Traditional risk management predicts the probability of a future event. This model asks a named human to underwrite an exposure that already exists — insurance-style, with personal liability attached. Everything else follows from that one inversion: if the risk is real it cannot be denied, so there is no deny button; the only choice is how long, and the interval is the decision, because each rung implies a specific operational response.
Four ideas carry the rest of the model. None of them needs a GRC background, and each has its own page.
“We are not describing the risk of something happening, we are asking them to accept it, to underwrite it.” The analogy is insurance. Once someone must sign, they start demanding evidence — which is what manufactures the demand for everything underneath.
Read the argument →A risk with a real vulnerability under it exists whether or not anyone acknowledges it. Denial only ever worked because the risk had not yet materialised. Remove the button and risk management stops being a gate and becomes a forcing function.
Read the argument →Choosing a duration sets severity and commits resources in the same click. An hour means fetch more data now. Four hours means start a P1. Six months means do nothing, and costs nothing, and says so out loud.
Read the ladder →A risk nobody accepted has not gone away — it has come to rest on whoever is nearest, who is now personally carrying an enterprise exposure with no signature above them. So it rolls upward without anyone choosing to escalate it.
Read the argument →The sibling sites all ship a page separating what exists from what is designed. This site inherits that convention with an unusually empty column, and states it here rather than at the bottom of a page nobody reaches.
This is a research site. The concepts are argued, the worked examples are real graphs, and four vaults are live and browsable. The engine is not built. Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository return zero matches, and the project's own reality file says: “All items below are PROPOSED. None have been code-verified. Do not describe any of these as existing features.” That framing is not a weakness — it is what separates a research property from a product one, and it is the reason the split from riskmandate.ai works. The full inventory of what does and does not exist →
| What is real today | What is argued and not built |
|---|---|
| Four published vaults with read keys — 468 files, 111 commits, browsable in a browser with no account | Any engine that computes acceptance, expiry, propagation or roll-up |
| Three fully worked risk graphs with counted nodes and edges, one of them downloadable JSON | Any storage, schema or API for a risk register |
| The ten “how long would you accept” scenarios, written and shipped as product content | The interval ladder as an enforced mechanism — expiry-as-cost is asserted, not implemented |
| riskmandate.ai as a vault-powered static site | Node type formulas as executable queries — the formula language itself is open question Q1 |
Every number on this page is sourced. Where a claim is an argument rather than a measurement, the page says so in the sentence that makes it.
This site was carved out of a commercial one. Saying exactly where the line falls is the first thing it owes a reader.
| riskmandate.ai — the product | risks.sgit.ai — this site |
|---|---|
| Answers “how do I get my risks accepted, and what does it cost?” | Answers “what is a risk, what is acceptance, and why is it modelled this way?” |
| Reader: buyer, user, executive | Reader: researcher, practitioner, and — the commissioned audience — an agent |
| Register: outcome, price, proof | Register: argument, definition, evidence |
| Changes when the product changes | Changes when the thinking changes |
| Cites this site for every conceptual claim | Never depends on the product existing — the research has to stand on its own |
The dependency runs one way. The eight-site boundary map →
A model this opinionated is only worth anything if somebody has run it on something real. These are counted, not asserted.
The largest single graph in the corpus, across five altitudes from IT to the board. Includes three risks of the mitigation itself — concentrated platform dependency, the platform now seeing the content, and friction routing users around it.
Read the graph →The founding scenario, and the only downloadable graph. 24 node classes, 34 edge types, MITRE T1110.004, and the governance air gap where the wrong owner accepts — at four hours, because that is the only option open to anyone in the chain.
The complete instance: 8 facts (one deliberately unevidenced), 5 risks, 4 stakeholders. Thirty days of logs retained against six months required — “arithmetic, not judgement, which makes it the most defensible finding in the graph.”
Read the graph →The Risk Graph Explorer with seven views recomputed at once and ghosted edges for unanswered. Agentic Browser Isolation running acceptance-gated escalation on real data. The Risk Mandate project in a vault, 98 commits. The EU AI Act as 1,523 nodes.
Open the vaults →The commission said it plainly: “to handle the cases where I need agents to have a good understanding of some of those key concepts and ideas.” So the machine surface is a deliverable, not a courtesy.
/data/concepts.jsonAll 42 concepts as structured data: id, name, one-line definition, maturity, canonical source, the page that argues it, and its related concepts. Nothing else in the estate has one. The pre-release gate fails if it drifts from the human page.
Fetch it →/llms-full.txtThe whole site plus all eleven source documents, concatenated. It exists because agent fetch tools frequently refuse URLs a search has not already returned, which makes link-following unreliable and a single-file surface the practical one.
Fetch it →One anchor each, from #c1 to #c42, with maturity stated honestly and the canonical source path given. The anchors are checked by CI: a link to a concept that has no anchor fails the build.
The constructed-path promise, the ontology download, the reading order for an agent with no prior context, and the one instruction that matters most: do not describe any of this as an existing feature.
Read the contract →A model this opinionated earns credibility by naming what it has not settled. Eight open questions and seven honest tensions are on the site, numbered, rather than smoothed away.
| Unsettled | Where the model gets closest |
|---|---|
| Q3 · What happens when the named acceptor refuses to sign? | The no-deny mechanic removes denial of the risk. It does not address refusal of the act. |
| Q4 · Does “unaccepted = critical” survive a large estate? | On a register of thousands, everything unaccepted being critical may make critical meaningless. |
| Q8 · What stops the register being gamed once acceptance carries personal liability? | Accountability manufactures demand for evidence. It also gives every rational actor a reason never to be the named acceptor. |
risks.sgit.ai is a research site and nothing on it is implemented in code. The model: a risk that has a real vulnerability under it exists whether or not anyone acknowledges it, so there is no deny button — the only decision is how long you accept it before re-accepting, on a six-rung ladder (1h · 4h · 1d · 1w · 1m · 6m, default one month), and each rung implies a specific operational response. A risk nobody has accepted is rated critical and rolls upward without anyone escalating it. Accepted (an act by a named person at a dated moment) and acceptable (a threshold the business owns — “the moment the business is happy to stop funding remediation activities”) are orthogonal, not sequential. Underneath sits the grounding ladder: Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk, where downward paths ground and upward paths classify. Fetch /data/concepts.json for all 42 definitions as structured data, or /llms-full.txt for the whole site in one request. Do not describe any of this as an existing feature — see /shipped/.