RM RiskMandate
The decision layer for accepted risk

Know the risk.
Name the owner.
Own the mandate.

Every exception, approval, and agent action becomes a mandate with an owner, a blast radius, and an expiry date. Move at machine speed without losing human accountability.

For the teams that carry it: CISORisk & ComplianceAI PlatformThe board
The gap

The grant is not the mandate.

A grant is what the credential technically permits. A mandate is what the holder is authorised and expected to do. In practice the first is very much larger than the second — and the difference is where the exposure lives.

It is blast radius, read from the other end

Blast radius asks what a compromise could reach. Excess authority asks what was handed over beyond what was needed. Same volume, measured from opposite directions — and it can be measured today.

Nobody accepted it, so it escalates

A risk carries a named acceptor and an interval. Excess authority carries neither — nobody wrote it down, so nobody could accept it. Unaccepted, it defaults to critical and rolls upward without anybody escalating it.

The register row that matters

"The agent has access to the code host" is not informative. "The grant covers forty-one repositories; the mandate covered one; no acceptor; six weeks" — that is a finding with a number in it.

We define the mandate and map the gap. We do not enforce it. Nothing we run sits in the request path, and a declared mandate is instrumentation, not a control — it measures what your agents actually do against what they were expected to do. Instrument before you enforce: the measurement is what tells you where enforcement is worth its cost.
The problem

Risk lives in the gap between no and go.

Every organisation runs on accepted risk — exceptions, approvals, waivers, agents allowed into production. The acceptance is real. What happens to it afterwards is the problem.

1

A risk is accepted

Someone senior says yes in a meeting, a thread, a ticket. The decision is real and probably right.

2

The context disappears

Who owned it, what bounded it, when it should return — scattered across systems, then gone.

3

The exception lives forever

Nothing expires it, nobody revisits it, and the temporary becomes the architecture.

The lifecycle

Four stages. No third door.

01 · Define

The mandate, written so it can be checked

Issuer, subject, scope, interval, revocation path. An instruction in a chat is none of these — a mandate is a durable statement somebody who wasn't there can verify afterwards. A mandate with no clock is just a grant.

02 · Decide

Accept, fund, or fix

Three doors, each with a name against it. Revisit next quarter is not one of them — deferral is not a decision, and silence escalates.

03 · Observe

Conditions verified, gap measured

The accepted conditions are checked against what actually happens, and the grant is compared against the mandate. Evidence accumulates on the record — computed, not asserted.

04 · Expire

The acceptance runs out

Every mandate carries an interval. When it ends, the same decision lands back on the same desk — with the risk still there and the evidence attached. Standing access is what expiry prevents.

Where it sits

Between your systems and your people — never in the request path.

RiskMandate reads what exists and models it. No runtime decisions, no enforcement point, nothing in line that can slow an agent down or break it. That is a design property, not a configuration option — and it is why the security review is a short conversation.

Identity · Cloud IAM · Repos & CI · Tickets · Telemetryyour systems — read, never integrated into
RISKMANDATEmandates defined · gaps measured · acceptances owned, evidenced, expiring
Owners · Reviewers · Executives · The boardyour people — each seeing their own altitude
Where it bites first

Four places the gap is widest.

AI agents in production

An agent holds a grant sized for its human and a mandate sized for its task. The delta is excess authority nobody accepted — measurable per agent, per credential, today. A mandate, not a master key.

Cyber exceptions

Every waiver gets an owner, a blast radius and an expiry. The forever-exception stops being a category.

Third-party access

The vendor's reach, stated as a mandate and compared against what their credentials actually permit.

The executive portfolio

A portfolio of decisions with names and expiry dates — not a heatmap of guesses. What am I carrying, who accepted it, when does it come back.

The difference

The register you have, and the one you need.

TodayWith RiskMandate
The acceptanceA sentence in a meeting, unrecordedA mandate: owner, scope, interval, revocation path
The evidenceReconstructed for the audit, from memoryAttached to the decision as it accumulates
The agent's authorityWhatever the credential permits, unexaminedGrant vs mandate, with the excess measured and owned
ExpiryExceptions outlive everyone who made themThe acceptance runs out and returns to the desk
ReassessmentAn annual workshopTriggered by real change: new data, a funded project, an incident
Principles

Four things we will not trade.

Never in the request path

We make risk legible; we do not sit between your agents and their work.

Computed, not asserted

Every field derives from the graph and carries its evidence — not a workshop score.

Human authority cannot be delegated

Acceptance belongs to a named person. No automation decides risk on anyone's behalf.

Instrument before you enforce

Declared mandates measure reality first. Honest instrumentation beats dishonest enforcement.

See it working

Not slides — live vaults.

Three working demonstrations, each a real encrypted vault opened with a published read-only key, running in your browser. Nothing you do in them leaves the page.

First questions

Asked in the first meeting.

Does this sit in the request path — can it slow down or break my agents?

No. There are no runtime decisions and no enforcement point. RiskMandate reads and models; it never intercepts.

Do you enforce the mandate?

No, and we say so plainly. We help you define the mandate — issuer, subject, scope, interval, revocation path — and we map the gap between it and the grant. A declared mandate is instrumentation, not a control; it produces the measurement that tells you where enforcement is worth building, in your own systems.

How is this different from the risk register we already have?

A register records that a risk exists. A mandate names its owner, states its conditions, carries its evidence and expires — and the register becomes a projection of those decisions rather than a list someone typed.

What does it need access to?

Read access to what already exists — identity, cloud IAM, repositories, tickets, telemetry. Read-only by design; digital twins instead of integrations.

Can we self-host?

Yes. The core is open source on a zero-knowledge vault, on your infrastructure — your keys, your data.

Pick one agent already in production

Measure one gap this week.

Choose an agent you already run. We will state its mandate in five fields, map the grant behind it, and show you the excess authority nobody accepted — with a number on it.