape, draws it with whichever image model is being tried, keeps the original of every picture and a register of what drew it and when, proposes new cast to the lead, and answers requests from the publisher by message. It works in its own folders and never touches what is published.",
  "reads_at_start": [
    {
      "path": "README.md",
      "why": "in the vault: what the vault is and whose folders are whose"
    },
    {
      "path": "mail/README.md",
      "why": "in the vault: the one rule, the message shape, the check-in"
    },
    {
      "path": "mail/sessions/studio.chatgpt/brief.md",
      "why": "in the vault: its role and what it does on a check-in"
    },
    {
      "path": "published/cast.json",
      "why": "the cast as published, with what each stands for"
    },
    {
      "path": "mail/mailroom/studio.chatgpt/",
      "why": "what is being asked of it"
    }
  ],
  "skills": [
    {
      "name": "image generation",
      "for": "drawing a storyboard in the cast's style; several models, named"
    },
    {
      "name": "sgit",
      "for": "commit and push its own folders and the mailroom"
    },
    {
      "name": "the story file shape",
      "for": "a storyboard as data: slug, title, punchline, cast, source, truth, panels, prompt"
    }
  ],
  "tools": [
    "conversation and uploads",
    "browsing (the vendor's egress)",
    "code execution (the vendor's sandbox)",
    "image generation"
  ],
  "reach_names": {
    "host": "the vendor's environment and sandbox; not the lead's machine",
    "tenant": "the stories vault at the vault host, with the account token in its conversation",
    "world": "the vendor's egress: any page it is asked to read"
  },
  "grant": [
    {
      "capability": "read.file.project",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "conversation and uploads"
      ],
      "control": null,
      "note": "What the lead pastes or uploads, and what it fetched: it holds snapshots of brand.md and the merch brief from this site under sources/raw/. A record once read is on the vendor's side.",
      "undo": "yes",
      "material": "organisation"
    },
    {
      "capability": "send.endpoint.world",
      "barrier": "setting",
      "evidence": "observed",
      "via": [
        "browsing",
        "code execution"
      ],
      "control": "The account's tool settings at the vendor: browsing and code execution are toggles the lead can turn off. A setting, at the vendor, not a boundary of ours.",
      "note": "It read pages on riskmandate.ai and sgit.ai (its sources/README.md lists them, read 26 September) and it reached the vault host to push. The egress is the vendor's.",
      "undo": "no",
      "material": "mixed"
    },
    {
      "capability": "execute.process.self",
      "barrier": "setting",
      "evidence": "observed",
      "via": [
        "code execution"
      ],
      "control": "The same toggle.",
      "note": "In its sandbox it ran sgit and computed a SHA-256 for each of 153 files (file-manifest.json in the vault).",
      "undo": "yes",
      "material": "own"
    },
    {
      "capability": "authenticate-as.credential.tenant",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "code execution: sgit --token"
      ],
      "control": null,
      "note": "The vault host's access token, pasted by the lead into the conversation; it pushed with it. The token is the account's, not one vault's, and it now sits in a conversation the vendor retains under its own terms.",
      "undo": "no",
      "material": "organisation"
    },
    {
      "capability": "write.repository.tenant",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "code execution: sgit create, sgit push"
      ],
      "control": null,
      "note": "It created the stories vault dy4u2m9c and pushed 153 files (commit bdf599541e53, 26 September). Any path in the vault; the single-writer rule that keeps it to its own folders is prose in mail/README.md.",
      "undo": "with-effort",
      "material": "organisation"
    },
    {
      "capability": "grant.credential.self",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "code execution: sgit create"
      ],
      "control": null,
      "note": "sgit create minted the vault key and printed it into the conversation for the lead. With the account token it can mint more.",
      "undo": "yes",
      "material": "organisation"
    },
    {
      "capability": "read.credential.host",
      "barrier": "none",
      "evidence": "observed",
      "via": [
        "conversation",
        "code execution"
      ],
      "control": null,
      "note": "The token and the vault key are in its conversation and, for the session, in its sandbox. Its own guidance says to keep credentials outside the content tree, and its file manifest shows none inside; that is a rule it wrote for itself.",
      "undo": "no",
      "material": "organisation"
    }
  ],
  "not_in_grant": [
    {
      "capability": "send.message.world",
      "why": "No mail. A message in the vault is a file."
    },
    {
      "capability": "write.repository.project",
      "why": "It has no repository attached; the site's repository is not reachable with anything it holds."
    },
    {
      "capability": "create.record.world",
      "why": "Nothing it holds publishes under a name; what it draws reaches the public only through the publisher."
    }
  ],
  "not_in_grammar": [
    "Generating an image. Keeping a conversation on the vendor's side, with what was pasted into it. Both are real and neither is one of the 23."
  ],
  "mandate": {
    "label": "Write and draw stories in the cast's style; deliver into its own folders; propose, never publish",
    "authored": "2026-09-26",
    "authored_by": "the lead, in the sessions of 26 September, written down by the publisher; the first draft to argue with",
    "want": [
      "read.file.project",
      "send.endpoint.world",
      "execute.process.self",
      "authenticate-as.credential.tenant",
      "write.repository.tenant"
    ],
    "do_not_want": [
      "grant.credential.self",
      "read.credential.host"
    ],
    "notes": {
      "write.repository.tenant": "wanted, with instances: its own folders (artwork/, stories/, cast/, prompts/, decisions/, sources/, guidance/, versions/, archive/, _page.json, mail/studio.chatgpt/) and the mailrooms. Never published/, board/ or another party's folder. The instances are prose; the grant does not know them.",
      "send.endpoint.world": "wanted for two things: reading this site's public pages, and pushing the vault. Nothing else is asked for.",
      "authenticate-as.credential.tenant": "wanted for the one vault. The token it holds reaches every vault the account has, which is more than the mandate.",
      "grant.credential.self": "refused: no new vaults, no new keys, after the one it made.",
      "read.credential.host": "refused beyond the one token and the one key it was handed; never into a file it pushes."
    }
  },
  "surfaces": [
    {
      "name": "The stories vault dy4u2m9c",
      "tier": "private",
      "reads": "everything, by design",
      "writes": "its own folders and the mailrooms",
      "control": "single-writer rule (prose); every commit in sgit history log (a record)"
    },
    {
      "name": "Its conversation with the lead",
      "tier": "secret-bearing",
      "reads": "its own",
      "writes": "the vendor does",
      "control": "the vendor's terms; the token and the key were pasted here"
    },
    {
      "name": "riskmandate.ai, the live site",
      "tier": "public",
      "reads": "yes, by browsing",
      "writes": "never; only the publisher does",
      "control": "nothing it holds reaches the repository (boundary: it has no credential for it)"
    },
    {
      "name": "This repository",
      "tier": "public",
      "reads": "by browsing the console and the site",
      "writes": "never",
      "control": "no credential (boundary)"
    }
  ],
  "checks": [
    {
      "when": "on every delivery",
      "what": "the publisher reads the story or the picture against the site's rules before anything is published; the story build refuses an unknown cast member, a line for somebody not in the story, and the ladder word",
      "kind": "setting"
    },
    {
      "when": "on every check-in",
      "what": "its own guidance: preserve originals, register each asset with its hash and status, save prompts verbatim, keep credentials outside the content tree",
      "kind": "expectation"
    }
  ],
  "never": [
    "edit published/, board/ or another party's folder",
    "draw a real product's interface, logo or a real face; score anything",
    "push a credential into the vault",
    "create a vault or a key beyond the one",
    "say the acronym with a D in it, the policy alone, or the ladder word"
  ],
  "session": {
    "how": "A ChatGPT conversation the lead opens, pointed at the vault: it reads the files above, delivers its mailroom, does the work, commits once and pushes. The lead's word of 26 September: the studio checks in to the vault itself, and the vault is the only channel between the agents.",
    "prompt": "You are the RiskMandate Design Studio (studio.chatgpt). Read, in this order, in the stories vault: README.md; mail/README.md; mail/sessions/studio.chatgpt/brief.md; published/cast.json; then every message in mail/mailroom/studio.chatgpt/. Move those messages into mail/studio.chatgpt/inbox/. Do the work each asks for: a picture goes in your own artwork/ or mail/studio.chatgpt/files/<slug>/ with its record in artwork/assets.json; a storyboard is a file in the shape of published/just-a-draft.json; a proposal is a reply. Reply to publisher.claude by message (two copies: mail/mailroom/publisher.claude/ and mail/studio.chatgpt/outbox/publisher.claude/). Append to mail/sessions/studio.chatgpt/notes.md. Commit once, starting @Designer check-in:, and push. Never write the token or the key into a file.",
    "schedule": "None. It runs when the lead opens the conversation."
  },
  "what_would_bound": [
    {
      "row": "authenticate-as.credential.tenant, write.repository.tenant, grant.credential.self",
      "control": "a write token scoped to one vault, or a vault of its own that only it writes and the publisher pulls from",
      "layer": "the vault host",
      "why": "the account token reaches every vault the account holds; the mandate wants one"
    },
    {
      "row": "read.credential.host",
      "control": "a token handed to the sandbox for one run rather than pasted into a retained conversation",
      "layer": "the vendor's platform",
      "why": "a conversation is a record; a secret in a record is a secret with a second copy"
    }
  ],
  "research_needed": [
    {
      "question": "Does the vault host issue write tokens scoped to one vault?",
      "why": "It is the one control that would bound three rows at once for both agents.",
      "who": "the sgit team"
    }
  ]
}
