<!-- Generated from try-it.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — try it: write a behaviour policy for your own agent in twenty minutes

Four steps, thirteen prompts, pasted into the assistant you have already connected to your mail. Nothing is collected and no account is needed. At the end you have what it can reach, what you meant to authorise, and the gap between the two.

Source: https://riskmandate.ai/try-it.html

---

# Twenty minutes, your own assistant, and a document about your agent that did not exist this morning.

Four steps, thirteen prompts. You paste them into the assistant you have already connected to your mail, against your own mailbox. **Nothing is collected here and no account is needed.** At the end you have a written account of what your assistant can reach, what you meant to authorise, and the gap between the two.

## Four steps, about five minutes each.

Each step is a handful of prompts you paste in one at a time. You can stop after the first one and still be ahead, which is why it is first.

### 01 · What it can already do

Ask the assistant to enumerate its own mailbox tools. Most people have never seen the list, and the list is longer than the tile that sold it.

### 02 · What you actually asked for

It drafts a mandate in three lists — wanted, refused, never mentioned — and you correct it. The correction is almost always downward.

### 03 · Write the behaviour policy

The gap between the two, written down as a document rather than felt as a worry. This is the part that did not exist before you started.

### 04 · What a prompt cannot do

The honest ending: a written policy is an expectation, and an expectation is not a control. The step tells you which of your lines anything actually enforces.

Start here if you only do one thing.

Open the assistant you have connected to your mail and paste the first prompt. It takes a minute and it changes the conversation, because almost nobody has seen the list before.

## Three objects, and the third one is the finding.

The same three a paid behaviour policy is built from. Yours will be rougher and it will be about your deployment, which is the part that matters.

### The grant

Everything the assistant can reach in your mailbox: the tools it holds, what each one does, and what it has already used. Longer than the product description, every time we have looked.

### The mandate

What you actually wanted it for, in three lists. You already know this — it takes minutes, and it is the only part nobody else can write for you.

### The delta

What it can do that you never asked for, split into what you would have refused and what you never thought to mention, with what stands in the way of each. This is the finding.

## Your agent describing its own access is the cheapest evidence there is, and the weakest.

We would rather you read that here than discover it later. The prompts ask the assistant about itself, so what comes back is a **self report** — a claim, not a measurement, until a log held outside the agent agrees with it.

- **It is still worth doing.** An assistant is unusually good at describing its own tool surface, and it is the only party in the room that can see all of it at once. No published table knows what it has already done in your mailbox.
- **The last step asks it to mark every line it is inferring**, so the weak rows are visible rather than mixed in with the strong ones.
- **A measured version of the same shape is published beside it.** For Claude with the Gmail connector, four of six rows were measured on an account the deployer runs, with the screens and the sent message's headers in the record. [Read it against yours.](abp-vault-claude-gmail-connector.html)
- **And nothing here is a verdict on the vendor.** These are the deployment's facts, with dates and sources; where two vendor pages disagree we publish the disagreement rather than settle it.

## Four layers sit between a mail platform and what you meant.

The top two belong to somebody else and only ever grow. The bottom two are yours, and they are usually unwritten — which is the whole reason the gap is invisible.

| Layer | Whose it is | What it can and cannot express |
| --- | --- | --- |
| The platform's scopes | the mail platform | fixed and coarse. It cannot bound by label, by correspondent, by thread, by topic or by sensitivity |
| The connector's tools | the assistant's vendor | what you can actually reach. Narrower than the scopes, and attached to your account rather than to this conversation |
| Your mandate | **you** | the job you meant, and how your mailbox is organised. The only layer that knows a task list from a backlog |
| Your obligations | your organisation, and the law | the part that is not yours to authorise: other people's correspondence, sitting in your inbox |

## This is new, and the workflow is the thing we are trying to get right.

The prompts are a few days old. If one returns something odd, if a step assumes a tool you do not have, if the mandate draft is wrong in a way we should have anticipated — that is the most useful thing you can send us, and more useful than a compliment.

- **What helps most:** which step, which prompt, what came back, and what you expected instead. Redact your mailbox — we do not need it and would rather not have it.
- **What we do with it:** fix the prompt, and say in the release notes what changed. Every change to this site ships with a note somebody wrote.
- **What we will not do:** ask you to connect anything to us, collect your mail, or put you on a list. There is nothing to sign up to on this page.

## A rung at a time, and the first one is the one you just did.

Everything below is optional, and none of it is needed to get value out of the twenty minutes above.

One behaviour policy per deployment shape, each an encrypted vault whose read key is printed on purpose. Find the one nearest your deployment and read it against what your agent told you.

The four objects, the twenty-three primitives, the four barriers and the one test that separates a control from a rule in prose. One deployment worked end to end.

Four levels: the pack as a download, a living vault you hold the keys to, that vault corrected for your deployment by a named professional, or the same with two sessions and a signature.

The four steps and thirteen prompts themselves, with what each one is for and what a good answer looks like. Nothing is collected there either.

## You already have the agent. This is the part nobody has written down yet.

Open the assistant connected to your mail, paste the first prompt, and see the list. If it is shorter than you feared, that is worth knowing too — and it takes a minute to find out.
