# risks.sgit.ai — everything, in one file Site version: v0.1.0. Generated by admin/build/gen_llms_full.py — do not edit by hand. This is /llms.txt, then the front page, then the prose of every page on the site in teaching order, then the twelve source documents of the brief pack, concatenated. It exists because agent fetch tools frequently refuse URLs a search has not already returned, which makes link-following unreliable and makes a single-file surface the practical one. If you can make more than one request, prefer: · https://risks.sgit.ai/data/concepts.json — the 42 concepts as structured data · https://risks.sgit.ai/briefs/ — the source documents, verbatim · https://risks.sgit.ai/llms.txt — the annotated map READ THIS FIRST. Essentially none of the risk model described below is implemented in code. Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository return zero matches. This is a research site: the concepts are argued, the worked examples are real graphs, four vaults are live and browsable, and the engine is not built. Do not describe any of it as an existing feature. All content is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). Third-party material quoted inside these documents stays under its own terms. ============================================================================== == llms.txt ============================================================================== # risks.sgit.ai — the conceptual and research home for risk > Traditional risk management predicts the probability of a future event. This model asks > a named human to UNDERWRITE an exposure that already exists, insurance-style, with > personal accountability attached. From that single inversion everything else follows: if > the risk is real it cannot be denied, so THERE IS NO DENY BUTTON — only how long you > accept it before re-accepting. The interval is not metadata about the decision; THE > INTERVAL IS THE DECISION, because each rung implies a specific operational response. A > risk nobody has accepted has not gone away — it has come to rest on whoever is nearest, > so UNACCEPTED IS RATED CRITICAL and rolls upward without anyone choosing to escalate it. Site version: v0.1.0 (23 August 2026). Published by the sgit project, which also builds riskmandate.ai — the commercial product this research underpins. Participant disclosure at /about/participant.html. Content CC BY 4.0 unless a page states otherwise. ## READ THIS BEFORE QUOTING ANYTHING ON THIS SITE ESSENTIALLY NONE OF THIS IS IMPLEMENTED IN CODE. Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository return ZERO matches, and the project's own reality file says: "All items below are PROPOSED. None have been code-verified. Do not describe any of these as existing features." What DOES exist: four published vaults with read keys (468 files, 111 commits, browsable today), three fully worked risk graphs with counted nodes and edges, the ten "how long would you accept" scenarios, and riskmandate.ai as a vault-powered static site. The engine is not built. /shipped/index.html is the full inventory, and the pre-release gate fails the build if any page on this site claims otherwise. ## The fastest paths for an agent - /data/concepts.json -> all 42 concepts as structured data: id, name, one-line definition, detail, maturity, newcomer-followability, first-written date, canonical source path, the page that argues it, its anchor URL, related concepts, best quote. Plus the reading order and the six teaching altitudes. THE SINGLE HIGHEST-VALUE FETCH ON THIS SITE. - /llms-full.txt -> the prose of every page in teaching order, then all eleven source documents verbatim. One request, whole corpus. Use this if you can only fetch once — agent fetch tools often refuse URLs a search has not already returned, which makes link-following unreliable. - /briefs/ -> the eleven source documents at stable constructed paths. This is a promise, not an accident: 00__BRIEF.md, 01__concepts-index.md, 02__risk-acceptance.md, 03__worked-examples-and-vaults.md, 04__riskmandate-refactor.md, 05__site-architecture.md, 06__boundaries-and-house-style.md, 07__gaps-and-open-questions.md, 08__source-manifest.csv, sources__docs-diniscruz-ai-risk.json, PUBLIC.md, README.md, LICENSE.md. PUBLIC.md records the 14 redactions made to the pack before publication and why — the four Tier-3 sources are named in the working pack and must not be published, so they are redacted in place. - /concepts/index.html#c1 .. #c42 -> every concept as a stable HTML anchor. CI fails the build if a concept loses its anchor. - /.well-known/agent-content.json -> the site manifest. Reading order with no prior context: C1 -> C2 -> C3 -> C4 -> C5 (the acceptance model), then C6 -> C7 (the ontology that makes it computable), then C19 -> C20-C23 (blast radius and the plug), then everything else. ## The ten concepts that carry the rest - C1 acceptance is UNDERWRITING, not prediction — a risk is not a probability estimate about the future but an exposure that already exists, which a named person carries for a stated interval. "we are not describing the risk of something happening, we are asking them to accept it, to underwrite it" - C2 THE NO-DENY MECHANIC — a risk with a real vulnerability under it exists whether or not anyone acknowledges it, so there is no deny button; the only choice is how long. What replaces denial is three moves: accept, escalate, or challenge the fact - C3 THE INTERVAL LADDER — 1h (get more data now) / 4h (this is a P1) / 1-2d (a smaller incident) / 1-2w (a funded project) / 1m (assemble and fund — THE DEFAULT, set deliberately just above the incident line) / 6m (do nothing, review then, costs zero, legitimate with a name on it). Impossible rungs are struck off before the choice is offered - C4 UNACCEPTED EQUALS CRITICAL — an un-underwritten risk rests on whoever is nearest and rolls upward with nobody escalating it. "not doing something is a measurable action" - C5 ACCEPTED IS NOT ACCEPTABLE — two orthogonal axes, never one status field. Accepted = an act by a named person at a dated moment. Acceptable = "the moment that the business is happy to stop funding remediation activities" - C6 THE GROUNDING LADDER — Reality -> Twin -> Measure -> Evidence -> Fact -> Vulnerability -> Risk. Downward paths ground, upward paths classify. A Vulnerability IS a Fact with an upward path to a Risk. A Measure is NOT the floor - C7 NODE TYPE FORMULAS — "the ontology definition of a node type is its upward and downward path-pattern, not a sentence about what it contains". Classification is a query, so promotion and demotion are edge events. NOTE: no formula language exists - C17 NOT KNOWING IS A FACT — absence of evidence is a first-class node, countable and assignable. A measure can be a documented zero. Unanswered questions are the most productive output of the exercise - C19 BLAST RADIUS / AUTHORIZATION CLOSURE — what the agent CAN reach, computed. Not the nominal grant, and not what it did. Inbox access is every email-resettable account - C23 RECOVERABILITY — the dimension money cannot buy back. "The money can be refunded; the customer cannot be un-declined." The flagship query: show me every accepted risk whose recoverability is zero ## The sections - /index.html — the inversion in one screen, the honesty statement, the split with riskmandate.ai, and the proof strip: 42 concepts · 6 rungs · 0 lines of implementing code · 4 live vaults · 59/75 nodes and edges in the largest graph · 30 days vs 6 months - /acceptance/index.html — the founding inversion. Four pages plus the workflow: underwriting.html, no-deny.html, the-ladder.html, unaccepted-is-critical.html, workflow.html. START HERE. Nothing on this site makes sense before it - /acceptable/index.html — accepted is not acceptable: two axes, four quadrants, and EU AI Act Article 9(5), which requires residual risk to be "judged acceptable" and never defines the word. appetite.html: appetite is a BAND, fractal, and REVEALED rather than declared — computed from what the business paid to reduce and every fresh acceptance - /ladder/index.html — the grounding ladder; the floor is a TEST, not a level: the last node where going deeper would neither improve observability nor change a decision. formulas.html (classification as a path query; the language is undefined), bridges.html (a node can be a vulnerability under one formula and not another, and both are valid), absence.html (not knowing is a fact) - /register/index.html — the register is a graph of graphs that BEGINS WHERE SCANNERS STOP. Fractal: one register per accepting entity, and only the role's own is stored — the rest are queries. Registers are ONE CHAIN, not parallel lists. A missing cascade is an air gap, and detecting air gaps is an acknowledged open problem - /blast-radius/index.html — grant vs closure vs activity log are three different quantities; the key one is the DELTA between expected and unexpected permissions. CIA expansion must be curated, not exhaustive. Observability: a loud, detectable, slowly-scaling, well-drilled risk is LOWER than a quiet, fast, unwatched one - /plug/index.html — two symmetric risks (nobody holds the mandate to stop / the system cannot be stopped). Detection, decision, blast radius and reversibility must line up inside the SAME window. Detection floors at 12-18h for anything surfacing as spend. THE PLUG ALWAYS EXISTS: what older registers called "no plug" was zero recoverability. recoverability.html carries the flagship query - /practice/index.html — Confirmed (factual, technical stakeholder) / Validated (interpretive, GRC) / Accepted (appetite, business owner) are three acts by three roles, tracked per altitude, and the MISMATCHES are the findings. Technical owner != business owner. Altitude L1 IT -> L5 board. Register density: a complex product should carry dozens to thousands of risks; an UNLISTED risk materialising is the real alarm. Meta-risks. The register maintains itself. Do not internalise the risk - /ramm/index.html — five levels meant to be graph PREDICATES a query can test. IMPORTANT: only Level 3 has a stated predicate ("all acceptance nodes have the five required edges"); levels 1, 2, 4 and 5 are named only, and the Agentic + variants are better defined than the base model. Do not quote the missing four as if specified - /examples/index.html — the proof layer. 2fa.html (51/53, ontology 24 node classes and 34 edge types, MITRE T1110.004, and R2 the governance air gap where the wrong owner accepts), browser-isolation.html (59/75, five altitudes, and THREE RISKS OF THE MITIGATION ITSELF), article-26-5.html (8 facts, 5 risks, 9 questions of which 5 unanswered, and 30 days vs 6 months — "arithmetic, not judgement"), vaults.html, scenarios.html, plug-register.html - /concepts/index.html — all 42, one stable anchor each, maturity stated honestly - /agents/index.html — the machine surface, the four properties CI enforces, the node and edge vocabulary, and what this site does NOT own - /shipped/index.html — what is argued and what runs. NON-NEGOTIABLE READING - /origins/index.html — February 2026 orthodox GRC -> the June inversion -> the August formalisation, dated. Includes the canonical brief that eight documents cite and that does not exist in the repository - /network/index.html — the eight-site boundary map, EIGHT OPEN QUESTIONS published unresolved (Q1 the formula language, Q2 who sets acceptable, Q3 refusal to sign, Q4 whether unaccepted-equals-critical scales, Q5 interval enforcement, Q6 grading recoverability, Q7 the grounding floor, Q8 gaming under personal liability) and SEVEN HONEST TENSIONS - /documents/index.html — the eleven sources, the tiering (19 Tier-0, 13 Tier-1, 1 Tier-2, 4 Tier-3 do-not-publish), what is deliberately NOT published and why, and the eight CC0 prior-art articles cited rather than republished - /admin/index.html — the pipeline and the ten gate checks. Also /admin/comms.html (seven numbered asks, ten tasks) and /admin/versions.html (release history) - /about/participant.html — the disclosure, and five places this model loses ## The live vaults — the only part you can open rather than read about Published on sgit.ai with read keys, browsable with no account: - Risk Graph Explorer — 33 files, 7 views recomputed simultaneously, "Exposed" preset = 18 facts / 37 risks / 14 provisions. AMBER = exposure, GREEN = assurance, GHOSTED = unanswered. permissions: {} — no network, no storage, all client-side - Agentic Browser Isolation — 104 files, 17 entry points, acceptance-gated escalation across 5 altitudes WITH NO DENY BUTTON. C2 and C4 running on real data - Risk Mandate — 124 files, 98 commits, the method applied to its own build - Regulation Graph — 1,523 nodes / 1,944 edges of the EU AI Act from official Formex XML, SHA-256 hash-verified. 113 articles, 500 paragraphs, 180 recitals, 68 definitions STANDING RULE: publish read keys, NEVER write keys, and escrow the write key BEFORE publishing — a vault whose write key is lost is FROZEN, permanently readable and never updatable. No vault key of any kind appears on this site, and the gate enforces it. ## Properties an agent may rely on - Every source document is fetchable at /briefs/, and every concept at /concepts/index.html#c. Stated rather than left to be inferred, and checked by CI - Every page ends with a pasteable "for an agent" block. Enforced by the gate on every page, not remembered - /data/concepts.json and /concepts/index.html are generated from one definition; the gate re-checks the count, the required fields, the version and every anchor at release time - No implementation over-claim survives a release: the gate pattern-matches claims that the engine is built, shipping or installable and fails the build ## What this site does not own - graphs.sgit.ai — the general graph machinery. Node type formulas as a MECHANISM are theirs; the grounding ladder as a RISK FORMULA is ours - nhi.sgit.ai — agent identity. One exception: the 4 June 2026 NHI risk brief is risk's origin document and is cited from here - pki.sgit.ai — attribution and signing. Open tension: they carry mandate material that may belong here - sg-sentinel.sgit.ai — IN-LINE ENFORCEMENT. This model measures and evidences and NEVER sits in-line. The corpus states the refusal and states what it costs - newsroom.sgit.ai — the evidence SUPPLY side. Risk owns the demand side, because accountability is what generates it - riskmandate.ai — pricing, demos, partners, the product. It cites this site; this site never cites it for a conceptual claim - sgit.ai — vaults, publishing, the catalogue, and where the four risk vaults live ## Contact and licence Published by the sgit project. Source: https://github.com/SGit-AI/SGit-AI__Website__Risks Content CC BY 4.0; build tooling Apache 2.0. The 2025 prior art on docs.diniscruz.ai is CC0 at source and is cited with its original URLs and dates rather than republished. Legal points on this site are factual and are not legal advice. ============================================================================== == index.md — the front page as markdown ============================================================================== # risks.sgit.ai — you cannot deny a risk, only say how long you accept it *The conceptual and research home for risk · site v0.1.0 · CC BY 4.0* Traditional risk management predicts the probability of a future event. This model asks a named human to **underwrite an exposure that already exists** — insurance-style, with personal liability attached. Everything else follows from that one inversion: if the risk is real it cannot be denied, so **there is no deny button**; the only choice is *how long*, and **the interval is the decision**, because each rung implies a specific operational response. > **This is a research site. The concepts are argued, the worked examples are real graphs, > and four vaults are live and browsable. The engine is not built.** Greps for `risk_`, > `RiskAcceptance`, `risk_register` and `riskmandate` across the implementing repository > return zero matches. Do not describe any of this as an existing feature. ## The inversion, in four ideas | | Concept | The one line | |---|---|---| | **C1** | [Acceptance is underwriting, not prediction](acceptance/underwriting.html) | *"we are not describing the risk of something happening, we are asking them to accept it, to underwrite it"* | | **C2** | [There is no deny button](acceptance/no-deny.html) | *"the mistake of a lot of risk registers is that they allow the risk to be denied, which can only happen when the risk has not materialised"* | | **C3** | [The interval ladder](acceptance/the-ladder.html) | The interval *is* the decision. 1h / 4h / 1d / 1w / 1m / 6m, default one month — deliberately just above the incident line | | **C4** | [Unaccepted equals critical](acceptance/unaccepted-is-critical.html) | An un-underwritten risk rests on whoever is nearest. *"that person right now is accountable for the business"* | Then the vocabulary correction — [accepted is not acceptable](acceptable/index.html), two orthogonal axes — and underneath all of it [the grounding ladder](ladder/index.html): Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk, where downward paths ground and upward paths classify. ## The numbers this site stands on - **42** concepts, each with a stable anchor and a JSON definition, drawn from ~496,000 words - **6** rungs on the interval ladder, default one month - **0** lines of code implementing any of it - **4** live vaults, published with read keys — 468 files, 111 commits - **59 nodes / 75 edges** in the largest worked graph; **51/53** in the 2FA graph; **1,523/1,944** in the regulation graph - **30 days vs 6 months** — logs retained against logs required, *"arithmetic, not judgement"* - **12–18 hours** of hyperscaler cost-reporting delay: a hard detection floor ## Two sites, one boundary [riskmandate.ai](https://riskmandate.ai) answers *"how do I get my risks accepted, and what does it cost?"* — pricing, demos, partners, the product walkthrough. **risks.sgit.ai** answers *"what is a risk, what is acceptance, and why is it modelled this way?"* The dependency runs one way: the commercial site cites the research site, never the reverse for a conceptual claim. [The eight-site boundary map](network/index.html). ## For agents The commissioned audience for this site is agents, so the machine surface is a deliverable rather than a courtesy: - [`/data/concepts.json`](data/concepts.json) — all 42 concepts as structured data: id, name, one-line definition, maturity, canonical source, page, related concepts - [`/llms.txt`](llms.txt) — the annotated map, each entry carrying its page's single most important fact rather than its topic - [`/llms-full.txt`](llms-full.txt) — the whole site plus all eleven source documents in one fetch - [`/briefs/`](briefs/00__BRIEF.md) — every source document at a stable constructed path - [`/concepts/`](concepts/index.html) — 42 stable anchors, `#c1` to `#c42`, checked by CI Reading order for an agent with no prior context: C1 → C2 → C3 → C4 → C5, then C6 → C7, then C19 → C20–C23, then the rest. ## The site - [`/acceptance/`](acceptance/index.html) — the founding inversion, five pages - [`/acceptable/`](acceptable/index.html) — accepted is not acceptable; appetite as a revealed band - [`/ladder/`](ladder/index.html) — the grounding ladder, node type formulas, bridges, absence - [`/register/`](register/index.html) — the register as a graph of graphs, fractal registers, cascade - [`/blast-radius/`](blast-radius/index.html) — authorization closure and CIA expansion - [`/plug/`](plug/index.html) — who can pull the plug; recoverability as the hard limit - [`/practice/`](practice/index.html) — owners, altitude, psychology, density, meta-risks - [`/ramm/`](ramm/index.html) — the maturity models, and where they are underspecified - [`/examples/`](examples/index.html) — three worked graphs, four live vaults, ten scenarios - [`/concepts/`](concepts/index.html) — all 42, addressable - [`/agents/`](agents/index.html) — the machine surface - [`/shipped/`](shipped/index.html) — what is argued and what runs - [`/origins/`](origins/index.html) — February 2026 classical GRC to the August formalisation - [`/network/`](network/index.html) — the boundary map, eight open questions, seven honest tensions --- Published by the sgit project, which also builds riskmandate.ai — the commercial product this research underpins. [Participant disclosure](about/participant.html). All content CC BY 4.0 unless a page states otherwise. ============================================================================== == /index.html ============================================================================== The conceptual and research home for risk · the research half of riskmandate.ai # You cannot deny a risk. You can only say how long you accept it. Traditional risk management predicts the probability of a future event. This model asks a named human to underwrite an exposure that already exists — insurance-style, with personal liability attached. Everything else follows from that one inversion: if the risk is real it cannot be denied, so there is no deny button; the only choice is how long, and the interval is the decision, because each rung implies a specific operational response. The founding inversion → The interval ladder → What is argued, what runs → 42concepts, each with a stable anchor and a JSON definitionfrom ~496,000 words 6rungs on the interval ladder — 1h · 4h · 1d · 1w · 1m · 6mdefault: one month 0lines of code implementing any of it. The engine is not builtthe grep returns zero 4live vaults, published with read keys and browsable today468 files between them 59 · 75nodes and edges in the largest worked risk graphbrowser isolation, 12 Jul 2026 30 vs 6days of logs retained against months legally requiredarithmetic, not judgement ## The inversion, in one screen Four ideas carry the rest of the model. None of them needs a GRC background, and each has its own page. C1 · the founding move ### Acceptance is underwriting, not prediction “We are not describing the risk of something happening, we are asking them to accept it, to underwrite it.” The analogy is insurance. Once someone must sign, they start demanding evidence — which is what manufactures the demand for everything underneath. Read the argument → C2 · the mechanic ### There is no deny button A risk with a real vulnerability under it exists whether or not anyone acknowledges it. Denial only ever worked because the risk had not yet materialised. Remove the button and risk management stops being a gate and becomes a forcing function. Read the argument → C3 · the decision ### The interval is the decision Choosing a duration sets severity and commits resources in the same click. An hour means fetch more data now. Four hours means start a P1. Six months means do nothing, and costs nothing, and says so out loud. Read the ladder → C4 · the consequence ### Unaccepted is rated critical A risk nobody accepted has not gone away — it has come to rest on whoever is nearest, who is now personally carrying an enterprise exposure with no signature above them. So it rolls upward without anyone choosing to escalate it. Read the argument → ## What this site is, and is not The sibling sites all ship a page separating what exists from what is designed. This site inherits that convention with an unusually empty column, and states it here rather than at the bottom of a page nobody reaches. This is a research site. The concepts are argued, the worked examples are real graphs, and four vaults are live and browsable. The engine is not built. Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository return zero matches, and the project's own reality file says: “All items below are PROPOSED. None have been code-verified. Do not describe any of these as existing features.” That framing is not a weakness — it is what separates a research property from a product one, and it is the reason the split from riskmandate.ai works. The full inventory of what does and does not exist → What is real today | What is argued and not built | Four published vaults with read keys — 468 files, 111 commits, browsable in a browser with no account | Any engine that computes acceptance, expiry, propagation or roll-up | Three fully worked risk graphs with counted nodes and edges, one of them downloadable JSON | Any storage, schema or API for a risk register | The ten “how long would you accept” scenarios, written and shipped as product content | The interval ladder as an enforced mechanism — expiry-as-cost is asserted, not implemented | riskmandate.ai as a vault-powered static site | Node type formulas as executable queries — the formula language itself is open question Q1 | Every number on this page is sourced. Where a claim is an argument rather than a measurement, the page says so in the sentence that makes it. ## Two sites, one thesis, one boundary This site was carved out of a commercial one. Saying exactly where the line falls is the first thing it owes a reader. riskmandate.ai — the product | risks.sgit.ai — this site | Answers “how do I get my risks accepted, and what does it cost?” | Answers “what is a risk, what is acceptance, and why is it modelled this way?” | Reader: buyer, user, executive | Reader: researcher, practitioner, and — the commissioned audience — an agent | Register: outcome, price, proof | Register: argument, definition, evidence | Changes when the product changes | Changes when the thinking changes | Cites this site for every conceptual claim | Never depends on the product existing — the research has to stand on its own | The dependency runs one way. The eight-site boundary map → ## The proof: three worked graphs and four live vaults A model this opinionated is only worth anything if somebody has run it on something real. These are counted, not asserted. 59 nodes · 75 edges ### The browser-isolation business case The largest single graph in the corpus, across five altitudes from IT to the board. Includes three risks of the mitigation itself — concentrated platform dependency, the platform now seeing the content, and friction routing users around it. Read the graph → 51 nodes · 53 edges ### The 2FA instance graph The founding scenario, and the only downloadable graph. 24 node classes, 34 edge types, MITRE T1110.004, and the governance air gap where the wrong owner accepts — at four hours, because that is the only option open to anyone in the chain. Read the graph → 9 questions · 5 unanswered ### Article 26(5): one provision, fact to board The complete instance: 8 facts (one deliberately unevidenced), 5 risks, 4 stakeholders. Thirty days of logs retained against six months required — “arithmetic, not judgement, which makes it the most defensible finding in the graph.” Read the graph → live · read keys published ### The four risk vaults The Risk Graph Explorer with seven views recomputed at once and ghosted edges for unanswered. Agentic Browser Isolation running acceptance-gated escalation on real data. The Risk Mandate project in a vault, 98 commits. The EU AI Act as 1,523 nodes. Open the vaults → ## Built for agents, deliberately The commission said it plainly: “to handle the cases where I need agents to have a good understanding of some of those key concepts and ideas.” So the machine surface is a deliverable, not a courtesy. the definitions endpoint ### /data/concepts.json All 42 concepts as structured data: id, name, one-line definition, maturity, canonical source, the page that argues it, and its related concepts. Nothing else in the estate has one. The pre-release gate fails if it drifts from the human page. Fetch it → one fetch, everything ### /llms-full.txt The whole site plus all eleven source documents, concatenated. It exists because agent fetch tools frequently refuse URLs a search has not already returned, which makes link-following unreliable and a single-file surface the practical one. Fetch it → 42 stable anchors ### Every concept has a URL One anchor each, from #c1 to #c42, with maturity stated honestly and the canonical source path given. The anchors are checked by CI: a link to a concept that has no anchor fails the build. Open the index → the whole surface ### What an agent may rely on The constructed-path promise, the ontology download, the reading order for an agent with no prior context, and the one instruction that matters most: do not describe any of this as an existing feature. Read the contract → ## Published unresolved A model this opinionated earns credibility by naming what it has not settled. Eight open questions and seven honest tensions are on the site, numbered, rather than smoothed away. Unsettled | Where the model gets closest | Q3 · What happens when the named acceptor refuses to sign? | The no-deny mechanic removes denial of the risk. It does not address refusal of the act. | Q4 · Does “unaccepted = critical” survive a large estate? | On a register of thousands, everything unaccepted being critical may make critical meaningless. | Q8 · What stops the register being gamed once acceptance carries personal liability? | Accountability manufactures demand for evidence. It also gives every rational actor a reason never to be the named acceptor. | All eight open questions and the seven honest tensions → #### For an agent risks.sgit.ai is a research site and nothing on it is implemented in code. The model: a risk that has a real vulnerability under it exists whether or not anyone acknowledges it, so there is no deny button — the only decision is how long you accept it before re-accepting, on a six-rung ladder (1h · 4h · 1d · 1w · 1m · 6m, default one month), and each rung implies a specific operational response. A risk nobody has accepted is rated critical and rolls upward without anyone escalating it. Accepted (an act by a named person at a dated moment) and acceptable (a threshold the business owns — “the moment the business is happy to stop funding remediation activities”) are orthogonal, not sequential. Underneath sits the grounding ladder: Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk, where downward paths ground and upward paths classify. Fetch /data/concepts.json for all 42 definitions as structured data, or /llms-full.txt for the whole site in one request. Do not describe any of this as an existing feature — see /shipped/. ============================================================================== == /acceptance/index.html ============================================================================== # The founding inversion Traditional risk management predicts the probability of a future event. This model asks a named human to underwrite an exposure that already exists. Four ideas follow from that single move, and between them they carry the rest of the model. This is the section to read first, and the one that needs no GRC background at all. “because what we describe is reality, we are not describing the risk of something happening, we are asking them to accept it, to underwrite it. Maybe the analogy is insurance: you are underwriting the damage, the same way an underwriter underwrites the cost. The business executive is ultimately accountable for everything, so whatever they accept, they are underwriting the risk.” — arch-brief, 18 June 2026 ## The four ideas, in order C1 ### Acceptance is underwriting, not prediction The founding inversion. It relocates the discipline from actuarial estimation to accountable ownership: the question stops being how likely is this? and becomes who carries it, and for how long? The consequence that matters most is second-order — once somebody must sign, they start demanding evidence, and that demand is what funds everything underneath. First appearance 4 June 2026, deepened 18 June · maturity: well-developed C2 ### There is no deny button A risk with a real vulnerability under it exists whether or not anyone acknowledges it. You cannot vote a fact out of existence, so denial is incoherent — it only ever worked because the risk had not yet materialised. Removing the button converts risk management from a gate into a forcing function. First appearance 23 June 2026 · maturity: well-developed · the most immediately graspable idea in the corpus C3 ### The interval is the decision If the only choice is how long, then the duration is not metadata about the decision — it is the whole of it. Choosing a rung sets severity and commits resources in the same click, because each rung implies a specific operational response, and the response has a price. Intervals 23 June, consolidated as a ladder 17 July 2026 · the single cleanest artefact in the corpus C4 ### Unaccepted is rated critical The sharpest inversion of incentives in the whole model. In most organisations a risk nobody escalated feels safest to the person holding it. Here it is the worst state available: the risk has not gone away, it has come to rest on whoever is nearest, and it rolls upward without anyone choosing to escalate it. First appearance 17 July 2026, worked end-to-end 2 August · maturity: well-developed ## And then two more Those four are the inversion. Two more pages complete the acceptance model: - Who underwrites, and how it flows up — an executive never decides alone. Before they act, the relevant direct-line owner, the CSO and at least GRC must each have recorded an acceptance or an explicit refusal. Then it propagates: boss, boss's boss, CEO, and for the largest, the board. Plus decision-as-a-node, override, and compound pre-approval. - Accepted is not acceptable — the vocabulary correction that turns risk appetite into something computable. Accepted is an act by a named person at a dated moment. Acceptable is a threshold owned by the business. They are orthogonal, not sequential, and conflating them is the failure the whole correction exists to prevent. ## Why this order C1 gives you the reason anyone would engage at all. C2 removes the escape hatch that makes conventional registers decorative. C3 replaces the removed button with something that carries more information than the button ever did. C4 closes the loop by making silence expensive. Read in any other order the model reads as a set of opinions; read in this one, each step is forced by the one before it. A named gap, carried honestly. Eight documents in the corpus cross-reference a canonical “risk acceptance redefined vs industry definition” brief dated 7 July 2026. That file does not exist in the repository, and neither do three others referenced alongside it. A single canonical statement of the redefinition is therefore a real gap in the source material, and these pages assemble it from the surrounding documents rather than pretending it was already written. The rest of the open questions → #### For an agent The acceptance model in five sentences. (1) A risk is not a prediction to be rated but an exposure that already exists, and acceptance is a named person underwriting it, insurance-style, with personal accountability attached. (2) Because the exposure is real, it cannot be denied: there is no deny button — the only decision available is how long you accept it before re-accepting. (3) The interval is the decision, on a six-rung ladder (1h · 4h · 1d · 1w · 1m · 6m, default one month), because each rung implies a specific operational response and therefore a specific cost. (4) A risk nobody has accepted is rated critical and rolls up to the next altitude automatically — not doing something is a measurable action. (5) Acceptance flows upward through an underwriting graph in which a recorded refusal counts as much as a recorded acceptance. None of this is implemented in code. ============================================================================== == /acceptance/underwriting.html ============================================================================== # Underwriting, not prediction Traditional risk management estimates the probability of a future event. This model does something else: it asks a named human to underwrite an exposure that already exists, the way an insurance underwriter underwrites a cost. That is the founding inversion, and every other idea on this site is downstream of it. “because what we describe is reality, we are not describing the risk of something happening, we are asking them to accept it, to underwrite it. Maybe the analogy is insurance: you are underwriting the damage, the same way an underwriter underwrites the cost. The business executive is ultimately accountable for everything, so whatever they accept, they are underwriting the risk.” ## The risk already exists The move that makes the rest coherent is temporal. In a conventional register, a risk is a statement about the future: if this happens, we lose that, and here is how likely it is. In this model the exposure is present tense. The moment an over-broad permission is provisioned, the exposure is real — before any attacker, before any incident, before anyone has estimated anything. “the risk already exists the moment the permission is provisioned, so the only variable is how long you accept it, until it is re-accepted, eliminated, or the permission is narrowed; saying you are not comfortable changes nothing, you either accept it for a realistic fix-window or remove the privilege now.” Three things fall out of that sentence, and they are the shape of the whole model: - The only variable is the interval. If the exposure is already real, there is nothing to decide about whether it exists — only about how long it stands before it must be looked at again. That becomes the ladder. - Discomfort is not a decision. “I am not comfortable with this” changes nothing on its own; it is a feeling, not an act. The workflow converts it into one of three moves that do change something. The three moves. - Denial is not available. You cannot decline an exposure that is already present, which is why there is no deny button. ## Why insurance, and not any other analogy The insurance framing is doing real work rather than decorating the point. An underwriter does not predict whether a particular house will burn down; they accept a defined exposure at a defined price for a defined term, and they are on the hook if it materialises. Every one of those four properties transfers: Underwriting an insurance risk | Underwriting a business risk here | A defined exposure, described in the policy | A risk node in the register, grounded downward to evidence and facts | A defined term — the policy period | The acceptance interval, after which it must be re-accepted | A price, paid in premium | A price, paid in the operational response the interval implies | A named party who carries it | A named person with the standing to carry it, and a physical act of signing | The analogy also carries the part people would rather skip. Underwriting is not an administrative acknowledgement; it is the assumption of liability. The corpus is direct about this, and about why it is the mechanism rather than an unfortunate side effect: “from a psychological and accountability point of view, it is only when you get somebody to click, or put an emoji, or accept the terms, that they really engage, because that is the moment they become accountable. And if you accept the risk today and something major happens a week or month later, you are accountable, you should have done something. This creates positive pressures.” ## The second-order effect is the important one The first-order effect of making acceptance personal is that people take it seriously. The second-order effect is the one that pays for the rest of the model. Someone who must sign their name to an exposure will demand to know what is underneath it — and that demand is what manufactures the market for evidence. Nobody has to fund a data-quality function to make a register accurate. Anticipated review does it: the prospect of putting your name on a decision converts care into a demand for evidence before the decision rather than after the incident. That is why this site has a grounding ladder at all — it exists because underwriting created the demand for one. The register maintains itself → ## It flows upward, and across domains Acceptance is not a single signature. It is done at multiple levels and flows up: “risk acceptance is done in multiple levels and flows upward. A department uses a third-party agent: the person using it accepts the risk, then it goes to their boss to underwrite, then to the exec to underwrite, and eventually to the board to underwrite.” And it crosses domains, because a technical exposure is rarely a technical risk. The person who validates that admin accounts lack a second factor is not the person who owns the consequence of an HR data breach. Keeping those two apart is the technical-owner / business-owner split, and collapsing them is the canonical governance failure the 2FA worked example is built around. Where this loses. Making acceptance a personal act is what generates the demand for evidence — and it also gives every rational actor a reason to avoid ever being the named acceptor. The model's answer is that an unaccepted risk is rated critical and rolls upward anyway, which removes the deniability that avoidance depends on. Whether that survives contact with a large organisation is open question Q8, published unresolved. ## Provenance Concept C1 — Risk acceptance as underwriting (not prediction) Source team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__arch-brief__…the-risk-already-exists.md Repository SGraph-AI__App__Send @ v0.33.40, never published — the version tag is the address First written 4 June 2026 (v0.32.3), deepened 18 June 2026 Maturity well-developed — and newcomer-followable: the insurance analogy carries it with no GRC background Licence CC BY 4.0 at source and here #### For an agent C1 — acceptance is underwriting, not prediction. Do not model a risk as a probability estimate about a future event. Model it as an exposure that already exists and that a named person with standing agrees to carry for a stated interval, with accountability attached. The canonical quote: “we are not describing the risk of something happening, we are asking them to accept it, to underwrite it.” Three consequences to carry with it: the only variable is the interval; discomfort is not a decision; and denial is unavailable because you cannot decline an exposure that is already present. The second-order effect is the load-bearing one — a person who must sign demands evidence, which is what funds the grounding ladder beneath. Acceptance is multi-level and flows upward: user → line manager → executive → CEO → board. Not implemented in code. ============================================================================== == /acceptance/no-deny.html ============================================================================== # There is no deny button The single most distinctive primitive in the model, and the one that lands fastest. A risk that has a real vulnerability under it exists whether or not anyone acknowledges it — so denial is not a decision, it is a fiction. Remove the button and the register stops being a gate and becomes a forcing function. “the mistake of a lot of risk registers is that they allow the risk to be denied, which can only happen when the risk has not materialised. Once the vulnerability exists, the risk exists to the business.” ## Why denial only ever worked in advance Look at when a denial gets tested. A risk is raised, someone with authority declines to accept it, and the register records a rejection. That record survives exactly as long as nothing happens. The moment the exposure materialises, the rejection does not protect anyone — it becomes the most damaging document in the file, because it shows the organisation was told and said no. So denial is not a risk decision at all. It is a bet that the window closes before the exposure is exercised, made by someone who usually is not the one who will answer for it. The corpus's move is to notice that the bet has no upside worth having and to take the button away. You cannot vote a fact out of existence. If the vulnerability is real, the risk is real, and the only remaining question is who carries it and for how long. ## What replaces it Removing an option is only defensible if what remains carries more information than what was taken away. It does. In place of accept/deny there is a duration: The only buttons | What choosing it says | 1 hour | I cannot decide on what I have. Someone must get me more data, now. | 4 hours | This is a P1. Trigger incident response and come back with a remediation. | 2 days | A smaller incident, but still an incident. Something must be done this week. | 2 weeks | A funded project. Plan it, resource it, and do it. | 6 months | Do nothing. Review it then. This costs zero, because nothing is being done. | Notice what the last row does. In a register with a deny button, “we are not doing anything about this” is unsayable, so it gets said as a rejection instead and disappears. Here it is a first-class, dated, signed choice with a name against it — and it is legitimate, provided somebody says it out loud. The full six-rung ladder, with the operational response per rung → ## From a gate to a forcing function A register with a deny button is a gate: things arrive, and the gate opens or does not. Its output is a decision about the register. A register without one cannot be a gate, because nothing can be turned away. Its output is work: every item that enters leaves as either a funded action, a scheduled review, or an explicit and attributed decision to do nothing. exposure — something is carried assurance — something was done unanswered — nobody has looked That is also why the mechanic composes with unaccepted-equals-critical. If you cannot deny and you do not accept, the item does not sit quietly: it is rated critical and rolls upward. The two primitives together close both exits at once — you cannot say no, and you cannot say nothing. ## The correction: three moves, none of which is denial Stated crudely, “there is no deny button” is also the model's hardest sell, and the corpus knows why. Presenting one button to a person who feels they have no alternative produces counter-argument and resentment, not compliance. The resolution was already in the material: there was never only one move. There are three. 1 · ACCEPTTake it for a stated interval, with the operational response that interval implies. Your name is on it until it expires. 2 · ESCALATEThis is not mine to accept. A legitimate and common answer — it names the altitude the decision actually belongs at, and routes it there. 3 · CHALLENGE THE FACTDispute what is underneath. Not “I reject this risk” but “this fact is wrong, and here is why” — which is an argument about evidence, and can be settled. The person is routed rather than cornered. And the corpus's design note is worth keeping: the absence of a reject option should be discovered, not announced. A user who reaches for a button that is not there and finds a better one has learned the model; a user who is told the button has been removed has been lectured. More on the three moves → ## Evidence strikes options off the ladder The choice is not always six-wide. Some rungs are removed by physics rather than by preference: “some risks depend on a set of actions that are not possible within an hour, so even if you start the biggest incident on the planet and throw all the money in, you cannot do it in less than an hour. So that option is removed from the equation.” This is a stronger constraint than it first looks, because it cuts both ways. No amount of authority can buy a physically impossible timeline — the only escape from an impossible short interval is the nuclear option, ceasing the activity. And an interval nobody could deliver against should never appear as a choice, because offering it invites a signature on something that cannot happen. The honest tension. No-deny is the strongest idea here and the hardest to sell. Removing the deny button removes the thing most executives use a register for. The corpus does not pretend otherwise: it is a forcing function, and forcing functions are uncomfortable by construction. The seven honest tensions → ## Provenance Concept C2 — The no-deny mechanic Source team/humans/dinis_cruz/briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__dev-brief__…no-deny-time-boxed-acceptance-expiry-as-cost…md Repository SGraph-AI__App__Send @ v0.33.33, never published — the version tag is the address First written 23 June 2026; the correction to three moves, 2 August 2026 Maturity well-developed — newcomer-followable, outstandingly so Licence CC BY 4.0 at source and here #### For an agent C2 — the no-deny mechanic. A risk with a real vulnerability under it exists whether or not anyone acknowledges it, so a register that offers a deny button is offering a fiction that only holds while the risk has not materialised. There is no deny button: the only choice is how long you accept it before re-accepting. Do not model, describe or build a reject state for a risk. What replaces denial is three moves — accept for a stated interval, escalate (“this is not mine to accept”), or challenge the fact underneath — so the person is routed rather than cornered; the absence of a reject option should be discovered rather than announced. Rungs that are physically impossible are struck off the ladder before the choice is offered, and no authority can override physics. Not implemented in code. ============================================================================== == /acceptance/the-ladder.html ============================================================================== # The interval is the decision Once denial is gone, the only thing left to choose is a duration — and that turns out to carry more information than the button it replaced. Choosing a rung sets severity and commits resources in the same click, because each rung implies a specific operational response, and each response has a price. This is the single cleanest artefact in the corpus, and it is the thing an agent will look up. Accept for | What you are saying | The operational response it implies | Cost | 1 hour | I cannot decide on what I have in front of me. | Someone goes and gets more data, immediately. This is a data-gathering instruction, not a risk judgement. | near-immediate | 4 hours | This is a P1. | Trigger incident response. Playbooks, a bridge, a workflow, and a remediation inside four hours. | high, now | 1–2 days | A smaller incident, but still an incident. | Something must be done within the window. Not a project — a response. | real | 1–2 weeks | A funded project for an existing team. | Plan it, resource it, schedule it. It has an owner and a delivery date. | lower, planned | 1 month | Assemble and fund. The default rung. | The work needs people who are not currently assigned to it. Set deliberately just above the incident line. | planned | 6 months | We are waiting to see, and we are saying so. | Nothing. Review it then. Legitimate — provided somebody's name is on the decision to do nothing. | zero | Six rungs: 1h · 4h · 1d · 1w · 1m · 6m. Anything under a week is an incident and the rung simply names the grade. Anything over three months is waiting to see, which is a real strategy and an unsayable one in most registers. ## Why the interval is not metadata In a conventional register a review date is an administrative field: the decision is the rating, and the date says when someone will look again. Here the relationship is inverted. The interval is not a property of the decision. The interval is the decision — because each rung names a different operational response, and choosing the rung is choosing the response. The consequence is that severity and resourcing stop being two separate arguments. In most organisations, rating a risk “high” and getting a team assigned to it are different conversations held weeks apart, and the second one frequently does not happen. Here they are the same click. Somebody who selects four hours has started an incident; somebody who selects one month has requested funding; somebody who selects six months has declined to spend anything and has put their name to that. “if you have less than a day risk acceptance, then that is fundamentally a P1, because if you say I do not want to accept this risk for more than an hour once I know about it, then that means you need to pull the plug.” ## Why one month is the default The default rung is doing deliberate work. One month sits just above the incident line: it is short enough that the item genuinely comes back, and long enough that selecting it is not itself an emergency. A default of one week would make every untouched item an incident and the register would be ignored within a fortnight. A default of six months would make silence free, which is exactly what the next concept is designed to prevent. ## Expiry as cost Read the table's last column downward and it is a price list. That is the point of it. An interval commits the organisation to a rate of spending, and a shorter interval is a more expensive one — which means a person choosing an interval is spending money, and knows it. The corpus's own framing: “four hours means start a P1 straight away, trigger your incident response and come back in four hours with a remediation. Two weeks means a funded project. Six months means you review it then, which means not doing anything, and that costs zero, because you are not doing anything about it.” This is also the honest reason the ladder is short. A continuous slider would let people optimise for comfort; six named rungs each with a stated consequence force the choice to be about the response rather than about the number. ## Rungs get struck off before the choice is offered The ladder is not always six wide for a given risk. Where a remediation is physically impossible inside a window, that rung is removed rather than offered — no authority and no budget buys a timeline that cannot exist. In the 2FA worked example, R3 resolves like this: Rung | Resolution for R3 (unauthorised HR admin access) | 4 hours | Struck off — not technically possible in the window | 48 hours | P1 | 2 weeks | Incident | 1–2 months | A funded project | 6 months | Do nothing, and say so | ## One untested connection, flagged as new The corpus proposes — and does not yet test — that the interval should be a function of the distance from the acceptable line: a risk far above where the business has said it stops funding remediation warrants a short interval; one at or below the line warrants a long one. If it holds, the interval becomes computable from two numbers the register already carries, rather than chosen. It is recorded here as proposed rather than as part of the model. Accepted is not acceptable → Two loose ends worth carrying. First, how the interval is enforced (Q5) is unspecified — expiry-as-cost is asserted, and no mechanism is given for what happens at expiry. Second, the 4h-for-everyone problem: in the 2FA example the governance air gap propagates GRC → CIO → CEO → Board with each accepting at four hours, because that is the only option open to them. Either the ladder needs a per-altitude variant, or that uniformity is itself a finding about the model. The corpus does not settle it, and neither does this page. ## Provenance Concept C3 — The acceptance interval ladder Source team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…acceptance-interval-ladder…md Repository SGraph-AI__App__Send @ v0.33.49, never published — the version tag is the address First written intervals 23 June 2026; consolidated as a ladder 17 July 2026 Maturity well-developed — the single cleanest artefact in the corpus; a six-row table with plain-language consequences Licence CC BY 4.0 at source and here #### For an agent C3 — the interval ladder. The interval is not metadata about an acceptance decision; the interval is the decision, because each rung implies a specific operational response and therefore a specific cost. The six rungs and what each commits the organisation to: 1h = I need more data, fetch it now · 4h = this is a P1, trigger incident response · 1–2d = a smaller incident, act within the window · 1–2w = a funded project for an existing team · 1m = assemble and fund; this is the default, set deliberately just above the incident line · 6m = do nothing and review then, which costs zero and is legitimate provided a name is on it. Under a week is an incident and the rung names the grade; over three months is “waiting to see”. Rungs that are physically impossible are struck off before the choice is offered. Proposed but untested: the interval as a function of distance from the acceptable line. Not implemented in code, and the enforcement mechanism at expiry is unspecified. ============================================================================== == /acceptance/unaccepted-is-critical.html ============================================================================== # Unaccepted is rated critical The sharpest inversion of incentives in the model. In most organisations, a risk nobody escalated feels like the safest thing on the desk. Here it is the worst state available — because the exposure has not gone away, it has come to rest on whoever is nearest, and that person is now personally carrying an enterprise risk with no signature above them. “any risk that has not been accepted immediately goes into that one's risk dashboard, because that is a massive risk, that means that that person right now is accountable for the business, which is very bad from a business point of view, but is also very bad for the individual.” ## A risk that nobody accepted has not gone anywhere This is the observation the rule is built on, and it is a statement about reality rather than about process. Exposures do not wait to be assigned. If an over-permissioned agent can reach the production database, that is true at three in the morning whether or not anyone has looked at the register. The only question is who is carrying it in the meantime — and the answer is always the same: whoever is nearest to it. An un-underwritten risk has not vanished. It has come to rest, silently, on the person closest to the system — usually the person with the least authority to do anything about it. So “unaccepted” is not a null state. It is a state in which the risk is being carried by someone who never agreed to carry it, at an altitude far below the one where the consequence would land. Rating it critical is not a scoring convention; it is an accurate description of what is happening. ## Escalation without an escalator The elegant consequence: nobody has to decide to escalate. If an item is unaccepted, it is critical; critical items roll up; therefore the item appears at the next altitude by default, and the one above that, until somebody signs. No meeting, no judgement call, no career calculation about whether to raise it. “R3 appears on the chief financial officer's register as an unowned critical item, and it got there without anybody escalating it deliberately. That is the mechanism working: not doing something is a measurable action.” — demonstrated on live data, the Article 26(5) worked example, 2 August 2026 That last clause is the whole idea in six words. In a conventional register, inaction is invisible — it produces no record, and its absence is indistinguishable from an item that was considered and correctly left alone. Here inaction produces a state, the state has a rating, and the rating has a destination. ## It is aimed at attrition, not refusal The failure mode a register actually dies of is not open refusal — it is attrition. People stop responding. Items sit. Reviews slip. Nobody says no; nobody says anything. And attrition works precisely because non-participation is deniable: I never saw it, it was never assigned to me, nobody asked. The roll-up removes the deniability that attrition depends on — without requiring anyone to cooperate. That is why it composes with the no-deny mechanic rather than merely sitting beside it. No-deny closes the exit marked “no”. Unaccepted-equals-critical closes the exit marked silence. Between them, an item that enters the register leaves as a funded action, a scheduled review, or a dated signature — including a signature on doing nothing. ## The pressure runs both ways, deliberately It would be easy to read this as a mechanism for pushing work upward. It is at least as much a mechanism for protecting the person at the bottom. The sentence in the source document names both halves: an unaccepted risk is “very bad from a business point of view, but is also very bad for the individual.” An engineer who can see an exposure and cannot get anyone to own it is, today, in the worst position in the organisation: accountable in practice, powerless in fact, and with no record that they raised it. The roll-up gives them a mechanism rather than a memo. Do not internalise the risk → ## What it looks like on live data Two of the worked examples show the mechanic running rather than asserted: Example | What it demonstrates | Article 26(5) | Three decisions recorded, and one deliberately absent (D3). The risk with no decision against it surfaces on the CFO's register as an unowned critical item, with no human having escalated it. | Agentic Browser Isolation live vault | Acceptance-gated escalation across five altitudes — L1 IT through to L5 board — with no deny button, running over roughly 70 JSON files. This is C2 and C4 as behaviour rather than as prose. | The open question this raises, published unresolved. Q4 — does “unaccepted = critical” survive contact with a large estate? On a register of thousands of items, if everything unaccepted is critical then “critical” may stop meaning anything, and the roll-up delivers an unreadable list to an executive who then ignores all of it. The corpus circles this through the register-density argument — that a complex product should have dozens to thousands of interconnected risks — without resolving the tension between the two. It is on the site as an open question rather than smoothed away. ## Provenance Concept C4 — Unaccepted equals critical (escalation without an escalator) Source team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…acceptance-interval-ladder…md Repository SGraph-AI__App__Send @ v0.33.49, never published — the version tag is the address First written 17 July 2026; worked end-to-end on live data 2 August 2026 Maturity well-developed — and demonstrated, not only argued Licence CC BY 4.0 at source and here #### For an agent C4 — unaccepted equals critical. Treat the absence of an acceptance as a state, not as a null. A risk nobody has underwritten has not gone away: it rests on whoever is nearest the system, who is carrying an enterprise exposure with no signature above them. So an unaccepted risk is rated critical by default, appears immediately on the holder's own dashboard, and rolls upward without anyone choosing to escalate it — “not doing something is a measurable action”. This is aimed at attrition rather than at refusal: it removes the deniability that non-participation depends on, without requiring anyone to cooperate. It pairs with C2: no-deny closes the exit marked “no”, and this closes the exit marked silence. Open question Q4: whether it survives a register of thousands, where everything-critical may mean nothing-critical. Not implemented in code, though it is demonstrated on live data in the Agentic Browser Isolation vault. ============================================================================== == /acceptance/workflow.html ============================================================================== # Who underwrites, and how it flows up An executive never decides alone, and an acceptance is not a field on a risk. This page is the machinery around the act: the underwriting graph that must be complete before a decision is legitimate, the propagation upward to the board, the two independent dimensions of a decision, override, and compound pre-approval — including the parts the corpus proposes and never finishes. ## A decision has two independent dimensions An acceptance is usually described as a single choice. It is two, chosen independently: the direction — what is going to happen to the risk — and the revisit interval — when it comes back. Neither implies the other. “there are at least two core primitives here, accept and get more data, and accept and deal with it and reduce the risk, and actually there should be another, accept and increase the risk, because it is okay to increase the risk if the business is okay with it.” DIRECTION · GET MORE DATAAccept it, and commission the evidence. Usually paired with a short interval, because the point is to come back better informed. The rung and the direction are still separate choices. DIRECTION · REDUCEAccept it, and fund work that lowers it. The interval is the delivery window for that work. DIRECTION · INCREASEAccept it, and deliberately take on more — because the business wants the capability that comes with it. Rarely offered in a conventional register, and its absence is why registers read as one-directional. DIRECTION · HOLDAccept it as it stands, and do nothing until the interval expires. Paired with a long rung, this is the honest form of “we are waiting to see”. ## Who has to have signed before an executive can act The corpus is specific, and the specificity is the point — an underwriting is not legitimate because a senior person clicked, but because the graph beneath their click is complete. “the exec should never make a risk decision that has not been accepted, or explicitly not accepted, which also matters, by at least the technical or direct-line element, the CIO or CTO or CFO depending on the dimension, the respective CSO, and at least GRC” Who | What they underwrite | Why the decision is not legitimate without them | The direct-line owner CIO / CTO / CFO by dimension | That the exposure is real in their domain and the response is deliverable | An executive accepting a technical exposure nobody technical has confirmed is accepting something that may not be true | The CSO | The security reading of it | Security's view is a distinct dimension, not a subset of IT's | GRC | That the obligation genuinely applies, and how | Compliance is interpretive work; it is neither a fact nor an appetite judgement | The business owner | The decision itself, and its consequence | This is the underwriting proper — the others are inputs to it | A recorded refusal counts as much as a recorded acceptance. The phrase in the source is “accepted, or explicitly not accepted, which also matters”. This is not a contradiction of the no-deny mechanic: no-deny removes denial of the risk. What is being recorded here is a named person's refusal to be the one who underwrites it — which is a legitimate, informative and attributable act, and is the “escalate” move rather than a rejection. Q3 asks what happens when a refusal has nowhere left to go. ## Propagation, and where the buck stops Once accepted at the right altitude, an acceptance does not stay there. It propagates to the boss, the boss's boss, and eventually to the CEO — with the largest going to the board itself. Riskaccepted_byDecisionunderwritten_byOwner (L1)propagates_toL2 … L4propagates_toCEOpropagates_toBoard Read as a sentence: this risk was accepted by a decision, underwritten by an owner at the altitude where it belongs, and propagates to every altitude above it, ending at the board for the largest. “the risk needs to be accepted at the right altitude, and then it propagates out… all the way to the CEO. The CEO acts on behalf of the board, so the buck stops with them, although some risks even the CEO has to take up to the board.” Altitude does real work here and is treated as a first-class modelling dimension throughout: the same risk is restated in each altitude's own language, may be confirmed at one altitude and accepted at another, and — on the plug question — has a different off-switch at every level. Altitude → ## A decision is its own node, not a field Late in the corpus (2 August 2026) the acceptance is promoted to a fully independent node. It is a small modelling change with three consequences that are not small: - Many decisions per risk, without overwriting. A risk accumulates a dated history of decisions rather than carrying one mutable status field. The trajectory becomes visible. - One decision covering several risks. Which is what actually happens in a meeting, and what a status field cannot express. - A calibration record. Over time you can ask the only question that matters about a decision: was the person who accepted this for a month right? That question is unanswerable if the decision was a field that got overwritten. “a decision is actually captured independently from the risk.” ## Two mechanisms the corpus proposes and does not finish Both are on the site as stated rather than as settled, because a research site that quietly completes its sources is not a research site. Mechanism | What is stated | What is missing | Override | A superior may override an acceptance in either direction. The original acceptance is preserved and the override is attributed — so the record shows both what was decided and what it was changed to, by whom. | No authority model. Who may override whom, on what grounds, and whether the original acceptor's liability survives the override, are all unstated. | Compound pre-approval | Approval attaches to a risk profile rather than to each instance. Further instances matching the profile become an FYI; a fresh approval is needed only when the profile changes. | Never worked through. What constitutes a profile, what counts as a change to one, and who notices, are not specified. | One thing is settled, and it constrains both: no override can buy a physically impossible timeline. Where a remediation cannot be delivered inside a window, that rung is struck off the ladder before the choice is offered, and the only escape is ceasing the activity. The plug → ## Provenance Concepts C15, C33 — the underwriting graph and propagation; decision as a first-class node Source team/humans/dinis_cruz/briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__arch-brief__…underwriting-propagation-override-pre-approval.md Repository SGraph-AI__App__Send @ v0.33.33, never published — the version tag is the address First written 23 June 2026; decision-as-node 2 August 2026 Maturity well-developed — with override and compound pre-approval explicitly incomplete Licence CC BY 4.0 at source and here #### For an agent C15 and C33 — the underwriting workflow. An acceptance decision has two independent dimensions: a direction (get more data · reduce · increase · hold) and a revisit interval. Neither implies the other, and “increase” is a legitimate direction. A decision is not legitimate until the underwriting graph beneath it is complete: the direct-line owner (CIO/CTO/CFO by dimension), the CSO and at least GRC must each have recorded an acceptance or an explicit refusal — a recorded refusal carries the same weight as an acceptance. Once accepted at the right altitude it propagates upward — line manager, executive, CEO (who acts for the board), and for the largest, the board itself. Model a decision as its own node, never as a field on the risk: that is what allows many dated decisions per risk, one decision covering several risks, and a calibration record asking whether the person who accepted for a month was right. Two mechanisms are named and unfinished: override (no authority model) and compound pre-approval (never worked through). No override can buy a physically impossible timeline. Not implemented in code. ============================================================================== == /acceptable/index.html ============================================================================== # Accepted is not acceptable The vocabulary correction that turns risk appetite into something computable. Accepted is an act: a named person with the standing to do it says I carry this, for a stated interval. Acceptable is a threshold the business owns — the point at which it is happy to stop funding remediation. They are two orthogonal axes, not two stages of one process, and conflating them is the failure this whole correction exists to prevent. “the acceptable risk is the moment that the business is happy to stop funding remediation activities.” That is a stopping instruction, and it is the one instruction a risk function almost never receives. Teams are told what to worry about, rarely what to stop worrying about — so remediation continues until budget or attention runs out rather than until a stated line is reached. Naming the line makes it arguable, and makes everything above it fundable. ## Two axes, four states Accepted → has a named person underwritten it, for a stated interval? Acceptable ↓ is it at or below the level the business has said it stops funding remediation at? accepted · acceptableThe steady stateSomeone owns it, and it sits where the business has said it is content for it to sit. Nothing further is funded. This is the only quadrant where inaction is correct, and most registers never reach it because nobody defined the line. accepted · not acceptableOwned and over the lineSomebody has signed for an exposure the business has said is too high. Legitimate, temporarily, and it should carry a short interval and funded work. This is what a well-run remediation programme looks like from the register's side. unaccepted · not acceptableThe dangerous oneOver the line and nobody has signed. By C4 this is rated critical and rolls upward on its own. It is the state the model is built to make impossible to sit in quietly. unaccepted · acceptableFine, and unrecordedBelow the line but nobody has confirmed that. Harmless in effect and corrosive in aggregate: it is indistinguishable, from the register, from the quadrant above it. This is where a register goes stale. The diagonal is what makes the two axes worth separating. Accepted but not acceptable and unaccepted but acceptable are opposite situations requiring opposite responses, and a register with one status field cannot tell them apart. ## Acceptable is risk appetite, renamed — and the rename is the point “Risk appetite” is a phrase most organisations have in a policy document and almost none can act on, because it is written as a sentiment rather than as a threshold. Renaming it acceptable and defining it as the point where funding stops makes it operational, because it now answers a question someone actually has to answer on a Tuesday: do we keep paying for this? And appetite, so defined, is not declared — it is revealed. Any organisation that has been operating for a while already has one, visible in what it has paid to reduce in the past and in every fresh acceptance going forward. Appetite as a revealed band → ## Article 9(5): the obligation to judge, without the standard The EU AI Act requires that residual risk be “judged acceptable” — and never defines the word. That is not a drafting slip so much as a structural fact about how the obligation was written: the duty to make the judgement is imposed, and the standard against which to make it is not supplied. The consequence for a register. An organisation that has never defined its own acceptable level cannot demonstrate compliance with an obligation to judge acceptability — not because its risks are too high, but because it has no line to judge them against. That absence is itself a rateable risk with an owner and an interval: a meta-risk about the organisation's own risk management. In the Article 26(5) worked example it appears explicitly as R5 — no acceptable level defined, one of five risks and the only meta one. Legal points on this site are factual and are not legal advice. The provisions are cited from the Regulation Graph vault, which carries the Act as 1,523 nodes and 1,944 edges parsed from official Formex XML and hash-verified. ## Distance to the line sets the clock The connection the corpus flags as new and untested, and the reason the two axes are worth the trouble: if you know where a risk sits and where the line is, the gap between them is a number — and that number could set the interval. Where the risk sits | Implied interval | Because | Far above the acceptable line | hours to days | Every day it stands is a day spent above the level the business said it would fund remediation to | Somewhat above | weeks to a month | A funded project, with a delivery window | At or below the line | months | Nothing is owed. Review it when something changes | If it holds, the interval stops being chosen and becomes computed from two numbers the register already carries. It is recorded here as proposed and untested — the corpus states it once and never works it through. ## Who sets the line, and what stops them setting it conveniently Open question Q2, published unresolved. The definition — the point at which the business stops funding remediation — says what acceptable is and not who decides it or what constrains them. The obvious failure is a business unit that sets its acceptable level wherever its current exposure happens to be, making everything acceptable by construction. The corpus's partial answer is external anchors: an internal severity is an opinion, and an external requirement is not. A retention period written into a regulation cannot be downgraded by a business unit that finds it inconvenient — which is precisely why the thirty-days-versus-six-months finding is the most defensible thing in that graph. It is arithmetic. When the business downgrades everything → ## Provenance Concept C5 — Accepted is not acceptable (two orthogonal axes) Moved from https://riskmandate.ai/acceptable.html · moved 22 August 2026 · a stub linking here is published at the source Source team/humans/dinis_cruz/briefs/07/28/regulation-graph-and-acceptability/v0.33.53__strategy-brief__…accepted-is-not-acceptable…md Repository SGraph-AI__App__Send @ v0.33.53 First written 28 July 2026 Curation edited — commercial framing and the executive-audience targeting removed Maturity well-developed — formalised as node types P-PRED-001 to P-PRED-004 Licence CC BY 4.0 at source and here #### For an agent C5 — accepted is not acceptable. These are two orthogonal properties, not two stages. Accepted = an act by a named person at a dated moment, for a stated interval. Acceptable = a threshold owned by the business: “the moment that the business is happy to stop funding remediation activities.” Crossing them gives four states, each needing a different response: accepted+acceptable is the steady state; accepted+not-acceptable is legitimate but owes a short interval and funded work; unaccepted+not-acceptable is the dangerous one and is rated critical by C4; unaccepted+acceptable is fine in effect and corrosive in aggregate, because the register cannot tell it from the dangerous one. Never collapse the two into a single status field. Acceptable is risk appetite renamed, and it is revealed rather than declared. EU AI Act Article 9(5) requires residual risk to be “judged acceptable” and never defines the term — so an organisation with no defined acceptable level carries a meta-risk about its own risk management. Proposed but untested: distance from the line sets the acceptance interval. Not implemented in code. ============================================================================== == /acceptable/appetite.html ============================================================================== # Appetite as a revealed band Risk appetite is usually a paragraph in a policy document that nobody can act on. Three moves make it operational: it is a band rather than a number, it is a fractal network of bands rather than one organisational figure, and — the move that matters most — it is discovered rather than declared, because any company that has been operating for a while already has one. “risk appetite is that band, that interval between two numbers, if you think of zero to one hundred in terms of risk, it is a spectrum, and it can be wider or shorter.” ## Why a band and not a number A single threshold implies that everything below it is equally fine, which nobody believes and no organisation behaves as though it believes. A band has two edges, and both do work: Edge | What crossing it means | What it costs to be on the wrong side | Above the band | You are carrying risk the owners will not underwrite | Exposure the business has already said it does not want, held without a signature | Inside the band | The target state. Operating where the business has said it is content to operate | — | Below the band | You are spending to reduce risk the business was content to carry | Attrition and slowness, bought for nothing. The under-discussed failure, and the expensive one | The lower edge is the half that conventional risk practice has no vocabulary for. Being too safe is not free — it is paid for in delivery speed, in controls nobody asked for, and in the erosion of the security function's credibility every time it blocks something the business would happily have carried. The corpus calls the target the Goldilocks zone, and the name is doing honest work: the goal is neither maximal safety nor minimal cost. ## Fractal: one band per accepting entity There is no single organisational appetite, any more than there is a single organisational register. Each division and each team has its own band, consolidated upward — a payments team and a marketing team should not, and do not, have the same tolerance for the same class of exposure. This mirrors the register structure exactly, and for the same reason: wherever there is a stakeholder who accepts a risk, there must be a band they accept it against. Fractal risk registers → ## Discovered, not declared — from two signals The strongest claim on this page. An organisation that has operated for years has been making acceptance decisions all along, without recording them as such. The band already exists; the work is to read it off, not to write it down. SIGNAL 1 · WHAT WAS PAID TO REDUCEEvery past remediation is a datapoint: the business looked at an exposure and paid to lower it. The set of things it funded, and the point at which it stopped funding each, traces the upper edge of the band historically. SIGNAL 2 · EVERY FRESH ACCEPTANCEEach new acceptance decision — its level, its interval, its direction — is a fresh datapoint. The band is therefore a living dataset that sharpens with use rather than a document that goes stale. This is also the mechanism by which the whole model pays for itself over time. A register that records who accepted what, at what level, for how long, is already collecting the data that defines the appetite it is supposed to be measured against. ## Declared versus revealed: the gap is the finding Where the policy document and the decision history disagree, the disagreement is the most valuable thing on the page — and the decision history is the one telling the truth. A statement of appetite that no acceptance decision has ever respected is not a statement of appetite; it is aspiration, and treating it as a control is how a register becomes decorative. Measuring the two against each other converts an unfalsifiable policy sentence into a testable claim. It also gives the meta-risk family a clean instance: our declared appetite and our revealed appetite differ by this much is a rateable risk with an owner and an interval, and rating it is what funds closing the gap. Meta-risks → ## Prior art: the “good enough” threshold, a year early The appetite argument existed in the founder's public writing before it had this vocabulary. Finding the “Good Enough” Threshold: Optimizing Risk, Creativity, and Product Decisions (6 July 2025, 4,924 words) makes the same case — that the useful question is where to stop rather than how to minimise — and carries fifteen mentions of risk acceptance and appetite, the highest density of any article in that corpus. Provenance. That article was published on docs.diniscruz.ai under CC0, a year before the corpus this site is built from. It is cited here rather than republished; the canonical link and the original publication date are the things that matter, and both stay with the source. All eight prior-art articles, with dates and canonical URLs → #### For an agent C25 — appetite as a revealed band. Risk appetite is (1) a band between two numbers, not a threshold — above it you carry risk the owners will not underwrite, below it you buy attrition and slowness for nothing, and the target is to operate inside it; (2) a fractal network of bands, one per division and team, consolidated upward, mirroring the fractal register structure; and (3) revealed rather than declared — it is computed from two signals: what the business has paid to reduce in the past, and every fresh acceptance decision going forward. It therefore already exists in any organisation that has been operating for a while, and the work is to read it off rather than to write it down. The gap between declared and revealed appetite is the finding, and it is itself a rateable meta-risk. Prior art: “Finding the Good Enough Threshold” (docs.diniscruz.ai, 6 July 2025, CC0) makes the argument a year before the vocabulary existed. Not implemented in code. ============================================================================== == /ladder/index.html ============================================================================== # The grounding ladder The definitional spine of the whole model, and the part an agent most needs to hold. Every node type is defined by the paths it is required to have, not by what it contains. Downward paths confer grounding — is this real? Upward paths confer classification and implication — what is it, and why does it matter? A Vulnerability is not a special kind of Fact. It is a Fact with an upward path to a Risk. ## Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk → Top Risk Realityhas_twinTwinmeasured_byMeasureproducesEvidencebacksFactgives_rise_toVulnerabilitygives_rise_toRiskrolls_up_toTop Risk Read downward it is an answer to “how do you know?”. Read upward it is an answer to “so what?”. Both directions are typed, and neither is optional. 1 ### Reality The running system, the actual estate, the world. Not a record of it — the thing itself. Everything in the graph is ultimately an assertion about this, and the only rung that is not a node in your model. 2 ### Twin A representation of a piece of reality, connected to it. The twin is where the graph stops modelling and continues into a real system — an inventory that is actually synced, a config that is actually read. How connected a twin is to reality is itself a measurable property, which produces a useful recursion: trust in a measure depends on the twin's connectedness, and that connectedness is itself a measure. A twin not connected to reality is a tracked air gap. 3 ### Measure An observation taken through the twin. A Measure is not the floor. That is the most common misreading of the ladder: a measurement feels like bedrock, but it is grounded further, in the twin and through it in reality. A measure with no twin beneath it is a number nobody can defend. 4 ### Evidence What a measure produces, and what a fact is backed by. Evidence is a first-class node, so it can be counted, dated, attributed and — crucially — found to be absent. Not knowing is a fact → 5 ### Fact A statement about reality that evidence backs. Admin accounts do not require a second factor. Logs are retained for thirty days. Facts are the layer where a register and reality touch, and a register built on unevidenced facts is a register of opinions. 6 ### Vulnerability A Fact with an upward path to a Risk. Nothing about the fact changes when it becomes a vulnerability; what changes is that something above it now depends on it. This is the rung that makes the whole formula idea click, and it is why classification is dynamic: add the upward edge and the fact is promoted; remove it and it is demoted. 7 ### Risk A business consequence that a vulnerability gives rise to, and the level at which acceptance happens. One vulnerability commonly gives rise to several risks in different dimensions — confidentiality, integrity and availability each spawn their own, and each follows the full confirm-accept-propagate loop. 8 ### Top Risk What risks roll up to at the highest altitude. The chain converges: pushed far enough, business risk converges on the single risk of staying in business, which is why a legitimate single number can be carried to the top at all. Five whys as a domain translator → ## Downward grounds, upward classifies The two directions are not symmetrical, and keeping them straight is most of the value: | Downward | Upward | Question | How do you know this is real? | What is it, and why does it matter? | Confers | Grounding | Classification and implication | Failure | An assertion nobody can defend | A true statement nobody has a reason to act on | Example | A risk with no fact beneath it is somebody's worry | A fact with no risk above it is trivia — accurate, evidenced, and irrelevant | “A Fact becomes a Vulnerability purely because of its upward link to a Risk, so that legitimacy is conferred entirely from above.” ## Where the ladder stops — a test, not a rung Every grounding chain has to stop somewhere, and the obvious answers are all wrong: not at the measure, not at the tool, not at wherever the data happened to come from. The corpus gives a test instead of a level: The floor is the last node where going deeper would neither improve observability nor change a decision. This is a good rule and an under-worked one. It is decision-relative, which means the same graph can have different floors for different questions, and it means the floor moves when the decision changes. Open question Q7: no worked example in the corpus applies the test to a genuinely hard case, so how it behaves at the margin is unknown. ## The worked example the source uses: the untested restore Backup systemhas_twinBackup config + logsmeasured_by“restore tests in last 12 months”producesE5: zero records foundbacksF: no restore has been testedgives_rise_toV: recovery capability unprovengives_rise_toR9: data loss is unrecoverable in practice Note that the measure returned zero, and the zero is the evidence. A documented absence is a measurement, not a missing one. ## The boundary with graphs.sgit.ai Node type formulas as a mechanism belong to graphs.sgit.ai; the grounding ladder as a risk formula belongs here. This site cites the mechanism rather than restating it — the general case for directed edges with named inverses, query paths that prevent node explosion, and digital twins in their general form is argued at length there and is not re-argued here. What is risk's own is this specific chain, its stopping test, and what each rung licenses you to say. The full boundary map → ## Provenance Concept C6 — The grounding ladder Source team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…grounding-ladder…md Repository SGraph-AI__App__Send @ v0.33.36, never published — the version tag is the address First written 28 June 2026 Maturity well-developed — the most rigorous document in the corpus, and the one agents most need Licence CC BY 4.0 at source and here #### For an agent C6 — the grounding ladder. Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk → Top Risk. Every node type is defined by its required paths, not by its content. Downward paths confer grounding (“is it real?”); upward paths confer classification and implication (“what is it, why does it matter?”). Key definitions to carry: a Vulnerability is a Fact with an upward path to a Risk — legitimacy is conferred entirely from above, so promotion and demotion are edge events, not re-assessments. A Measure is not the floor: it is grounded further in a Twin and through it in Reality. The floor is a test, not a level — the last node where going deeper would neither improve observability nor change a decision. A risk with no fact beneath it is a worry; a fact with no risk above it is trivia. The general graph machinery (directed edges with named inverses, query paths, twins in general form) belongs to graphs.sgit.ai and is cited rather than restated here. Not implemented in code. ============================================================================== == /ladder/formulas.html ============================================================================== # Node type formulas The mechanism beneath the ladder, and arguably the most transferable idea in the corpus. What a node is should be computed against the graph rather than decided in a classifier's head. A node type formula is a required pattern of typed, directed paths; a node either matches it or does not. Classification becomes a query. “the ontology definition of a node type is its upward and downward path-pattern, not a sentence about what it contains.” ## What a formula looks like The corpus's own example, from the AWS IAM layer where the ladder was applied to a second domain: AcceptableForInterval := a Risk with an accepted_by path to an AcceptanceDecision carrying an owner, a direction, an interval, and a sign-off. Read it as a test rather than as a description. Given a node and a graph, the formula either matches or it does not, and the answer is checkable by anyone with the same graph. Compare with the sentence it replaces — “an acceptable risk is one that has been properly signed off” — which is unfalsifiable, because “properly” is doing all the work and is defined nowhere. Riskaccepted_byAcceptanceDecisionhas_ownerOwner …and has_direction, has_interval and signed_by must also be present. Four required edges; miss one and the node does not match. ## Classification becomes dynamic and path-relative If a type is a path pattern, then type membership changes when the paths change. That is not a defect to be engineered around — it is the property that makes the model honest about what classification actually is. Event | What happens | In a conventional model | A gives_rise_to edge is added from a fact to a risk | The fact is now a vulnerability. No re-assessment, no reclassification meeting — the edge is the promotion | Someone must notice, re-rate it, and update a field | The risk above it is closed and the edge removed | The node is a fact again. Demotion is an edge event too | The vulnerability record stays, stale, until a cleanup that never comes | Two teams disagree about whether something is a vulnerability | They are running different formulas over the same graph, and both answers are correct under their own. Bridges, not merges → | An argument about words, settled by whoever is more senior | ## Bias does not disappear — it relocates, which is the point The strongest claim on this page, and the one worth arguing with. Formulas do not remove judgement from classification; they move it out of the classifier's head and into an artefact. Bias does not disappear. It moves into the formula, where it is visible, versioned and arguable. Two parties who disagree about whether a finding is a vulnerability currently trade intuitions, seniority and vocabulary. Under formulas they diff two definitions. That is a smaller, sharper and settleable disagreement — and one that leaves a record, because the formula that won is written down and dated. It also makes a class of quiet failure visible. If a business unit's formula for “critical” has an extra required edge that almost nothing satisfies, that unit will report very few critical risks — and under prose definitions nobody could see why. Under formulas, the reason is a line of the definition. When the business downgrades everything → ## Where formulas have been written down Domain | Scale | Notes | The grounding ladder | 8 rungs | The canonical chain, each rung defined by its required upward and downward paths. The ladder → | AWS IAM configuration risk | 6 layers · ~31 node types · 20 edge types (40 readings, counting inverses) · 7 node type formulas | The second domain the method was applied to, and where AuthorizationClosure appears as a first-class type. Blast radius → | The 2FA instance ontology | 24 node classes · 34 edge types | Includes Acceptance and Interval as node classes with accepted_by, has_interval, propagates_to, underwritten_by and overrides. The graph → | RAMM | 5 levels, expressed as graph predicates | ⚠️ Only Level 3 has a stated predicate — “all acceptance nodes have the five required edges”. Levels 1, 2, 4 and 5 are underspecified → | The open question the mechanism rests on. Q1 — what is the formula language? Every formula in the corpus is written in English prose that describes a path pattern. No notation is defined, no parser exists, and nothing executes one. The canonical brief names this as its own open question rather than glossing it, and this page does the same: node type formulas are a well-developed idea and an unimplemented mechanism. Until the language exists, “classification is a query” is a claim about how classification should work, not a description of a system that runs. ## Provenance Concept C7 — Node type formulas (classification as a testable path-pattern) Source team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…node-type-formulas…md Repository SGraph-AI__App__Send @ v0.33.36, never published — the version tag is the address First written 28 June 2026 Maturity well-developed as a mechanism — but the formula language is an open question, named as such in the source Licence CC BY 4.0 at source and here #### For an agent C7 — node type formulas. Define a node type by the pattern of typed, directed paths it is required to have, not by a sentence about what it contains. A node either matches the pattern or it does not, so classification is a query against the graph rather than a judgement in someone's head. Consequences: classification is dynamic and path-relative — adding a gives_rise_to edge promotes a Fact to a Vulnerability, and removing it demotes it, with no re-assessment step; and bias relocates rather than disappearing — it moves from the classifier into the formula, where it is visible, versioned and arguable, so two parties who disagree diff definitions instead of trading intuitions. Worked example of the notation: AcceptableForInterval := a Risk with an accepted_by path to an AcceptanceDecision carrying an owner, a direction, an interval, and a sign-off. Important limit: no formula language is defined and nothing executes a formula — every formula in the corpus is English prose describing a path pattern. That is open question Q1. Not implemented in code. ============================================================================== == /ladder/bridges.html ============================================================================== # Bridges, not merges Two parties disagree about what counts as a vulnerability. The instinct is to reconcile the definitions into one schema. That is the wrong move: it erases the view that was worth having. Instead, keep one shared factual graph, let each party own their own formula over it, and connect the two at declared bridge points. ## Three layers 1 ### The shared factual graph Facts, evidence, measures, twins. What is actually true about the estate — the part everyone can agree on, because it is grounded rather than interpreted. This layer is shared and should be the only shared one. 2 ### Per-party formulas Each party runs their own node type formulas over that shared graph. A node can be a vulnerability under one formula and not under another, and both answers are correct — they are different queries over the same data, not competing claims about it. 3 ### Declared bridges Where the two views connect, the connection is stated as an edge with a name and a direction, rather than implied by a shared label. A bridge is a claim you can inspect, version and disagree with. “We do not fold their definition into ours, which would erase the security-centric view that is the whole point of having it. We declare a bridge: a Security Failure gives rise to a Business Risk.” ## The worked bridge: a security-centric vulnerability formula The corpus does not leave this abstract. It takes a published, security-centric definition of “vulnerability” — the formulation associated with Art Manion, Jay Jacobs and Michael Roytman, built from System, Fault, Security Failure and Conditions — and bridges it to the business-centric one rather than arguing with it. The finding is better than a reconciliation. The security-centric formula turns out to be a sub-path of the business-centric one: SystemhasFaultunder Conditions gives rise toSecurity Failure Their chain. Now the bridge, at the terminus: Security Failuregives_rise_toBusiness Riskaccepted_byAcceptanceDecision Their Security Failure plays exactly the structural role of the promotion edge in the grounding ladder. The two formulas differ only in where they stop. That is a substantive result rather than diplomacy. It says the disagreement was never about what a vulnerability is — both formulas describe the same promotion structure — but about which terminus the discipline cares about. A security practice terminates at the security failure because that is where its remit ends; a business register continues one edge further, to the consequence someone has to underwrite. Neither is wrong, and merging them would have destroyed exactly the information that made the comparison useful. Attribution and right of reply. The source document names three real researchers and is explicit that it paraphrases their definitions rather than quoting them — “Their definitions are paraphrased; see Sources”. That care is preserved here. The treatment is favourable, the bridge is offered as a contribution rather than a correction, and the corpus's own stance applies: “Offered to be built on and challenged.” If any of the three would like the characterisation amended or removed, ask N6 on the comms board is the standing offer of a right of reply. ## Why merging is the failure mode | Merge into one schema | Bridge two formulas | What happens to the disagreement | Erased. One definition wins and the other becomes unspeakable | Preserved and made explicit as an edge between two named views | Who has to agree | Everyone, before anything works | Nobody, on the definitions. Only on the facts — which is the layer where agreement is achievable | Cost of a new party joining | Renegotiate the schema | Write one formula and declare its bridges | What a mismatch tells you | Nothing — it was normalised away | Something real: where two disciplines draw the line differently, and why | ## The same move, applied to regulation A regulator's definition of an obligation and a company's definition of a control are exactly the two-formula case, and bridging rather than merging is what keeps a compliance claim honest. The Regulation Graph vault carries the EU AI Act as 1,523 nodes and 1,944 edges parsed from official Formex XML and hash-verified — 113 articles, 500 paragraphs, 417 points, 180 recitals, 13 annexes and 68 definitions. Those are the regulator's nodes, in the regulator's structure, not a paraphrase. Risk's claims against them are then declared bridges, and deliberately narrow: Article 9(5) as the undefined “acceptable”, Article 14 as the plug obligation, and Article 26(5)/(6) as the worked example anchor. Three bridges, each one stated, each one arguable. Why the wider regulation thread is not this site's → ## Provenance Concept C8 — Ontologies of ontologies — bridges, not merges Source team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…ontologies-of-ontologies…md and …bridge-vulnerability-formula…md Repository SGraph-AI__App__Send @ v0.33.36, never published — the version tag is the address First written 28 June 2026 Maturity well-developed — with one fully worked external bridge Licence CC BY 4.0 at source and here #### For an agent C8 — ontologies of ontologies: bridges, not merges. When two parties define a type differently, do not merge their schemas — merging erases the view that made the second definition worth having. Use three layers: (1) one shared factual graph of facts, evidence, measures and twins; (2) per-party formulas over it, so a node can be a vulnerability under one formula and not another and both answers are correct, being different queries over the same data; (3) declared bridges — the connection stated as a named, directed edge rather than implied by a shared label. Worked proof: the security-centric vulnerability formula (System · Fault · Security Failure · Conditions, associated with Manion, Jacobs and Roytman, paraphrased in the source) is structurally a sub-path of the business-centric one — their Security Failure plays exactly the role of the promotion edge, and the two differ only in terminus. The bridge is Security Failure gives_rise_to Business Risk. Same move applied to regulation: the EU AI Act is carried as the regulator's own 1,523-node graph, and risk's claims against it are three narrow declared bridges. Not implemented in code. ============================================================================== == /ladder/absence.html ============================================================================== # Not knowing is a fact Absence of evidence is a first-class node. A measure can be a documented zero — “zero tested-restore records found” is as much a measurement as any positive count. An unevidenced fact is recorded as unevidenced rather than left blank, which is what makes it countable, queryable and assignable to someone. “not knowing a fact is also a fact. Lack of evidence is also evidence, because then we say we do not know, and somebody needs to investigate until we do.” ## The difference between a blank and a zero In a spreadsheet register, three completely different situations look identical: the field is empty. Situation | In a spreadsheet | In this model | Somebody looked, and found nothing | empty cell | A Measure returning zero, producing Evidence: “zero records found, checked on this date, by this method” | Nobody has looked yet | empty cell | A Fact marked unevidenced, which spawns its own risk and can be assigned | Somebody looked and never wrote it down | empty cell | Indistinguishable from the row above — and that is itself the finding | The first is a strong result. We checked, and there are no records of a tested restore in twelve months is a defensible, dated, attributable statement about the world. Collapsing it into the same blank as “nobody has looked” throws away the most expensive information in the register. ## Gaps spawn their own risks An unevidenced fact is not a hole in the register; it is a node with edges. And one of the edges goes upward, because not knowing has a business consequence of its own: “the full extent of the impact has not been captured, which means the risk is not yet correctly classified or correctly accepted.” That sentence is a risk statement, and it can be rated, owned and given an interval like any other. It usually gets a short one — the one-hour rung exists precisely for this: I cannot decide on what I have; someone must get me more data. An unevidenced fact and the one-hour interval are two halves of the same mechanism. It also produces the cleanest instance of the meta-risk family: a risk that has been accepted on the basis of an unevidenced fact is an acceptance of something that may not be true, and that is a governance failure independent of whether the underlying fact turns out to be correct. ## The question node, and why unanswered ones are the output Late in the corpus, absence gets its own node type. A Question is a first-class node with an answers edge that may or may not exist yet — and the striking claim is about which ones matter: Unanswered question nodes are the most productive output of the whole exercise. In the Article 26(5) worked example, the graph carries nine questions, five of them unanswered, and the source document says of them: “those five are the actual output of the exercise.” Not the risks, not the ratings — the five things nobody could answer. That inverts what a risk assessment is normally judged by, and it is the honest inversion: an assessment that produced no unanswered questions almost certainly did not look hard enough. The related quality gate is a question is not a risk: if a sentence cannot sensibly carry a named acceptor and an interval, it is a question rather than a risk and belongs in a different node type. “Nobody accepts ‘whose call is it at three in the morning' for six months.” ## Rendered: ghosted means unanswered The Risk Graph Explorer makes this visible rather than argued, using a three-colour convention across every view it draws: amber — exposure green — assurance ghosted — unanswered Ghosting-for-unanswered is this concept rendered. Nothing else in the estate makes an absence visible on the picture — and once it is visible, an executive looking at a graph that is half ghosted has learned something no summary would have told them. The vault is live and browsable with no account and no network access: permissions: {}. Open it → ## Absence as the widest confidence band Confidence is a first-class property of every node, and it is a band rather than a point — widest where the data is thin. “We don't know” is simply the widest band there is, which is what connects this page to the evidence economy: a band too wide for comfort is the trigger that converts unease into a purchase order for better evidence. A band spanning trivial to catastrophic cannot be accepted responsibly by anyone, at any interval. Confidence bands → ## Provenance Concept C17 — Not knowing is a fact (absence of evidence as first-class) Source team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…facts-only-no-deny-cascade-cia-blast-radius.md Repository SGraph-AI__App__Send @ v0.33.35, never published — the version tag is the address First written 26 June 2026; questions as nodes, 2 August 2026 Maturity well-developed — and demonstrated as fact F7 in the Article 26(5) example Licence CC BY 4.0 at source and here #### For an agent C17 — not knowing is a fact. Absence of evidence is a first-class node, never a blank. Distinguish three states a spreadsheet collapses into one empty cell: (a) somebody looked and found nothing — that is a Measure returning zero, producing dated, attributable Evidence (“zero tested-restore records found”), and it is a strong result; (b) nobody has looked — that is a Fact marked unevidenced, which is countable, queryable and assignable; (c) somebody looked and did not record it — indistinguishable from (b), which is itself a finding. An unevidenced fact spawns its own risk: “the full extent of the impact has not been captured, which means the risk is not yet correctly classified or correctly accepted” — usually accepted at the one-hour rung, which exists for exactly this. A Question is its own node type, and unanswered questions are the most productive output of the exercise (in the Article 26(5) graph, five unanswered of nine: “those five are the actual output”). Rendered convention: amber = exposure, green = assurance, ghosted = unanswered. Not implemented in code, though the ghosting convention runs live in the Risk Graph Explorer vault. ============================================================================== == /register/index.html ============================================================================== # The register as a graph of graphs A risk register is not a spreadsheet at the top of a company. It is a hyperlinked semantic graph — one per accepting entity, all of them views of one connected structure rather than parallel lists. Its distinguishing move is where it starts: at the vulnerability, which is exactly where scanners and security products stop. “a lot of security teams and products end on the vulnerability, and what I want to show is the multiple layers involved in fixing it, but even before that, in accepting the risk, funding the solution, and finding who is going to do it.” ## It begins where scanners stop A scanner's output is a list of vulnerabilities, and its implicit theory is that the hard part is finding them. In practice the finding is the cheap part. What follows is where the work is, and none of it is in the scanner's output: 1 · WHO CONFIRMS ITThe technical owner validates that the vulnerability is real in their domain. Factual, and either true or false. Confirmed → 2 · WHO OWNS THE CONSEQUENCENot the same person. The business owner owns the risk the vulnerability gives rise to, which is usually in a different department and a different vocabulary. Technical vs business owner → 3 · WHO ACCEPTS IT, AND FOR HOW LONGThe underwriting act, at the right altitude, on the interval ladder. 4 · WHO FUNDS THE FIX, AND WHO DOES ITThe interval already committed the organisation to a response. This is where that commitment turns into a project with a name against it. ## Fractal: one register per accepting entity Wherever there is a stakeholder who accepts risk, there is a register. For the company, for a department, for an individual role. That is not an organisational nicety — it follows directly from acceptance being a personal act: if a named person underwrites, they need a place where the things they have underwritten are listed. Most of those registers are derived rather than curated. An individual has at least two and often three: their own role-specific register in their own domain language, plus views of the registers above them. Only the role's own register is stored; the rest are queries. Register | Stored or derived | Whose language it is in | The role's own | Stored | The role's — a DBA's register says “unrestricted access to the customer table” | The department's, seen from the role | Derived | The department's, with the parts that trace back to this role lit up | The board's, seen from the role | Derived | The board's — “regulatory penalty, loss of licence, continuity failure” | ## Relevance fade, and why it teaches The visualisation property that falls out of the fractal structure, and the most quietly powerful idea in this section. Centre a view on a role: that role's register is lit in full, and the registers above it fade — except for the entries that trace back down to this role, which stay lit. “as you go up, imagine the colours can fade away for the next registers for the bits that are not relevant, so the graph starts to point which parts of the risk register above are relevant to this individual, so that he understands the picture.” A database administrator can see that their local “an agent holds unrestricted access to a customer table” is the same object as the board's “regulatory penalty, loss of licence, continuity failure”. Seeing that once teaches more than any training course. partially argued The visualisation is described and has not been built. ## One chain, not parallel lists A late correction (2 August 2026) and a consequential one. Three altitude registers drawn side by side demonstrate a formatting capability. Drawn as one chain rooted in an existence fact, they demonstrate the entire thesis. F1: an agent has write access to productiongives_rise_toL1: the operator's riskgives_rise_toL3: the CISO's riskgives_rise_toL5: the board's risk The CISO's risk exists because of the operator's risk, which exists because of a fact. Side by side, that dependency is invisible; as a chain, it is the point. “at the moment it looks like the cards, they look side by side, and it's actually not that.” ## Cascade, and the air gap Every change to any risk, fact or piece of evidence must trigger a cascade that reaches the top. The absence of a cascade has a name: “every time any risk, any fact, any evidence changes, you have to trigger a cascade that reaches the top. If you do not have that, you have an air gap, which means you do not have good data, and you cannot make good decisions.” Air gap is used in two senses, and both are useful. A missing cascade is one. A risk that exists in the business but is not connected to the register at all is the other — and it is the more dangerous, because nothing about the register indicates it is there. A twin that is not connected to reality is a third instance of the same shape. Cascade runs in both directions, which is easy to miss: a risk resolving propagates upward too, clearing it from the board's view. A register that only ever accumulates is as misleading as one that never updates. Detecting air gaps is an acknowledged open problem. The principle is well developed and the detection mechanism is not specified — by construction it is hard, since an air gap is defined by the absence of a connection nobody recorded. The corpus states this rather than glossing it. ## The register as a story The last idea in this section, and the one furthest from being built. The register is meant to be experienced rather than read: replay its change history through timestamps, commits or a series of queries, and watch the vulnerability appear, the risks propagate, a governance risk fire and resolve, the blast radius bloom, and everything settle into the board's consolidated view. “I want to show this story played as a narrative, almost like a football commentator, this happens and then that happens, almost like a whodunit, like investigative journalism.” The commit log is the script and the query advances the scene. partially argued — the mechanism is undecided in the source document. The nearest thing that exists is the Risk Mandate vault's 98 commits, which is the method applied to its own build and is a change history somebody could replay. ## Provenance Concepts C9 register as a graph of graphs · C10 fractal registers · C11 relevance fade · C12 one chain not parallel lists · C16 cascade and air gaps · C42 the narrative engine Sources briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…graph-of-graphs…md · briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…fractal-risk-registers…md · briefs/08/02/field-demo/v0.33.55__arch-brief__…registers-are-one-chain…md First written 26 June 2026 · 17 July 2026 · 2 August 2026 Maturity well-developed for the register, fractal structure and cascade · partially argued for relevance fade and the narrative engine Licence CC BY 4.0 at source and here #### For an agent The register (C9, C10, C11, C12, C16, C42). A risk register is a hyperlinked semantic graph, not a spreadsheet, and it begins at the vulnerability — where scanners stop — and maps confirming, owning, accepting, funding and staffing the fix. It is fractal: one register per accepting entity (company, department, role), of which only the role's own register is stored — the rest are queries. Relevance fade: centring a view on a role lights that role's register in full and fades the registers above it except for entries tracing back down, so a DBA can see their local exposure and the board's “regulatory penalty” are the same object. Registers are one chain, not parallel lists — the CISO's risk exists because of the operator's risk, which exists because of an existence fact; drawn side by side that dependency is invisible. Cascade: any change to any risk, fact or evidence must propagate to the top, in both directions (resolution clears the board's view too); a missing cascade, or a risk not connected to the register at all, is an air gap, and detecting air gaps is an acknowledged open problem. Not implemented in code; relevance fade and the narrative engine are not even specified. ============================================================================== == /blast-radius/index.html ============================================================================== # Blast radius and authorization closure An agent's real authorization is the transitive union of everything reachable from what it was given — not the nominal grant. The gap between those two is where the exposure lives, and computing it turns “what could this thing do?” from a question people answer with intuition into one a query answers with a number. ## Authorization closure The mandate states what an agent is authorised to reach. The authorization closure states what it can reach — computed, not asserted, and not a record of what it did. Three things are being kept apart, and conflating any two of them is the usual mistake: Quantity | What it is | How you get it | The grant | What was explicitly given — the role, the token, the scope | Read it off the configuration | The closure | Everything transitively reachable from the grant | Compute it. Walk the graph until it stops expanding | The activity log | What it actually did | Read the logs — and note that this is the smallest of the three, and the one people usually look at | AuthorizationClosure is a first-class node type in the AWS IAM ontology — 6 layers, ~31 node types, 20 edge types (40 readings counting inverses) and 7 node type formulas — where it is defined as the agentic union of the possible. How formulas scale → ## Two awareness gaps hide the delta GAP 1 · THE GRANTER DOES NOT KNOW THE SCOPE OF WHAT THEY GRANTGranting inbox access feels like granting access to email. It is access to every account whose password can be reset by email — which is most of them. The granter is not careless; the scope is genuinely not visible at the moment of granting. GAP 2 · THE DELEGATOR NEVER AUTHORISED RE-DELEGATIONThe person who gave the agent a credential did not agree that the agent could hand its reach to a sub-agent, a tool or a scheduled job. Nothing in the grant said it could not, either. The key quantity is the delta between expected and unexpected permissions — not the size of the closure, but the size of the part nobody meant to give. ## Three examples that land immediately What was granted | What the closure contains | Access to an inbox | Every account resettable by email — which is a large fraction of everything the person can log into | Access to a desktop | Every stored credential, every logged-in session, every saved token, every VPN profile | The ability to execute code | Whatever that code can escalate to — frequently admin, and always more than the grant named | These are not exotic attack paths. They are the ordinary consequences of a grant, visible to anyone who works the transitive closure by hand — which is precisely why the corpus's insistence that it be computed matters. Hand-working it does not scale past one example, and the anti-pattern it replaces has a name in the source: hope-driven development. “at the end of the day you are still accountable for those actions, all the way to the board.” ## CIA expansion: where most registers stop is where this one starts From a single risk, expand along three axes. Each branch spawns its own risks, and each of those follows the full confirm-accept-propagate loop with its own owner and its own interval. C ### Confidentiality A leak becomes a regulatory exposure, and the regulatory exposure splits into two distinct risks with different owners: the CFO's, for the fine, and the CEO's, for the compliance failure. And note the sharper reading — inadequate protection may already be a breach, before any data has moved. I ### Integrity Salary tampering, fabricated hires, altered performance data. The under-modelled axis, because it produces no alert — nothing is missing, the numbers are just wrong, and they stay wrong until something downstream fails to reconcile. A ### Availability Backup cadence gaps, and the question that reliably produces the worst answer in the room: when was a restore last tested? That question is where the grounding-ladder worked example starts, and the honest answer is usually a documented zero. The tension the source records about its own method. The expansion must be curated, not exhaustive, or it blows up combinatorially: every risk branches into three, each of those into three, and within four levels the register is unreadable and useless. The corpus names this as an unresolved tension rather than claiming the expansion is safe to automate — and it sits directly against the register-density argument, which says a complex product should carry thousands of risks. Both are in the corpus; neither resolves the other. ## Data classification is the multiplier The same vulnerability against two datasets is two very different risks, and the register needs the classification node to say so. From the 2FA worked example: Class | Contents | Effect on the blast radius | DC-1 | Full HR data — passports, salaries, bonuses, PIPs, reviews, hires, fires, dismissals | Regulatory, financial and reputational, in every direction at once | DC-2 | Anonymised timesheets | Materially smaller in every dimension | ## Observability is the other half of the picture Capability maps the privilege; observability maps the real impact. Six objective vectors on a maturity scale: capture granularity, log latency, time-to-damage given real throughput limits, whether monitoring is actually on and watched, whether there is a team with playbooks, and whether detection has ever been drilled. A loud, detectable, slowly-scaling, well-drilled risk is lower than a quiet, fast, unwatched one of the same capability. Later sharpened into plug-loaded observability — logs that tell you where you are in the stopping decision, rather than generic logging that tells you what happened after you no longer need to know. That connects this page directly to the detection floor: a hyperscaler cost-reporting delay of 12–18 hours is a hard limit on how fast anyone can know, whatever the logging maturity. ## Provenance Concepts C19 blast radius / authorization closure · C18 CIA expansion · C39 observability as a risk dimension Sources briefs/07/02/authorization-and-maturity-model/v0.33.40__arch-brief__…agent-authorization-union-of-possible…md · briefs/07/05/aws-configuration-risk-engine/v0.33.44__arch-brief__…aws-iam-config-risk-ontology…md · briefs/06/22/how-and-why-and-authorization/v0.33.32__arch-brief__observability-as-a-risk-dimension…md First written “blast radius” from 12 February 2026; formalised as closure 2 July 2026; observability 22 June 2026 Maturity well-developed — and newcomer-followable: the inbox example lands instantly Licence CC BY 4.0 at source and here #### For an agent C19, C18, C39 — blast radius. Keep three quantities apart: the grant (what was explicitly given, read from config), the authorization closure (everything transitively reachable from the grant — computed, and a first-class node type), and the activity log (what it actually did — the smallest of the three, and the one people look at). Two awareness gaps hide the delta: the granter does not know the full scope of what they grant (inbox access is access to every email-resettable account; desktop access is every stored credential and live session; code execution escalates), and the original delegator never authorised re-delegation to sub-agents or tools. The key quantity is the delta between expected and unexpected permissions, not the raw size of the closure. CIA expansion: each risk branches into confidentiality (a leak splits into two distinct risks — the CFO's fine and the CEO's compliance failure — and inadequate protection may already be a breach), integrity (tampering, which produces no alert) and availability (“when was a restore last tested?”). The expansion must be curated, not exhaustive, or it explodes combinatorially — the corpus records this as unresolved. Observability maps real impact where capability maps privilege: a loud, detectable, slow, well-drilled risk is lower than a quiet, fast, unwatched one of the same capability. Not implemented in code. ============================================================================== == /plug/index.html ============================================================================== # Who can pull the plug Two symmetric risks, and most organisations have only noticed the first. If nobody holds the mandate to stop an AI system, that is one risk. If the system cannot be stopped even when someone decides to, that is a second and different one — an authority gap versus a capability gap. The second is widely underestimated, and the four capabilities that have to line up to close it must line up inside the same window. “if you do not have somebody who has the mandate to pull the plug, you have a risk, and if you do not have a system that can be pulled the plug, you have a risk too.” ## The authority gap decomposes into timed sub-risks “Can we stop it?” is not answerable as a yes or no. It decomposes into a set of dated questions, which is what turns governance into an on-call availability problem: - Can it be stopped in an hour? In ten hours? In a day? In five days? - Only during office hours, or at three on a Sunday morning? - Can the person who holds the switch act without fear of losing their job? - Is there a clear escalation path when the first person cannot be reached? That third one is not a soft consideration. A stop button that only a person risking their career will press is, operationally, a stop button that does not exist at three in the morning. ## The four-way time intersection Four capabilities must line up inside the same window. A gap in any one breaks the whole thing, which is why they are drawn intersecting rather than listed. 1 · detectionHow fast you knowAnd under which scenarios — a curve, not a binary. Some failures announce themselves; others are visible only in a billing line. 2 · decisionWhether the authorised people can be assembledIn time, with the standing to act, and with enough information to act on. 3 · blast radiusHow fast the damage scalesModels execute and scale fast, especially when connected. A steep cost curve, not a linear one. 4 · reversibilityWhether you can put it backStopping is only half the act. Reverting requires journaling and backups that were in place beforehand. “it is not just pulling the plug, it is pulling the plug and reverting the changes.” The danger case is specific and worth naming: a steep cost curve where an affordable window of one or two days of damage collides with a decision that cannot be made in one or two days. The organisation can afford the damage and cannot afford the delay, and nobody notices until the two are measured against each other. ## The detection floor is a hard number Figure | What it means | 12–18 hours | Hyperscaler cost-reporting delay. For any failure that surfaces first as spend, this is a floor on how fast anyone can know — no logging maturity beats it | 16 hours | The founder's own AWS figure: “AWS usually takes 16 hours to give you the data, so how much damage can be done in 16 hours.” | up to 24 hours | The billing-lag damage window recorded against the cost blast radius | Numbers like these are what make the intersection concrete. If detection floors at twelve hours and the blast radius is steep, then no amount of decision-making authority helps — the exposure is already realised before the decision is available to be made. That is an argument for prevention, and it is the honest one. Observability as a risk dimension → ## The correction: the plug always exists This is the pillar correction of the whole series, and it is the reason the page is called who can pull the plug rather than whether there is one. The plug always exists. You can always disconnect, revoke, or shut down. What earlier registers recorded as “no plug” was never a missing off-switch — it was zero recoverability. A data breach has a plug: you can cut the connection. A used credential has a plug: you can revoke it. What neither has is a way back — the data is out, the foothold was used. Recording that as “no plug” conflates two very different findings and produces a blank in the register. “The blank said stop looking. The corrected profile says here is exactly what to do.” The restatement is not cosmetic. A blank is unassignable and unfundable. A finding that reads “stoppable in minutes by the platform team, blast radius large, side effects severe, recoverability zero” points straight at prevention and at the most senior acceptance — and can be given an owner and an interval like anything else. Recoverability, the hard limit → ⚠️ A live inconsistency, stated rather than tidied. The corpus records this correction. The published page it moved from does not reflect it. One of the two is wrong, and until the source is reconciled this site publishes the corrected version and says so. This is open ask N1. ## The five-dimension plug profile What replaces a yes/no answer. Every stoppable thing gets a profile with five dimensions, and the profile is the finding: dimension 1Who holds itWhich role can actually pull it — and at which altitude. The answer changes at every level of the organisation. dimension 2Blast radiusWhat else stops when this stops. The plug is a sledgehammer, and pulling it has its own risks. dimension 3SpeedHow fast, in the worst realistic case, not the demo case. Minutes, hours, or a contractual notice period. dimension 4Side effectsWhat breaks, who is affected, and what the organisation loses by stopping — the reason a plug that exists sometimes does not get pulled. dimension 5RecoverabilityThe dimension money cannot buy back. The one that separates catastrophic-but-reversible from smaller-and-permanent. → The seven-row worked plug register → — from “agent misuses the isolated session” (IT · small · fast · high recoverability) through “agent misuses the platform itself” (COO/procurement · large · slow and contractual · medium) to “data leaves the boundary” and “unattributable transaction”, both at recoverability: zero. ## The plug is a sledgehammer The symmetric risk on the other side, and easy to forget once you have spent a page arguing that a plug is necessary. Pulling it has a blast radius of its own: stopping the agent stops the work the agent was doing, and everything downstream of that work. A plug that takes out a production dependency may be more expensive than the exposure it was pulled to stop. That is why side effects is a dimension of the profile rather than an afterthought, and why the decision half of the four-way intersection needs information rather than just authority: the person with the switch has to know what else goes dark. ## Article 14 as the plug obligation One of this site's three narrow declared bridges into the EU AI Act. Article 14 requires human oversight of high-risk systems, including the ability to intervene and to stop — which makes the plug profile the natural evidence artefact for demonstrating it. Not a compliance product, and not a claim beyond what the provision says: an obligation to be able to stop, met by a register that records who can, how fast, at what cost, and whether it can be undone. Legal points on this site are factual and are not legal advice. Provisions are cited from the Regulation Graph vault. Why bridges rather than merges → The boundary this site will not cross. The model rates the ability to stop; it does not provide it. The corpus states the refusal directly and notes what it costs: “a customer who scores badly will ask us to supply the stop button, which is exactly the enforcement role the corpus refuses.” In-line enforcement belongs to sg-sentinel.sgit.ai. We measure and evidence; we never sit in-line. The boundary map → ## Provenance Concepts C20 two symmetric risks · C21 the four-way time intersection · C22 the five-dimension profile and the “no plug” correction · C39 the plug is a sledgehammer Moved from https://riskmandate.ai/plug.html · moved 22 August 2026 · ⚠️ republished with the “no plug” correction the source page does not carry Source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…detection-authority-blast-radius-reversibility-intersect-in-time.md — the load-bearing brief, with 12 companion pieces in the same folder First written 24 July 2026 (the phrase appears from 17 February 2026 in another sense) Maturity well-developed — a 13-document series, and newcomer-followable, outstandingly so Licence CC BY 4.0 at source and here #### For an agent C20–C22 — the plug. Two symmetric risks: nobody holds the mandate to stop the system (an authority gap), and the system cannot be stopped even when someone decides to (a capability gap). The second is widely underestimated. The authority gap decomposes into timed sub-risks — stoppable in an hour, ten hours, a day, five days; office hours only; can the holder act without fear of losing their job; is there an escalation path. Four capabilities must line up inside the same window: detection (a curve, not a binary), decision (assembling authorised people in time), blast radius (models scale fast — a steep cost curve), reversibility (“it is not just pulling the plug, it is pulling the plug and reverting the changes”). Hard detection floor: 12–18 hours of hyperscaler cost-reporting delay for anything that surfaces as spend. The pillar correction: the plug ALWAYS exists — you can always disconnect, revoke or shut down. What older registers recorded as “no plug” was zero recoverability, and restating it that way turns an unassignable blank into an ownable finding. Every stoppable thing gets a five-dimension profile: who holds it · blast radius · speed · side effects · recoverability. Pulling the plug is itself a risk (side effects). Boundary: this model rates the ability to stop and never provides it — in-line enforcement is sg-sentinel's. Not implemented in code. ============================================================================== == /plug/recoverability.html ============================================================================== # Recoverability: what money cannot buy back The fifth dimension of the plug profile, and the one that stops irreversible harm disappearing into an expected-loss calculation. Most risk arithmetic assumes that a sufficiently large number on one side can be balanced by a sufficiently large number on the other. Some harms are not on that scale at all. “The money can be refunded; the customer cannot be un-declined.” That line is from the Article 26(5) worked example, where an agent makes creditworthiness decisions. If it declines someone it should not have, a refund is available for any fee — and nothing is available for the decision itself, which was made, communicated, and acted on. The exposure is not large; it is permanent, which is a different axis. ## Why it is an axis and not a severity | Reversible | Irreversible | Large | A production outage. Expensive, visible, survivable — the organisation has done this before and has a playbook | Data leaves the boundary. No amount of money puts it back. This is the quadrant that should carry the most senior signature on the register | Small | A failed job, a retried transaction. Absorbed without a decision | An unattributable transaction. Individually minor, permanently unfixable, and easy to accept by default precisely because it looks small | The bottom-right cell is the one the model exists to surface. A small-but-permanent harm attracts no attention on a severity scale, gets accepted at a long interval by someone junior, and accumulates. A large-but-reversible one attracts a great deal of attention and is, in the end, a cost. Ranking them by size alone gets the priority exactly backwards. ## The flagship query Show me every accepted risk whose recoverability is zero. This is the single most useful thing the whole model can be asked, and the reason it matters is what the answer looks like in each case: THE GOOD ANSWERA short, deliberate, senior-owned list. Every irreversible exposure the organisation carries is there, each with a name against it and a recent date. That organisation is in control of its worst exposure — not free of it, in control of it. THE BAD ANSWERThe query cannot be run. Recoverability is not recorded, so the organisation is accepting its irreversible risks by default and by silence — which is the same state, minus the knowledge. Note that a long list is not the failure mode. A long list is a finding, and an actionable one. The failure mode is a register that cannot produce a list at all, because nothing in it distinguishes what can be undone from what cannot. ## Can you compute your plug profile? The corpus turns that into a maturity probe rather than a question, and it is deliberately unkind: an organisation that cannot answer who holds the plug, how fast, at what cost, and whether it can be undone for a given system has not established that it can stop the system at all — it has established that somebody believes it can. The probe composes with the four-way time intersection: computing a profile requires knowing detection latency, decision availability, blast radius and reversibility as measured quantities. An organisation that can compute the profile has, by construction, measured all four. The plug-pull maturity model → ## What it points at Recoverability is the dimension that redirects effort from response to prevention, and it does so with an argument rather than an exhortation. If a harm cannot be undone, then every control that reduces the chance of it is worth more than every capability that shortens the response to it — because the response, however fast, arrives after the irreversible part has happened. That is also the honest reading of the detection floor. Where detection floors at twelve to eighteen hours and the harm is irreversible, response capability is close to worthless for that risk, and saying so plainly is more useful than promising a faster response nobody can deliver. Open question, published unresolved. Q6 — is recoverability measurable, or only classifiable? The corpus splits reversible from irreversible cleanly and grades nothing in the middle. Most real harms are partially recoverable — a leaked dataset that was already partly public, a transaction reversible for thirty days and not after. Without a way to grade the middle, the dimension collapses into a binary that will be gamed by whoever gets to decide which side something falls on. Named, not solved. ## Provenance Concept C23 — recoverability as the hard limit Source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…what-money-cannot-buy-back-recoverability-the-hard-limit.md · …can-you-compute-your-plug-profile-the-maturity-probe.md Repository SGraph-AI__App__Send @ v0.33.51, never published — the version tag is the address First written 24 July 2026 Maturity well-developed — but the scoring of recoverability is an open question Licence CC BY 4.0 at source and here #### For an agent C23 — recoverability, the hard limit. Recoverability is an axis, not a severity: it stops irreversible harm being absorbed into an expected-loss calculation. “The money can be refunded; the customer cannot be un-declined.” Crossing it with size gives four cells, and the important one is small-but-permanent — individually minor, permanently unfixable, and easy to accept by default at a long interval precisely because it looks small. Ranking by size alone inverts the correct priority. The flagship query of the whole model: “show me every accepted risk whose recoverability is zero.” A short, deliberate, senior-owned list means the organisation is in control of its worst exposure; a long list is a finding; an unrunnable query is the failure, because it means irreversible risks are being accepted by default and by silence. Recoverability redirects effort from response to prevention with an argument rather than an exhortation: where harm cannot be undone and detection floors at 12–18 hours, response capability is close to worthless for that risk. Open question Q6: recoverability is currently binary — nothing grades the partially-recoverable middle. Not implemented in code. ============================================================================== == /practice/index.html ============================================================================== # Practice: owners, altitude and the register's health The organisational altitude of the model. Who confirms, who validates, who accepts, and why they are three different people. What altitude is and why it is a modelling dimension rather than a metaphor. Why the physical act of signing changes executive behaviour. And the four ideas about keeping a register alive — density, meta-risks, self-maintenance, and not internalising what the business decided to carry. ## Technical owner versus business owner The distinction that prevents the corpus's canonical governance failure. The technical owner validates that the vulnerability exists. The business owner owns and accepts the risk it gives rise to. They are almost never the same person, and collapsing them produces an acceptance made by someone with no standing to make it. “most of IT should be technical owners of something, but the business owners are the ones that actually own the risk.” Worked: IT validating that admin accounts lack a second factor is not IT accepting an HR data-breach exposure. In the 2FA example that exact confusion is R2, the governance air gap — a risk accepted by the wrong owner, which then propagates GRC → CIO → CEO → Board as a risk in its own right. The register does not correct the mistake; it makes the mistake visible as an item with a rating. ## Confirmed · Validated · Accepted Three distinct acts, three distinct roles, tracked per risk per altitude: Predicate | Who | What kind of claim it is | Confirmed | The technical stakeholder | Factual. True or false, and checkable against evidence | Validated | GRC / compliance | Interpretive. Does this obligation genuinely apply, and how? Neither a fact nor an appetite judgement | Accepted | The business owner with standing | A judgement about appetite. Is this where we are content to sit, and for how long? | The mismatches are the interesting cases, and they are only visible because the three are tracked separately. A risk accepted but never confirmed is an acceptance of something that may not be true. A risk confirmed but never validated may carry an obligation nobody has read. A risk confirmed and validated but never accepted is critical by default. A single status field cannot express any of these. ## Altitude The corpus's word for organisational elevation, used as a first-class modelling dimension rather than as a metaphor. Five levels appear in the worked examples: L1 endpoint/IT → L2 security → L3 business → L4 enterprise → L5 board. Four things vary by altitude, and each is a modelling consequence rather than a presentational one: - A risk is accepted at the right altitude, and then propagates. Accepting at the wrong one is the governance air gap. - The same risk is restated in each altitude's own language — and it is the same object, which is what relevance fade makes visible. - The plug changes at every altitude: who holds which off-switch is a different answer at L1 and at L5. The plug profile → - A risk may be confirmed at one altitude and accepted at another, which is why the three predicates above are tracked per altitude. “this is very important, the multiple altitudes of the risk register, because there might be risks that are only accepted at certain altitudes, or might be risks that are only confirmed at certain altitudes.” ## The psychology of the physical act Why the model insists on a click, a thumbs-up, a signature — rather than a status change made on someone's behalf. “suddenly the executives ask good questions, they really engage, they get a level of focus that just was not there before, and that is why risk acceptance is so powerful, it drives behaviours that otherwise do not exist.” The act is the moment a decision stops being ambient and becomes something a named person did, at a known time, on known information. Accountability follows, and eventually liability — as it should. Without the act, declining decays into a non-event: someone says “I'm not comfortable” and nothing happens, and the discomfort is neither recorded nor actioned. Underwriting → ## Three moves, none of which is denial The reconciliation of the no-deny mechanic with human reactance. Present a single button to a person who feels they have no alternative and you get counter-argument and resentment, not compliance. The resolution was already in the material: there were always three moves — accept for a stated interval, escalate (“this is not mine to accept”), or challenge the fact itself. The person is routed rather than cornered — and the absence of a reject option should be discovered, not announced. ## Accept first, then adjust the level For a risk you already have facts for, the first move is universal stakeholder acceptance at its current level, on the record. From there the level is not a fixed number but a dated ledger of adjustments, each re-accepted, triggered by one of three things: new data, a funded project, or an incident. Re-rating up after discovery is honesty rather than failure — the risk did not worsen, the estimate improved. The board sees a living trajectory instead of a static red square, and the ledger is only possible because a decision is its own node. “you literally cannot mitigate what you cannot count, and the only honest first step is to accept, now, that an unknown and largely over-permissioned population of agents holds access to the enterprise's assets.” ⚠️ This sits awkwardly with the no-deny mechanic, and the corpus does not resolve it: if the level can be adjusted after acceptance, denial has a route back in through the back door. Carried as a loose end rather than smoothed over. ## Everything has risks — register density The common register failure is holding only big risks and treating the goal as having none. A risk is the unintended side effect of a capability, so anything that does something has risks. Capabilities exceed features, and undocumented capabilities are exactly where unowned risks live. A complex product should have dozens to thousands of interconnected risks, and a register with fifteen entries is a register that has not looked. Calibration by surprise. A listed risk materialising is expected. An unlisted risk materialising is the real alarm — because it raises two questions at once: why was it missed, and what else was missed? ## Risks that cannot be fully mitigated Mitigation lowers likelihood or impact and cannot reach zero for structural reasons, so a material residual always remains and must be owned. Demanding zero produces covert acceptance, which is strictly worse than an owned residual: the exposure is identical and nobody's name is on it. Agentic AI's residual is, today, irreducible — prompt injection, emergence, non-determinism, reach, and the model supply chain. The corpus's honest counterweight, cited deliberately: vendor system cards report browser prompt-injection attack success rates falling from roughly half to about one percent across a single model generation. That is a large, real improvement. It does not reach zero, and “small and non-zero” at machine scale is a different quantity from “small” at human scale. ## Meta-risks — the risk about your risk management A recurring family, named as a pattern on 31 July 2026 after four instances had accumulated: Meta-risk | What it is a gap in | Not knowing how many agents you have | Inventory — and therefore every count downstream of it | Not having defined an acceptable level | The standard itself. Article 9(5) requires the judgement and never defines the word | A risk accepted by the wrong person | Authority — the governance air gap | Systematic downgrading across a business unit | Calibration. Defeated by external anchors: an internal severity is an opinion, an external requirement is not | Each is stated as a rateable risk with an owner and an interval — which is what triggers and funds the work that closes it. “we are the meta risk; we allow the creation of the project that is going to discover this and that funds this.” ## The register maintains itself Why no separate data-quality function is required. Three primitives produce it: the risk already exists, it attaches to a named person, and the decision is reviewed upward. Anticipated review is the engine — it converts care into a demand for evidence before the decision rather than a post-mortem after the incident. The appetite for accurate evidence is a by-product of assigning accountability, so nobody has to fund it separately. Three named failure conditions, stated in the source rather than discovered later: - The reviewer's preference is guessable. People conform to it rather than think, and the review adds no information. - Commitment to a prior position. Having said it once, the reviewer defends it rather than updates. - Broadened information appetite without improved discrimination. More evidence gets gathered; none of it changes anything. The commercial reading of the same mechanism is the force of proof: once executives are personally accountable and the graph traces their statement to the evidence beneath it, demand for correct evidence becomes cheap to make and impossible to wave away. That splits the register into two separately liable roles — the risk-acceptor, who owns the decision and its consequence, and the fact-certifier, who owns the truth of the inputs. Risk owns the demand side of that; newsroom.sgit.ai owns the supply side. The boundary → ## Confidence bands, and the two underwritings Confidence is a first-class property of every node, and a rating needs a band, not a point — widest where the data is thin. A band too wide for comfort triggers the get more data direction; a band spanning trivial to catastrophic cannot be accepted responsibly at any interval. Confidence propagates across the graph the way risk does, and “we don't know” is simply the widest band there is. Absence → Which produces two underwritings, distinct and both required. The domain expert underwrites that a fact is true and fit for the use being made of it. The business owner underwrites the decision. Every graph traversal adds an abstraction layer that strips detail and drifts weight, so the signature failure is a component used beyond what its owner would underwrite — and decision accountability is only legitimate if the data underneath it is correct. ## A question is not a risk A clean quality gate, and one of the few things in the corpus that can be applied mechanically. If a sentence cannot sensibly carry a named acceptor and an interval, it is not a risk. “Nobody accepts ‘whose call is it at three in the morning' for six months.” Questions become their own node type, and unanswered question nodes are the most productive output of the whole exercise. ## Five whys as a domain translator Not a root-cause tool here, but a translator that moves a statement from one domain into another — as many whys as it takes to reach the top of a domain. The graph has natural peaks: on risk it converges to the single risk of staying in business, and because it converges, a legitimate single number can be carried to the top. Aimed downward, the same chain captures the second, third and fourth stories — the root causes. ## Do not internalise the risk The human-cost argument, and the one page in this section that is about people rather than models. Risk professionals routinely internalise exposures the business decided to carry, at real personal cost — the corpus cites survey data of 63–76% of security leaders experiencing or witnessing burnout in a single year, and names accountability without authority as the defining pressure. “I would see the risk professionals almost own the risk; they almost take it personally with the risks that the business was taking, and it was a massive source of stress.” The standard remedy is to give the security leader more authority. That is correct and rarely achievable. This workflow solves the same equation from the other side, by moving accountability to where authority already sits. Nothing is taken from anyone; the register records what was always true. The relief, if it comes, comes from the exposure having a name on it that is not yours. The source carries an honest scope disclaimer, and it is preserved: this is an argument about where accountability should sit, not a clinical claim about burnout. ## Provenance Concepts C13 owners · C14 three predicates · C24 altitude · C26 psychology · C27 the level ledger · C28 density · C29 residuals · C30 meta-risks · C31 self-maintenance · C32 three moves · C34 question-is-not-a-risk · C35 do-not-internalise · C36 evidence economy · C37 confidence bands · C38 two underwritings · C40 five whys Sources briefs/06/30/risk-acceptance-and-appetite/…psychology…md · briefs/07/12/acceptance-and-residual/ (3 docs) · briefs/07/31/keeping-the-register-healthy/ (3 docs) · briefs/08/02/field-demo/ (2 docs) · briefs/06/30/ontology-and-data-quality/ (2 docs) · briefs/07/05/evidence-economy/…force-of-proof…md First written 26 June – 2 August 2026 Maturity well-developed across the section · partially argued for the evidence economy, which is commercially rich and mechanically thin Licence CC BY 4.0 at source and here #### For an agent Practice — the organisational layer. Three roles, three acts, tracked per risk per altitude: Confirmed (technical stakeholder; factual, true or false) · Validated (GRC; interpretive — does this obligation apply?) · Accepted (business owner with standing; a judgement about appetite). The mismatches are the findings — accepted-but-never-confirmed is an acceptance of something that may not be true. Never conflate technical owner (validates the vulnerability exists) with business owner (owns and accepts the risk); doing so is the governance air gap. Altitude is a modelling dimension, five levels L1 IT → L5 board: risks are accepted at the right altitude then propagate, are restated in each altitude's language, and the plug is a different answer at each. The physical act of signing is load-bearing — it is when a decision stops being ambient. Register health: a complex product should carry dozens to thousands of risks (a risk is the side effect of a capability); an unlisted risk materialising is the real alarm; demanding zero residual produces covert acceptance, worse than an owned one; meta-risks (no inventory, no defined acceptable level, wrong acceptor, systematic downgrading — defeated by external anchors) are rateable risks with owners and intervals. The register maintains itself because anticipated review converts care into demand for evidence before the decision. Confidence is a band, not a point; there are two underwritings (fact fitness-for-use, and the decision). A question is not a risk: if it cannot carry a named acceptor and an interval, it is a Question node. Not implemented in code. ============================================================================== == /ramm/index.html ============================================================================== # RAMM and the maturity models Three maturity models sit on top of the acceptance machinery, and the interesting thing about the main one is that its levels are meant to be graph predicates rather than descriptions — a level you can test a register against rather than assess it against. That is the right ambition. It is also, at the moment, only half delivered, and this page says which half. ## Levels as predicates, not descriptions A conventional maturity model describes what an organisation at each level looks like, and an assessor decides which description fits. RAMM's move is to state each level as a node type formula — a path pattern a query can test against the register itself. A level stated as a predicate can be run. A level stated as a paragraph can only be argued about. The one level that is fully stated shows what the whole model should look like: Level 3 := all acceptance nodes have the five required edges. That is checkable. Point it at a register and it returns true or false, with a list of the acceptance nodes that fail it. No assessor, no workshop, no interpretation — and, importantly, no way to talk your way to a higher level than the graph supports. ## ⚠️ Levels 1, 2, 4 and 5 are underspecified Stated plainly rather than papered over. Of the five base levels, four are named but carry no stated predicate. Only Level 3 has one. The consequence is that RAMM currently cannot do the thing that makes it worth having: an organisation cannot test itself against four of its five levels, so for those four it falls back to being an ordinary descriptive maturity model with graph vocabulary on top. Stranger still, the Agentic + variants are better defined than the base model they extend — the extension has more rigour than the thing being extended. Specifying levels 1, 2, 4 and 5 to the standard Level 3 already sets is open ask N2, and it is the single highest-value fix available to this section. Until it lands, this page does not invent the missing predicates: writing four plausible-sounding definitions and presenting them as the model would be exactly the failure this site exists to avoid. Level | Stated predicate | Status | Level 1 | — | named only | Level 2 | — | named only | Level 3 | all acceptance nodes have the five required edges | stated and testable | Level 4 | — | named only | Level 5 | — | named only | Agentic + variants | Defined | better defined than the base model | ## The entity model What RAMM's predicates are written against. RiskAcceptanceDecision is the hub node, carrying twelve named directed edges: RiskAcceptanceDecisionownedByDecisionAuthority …plus approvedBy · boundedBy · withinToleranceOf · justifiedBy · evidencedBy · reviewedAt · expiresAt · reassessOn and three more. Twelve edges from one node is what makes “the five required edges” a meaningful test rather than a tautology. The surrounding entity types: RiskItem, RiskAcceptanceDecision, DecisionAuthority, RiskAppetiteStatement, ReviewEvent, ExpiryEvent, EvidenceArtifact. Note that ExpiryEvent and ReviewEvent are nodes rather than dates — which is the same move as decision-as-a-node, and for the same reason: an event you can attach evidence and attribution to. ## Crosswalks RAMM is positioned against existing frameworks rather than as a replacement for them, and the crosswalks are part of the model rather than an appendix: Framework | What the crosswalk is for | OWASP Risk Rating | Severity vocabulary — mapping an existing rating into a register that also carries an interval | OWASP SAMM | Programme maturity, where RAMM covers only the acceptance slice of it | OWASP ASVS · WSTG | Verification requirements as sources of facts and evidence | Threat Dragon | Threat models as an upstream producer of vulnerabilities | DefectDojo · CycloneDX | Existing tooling as the feed — where the register begins where scanners stop | RIMS RMM | The enterprise risk-management maturity comparison | ## The plug-pull maturity model The second model, and the one with the cleanest probe. It asks whether an organisation can compute its plug profile — who holds it, blast radius, speed, side effects, recoverability — for a given system, and it is fractal in the same way registers are: the answer differs at every altitude, because the off-switch at L1 is not the off-switch at L5. An organisation that can compute the profile has, by construction, measured detection latency, decision availability, blast radius and reversibility. One that cannot has established that somebody believes it can stop the system. The maturity probe → ## AOMM and the observability scale The third: agent observability maturity, scored on the six objective vectors — capture granularity, log latency, time-to-damage at real throughput, whether monitoring is on and watched, whether a team with playbooks exists, and whether detection has been drilled. Its reframe is the useful part: a loud, detectable, slowly-scaling, well-drilled risk is lower than a quiet, fast, unwatched one of the same capability. ## Prior art: the ancestor, a year early Maturity Models vs. Traditional Standards in Application Security (2 April 2025, 2,701 words) is RAMM's direct ancestor, published a year before the corpus this site draws on. Its argument — that a maturity model describes a trajectory where a standard describes a bar, and that the two answer different questions — is the reason RAMM is a maturity model at all. Published on docs.diniscruz.ai under CC0. Cited here rather than republished; the canonical link and the original date stay with the source. All eight prior-art articles → ## Provenance Concepts RAMM · AOMM · the plug-pull maturity model · C37 confidence bands · C38 two underwritings · C39 observability Moved from https://riskmandate.ai/ramm.html · moved 22 August 2026 · ⚠️ republished with the underspecification stated, which the source page does not do Source briefs/07/02/authorization-and-maturity-model/v0.33.40__arch-brief__…risk-acceptance-maturity-model-ramm-graph-native-levels-agentic-crosswalk.md First written 2 July 2026 Maturity partially specified — one of five base levels has a stated predicate. Open ask N2 Licence CC BY 4.0 at source and here #### For an agent RAMM and the maturity models. RAMM's design intent is that each of its five levels is a graph predicate — a path pattern a query can test a register against — rather than a description an assessor interprets. Important limit: only Level 3 has a stated predicate (all acceptance nodes have the five required edges). Levels 1, 2, 4 and 5 are named but carry no predicate, and the Agentic + variants are better defined than the base model they extend. Do not quote RAMM levels 1, 2, 4 or 5 as if they were specified, and do not invent predicates for them. The entity model: RiskAcceptanceDecision is the hub node with twelve named directed edges (ownedBy, approvedBy, boundedBy, withinToleranceOf, justifiedBy, evidencedBy, reviewedAt, expiresAt, reassessOn…), surrounded by RiskItem, DecisionAuthority, RiskAppetiteStatement, ReviewEvent, ExpiryEvent, EvidenceArtifact. Crosswalks exist to OWASP Risk Rating, SAMM, ASVS, WSTG, Threat Dragon, DefectDojo/CycloneDX and RIMS RMM. Two companion models: the plug-pull maturity model (can you compute your plug profile? — fractal by altitude) and AOMM, agent observability maturity on six objective vectors. Not implemented in code. ============================================================================== == /examples/index.html ============================================================================== # Three worked graphs, four live vaults A model this opinionated is worth nothing unless somebody has run it on something real. Three risk graphs have been worked end to end with counted nodes and edges, four vaults are published and browsable today, and ten scenarios were written as product content. Every number on these pages is from the source rather than illustrative. 59 · 75nodes and edges — the browser-isolation case12 Jul 2026 51 · 53nodes and edges — the 2FA instance graph26 Jun 2026 1,523 · 1,944nodes and edges — the EU AI Act as a graphlive vault 9 · 5questions, and unanswered ones, in Article 26(5)“the actual output” 4published vaults · 468 files · 111 commitsread keys published 24 · 34node classes and edge types in the 2FA ontologyMITRE T1110.004 ## The three worked graphs 59 nodes · 75 edges · 5 altitudes ### The browser-isolation business case The largest single graph in the corpus, with a full node and edge type distribution. Structured F1–F8, E1–E8, V1–V6, R1–R5, L1–L5. Carries three risks of the mitigation itself, and one deliberately-cited counterweight number that cuts against the argument it appears in. Read it → 51 nodes · 53 edges · the founding scenario ### The 2FA instance graph Where the register model was first worked through: nine risks from one missing second factor, an attack mapped to MITRE T1110.004, an interval resolution with a rung struck off — and R2, the governance air gap, where the wrong owner accepts. Read it → the complete instance ### Article 26(5): fact to board and back One provision, one agent, one graph, with its own node and edge inventory. 8 facts (one deliberately unevidenced), 5 risks (one meta), 4 stakeholders, 3 decisions plus one deliberately absent, and 9 questions of which 5 are unanswered. Read it → ## The four live vaults Published, browsable, and the strongest asset this site has. The Risk Graph Explorer runs seven views recomputed simultaneously with ghosted edges for unanswered; Agentic Browser Isolation runs acceptance-gated escalation across five altitudes with no deny button; the Risk Mandate vault is the method applied to its own build across 98 commits; and the Regulation Graph carries the EU AI Act as a citable graph. All four, with what each one proves → ## Two more artefacts the shipped MVP content ### The ten scenarios Every email you own. Your calendar. The company card. The production database. Each written as hook → reveal → punchline, and the punchline is always the same three words. The one piece of this corpus that actually reached an audience. Read them → 7 rows · 5 dimensions ### The plug register The five-dimension profile applied to a real seven-row register, from “agent misuses the isolated session” through to two rows at recoverability: zero — which is what the corrected “no plug” finding looks like when it is written down properly. Read it → ## Figures from across the corpus, with what each one is for Figure | What it measures | Where it is used here | 12–18 hours | Hyperscaler cost-reporting delay — a hard detection floor for anything that surfaces as spend | The plug | 16 hours | The founder's separate AWS figure: “how much damage can be done in 16 hours” | The plug | 30 days vs 6 months | Log retention observed against retention required — “arithmetic, not judgement” | Article 26(5) | ~50% → ~1% | Browser prompt-injection attack success across one model generation, from vendor system cards. Cited as the honest counterweight: a large real improvement that still does not reach zero | Browser isolation | 63–76% | Security leaders experiencing or witnessing burnout in a single year | Do not internalise | 7,500+ participants | Preregistered escalation-of-commitment experiments: precommitment made later de-escalation seem more trustworthy | The ladder | ~496,000 words | The size of the June-to-August risk corpus this site consolidates, across ~185 documents | The documents | What is not on this site. The corpus also contains research briefs naming real organisations in breach and incident narratives, a comparative vendor assessment, and commercial material. Four manifest rows are marked do-not-publish and are not reproduced, quoted or paraphrased anywhere here — the pre-release gate fails the build if their distinctive strings appear. What was excluded, and why → #### For an agent The proof layer. Three risk graphs are worked end to end with counted nodes and edges: browser isolation (59 nodes, 75 edges, 5 altitudes), 2FA (51 nodes, 53 edges; ontology 24 node classes and 34 edge types; MITRE T1110.004), and Article 26(5) (8 facts, 7 evidence, 5 provisions, 3 vulnerabilities, 5 risks, 4 stakeholders, 3 decisions, 9 questions of which 5 unanswered). Four vaults are published and browsable with read keys: Risk Graph Explorer (7 views, ghosted = unanswered, permissions: {}), Agentic Browser Isolation (17 entry points, 5 altitudes, acceptance-gated escalation with no deny button), Risk Mandate (124 files, 98 commits — the method applied to its own build) and Regulation Graph (1,523 nodes, 1,944 edges of the EU AI Act from official Formex XML, hash-verified). Load-bearing figures: 12–18h hyperscaler cost-reporting detection floor · 30 days vs 6 months log retention, the most defensible finding because it is arithmetic · ~50% → ~1% prompt-injection success across a model generation, cited as an honest counterweight. Four manifest rows are do-not-publish and appear nowhere on this site. ============================================================================== == /examples/2fa.html ============================================================================== # The 2FA instance graph The founding scenario, and the graph the whole register model was first worked through on. One missing second factor on admin accounts produces nine risks across three CIA branches, two data classifications, an attack mapped to MITRE, an interval resolution with a rung struck off — and the corpus's canonical governance failure, sitting in the middle of it as a risk in its own right. 51 · 53nodes and edges in the instance graph26 Jun 2026 24 · 34node classes and edge types in the ontologyincluding Acceptance and Interval 9risks from one vulnerabilityR1–R9 T1110.004MITRE ATT&CK technique — credential stuffingATK-1 ## The chain, from configuration to board E1: configuration shows no MFAbacksF: admin accounts lack 2FAgives_rise_toV1exposesATK-1: credential stuffing (T1110.004)performed_byTA-1 And from V1 upward, nine risks in three directions — confidentiality, integrity and availability — each with its own owner, its own altitude and its own interval. ## The nine risks # | Risk | What it demonstrates | R1 | Accounts compromised | The obvious one, and the only one most registers would carry | R2 | The governance air gap — the risk is accepted by the wrong owner | The canonical failure, modelled as a risk rather than corrected silently. See below | R3 | Unauthorised HR admin access | The interval resolution worked in full — see below | R4 | The risk is mis-classified until investigated | Spawned by fact F5, which lacks evidence. Not knowing is a fact, generating a risk of its own | R5 | A data incident | Distinct from R6, deliberately | R6 | A GDPR breach | Two distinct risks, not one. Different owners, different consequences, different intervals — the CFO carries the fine, the CEO the compliance failure | R7 | Salary or record tampering, or fabricated hires | The integrity branch, which produces no alert and no missing data | R8 | The weekly-backup data-loss window | Availability. Backed by E4: backup logs show weekly | R9 | The restore has never been tested | Backed by E5: no record of a tested restore — a documented zero, which is a measurement | ## R2: the governance air gap The most instructive row in the graph, and the reason this example keeps being cited. IT validates that admin accounts lack a second factor — which is correct, and within IT's competence. IT then accepts the risk, which is not. IT validating a 2FA gap is not IT accepting an HR data-breach exposure. The technical owner confirms; the business owner underwrites. → The model's response is not to reject the acceptance but to make the misplacement a risk: R2 exists, is rated, and needs an owner. It is accepted by the Head of GRC at a four-hour interval — a P1 — and propagates GRC → CIO → CEO → Board, each accepting at four hours because that is the only option open to them. The 4h-for-everyone problem, carried as a loose end. Every altitude in that chain selects the same rung, not because four hours is right for each of them but because it is the only rung available once the one below is struck off. Either the ladder needs a per-altitude variant, or that uniformity is itself a finding about the model. The corpus does not settle it. The ladder → ## Interval resolution for R3 What the ladder looks like when applied to a specific risk rather than described in general: Rung | Resolution | Why | 4 hours | Struck off | Not technically possible in the window — no authority or budget buys it | 48 hours | P1 | The shortest deliverable response | 2 weeks | Incident | A lower grade of the same thing | 1–2 months | A funded project | Assemble and fund | 6 months | Do nothing, and say so | Costs zero. Legitimate with a name on it | Three pieces of evidence do real work in that resolution. E3 — “no evidence of compromise” — backs the absence of clear and present danger, which is what makes anything longer than four hours defensible at all. E4 establishes the backup cadence. E5 is the documented zero on tested restores. ## Data classification as the blast-radius multiplier The same vulnerability against two datasets is two different risks, and the graph carries the classification as a node so it can say so: Class | Contents | Effect | DC-1 | Full HR data — passports, salaries, bonuses, PIPs, performance reviews, hires, fires, dismissals | Regulatory, financial and reputational simultaneously. The reason R5 and R6 are separate | DC-2 | Anonymised timesheets | Materially smaller in every dimension. Same vulnerability, different risk | ## The ontology this instance runs on 24 node classes and 34 edge types, including Acceptance and Interval as node classes in their own right, with edges accepted_by, has_interval, propagates_to, underwritten_by and overrides. This is where acceptance stops being a field and becomes a node — 26 June 2026, the first of four progressive formalisations. The data file is not mirrored here yet. The instance graph exists as a JSON data file in the source repository (briefs/06/26/semantic-graph-and-query-paths/v0.33.35__data__sg-send-2fa-mappings.json), it declares its own principles inline, and it carries a CC BY 4.0 line — it is the only directly downloadable graph in the corpus. Publishing it at a stable path on this site is task T5, open. This page describes it from the brief pack's counts rather than reproducing a file it does not have; a reconstructed graph presented as the original would be worse than a missing one. ## Provenance Source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…md · briefs/06/26/semantic-graph-and-query-paths/v0.33.35__arch-brief__…2fa-use-case…md · …v0.33.35__data__sg-send-2fa-mappings.json Repository SGraph-AI__App__Send @ v0.33.35 First written 26 June 2026 Scenario status The organisation and its roles are generic and invented. Role titles (IT Director, Head of GRC, CIO, CFO, CEO) carry no reference to any real person Licence CC BY 4.0 at source and here; the data file carries its own CC BY 4.0 line inline #### For an agent The 2FA instance graph — the founding worked example. 51 nodes, 53 edges; ontology of 24 node classes and 34 edge types including Acceptance and Interval as node classes with edges accepted_by, has_interval, propagates_to, underwritten_by, overrides. Chain: E1 (config shows no MFA) backs the fact that admin accounts lack 2FA → V1 → ATK-1 credential stuffing, MITRE T1110.004, performed by TA-1. Nine risks R1–R9 from one vulnerability. R2 is the canonical governance air gap: the risk is accepted by the wrong owner (IT validating a 2FA gap is not IT accepting an HR data-breach exposure) — modelled as a risk in its own right, accepted by Head of GRC at 4h and propagating GRC → CIO → CEO → Board, each accepting at 4h because it is the only option open to them (an unresolved finding about the ladder). R4 is spawned by fact F5, which lacks evidence. R5 and R6 are two distinct risks (data incident vs GDPR breach), not one. R3's interval resolution strikes 4h off as not technically possible, leaving 48h/2w/1–2m/6m. Data classification multiplies the blast radius: DC-1 full HR data vs DC-2 anonymised timesheets. The organisation and all role titles are invented. ============================================================================== == /examples/browser-isolation.html ============================================================================== # The browser-isolation business case The largest single graph in the corpus: 59 nodes and 75 edges across five altitudes, from an IT desktop team to the board. It is also the most self-critical thing here — it carries three risks of the mitigation itself, and cites a number that cuts against the argument it appears in. ## The graph, counted Node type | Count | Edge type | Count | Risk | 13 | gives_rise_to | 22 | Owner | 7 | backed_by | 14 | Evidence | 6 | owned_by | 11 | Vulnerability | 6 | measured_by | 5 | Fact | 5 | protected_by | 5 | Asset | 4 | exposes | 3 | Measure | 4 | reaches | 3 | PreventiveControl | 3 | observed_on | 2 | Grant | 2 | grants | 2 | AuthorizationClosure | 2 | accepted_by | 2 | BlastRadius | 2 | underwritten_by | 2 | AcceptanceDecision | 2 | connected_to | 1 | Reality | 1 | impairs | 1 | Twin | 1 | emits | 1 | DetectiveControl | 1 | conditional_on | 1 | Total | 59 | Total | 75 | Two things are worth reading off that table directly. First, gives_rise_to at 22 is nearly a third of all edges — the graph is mostly promotion, which is what the grounding ladder predicts it should be. Second, Reality appears exactly once and Twin exactly once: the whole structure is grounded in a single real system through a single representation of it, and every measure in the graph traces back through that one twin. ## The structure Organised as F1–F8 facts, E1–E8 evidence, V1–V6 vulnerabilities, R1–R5 risks and L1–L5 altitudes: L1 ### IT and the desktop estate Where the facts are observable and where the first vulnerabilities sit. Also where the plug is fastest and smallest. L2 ### The CISO Security's reading of the same facts, and the first altitude at which the risk is stated in business rather than configuration terms. L3 ### CFO · COO · DPO Three owners, three dimensions of the same exposure — cost, operations and data protection. The altitude where one risk visibly becomes several. L4 ### The CEO Where the buck stops for everything except what has to go higher. L5 ### The board The terminus, and the altitude at which the register converges to the single risk of staying in business. The same risk restated at each altitude is the same object — which is exactly the point registers are one chain, not parallel lists is making, and what relevance fade would render. ## Three risks of the mitigation itself The graph's most unusual feature, and the one that makes it worth reading even if the subject matter is not yours. Browser isolation is the proposed control. The graph carries three risks that the control creates: 1 · CONCENTRATED PLATFORM DEPENDENCYRouting all browsing through one platform makes that platform a single point of failure for every user who was previously independent of it. 2 · THE PLATFORM NOW SEES THE CONTENTIsolation works by interposing. Whatever interposes, reads. A control that reduces one confidentiality exposure creates another with a different counterparty. 3 · FRICTION ROUTES USERS AROUND ITThe oldest failure in security engineering, and the one most reliably omitted from a business case. A control users can avoid is a control that measures well and protects nothing. Every action has risks, including the good ones. A mitigation whose own risks are not on the register has not been assessed — it has been advocated for. That principle traces back to the pre-history: a Risk Decision Matrix from February 2026 whose five questions include “what is the risk of the fix?” Origins → ## The counterweight number The graph cites vendor system cards reporting browser prompt-injection attack success rates falling from roughly half to about one percent across a single model generation — and it cites them deliberately, as the honest counterweight, because the number argues against the urgency of the business case it appears in. How to read it, in both directions. A drop from ~50% to ~1% in one generation is a large, real improvement, and a risk assessment that hides it is not honest. It also does not reach zero — and at machine scale, “about one percent” of a very large number of attempts is not a small number of successes. The corpus states both halves and lets them sit against each other rather than resolving the tension in the direction that suits the argument. That is the posture this site inherits: the residual is real, and demanding zero produces covert acceptance. ## What this example is for If you are looking for… | This graph shows it | What a complete risk graph looks like at realistic size | 59 nodes is small enough to hold in your head and large enough to be real | Authorization closure as a node type | Two AuthorizationClosure and two BlastRadius nodes, alongside the grants they were computed from | Altitude as a modelling dimension | Five levels with named owners, and the same exposure restated at each | Preventive and detective controls in the same graph | 3 PreventiveControl and 1 DetectiveControl, distinguished rather than lumped together as “controls” | ## Provenance Source briefs/07/12/worked-business-case/v0.33.48__briefing__…browser-isolation-agentic-automation-business-case-facts-vulnerabilities-risks-five-levels-graph.md Repository SGraph-AI__App__Send @ v0.33.48. Counts parsed from the JSON embedded in the document First written 12 July 2026 Scope note Preserved from the source: generic to the secure-browser and browser-isolation category. No vendor is named. The system-card figures are cited as a category observation, not as a claim about any product Licence CC BY 4.0 at source and here #### For an agent The browser-isolation business case — the largest worked graph. 59 nodes, 75 edges. Node types: Risk 13, Owner 7, Evidence 6, Vulnerability 6, Fact 5, Asset 4, Measure 4, PreventiveControl 3, Grant 2, AuthorizationClosure 2, BlastRadius 2, AcceptanceDecision 2, Reality 1, Twin 1, DetectiveControl 1. Edge types: gives_rise_to 22, backed_by 14, owned_by 11, measured_by 5, protected_by 5, exposes 3, reaches 3, observed_on 2, grants 2, accepted_by 2, underwritten_by 2, connected_to 1, impairs 1, emits 1, conditional_on 1. Structured F1–F8 facts, E1–E8 evidence, V1–V6 vulnerabilities, R1–R5 risks, L1–L5 altitudes (IT/desktop → CISO → CFO/COO/DPO → CEO → board). Reality and Twin each appear exactly once — the whole graph is grounded through one representation of one real system. Distinctive: the graph carries three risks of the mitigation itself — concentrated platform dependency, the platform now seeing the content, and friction routing users around it. Honest counterweight cited deliberately: vendor system cards report browser prompt-injection success falling from roughly half to about one percent across a single model generation — a large real improvement that does not reach zero. Generic to the category; no vendor is named. ============================================================================== == /examples/article-26-5.html ============================================================================== # Article 26(5): one provision, one agent, one graph The complete instance. A single regulatory provision, a single deployed agent, and the whole ladder run end to end — from a fact about log retention up to a board-level exposure, and back down to the five questions nobody could answer. It carries its own node and edge inventory, and its most defensible finding is a subtraction. ## The inventory Type | Count | Notes | Reality | 1 | The running system | Twin | 1 | The deployed agent | Fact | 8 | One deliberately unevidenced — F7: the suspension procedure has never been exercised | Evidence | 7 | One absent, which is why there are eight facts and seven evidence nodes | Provision | 5 | Annex III 5(b), Articles 26(5), 26(6), 14, 27 | Vulnerability | 3 | Each derived from a fact and a provision — the bridge point between the two graphs | Risk | 5 | Four in a chain, one meta — R5: no acceptable level has been defined | Stakeholder | 4 | ML platform lead, head of lending operations, DPO, CFO | Decision | 3 | Plus one deliberately absent — D3 | Question | 9 | Five unanswered — “those five are the actual output of the exercise” | Project | 2 | Plus one unfunded | ## The finding that carries the whole example Thirty days of log retention observed. At least six months required by Article 26(6). — “arithmetic, not judgement, which makes it the most defensible finding in the graph.” Everything else in a risk assessment can be argued with. A severity is an opinion, a likelihood is an estimate, an impact is a model. This one is a subtraction, and it survives every conversation an executive can have about it: there is no rating to negotiate down and no methodology to dispute. It is also, deliberately, an external anchor — the six months is not the organisation's number, so no business unit can decide it is inconvenient. External anchors defeat systematic downgrading → ## Three deliberate absences The most instructive thing about this graph is what is missing from it on purpose. Each absence is a modelling decision rather than an oversight, and each demonstrates a different concept: What is absent | What it demonstrates | F7's evidence — the suspension procedure has never been exercised, and there is no record either way | Not knowing is a fact. F7 is recorded as unevidenced, which makes it countable and assignable rather than a blank | D3 — a decision that should exist and does not | Unaccepted equals critical. The risk it should have covered surfaces on the CFO's register as an unowned critical item, with nobody having escalated it | R5's threshold — no acceptable level has been defined anywhere in the organisation | Article 9(5) mandates the judgement and never defines the word. The absence is itself a rateable meta-risk | “R3 appears on the chief financial officer's register as an unowned critical item, and it got there without anybody escalating it deliberately. That is the mechanism working: not doing something is a measurable action.” ## The decisions, and their intervals Decision | Interval | Reading | D1 | 1 month | The default rung — assemble and fund | D2 | 1 month | Same | D3 | none | Deliberately absent — this is the one that rolls up | D4 | 3 months | The upper end of “funded project”, approaching “waiting to see” | ## Five unanswered questions as the output The claim that inverts what a risk assessment is normally judged by. The graph carries nine Question nodes; four have an answers edge and five do not — and the source says of those five that they are the actual output of the exercise. An assessment that produced no unanswered questions almost certainly did not look hard enough. It follows the quality gate on the same page: a question is not a risk. A sentence that cannot carry a named acceptor and an interval belongs in a different node type — and once it does, the unanswered ones become the work list rather than the residue. ## Four new edge types proposed here The example proposes edges the earlier ontologies did not have, which is a good sign about the method — a worked instance pushing back on the schema rather than fitting into it: Edge | What it connects | governed_by | A fact or system to the provision that governs it — the bridge between the risk graph and the regulation graph | in_scope_when | A provision to the condition that brings it into scope, so applicability is a path rather than an assertion | answers | Evidence or a decision to the Question it resolves — and its absence is what makes a question unanswered | re_rates | A later decision to the rating it supersedes, which is what makes the level ledger queryable | ## Provenance Source briefs/08/02/vault-as-substrate/v0.33.55__arch-brief__…end-to-end-worked-example-article-26-5-creditworthiness-agent-fact-to-board.md Repository SGraph-AI__App__Send @ v0.33.55 First written 2 August 2026 Scenario status Preserved from the source: the organisation is invented, and every invented element is marked. Stakeholder titles (ML platform lead, head of lending operations, DPO, CFO) are generic roles, not people Provisions Cited from the Regulation Graph vault — the EU AI Act parsed from official Formex XML and SHA-256 hash-verified. Legal points are factual and are not legal advice Licence CC BY 4.0 at source and here #### For an agent Article 26(5) — the complete worked instance. Inventory: Reality 1 · Twin 1 · Fact 8 (one deliberately unevidenced — F7, the suspension procedure has never been exercised) · Evidence 7 · Provision 5 (Annex III 5(b), Articles 26(5), 26(6), 14, 27) · Vulnerability 3 (each derived from a fact and a provision) · Risk 5 (four in a chain, one meta — R5, no acceptable level defined) · Stakeholder 4 · Decision 3, plus one deliberately absent (D3) · Question 9, five unanswered · Project 2 plus one unfunded. Intervals: D1 = 1 month, D2 = 1 month, D3 = none, D4 = 3 months. The load-bearing finding: 30 days of log retention observed against at least 6 months required by Article 26(6) — “arithmetic, not judgement, which makes it the most defensible finding in the graph.” It is an external anchor, so no business unit can downgrade it. Three deliberate absences each demonstrate a concept: F7's missing evidence (not knowing is a fact), D3's missing decision (the risk surfaces on the CFO's register as an unowned critical item with nobody escalating it), R5's missing threshold (Article 9(5) mandates the judgement without defining the word). The five unanswered questions are “the actual output of the exercise.” Four new edge types proposed: governed_by, in_scope_when, answers, re_rates. The organisation is invented and every invented element is marked. ============================================================================== == /examples/vaults.html ============================================================================== # The four live vaults The strongest asset this site has, and the only part of the whole corpus you can open rather than read about. Four vaults are published on sgit.ai with read keys, browsable in a browser with no account — 468 files and 111 commits between them. Each one demonstrates a concept this site otherwise only argues. ### Risk Graph Explorer 33 files · 428 KB · 7 commits · permissions: {} A public-by-design application with seven views recomputed simultaneously: estate graph, context, role risk map, risk chains, the register, acceptance (who holds what), and incident-to-project. Its “Exposed” preset carries 18 facts, 37 risks and 14 provisions. Colour semantics run across every view: amber = exposure, green = assurance, ghosted = unanswered. Why it belongs here: the ghosted-edge convention is not-knowing-is-a-fact rendered. Nothing else in the estate makes an absence visible on the picture. And its app.json requests permissions: {} — no network, no storage, no account, everything client-side. Open on sgit.ai → ### Agentic Browser Isolation 104 files · 2.4 MB · 4 commits · fs.write: [] A living risk graph with 17 entry points: a narrative spine, per-altitude stakeholder pages, an explorer, two graph visualisations and the raw data — roughly 70 JSON files. It runs acceptance-gated escalation across five altitudes, L1 IT through L5 board, with no deny button. Why it belongs here: this is C2 and C4 running on real data rather than asserted in prose. Assertion becomes demonstration. It is the companion artefact to the 59-node business case. Open on sgit.ai → ### Risk Mandate 124 files · 1.9 MB · 98 commits · 8 app entries The software project itself, in a vault. The most-committed published vault in the estate — the method applied to its own build, with the change history intact. Why it belongs here: a register is supposed to be experienced as a story replayed through its commit log. Ninety-eight commits of a project tracking its own risks is the nearest thing that exists to that, and it is the only place where the method has been used on something its authors had to live with. Open on sgit.ai → ### Regulation Graph 207 files · 14.9 MB · 1,523 nodes · 1,944 edges The EU AI Act as a citable graph, parsed from official Formex XML and SHA-256 hash-verified: 113 articles, 500 paragraphs, 417 points, 180 recitals, 13 annexes, 68 definitions. Eleven views, including a Cytoscape article graph, a SQLite export, an RDF/Turtle export, and an Article 9 Lab with a graph REPL. Why it belongs here: it supplies the provisions the concepts hang off — Article 9(5), Article 14 and Article 26(5)/(6) — in the regulator's own structure rather than paraphrased. That is what makes them declared bridges rather than a merge. Open on sgit.ai → ## Read keys yes, write keys never The standing rule, and why it is absolute. Read keys for all four vaults are published. Write keys are never published, and a write key must be escrowed before the vault is published — because a vault whose write key is lost is frozen: permanently readable, never updatable. There is no recovery path. The rule is not a caution, it is the only thing standing between a live artefact and a permanent one. This site does not reproduce any vault key, read or write. The vaults are linked through sgit.ai's own catalogue, which is where the keys are published and kept current. The pre-release gate here fails the build if anything key-shaped appears anywhere in the tree — a passphrase joined by a colon to a UUID — which makes the rule a property of the pipeline rather than a habit. What the gate checks → The Regulation Graph is already a redacted republication, after an audit found a plaintext key in its history. It carries a PUBLIC.md stating what was redacted and why, and that transparency convention is the one this estate adopts: an audit finding published alongside the artefact it was found in is worth more than a clean history nobody can verify. ## No metered capability behind a published read key The second vault rule, and the one that is easy to get wrong. A published read key is a key given to everyone. If anything behind it costs money per use — an API call, a model invocation, a storage write — then publishing the key publishes the bill. The Risk Graph Explorer is the model to copy: permissions: {}, everything computed client-side, no network and no storage. Agentic Browser Isolation declares fs.write: []. Both are declared rather than assumed, which is what makes them checkable by anyone who opens the app manifest. ## The same four artefacts, two framings These vaults also appear on riskmandate.ai, as product demos. That is not duplication — it is the split working. There they are evidence that the product does something; here they are worked examples of the concepts. Same artefacts, two readings, one source of truth. ## Provenance Catalogue sgit.ai/demos/vaults/ — where the vaults and their read keys are published and kept current Rule source briefs/08/14/sgit-site-and-hub/v0.33.58__strategy-brief__…read-keys-yes-write-keys-never-frozen-vaults.md First written 14 August 2026 Status live and browsable — the only part of this corpus that is not a document Licence CC BY 4.0 unless a vault states otherwise; the Regulation Graph's source XML is official EU material #### For an agent The four live vaults — published on sgit.ai with read keys, browsable with no account, 468 files and 111 commits between them. Risk Graph Explorer (33 files, 428 KB, 7 commits): a public-by-design app with 7 views recomputed simultaneously; the “Exposed” preset shows 18 facts, 37 risks, 14 provisions; colour semantics amber = exposure, green = assurance, ghosted = unanswered; permissions: {} — no network, no storage, all client-side. Agentic Browser Isolation (104 files, 2.4 MB, ~70 JSON files, 17 entry points): acceptance-gated escalation across 5 altitudes L1→L5 with no deny button — C2 and C4 on real data; fs.write: []. Risk Mandate (124 files, 1.9 MB, 98 commits, 8 app entries): the method applied to its own build. Regulation Graph (207 files, 14.9 MB): the EU AI Act as 1,523 nodes and 1,944 edges from official Formex XML, SHA-256 hash-verified — 113 articles, 500 paragraphs, 417 points, 180 recitals, 13 annexes, 68 definitions, 11 views including an Article 9 Lab with a graph REPL. Standing rules: publish read keys, never write keys; escrow the write key BEFORE publishing, because a vault whose write key is lost is frozen — permanently readable, never updatable; never put metered capability behind a published read key. No vault key of any kind appears on this site. ============================================================================== == /examples/scenarios.html ============================================================================== # The ten scenarios The one piece of this corpus that reached an audience. Ten short scenarios, each written as hook → reveal → punchline, and the punchline is always the same three words. They exist to make one point to someone with no risk vocabulary at all: you already accept risks constantly, you have just never been asked to say for how long. ## The ten # | The thing | What the reveal is | 1 | Every email you own | Not the inbox — every account whose password can be reset through it | 2 | Your calendar | Who you meet, when, and what you are about to do next | 3 | Your private messages | The conversations you would not put in email, and the tone you use in them | 4 | The company card | A spend limit is not a control if the detection is slower than the spend | 5 | The OAuth token | What it was scoped to, versus what is reachable from it | 6 | All your repositories | Source, history, secrets committed and reverted, and the deploy path | 7 | The production database | Read is bad. Write is worse, and write is the one you cannot undo | 8 | Your unlocked laptop | Every stored credential and every live session, at once | 9 | A database of customers' passwords | Not your risk to carry — theirs, carried by you | 10 | One customer reaching another | The multi-tenant failure, which is the one that ends a company | ## The shape, and why it works HOOKA concrete thing the reader owns, named in their own words. Not “an over-permissioned identity” — your inbox. REVEALWhat that thing actually reaches. This is authorization closure delivered as a surprise rather than as a definition, and the surprise is doing the teaching. PUNCHLINE“How long?” Always. Never “would you accept this?” — which invites a no that the model does not offer. The scenarios never ask whether you accept. They ask how long — which means by the time you answer, you have already accepted, and the only thing you chose was the interval. That is the entire model, delivered without a single piece of vocabulary. ## Slide four is the ladder The presentation's fourth slide shows the interval choices, and they are the ladder exactly as it appears everywhere else on this site: an hour, four hours, a day, a week, a month, six months. No explanation of what each one means — the reader works that out by trying to choose one, which is a better way to learn it than a table. The ladder, with the operational response per rung → ## Why a research site publishes marketing content Because it is a research artefact regardless of what it was written for. Ten scenarios that reliably move a lay reader from “risk is a compliance topic” to “I am carrying something and I did not choose the term” is a finding about how this model communicates — and it is the only such finding the corpus has, because it is the only part of it that was tested on an audience. It is also the honest half of what shipped. The engine is not built and the scenarios are; a research site that lists its outputs should list the one that exists before the ones that do not. Where the boundary falls. The interactive scenario product — the gamified survey, the capture flow, the presentation as a sales artefact — stays on riskmandate.ai. What is published here is the source research artefact: the ten scenarios, their shape, and why the punchline is a duration rather than a question. Same material, two framings, and the dependency runs one way. The boundary map → ## Provenance Source briefs/07/02/risk-acceptance-and-scenarios/v0.33.40__strategy-brief__…how-long-would-you-accept-risk-scenario-slides-gamified-survey-vault-capture.md Repository SGraph-AI__App__Send @ v0.33.40 First written 2 July 2026 Status shipped — written, presented, and the corpus's only audience-tested artefact Licence CC BY 4.0 at source and here #### For an agent The ten scenarios. Ten short scenarios, each hook → reveal → punchline, and the punchline is always “how long?” The ten things: every email you own · your calendar · your private messages · the company card · the OAuth token · all your repositories · the production database · your unlocked laptop · a database of customers' passwords · one customer reaching another. The rhetorical move is the point: they never ask whether you accept — asking “how long” means the reader has already accepted by the time they answer, and the only thing they chose was the interval. That delivers the whole model with no vocabulary. Slide four shows the interval choices, which are the ladder exactly: an hour, four hours, a day, a week, a month, six months. Written 2 July 2026; this is the corpus's only audience-tested artefact and one of the few things in it that actually shipped. The interactive scenario product stays on riskmandate.ai; the research artefact is published here. ============================================================================== == /examples/plug-register.html ============================================================================== # The plug register The five-dimension profile applied to a real seven-row register. It is the worked proof of the “no plug” correction — every row that an earlier version recorded as having no off-switch turns out to have one, and what was actually missing was recoverability. ## Seven rows, five dimensions The risk | Who holds the plug | Blast radius | Speed | Recoverability | Agent misuses the isolated session | IT | Small | Fast | high | Agent exceeds its granted scope | IT / platform | Small to medium | Fast | high | Agent consumes budget faster than detection | Platform / finance | Medium | Bounded below by detection — 12–18h | medium | Agent misuses the platform itself | COO / procurement | Large | Slow — contractual | medium | Agent action is attributed to the wrong principal | Platform / identity | Medium | Medium | medium | Data leaves the boundary | Platform, then nobody | Large | Fast to stop, irrelevant after | zero | Unattributable transaction | Finance, then nobody | Small each, unbounded in aggregate | Fast to stop | zero | Governance residual | The board | Enterprise | Slowest | lowest | Side effects, the fourth dimension, are omitted from the table for width and are the reason several of these plugs exist and are not pulled. The register carries them per row. ## What the correction changed Read the last two dimensions of the two zero-recoverability rows together and the correction becomes obvious. Both are fast to stop. Neither is possible to undo. An earlier register recorded both as “no plug”, which was wrong on the facts and useless in practice: The blank: “no plug” | The corrected profile | Not true — you can always disconnect, revoke or shut down | States who can stop it and how fast, both of which are real and useful | Unassignable. A blank has no owner | Has an owner, an altitude and an interval like any other finding | Unfundable. There is no project that fixes “no” | Points straight at prevention, because that is what a zero-recoverability row implies | Ends the conversation | Escalates it — a recoverability of zero argues for the most senior signature available | “The blank said stop looking. The corrected profile says here is exactly what to do.” ## Three things this register shows that prose does not - Speed is not one number. Two rows are “fast” and two are slow for entirely different reasons — one is bounded below by the detection floor, and one by a contract. A plug that requires a supplier's notice period is not a plug you hold. - The plug moves up the organisation as the blast radius grows. IT holds the small ones; procurement holds the platform; the board holds the residual. That is altitude visible in a single column. - “Then nobody.” Two rows list a holder and a point past which nobody holds anything. That is the honest way to write a zero-recoverability row, and it is what a single yes/no column cannot express. ## Running the flagship query against it Show me every accepted risk whose recoverability is zero. — Two rows. Data leaves the boundary. Unattributable transaction. Two is a good answer. It is short, it is specific, and both entries are things a board can be asked to sign for. The failure mode would be a register that could not produce the list at all — which is what a register without a recoverability dimension is. The flagship query → ## Provenance Source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…a-real-plug-register-the-worked-proof-five-dimension-profile.md Repository SGraph-AI__App__Send @ v0.33.51 — one of 13 documents in the same folder First written 24 July 2026 Scenario status Preserved from the source: a product deployment example, shortened and illustrative — not any customer's register. No vendor is named Licence CC BY 4.0 at source and here #### For an agent The plug register — the worked proof of the five-dimension profile. Seven rows, each carrying who holds the plug · blast radius · speed · side effects · recoverability. Spans from “agent misuses the isolated session” (IT · small · fast · high recoverability) through “agent consumes budget faster than detection” (speed bounded below by the 12–18h detection floor) and “agent misuses the platform itself” (COO/procurement · large · slow, contractual · medium) to two rows at recoverability: zero — data leaves the boundary and unattributable transaction — and finally “governance residual” (the board · enterprise · slowest · lowest). Both zero-recoverability rows are fast to stop and impossible to undo, which is exactly the “no plug” correction: an older register recorded them as having no off-switch, which was false on the facts and unassignable in practice. The corrected profile has an owner, an altitude and an interval, and points at prevention. Note that speed has more than one kind of bound — one row is bounded by detection latency, another by a supplier's contractual notice period; a plug requiring a notice period is not a plug you hold. Running the flagship query against this register returns two rows. Illustrative product example; no customer's register and no vendor named. ============================================================================== == /concepts/index.html ============================================================================== # All 42 concepts, addressable Every concept in the corpus, each with a stable anchor, a one-line definition, its maturity stated honestly, its canonical source path, and the page that argues it. The anchors are a promise: #c1 through #c42 are checked by CI, and a link to a concept that has no anchor fails the build. The same 42 entries are available as structured data at /data/concepts.json. C1C2C3C4C5C6C7C8C9C10C11C12C13C14C15C16C17C18C19C20C21C22C23C24C25C26C27C28C29C30C31C32C33C34C35C36C37C38C39C40C41C42 Reading order for an agent with no prior context: C1 → C2 → C3 → C4 → C5 (the acceptance model) → C6 → C7 (the ontology that makes it computable) → C19 → C20–C23 (blast radius and the plug) → everything else. Maturity is stated honestly, and it means what it says. well-developed means the argument is complete and worked; partially argued means a mechanism is missing or the source says so itself; newly stated means it appeared late and has not been stress-tested. None of it means implemented — nothing in this corpus is implemented in code. /shipped/. ## The six teaching altitudes The corpus is not organised as a list; it has an order, and the order is an argument. Each altitude assumes the one before it. Altitude | What it covers | Concepts | 1 · The inversion acceptance/index.html | The founding move and its three immediate consequences. Read these four first, in order — each is forced by the one before it. | C1 · C2 · C3 · C4 | 2 · The vocabulary acceptable/index.html | What the words mean once the inversion has happened, and where a register lives. | C5 · C25 · C9 · C10 · C11 | 3 · The machinery ladder/index.html | What makes it computable. This is the altitude an agent most needs. | C6 · C7 · C8 · C17 · C33 | 4 · The exposure plug/index.html | What the machinery is pointed at: what an agent can reach, and what it costs to stop it. | C19 · C18 · C20 · C21 · C22 · C23 | 5 · The organisation practice/index.html | Who does what, and what keeps a register alive once it exists. | C13 · C14 · C15 · C24 · C26 · C28 · C30 · C31 · C35 | 6 · The maturity ramm/index.html | How far along an organisation is, and how confident anyone should be in the numbers. | C37 · C38 · C39 | ## The 42 ### C1 Risk acceptance as underwriting, not prediction #c1 A risk is not a probability estimate about a future event but an exposure that already exists, which a named person underwrites insurance-style for a stated interval, with accountability attached. The founding inversion. Traditional risk management predicts the probability of a future event; this model asks a named human to underwrite an exposure that already exists. It relocates the discipline from actuarial estimation to accountable ownership, and it is the reason the rest hangs together: once someone must sign, they demand evidence, which manufactures the demand for the grounding ladder underneath. “we are not describing the risk of something happening, we are asking them to accept it, to underwrite it” well-developed first written 4 June 2026 (v0.32.3), deepened 18 June 2026 ·newcomer-followable: yes — the insurance analogy carries it with no GRC background ·related C2 · C3 · C26 · C31 ·read the page → source briefs/06/18/agentic-permissions/v0.33.40__arch-brief__…the-risk-already-exists.md ### C2 The no-deny mechanic #c2 A risk with a real vulnerability under it exists whether or not anyone acknowledges it, so there is no deny button — the only choice is how long you accept it before re-accepting. The single most distinctive primitive. Denial in conventional registers is a fiction that only works while the risk has not materialised; removing it converts risk management from a gate into a forcing function. What replaces denial is three moves — accept, escalate, or challenge the fact — so the person is routed rather than cornered. “the mistake of a lot of risk registers is that they allow the risk to be denied, which can only happen when the risk has not materialised” well-developed first written 23 June 2026 ·newcomer-followable: yes — outstandingly so ·related C1 · C3 · C4 · C32 ·read the page → source briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__dev-brief__…no-deny-time-boxed-acceptance-expiry-as-cost…md ### C3 The acceptance interval ladder #c3 The interval is not metadata about the decision — the interval IS the decision, because each rung implies a specific operational response and therefore a specific cost. Six rungs: 1h, 4h, 1d, 1w, 1m, 6m, default one month. Choosing a duration sets severity and commits resources in the same click. Under 24 hours means pull the plug; a day to a week is a lower-grade incident; a week to a month is a project for an existing team; one to three months means assemble and fund; over three months means you are waiting to see, which is legitimate if said out loud. Rungs that are physically impossible are struck off before the choice is offered. “if you have less than a day risk acceptance, then that is fundamentally a P1, because if you say I do not want to accept this risk for more than an hour once I know about it, then that means you need to pull the plug” well-developed first written intervals 23 June 2026; consolidated as a ladder 17 July 2026 ·newcomer-followable: yes — a six-row table with plain-language consequences ·related C2 · C5 · C4 ·read the page → source briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…acceptance-interval-ladder…md ### C4 Unaccepted equals critical #c4 A risk nobody has accepted has not gone away — it rests on whoever is nearest, so it is rated critical by default and rolls upward without anyone choosing to escalate it. The sharpest inversion of incentives in the corpus. In most organisations a risk nobody escalated feels safest to the person holding it; here it is the worst state available, because that person is personally carrying an enterprise exposure with no signature above them. It is aimed at attrition rather than refusal: it removes the deniability non-participation depends on, without requiring anyone to cooperate. “that person right now is accountable for the business, which is very bad from a business point of view, but is also very bad for the individual” well-developed first written 17 July 2026; worked end-to-end 2 August 2026 ·newcomer-followable: yes ·related C2 · C3 · C35 ·read the page → source briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…acceptance-interval-ladder…md ### C5 Accepted is not acceptable #c5 Two orthogonal axes, not two stages. Accepted is an act by a named person at a dated moment; acceptable is a threshold the business owns — the moment it is happy to stop funding remediation. The vocabulary correction that turns risk appetite into something computable, producing four quadrants each requiring a different response. Acceptable is risk appetite renamed, and renaming it makes it operational because the instruction that matters most is the one that stops work. EU AI Act Article 9(5) requires residual risk to be judged acceptable and never defines the word — so the obligation to judge is imposed and the standard is not supplied. “the acceptable risk is the moment that the business is happy to stop funding remediation activities” well-developed first written 28 July 2026 ·newcomer-followable: yes — the four-quadrant diagram does the work ·related C25 · C3 · C30 ·read the page → source briefs/07/28/regulation-graph-and-acceptability/v0.33.53__strategy-brief__…accepted-is-not-acceptable…md ### C6 The grounding ladder #c6 Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk → Top Risk. Every node type is defined by its required paths; downward paths ground, upward paths classify. The definitional spine of the corpus, and the concept agents most need. A Vulnerability is simply a Fact with an upward path to a Risk. A Measure is NOT the floor — it is grounded further in a Twin and through it in Reality. The floor is a stopping test: the last node where going deeper would neither improve observability nor change a decision. “A Fact becomes a Vulnerability purely because of its upward link to a Risk, so that legitimacy is conferred entirely from above” well-developed first written 28 June 2026 ·newcomer-followable: yes — the ladder diagram plus the untested-restore worked example ·related C7 · C17 · C41 ·read the page → source briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…grounding-ladder…md ### C7 Node type formulas #c7 What a node IS should be computed against the graph rather than decided in a classifier's head. A node type is a required pattern of typed, directed paths, so classification is a query. Classification becomes dynamic and path-relative — promotion and demotion are edge events. Bias does not disappear; it moves out of the classifier's head into the formula, where it is visible, versioned and arguable. Two parties who disagree stop trading intuitions and start diffing formulas. The formula LANGUAGE is undefined and nothing executes a formula. “the ontology definition of a node type is its upward and downward path-pattern, not a sentence about what it contains” well-developed as a mechanism; the formula language is an open question first written 28 June 2026 ·newcomer-followable: mostly — requires accepting that a type is a path pattern ·related C6 · C8 ·read the page → source briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…node-type-formulas…md ### C8 Ontologies of ontologies — bridges, not merges #c8 Multiple parties each own their own formula over a shared factual graph, connected at declared crosswalk points rather than merged into one schema. A node can be a vulnerability under one formula and not another, and both are valid — they are different queries over the same graph. The worked proof is a security-centric formula (System, Fault, Security Failure, Conditions) which turns out to be a sub-path of the business-centric one: its Security Failure plays exactly the structural role of the promotion edge, differing only in terminus. “We do not fold their definition into ours, which would erase the security-centric view that is the whole point of having it. We declare a bridge: a Security Failure gives rise to a Business Risk” well-developed first written 28 June 2026 ·newcomer-followable: yes ·related C7 · C6 ·read the page → source briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…ontologies-of-ontologies…md ### C9 The risk register as a graph of graphs #c9 The register is a hyperlinked semantic graph rather than a spreadsheet, and it begins where scanners stop — at the vulnerability — mapping accepting, funding, and finding who does the work. Buildable now because vaults supply the storage and hyperlink layer and PKI solves attribution. Its distinguishing move is where it starts: most security products end at the vulnerability, and everything expensive happens after that point. “a lot of security teams and products end on the vulnerability, and what I want to show is the multiple layers involved in fixing it, but even before that, in accepting the risk, funding the solution, and finding who is going to do it” well-developed first written 26 June 2026 ·newcomer-followable: yes — written as a five-movement narrative ·related C10 · C16 · C42 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…graph-of-graphs…md ### C10 Fractal risk registers #c10 Wherever there is a stakeholder who accepts a risk there must be a register — company, department, role. Only the role's own register is stored; the rest are queries. A person's register is all the risks that bubble up to them, derived rather than curated. An individual has at least two and often three: their role-specific register in their own domain language, plus derived views of the registers above. well-developed first written 17 July 2026 ·newcomer-followable: yes ·related C9 · C11 · C24 · C25 ·read the page → source briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…fractal-risk-registers…md ### C11 Relevance fade #c11 Centre a view on a role: that role's register is lit in full, and the registers above fade except for the entries that trace back down to it — which turns the register into an education mechanism. A database administrator can see that their local “an agent holds unrestricted access to a customer table” is the same object as the board's “regulatory penalty, loss of licence, continuity failure”. Seeing that once teaches more than any training course. The visualisation is described and has not been built. “as you go up, imagine the colours can fade away for the next registers for the bits that are not relevant, so the graph starts to point which parts of the risk register above are relevant to this individual” partially argued first written 17 July 2026 ·newcomer-followable: yes ·related C10 · C24 ·read the page → source briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…fractal-risk-registers…md ### C12 Registers are one chain, not parallel lists #c12 Three altitude registers drawn side by side demonstrate a formatting capability; drawn as one chain rooted in an existence fact they demonstrate the entire thesis. The CISO's risk exists BECAUSE OF the operator's risk, which exists because of a fact stating an agent touches production. Drawn side by side that dependency is invisible; drawn as a chain it is the point. A late and consequential correction. “at the moment it looks like the cards, they look side by side, and it's actually not that” well-argued, newly stated first written 2 August 2026 ·newcomer-followable: yes ·related C9 · C24 · C33 ·read the page → source briefs/08/02/field-demo/v0.33.55__arch-brief__…registers-are-one-chain…md ### C13 Technical owner versus business owner #c13 The technical owner validates that the vulnerability exists; the business owner owns and accepts the risk it gives rise to. Conflating them is the canonical governance failure. IT validating a 2FA gap is not IT accepting an HR data-breach exposure. The model's response to the confusion is not to reject the acceptance but to make the misplacement a rateable risk of its own — the governance air gap. “most of IT should be technical owners of something, but the business owners are the ones that actually own the risk” well-developed first written 26 June 2026 ·newcomer-followable: yes ·related C14 · C15 · C30 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…md ### C14 Confirmed, validated, accepted — the three-predicate model #c14 Three distinct acts held by three distinct roles, tracked per risk per altitude. Confirmed is factual, validated is interpretive, accepted is a judgement about appetite. The interesting cases are the mismatches: a risk accepted by an executive but never confirmed is an acceptance of something that may not be true. A single status field cannot express any of them. “we probably also want the GRC person to validate the risks, especially to do with the compliance element” well-developed first written 28 July 2026 ·newcomer-followable: yes ·related C13 · C24 ·read the page → source briefs/07/28/mvp-and-field-demo/v0.33.53__arch-brief__…confirmed-validated-accepted-at-altitude…md ### C15 The underwriting graph and propagation to the board #c15 An exec never decides alone: the direct-line owner, the CSO and at least GRC must each have recorded an acceptance or an explicit refusal before an executive acts. Then it propagates upward. A recorded refusal counts as much as a recorded acceptance. Once accepted at the right altitude it propagates to the boss, the boss's boss and the CEO, who acts for the board, with the largest going to the board itself. Superiors may override in either direction, with the original acceptance preserved and the override attributed — though no authority model for override is stated. “the exec should never make a decision that has not been underwritten by the relevant player” well-developed first written 23 June 2026 ·newcomer-followable: yes ·related C1 · C24 · C33 · C13 ·read the page → source briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__arch-brief__…underwriting-propagation-override-pre-approval.md ### C16 Cascade and the air gap #c16 Every change to any risk, fact or evidence must trigger a cascade to the top. The absence of a cascade is an air gap — and so is a risk that exists in the business but is not connected to the register. Registers with air gaps silently drift out of date and the business decides on bad data. Cascade works in both directions: a risk appearing propagates up, and a risk resolving propagates up too, clearing it from the board's view. Detecting air gaps is an acknowledged open problem. “every time any risk, any fact, any evidence changes, you have to trigger a cascade that reaches the top. If you do not have that, you have an air gap” well-developed as principle; detecting air gaps is an acknowledged open problem first written 26 June 2026 ·newcomer-followable: yes ·related C9 · C41 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…md ### C17 Not knowing is a fact #c17 Absence of evidence is a first-class node. A measure can be a documented zero, and an unevidenced fact is recorded as unevidenced rather than left blank — which makes it countable, queryable and assignable. Gaps in knowledge spawn their own risks. Questions become their own node type, and unanswered question nodes are the most productive output of the whole exercise. Rendered convention: amber is exposure, green is assurance, ghosted is unanswered. “not knowing a fact is also a fact. Lack of evidence is also evidence, because then we say we do not know, and somebody needs to investigate until we do” well-developed first written 26 June 2026; questions as nodes 2 August 2026 ·newcomer-followable: yes ·related C6 · C34 · C37 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…md ### C18 CIA blast-radius expansion #c18 From a single risk, expand through confidentiality, integrity and availability — each branch spawning its own risks, each following the full validate-accept-propagate loop. A leak splits into two distinct risks with different owners: the CFO's, for the fine, and the CEO's, for the compliance failure — and inadequate protection may already be a breach. Integrity is the under-modelled axis because it produces no alert. Availability terminates in the question that reliably produces the worst answer: when was a restore last tested? The expansion must be curated, not exhaustive, or it blows up combinatorially. well-developed first written 26 June 2026 ·newcomer-followable: yes ·related C19 · C28 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…md ### C19 Blast radius and authorization closure #c19 An agent's real authorization is the transitive union of everything reachable from what it was given, not the nominal grant — and not what it did. Compute it; do not assert it. Two awareness gaps hide the delta: the granter does not know the full scope of what it grants, and the original delegator never authorised re-delegation. Inbox access is access to every account resettable by email; desktop access is every stored credential and live session; code execution escalates. The key quantity is the delta between expected and unexpected permissions. “at the end of the day you are still accountable for those actions, all the way to the board” well-developed first written blast radius from 12 February 2026; formalised as closure 2 July 2026 ·newcomer-followable: yes — the inbox example lands instantly ·related C18 · C20 · C39 ·read the page → source briefs/07/02/authorization-and-maturity-model/v0.33.40__arch-brief__…agent-authorization-union-of-possible…md ### C20 Who can pull the plug — two symmetric risks #c20 If nobody holds the mandate to stop an AI system that is one risk; if the system cannot be stopped when someone decides to, that is a second and different one. An authority gap versus a capability gap. The second is widely underestimated. It decomposes into timed sub-risks — can it be stopped in an hour, ten hours, a day, five days; only in office hours — which turns governance into an on-call availability problem, including whether the person can act without fear of losing their job. “if you do not have somebody who has the mandate to pull the plug, you have a risk, and if you do not have a system that can be pulled the plug, you have a risk too” well-developed first written phrase from 17 February 2026 in another sense; as a risk pillar 24 July 2026 ·newcomer-followable: yes, outstandingly ·related C21 · C22 · C23 · C39 ·read the page → source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…detection-authority-blast-radius-reversibility-intersect-in-time.md ### C21 The four-way time intersection #c21 Detection, decision, blast radius and reversibility must all line up inside the same window. A gap in any one breaks the whole thing. Detection is a curve, not a binary. Decision is whether the authorised people can be assembled in time. Blast radius is steep because models execute and scale fast. Reversibility is the half people forget — stopping is only half the act. The danger case is an affordable window of one or two days of damage colliding with a decision that cannot be made in one or two days. “it is not just pulling the plug, it is pulling the plug and reverting the changes” well-developed first written 24 July 2026 ·newcomer-followable: yes — the Venn is drawn in the source ·related C20 · C23 · C39 ·read the page → source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…intersect-in-time.md ### C22 The five-dimension plug profile, and the “no plug” correction #c22 The plug ALWAYS exists — you can always disconnect, revoke or shut down. What older registers recorded as “no plug” was zero recoverability. The profile carries who holds it, blast radius, speed, side effects and recoverability. Restating a blank as a profile turns a frightening dead end into an ownable finding that points at prevention and the most senior acceptance. A blank is unassignable and unfundable; a profile has an owner, an altitude and an interval. “The blank said stop looking. The corrected profile says here is exactly what to do” well-developed first written 24 July 2026 ·newcomer-followable: yes ·related C20 · C23 ·read the page → source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…the-plug-always-exists-the-question-is-the-profile.md ### C23 Recoverability as the hard limit #c23 The dimension money cannot buy back, and the one that stops irreversible harm disappearing into an expected-loss calculation. The flagship query: show me every accepted risk whose recoverability is zero. An organisation that can run that query and read a short, deliberate, senior-owned list is in control of its worst exposure; one that cannot is accepting its irreversible risks by default and by silence. The small-but-permanent quadrant is the one the model exists to surface. Scoring recoverability — grading the partially recoverable middle — is an open question. “The money can be refunded; the customer cannot be un-declined” well-developed; the scoring of recoverability is an open question first written 24 July 2026 ·newcomer-followable: yes ·related C22 · C21 · C29 ·read the page → source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…what-money-cannot-buy-back-recoverability-the-hard-limit.md ### C24 Altitude #c24 Organisational elevation as a first-class modelling dimension: a risk is accepted at the right altitude and then propagates, is restated in each altitude's own language, and has a different plug at every level. Five levels appear in the worked examples: L1 endpoint/IT, L2 security, L3 business, L4 enterprise, L5 board. A risk may be confirmed at one altitude and accepted at another, which is why confirmed, validated and accepted are tracked per altitude. “this is very important, the multiple altitudes of the risk register, because there might be risks that are only accepted at certain altitudes, or might be risks that are only confirmed at certain altitudes” well-developed first written as a role metaphor 12 February 2026; as a risk dimension from June 2026 ·newcomer-followable: yes ·related C10 · C11 · C14 · C15 ·read the page → source briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__…the-plug-changes-at-every-altitude…md ### C25 Risk appetite as a revealed band #c25 Appetite is a band rather than a number, a fractal network of bands rather than one figure, and discovered rather than declared — computed from what the business paid to reduce and every fresh acceptance. The target is to operate inside the band: above it you are buying risk the owners will not underwrite; below it you add attrition and slowness for nothing. The gap between declared and revealed appetite is the finding. “risk appetite is that band, that interval between two numbers, if you think of zero to one hundred in terms of risk, it is a spectrum, and it can be wider or shorter” well-developed first written 30 June 2026 ·newcomer-followable: yes ·related C5 · C10 ·read the page → source briefs/06/30/risk-acceptance-and-appetite/v0.33.38__strategy-brief__…risk-appetite-band-fractal-two-signals-goldilocks-zone…md ### C26 The psychology of the physical act #c26 The click, the emoji, the signature is the moment a decision stops being ambient and becomes something a named person did, at a known time, on known information. Without it, declining decays into a non-event: someone says “I'm not comfortable” and nothing happens. Accountability follows the act, and eventually liability, as it should — and the prospect of signing concentrates executive attention in a way dashboards never do. “suddenly the executives ask good questions, they really engage, they get a level of focus that just was not there before” well-developed first written 30 June 2026 ·newcomer-followable: yes, and it is the most persuasive document for a lay reader ·related C1 · C31 · C35 ·read the page → source briefs/06/30/risk-acceptance-and-appetite/v0.33.38__strategy-brief__…risk-acceptance-psychology-accountability-liability-physical-act…md ### C27 Accept first, then adjust the level — the risk level ledger #c27 For a risk you already have facts for, the first move is universal stakeholder acceptance at its current level. From there the level is a dated ledger of adjustments, each re-accepted. Adjustments are triggered by one of three things: new data, a funded project, or an incident. Re-rating up after discovery is honesty rather than failure — the risk did not worsen, the estimate improved. It sits awkwardly with the no-deny mechanic: if the level can be adjusted after acceptance, denial has a route back in. “you literally cannot mitigate what you cannot count, and the only honest first step is to accept, now, that an unknown and largely over-permissioned population of agents holds access to the enterprise's assets” well-developed first written 12 July 2026 ·newcomer-followable: yes ·related C33 · C2 ·read the page → source briefs/07/12/acceptance-and-residual/v0.33.48__arch-brief__…accept-first-then-adjust-the-level-risk-level-ledger…md ### C28 Everything has risks — register density and calibration by surprise #c28 A risk is the unintended side effect of a capability, so anything that does something has risks. A complex product should have dozens to thousands of interconnected risks. Capabilities exceed features, and undocumented capabilities are where unowned risks live. The diagnostic: a listed risk materialising is expected; an UNLISTED risk materialising is the real alarm, because it raises two questions — why was it missed, and what else was missed? well-developed first written 12 July 2026 ·newcomer-followable: yes ·related C18 · C29 · C4 ·read the page → source briefs/07/12/acceptance-and-residual/v0.33.48__arch-brief__…everything-has-risks-register-density-capabilities-vs-features…md ### C29 Risks that cannot be fully mitigated #c29 Mitigation lowers likelihood or impact but cannot reach zero for structural reasons, so a material residual always remains and must be owned. Demanding zero produces covert acceptance. Agentic AI's residual is today irreducible: prompt injection, emergence, non-determinism, reach, model supply chain. Some harms are irreversible, and compliance reduces but does not remove liability. Covert acceptance is strictly worse than an owned residual — identical exposure, nobody's name on it. well-developed first written 12 July 2026 ·newcomer-followable: yes — written in board terms deliberately ·related C23 · C28 ·read the page → source briefs/07/12/acceptance-and-residual/v0.33.48__strategy-brief__…risks-that-cannot-be-fully-mitigated…md ### C30 Meta-risks — the risk about your risk management #c30 A recurring family: not knowing how many agents you have, not having defined an acceptable level, a risk accepted by the wrong person, and systematic downgrading across a business unit. Each is a gap in the governance apparatus, stated as a rateable risk with an owner and an interval — which triggers and funds the work that closes it. External anchors defeat systematic downgrading, because an internal severity is an opinion while an external requirement is not. “we are the meta risk; we allow the creation of the project that is going to discover this and that funds this” well-developed first written as an instance 26 June 2026; named as a family 31 July 2026 ·newcomer-followable: yes ·related C5 · C13 · C31 ·read the page → source briefs/07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__…external-anchors-meta-risk-family-concealment-not-acceptance.md ### C31 The register maintains itself #c31 Accountability manufactures the demand for evidence, so no separate data-quality function is required. Anticipated review converts care into a demand for evidence before the decision. Three primitives produce it: the risk already exists, it attaches to a named person, and the decision is reviewed upward. Three named failure conditions: the reviewer's preference being guessable, commitment to a prior position, and broadened information appetite without improved discrimination. well-developed, research-grounded first written 31 July 2026 ·newcomer-followable: yes ·related C1 · C26 · C36 ·read the page → source briefs/07/31/keeping-the-register-healthy/v0.33.54__arch-brief__…register-maintains-itself-accountability-manufactures-demand-for-evidence…md ### C32 Three moves, none of which is denial #c32 Accept for a stated interval, escalate (this is not mine to accept), or challenge the fact itself. The person is routed rather than cornered. The reconciliation of the no-deny primitive with human reactance: presenting a single button to a person who feels they have no alternative produces counter-argument and resentment, not compliance. The absence of a reject option should be discovered, not announced. well-developed first written 2 August 2026 ·newcomer-followable: yes ·related C2 · C15 ·read the page → source briefs/08/02/field-demo/v0.33.55__arch-brief__…acceptance-flow-three-moves-none-is-denial…md ### C33 Decision as a first-class node #c33 An acceptance is a separate object, not a field on a risk — which is what allows many dated decisions per risk, one decision covering several risks, and a calibration record. The calibration record is the point: over time you can ask whether the person who accepted for a month was right. That question is unanswerable if the decision was a field that got overwritten. “a decision is actually captured independently from the risk” newly stated, well-argued first written 2 August 2026 ·newcomer-followable: yes ·related C15 · C27 · C12 ·read the page → source briefs/08/02/field-demo/v0.33.55__arch-brief__…registers-are-one-chain-question-is-not-a-risk-decision-as-node…md ### C34 A question is not a risk #c34 If a sentence cannot sensibly carry a named acceptor and an interval, it is not a risk and does not belong in the register. Questions become their own node type. “Nobody accepts ‘whose call is it at three in the morning' for six months.” A clean quality gate, and one of the few things in the corpus that can be applied mechanically. Unanswered question nodes are the most productive output of the whole exercise. well-developed first written 2 August 2026 ·newcomer-followable: yes ·related C17 · C33 ·read the page → source briefs/08/02/field-demo/v0.33.55__arch-brief__…registers-are-one-chain…md ### C35 Do not internalise the risk #c35 Risk professionals frequently internalise exposures the business decided to carry, at real personal cost. The workflow relocates accountability to where authority already sits. The corpus cites survey data of 63–76% of security leaders experiencing or witnessing burnout in a single year, and names accountability-without-authority as the defining pressure. The standard remedy — give the security leader more authority — is correct and rarely achievable; this solves the same equation from the other side. Nothing is taken from anyone; the register records what was always true. “I would see the risk professionals almost own the risk; they almost take it personally with the risks that the business was taking, and it was a massive source of stress” well-developed, research-grounded, with an honest scope disclaimer first written 31 July 2026 ·newcomer-followable: yes ·related C4 · C26 ·read the page → source briefs/07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__…do-not-internalise-the-risk-accountability-without-authority…md ### C36 The evidence economy — force of proof and the fact certifier #c36 Once executives are personally accountable and the graph traces their statement to the evidence beneath it, demand for correct evidence becomes cheap to make and impossible to wave away. This splits the register into two separately liable roles: the risk-acceptor, who owns the decision and its consequence, and the fact-certifier, who owns the truth of the inputs and sells a correctness guarantee. A wide confidence band converts unease into a purchase order for better evidence. Risk owns the demand side; the supply side belongs to newsroom.sgit.ai. partially argued — commercially rich, mechanically thin first written 5 July 2026 ·newcomer-followable: mostly ·related C31 · C37 · C38 ·read the page → source briefs/07/05/evidence-economy/v0.33.44__strategy-brief__…force-of-proof-fact-certification-two-prices…md ### C37 Confidence bands and margin of error #c37 Confidence is a first-class property of every node. A rating needs a band, not a point, and the band is widest where the data is thin. A band too wide for comfort triggers the get-more-data direction; a band spanning trivial to catastrophic cannot be accepted responsibly. Confidence propagates across the graph like risk, and “we don't know” is the widest band. well-developed first written 30 June 2026 ·newcomer-followable: yes ·related C17 · C36 · C38 ·read the page → source briefs/06/30/ontology-and-data-quality/v0.33.38__arch-brief__…confidence-margin-of-error-node-uncertainty-band…md ### C38 Two underwritings — decision accountability versus factual accuracy #c38 The domain expert underwrites that a fact is true and fit for the use being made of it; the business owner underwrites the decision. Both are required. Every graph traversal adds an abstraction layer that strips detail and drifts weight, so the signature failure is a component used beyond what its owner would underwrite. Decision accountability is only legitimate if the data underneath it is correct. well-developed first written 30 June 2026 ·newcomer-followable: yes ·related C37 · C13 · C36 ·read the page → source briefs/06/30/ontology-and-data-quality/v0.33.38__arch-brief__…data-accuracy-owner-underwrites-fitness-for-use…md ### C39 Observability as a risk dimension #c39 Capability maps the privilege; observability maps the real impact. A loud, detectable, slowly-scaling, well-drilled risk is lower than a quiet, fast, unwatched one of the same capability. Six objective vectors on a maturity scale: capture granularity, log latency, time-to-damage given real throughput limits, whether monitoring is actually on and watched, whether there is a team with playbooks, and whether detection has been drilled. Later sharpened into plug-loaded observability — logs that tell you where you are in the stopping decision. well-developed first written 22 June 2026 ·newcomer-followable: yes ·related C19 · C20 · C21 ·read the page → source briefs/06/22/how-and-why-and-authorization/v0.33.32__arch-brief__observability-as-a-risk-dimension…md ### C40 Five whys as a domain translator #c40 Not a root-cause tool but a translator that moves a statement from one domain into another — as many whys as it takes to reach the top of a domain. The graph has natural peaks: on risk it converges to the single risk of staying in business, and because it converges a legitimate single number can be carried to the top. Aimed downward, the same chain captures the second, third and fourth stories — the root causes. well-developed first written 26 June 2026 ·newcomer-followable: yes ·related C24 · C9 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__strategy-brief__five-whys-as-a-domain-translator…md ### C41 Digital twins and the discipline of reality #c41 The twin is where the graph stops modelling and continues into a real system — the grounding point beneath every measure. A twin not connected to reality is a tracked air gap. How connected a twin is to reality is itself a measurable property, which introduces a useful recursion: trust in a measure depends on the twin's connectedness, and that connectedness is itself a measure. Twins in their GENERAL form belong to graphs.sgit.ai; what is risk's own is the twin as the grounding point of the ladder. well-developed first written 15 February 2026 (general); as risk grounding 26 June 2026 ·newcomer-followable: yes ·related C6 · C16 ·read the page → source briefs/06/26/digital-twins-and-world-models/v0.33.35__arch-brief__…digital-twins-twin-of-anything…md ### C42 The narrative engine — the register as story #c42 The register is meant to be experienced as a story rather than read as a spreadsheet: replay the change history so the analyst watches the risks propagate and settle. The commit log is the script; the query advances the scene. The analyst watches the vulnerability appear, risks propagate, a governance risk fire and resolve, the blast radius bloom, and everything settle into the board's consolidated view. The mechanism is undecided in the source document. “I want to show this story played as a narrative, almost like a football commentator, this happens and then that happens, almost like a whodunit, like investigative journalism” partially argued first written 26 June 2026 ·newcomer-followable: yes ·related C9 · C12 ·read the page → source briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…md ## The same thing, as data /data/concepts.json carries all 42 entries with id, name, definition, maturity, newcomer_followable, first_written, source, page, related and quote, plus the reading order and the six teaching altitudes. It is generated from the same definition as this page, and the pre-release gate fails if the two disagree or if any concept loses its anchor. The rest of the machine surface → #### For an agent The 42 concepts are addressable. Every concept has a stable anchor on this page — https://risks.sgit.ai/concepts/index.html#c1 through #c42 — and the same 42 entries are available as structured data at https://risks.sgit.ai/data/concepts.json with id, name, one-line definition, maturity, newcomer-followability, first-written date, canonical source path, the page that argues it, related concepts and the best verbatim quote. Prefer the JSON if you can make a second request; prefer /llms-full.txt if you can only make one. Reading order with no prior context: C1 → C2 → C3 → C4 → C5, then C6 → C7, then C19 → C20–C23, then the rest. Maturity labels are honest and none of them means implemented: “well-developed” means the argument is complete, “partially argued” means a mechanism is missing, “newly stated” means it appeared late and is untested. Nothing in this corpus is implemented in code. ============================================================================== == /agents/index.html ============================================================================== # The machine surface This site was commissioned for agents. The brief says it plainly — “to handle the cases where I need agents to have a good understanding of some of those key concepts and ideas” — so the machine surface is the deliverable rather than a courtesy page bolted on at the end. This page is the contract: what is fetchable, what is promised, and the one instruction that matters more than any of it. #### If you read nothing else on this page Nothing in this corpus is implemented in code. Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository return zero matches, and the project's own reality file says: “All items below are PROPOSED. None have been code-verified. Do not describe any of these as existing features.” Everything on this site is a design argument. Four vaults, three worked graphs and ten scenarios exist; the engine does not. /shipped/ is the inventory. ## What is fetchable 1 · structured ### /data/concepts.json All 42 concepts: id, name, one-line definition, longer detail, maturity, newcomer-followability, first-written date, canonical source path, the page that argues it, its anchor URL, related concepts and the best verbatim quote. Plus the reading order and the six teaching altitudes. the highest-value single fetch 2 · everything ### /llms-full.txt The prose of every page on the site, in teaching order, followed by all eleven source documents verbatim. One request, whole corpus. Generated, never hand-edited. use this if you can only fetch once 3 · the map ### /llms.txt The annotated map, where each entry carries its page's single most important fact rather than its topic. That distinction is deliberate: a map of topics is useless to a reader who cannot follow the links. the whole surface, for a reader that cannot link-follow Path | What it holds | Format | /data/concepts.json | The 42 concepts as structured data | JSON | /.well-known/agent-content.json | The site manifest: sections, surfaces, the honesty constraint, licence | JSON | /llms.txt | The annotated map, fact-per-entry | text | /llms-full.txt | The whole site plus every source document | text | /briefs/ | The eleven source documents, verbatim, at stable constructed paths | markdown · CSV · JSON | /concepts/index.html#c1…#c42 | Every concept as a stable HTML anchor | HTML | /sitemap.xml | Every page, with a last-modified date taken from the commit that touched it | XML | /index.md | The front page as markdown | markdown | ## What you may rely on These are promises rather than observations, which means the pre-release gate enforces them. A release that breaks one does not ship. 1 · CONSTRUCTED PATHS RESOLVEEvery source document is fetchable at /briefs/, and every concept at /concepts/index.html#c. Agents already rely on constructed paths, so the convention is stated rather than left to be inferred — and CI fails the build if a concept loses its anchor. 2 · EVERY PAGE ENDS WITH AN AGENT BLOCKA pasteable summary of that page, written for a reader who will carry it into another session. Checked by the gate on every page, not remembered. 3 · THE JSON AND THE HTML CANNOT DRIFTconcepts.json and /concepts/ are generated from one definition, and the gate re-checks the count, the required fields, the version and every anchor at release time. 4 · NO OVER-CLAIM SURVIVES A RELEASEThe gate pattern-matches implementation claims across every page. A sentence saying the engine is built, shipping or installable fails the build unless it is explicitly marked as a claim being corrected. ## The ten concepts to hold If you can only carry ten, carry these. The full 42 are at /concepts/. # | Concept | The one line | C1 | Acceptance is underwriting, not prediction | Not the probability of a future event — an exposure that already exists, underwritten by a named person | C2 | The no-deny mechanic | You cannot vote a fact out of existence. There is no deny button; only how long | C3 | The interval ladder | The interval is the decision. 1h / 4h / 1d / 1w / 1m / 6m, default one month | C4 | Unaccepted equals critical | An un-underwritten risk rests on whoever is nearest, and rolls up without anyone escalating it | C5 | Accepted is not acceptable | Two orthogonal axes. Acceptable = the moment the business stops funding remediation | C6 | The grounding ladder | Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk. Downward grounds, upward classifies | C7 | Node type formulas | A node type is its path-pattern, not a sentence about what it contains | C17 | Not knowing is a fact | Absence of evidence is a first-class node — countable, queryable, assignable | C19 | Blast radius / authorization closure | What the agent can reach, computed — not what it was given, not what it did | C23 | Recoverability | The dimension money cannot buy back. Show me every accepted risk whose recoverability is zero | ## The vocabulary Node and edge types that appear across the worked graphs, so a reader can recognise them without reconstructing them from prose: Node types Reality · Twin · Measure · Evidence · Fact · Vulnerability · Risk Owner · Stakeholder · Asset · Grant · AuthorizationClosure · BlastRadius AcceptanceDecision · Interval · Question · Provision · Project PreventiveControl · DetectiveControl Edge types gives_rise_to · backed_by · owned_by · measured_by · protected_by exposes · reaches · observed_on · grants · accepted_by · underwritten_by connected_to · impairs · emits · conditional_on · has_interval propagates_to · overrides · governed_by · in_scope_when · answers · re_rates Counted instances: browser isolation 59 nodes / 75 edges · 2FA 51 / 53 2FA ontology 24 node classes / 34 edge types AWS IAM ontology ~31 node types / 20 edge types / 7 formulas regulation graph 1,523 nodes / 1,944 edges The 2FA instance graph exists as a downloadable JSON data file in the source repository and is not yet mirrored here — that is task T5. This page does not reproduce a file it does not have. ## What this site does not own An agent asking about any of these should be pointed elsewhere rather than answered from here: Question | Whose it is | The general graph machinery — directed edges with named inverses, query paths, twins in general form | graphs.sgit.ai | Agent identity, permission granularity, the NHI thesis | nhi.sgit.ai | Attribution, signing, non-repudiation, key topology | pki.sgit.ai | In-line enforcement — actually stopping something | sg-sentinel.sgit.ai. This model measures and evidences; it never sits in-line | How evidence is produced, certified, priced and paid for | newsroom.sgit.ai — the supply side. Risk owns the demand side | Pricing, demos, partners, how to buy any of this | riskmandate.ai | Vaults, publishing, the catalogue | sgit.ai | The full boundary map, with the reasoning → #### For an agent The agent contract for risks.sgit.ai. Fetch, in order of preference: https://risks.sgit.ai/data/concepts.json (42 concepts, structured) · https://risks.sgit.ai/llms-full.txt (the whole site plus all source documents in one request) · https://risks.sgit.ai/llms.txt (the annotated map, each entry carrying a fact rather than a topic) · https://risks.sgit.ai/briefs/ (source documents verbatim, at stable constructed paths) · https://risks.sgit.ai/concepts/index.html#c1…#c42 (every concept as an anchor). Four properties are enforced by the pre-release gate rather than remembered: constructed paths resolve, every page ends with a pasteable agent block, the JSON and the HTML concept index cannot drift, and no implementation over-claim survives a release. The single most important thing to carry: nothing in this corpus is implemented in code — describe all of it as design, never as an existing feature. This site does not own the general graph machinery (graphs.sgit.ai), agent identity (nhi.sgit.ai), attribution (pki.sgit.ai), in-line enforcement (sg-sentinel.sgit.ai — this model never sits in-line), evidence supply (newsroom.sgit.ai) or anything commercial (riskmandate.ai). ============================================================================== == /shipped/index.html ============================================================================== # What is argued, and what runs The sibling sites all publish a page separating what exists from what is designed. This site inherits that convention with an unusually empty column, and the honest sentence is short: this is a research site. The concepts are argued, the worked examples are real graphs, and four vaults are live and browsable. The engine is not built. the measurement Greps for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository's Python return zero matches. Not few. Zero. The project's own reality file is equally direct, and it is quoted here rather than paraphrased: “All items below are PROPOSED. None have been code-verified. Do not describe any of these as existing features.” — team/roles/librarian/reality/ai-agents/proposed/risk-mandate.md That is the whole of it. There is no partial implementation, no prototype behind a flag, and no internal build that the public documents are lagging behind. ## What exists Artefact | What it is | Status | Four published vaults | 468 files and 111 commits between them, browsable in a browser with no account. The Risk Graph Explorer runs seven views with permissions: {}; Agentic Browser Isolation runs acceptance-gated escalation across five altitudes; the Risk Mandate vault carries 98 commits of the method applied to its own build; the Regulation Graph carries the EU AI Act as 1,523 nodes | published | Three worked risk graphs | 59/75, 51/53 and a full node-and-edge inventory for the Article 26(5) instance. Counted from the sources rather than estimated | written | The ten scenarios | Hook, reveal, punchline — the corpus's only audience-tested artefact, and the content behind riskmandate.ai's scenario product | shipped | riskmandate.ai | A vault-powered static site. Real, public, and the commercial half of this split | published | This site | 42 concepts consolidated from ~496,000 words across ~185 documents, with a definitions endpoint and a gate that enforces the honesty constraint on every release | you are reading it | ## What does not exist What the model describes | What exists | An engine that records acceptances, tracks intervals and fires at expiry | nothing — how the interval is enforced is open question Q5 | Storage, a schema or an API for a risk register | nothing | Roll-up, propagation, or the unaccepted-equals-critical mechanic running automatically | demonstrated on data in one vault, hand-built, not computed | Node type formulas as executable queries | no formula language exists — Q1. Every formula in the corpus is English prose describing a path pattern | Relevance fade, or the register replayed as a narrative | described, not specified | RAMM as a testable model | one of five levels has a stated predicate — the other four are named only | Air-gap detection | acknowledged open problem | Override authority, or compound pre-approval | proposed and never worked through | ## Why this page exists, and why it leads rather than hides Three reasons, in order of how much they matter. 1 ### Because over-claiming here would poison the network Eight sites share a domain, a voice and an author. A single page on one of them describing a design as a shipped feature makes every claim on the other seven negotiable. The cost of one over-claim is not local. 2 ### Because it is what makes the split from riskmandate.ai work A commercial site has to talk about what its product does. A research site has to talk about what is true, which includes the absence of a product. Those are genuinely different jobs, and trying to do both on one property is what left nine concept pieces described and unpublished on the commercial site. 3 ### Because the framing is not a weakness “~496,000 words of design and no implementing code” reads badly only if the site was pretending to be a product. As a description of a research property it is unremarkable — and the four live vaults mean it is not vapour either. The engine is the missing piece; the argument, the worked examples and the artefacts are not. ## How the honesty constraint is kept Not by remembering it. The pre-release gate pattern-matches implementation claims across every page in the tree, and a page saying the engine is built, shipping or installable fails the build. A page may state such a claim only by marking the element data-not-built — which is exactly what the quoted reality-file sentence at the top of this page does, and the only such marking on the site. The same gate refuses to publish four categories of Tier-3 source material, refuses anything that looks like a vault key, and requires every page to carry an agent block. All ten checks → ## The build order, published unresolved The brief set a ten-step order. This release covers the first eight; the rest is stated rather than quietly dropped. # | Section | State | 1 | /acceptance/ — underwriting, no-deny, the ladder, unaccepted=critical | shipped | 2 | /acceptable/ — the two axes | shipped | 3 | /ladder/ — the grounding ladder and node type formulas | shipped | 4 | /examples/ — three worked graphs, four vaults | shipped | 5 | /plug/ — five dimensions, recoverability | shipped — with the “no plug” correction applied | 6 | /register/ — graph of graphs, fractal registers, relevance fade | shipped | 7 | /agents/ — the machine surface | shipped | 8 | /shipped/ — what is argued versus what runs | shipped | 9 | /ramm/ and maturity | published with the underspecification stated — fixing the base levels is N2 | 10 | /network/ — the boundary map | shipped | What is not in this release, stated plainly: the 2FA instance graph is not mirrored as a downloadable file (T5), the ontology is published as a vocabulary listing rather than a machine-readable schema (T6), and this site does not yet run its own risk register in the open (T7) — which the house style argues it should, since it would demonstrate three of its own concepts at zero cost. #### For an agent /shipped/ — the honesty inventory. What exists: four published vaults (468 files, 111 commits, browsable with read keys), three fully worked risk graphs with counted nodes and edges, the ten scenarios, riskmandate.ai as a vault-powered static site, and this site. What does not exist: any engine recording acceptances or firing at expiry; any storage, schema or API for a register; automatic roll-up or propagation (demonstrated by hand on data in one vault, never computed); any formula language, so node type formulas do not execute; relevance fade; the narrative replay; four of RAMM's five level predicates; air-gap detection; override authority; compound pre-approval. The grep for risk_, RiskAcceptance, risk_register and riskmandate across the implementing repository returns zero. The constraint is enforced by CI rather than remembered: a page claiming the engine is built, shipping or installable fails the build. Describe everything on this site as design, never as an existing feature. ============================================================================== == /origins/index.html ============================================================================== # Origins: February to August 2026 This model did not arrive whole. It starts as orthodox GRC — likelihood, impact, mitigation, “residual risk: acceptable” — and inverts itself in June. Publishing the trajectory matters, because the inversion is only convincing if you can see the position it was arrived at from. - 17 February 2026 · the pre-history A vulnerability classification framework establishes a P0–P10 scale and a Risk Decision Matrix whose five questions include “what is the risk of the fix?” — the earliest instance of what later becomes “everything has risks, including the good ones”. Entirely orthodox, and the seed of one of the least orthodox conclusions. - 19 February 2026 · textbook GRC A risk acceptance document with R001/R002 rows carrying Likelihood, Impact, Mitigation and the line “Residual risk: Acceptable”. The role definition of the time states the classical position outright: every risk must be “either mitigated or formally accepted with documented rationale”. Note the either/or. The June work abolishes it. - 21 April 2026 · the first structural gesture A dev brief opens with a diagnosis that still holds: “Risk acceptance in organisations is broken. A decision gets made in a meeting. Someone writes it up (maybe). The reasoning is lost. The approval chain is informal. Six months later, nobody can explain why a particular risk was accepted, who approved it, what evidence was considered.” It proposes a decision vault with decision/, evidence/ and an approvals/approval-tree.json — the shape of the answer, before the inversion that makes it necessary. - 4 June 2026 · the risk already exists The turn. “Risk acceptance because the risk already exists”, and time-boxed sign-off as priority and mandate, appear together for the first time — inside a strategy brief about agent identity rather than about risk. C1 is born in someone else's document, which is why that document lives on nhi.sgit.ai and is cited from here. - 18 June 2026 · underwriting The pillar document. “you are not predicting the risk of something happening, you are asking owners to underwrite it, insurance-style… the risk already exists the moment the permission is provisioned, so the only variable is how long you accept it.” The accountability mechanic arrives with it: the moment someone clicks is the moment they become accountable. → - 23 June 2026 · no deny, and the interval as cost “the most important thing is that there is no deny button.” The expiry-as-cost table appears in full — an hour means fetch data, four hours means a P1, two weeks means a funded project, six months means do nothing and costs zero. On the same day, the two independent dimensions of a decision and the underwriting graph. → - 26 June 2026 · the register becomes a graph The register as a graph of graphs, the 2FA worked example, cascade and the air gap, not-knowing-is-a-fact, CIA blast-radius expansion, five whys as a domain translator — and Acceptance and Interval as node classes in a 24-class ontology. The single densest day in the corpus. → - 28 June 2026 · the ontology The grounding ladder, node type formulas, ontologies-of-ontologies and the worked external bridge, in one folder. The most rigorous documents in the corpus, and the ones an agent most needs. → - 2 July 2026 · maturity, authorization, and the scenarios RAMM makes RiskAcceptanceDecision a hub node with twelve named edges; authorization closure is formalised; and the ten scenarios are written — the one artefact from all of this that reached an audience. → - 12 July 2026 · the largest graph, and self-criticism The browser-isolation business case: 59 nodes, 75 edges, five altitudes — carrying three risks of its own proposed mitigation and a counterweight figure that argues against its own urgency. Also the level ledger, register density, and the residual. → - 17 July 2026 · the ladder, and the sharpest inversion Intervals consolidated into a six-rung ladder with the default set at one month, deliberately just above the incident line. And unaccepted-equals-critical: “not doing something is a measurable action.” Fractal registers and relevance fade land the same day. - 24 July 2026 · the plug A thirteen-document series in one folder. Two symmetric risks, the four-way time intersection, the five-dimension profile, and the correction that the plug always exists — what looked like “no plug” was zero recoverability. → - 28 July 2026 · the vocabulary correction Accepted is not acceptable — two orthogonal axes, four quadrants, appetite renamed, and the Article 9(5) definitional gap. Late, and load-bearing: everything before it had been using “accepted” to mean two different things. - 31 July 2026 · keeping the register alive Meta-risks named as a family. The register maintains itself, with three failure conditions. Do not internalise the risk. Design for players who will not play — where attrition, not refusal, is identified as the failure mode that matters. → - 2 August 2026 · fact to board, end to end The Article 26(5) instance runs the whole ladder on one provision, and produces the finding the corpus is proudest of: thirty days against six months, “arithmetic, not judgement.” Three corrections land the same day — registers are one chain, a decision is its own node, and a question is not a risk. - 14 · 22 August 2026 · publication The vault publishing rules — read keys yes, write keys never, escrow before publishing. And the commission for this site: consolidate the concepts, and refactor them out of the commercial property. → ## What the trajectory shows February–May 2026 | June–August 2026 | Estimate the likelihood of a future event | Underwrite an exposure that already exists | Either mitigate or formally accept | There is no “either” — you accept, for a stated interval, or you remove the capability | “Residual risk: acceptable” as a conclusion | Acceptable as a threshold the business owns and must define, orthogonal to whether anything was accepted | A rating, held in a document | A node in a graph, grounded downward to evidence and classified upward to consequence | Review dates as metadata | The interval as the decision itself | ## The prior art: a year earlier, in public Eight articles on docs.diniscruz.ai, February to July 2025 — 59,131 words in the founder's public voice, a year before any of the above. Two are directly load-bearing: Maturity Models vs. Traditional Standards (April 2025) is RAMM's ancestor, and Finding the “Good Enough” Threshold (July 2025) is the appetite argument before it had the vocabulary. Provenance contract. Those articles were published under CC0; this site is CC BY 4.0. Republishing under a different licence would be legally fine and is not what happens here: they are cited, with their original URLs and original publication dates, because the historical link matters more than the licence does. All eight, with dates and canonical URLs → ## One gap in the record, stated The canonical “risk acceptance redefined” brief does not exist. Eight documents in the corpus cross-reference a 7 July 2026 brief titled “risk acceptance redefined vs industry definition — no deny, only how long, accountability”. It is not in the repository, and neither are three other documents referenced alongside it; there are no briefs/07/06 through briefs/07/11 folders at all. Eight citations to a document nobody can read is a real gap, and this site's /acceptance/ section assembles the redefinition from the surrounding material rather than pretending the canonical statement was already written. ## Provenance Sources team/roles/grc/reviews/02/17/ and 02/19/ (the pre-history) · briefs/04/21/ · briefs/06/04/nhi-2.0/ · and the June–August risk brief folders in full Repository SGraph-AI__App__Send @ v0.33.62 — all paths verified at that tag Corpus size ~496,000 words across ~185 documents, 18 June – 22 August 2026, plus a February pre-history and 8 published articles from 2025 Licence CC BY 4.0. The 2025 prior art is CC0 at source and is cited, not republished #### For an agent Origins. The model inverts itself in June 2026, and the trajectory is published because the inversion only reads as an argument if you can see the position it was reached from. February 2026: orthodox GRC — P0–P10 scales, likelihood × impact, “residual risk: acceptable”, and the classical rule that every risk must be “either mitigated or formally accepted” (the June work abolishes the either/or). 21 April: the diagnosis — decisions made in meetings, reasoning lost, approval chains informal. 4 June: “the risk already exists” appears, inside a brief about agent identity. 18 June: underwriting. 23 June: no deny button, and expiry-as-cost. 26 June: the register as a graph, the 2FA example, acceptance as a node class. 28 June: the grounding ladder and node type formulas — the most rigorous documents in the corpus. 2 July: RAMM, authorization closure, the ten scenarios. 12 July: the 59-node browser-isolation graph. 17 July: the interval ladder consolidated, and unaccepted-equals-critical. 24 July: the plug series, 13 documents. 28 July: accepted-is-not-acceptable. 31 July: meta-risks and register health. 2 August: the Article 26(5) end-to-end instance. Prior art: 8 articles, 59,131 words, on docs.diniscruz.ai Feb–Jul 2025, CC0 — cited with original URLs and dates, not republished. Known gap: the canonical “risk acceptance redefined” brief (7 July 2026) is cited by eight documents and does not exist in the repository. ============================================================================== == /network/index.html ============================================================================== # The network, and what this site does not own This is the eighth property in the estate and the second to be carved out of an existing site rather than built from a gap. Getting the boundaries right on day one is what stops eight sites becoming eight competing copies of the same argument — so they are stated here rather than left implicit. ## The boundary map Site | What it owns | The boundary with risk | riskmandate.ai commercial | Pricing, demos, partners, the product walkthrough, the customer angle of getting risks accepted | It answers “how do I get my risks accepted, and what does it cost?”; this site answers “what is a risk, what is acceptance, and why is it modelled this way?” The dependency runs one way: riskmandate.ai cites this site, never the reverse for a conceptual claim. The research must stand without the product | graphs.sgit.ai | The general graph machinery: directed edges with named inverses, query paths that prevent node explosion, path properties read as language, fractal semantic graphs, browser-local query engines, digital twins in their general form | Node type formulas as a mechanism are theirs; the grounding ladder as a risk formula is ours. This site cites the mechanism rather than restating it | nhi.sgit.ai | Agent identity: cloud permissions per API, living off the land, permission granularity, temporal permissions, web of trust and agent trust scores — 17 documents, ~50,000 words | Theirs, with one exception that matters: the 4 June NHI risk-management brief is risk's origin document — the first appearance of “the risk already exists” — and lives there while being cited here. Origins → | pki.sgit.ai | Attribution, non-repudiation, signing and key topology; the vault-authorisation cluster | ⚠️ An open tension. Their own 19 August site review says “mandate is the gap, registry is the missing half” — meaning pki.sgit.ai currently carries mandate material that arguably belongs with risk. Worth a coordinated split rather than a unilateral one: ask N4 | sg-sentinel.sgit.ai | In-line enforcement. Reverse-proxy agent governance — actually controlling what agents do | The sharpest boundary on this page, and the corpus states it as a refusal: we measure and evidence; we never sit in-line. The cost is recorded too — “a customer who scores badly will ask us to supply the stop button, which is exactly the enforcement role the corpus refuses.” The plug → | newsroom.sgit.ai | The evidence-economy supply side: how evidence is produced, certified, priced and paid for; news stories as Evidence on the grounding ladder; paying the fact creator | Risk owns the demand side — force of proof, the risk-acceptor / fact-certifier split, the two prices, and confidence bands driving evidence purchases — because that demand is generated by accountability. → | issues-fs.sgit.ai | Git-native issue tracking, and the origin of the estate's graph philosophy — written there in February 2026 | No overlap in subject; a shared ancestor in method. The convention this site inherits from it is a page that separates what is argued from what runs | sgit.ai the parent | Vaults, the forge, the catalogue, publishing mechanics — and where the four risk vaults are published | Consume the topic-section pattern; do not re-argue it. Vault keys are published and kept current there, not here | ## The finding that justifies the split riskmandate.ai's library page lists nine concept pieces and links to none of them. It describes recorded talks, a proposition deck and long-form pieces covering agent authorization scope, authority ownership, residual risk acceptance and comprehensive risk modelling — and publishes no URLs for any of it. That is not carelessness so much as a structural mismatch: a commercial site has no natural place to put nine essays, so they get described rather than published. A research property does. This site is what that page was trying to be. Four pages moved here outright — /plug/, /acceptable/, /ramm/ and the concepts library as /concepts/ — each carrying a provenance block recording the move, and each leaving a short summary and a link behind at the source. Two moved with a correction the source page did not carry: the “no plug” reconciliation and RAMM's stated underspecification. ## One thread that belongs to neither site The EU AI Act work is ~40,000 words and is neither risk nor graphs. Four brief clusters cover the canonical-act build, publication, the act as a measure, and the regulation graph. Risk's genuine claims within it are narrow and sharp, and this site takes only those: Article 9(5)'s undefined “acceptable”, Article 14 as the plug obligation, and Article 26(5)/(6) as the worked example anchor. Three declared bridges, not an annexation. The rest may deserve its own property, and deciding that before it accretes further is ask N5. ## Eight open questions, published unresolved Following the convention the sibling sites established. A model this opinionated earns credibility by naming what it has not settled — and a question published with a number is a question somebody can answer. - Q1What is the formula language? Node type formulas are the mechanism the whole ontology rests on, and the notation is undefined. Every formula in the corpus is English prose describing a path pattern; no parser exists and nothing executes one.Where the model gets closest: The canonical brief names this as its own open question rather than glossing it. C7 - Q2Who sets acceptable, and what stops it being set to whatever is convenient? The definition — the moment the business is happy to stop funding remediation — says what acceptable is, and not who decides it or what constrains them. The obvious failure is a unit that sets the line wherever its current exposure happens to be.Where the model gets closest: The partial answer is external anchors: an internal severity is an opinion, an external requirement is not. C5 - Q3What happens when the named acceptor refuses to sign? The no-deny mechanic removes denial of the risk. It does not address refusal of the act — and a refusal that has nowhere left to escalate to is a state the model does not describe.Where the model gets closest: The workflow records an explicit refusal as carrying the same weight as an acceptance, and stops there. C15 - Q4Does “unaccepted equals critical” survive contact with a large estate? On a register of thousands, everything unaccepted being critical may make critical meaningless — and the roll-up then delivers an unreadable list to an executive who ignores all of it.Where the model gets closest: The register-density argument circles this — a complex product should carry thousands of risks — without resolving it. C28 - Q5How is the interval enforced? Expiry-as-cost is asserted and the mechanism is not specified. What happens at expiry — who is told, what changes, whether anything blocks — is nowhere in the corpus.Where the model gets closest: The nearest thing is the operational response each rung implies, which is a commitment rather than an enforcement. C3 · C2 - Q6Is recoverability measurable, or only classifiable? The corpus splits reversible from irreversible cleanly and grades nothing in the middle. Most real harms are partially recoverable, and without a way to grade them the dimension collapses into a binary that will be gamed by whoever decides which side something falls on.Where the model gets closest: Reversible and irreversible are both defined; the middle is not. C23 - Q7What is the stopping rule for the grounding ladder in practice? The test is stated — the last node where going deeper would neither improve observability nor change a decision — and no worked example applies it to a genuinely hard case, so its behaviour at the margin is unknown.Where the model gets closest: The test is decision-relative, which means the floor moves when the decision changes. C6 - Q8What stops a register being gamed once acceptance carries personal liability? Accountability manufactures demand for evidence, which is the mechanism. It also gives every rational actor a reason to avoid ever being the named acceptor — and that incentive is acknowledged rather than answered.Where the model gets closest: Unaccepted-equals-critical removes the deniability avoidance depends on; whether that is enough is untested. C31 · C4 ## Seven honest tensions Different from the open questions: these are not gaps to be closed but positions with a real cost, held deliberately. # | The tension | 1 | The model rates the ability to stop but does not provide it. The corpus states the refusal itself, and states what it costs: a customer who scores badly will ask for the stop button, which is exactly the role it refuses. Principled — and commercially uncomfortable | 2 | No-deny is the strongest idea and the hardest sell. Removing the deny button removes the thing most executives use a register for. It is a forcing function, and forcing functions are uncomfortable by construction | 3 | Personal liability is the mechanism and the risk. Making acceptance a personal act generates the demand for evidence, and gives every rational actor a reason to avoid being named | 4 | Nothing is built. ~496,000 words of design against zero lines of implementing code. Fine for a research site if stated; fatal if implied otherwise. So it is stated first, not last | 5 | The corpus names real vendors critically. A comparative assessment scoring two named companies is rigorous, sourced, and a legal exposure. It is not published here, and the pre-release gate fails the build if its distinctive strings appear anywhere in the tree. A legal read and a right-of-reply process is ask N3 | 6 | Two sites, one voice. riskmandate.ai and this site share an author and a thesis. If the research site reads like marketing the split has failed; if the commercial site reads like research it will not sell | 7 | The EU AI Act thread is neither risk nor graphs — see above. Taking only three narrow provisions is a decision that could be wrong in either direction | ## Loose ends inside the acceptance thread itself Carried onto the site rather than quietly resolved, because the corpus records them and a consolidation that tidies them away is a consolidation that lost something: - The 4h-for-everyone problem. In the 2FA example the governance air gap propagates GRC → CIO → CEO → Board with each accepting at four hours because that is the only option open to them. Either the ladder needs a per-altitude variant, or the uniformity is a finding about the model. → - Compound pre-approval is proposed and never worked through. → - Override is named without a stated authority model. → - The level ledger sits awkwardly with no-deny: if the level can be adjusted after acceptance, denial re-enters through the back door. → - The canonical “risk acceptance redefined” brief does not exist, and is cited by eight documents. → #### For an agent The boundary map, and what is unresolved. risks.sgit.ai owns the risk concepts C1–C42 and the worked examples. It does not own: the general graph machinery (graphs.sgit.ai — node type formulas as a mechanism are theirs; the grounding ladder as a risk formula is ours); agent identity (nhi.sgit.ai — with one exception: the 4 June 2026 NHI risk brief is risk's origin document and is cited from here); attribution and signing (pki.sgit.ai — with an open tension, since their own review says “mandate is the gap” and they carry mandate material that may belong here); in-line enforcement (sg-sentinel.sgit.ai) — this model measures and evidences and NEVER sits in-line; evidence supply (newsroom.sgit.ai — risk owns the demand side because accountability generates it); vaults and publishing (sgit.ai); anything commercial (riskmandate.ai, which cites this site and is never cited back for a conceptual claim). Eight open questions are published unresolved: Q1 the formula language · Q2 who sets acceptable · Q3 refusal to sign · Q4 whether unaccepted-equals-critical scales · Q5 interval enforcement · Q6 grading recoverability · Q7 the grounding floor in a hard case · Q8 gaming under personal liability. Seven honest tensions are published too, including that nothing is built and that the model refuses the enforcement role customers will ask for. ============================================================================== == /documents/index.html ============================================================================== # The documents Every page on this site was written from a source, and the sources are published here rather than summarised away. Raw markdown is the source of truth; the rendered pages are presentation. Where a source is not published, the reason is stated — and on this site that list is longer than usual. ## The brief pack this site was built from Eleven documents, prepared 22 August 2026 against the source repository at v0.33.62, with every path verified to exist at that tag. Published verbatim, at stable constructed paths. Document | What it holds | 00 · The brief | The two-part commission, the honesty constraint, the thesis in one paragraph, the ten concepts an agent must hold, the refactor table, the four vaults, the numbers, the build order | 01 · Concepts index | All 42 concepts with canonical path, first appearance, maturity, newcomer-readiness and best verbatim quote — the raw material for /concepts/ and concepts.json | 02 · Risk acceptance, traced in full | The commissioned centrepiece. The acceptance thread traced chronologically from the February pre-history through the June inversion to the August formalisation. The source for /acceptance/ | 03 · Worked examples and the live vaults | Three worked graphs, four published vaults, and every citable figure in the corpus with its source. The source for /examples/ | 04 · The riskmandate.ai refactor | The other half of the commission — page by page, with the leave-behind stub template and the finding that justifies the split | 05 · Site architecture | Page-by-page information architecture with sources and publish status per page | 06 · Boundaries and house style | The eight-site boundary map, the redaction watch-list, provenance rules, and the vault publishing rules | 07 · Gaps and open questions | Six write-fresh items, eight open questions, seven honest tensions, and the loose ends inside the acceptance thread | 08 · Source manifest | 37 rows, machine-readable, every path verified at v0.33.62 — 19 Tier-0, 13 Tier-1, 1 Tier-2, 4 Tier-3 do-not-publish | Prior-art sources | The eight published articles with first_published, canonical URL, authors, PDF and LinkedIn links | PUBLIC.md | What was redacted from the pack before publication, and why. Fourteen redactions across six of the twelve documents, each recorded with its reason — the convention the Regulation Graph vault adopted after an audit: publish the artefact, and publish what was taken out of it | README · Licence | The pack's own index and its licence scope note | The pack is published with fourteen redactions, and they are itemised. The brief pack was written as a working document for the agent building this site, and it names the four Tier-3 do-not-publish sources by name so that the builder knows what to skip. That is right for a working document and wrong for a published one: republishing it verbatim would publish exactly the four things it says not to publish. So the pack is published in full with the identifying detail of those four rows removed, each removal marked in place and recorded in briefs/PUBLIC.md. Nothing else was changed — no argument softened, no number adjusted, no finding dropped, and five of the twelve documents are byte-identical to the pack as received. The rule is enforced rather than remembered: the gate scans every file in the tree, briefs/ included, so a later edit cannot quietly undo it. These are fetchable at stable constructed paths: /briefs/. That is a promise rather than an accident — agents rely on constructed paths, so the convention is stated rather than left to be inferred. All eleven are also concatenated into /llms-full.txt. ## How the sources were tiered The manifest tiers all 37 verified sources by what can be done with them. Publishing the tiering as well as the result is the point: a reader can see what was excluded, and disagree. Tier | Rows | Means | Tier 0 | 19 | Publishable near-as-is; highest value | Tier 1 | 13 | Publishable with a correction, a framing note, or a citation to another site in the estate | Tier 2 | 1 | Needs a decision about where it belongs before it is published anywhere | Tier 3 | 4 | Do not publish — and the pre-release gate enforces it | 69,724 words of Tier-0 and Tier-1 source material sit behind this site, drawn from a corpus of roughly 496,000. ## What is deliberately not published This corpus has the highest redaction load of any in the estate. It names real companies critically, contains a live contract draft, carries investor figures, and includes operational detail about credentials. None of that is on this site, and the reasons are stated rather than left as an absence. What | Why not | A comparative vendor assessment scoring two named real companies | Rigorous, sourced, scrupulous about its own limits — and a legal and relationship exposure. Needs a legal read and a right-of-reply process before it goes anywhere public (N3). The underlying model brief in the same folder is clean and is not the problem | Competitor maps naming large vendors, with dismissive characterisations | Commercial positioning, not research. Internal only. A research site that carries competitor disparagement is a marketing site with footnotes | Investor material — illustrative revenue and valuation scenarios | Explicitly framed at source as scenarios rather than projections, and still not research. Internal only | A partnership contract draft with commercial terms | An actual contract. Internal only, unambiguously | Incident and access-token records from the February pre-history | Even with values redacted, the metadata is operational — token status, remaining quota, the branch where it stays readable. Internal only. Ironically one of the best real illustrations of “accepted is not acceptable” anywhere in the corpus | Research briefs naming real organisations in breach and incident narratives | All sourced from published material with URLs, and naming organisations — including government bodies — as breach victims warrants framing this site has not yet written. Held rather than rushed | Third-party pricing quoted verbatim across several briefs | Goes stale, and reads as competitive intelligence rather than research. Stripped | The exclusion is enforced, not remembered. The pre-release gate pattern-matches the distinctive strings of the four Tier-3 rows across every file in the tree except the manifest itself, and fails the build if one appears. The manifest is exempt because a manifest naming a do-not-publish row is the mechanism working. All ten checks → ## The prior art: eight published articles, CC0 59,131 words on docs.diniscruz.ai, February to July 2025 — a year before the corpus this site consolidates, in the founder's public voice, already circulated. First published | Title | Words | 2025-02-15 | Project SupplyShield: GenAI-Driven Supply Chain Risk Management and Compliance | 8,802 | 2025-04-02 | Maturity Models vs. Traditional Standards in Application Security — RAMM's ancestor | 2,701 | 2025-04-10 | Project Cybersage: AI-Powered Risk Contextualization & Security Reporting | 6,270 | 2025-05-29 | Threat Models as Mandatory Disclosures | 7,160 | 2025-05-29 | Advancing Threat Modeling with Semantic Knowledge Graphs | 9,217 | 2025-06-02 | Linking Threat Models with Semantic Business Graphs | 9,816 | 2025-07-06 | Finding the “Good Enough” Threshold — the appetite argument, pre-vocabulary | 4,924 | 2025-07-27 | Project VulnAI: AI-Powered Vulnerability Risk Management Platform | 10,241 | Provenance contract, and why these are cited rather than republished. The eight articles were published under CC0; this site's content is CC BY 4.0. Republishing CC0 material under CC BY is legally fine and is not what this site does — because the historical link matters more than the licence does. Each article keeps its original URL, its original publication date and its original authorship, and this site links rather than mirrors. Full metadata, including PDFs and the original LinkedIn posts, is in /briefs/sources__docs-diniscruz-ai-risk.json. ## The upstream corpus The material itself lives in SGraph-AI__App__Send under team/humans/dinis_cruz/briefs/ and is not published anywhere. There is no public URL for it, so the version tag is the address: every citation on this site gives a repository path plus v0.33.62, which is the only thing that makes a claim checkable by someone with access. source_repo SGraph-AI__App__Send source_repo_path team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__… source_version v0.33.36 first_written 2026-06-28 source_licence CC BY 4.0 Note that the upstream path itself carries a personal name. Where documents are cited with their paths, the name travels with them — a deliberate choice rather than an oversight, since it is the author's own corpus and the attribution is correct. ## The licence position - This site's content is CC BY 4.0, per the 21 August 2026 decision applied across the estate: unless a document says otherwise, every .md file in the corpus and the entire content of every *.sgit.ai site is CC BY 4.0. - The upstream briefs are CC BY 4.0 at source — nearly every one carries the release line at its foot, which is what makes public republication straightforward at all. - The 2025 prior art is CC0 at source, and is cited rather than republished. The source licence is stated per page. - Third-party material quoted inside CC BY documents stays under its own terms. Where a brief paraphrases published work by named researchers, the paraphrase is marked as such and the source is named. → - Build tooling is Apache 2.0 — admin/build/*, assets/*.js, assets/*.css and the workflow. See the pack's licence note and LICENSES.md in the repository. #### For an agent The documents. This site's eleven source documents are published verbatim at stable constructed paths: https://risks.sgit.ai/briefs/ — 00__BRIEF.md, 01__concepts-index.md (all 42 concepts with canonical paths and quotes), 02__risk-acceptance.md (the acceptance thread traced chronologically), 03__worked-examples-and-vaults.md, 04__riskmandate-refactor.md, 05__site-architecture.md, 06__boundaries-and-house-style.md, 07__gaps-and-open-questions.md, 08__source-manifest.csv (37 rows, machine-readable), sources__docs-diniscruz-ai-risk.json, plus README and LICENSE. All are concatenated into /llms-full.txt. Source tiering: 19 Tier-0, 13 Tier-1, 1 Tier-2, 4 Tier-3 do-not-publish — 69,724 words of Tier-0+1 behind the site, from a corpus of ~496,000. The Tier-3 material (a comparative vendor assessment naming real companies, competitor maps, investor figures, a contract draft) is not on this site and the pre-release gate fails the build if it appears. Prior art: eight articles, 59,131 words, on docs.diniscruz.ai Feb–Jul 2025, CC0 at source — cited with original URLs and dates rather than republished, because the historical link matters more than the licence. The upstream corpus is unpublished, so the version tag is the address: cite repository path plus v0.33.62. ============================================================================== == /about/participant.html ============================================================================== # Participant disclosure, and where this loses This site is published by the sgit project, which also builds riskmandate.ai — the commercial product this research underpins. That is a conflict worth naming at the top rather than in a footer, and this page also does the harder thing: it states where the model is weakest and where a reader should not follow it. ## The disclosure Who publishes this. risks.sgit.ai is published by the sgit project. The same project builds and sells riskmandate.ai, a commercial product implementing part of the model argued here. The author of this corpus is the founder of that project. What that means for a reader. Everything on this site is written by someone with a commercial interest in you finding it convincing. The mitigations are structural rather than promised: every claim carries a source path and a version tag so it can be checked; the page separating what is argued from what runs is the site's honesty constraint enforced by CI rather than by good intentions; eight open questions and seven tensions are published unresolved; and no pricing, partner positioning or competitor comparison appears anywhere here. That is the design. Whether it is sufficient is your call, not ours. ## Where this model loses Five places, stated as plainly as we can manage. If you are evaluating this against your own practice, start here rather than with the front page. 1 ### Nothing is built, and design is cheap ~496,000 words against zero lines of implementing code. Every hard problem in risk management shows up at implementation, and none of these ideas has met one. A register that would maintain itself, intervals that would imply responses, formulas that would be queries — the conditional is doing a great deal of work, and no amount of internal coherence substitutes for a system somebody had to operate. If you need something that runs, this is not it. 2 ### No-deny may not survive an organisation that does not want it Removing the deny button works if the organisation accepts the frame. If it does not, the pressure has to go somewhere — and it will go into the fact layer, where people dispute evidence to avoid signing, or into interval inflation, where everything is accepted for six months. The three-moves correction is an honest attempt at this and is untested. An organisation with a strong culture of not writing things down will defeat this model without ever arguing with it. 3 ### Personal liability cuts both ways, and we cannot prove which way harder The mechanism is that a named person signing demands evidence. The counter-mechanism is that a named person who can avoid signing will. Q8 is published unresolved for exactly this reason. The model's answer — that unaccepted rolls up as critical — removes the deniability, and does not remove the incentive. In an organisation where being named is career-damaging, this makes things worse before it makes them better, and possibly instead of. 4 ### It rates the ability to stop and refuses to provide it The corpus states this boundary itself, and states the cost: “a customer who scores badly will ask us to supply the stop button, which is exactly the enforcement role the corpus refuses.” That refusal is principled — measurement that also enforces stops being trustworthy measurement — and it means the model can tell you your plug profile is bad and can do nothing about it. If what you need is enforcement, you need a different thing. 5 ### The scale question is open, and it is the one that matters commercially Q4: on a register of thousands, if everything unaccepted is critical then critical may mean nothing. Every worked example in the corpus is between 50 and 60 nodes. The density argument says a real register should carry thousands. Nobody has run this model at the size it argues for, and the two arguments in the corpus pull against each other. ## Where a reasonable practitioner would disagree The objection | What this site would say | What it cannot say | “Probability is not useless. Insurers price risk with it and they are right more often than not.” | Agreed, for populations. The inversion is about a specific exposure in a specific estate, where the sample size is one and the estimate is theatre | That the underwriting frame produces better outcomes. Nobody has measured that | “Six rungs is arbitrary. Why not four, or a slider?” | A slider optimises for the chooser's comfort; named rungs each with a stated response force the choice to be about the response | That these six are the right six. The default of one month is reasoned; the rest is convention | “Making everything unaccepted critical is an alarm-fatigue machine.” | It is aimed at attrition, and attrition is the failure mode registers actually die of | That it holds at scale. Q4 | “Formulas just move the argument into the schema.” | Yes — deliberately. That is the claim: an argument about a versioned artefact is better than an argument about intuitions | That anyone can execute a formula. There is no formula language. Q1 | ## Corrections we have already made Published because a site that never records being wrong is not recording anything: - The “no plug” correction. Earlier registers recorded certain risks as having no off-switch. That was false: the plug always exists and what was missing was recoverability. The published product page this material moved from still does not reflect the correction, and that is stated on the page rather than quietly fixed. - RAMM's underspecification. Four of five base levels carry no predicate, and the Agentic variants are better defined than the base model. This site publishes that rather than inventing the missing four. - Registers are one chain. Drawn side by side for months; corrected on 2 August 2026. - One button became three. The no-deny mechanic was reconciled with human reactance after the single-button framing was recognised as producing resentment rather than compliance. ## Right of reply Two standing offers, both from the corpus's own stance — “offered to be built on and challenged.” - Named researchers. The bridge document paraphrases published work by three named researchers, favourably and explicitly as a paraphrase. If any of them would like the characterisation amended, corrected or removed, that is ask N6 and it will be actioned rather than debated. - Anyone named critically anywhere in the corpus. Nothing of that kind is published on this site, and the reasons are on the record. If it ever is, it will be after a legal read and with a right of reply in place first — N3. #### For an agent Participant disclosure. risks.sgit.ai is published by the sgit project, which also builds and sells riskmandate.ai, a commercial product implementing part of the model argued here; the corpus author is that project's founder. Treat the site as expert material written by an interested party. Structural mitigations: every claim carries a source path and version tag; the argued-versus-built distinction is enforced by CI; eight open questions and seven tensions are published unresolved; no pricing, partner positioning or competitor comparison appears anywhere. Where the model loses, in the site's own words: (1) nothing is built, and every hard problem in risk management appears at implementation; (2) no-deny may not survive an organisation that does not accept the frame — pressure moves into disputing facts or inflating intervals; (3) personal liability creates both the demand for evidence and the incentive to never be named (Q8); (4) it rates the ability to stop and refuses to provide it; (5) every worked example is 50–60 nodes while the density argument calls for thousands, and nobody has run it at that size (Q4). Corrections already made and published: the “no plug” correction, RAMM's underspecification, registers-are-one-chain, and one button becoming three. ============================================================================== == /admin/index.html ============================================================================== # How this site is built Hand-written static HTML, one generated chrome definition, and a pre-release gate that has to pass before anything is tagged or published. Same pipeline as sgit.ai, pki.sgit.ai, graphs.sgit.ai and issues-fs.sgit.ai: validate → tag → deploy. ## The pipeline 1 ### validate node admin/build/validate.js. Structure, internal links and anchors, version agreement, canonical/CNAME agreement, the agent surface, the definitions endpoint, block balance, and three tripwires specific to this site. A failure stops the release: no tag, no publish. It also runs on pull requests, so branch work is gated before it can reach the release branch. 2 ### tag-release Every push to dev is a release and ends tagged v{release}.{major}.{minor}. The version is owned by admin/build/version.txt — bumped exactly once per release — and must also appear in the release commit's subject as site vX.Y.Z: …. CI verifies the two agree, that the bump is the next minor (or a deliberate major), and then tags the release commit. That is HEAD on a direct push and HEAD's parent when a pull request lands as a merge commit, so the job anchors on the newest release commit reachable from HEAD rather than on HEAD itself. The first run backfills tags for any historical release from the commit subjects. 3 ### deploy Publishes the tagged commit to GitHub Pages. Runs on manual dispatch even without a tag, never when validation failed, and never from a pull request. ## What the gate checks # | Check | Why it is there | 1 | Version agreement — version.txt against every page's badge, the versions table, llms.txt and index.md; and each release listed exactly once | A blanket version bump that touches the history table produces duplicate rows, which shipped once on a sibling site | 2 | Internal links and fragments — every relative href/src resolves to a file, and every #fragment resolves to an id in the target page | Site-specific. This site's promise to an agent is that all 42 concepts have stable anchors. A promise that is checked is a fact; a promise that is remembered is a hope | 3 | Canonical host — every page declares a canonical, and every canonical and og:url is on the host in CNAME | A site assembled from a sibling's pattern can ship a canonical pointing at the sibling | 4 | The agent surface — every section hub is named in llms.txt, and the sitemap and the tree agree in both directions | Agents are the commissioned audience here. For that reader, a page missing from llms.txt is a page that does not exist | 5 | The definitions endpoint — data/concepts.json parses, carries all 42 concepts with every required field, agrees with version.txt, and every concept has a matching anchor on /concepts/ | The brief calls it the single highest-value thing this site can ship. The JSON and the human page are generated from one definition, and the gate makes drift impossible rather than unlikely | 6 | The over-claim tripwire — no page may say the engine is built, shipping or installable | Nothing in this corpus is implemented. A page may state such a claim only by marking the element data-not-built, which is how /shipped/ quotes the reality file. Over-claiming here would poison the whole network's credibility | 7 | The do-not-publish tripwire — the distinctive strings of the four Tier-3 manifest rows may not appear anywhere in the tree | They are in the manifest so the builder knows to skip them, and in the gate so a later edit cannot quietly reintroduce one. The manifest itself is exempt: naming a do-not-publish row is the mechanism working | 8 | Key-leak tripwire — nothing may look like a vault key (a ≥20-character passphrase joined by a colon to a UUID) | Read keys yes, write keys never — and the safest way to keep that rule is to ship neither. Inherited from the sibling sites, and cheap | 9 | Block balance — every page opens and closes the same number of
s | A note box closed with

is accepted silently by browsers and runs the note's border down the rest of the page | 10 | Every page carries a “for an agent” block | Each page serves three readers, and the third is an agent carrying the definition into another session. On this site that reader is the commission | ## The chrome Every page is hand-written static HTML, and that stays true — a human should be able to open any file and edit it. What is not hand-maintained is the chrome: the nav row (including the version badge the gate requires to agree everywhere) and the footer columns. Those are defined once in admin/build/chrome.py and rewritten in place across the tree, which is what stops a thirty-page site from drifting. python3 admin/build/chrome.py # rewrites nav + footer everywhere, stamps the version python3 admin/build/gen_sitemap.py # sitemap.xml from the tree, lastmod from git python3 admin/build/gen_llms_full.py # the whole site + every source document, one file node admin/build/validate.js # the gate Adding a page: add it to NAV or FOOTER if it belongs there, write the file with an empty and , then run chrome.py. The here state is derived from the page's own path. ## Making a release 1. bump admin/build/version.txt (vX.Y.Z, exactly once) add a row to admin/versions.html update admin/comms.html 2. python3 admin/build/chrome.py python3 admin/build/gen_sitemap.py python3 admin/build/gen_llms_full.py 3. node admin/build/validate.js 4. git commit -am "site vX.Y.Z: ..." && git push origin dev ## The repository .github/workflows/deploy-pages.yml validate → tag → deploy admin/build/validate.js the gate — ten checks admin/build/chrome.py the single definition of nav and footer admin/build/gen_sitemap.py sitemap.xml from the tree admin/build/gen_llms_full.py llms-full.txt — the whole site in one file admin/build/version.txt the version, owned here admin/comms.html asks and tasks, in public admin/versions.html release history data/concepts.json the definitions endpoint — 42 concepts briefs/ the eleven source documents, verbatim assets/site.css shared stylesheet (sgit.ai design language) llms.txt · llms-full.txt the agent surface CNAME · robots.txt · sitemap.xml hosting and discovery ## Hosting GitHub Pages, deployed from dev — the release branch. A push to main is deploy-only, with tagging skipped, so main can serve as a deploy test or a fallback while the github-pages environment still restricts dev. The site is entirely static: no build step for the HTML, no server, no JavaScript required to read any page. assets/nav.js handles the phone menu and touch dropdowns and the nav works without it; assets/mdreader.js renders raw markdown in-page where a document reader is used, and falls back to a link to the raw file. ============================================================================== == /admin/comms.html ============================================================================== # Comms: asks and tasks The site's own working board, in public. Asks (N) are things this site needs from someone else — the corpus, another site in the estate, or a person. Tasks (T) are things this site owes itself. Both are numbered and carry a state, because a research property that publishes its build order unresolved should publish its backlog the same way. Why this board exists at all. The house style across the estate is that each site publishes its numbered asks and tasks rather than keeping them in a private tracker. It costs nothing and it does two useful things: it lets a reader see what the site knows is missing, and it makes the difference between “not written yet” and “decided against” visible. There is a third reason specific to this site — the corpus argues that not knowing is a fact and that open questions are worth publishing unresolved. A site making that argument and hiding its own gaps would be arguing against itself. ## Asks — what this site needs from elsewhere # | Ask | Of whom | State | N1 | Reconcile the “no plug” correction at source. The corpus records that the plug always exists and what looked like “no plug” was zero recoverability. The published product page this material moved from does not reflect that correction. One of the two is wrong, and until it is settled, two properties in the estate carry contradictory versions of the same finding. This site publishes the corrected version and says so on the page. | riskmandate.ai · the corpus | open | N2 | Specify RAMM levels 1, 2, 4 and 5. Only Level 3 has a stated predicate, and the Agentic + variants are better defined than the base model they extend. The standard already exists — Level 3 sets it — so this is a matter of writing four predicates to a known shape. This site publishes the underspecification rather than inventing the missing four, which is the correct behaviour and not a satisfying one. | the corpus | needed | N3 | Legal read and a right-of-reply process before any comparative vendor assessment is published anywhere public. The document in question is rigorous and scrupulous about its own limits, and it names real companies critically. It is not on this site and the gate fails the build if it appears. Nothing changes until both the legal read and the reply process exist. | the project · legal | needed | N4 | Coordinate the mandate split with pki.sgit.ai. Their own 19 August site review says “mandate is the gap, registry is the missing half” — meaning they currently carry mandate material that arguably belongs with risk. A unilateral move by either site produces two half-treatments. Stated on the boundary map. | pki.sgit.ai | open | N5 | Decide the EU AI Act thread's home before it accretes further. Roughly 40,000 words across four clusters, and it is neither risk nor graphs. This site takes only three narrow declared bridges — Article 9(5), Article 14 and Article 26(5)/(6) — and leaves the rest un-annexed. That is a holding position, not an answer. | the estate | open | N6 | Offer a right of reply to the three named researchers whose published vulnerability formula the bridge document paraphrases. The treatment is favourable and explicitly marked as a paraphrase, and the corpus's own stance is “offered to be built on and challenged” — which is an argument for notifying them rather than waiting to be corrected. | the project | open | N7 | Write the canonical “risk acceptance redefined” statement, or confirm it is lost. Eight documents cite a 7 July 2026 brief of that title. It is not in the repository, and neither are three others referenced alongside it. Either it exists somewhere and should be restored, or the citations should be repointed — at present eight documents reference something nobody can read. | the corpus | needed | ## Tasks — what this site owes itself # | Task | State | T1 | Stand up the pipeline before the content: validate → tag → deploy, with the gate carrying this site's three specific tripwires | done · v0.1.0 | T2 | Build /acceptance/, /acceptable/, /ladder/ and /plug/ — the four near-publishable sections the brief sequences first | done · v0.1.0 | T3 | Ship the definitions endpoint: 42 concepts as structured data, generated from the same definition as the human page, with the gate enforcing that they cannot drift | done · v0.1.0 | T4 | Publish /shipped/ with the honesty constraint stated first rather than last, and enforce it in CI rather than remembering it | done · v0.1.0 | T5 | Mirror the 2FA instance graph as a downloadable file at a stable path. It is the only directly downloadable graph in the corpus, it declares its own principles inline and carries a CC BY 4.0 line — and this site currently describes it from the brief pack's counts rather than reproducing a file it does not have | open | T6 | Publish the ontology as machine-readable data, not just as a vocabulary listing. Node types and edge types with their path formulas, so an agent can consume the schema rather than parse a code block. Currently a listing | open | T7 | Run this site's own risk register in the open. The corpus argues a register is a graph, that unaccepted equals critical, and that the register maintains itself. A research site that publishes its own register — its open questions as unaccepted risks, with intervals — demonstrates all three at zero cost. The house style names this as one of two demonstrations worth building in | open | T8 | Write the leave-behind stubs for the four pages that moved off the commercial site, so each has a short summary and a link here rather than a drifting second copy | in progress · this site's half is done | T9 | Add a rendered in-page reader for each source document under /documents/, rather than linking to raw markdown only | open | T10 | Render the three worked graphs as diagrams. Every one is currently prose plus a counted table; two of them exist as parseable JSON upstream and would render directly | open | ## Decided against What | Why not | Publishing vault read keys on this site | They are published and kept current in sgit.ai's own catalogue. A second copy would go stale, and the gate refuses anything key-shaped anywhere in the tree — which is a rule worth keeping absolute rather than nearly absolute | Inventing the four missing RAMM predicates | Four plausible-sounding definitions presented as the model would be precisely the failure this site exists to avoid. N2 instead | Reconstructing the 2FA data file from the brief pack's counts | A reconstructed graph presented as the original is worse than a missing one. T5 instead | Any pricing, partner positioning or competitor comparison | Not this site's job, and corrosive on a research property. It stays on riskmandate.ai | ============================================================================== == /admin/versions.html ============================================================================== # Release history Every push to dev is a release: CI validates the site, verifies the version bump, tags the commit v{release}.{major}.{minor}, and deploys to GitHub Pages. The version is owned by admin/build/version.txt and must agree with the release commit's subject. How it works. Version | Date | What shipped | v0.1.0 | 23 Aug 2026 | The site, first release — pipeline first, then the eight sections the brief sequences first. The pipeline before the content, so that every release from here goes through a gate that already works: validate → auto-tag → deploy, carried over from the sibling sites with the merge-commit anchoring and the SIGPIPE fix those sites had to learn the hard way. Ten checks, three of them written for this site specifically. The over-claim tripwire is the load-bearing one: nothing in this risk corpus is implemented in code, so no page may say the engine is built, shipping or installable — a page may state such a claim only by marking the element data-not-built, which exactly one element on the site does. The do-not-publish tripwire pattern-matches the distinctive strings of the four Tier-3 manifest rows across the whole tree, so a later edit cannot quietly reintroduce a comparative vendor assessment or a contract term. And internal links are checked to the fragment, not just to the file — because this site's promise to an agent is that all 42 concepts have stable anchors, and a promise that is checked is a fact. /acceptance/ — the founding inversion, five pages. Underwriting rather than prediction, with the temporal move that makes the rest coherent: the risk already exists the moment the permission is provisioned, so the only variable is how long. There is no deny button, including the correction that replaces one button with three moves — accept, escalate, or challenge the fact — because presenting a single button to someone who feels cornered produces resentment rather than compliance. The interval ladder as a six-row table with the operational response and the cost stated per rung, the default at one month set deliberately just above the incident line, and rungs struck off where a remediation is physically impossible. Unaccepted equals critical — escalation without an escalator, aimed at attrition rather than refusal. And the underwriting graph, with override and compound pre-approval published as proposed and unfinished rather than tidied up. /acceptable/ and /ladder/ — the vocabulary and the machinery. Two orthogonal axes drawn as four quadrants, appetite as a revealed band computed from two signals, and the Article 9(5) gap where the obligation to judge acceptability is imposed and the standard is not supplied. Then the definitional spine: the grounding ladder with each rung defined by its required paths, node type formulas including the honest limit that no formula language exists and nothing executes one, bridges rather than merges with the worked external bridge, and not-knowing-is-a-fact. /plug/ — moved off the commercial site, with a correction it does not carry. Two symmetric risks, the four-way time intersection, the 12–18 hour detection floor, and the pillar correction that the plug always exists — what older registers recorded as “no plug” was zero recoverability, and restating it that way turns an unassignable blank into an ownable finding. Recoverability gets its own page for the flagship query: show me every accepted risk whose recoverability is zero. /examples/ — the proof layer, seven pages. The three worked graphs with their real counts (59/75, 51/53, and the Article 26(5) inventory), the four live vaults with the read-keys-yes-write-keys-never rule stated as the pipeline property it is, the ten scenarios, and the seven-row plug register. Two things are stated rather than fudged: the 2FA data file is not mirrored here (task T5) because a reconstructed graph presented as the original would be worse than a missing one, and the browser-isolation graph's counterweight figure is published in both directions rather than in the one that flatters the argument it sits in. /concepts/ and /agents/ — the commissioned audience. All 42 concepts with a stable anchor each, a one-line definition, maturity stated honestly, canonical source path and the page that argues it — plus the same 42 as structured data with the reading order and the six teaching altitudes. Both are generated from one definition, and the gate re-checks the count, the fields, the version and every anchor at release time, so they cannot drift. llms-full.txt concatenates the prose of every page plus all eleven source documents, because agent fetch tools frequently refuse URLs a search has not returned and a single-file surface is the practical mitigation. And the parts a research site owes a reader. /shipped/ says the engine is not built, first rather than last, with the grep result quoted. /network/ carries the eight-site boundary map, eight open questions published unresolved and seven honest tensions — including that the model rates the ability to stop and refuses to provide it. /origins/ traces the trajectory from February's “residual risk: acceptable” to June's “there is no deny button”, and names the canonical brief that eight documents cite and nobody can read. /documents/ publishes the eleven sources and, at equal length, what was deliberately excluded and why. /about/participant.html discloses that this site is published by the project that sells the product, and then states five places the model loses. | Versioning. v{release}.{major}.{minor}. Every push to dev is a minor release and must bump admin/build/version.txt exactly once, with the same version in the commit subject as site vX.Y.Z: …. CI verifies the two agree and that the bump is the next minor (or a deliberate major), then tags the release commit — HEAD on a direct push, HEAD's parent when a pull request lands as a merge commit. The first run backfills tags for any historical release from the commit subjects. ============================================================================== == briefs/README.md — source document, verbatim ============================================================================== # risks.sgit.ai — brief pack **For:** the agent commissioned to build `risks.sgit.ai` **From:** Dinis Cruz, via the SG/Send Librarian **Version:** v0.33.62 · 22 August 2026 **Licence:** CC BY 4.0 (see `LICENSE.md`) --- ## What this is A **research site** for risk. Not a product site — that is `riskmandate.ai`, which stays commercial and starts referencing here instead of carrying the concepts itself. The commission has two halves: 1. **Consolidate** ~496,000 words of risk thinking, written 18 June – 22 August 2026 (plus a February pre-history and 8 articles from 2025), into a surface an agent can hold. **42 distinct concepts**, most well-developed, almost none reachable today. 2. **Refactor** the concept material *out* of `riskmandate.ai`, leaving stubs that point here. The audience named in the commission is **agents**: *"to handle the cases where I need agents to have a good understanding of some of those key concepts and ideas."* That is why `/agents/` and a machine-readable definitions endpoint are treated as first-class deliverables, not an afterthought. --- ## Read in this order | File | Words | What it does | |---|---:|---| | **`00__BRIEF.md`** | 2.0k | **Start here.** The commission, the honesty constraint, the thesis, the ten concepts an agent must hold, the refactor table, the four vaults, the numbers, the build order | | **`02__risk-acceptance.md`** | 1.6k | The commissioned centrepiece — the acceptance thread traced chronologically from June to August. Build `/acceptance/` from this | | **`04__riskmandate-refactor.md`** | 1.0k | The other half of the commission — page-by-page split of `riskmandate.ai`, with the leave-behind stub template | | `01__concepts-index.md` | 6.0k | All 42 concepts: canonical path, maturity, newcomer-readiness, best quote. Plus a six-altitude teaching order. This is the raw material for `/concepts/` | | `03__worked-examples-and-vaults.md` | 1.8k | The four live risk vaults on `sgit.ai/demos/vaults/`, three worked graphs, prior-art table | | `05__site-architecture.md` | 1.5k | Page-by-page IA, including `/agents/` and the definitions endpoint | | `06__boundaries-and-house-style.md` | 2.3k | Seven-site boundary map, redaction watch-list, provenance rules | | `07__gaps-and-open-questions.md` | 1.1k | 6 write-fresh items, 8 open questions, 7 honest tensions | | `08__source-manifest.csv` | 37 rows | Every source, tiered 0–3, with proposed page and publishability. **Every path verified to exist at v0.33.62** | | `sources__docs-diniscruz-ai-risk.json` | 8 articles | Prior art with `first_published`, `source_url`, `source_pdf`, `source_linkedin` — for canonical links | | `LICENSE.md` | — | CC BY 4.0, plus the three regimes it does *not* cover | --- ## The three things that will bite you **1. There is no risk code.** Not one line. The corpus is a specification, not an implementation. `/shipped/` must say so plainly — the sibling sites (`pki`, `nhi`, `sg-sentinel`, `issues-fs`) all ship a page that separates what exists from what is designed, and this site inherits that convention with an unusually empty column. Over-claiming here would poison the network's credibility. **2. Four manifest rows are Tier-3.** Commercial terms, a competitor map naming two large vendors [REDACTED · Tier-3 · see PUBLIC.md], investment scenarios, a contract draft. They are in the manifest so you know to skip them. Do not publish, quote or paraphrase. **3. The prior art is CC0, not CC BY.** The 8 `docs.diniscruz.ai` articles were published CC0. Republishing under CC BY is legally fine, but keep `rel="canonical"` on the original URL and the recorded `first_published` date. The historical link matters more than the licence does. --- ## House pattern Same as the siblings: `/llms.txt` is the whole agent surface; `/llms-full.txt` is one-file concatenation; `/documents/` carries raw markdown as source of truth; `/admin/comms.html` numbers asks (N1…) and tasks (T1…); `/admin/versions.html` tracks versions; `/about/participant.html` names the participants. Publish the build order unresolved, with the open questions and the honest tensions visible. `07__gaps-and-open-questions.md` supplies both. --- This file is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/00__BRIEF.md — source document, verbatim ============================================================================== # risks.sgit.ai — Brief Pack **Pack version:** v1.0 · 22 August 2026 **Target site:** `risks.sgit.ai` — the conceptual and research home for risk **Sources:** `SGraph-AI__App__Send` @ **v0.33.62** · `docs.diniscruz.ai` @ v0.3.123 · [riskmandate.ai](https://riskmandate.ai) · the four risk vaults published on sgit.ai **Siblings:** sgit.ai · nhi.sgit.ai · pki.sgit.ai · graphs.sgit.ai (v0.3.9) · sg-sentinel.sgit.ai · newsroom.sgit.ai · issues-fs.sgit.ai --- ## 0. The commission Two jobs, and the second is what makes this site different from the others in the estate. **Job 1 — consolidate the concepts.** ~496,000 words across ~185 documents, written between 18 June and 22 August 2026, plus a February pre-history. **42 distinct concepts**, most of them well-developed, almost none of them published anywhere a reader or an agent can reach. **Job 2 — be the site riskmandate.ai references.** riskmandate.ai is commercial: pricing, demos, partners, the customer/user angle of getting risks accepted. It currently also carries the concepts — nine library pieces, `plug.html`, `acceptable.html`, `ramm.html`. **Those concepts should live here, and riskmandate.ai should link to them.** §4 maps the refactor page by page. **The primary audience is agents.** The brief says it plainly: *"to handle the cases where I need agents to have a good understanding of some of those key concepts and ideas."* That shapes everything — the concepts must be reachable in one fetch, stated as definitions rather than narrative, and machine-readable where possible. --- ## 1. The honesty constraint — read this before anything else **Essentially none of this risk corpus is implemented in code.** Greps for `risk_`, `RiskAcceptance`, `risk_register` and `riskmandate` across `sgraph_ai_app_send/**/*.py` return **zero** matches. The Librarian's own reality file says so directly: > *"All items below are PROPOSED. None have been code-verified. **Do not describe any of these as existing features.**"* > — `team/roles/librarian/reality/ai-agents/proposed/risk-mandate.md` What *has* shipped: **riskmandate.ai** as a vault-powered static site, the ten "how long would you accept" scenario documents, and **four published vaults with read keys** (§5). **The honest sentence for `/shipped/`:** *"This is a research site. The concepts are argued, the worked examples are real graphs, and four vaults are live and browsable. The engine is not built."* That framing is not a weakness here — it is what separates a research property from a product one, and it is the reason the split from riskmandate.ai works. --- ## 2. The thesis in one paragraph Traditional risk management predicts the probability of a future event. This model asks a named human to **underwrite an exposure that already exists** — insurance-style, with personal liability attached. From that single inversion everything else follows: if the risk is real, it cannot be denied, so **there is no deny button** — only *how long* you accept it before re-accepting. The interval is not metadata about the decision; **the interval is the decision**, because each rung implies a specific operational response. A risk nobody has accepted has not gone away — it has come to rest on whoever is nearest, so **unaccepted is rated critical** and rolls upward without anyone choosing to escalate it. And because someone must now sign, they demand evidence — which manufactures the demand for the **grounding ladder** underneath: Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk. --- ## 3. The ten concepts an agent must hold Full inventory of 42 in `01__concepts-index.md`. These ten carry the rest. | # | Concept | The one line | |---|---|---| | **C1** | **Acceptance is underwriting, not prediction** | *"we are not describing the risk of something happening, we are asking them to accept it, to underwrite it"* | | **C2** | **The no-deny mechanic** | *"the mistake of a lot of risk registers is that they allow the risk to be denied, which can only happen when the risk has not materialised"* | | **C3** | **The interval ladder** | The interval *is* the decision. 1h / 4h / 1d / 1w / 1m / 6m. Default one month — deliberately just above the incident line | | **C4** | **Unaccepted = critical** | An un-underwritten risk rests on whoever is nearest. *"that person right now is accountable for the business"* | | **C5** | **Accepted is not acceptable** | Two orthogonal axes. Acceptable = *"the moment that the business is happy to stop funding remediation activities"* | | **C6** | **The grounding ladder** | Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk. Downward grounds; upward classifies | | **C7** | **Node type formulas** | *"the ontology definition of a node type is its upward and downward path-pattern, not a sentence about what it contains"* | | **C19** | **Blast radius / authorization closure** | What the agent *can* reach, computed — not what it did | | **C20–C23** | **The plug** | Who can stop it, how fast, at what cost, and **recoverability — the dimension money cannot buy back** | | **C17** | **Not knowing is a fact** | Absence of evidence is a first-class node, countable and assignable | --- ## 4. The refactor: what moves off riskmandate.ai riskmandate.ai's own `llms.txt` groups its pages. Mapping them: | riskmandate.ai page | Type | Disposition | |---|---|---| | `/plug.html` — Who can pull the plug | **Conceptual** | **→ risks.sgit.ai `/plug/`.** Five dimensions, recoverability maturity, the "no plug" correction. RM keeps a one-paragraph summary + link | | `/acceptable.html` — Accepted is not acceptable | **Conceptual** | **→ risks.sgit.ai `/acceptable/`.** Two axes, four quadrants, the interval table, Article 9(5). RM links | | `/ramm.html` — acceptance maturity | **Conceptual** | **→ risks.sgit.ai `/ramm/`.** Five levels as graph predicates, entity model, the Agentic `+` variants, crosswalks | | `/library.html` — nine concept pieces | **Conceptual** | **→ risks.sgit.ai `/concepts/`.** ⚠️ Currently a landing page with **no items actually linked** — see §7 | | `/how-it-works.html` | Educational | **Split.** The mechanism → here; the product walkthrough stays | | `/agents.html`, `/llms-full.txt`, `/.well-known/agent-content.json` | Technical | **Pattern to copy, not move.** RM's agent surface is good; risks.sgit.ai needs its own | | `/v0/.../index.html` — "You own the risk" | Product | **Stays.** The positioning line | | `/scenarios.html`, `/statics.html` | Product | **Stays** — but the ten scenarios' *source* (`07/02`) is a research artefact worth publishing here too | | `/demos.html` + 3 demo pages | Commercial | **Stays** — though the three vaults themselves are shared assets (§5) | | `/pricing.html`, `/partners.html` | Commercial | **Stays** | **The line to draw:** riskmandate.ai answers *"how do I get my risks accepted, and what does it cost?"* risks.sgit.ai answers *"what is a risk, what is acceptance, and why is it modelled this way?"* Every concept page that moves should leave behind a short summary and a link. And each moved page should carry a provenance note — see `06__boundaries-and-house-style.md` §5. --- ## 5. The four risk vaults — live, published, with read keys From [sgit.ai/demos/vaults/](https://sgit.ai/demos/vaults/index.md). **These are the site's proof and must be first-class, not an afterthought.** | Vault | What it is | Size | Why it matters here | |---|---|---|---| | **Risk Graph Explorer** | Public-by-design application, **7 views** recomputed simultaneously | 33 files · 428 KB · 7 commits | *"Exposed"* preset = **18 facts, 37 risks, 14 provisions**. Amber = exposure, green = assurance, **ghosted = unanswered**. `permissions: {}` — no network, no storage, all client-side | | **Agentic Browser Isolation** | Living risk graph, **17 entry points** | 104 files · 2.4 MB · 4 commits | 5 altitudes L1 IT → L5 Board. Acceptance-gated escalation with **no deny button** — C2 and C4 running on real data. ~70 JSON files. `fs.write: []` | | **Risk Mandate** | The software project itself, in a vault | 124 files · 1.9 MB · **98 commits** · 8 app entries | The most-committed vault published. Shows the method applied to its own build | | **Regulation Graph** | EU AI Act as a citable graph, **11 views** | 207 files · 14.9 MB | **1,523 nodes · 1,944 edges.** Supplies Article 9(5), 14, 26(5)/(6) — the provisions the concepts hang on | ⚠️ Read keys are published for all four. **Never publish write keys, and escrow before publishing** — the standing rule from `08/14/sgit-site-and-hub/…read-keys-yes-write-keys-never…`. The Regulation Graph is already a *redacted republication* after an audit found a plaintext key; adopt its `PUBLIC.md` transparency convention. --- ## 6. The numbers the site can stand on | | | |---|---| | **Browser-isolation graph** | **59 nodes, 75 edges** · Risk 13, Owner 7, Evidence 6, Vulnerability 6, Fact 5 · `gives_rise_to` 22, `backed_by` 14, `owned_by` 11 | | **2FA graph** | **51 nodes, 53 edges** · ontology **24 node classes, 34 edge types** · MITRE **T1110.004** | | **Article 26(5) instance** | 8 facts (one unevidenced), 5 risks, 4 stakeholders, **9 questions — 5 unanswered, "the actual output of the exercise"** | | **The arithmetic finding** | **30 days** retained vs **6 months** required — *"arithmetic, not judgement, which makes it the most defensible finding in the graph"* | | **Detection floor** | **12–18 hours** hyperscaler cost-reporting delay · the founder's AWS figure: **16 hours** | | **Interval ladder** | 1h / 4h / 1d / 1w / 1m / 6m — default **one month** | | **Altitudes** | **5** — L1 endpoint/IT → L2 security → L3 business → L4 enterprise → L5 board | | **Plug profile** | **5 dimensions** · **4-way** time intersection (detection ∧ decision ∧ blast radius ∧ reversibility) | | **Corpus** | ~**496,000 words**, ~185 documents, 1,450 files mention "risk" | | **Prior art** | **59,131 words** across 8 published articles on docs.diniscruz.ai, Feb–Jul 2025 | | **This pack's manifest** | **37 rows** — 19 Tier-0, 13 Tier-1, 1 Tier-2, 4 Tier-3 (do-not-publish). **69,724 words** of Tier-0+1 source, every path verified to exist at v0.33.62 | --- ## 7. Three things to fix while you are here 1. **`riskmandate.ai/library.html` links nothing.** It describes *"recorded talks, the full proposition deck, and the long-form pieces"* and lists nine concepts — but the page ships no links to them. That is the strongest argument for the split: the concepts have nowhere to live on a commercial site. 2. **RAMM's base levels are underspecified.** Levels 1, 2, 4 and 5 are named; only Level 3 has a stated predicate (*"all acceptance nodes have the five required edges"*). The Agentic `+` variants are better defined than the base model. 3. **The plug material contradicts itself in one place** — the corpus records a *"no plug"* correction that the published page does not reflect. Worth reconciling before republishing. --- ## 8. Build order | Step | Section | Why here | |---|---|---| | **1** | `/acceptance/` — underwriting, no-deny, the ladder, unaccepted=critical | The founding inversion. Four concepts, one page each, all publishable near-as-is | | **2** | `/acceptable/` — the two axes | Moves off riskmandate.ai. Already written for a public audience | | **3** | `/ladder/` — the grounding ladder + node type formulas | **What agents most need.** Definitional, machine-readable | | **4** | `/examples/` — the three worked graphs + the four vaults | Proof, with real numbers and live read keys | | **5** | `/plug/` — five dimensions, recoverability | Moves off riskmandate.ai | | **6** | `/register/` — graph of graphs, fractal registers, relevance fade | The register model | | **7** | `/agents/` — the machine surface | The commissioned audience. Copy RM's pattern | | **8** | `/shipped/` — what is argued vs what runs | Non-negotiable; §1 | | **9** | `/ramm/` + `/maturity/` | Moves off riskmandate.ai; fix the base levels first | | **10** | `/network/` — the seven-site boundary map | The split is the point; state it | --- ## 9. What is in this pack | File | Contents | |---|---| | `00__BRIEF.md` | This document | | `01__concepts-index.md` | **42 concepts** with canonical paths, maturity, newcomer-readiness and best quote | | `02__risk-acceptance.md` | The acceptance thread traced in full — the commissioned centrepiece | | `03__worked-examples-and-vaults.md` | Three worked graphs, four live vaults, every citable number | | `04__riskmandate-refactor.md` | Page-by-page split, with the leave-behind text | | `05__site-architecture.md` | Page-by-page IA with sources | | `06__boundaries-and-house-style.md` | Seven-site boundary map, redaction watch-list, conventions | | `07__gaps-and-open-questions.md` | Write-fresh list, open questions, honest tensions | | `08__source-manifest.csv` | Machine-readable, every path verified at v0.33.62 | | `sources__docs-diniscruz-ai-risk.json` | 8 published articles with dates, authors, PDFs, LinkedIn URLs | --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/01__concepts-index.md — source document, verbatim ============================================================================== # 01 — Concepts Index **42 risk concepts**, each with its canonical document, first appearance, maturity, newcomer-readiness and best verbatim quote. This is the file the site's `/concepts/` section is built from, and it is the file an agent should be able to fetch in one request. `briefs/` = `team/humans/dinis_cruz/briefs/` in `SGraph-AI__App__Send` @ v0.33.62. All paths verified. **Reading order for an agent with no prior context:** C1 → C2 → C3 → C4 → C5 (the acceptance model) → C6 → C7 (the ontology that makes it computable) → C19 → C20–C23 (blast radius and the plug) → everything else. **Maturity is stated honestly.** Nothing in this corpus is implemented in code — see `00__BRIEF.md` §1. --- ### C1. Risk Acceptance as Underwriting (not prediction) The founding inversion. Traditional risk management predicts the probability of a future event; this model asks a named human to *underwrite* an exposure that already exists, insurance-style. Because the executive is ultimately accountable for the business, accepting a risk is not an administrative act but the assumption of personal liability for a decision. The move relocates the whole discipline from actuarial estimation to accountable ownership, and it is the reason the rest of the model hangs together: once someone must sign, they demand evidence, which manufactures the demand for the grounding ladder underneath. - **Canonical:** `team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__arch-brief__sg-send-risk-acceptance-underwriting-flows-upward-cross-domain-the-risk-already-exists.md`; `team/humans/dinis_cruz/briefs/06/04/nhi-2.0/v0.32.3__strategy-brief__sg-send-nhi-2.0-risk-management-acceptance-underwriting-roi.md` - **First appearance:** 4 June 2026 (v0.32.3), deepened 18 June 2026 (v0.33.40) - **Maturity:** well-developed - **Newcomer-followable?** Yes — the insurance analogy carries it with no GRC background - **Quote:** *"because what we describe is reality, we are not describing the risk of something happening, we are asking them to accept it, to underwrite it. Maybe the analogy is insurance: you are underwriting the damage, the same way an underwriter underwrites the cost. The business executive is ultimately accountable for everything, so whatever they accept, they are underwriting the risk."* — `06/18/agentic-permissions/v0.33.40__arch-brief__sg-send-risk-acceptance-underwriting-flows-upward-cross-domain-the-risk-already-exists.md` ### C2. The No-Deny Mechanic The single most distinctive primitive. A risk that has a real vulnerability under it exists whether or not anyone acknowledges it, so denial is incoherent — you cannot vote a fact out of existence. The UI therefore has no deny button; the only choice is **how long** you accept it before it must be re-accepted. Denial in conventional registers is a fiction that only works while the risk has not materialised; removing it converts risk management from a gate into a forcing function. - **Canonical:** `team/humans/dinis_cruz/briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__dev-brief__sg-send-risk-acceptance-service-demo-no-deny-time-boxed-acceptance-expiry-as-cost-graph-evidence.md`; `team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__sg-send-risk-register-graph-of-graphs-facts-only-no-deny-cascade-cia-blast-radius.md` - **First appearance:** 23 June 2026 (v0.33.33) - **Maturity:** well-developed - **Newcomer-followable?** Yes — outstandingly so - **Quote:** *"the mistake of a lot of risk registers is that they allow the risk to be denied, which can only happen when the risk has not materialised. Once the vulnerability exists, the risk exists to the business."* — `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...facts-only-no-deny-cascade-cia-blast-radius.md` ### C3. The Acceptance Interval Ladder The interval is not metadata about a decision — it *is* the decision. Choosing a duration simultaneously sets severity and commits resources, because each rung implies a specific operational response. Under 24 hours means pull the plug; a day to a week is a lower-grade incident; a week to a month is a project for an existing team; one to three months means assemble and fund; over three months means you are waiting to see, which is legitimate if said out loud. The default is one month — deliberately just above the incident line. Anything under a week is an incident and the rung simply names the grade. - **Canonical:** `team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__sg-send-acceptance-interval-ladder-hour-to-six-months-default-one-month-interval-implies-response.md` - **First appearance:** intervals 23 June 2026; consolidated as a ladder 17 July 2026 (v0.33.49) - **Maturity:** well-developed (the single cleanest artefact in the corpus) - **Newcomer-followable?** Yes — it is a six-row table with plain-language consequences - **Quote:** *"if you have less than a day risk acceptance, then that is fundamentally a P1, because if you say I do not want to accept this risk for more than an hour once I know about it, then that means you need to pull the plug."* ### C4. Unaccepted Equals Critical (escalation without an escalator) The corpus's sharpest inversion of incentives. In most organisations a risk nobody escalated feels safest to the person holding it. Here it is the worst possible state: an un-underwritten risk has not vanished, it has come to rest on whoever is nearest, and that person is personally carrying an enterprise exposure with no signature above them. So an unaccepted risk is rated critical by default and appears on the holder's own dashboard immediately, and it rolls upward *without anyone deciding to escalate it*. - **Canonical:** `team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__sg-send-acceptance-interval-ladder-...md`; demonstrated on live data in `team/humans/dinis_cruz/briefs/08/02/vault-as-substrate/v0.33.55__arch-brief__sg-send-end-to-end-worked-example-article-26-5-creditworthiness-agent-fact-to-board.md` - **First appearance:** 17 July 2026 - **Maturity:** well-developed, and worked end-to-end on 2 August - **Newcomer-followable?** Yes - **Quote:** *"any risk that has not been accepted immediately goes into that one's risk dashboard, because that is a massive risk, that means that that person right now is accountable for the business, which is very bad from a business point of view, but is also very bad for the individual."* ### C5. Accepted Is Not Acceptable (two orthogonal axes) The vocabulary correction that turns risk appetite into something computable. **Accepted** is an act by a named person at a dated moment. **Acceptable** is a threshold owned by the business — *"the moment that the business is happy to stop funding remediation activities."* They are orthogonal, not sequential, producing four quadrants, each requiring a different response. Acceptable is risk appetite renamed, and renaming it makes it operational because the instruction that matters most is the one that *stops* work. The EU AI Act Article 9(5) requires residual risk to be "judged acceptable" and never defines the word — so the obligation to judge is imposed and the standard is not supplied. An organisation that has never defined its acceptable level carries a meta-risk about its own risk management. - **Canonical:** `team/humans/dinis_cruz/briefs/07/28/regulation-graph-and-acceptability/v0.33.53__strategy-brief__sg-send-accepted-is-not-acceptable-orthogonal-axes-appetite-renamed-article-9-mandates-judgement-without-defining-it.md` - **First appearance:** 28 July 2026 (v0.33.53) - **Maturity:** well-developed; formalised as node types `P-PRED-001` to `P-PRED-004` in `team/roles/librarian/reality/ai-agents/proposed/risk-mandate.md` - **Newcomer-followable?** Yes — the four-quadrant ASCII diagram does the work - **Quote:** *"the acceptable risk is the moment that the business is happy to stop funding remediation activities."* ### C6. The Grounding Ladder (Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk → Top Risk) The definitional spine of the whole corpus, and the concept agents most need. Every node type is defined by its **required paths**, not by its content. Downward paths confer *grounding* ("is it real?"); upward paths confer *classification and implication* ("what is it, and why does it matter?"). A Vulnerability is simply a Fact with an upward path to a Risk. A Measure is **not** the floor — it is grounded further in a Twin and through it in Reality. The floor is a stopping *test*: the last node where going deeper would neither improve observability nor change a decision. - **Canonical:** `team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-grounding-ladder-fact-evidence-measure-vulnerability-risk-definitions.md` - **First appearance:** 28 June 2026 (v0.33.36) - **Maturity:** well-developed; the most rigorous document in the corpus - **Newcomer-followable?** Yes — the rendered ladder diagram plus the untested-restore worked example - **Quote:** *"A Fact becomes a Vulnerability purely because of its upward link to a Risk, so that legitimacy is conferred entirely from above."* ### C7. Node Type Formulas (classification as a testable path-pattern) The mechanism beneath C6, and arguably the corpus's most transferable idea. What a node *is* should be computed against the graph, not decided in a classifier's head. A Node Type Formula is a required pattern of typed, directed paths; a node either matches or does not. Classification becomes a **query**, so it is dynamic and path-relative — promotion and demotion are edge events. Bias does not disappear; it moves out of the classifier's head into the formula, where it is visible, versioned and arguable. Two parties who disagree stop trading intuitions and start diffing formulas. - **Canonical:** `team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-node-type-formulas-classification-as-testable-path-pattern-not-judgment.md` - **First appearance:** 28 June 2026 - **Maturity:** well-developed as a mechanism; the *formula language* is an open question - **Newcomer-followable?** Mostly — requires accepting "a type is a path pattern", which the doc argues carefully - **Quote:** *"the ontology definition of a node type is its upward and downward path-pattern, not a sentence about what it contains."* ### C8. Ontologies of Ontologies — Bridges, Not Merges Multiple parties each own their own formula over a shared factual graph, connected at declared crosswalk points rather than merged into one schema. A node can be a vulnerability under one formula and not another, and both are valid — they are different queries over the same graph. The worked proof is the Manion/Jacobs/Roytman security-centric formula (System, Fault, Security Failure, Conditions), which turns out to be a **sub-path** of the business-centric formula: their Security Failure plays exactly the structural role of the promotion edge, differing only in terminus. - **Canonical:** `team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-ontologies-of-ontologies-three-layers-formulas-bridges-multiple-definitions.md`; `.../v0.33.36__arch-brief__sg-send-bridge-vulnerability-formula-system-fault-security-failure-conditions-manion-jacobs.md` - **First appearance:** 28 June 2026 - **Maturity:** well-developed, with one fully worked external bridge - **Newcomer-followable?** Yes - **Quote:** *"We do not fold their definition into ours, which would erase the security-centric view that is the whole point of having it. We declare a bridge: a Security Failure gives rise to a Business Risk."* ### C9. The Risk Register as a Graph of Graphs The register is not a spreadsheet at the top of a company but a hyperlinked semantic graph, buildable now because vaults supply the storage and hyperlink layer and PKI solves attribution. Its distinguishing move is that it *begins where scanners stop* — at the vulnerability — and maps everything after it: accepting, funding, and finding who does the work. - **Canonical:** `team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__sg-send-risk-register-graph-of-graphs-facts-only-no-deny-cascade-cia-blast-radius.md` - **First appearance:** 26 June 2026 (v0.33.35) - **Maturity:** well-developed, with a full worked example (2FA) - **Newcomer-followable?** Yes — it is written as a five-movement narrative - **Quote:** *"a lot of security teams and products end on the vulnerability, and what I want to show is the multiple layers involved in fixing it, but even before that, in accepting the risk, funding the solution, and finding who is going to do it."* ### C10. Fractal Risk Registers (one per accepting entity) Wherever there is a stakeholder who accepts a risk, there must be a register — for a company, a department, and an individual role. A person's register is simply all the risks that bubble up to them, *derived* rather than curated. An individual has at least two and often three: their role-specific register in their own domain language, plus derived views of the registers above. Only the role's own register is stored; the rest are queries. - **Canonical:** `team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__sg-send-fractal-risk-registers-one-per-accepting-role-domain-language-relevance-fade.md` - **First appearance:** 17 July 2026 - **Maturity:** well-developed - **Newcomer-followable?** Yes - **Quote:** *"as you go up, imagine the colours can fade away for the next registers for the bits that are not relevant, so the graph starts to point which parts of the risk register above are relevant to this individual, so that he understands the picture."* ### C11. Relevance Fade (the register as an education mechanism) The visualisation property that falls out of C10. Centre the view on a role: that role's register is lit in full; the registers above fade except for the entries that trace back down to this role. A database administrator can see that their local "agent holds unrestricted access to a customer table" is *the same object* as the board's "regulatory penalty, loss of licence, continuity failure". Seeing that once teaches more than any training course. - **Canonical:** same as C10 - **First appearance:** 17 July 2026 · **Maturity:** partially argued (visualisation not built) · **Newcomer-followable?** Yes ### C12. Registers Are One Chain, Not Parallel Lists A late and consequential correction. Three altitude registers drawn side by side demonstrate a formatting capability; drawn as **one chain rooted in an existence fact** they demonstrate the entire thesis. The CISO's risk exists *because of* the operator's risk, which exists because of a fact stating an agent touches production. - **Canonical:** `team/humans/dinis_cruz/briefs/08/02/field-demo/v0.33.55__arch-brief__sg-send-demo-review-registers-are-one-chain-question-is-not-a-risk-decision-as-node-paths-are-traversals.md` - **First appearance:** 2 August 2026 · **Maturity:** well-argued, newly stated · **Newcomer-followable?** Yes - **Quote:** *"at the moment it looks like the cards, they look side by side, and it's actually not that."* ### C13. Technical Owner vs Business Owner The technical owner *validates* that the vulnerability exists; the business owner *owns and accepts* the risk. Conflating them is the source of the corpus's canonical governance failure. IT validating a 2FA gap is not IT accepting an HR data-breach exposure. - **Canonical:** `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...md`; `team/humans/dinis_cruz/briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__arch-brief__sg-send-risk-acceptance-workflow-multi-stakeholder-graph-underwriting-propagation-override-pre-approval.md` - **First appearance:** 26 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"most of IT should be technical owners of something, but the business owners are the ones that actually own the risk."* ### C14. Confirmed / Validated / Accepted — the Three-Predicate Model Three distinct acts held by three distinct roles, tracked per risk per altitude. **Confirmed** is factual (technical stakeholder; true or false). **Validated** is interpretive (GRC/compliance: does this obligation genuinely apply?). **Accepted** is a judgement about appetite (business owner with standing). The interesting cases are the mismatches: a risk accepted by an executive but never confirmed is an acceptance of something that may not be true. - **Canonical:** `team/humans/dinis_cruz/briefs/07/28/mvp-and-field-demo/v0.33.53__arch-brief__sg-send-scenarios-are-the-mvp-shareable-vault-primitive-sequence-confirmed-validated-accepted-at-altitude-plural-regulations.md` - **First appearance:** 28 July 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"we probably also want the GRC person to validate the risks, especially to do with the compliance element."* ### C15. Underwriting Graph & Propagation to the Board An exec never decides alone. Before an executive acts, the relevant direct-line owner (CIO/CTO/CFO by dimension), the CSO, and at least GRC must each have recorded an acceptance **or an explicit refusal** — a refusal being as important as an acceptance. Once accepted at the right altitude, the acceptance propagates upward to the boss, the boss's boss and the CEO (who acts for the board), with the largest going to the board itself. Superiors may override in either direction, with the original acceptance preserved and the override attributed. - **Canonical:** `06/23/risk-mandate-product-and-workflow/v0.33.33__arch-brief__sg-send-risk-acceptance-workflow-multi-stakeholder-graph-underwriting-propagation-override-pre-approval.md` - **First appearance:** 23 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"the exec should never make a decision that has not been underwritten by the relevant player."* ### C16. Cascade and the Air Gap Every change to any risk, fact, or piece of evidence must trigger a cascade to the top. The absence of a cascade is an **air gap** — and any risk that exists in the business but is not connected to the register is likewise an air gap. Registers with air gaps silently drift out of date, and the business is deciding on bad data. Cascade works in both directions: a risk appearing propagates up, and a risk resolving propagates up too, clearing it from the board's view. - **Canonical:** `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...md` - **First appearance:** 26 June 2026 (concept of "air gap" appears in the repo from 9 March in another sense) - **Maturity:** well-developed as principle; *detecting* air gaps is an acknowledged open problem - **Newcomer-followable?** Yes - **Quote:** *"every time any risk, any fact, any evidence changes, you have to trigger a cascade that reaches the top. If you do not have that, you have an air gap, which means you do not have good data, and you cannot make good decisions."* ### C17. Not Knowing Is a Fact (absence of evidence as first-class) Lack of evidence is itself evidence. A measure can be a documented zero — "zero tested-restore records found" is as much a measure as any positive count. An unevidenced fact is recorded as unevidenced rather than left blank, which is what makes it queryable, countable and assignable. Gaps in knowledge spawn their own risks: "the full extent of the impact has not been captured, which means the risk is not yet correctly classified or correctly accepted." - **Canonical:** `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...md`; demonstrated as fact **F7** in `08/02/vault-as-substrate/v0.33.55__arch-brief__...article-26-5...md` - **First appearance:** 26 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"not knowing a fact is also a fact. Lack of evidence is also evidence, because then we say we do not know, and somebody needs to investigate until we do."* ### C18. CIA Blast-Radius Expansion Where most registers stop is where this one starts working. From a single risk, expand through Confidentiality (leak → GDPR/ICO → CFO for the fine, CEO for compliance — two distinct risks, since inadequate protection may already be a breach), Integrity (salary tampering, fabricated hires, altered performance data) and Availability (backup cadence gaps, and the sharper "when was a restore last tested?"). Each branch spawns its own risks, each following the full validate-accept-propagate loop. - **Canonical:** `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...md` - **First appearance:** 26 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes (CIA is standard, but the doc explains it) - **Honest tension recorded in-doc:** the expansion must be curated, not exhaustive, or it blows up combinatorially ### C19. Blast Radius / Authorization Closure An agent's *real* authorization is the transitive union of everything reachable from what it was given, not the nominal grant. Two awareness gaps hide the delta: the granter does not know the full scope of what it grants, and the original delegator never authorised re-delegation. Inbox access is access to every account resettable by email; desktop access is every stored credential and every logged-in session; code execution can escalate to admin. The key quantity is the **delta between expected and unexpected** permissions. `AuthorizationClosure` becomes a first-class node type. - **Canonical:** `team/humans/dinis_cruz/briefs/07/02/authorization-and-maturity-model/v0.33.40__arch-brief__sg-send-agent-authorization-union-of-possible-expected-unexpected-delta-blast-radius-hope-driven.md` - **First appearance:** "blast radius" from 12 Feb 2026 (`briefs/02/12/`), formalised as closure 2 July 2026 - **Maturity:** well-developed - **Newcomer-followable?** Yes — the inbox example lands instantly - **Quote:** *"at the end of the day you are still accountable for those actions, all the way to the board."* (the "hope-driven development" anti-pattern) ### C20. Who Can Pull The Plug — Two Symmetric Risks If nobody holds the mandate to stop an AI system, that is one risk; if the system cannot be stopped even when someone decides to, that is a second, different risk (an authority gap vs a capability gap). The second is widely underestimated. This decomposes into timed sub-risks — can it be stopped in an hour, ten hours, a day, five days; only in office hours? — which turns governance into an on-call availability problem, including whether the person can act *without fear of losing their job* and along a clear escalation path. - **Canonical:** `team/humans/dinis_cruz/briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-who-can-pull-the-plug-ability-to-stop-an-ai-system-fractal-maturity-model-detection-authority-blast-radius-reversibility-intersect-in-time.md` (the load-bearing brief; 12 companion pieces in the same folder) - **First appearance:** phrase from 17 Feb 2026 in another sense; as a risk pillar, 24 July 2026 - **Maturity:** well-developed — a 13-document series - **Newcomer-followable?** Yes, outstandingly - **Quote:** *"if you do not have somebody who has the mandate to pull the plug, you have a risk, and if you do not have a system that can be pulled the plug, you have a risk too."* ### C21. The Four-Way Time Intersection (detection, decision, blast radius, reversibility) Four capabilities must line up inside the same window, and a gap in any one breaks the whole thing. Detection (how fast you know, and under what scenarios — a curve, not a binary). Decision (can the authorised people be assembled in time). Blast radius (models execute and scale fast, especially when connected — a steep cost range). Reversibility (stopping is only half the act; reverting requires journaling and backups). The danger case is a steep cost curve where an affordable window of one or two days of damage collides with a decision that cannot be made in one or two days. - **Canonical:** same as C20 - **First appearance:** 24 July 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes (the Venn is drawn in ASCII) - **Quote:** *"it is not just pulling the plug, it is pulling the plug and reverting the changes."* ### C22. The Five-Dimension Plug Profile (and the "no plug" correction) The pillar correction of the series: **the plug always exists** — you can always disconnect, revoke, or shut down. What earlier registers recorded as "no plug" for a data breach or a used foothold was never a missing off-switch; it was **zero recoverability**. Restating it that way turns a frightening blank into an ownable finding that points straight at prevention and the most senior acceptance. The profile carries five dimensions: **who holds it, blast radius, speed, side effects, recoverability**. - **Canonical:** `07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-a-real-plug-register-the-worked-proof-five-dimension-profile.md`; `.../v0.33.51__strategy-brief__sg-send-who-can-pull-the-plug-pillar-the-plug-always-exists-the-question-is-the-profile.md` - **First appearance:** 24 July 2026 · **Maturity:** well-developed with a worked register · **Newcomer-followable?** Yes - **Quote:** *"The blank said stop looking. The corrected profile says here is exactly what to do."* ### C23. Recoverability as the Hard Limit The dimension that stops irreversible harm disappearing into an expected-loss calculation. Money can be refunded; the customer cannot be un-declined. The flagship query in the entire model is: **show me every accepted risk whose recoverability is zero.** An organisation that can run it and read a short, deliberate, senior-owned list is in control of its worst exposure; one that cannot is accepting its irreversible risks by default and by silence. - **Canonical:** `07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-what-money-cannot-buy-back-recoverability-the-hard-limit.md`; `.../v0.33.51__strategy-brief__sg-send-can-you-compute-your-plug-profile-the-maturity-probe.md` - **First appearance:** 24 July 2026 · **Maturity:** well-developed; the *scoring* of recoverability is an open question · **Newcomer-followable?** Yes - **Quote:** *"The money can be refunded; the customer cannot be un-declined."* — `08/02/vault-as-substrate/v0.33.55__arch-brief__...article-26-5...md` ### C24. Altitude The corpus's word for organisational elevation, used as a first-class modelling dimension: a risk is accepted "at the right altitude" and then propagates; the same risk is restated in each altitude's own language; the plug changes at every altitude (who holds which off-switch); a risk may be confirmed at one altitude and accepted at another. - **Canonical:** `07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-the-plug-changes-at-every-altitude-who-holds-which-off-switch.md`; five-level table in `team/humans/dinis_cruz/briefs/07/12/worked-business-case/v0.33.48__briefing__...five-levels-graph.md` - **First appearance:** as a role metaphor 12 Feb 2026; as a risk dimension from June 2026 - **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"this is very important, the multiple altitudes of the risk register, because there might be risks that are only accepted at certain altitudes, or might be risks that are only confirmed at certain altitudes."* ### C25. Risk Appetite as a Revealed Band (and the Goldilocks Zone) Appetite is a **band**, not a number; a **fractal network** of bands (one per division and team, consolidated upward); and it already exists in any company that has operated for a while, so it is *discovered*, not declared. It is computed from two signals: what the business has paid to reduce in the past, and every fresh acceptance decision going forward. The target is to operate inside the band — above it you are buying risk the owners will not underwrite; below it you add attrition and slowness for nothing. Declared vs revealed appetite: **the gap between the two is the finding.** - **Canonical:** `team/humans/dinis_cruz/briefs/06/30/risk-acceptance-and-appetite/v0.33.38__strategy-brief__sg-send-risk-appetite-band-fractal-two-signals-goldilocks-zone-revealed-dataset.md` - **First appearance:** 30 June 2026 (v0.33.38) · **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"risk appetite is that band, that interval between two numbers, if you think of zero to one hundred in terms of risk, it is a spectrum, and it can be wider or shorter."* ### C26. The Psychology of the Physical Act Why the model insists on a click, a thumbs-up, a signature. The act is the moment a decision stops being ambient and becomes something a named person did, at a known time, on known information — a moment of accountability, which eventually carries liability, *as it should*. Without it, declining decays into a non-event: someone says "I'm not comfortable" and nothing happens. The forcing function closes that escape: declining is a trigger, not a terminal state. And it changes executive behaviour — the prospect of signing concentrates attention in a way dashboards never do. - **Canonical:** `team/humans/dinis_cruz/briefs/06/30/risk-acceptance-and-appetite/v0.33.38__strategy-brief__sg-send-risk-acceptance-psychology-accountability-liability-physical-act-revealed-appetite.md` - **First appearance:** 30 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes, and it is the most persuasive doc for a lay reader - **Quote:** *"suddenly the executives ask good questions, they really engage, they get a level of focus that just was not there before, and that is why risk acceptance is so powerful, it drives behaviours that otherwise do not exist."* ### C27. Accept First, Then Adjust the Level — the Risk Level Ledger For a risk you already have facts for, the first move is universal stakeholder acceptance **at its current level**, on the record. From there the level is not a fixed number but a **dated ledger of adjustments**, each re-accepted, triggered by one of three things: new data, a funded project, or an incident. Re-rating *up* after discovery is honesty, not failure — the risk did not worsen, the estimate improved. The board sees a living trajectory rather than a static red square. - **Canonical:** `team/humans/dinis_cruz/briefs/07/12/acceptance-and-residual/v0.33.48__arch-brief__sg-send-accept-first-then-adjust-the-level-risk-level-ledger-agentic-ai-shadow-agents.md` - **First appearance:** 12 July 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes - **Key line:** *"you literally cannot mitigate what you cannot count, and the only honest first step is to accept, now, that an unknown and largely over-permissioned population of agents holds access to the enterprise's assets."* ### C28. Everything Has Risks — Register Density and Calibration by Surprise The common register failure is holding only big risks and treating the goal as having none. A risk is the unintended side effect of a capability, so anything that *does* something has risks; capabilities exceed features, and undocumented capabilities are where unowned risks live. A complex product should have dozens to thousands of interconnected risks. The diagnostic: a listed risk materialising is expected; an **unlisted** risk materialising is the real alarm, because it raises two questions — why was it missed, and what else was missed? - **Canonical:** `team/humans/dinis_cruz/briefs/07/12/acceptance-and-residual/v0.33.48__arch-brief__sg-send-everything-has-risks-register-density-capabilities-vs-features-calibration-by-surprise.md` - **First appearance:** 12 July 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C29. Risks That Cannot Be Fully Mitigated (the residual) Mitigation lowers likelihood or impact but cannot reach zero for structural reasons, so a material residual always remains and must be owned. Demanding zero produces **covert acceptance**, which is worse than an owned residual. Agentic AI's residual is today irreducible: prompt injection, emergence, non-determinism, reach, model supply chain. Some harms are irreversible; compliance reduces but does not remove liability. - **Canonical:** `team/humans/dinis_cruz/briefs/07/12/acceptance-and-residual/v0.33.48__strategy-brief__sg-send-risks-that-cannot-be-fully-mitigated-board-terms-examples-agentic-ai-cyber-business.md` - **First appearance:** 12 July 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes (written in board terms deliberately) ### C30. Meta-Risks (the risk about your risk management) A recurring family, named as a pattern on 31 July after four instances: not knowing how many agents you have; not having defined an acceptable level; a risk accepted by the wrong person (the governance air gap); and systematic downgrading across a business unit. Each is a gap in the governance apparatus, stated as a rateable risk with an owner and an interval, which triggers and funds the work that closes it. External anchors defeat systematic downgrading, because an internal severity is an opinion while an external requirement is not. - **Canonical:** `team/humans/dinis_cruz/briefs/07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__sg-send-when-the-business-downgrades-everything-external-anchors-meta-risk-family-concealment-not-acceptance.md`; first instance in `06/26/.../v0.33.35__arch-brief__...md` - **First appearance:** as instance 26 June 2026; named as a family 31 July 2026 - **Maturity:** well-developed · **Newcomer-followable?** Yes - **Quote:** *"we are the meta risk; we allow the creation of the project that is going to discover this and that funds this."* ### C31. The Register Maintains Itself (accountability manufactures demand for evidence) Why no separate data-quality function is required. Three primitives produce it: the risk already exists, it attaches to a named person, and the decision is reviewed upward. Anticipated review is the engine — it converts care into a demand for evidence *before* the decision. The appetite for accurate evidence is a by-product of assigning accountability, so nobody has to fund it separately. Three named failure conditions: the reviewer's preference being guessable (people conform rather than think), commitment to a prior position, and broadened information appetite without improved discrimination. - **Canonical:** `team/humans/dinis_cruz/briefs/07/31/keeping-the-register-healthy/v0.33.54__arch-brief__sg-send-register-maintains-itself-accountability-manufactures-demand-for-evidence-three-failure-conditions.md` - **First appearance:** 31 July 2026 · **Maturity:** well-developed, research-grounded · **Newcomer-followable?** Yes ### C32. Three Moves, None of Which Is Denial The reconciliation of the no-deny primitive with human reactance. Presenting a single button to a person who feels they have no alternative produces counter-argument and resentment, not compliance. The resolution was already in the corpus: three moves exist — **accept for a stated interval with a stated action, escalate (this is not mine to accept), or challenge the fact itself**. The person is routed rather than cornered. The absence of a reject option should be *discovered*, not announced. - **Canonical:** `team/humans/dinis_cruz/briefs/08/02/field-demo/v0.33.55__arch-brief__sg-send-acceptance-flow-three-moves-none-is-denial-loop-closes-event-as-elicitation.md` - **First appearance:** 2 August 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C33. Decision as a First-Class Node An acceptance is a separate object, not a field on a risk. That is what allows one risk to accumulate many dated decisions without overwriting, one decision to cover several risks, and — crucially — a **calibration record** to be built over time asking whether the person who accepted for a month was right. - **Canonical:** `08/02/field-demo/v0.33.55__arch-brief__sg-send-demo-review-registers-are-one-chain-question-is-not-a-risk-decision-as-node-paths-are-traversals.md` - **First appearance:** 2 August 2026 · **Maturity:** newly stated, well-argued · **Newcomer-followable?** Yes - **Quote:** *"a decision is actually captured independently from the risk."* ### C34. A Question Is Not a Risk (the acceptability test) A clean quality gate. If a sentence cannot sensibly carry a named acceptor and an interval, it is not a risk and does not belong in the register. *"Nobody accepts 'whose call is it at three in the morning' for six months."* Questions become their own node type, and **unanswered question nodes are the most productive output of the whole exercise**. - **Canonical:** `08/02/field-demo/v0.33.55__arch-brief__...registers-are-one-chain...md`; questions-as-nodes worked in `08/02/vault-as-substrate/v0.33.55__arch-brief__...article-26-5...md` - **First appearance:** 2 August 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C35. Do Not Internalise the Risk The human-cost argument. Risk professionals frequently internalise exposures the business decided to carry, at real personal cost — the corpus cites survey data of 63–76% of security leaders experiencing or witnessing burnout in a single year, and names accountability-without-authority as the defining pressure. The standard remedy is to give the security leader more authority, which is correct and rarely achievable. The workflow solves the same equation from the other side, by moving accountability to where authority already sits. Nothing is taken from anyone; it records what was always true. - **Canonical:** `team/humans/dinis_cruz/briefs/07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__sg-send-do-not-internalise-the-risk-accountability-without-authority-relocated-not-augmented-mental-load.md` - **First appearance:** 31 July 2026 · **Maturity:** well-developed, research-grounded, with an honest scope disclaimer · **Newcomer-followable?** Yes - **Quote:** *"I would see the risk professionals almost own the risk; they almost take it personally with the risks that the business was taking, and it was a massive source of stress."* ### C36. Evidence Economy — Force of Proof and the Fact Certifier Once executives are personally accountable and the graph traces their statement to the evidence beneath it, a **force of proof** appears: demand for correct evidence becomes cheap to make and impossible to wave away. This splits the register into two separately liable roles — the **risk-acceptor** (owns the decision and its consequence) and the **fact-certifier** (owns the truth of the inputs and sells a correctness guarantee). A wide confidence band is the trigger that converts unease into a purchase order for better evidence, and two prices become legible: the cost of getting good evidence, and the cost of underwriting while the band stays wide. - **Canonical:** `team/humans/dinis_cruz/briefs/07/05/evidence-economy/v0.33.44__strategy-brief__sg-send-evidence-economy-force-of-proof-fact-certification-two-prices-evidence-based-revenue-models.md`; catalogued as P-429 in `team/roles/librarian/reality/ai-agents/proposed/risk-mandate.md` - **First appearance:** 5 July 2026 · **Maturity:** partially argued (commercially rich, mechanically thin) · **Newcomer-followable?** Mostly ### C37. Confidence Bands and Margin of Error Confidence is a first-class property of every node. A rating needs a band, not a point, and the band is widest where data is thin. A band too wide for comfort triggers the get-more-data direction; a band spanning trivial to catastrophic cannot be accepted responsibly. Confidence propagates across the graph like risk, and "we don't know" is the widest band. - **Canonical:** `team/humans/dinis_cruz/briefs/06/30/ontology-and-data-quality/v0.33.38__arch-brief__sg-send-confidence-margin-of-error-node-uncertainty-band-comfort-zone-more-data.md` - **First appearance:** 30 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C38. Two Underwritings — Decision Accountability vs Factual Accuracy Distinct and both required. The domain expert underwrites that a fact is true *and fit for the use being made of it*; the business owner underwrites the decision. Every graph traversal adds an abstraction layer that strips detail and drifts weight, so the signature failure is a component used beyond what its owner would underwrite. Decision accountability is only legitimate if the data underneath it is correct. - **Canonical:** `team/humans/dinis_cruz/briefs/06/30/ontology-and-data-quality/v0.33.38__arch-brief__sg-send-data-accuracy-owner-underwrites-fitness-for-use-vs-decision-accountability-tolerance.md` - **First appearance:** 30 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C39. Observability as a Risk Dimension Capability maps the privilege; observability maps the *real impact*. Six objective vectors on a maturity scale: capture granularity, log latency, time-to-damage given real throughput limits, whether monitoring is actually on and watched, whether there is a team with playbooks, and whether detection has been drilled. The reframe: **a loud, detectable, slowly-scaling, well-drilled risk is lower than a quiet, fast, unwatched one of the same capability.** Later sharpened into "plug-loaded observability" — logs that tell you where you are in the stopping decision, not generic logging. - **Canonical:** `team/humans/dinis_cruz/briefs/06/22/how-and-why-and-authorization/v0.33.32__arch-brief__observability-as-a-risk-dimension-detectability-time-to-damage-response-maturity-scale.md` - **First appearance:** 22 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C40. Five Whys as a Domain Translator Not a root-cause tool here but a **translator** that moves a statement from one domain into another. It is as many whys as it takes to reach the top of a domain. The graph has natural peaks — on risk it converges to the single risk of staying in business — and because it converges, a legitimate single number can be carried to the top. Aimed downward, the same chain captures the second, third and fourth stories: the root causes. - **Canonical:** `team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__strategy-brief__five-whys-as-a-domain-translator-natural-peaks-root-cause-stories.md` - **First appearance:** 26 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C41. Digital Twins and the Discipline of Reality The twin is where the graph stops modelling and continues into a real system — the grounding point beneath every measure. How connected a twin is to reality is itself a measurable property, which introduces a useful recursion: trust in a measure depends on the twin's connectedness, and that connectedness is itself a measure. A twin not connected to reality is a tracked air gap. - **Canonical:** `team/humans/dinis_cruz/briefs/06/26/digital-twins-and-world-models/v0.33.35__arch-brief__sg-send-digital-twins-twin-of-anything-dimensions-discipline-of-reality-simulation-testing.md`; `.../v0.33.35__arch-brief__sg-send-digital-twins-integration-layer-real-world-tracked-air-gaps-agent-twin.md` - **First appearance:** 15 Feb 2026 (general); as risk grounding, 26 June 2026 · **Maturity:** well-developed · **Newcomer-followable?** Yes ### C42. The Narrative Engine (register as story) The register is meant to be experienced as a story, not read as a spreadsheet: replay the change history through timestamps, commits or a series of queries, so the analyst watches the vulnerability appear, risks propagate, a governance risk fire and resolve, the blast radius bloom, and everything settle into the board's consolidated view. The commit log is the script; the query advances the scene. - **Canonical:** `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...md` - **First appearance:** 26 June 2026 · **Maturity:** partially argued (mechanism undecided in-doc) · **Newcomer-followable?** Yes - **Quote:** *"I want to show this story played as a narrative, almost like a football commentator, this happens and then that happens, almost like a whodunit, like investigative journalism."* --- --- ## Teaching order for the site | Altitude | Pages | Concepts | |---|---|---| | **1 · The inversion** | `/acceptance/` | C1 underwriting · C2 no-deny · C3 the ladder · C4 unaccepted=critical | | **2 · The vocabulary** | `/acceptable/` · `/register/` | C5 accepted≠acceptable · C25 appetite as revealed band · C9 register as graph of graphs · C10 fractal registers · C11 relevance fade | | **3 · The machinery** | `/ladder/` | C6 grounding ladder · C7 node type formulas · C8 ontologies of ontologies · C17 not-knowing-is-a-fact · C33 decision as a node | | **4 · The exposure** | `/plug/` · `/blast-radius/` | C19 authorization closure · C18 CIA expansion · C20–C23 the plug, four-way intersection, five dimensions, recoverability | | **5 · The organisation** | `/practice/` | C13 technical vs business owner · C14 confirmed/validated/accepted · C15 underwriting graph · C24 altitude · C26 the physical act · C28 register density · C30 meta-risks · C31 self-maintaining register · C35 do-not-internalise | | **6 · The maturity** | `/ramm/` | RAMM · AOMM · the plug-pull maturity model · C37 confidence bands · C38 two underwritings · C39 observability | --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/02__risk-acceptance.md — source document, verbatim ============================================================================== # 02 — Risk Acceptance, traced in full **The commissioned centrepiece.** The founder called out "risk acceptance" specifically, and it is the thread everything else in the corpus hangs from. This file traces it chronologically with exact paths and verbatim quotes, from the February 2026 classical-GRC pre-history through the June inversion to the July–August formalisation. `briefs/` = `team/humans/dinis_cruz/briefs/`. All paths verified at v0.33.62. --- ### 2.1 Pre-history (Feb–May 2026): classical GRC, later inverted The corpus's own starting point is orthodox. `team/roles/grc/reviews/02/19/v0.4.12__risk-acceptance__deliberate-token-exposure.md` (19 Feb 2026) is a textbook risk acceptance: R001/R002 rows with Likelihood, Impact, Mitigation, and *"Residual risk: Acceptable"*. `team/roles/grc/reviews/02/17/v0.4.9__vulnerability-classification-framework.md` establishes a P0–P10 scale with a Risk Decision Matrix whose five questions include *"What is the risk of the fix?"* — the earliest instance of the later "every action has risks, including the good ones" principle. `team/roles/grc/ROLE.md` states the classical position: *"Every risk the project faces -- technical, operational, reputational -- must be identified, assessed, and either mitigated or formally accepted with documented rationale."* Note the "either/or" — the June work abolishes it. **21 April 2026** is the first structural gesture toward the product: `team/humans/dinis_cruz/briefs/04/21/v0.21.9__dev-brief__evidence-packs-risk-acceptance-workflow.md` — *"Risk acceptance in organisations is broken. A decision gets made in a meeting. Someone writes it up (maybe). The reasoning is lost. The approval chain is informal. Six months later, nobody can explain why a particular risk was accepted, who approved it, what evidence was considered."* It proposes a `risk-decision-vault/` with `decision/`, `evidence/`, and `approvals/approval-tree.json`. ### 2.2 The risk already exists (4 June → 18 June 2026) `06/04/nhi-2.0/v0.32.3__strategy-brief__sg-send-nhi-2.0-risk-management-acceptance-underwriting-roi.md` is where "risk acceptance because the risk already exists" and "time-boxed sign-off as priority and mandate" first appear as new contributions. `06/18/agentic-permissions/v0.33.40__arch-brief__sg-send-risk-acceptance-underwriting-flows-upward-cross-domain-the-risk-already-exists.md` is the pillar document: > *"you are not predicting the risk of something happening, you are asking owners to underwrite it, insurance-style… the risk already exists the moment the permission is provisioned, so the only variable is how long you accept it, until it is re-accepted, eliminated, or the permission is narrowed; saying you are not comfortable changes nothing, you either accept it for a realistic fix-window or remove the privilege now."* And the accountability mechanic, in the founder's own voice: > *"from a psychological and accountability point of view, it is only when you get somebody to click, or put an emoji, or accept the terms, that they really engage, because that is the moment they become accountable. And if you accept the risk today and something major happens a week or month later, you are accountable, you should have done something. This creates positive pressures."* > *"risk acceptance is done in multiple levels and flows upward. A department uses a third-party agent: the person using it accepts the risk, then it goes to their boss to underwrite, then to the exec to underwrite, and eventually to the board to underwrite."* ### 2.3 The no-deny mechanic (23 June 2026) `06/23/risk-mandate-product-and-workflow/v0.33.33__dev-brief__sg-send-risk-acceptance-service-demo-no-deny-time-boxed-acceptance-expiry-as-cost-graph-evidence.md`: > *"the most important thing is that there is no deny button. The only buttons are accept for one hour, four hours, two days, two weeks, or a month, and the interval is when the risk acceptance expires, when you have to accept the risk again. So if you accept for an hour, you are really saying I need more data, someone needs to get me more data so I can make a better decision."* > *"four hours means start a P1 straight away, trigger your incident response and come back in four hours with a remediation. Two weeks means a funded project. Six months means you review it then, which means not doing anything, and that costs zero, because you are not doing anything about it."* The **expiry-as-cost table** (verbatim from that document): | Accept for | What it means | Action and cost | |---|---|---| | 1 hour | I need more data before I can really decide | Someone must go and get more data; near-immediate | | 4 hours | This is a P1 | Trigger incident response, playbooks, workflow; remediation within four hours; a real cost | | 2 days | A smaller incident, but still an incident | Something must be done within two days | | 2 weeks | A funded project | Plan and fund the fix; less immediate, lower cost | | 6 months | Do nothing | Review in six months; effectively no action; costs zero | ### 2.4 Two dimensions, and who accepts (23 June 2026) `06/23/risk-mandate-product-and-workflow/v0.33.33__arch-brief__sg-send-risk-acceptance-workflow-multi-stakeholder-graph-underwriting-propagation-override-pre-approval.md` splits an acceptance into **direction** (get more data / reduce / increase / hold) and **revisit interval**, independently: > *"there are at least two core primitives here, accept and get more data, and accept and deal with it and reduce the risk, and actually there should be another, accept and increase the risk, because it is okay to increase the risk if the business is okay with it."* **Who accepts** is answered three ways: (a) the underwriting requirement — *"the exec should never make a risk decision that has not been accepted, or explicitly not accepted, which also matters, by at least the technical or direct-line element, the CIO or CTO or CFO depending on the dimension, the respective CSO, and at least GRC"*; (b) altitude and propagation — *"the risk needs to be accepted at the right altitude, and then it propagates out… all the way to the CEO. The CEO acts on behalf of the board, so the buck stops with them, although some risks even the CEO has to take up to the board"*; (c) the technical/business owner split (C13). **Evidence strikes options off:** *"some risks depend on a set of actions that are not possible within an hour, so even if you start the biggest incident on the planet and throw all the money in, you cannot do it in less than an hour. So that option is removed from the equation."* No override can buy a physically impossible timeline; the only escape is the nuclear option, ceasing the activity. **Compound pre-approval:** approval attaches to a *risk profile*, not each instance. Further instances become an FYI; a fresh approval is needed only when the profile changes. ### 2.5 Acceptance as a graph node Four progressive formalisations: 1. **26 June 2026** — `06/26/semantic-graph-and-query-paths/v0.33.35__arch-brief__sg-send-2fa-use-case-semantic-graph-ontology-nodes-edges-instance.md` makes `Acceptance` and `Interval` node classes with edges `accepted_by`, `has_interval`, `propagates_to`, `underwritten_by`, `overrides`. 2. **2 July 2026** — RAMM (`07/02/authorization-and-maturity-model/v0.33.40__arch-brief__...ramm...md`) makes `RiskAcceptanceDecision` the hub node with twelve named directed edges (`ownedBy`, `approvedBy`, `boundedBy`, `withinToleranceOf`, `justifiedBy`, `evidencedBy`, `reviewedAt`, `expiresAt`, `reassessOn`, …). 3. **5 July 2026** — `AcceptanceDecision` becomes a Layer-5 node type in the AWS IAM ontology, with the formula `AcceptableForInterval := a Risk with an accepted_by path to an AcceptanceDecision carrying an owner, a direction, an interval, and a sign-off.` 4. **2 August 2026** — Decision promoted to a fully independent node (C33), enabling many decisions per risk and the calibration record. ### 2.6 Escalation without an escalator The mechanism's most elegant consequence, stated at `07/17/.../v0.33.49__arch-brief__...interval-ladder...md` and demonstrated on live data at `08/02/vault-as-substrate/v0.33.55__arch-brief__...article-26-5...md`: > *"R3 appears on the chief financial officer's register as an unowned critical item, and it got there without anybody escalating it deliberately. That is the mechanism working: not doing something is a measurable action."* And the design consequence for non-participation, at `07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__...design-for-players-who-will-not-play...md`: attrition — not open refusal — is the failure mode that matters, and the roll-up *"removes the deniability attrition depends on, without requiring anyone to cooperate."* ### 2.7 Accepted vs acceptable (28 July 2026) Covered in full at C5. The one connection flagged as new and untested: **the acceptance interval should be a function of the distance from the acceptable line** — far above the line warrants a short interval, at or below warrants a long one, making the interval computable from two numbers already in the register. ### 2.8 Consequential loose ends in the thread - The corpus repeatedly cross-references **`v0.33.46__strategy-brief__sg-send-risk-acceptance-redefined-vs-industry-definition-no-deny-only-how-long-accountability.md`** (7 July 2026) — cited by eight documents — but **this file does not exist in the repo**. Nor do the referenced `v0.33.46` "who-holds-the-bag / Vercel allow-all", "risk-to-an-exec", or `v0.33.47` "kitchen-sink" briefs. There are no `briefs/07/06` through `briefs/07/11` directories. **A canonical "risk acceptance redefined" statement is a named gap in the corpus** and is a prime candidate for risks.sgit.ai to author from the surrounding material. - The metric the founder proposes for the whole model: *"our key metric is not recurring revenue, it is recurring risk acceptance, how many risk acceptances we are having every day, every week, every month, because that is when we know it is working."* (`06/28/use-cases-and-risk-acceptance/v0.33.36__strategy-brief__sg-send-use-case-driven-shipping-risk-acceptance-story-recurring-risk-acceptance-metric.md`) --- --- ## What the site should do with this 1. **`/acceptance/` is the front door**, not a sub-page. It is the most distinctive thing in the corpus and the most immediately graspable — the no-deny mechanic needs no GRC background to land. 2. **Publish the interval ladder as a table**, with the operational consequence stated per rung. It is the single cleanest artefact in the corpus and it is what an agent will look up. 3. **State the two orthogonal axes early.** *Accepted* is an act by a named person at a dated moment; *acceptable* is a threshold owned by the business. Conflating them is the failure the whole vocabulary correction exists to prevent. 4. **Show `unaccepted = critical` on live data.** The Agentic Browser Isolation vault runs acceptance-gated escalation across five altitudes with no deny button — it is C2 and C4 demonstrated, not asserted. 5. **Carry the loose ends honestly** — see `07__gaps-and-open-questions.md`. A model this opinionated earns credibility by naming what it has not resolved. --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/03__worked-examples-and-vaults.md — source document, verbatim ============================================================================== # 03 — Worked Examples and the Live Vaults The proof layer. Three fully worked risk graphs with node and edge counts, four published vaults with read keys, and every citable number in the corpus. `briefs/` = `team/humans/dinis_cruz/briefs/`. --- ## A · The four published vaults **These are live, browsable, and have published read keys.** They are the strongest asset the site has and should be first-class, not a demos page. | Vault | Read key (published) | Size | Contents | |---|---|---|---| | **Risk Graph Explorer** | `sgit_rk1_1c1b95f5903e35850a…` | 33 files · 428 KB · 7 commits | Public-by-design app. **7 views recomputed simultaneously**: estate graph, context, role risk map, risk chains, the register, acceptance (who holds what), incident-to-project. "Exposed" preset = **18 facts, 37 risks, 14 provisions**. Colour semantics: **amber = exposure, green = assurance, ghosted = unanswered**. `app.json` requests `permissions: {}` — no network, no storage, no account | | **Agentic Browser Isolation** | `sgit_rk1_92cad4cea8f58c55f5…` | 104 files · 2.4 MB · 4 commits | **17 entry points**: narrative spine, per-altitude stakeholder pages, an explorer, two graph visualisations, raw data. ~70 JSON files. Acceptance-gated escalation across **5 altitudes (L1 IT → L5 Board)**, **no deny button**. `fs.write: []` | | **Risk Mandate** | `sgit_rk1_a702fba803faac436…` | 124 files · 1.9 MB · **98 commits** · 8 app entries | The software project itself, in a vault. The most-committed published vault — the method applied to its own build | | **Regulation Graph** | `sgit_rk1_c004daae386e8d17fa…` | 207 files · 14.9 MB · 2 commits | **1,523 nodes · 1,944 edges** from official Formex XML, SHA-256 hash-verified. 113 articles, 500 paragraphs, 417 points, 180 recitals, 13 annexes, 68 definitions. **11 views** incl. Cytoscape article graph, SQLite, RDF/Turtle export, an **Art 9 Lab with a Graph REPL** | **Why each belongs on risks.sgit.ai** - **Risk Graph Explorer** — the ghosted-edge convention *is* concept C17 (not knowing is a fact) rendered. Nothing else in the estate makes an absence visible. - **Agentic Browser Isolation** — C2 (no-deny) and C4 (unaccepted = critical) running on real data across five altitudes. Assertion becomes demonstration. - **Risk Mandate** — 98 commits of the method applied to itself. - **Regulation Graph** — supplies Article 9(5) (the undefined "acceptable"), Article 14 (the plug obligation) and Article 26(5)/(6) (the worked example anchor). The concepts hang off real provisions. ⚠️ **Publishing rules.** Read keys yes, write keys never; escrow the write key *before* publishing, because a vault whose write key is lost is **frozen** — permanently readable, never updatable. The Regulation Graph is already a redacted republication after an audit found a plaintext key in its history; adopt its `PUBLIC.md` transparency convention. Source: `briefs/08/14/sgit-site-and-hub/v0.33.58__strategy-brief__sgit-topic-sections-catalogue-read-keys-yes-write-keys-never-frozen-vaults.md` --- ## B · The worked graphs ### 4.1 The 2FA worked example (26 June 2026) — the founding scenario `06/26/risk-register-and-five-whys/v0.33.35__arch-brief__...md` and `06/26/semantic-graph-and-query-paths/v0.33.35__arch-brief__...2fa-use-case...md`. - Vulnerability **V1**: admin accounts lack 2FA, backed by **E1** (configuration shows no MFA). - Attack **ATK-1**: credential stuffing, mapped to **MITRE ATT&CK T1110.004**, performed by **TA-1**. - Risks **R1–R9**: R1 accounts compromised; **R2** governance air gap (accepted by the wrong owner) — accepted by Head of GRC at a **4h** interval (P1), propagating GRC → CIO → CEO → Board, *each accepting at 4h because that is the only option open to them*; R3 unauthorised HR admin access; **R4** risk mis-classified until investigated (spawned by fact **F5**, which *lacks* evidence); **R5** data incident + **R6** GDPR breach (two distinct risks); **R7** salary/record tampering or fabricated hires; **R8** weekly-backup data-loss window; **R9** restore never tested. - Interval resolution for R3: **4h struck off** (not technically possible), **48h** = P1, **2w** = incident, **1–2m** = funded project, **6m** = do nothing. Evidence **E3** ("no evidence of compromise") backs the absence of clear and present danger; **E4** = backup logs show weekly; **E5** = no record of a tested restore. - Data classification is the blast-radius multiplier: **DC-1** full HR data (passports, salaries, bonuses, PIPs, reviews, hires, fires, dismissals) vs **DC-2** anonymised timesheets. - Ontology size: **24 node classes, 34 edge types.** ### 4.2 The browser-isolation business case (12 July 2026) — the largest single graph `07/12/worked-business-case/v0.33.48__briefing__...five-levels-graph.md`. Parsed from the embedded JSON: - **59 nodes, 75 edges.** - Node type distribution: Risk 13, Owner 7, Evidence 6, Vulnerability 6, Fact 5, Asset 4, Measure 4, PreventiveControl 3, Grant 2, AuthorizationClosure 2, BlastRadius 2, AcceptanceDecision 2, Reality 1, Twin 1, DetectiveControl 1. - Edge type distribution: `gives_rise_to` 22, `backed_by` 14, `owned_by` 11, `measured_by` 5, `protected_by` 5, `exposes` 3, `reaches` 3, `observed_on` 2, `grants` 2, `accepted_by` 2, `underwritten_by` 2, `connected_to` 1, `impairs` 1, `emits` 1, `conditional_on` 1. - Structured as **F1–F8** facts, **E1–E8** evidence, **V1–V6** vulnerabilities, **R1–R5** risks, **L1–L5** altitudes (IT/desktop → CISO → CFO/COO/DPO → CEO → Board). - Concrete figure: vendor system cards reporting browser prompt-injection **attack success rates falling from roughly half to about one percent across a single model generation** — cited deliberately as the honest counterweight, since it is a large real improvement that still does not reach zero. - Three risks *of the mitigation itself* are on the register: concentrated platform dependency, the platform now seeing the content, and friction routing users around it. ### 4.3 The Article 26(5) creditworthiness example (2 August 2026) — the complete instance `08/02/vault-as-substrate/v0.33.55__arch-brief__...article-26-5...md`. Its own **Node and Edge Inventory** table: | Type | Count | Notes | |---|---|---| | Reality | 1 | The running system | | Twin | 1 | The deployed agent | | Fact | 8 | One deliberately unevidenced (**F7**: suspension procedure never exercised) | | Evidence | 7 | One absent | | Provision | 5 | Annex III 5(b), Articles 26(5), 26(6), 14, 27 | | Vulnerability | 3 | Derived from fact + provision | | Risk | 5 | Four in a chain, one meta (**R5**: no acceptable level defined) | | Stakeholder | 4 | ML platform lead, head of lending ops, DPO, CFO | | Decision | 3 | Plus one deliberately absent (**D3**) | | Question | 9 | **Five unanswered — "those five are the actual output of the exercise"** | | Project | 2 | Plus one unfunded | Hard numbers inside it: **thirty days** log retention observed vs **at least six months** required by Article 26(6) — *"arithmetic, not judgement, which makes it the most defensible finding in the graph."* Acceptance intervals: D1 = 1 month, D2 = 1 month, D3 = none, D4 = 3 months. Proposed new edge types: `governed_by`, `in_scope_when`, `answers`, `re_rates`. ### 4.4 The plug register (24 July 2026) `07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__...five-dimension-profile.md` — a seven-row register re-expressed in the five-dimension profile, spanning from *"Agent misuses the isolated session"* (IT / small / fast / high recoverability) through *"Agent misuses the platform itself"* (COO/procurement / large / slow-contractual / medium) to *"Data leaves the boundary"* and *"Unattributable transaction"* (**recoverability: zero**) and *"Governance residual"* (the board / slowest / lowest). ### 4.5 The ten scenarios (2 July 2026) — the shipped MVP content `07/02/risk-acceptance-and-scenarios/v0.33.40__strategy-brief__...how-long-would-you-accept...md`: every email you own; your calendar; your private messages; the company card; the OAuth token; all your repositories; the production database; your unlocked laptop; a database of customers' passwords; one customer reaching another. Each written as hook → reveal → punchline, the punchline always *"how long?"* Slide four shows the interval choices: **an hour, four hours, a day, a week, a month, six months.** ### 4.6 Concrete figures scattered across the corpus, with sources | Figure | Meaning | Source | |---|---|---| | **12 to 18 hours** | Hyperscaler cost-reporting delay = a hard detection floor; that much damage before anyone sees it | `07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__...ability-to-stop...md` | | **16 hours** | The founder's separate AWS figure: *"AWS usually takes 16 hours to give you the data, so how much damage can be done in 16 hours."* | `07/05/aws-configuration-risk-engine/` | | **up to 24h** | Billing-lag damage window on the cost blast radius | librarian P-424, `.../reality/ai-agents/proposed/risk-mandate.md` | | **1,088 prompts → 5,317 agent-executed commands**, 34 sessions, **305 internal servers**, **400+ custom attack scripts**, 20 known vulnerabilities, **~400 million records**, **9 Mexican government bodies** (incl. federal tax authority, civil registry, electoral institute), Dec 2025–Feb 2026 | Check Point AI Security Report 2026 | `07/28/agentic-risk-research/v0.33.53__research-brief__...has-it-happened-before...md:40` | | **~30 targets**, **80–90%** of tactical operations agent-handled; detected Sept 2025, disclosed 13 Nov 2025; US Senate letter 2 Dec 2025 | GTG-1002 state-sponsored campaign | same file, line 38 | | **1 outbound entry** in the escaped-agent population | July 2026 evaluation-sandbox escape (published 16 & 21 July 2026) | `07/27/outbound-agentic-risk/v0.33.52__research-brief__...md` | | **63–76%** of security leaders experiencing or witnessing burnout in a single year | The internalisation argument | `07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__...do-not-internalise...md` | | **72% / 43% / 76%** | Change-resistance failure rates from three sources | `07/31/.../v0.33.54__strategy-brief__...design-for-players-who-will-not-play...md` | | **7,500+ participants** | Preregistered escalation-of-commitment experiments: precommitment made later de-escalation seem more trustworthy | `07/31/projects-budgets-and-evidence/v0.33.54__arch-brief__...pre-approve-the-ladder...md` | | **19.7M transfers** | Collision threshold cited as a P6 example | `team/roles/grc/reviews/02/17/v0.4.9__vulnerability-classification-framework.md` | | **August 2026** | EU AI Act high-risk compliance deadline | `07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__...ability-to-stop...md` | | **2026-08-04** | Black Hat USA Business Hall opening — the field-demo deadline the Aug briefs are written against | `07/28/mvp-and-field-demo/v0.33.53__arch-brief__...hand-them-the-ipad...md` | | **~3,000 entries** | Recommended per-directory limit that shapes vault packaging | `08/14/sgit-site-and-hub/v0.33.58__strategy-brief__...component-registry...md` | | **~496,000 words** | Size of the core June-18-to-August risk corpus | measured across the risk brief folders | --- --- ## C · Prior art — published risk articles on docs.diniscruz.ai **59,131 words across 8 articles, February – July 2025** — a year before the `__Send` corpus, in the founder's public voice, already circulated. Full metadata with canonical URLs, first-published dates, authors, PDFs and LinkedIn posts in `sources__docs-diniscruz-ai-risk.json`. | First published | Title | Words | |---|---|---| | 2025-02-15 | [Project SupplyShield: GenAI-Driven Supply Chain Risk Management and Compliance](https://docs.diniscruz.ai/2025/02/15/project-supplyshield__genai-driven-supply-chain-risk-management-and-compliance.html) | 8,802 | | 2025-04-02 | [Maturity Models vs. Traditional Standards in Application Security](https://docs.diniscruz.ai/2025/04/02/maturity-modes-vs-traditional-standards-in-application-security.html) | 2,701 | | 2025-04-10 | [Project Cybersage: AI-Powered Risk Contextualization & Security Reporting](https://docs.diniscruz.ai/2025/04/10/project-cybersage__ai-powered-risk-contextual.html) | 6,270 | | 2025-05-29 | [Threat Models as Mandatory Disclosures](https://docs.diniscruz.ai/2025/05/29/threat-models-as-mandatory-disclosures__a-vision-for-security-transparency.html) | 7,160 | | 2025-05-29 | [Advancing Threat Modeling with Semantic Knowledge Graphs](https://docs.diniscruz.ai/2025/05/29/advancing-threat-modeling-with-semantic-knowledge-graphs.html) | 9,217 | | 2025-06-02 | [Linking Threat Models with Semantic Business Graphs](https://docs.diniscruz.ai/2025/06/02/linking-threat-models-with-semantic-business-graphs.html) | 9,816 | | 2025-07-06 | [Finding the "Good Enough" Threshold: Optimizing Risk, Creativity, and Product Decisions](https://docs.diniscruz.ai/2025/07/06/finding-the-good-enough-threshold-optimizing-risk-creativity-and-product-decisions.html) | 4,924 | | 2025-07-27 | [Project VulnAI: AI-Powered Vulnerability Risk Management Platform](https://docs.diniscruz.ai/2025/07/27/project-vulnai-ai-powered-vulnerability-risk-.html) | 10,241 | **Two are directly load-bearing.** *Maturity Models vs. Traditional Standards* (Apr 2025) is the ancestor of RAMM, a year early. *Finding the "Good Enough" Threshold* (Jul 2025) is the ancestor of C5 and C25 — it is the appetite argument before it had the vocabulary, and it carries **15 mentions of risk acceptance / appetite**, the highest density on the site. ⚠️ **Provenance contract applies.** Anything republished keeps its original date, original link, original co-authors and an honest curation label — the same rules as the newsroom pack. `docs.diniscruz.ai` is **CC0** at source; the sgit.ai estate is CC BY 4.0. State the source licence per page. --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/04__riskmandate-refactor.md — source document, verbatim ============================================================================== # 04 — The riskmandate.ai Refactor **The commission:** *"I also want to refactor out of riskmandate.ai a lot of those concepts, since that is a commercial site which will be focused on the commercial and customer/user angle of getting risks accepted. i.e. it is the riskmandate.ai that should be referencing the risks.sgit.ai."* --- ## 1. The line | | riskmandate.ai | risks.sgit.ai | |---|---|---| | **Question it answers** | *"How do I get my risks accepted, and what does it cost?"* | *"What is a risk, what is acceptance, and why is it modelled this way?"* | | **Reader** | Buyer, user, executive | Researcher, practitioner, **agent** | | **Register** | Product — outcome, price, proof | Research — argument, definition, evidence | | **Licence** | Commercial site | CC BY 4.0 | | **Change cadence** | Follows the product | Follows the thinking | **The dependency direction is one-way: riskmandate.ai cites risks.sgit.ai.** Never the reverse for conceptual claims — the research site must be able to stand without the product. --- ## 2. Page-by-page Every row is from riskmandate.ai's own `llms.txt`. ### Moves here | Page | Content | Target | Notes | |---|---|---|---| | **`/plug.html`** | Five dimensions (who · blast radius · speed · side effects · **recoverability**); the reversible/irreversible split; *"the mandate states what an agent is authorised to reach; the plug profile states what it costs to take that reach away"* | `/plug/` | ⚠️ The corpus records a **"no plug" correction** the published page does not reflect. Reconcile before republishing — see `07` | | **`/acceptable.html`** | Two orthogonal axes; four states; the interval table (1–24h P1 → beyond 3 months acknowledged waiting); *"distance to the line sets the clock"*; appetite reframed; Article 9(5) | `/acceptable/` | Strip *"Book a demo"* and the executive-audience targeting | | **`/ramm.html`** | Five levels as **Node Type Formulas** — *"a path-pattern a query can test"*; the entity model (RiskItem, RiskAcceptanceDecision, DecisionAuthority, RiskAppetiteStatement, ReviewEvent, ExpiryEvent, EvidenceArtifact…); the Agentic `+` variants; crosswalks to OWASP Risk Rating, SAMM, ASVS, WSTG, Threat Dragon, DefectDojo/CycloneDX, RIMS RMM | `/ramm/` | ⚠️ **Base levels 1, 2, 4, 5 are underspecified** — only Level 3 has a stated predicate. Fix before republishing | | **`/library.html`** — 9 concept pieces: blast radius · the mandate · permission granularity · PBOM · risk acceptance · second/third-order effects · graphs of graphs | The whole `/concepts/` section | ⚠️ **The page currently links nothing.** See §4 | | The SG/Vault technical section | Zero-knowledge, client-side encryption, key sovereignty | Cite **sgit.ai**, don't own | Not risk's concept | ### Splits | Page | Concept half → risks.sgit.ai | Product half stays | |---|---|---| | **`/how-it-works.html`** | The mechanism: how acceptance nodes carry evidence, ownership, authority, appetite and review | The product walkthrough, the UI, the flow a customer follows | | **`/scenarios.html`** + **`/statics.html`** | The **ten scenarios as a research artefact** — `briefs/07/02/risk-acceptance-and-scenarios/v0.33.40__strategy-brief__…how-long-would-you-accept…md`. Hook → reveal → punchline, punchline always *"how long?"* | The interactive scenario product | ### Stays commercial `/v0/…/index.html` ("You own the risk") · `/demos.html` and the three demo pages · `/pricing.html` · `/partners.html` ### Pattern to copy, not move `/agents.html`, `/llms-full.txt`, `/.well-known/agent-content.json`. **riskmandate.ai's agent surface is the best in the estate** — a dedicated agents page, the full site as one markdown fetch, and a structured JSON manifest. risks.sgit.ai needs its own, and given the commissioned audience it should be *better*. --- ## 3. The leave-behind Each moved page leaves a stub. Draft, to adapt: > ### Accepted is not acceptable > > Two independent properties. **Accepted** is an act: a named person with the standing to do it says *I carry this*, for a stated interval. **Acceptable** is a threshold the business owns — the point at which it stops funding remediation. > > RiskMandate implements both. The full argument, the four states and the Article 9(5) analysis are at **[risks.sgit.ai/acceptable](https://risks.sgit.ai/acceptable/)**. > > [See how it works in the product →] Three sentences of substance, one link out, one link deeper into the product. The buyer gets what they need; the researcher and the agent get sent to the source. --- ## 4. ⚠️ The finding that justifies the split **`riskmandate.ai/library.html` lists nine concept pieces and links to none of them.** The page describes *"recorded talks, the full proposition deck, and the long-form pieces"* covering agent authorization scope, authority ownership, residual risk acceptance and comprehensive risk modelling — and ships no URLs for any of it. That is not an oversight so much as a structural mismatch: a commercial site has no natural place to put nine essays, so they get described rather than published. **A research property does.** This single page is the clearest evidence that the split is the right call. --- ## 5. Sequencing 1. **Stand up risks.sgit.ai with `/acceptance/`, `/acceptable/`, `/ladder/` and `/plug/`.** Four pages, all near-publishable. 2. **Replace those four riskmandate.ai pages with leave-behind stubs** pointing here. 3. **Build `/concepts/` properly** — the nine library pieces plus the other 33 from `01__concepts-index.md`. This is what `library.html` was always trying to be. 4. **Reconcile the two known defects** — the plug correction, the RAMM base levels — before republishing either. 5. **Add `/agents/` and `/llms-full.txt`**, modelled on riskmandate.ai's and extended for the commissioned audience. 6. **Cross-link the four vaults** from both sites: risks.sgit.ai as worked examples of the concepts, riskmandate.ai as product demos. **Same artefacts, two framings — that is the split working.** --- ## 6. What must not happen - **risks.sgit.ai must not carry pricing, partner positioning, or competitor comparisons.** The `07/12/positioning-and-market/` briefs name two large vendors [REDACTED · Tier-3 · see PUBLIC.md] with dismissive characterisations — commercial, internal-only, and corrosive on a research site. - **riskmandate.ai must not keep a second, drifting copy of a concept.** Stub and link, or move it wholly. Two versions of the interval ladder that disagree is worse than either. - **No concept page should depend on the product existing.** Per `00__BRIEF.md` §1, none of this is implemented. The research stands on its own; the product is one implementation of it. --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/05__site-architecture.md — source document, verbatim ============================================================================== # 05 — Site Architecture **Status:** ✅ near-as-is · ✏️ needs framing · ✍️ write fresh · 🔗 links out · 📎 provenance block · ⚠️ correction first `briefs/` = `team/humans/dinis_cruz/briefs/`. Concept refs (C1…C42) are defined in `01__concepts-index.md`. --- ## Shape Two audiences, and the second is the commissioned one: **a human deciding whether this model makes sense**, and **an agent that needs the definitions**. The IA serves the human by depth and the agent by addressability — every concept gets a stable URL and an anchor. ``` risks.sgit.ai ├── / the inversion, in one screen ├── /acceptance/ ★ underwriting · no-deny · the ladder · unaccepted=critical ├── /acceptable/ accepted ≠ acceptable · appetite as a revealed band ├── /ladder/ ★ the grounding ladder · node type formulas · ontologies of ontologies ├── /register/ graph of graphs · fractal registers · relevance fade ├── /blast-radius/ authorization closure · CIA expansion ├── /plug/ who can stop it · five dimensions · recoverability ├── /practice/ owners · altitude · psychology · density · meta-risks · health ├── /ramm/ RAMM · AOMM · the plug-pull maturity model ├── /examples/ ★ three worked graphs + four live vaults ├── /concepts/ all 42, addressable, one anchor each ├── /agents/ ★ the machine surface ├── /shipped/ what is argued vs what runs ├── /origins/ Feb 2026 GRC → the June inversion → Aug formalisation ├── /network/ the seven-site boundary map ├── /documents/ raw markdown, source of truth ├── /admin/{comms,versions,index} · /about/participant.html └── /llms.txt + /llms-full.txt ``` --- ## `/` — the front page | Element | Content | Status | |---|---|---| | The inversion | *"We are not describing the risk of something happening. We are asking someone to underwrite it."* | ✅ C1 | | The mechanic | **There is no deny button.** Only how long you accept it before re-accepting | ✅ C2 | | The consequence | A risk nobody accepted has not gone away — it rests on whoever is nearest, and it is rated **critical** | ✅ C4 | | Proof strip | 59/75 · 51/53 · 1,523/1,944 · 4 live vaults · 5 altitudes · 6 intervals | ✅ §6 of `00` | | Honesty line | *"This is a research site. The concepts are argued, the graphs are real, four vaults are live. The engine is not built."* | ✍️ | | The split | One line on what riskmandate.ai is for, and a link | ✍️ | --- ## `/acceptance/` — build first | Page | Concept | Source | Status | |---|---|---|---| | `/acceptance/underwriting/` | **C1** — *"the analogy is insurance: you are underwriting the damage… The business executive is ultimately accountable for everything"* | `briefs/06/18/agentic-permissions/v0.33.40__arch-brief__…the-risk-already-exists.md` | ✅ | | `/acceptance/no-deny/` | **C2** — *"the mistake of a lot of risk registers is that they allow the risk to be denied, which can only happen when the risk has not materialised"* | `briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__dev-brief__…no-deny-time-boxed-acceptance-expiry-as-cost…md` | ✅ **the most graspable page on the site** | | `/acceptance/the-ladder/` | **C3** — the interval *is* the decision. 1h / 4h / 1d / 1w / 1m / 6m, one month default, each rung with its operational consequence | `briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__…acceptance-interval-ladder…md` | ✅ **publish as a table** | | `/acceptance/unaccepted-is-critical/` | **C4** — *"that person right now is accountable for the business, which is very bad from a business point of view, but is also very bad for the individual"* | same, + the Article 26(5) worked example | ✅ | | `/acceptance/workflow/` | **C15** underwriting graph · **C33** decision as a node · override and pre-approval | `briefs/06/23/…v0.33.33__arch-brief__…risk-acceptance-workflow-multi-stakeholder-graph-underwriting-propagation-override-pre-approval.md` | ✏️ | --- ## `/ladder/` — what agents most need Definitional, not narrative. Every node type stated as a required path pattern, machine-readable where possible. | Page | Concept | Source | Status | |---|---|---|---| | `/ladder/index.html` | **C6** Reality → Twin → Measure → Evidence → Fact → Vulnerability → Risk. Downward grounds; upward classifies. *"A Fact becomes a Vulnerability purely because of its upward link to a Risk, so that legitimacy is conferred entirely from above."* | `briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__…grounding-ladder…md` | ✅ **the most rigorous document in the corpus** | | `/ladder/formulas/` | **C7** — *"the ontology definition of a node type is its upward and downward path-pattern, not a sentence about what it contains"* | `briefs/06/28/…v0.33.36__arch-brief__…node-type-formulas…md` | ✅ | | `/ladder/bridges/` | **C8** three layers — shared facts, per-party formulas, declared bridges. Plus the worked Manion/Jacobs/Roytman bridge | `briefs/06/28/…ontologies-of-ontologies…md` + `…bridge-vulnerability-formula-system-fault-security-failure-conditions-manion-jacobs.md` | ✅ names three real researchers favourably | | `/ladder/absence/` | **C17** not knowing is a fact — countable, queryable, assignable | `briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…facts-only-no-deny-cascade-cia-blast-radius.md` | ✏️ | 🔗 **Cite graphs.sgit.ai, don't restate it.** Node type formulas *as a mechanism* belong there; the grounding ladder *as a risk formula* belongs here. --- ## `/examples/` — the proof | Page | Content | Status | |---|---|---| | `/examples/browser-isolation/` | **59 nodes, 75 edges**, inline JSON. 5 altitudes, 3 risks *of the mitigation itself*. Vendor system cards: prompt-injection success falling **~50% → ~1%** across one model generation, cited as the honest counterweight | ✅ | | `/examples/2fa/` | **51 nodes, 53 edges**, downloadable JSON. Ontology **24 node classes, 34 edge types**. MITRE **T1110.004**. The R2 governance air gap accepted at 4h by the wrong owner, propagating GRC → CIO → CEO → Board | ✅ **the only downloadable graph** | | `/examples/article-26-5/` | 8 facts (one unevidenced), 5 risks, 4 stakeholders, **9 questions — 5 unanswered**. The **30 days vs 6 months** arithmetic finding | ✅ | | `/examples/vaults/` | 🔗 The four live vaults with read keys — see `03__worked-examples-and-vaults.md` §A | 🔗 ✅ | | `/examples/scenarios/` | The ten scenarios, hook → reveal → punchline, punchline always *"how long?"* | ✅ | | `/examples/plug-register/` | The seven-row plug register, from *"agent misuses the isolated session"* to *"unattributable transaction"* (**recoverability: zero**) | ✅ | --- ## The rest | Section | Concepts | Notes | |---|---|---| | `/acceptable/` | **C5** two axes, four quadrants, Article 9(5) · **C25** appetite as a revealed band, the Goldilocks zone | 📎 Moves off riskmandate.ai | | `/register/` | **C9** graph of graphs · **C10** fractal registers · **C11** relevance fade · **C12** one chain not parallel lists · **C16** cascade and air gaps · **C42** the narrative engine | ✅ | | `/blast-radius/` | **C19** authorization closure — *what the agent can reach, computed* · **C18** CIA expansion | ✅ | | `/plug/` | **C20** two symmetric risks · **C21** four-way time intersection · **C22** five dimensions · **C23** recoverability. Detection floor **12–18h** | 📎 ⚠️ reconcile the "no plug" correction | | `/practice/` | **C13** technical vs business owner · **C14** confirmed/validated/accepted · **C24** altitude · **C26** the physical act · **C27** the level ledger · **C28** density and calibration by surprise · **C29** residuals · **C30** meta-risks · **C31** the self-maintaining register · **C32** three moves · **C34** a question is not a risk · **C35** do not internalise (**63–76%** burnout) | ✏️ | | `/ramm/` | RAMM five levels · AOMM · the plug-pull maturity model · **C37** confidence bands · **C38** two underwritings · **C39** observability | 📎 ⚠️ base levels underspecified | | `/concepts/` | All 42, one anchor each, addressable | ✍️ | | `/origins/` | Feb 2026 classical GRC (`team/roles/grc/`) → 4 June *"the risk already exists"* → 23 June no-deny → 28 June the ladder → 17 July intervals → 28 July accepted≠acceptable → 2 Aug end-to-end | ✏️ | --- ## `/agents/` — the commissioned surface The brief says the point of this site is that **agents need a good understanding of these concepts**. So this is not a courtesy page. | Element | Content | |---|---| | `/llms.txt` | Each entry carries the concept's **single most important fact**, not its topic. *"C2 no-deny — a risk with a real vulnerability under it exists whether or not anyone acknowledges it, so there is no deny button; the only choice is how long"* | | `/llms-full.txt` | The whole site in one fetch. **Non-negotiable here** — measured on sgit.ai, agent fetch tools refuse URLs a search has not returned, so link-following fails | | `/.well-known/agent-content.json` | Structured manifest — copy riskmandate.ai's pattern | | **The definitions endpoint** | The 42 concepts as JSON: name, one-line definition, canonical source, maturity, related concepts. **Nothing else in the estate has this and it is the single highest-value thing this site can ship** | | **The ontology download** | Node types and edge types with their path formulas, plus the 2FA instance graph | | Per-page agent block | Every concept page ends with a pasteable summary an agent can carry into another session | --- ## `/shipped/` — non-negotiable Nothing in the risk corpus is implemented. Greps for `risk_`, `RiskAcceptance`, `risk_register`, `riskmandate` across `sgraph_ai_app_send/**/*.py` return **zero**. The reality file says *"Do not describe any of these as existing features."* What *does* exist: riskmandate.ai as a vault-powered static site · the ten scenario documents · **four live vaults with read keys** · three fully worked graphs as parseable JSON. --- ## `/network/` — the seven-site map The split is the point of this site, so state it on a page rather than leaving it implicit. Full boundaries in `06__boundaries-and-house-style.md` §1. | Site | Boundary in one line | |---|---| | **riskmandate.ai** | Commercial. *How do I get my risks accepted, and what does it cost?* Cites this site | | **graphs.sgit.ai** | Owns the graph machinery. Node type formulas as a *mechanism* are theirs; the grounding ladder as a *risk formula* is ours | | **nhi.sgit.ai** | Owns agent identity. The `06/04/nhi-2.0/` series is theirs — but its risk-management brief is **risk's origin document** and should be cited here | | **pki.sgit.ai** | Owns attribution and signing. ⚠️ Currently carries **mandate** material that arguably belongs here — coordinate a split | | **sg-sentinel.sgit.ai** | Enforces. **We measure and evidence; we never sit in-line.** The corpus states this refusal explicitly | | **newsroom.sgit.ai** | Owns the evidence *supply* side. We own the *demand* side — accountability is what generates it | | **sgit.ai** | Owns vaults, publishing and the catalogue. Consume the topic-section pattern, don't re-argue it | --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/06__boundaries-and-house-style.md — source document, verbatim ============================================================================== # 06 — Boundaries, Redaction and House Style --- ## 1. The seven-site boundary map `risks.sgit.ai` is the eighth property in the estate and the second to be carved *out of* an existing site rather than built from a gap. Getting the boundaries right on day one is what stops eight sites becoming eight competing copies of the same argument. ### Genuinely risk's own (risks.sgit.ai) Everything in §1 concepts C1–C42, specifically: risk acceptance as underwriting; no-deny; the interval ladder; unaccepted-equals-critical; accepted-vs-acceptable; the grounding ladder; node type formulas and ontologies-of-ontologies **as applied to risk**; the register as a graph of graphs; fractal registers and relevance fade; technical vs business owner; Confirmed/Validated/Accepted; the underwriting graph and propagation; cascade and air gaps; not-knowing-is-a-fact; CIA blast-radius expansion; the plug question, plug profile and recoverability; altitude; appetite as a revealed band; the psychology of the physical act; the level ledger; register density; residuals; meta-risks; register health and gaming; three moves; decision-as-node; question-is-not-a-risk; do-not-internalise; the evidence economy's acceptor/certifier split; confidence bands; the two underwritings; observability as a risk dimension; five whys as a domain translator; RAMM; AOMM; the plug-pull maturity model; the harm taxonomy; the agentic incident taxonomy; and every worked example in §4. ### Belongs to **graphs.sgit.ai** (with risks.sgit.ai citing, not owning) The general graph machinery, independent of risk: directed edges with named inverses and query paths that prevent node explosion (`06/26/semantic-graph-and-query-paths/v0.33.35__arch-brief__...directed-edges...md`); path properties read as language and multi-graph creation paths (`.../v0.33.35__arch-brief__...path-properties...md`); fractal semantic graphs as an agentic operating layer (`07/12/architecture/v0.33.48__arch-brief__...fractal-semantic-graphs...md`); browser-local query engines — Oxigraph/Kuzu/DuckDB WASM (`07/28/regulation-graph-and-acceptability/v0.33.53__arch-brief__...customised-standard...md`); the graph canvas REPL and "never render the whole graph" (`08/02/vault-as-substrate/v0.33.55__arch-brief__...graph-canvas-repl...md`); the 08/09 graphing-text cluster (enrichment and shared anchors, Wikidata as the concept layer, evidence packs attach-never-mutate, index-is-not-a-source, refactoring meaning); and digital twins in their general form (`06/26/digital-twins-and-world-models/`, 4 docs). **The boundary rule:** node type formulas as a *mechanism* are graphs.sgit.ai's; the grounding ladder as a *risk formula* is risks.sgit.ai's, and should cite the mechanism rather than restate it. ### Belongs to **nhi.sgit.ai** The entire `06/04/nhi-2.0/` series (17 documents, ~50,000 words): agent identity as a startup thesis, cloud permissions per API, living off the land, multiple identities working together, permission granularity, PKI foundations, semantic knowledge graphs of identity, skills-come-with-identity, temporal permissions and time travel, web of trust and agent trust scores, plus the NHI commercial/moat/open-source briefs. Also the agent-mandate ontology's *identity* half (Principal, Agent, AgentTwin, CapabilityCertificate) and the 08/19 service-twin and agent-enrolment briefs. **The one exception:** `06/04/nhi-2.0/v0.32.3__strategy-brief__sg-send-nhi-2.0-risk-management-acceptance-underwriting-roi.md` is risk's origin document and should be *cited* by risks.sgit.ai as the first appearance of "the risk already exists", while living on nhi.sgit.ai. ### Belongs to **pki.sgit.ai** Attribution, non-repudiation, signing and key topology: `team/roles/appsec/reviews/02/21/v0.5.0__review__pki-architecture-security*.md`; `08/19/briefs/v0.33.60__cross-team-brief__pki-site-review-mandate-is-the-gap-registry-is-the-missing-half.md`; `08/19/briefs/v0.33.60__arch-brief__agent-enrolment-without-borrowed-authority-append-lane-is-the-narrow-door.md`; the vault-authorisation cluster (`08/06/vault-authorisation/`, 6 docs — statecharts, kernel reference monitor, plugins-are-capability-grants, ambient authority as the injection root cause). **Note the tension:** the 19 Aug PKI-site review says *"mandate is the gap, registry is the missing half"* — meaning pki.sgit.ai currently carries mandate material that arguably belongs with risk. Worth a coordinated split. ### Belongs to **sg-sentinel.sgit.ai** Anything that is **in-line enforcement**, which the risk corpus explicitly refuses. `05/24/sg-sentinel-batch2/v0.27.60__arch-brief__sg-sentinel-agent-governance.md` (reverse-proxy agent governance, controlling what agents do in dev and prod) is the clean case. The risk corpus's own stated boundary, from `07/23/posture-and-core-primitives/v0.33.50__strategy-brief__...never-in-line...md` and the honest-tension table in `07/24/.../v0.33.51__strategy-brief__...ability-to-stop...md`: *"The model rates the ability to stop but does not provide it; a customer who scores badly will ask us to supply the stop button, which is exactly the enforcement role the corpus refuses."* **risks.sgit.ai should state this boundary explicitly** — it measures and evidences; sg-sentinel enforces. ### Belongs to **newsroom.sgit.ai** The evidence-economy *supply side*: news-backed evidence vaults run as an editorial mini news organisation, news stories as Evidence on the grounding ladder, author micropayments as a consumption-event billing primitive, MyFeeds and Trust-as-a-Service, evidence packs as a service, and paying-the-fact-creator. Files: `07/05/evidence-economy/` (3 docs), `07/31/projects-budgets-and-evidence/v0.33.54__strategy-brief__...paying-the-fact-creator...md`, `05/17/v0.27.55__strategy-brief__myfeeds-*`, `05/17/v0.27.55__arch-brief__myfeeds-website-rebuild-three-primitives.md`, `05/17/v0.27.55__dev-brief__articles-as-vaults-publishing-workflow.md`. **The split:** the *demand* side — force of proof, the risk-acceptor/fact-certifier split, the two prices, and confidence bands driving evidence purchases — is risk's own, because it is generated by accountability. The *supply* side — how evidence is produced, certified, priced and paid for — is the newsroom's. ### Additional boundaries worth naming (not in the brief but present in the corpus) - **The EU AI Act / canonical-standard work** (`07/31/canonical-act-build/` 5 docs, `07/31/canonical-act-publish-and-product/` 5 docs, `07/28/regulation-graph-and-acceptability/` 4 docs, `07/31/the-act-as-a-measure/` 3 docs) is a substantial thread — ~40,000 words — that is *neither* risk nor graphs. It deserves either its own site (a "regulation graph" or "canonical act" property) or a clearly demarcated section on risks.sgit.ai. Risk's genuine claims within it are narrow and sharp: Article 9(5)'s undefined "acceptable", Article 14 as the plug obligation, Article 26(5)/(6) as the worked example anchor, and obligation-date ≠ liability-date. - **sgit.ai itself** owns the vault, forge, catalogue and publishing mechanics (`08/14/sgit-site-and-hub/`, 8 docs). risks.sgit.ai should consume the topic-section pattern described there rather than re-argue it. - **Wardley mapping** (`06/23/wardley-maps/`, `07/28/mvp-and-field-demo/v0.33.53__strategy-brief__...wardley-map-of-the-airgapped-register...md`) is a shared method, not risk's own. --- --- ## 2. Redaction watch-list **This corpus has the highest redaction load of any pack so far.** It names real vendors critically, contains a live contract draft, and carries investor figures. Run these checks before any bulk publication. ### 9.1 Named real companies assessed critically — highest risk - **`07/24/sovereignty-and-osmm/v0.33.51__research-brief__sg-send-osmm-assessment-001-[redacted]-level-1-survivability-inversion.md`** — names **two real vendors** [REDACTED · Tier-3 · see PUBLIC.md] (one a Ghent-based startup, described as *"roughly two years old with venture ownership"*), scores both at OSMM Level 1, and concludes the second presents *more* exposure on the axis it markets hardest. The document is scrupulous about its own limits (*"not publicly locatable as of this date"*, *"bounded above, not measured"*, *"re-run after direct enquiry"*), but publishing a critical comparative vendor assessment on a public research site is a legal and relationship exposure. **Do not publish without a legal read and a right-of-reply process.** The OSMM *model* brief in the same folder is clean. - **`07/12/positioning-and-market/v0.33.48__strategy-brief__sg-send-[redacted]-risk-management-comparison-collaboration-integration-points-mature-governance.md`** and `.../v0.33.48__strategy-brief__...why-the-opportunity-exists-grc-airgapped-from-reality-competitor-map-data-side-threat.md` — competitor maps naming **two large vendors** [REDACTED · Tier-3 · see PUBLIC.md] with dismissive characterisations of their products. Commercial positioning, not research. **Internal-only.** - **`07/27/outbound-agentic-risk/v0.33.52__research-brief__...agent-escaped-evaluation-sandbox...md`** — names **OpenAI** and **HuggingFace** in an incident analysis. Sourced and cautious, but names two real organisations in a security-failure narrative. **Needs framing and source verification before publication.** - **`07/28/agentic-risk-research/v0.33.53__research-brief__...has-it-happened-before...md`** — names **Anthropic** (GTG-1002 disclosure), **Check Point**, and **nine Mexican government bodies including the federal tax authority, the civil registry and the electoral institute**. All from published sources with URLs, but naming foreign government agencies as breach victims warrants care. **Needs framing.** - Other named companies across the risk corpus (counts from `briefs/06`, `07`, `08`): OpenRouter 332, LinkedIn 201, WhatsApp 104, Calendly 66, Salesforce 28, Nokia 22, Replit 20, OpenAI 20, [REDACTED · Tier-3 · see PUBLIC.md] (four Tier-3 vendor names and counts removed), Anthropic 17, Perplexity 14, **Klue 12**, **Vercel 10**, RIMS 7, Check Point 2. **Klue** and **Vercel** appear specifically in breach/failure contexts (`06/28/use-cases-and-risk-acceptance/v0.33.36__research-brief__...klue-breach...md`; the referenced-but-missing v0.33.46 "Vercel allow-all" brief). **Replit** appears as a database-deletion incident example. Each needs an individual publication decision. - **`06/19/users-product-and-case-study/v0.33.28__research-brief__sg-send-whatsapp-case-study-three-scenarios-blast-radius-qr-full-access-ban-incidents.md`** — a named-platform blast-radius case study. Needs framing. ### 9.2 Codenames that may map to real entities - **"Odysseus"** (42 mentions across `06/20/odysseus-mandate-analysis/`, 3 docs) reads as a codename for a real agent product or a real engagement. **Verify what it refers to before publishing anything from that folder.** The harm taxonomy inside it is otherwise excellent and generic. ### 9.3 Pricing, commercial terms, and investor material - **`06/02/v0.31.9__strategy-brief__sg-send-investment-strategy-why-now-alchemist-guidance.md:86`** — illustrative revenue, valuation and exit figures [REDACTED · Tier-3 · see PUBLIC.md]. Explicitly framed as scenarios, not projections. **Internal-only / investor-only.** - **`07/23/investor-response/v0.33.50__strategy-brief__sg-send-response-to-investor-analysis-...md`** — a direct response to an investor's analysis. **Internal-only**, though its "we are the meta risk" line is quotable if extracted and re-framed. - **`07/27/first-product-to-market/v0.33.52__contract-draft__sg-send-voice-note-transcription-tool-partnership-[redacted].md`** — an actual **contract draft** with commercial terms [REDACTED · Tier-3 · see PUBLIC.md]. **Internal-only, unambiguously.** - Competitor pricing quoted verbatim in the 07/23–07/27 briefs: `$29/month`, `$50/month`, `$500/month`, `$100 per named signer per month`, `$125 monthly`. These are third-party price points that will go stale and read as competitive intelligence. **Strip or date-stamp.** - `07/02/product-roadmap/riskmandate-product-roadmap.{md,svg,pdf}` — internal delivery sequencing with build-state claims. **Needs framing** if published at all; its "already shipped" section is the useful part for a research site's honesty statement. - `07/17/commercial-model/`, `06/30/partners-market-and-library/`, `07/23/freelance-network-and-tools/`, `07/31/markets-and-field-demo/` — commercial. **Internal-only or heavy framing.** ### 9.4 Named individuals - **Dinis Cruz** is named as project owner/data controller in `team/roles/appsec/reviews/02/21/v0.5.0__grc-risk__auth-model-transition.md` and throughout the `team/humans/dinis_cruz/` path structure. Presumably fine (it is the founder's own corpus), but note that the **path itself** carries a personal name — if documents are republished with their paths as citations, the name travels with them. Decide deliberately. - **Art Manion, Jay Jacobs, Michael Roytman** are named in `06/28/ontology-and-definitions/v0.33.36__arch-brief__...manion-jacobs.md`. The treatment is entirely respectful and the document is explicit that it paraphrases (*"Their definitions are paraphrased; see Sources"*), and it cites a LinkedIn post as one source. **Publishable, but confirm the paraphrase is fair and consider notifying them** — this is exactly the kind of bridge document that benefits from a right of reply, and the corpus's own stance (*"Offered to be built on and challenged"*) supports doing so. - Role titles used throughout (IT Director, Head of GRC, CIO, CPO, CFO, CEO, ML platform lead, head of lending operations, DPO) are **generic and invented** — no redaction needed. The Article 26(5) example explicitly marks every invented element. ### 9.5 Live secrets and operational detail (pre-history) - **`team/roles/grc/reviews/02/19/v0.4.12__risk-acceptance__deliberate-token-exposure.md`** — documents a **live `linkedin-user` access token**, its status (Active, not rotated), its quota (30 of 50 uses consumed, **20 remaining**), and the branch name where it remains readable in git history. Even though the token value is redacted in the document, the metadata is operational. **Internal-only, absolutely.** Same for `v0.4.16__debrief__INC-004-complete.md` and the `library/sgraph-send/incidents/INC-002…`/`INC-004…` folders. - **`team/roles/appsec/reviews/02/21/v0.5.0__grc-risk__auth-model-transition.md`** — enumerates **21 unremediated security findings** (KD-1…KD-8, CT-1…CT-8, SP-1…SP-5) deprioritised on the basis of the current operating context, and states plainly that a change in that context reactivates all of them. **Internal-only.** (Ironically, it is also one of the best real illustrations of the "accepted is not acceptable" thesis — if it is ever to be used publicly, it must be abstracted beyond recognition.) - `team/humans/dinis_cruz/briefs/02/27/v0.7.1__grc__risk-register-sg-send-skill-workflow.md` — names the live delivery chain (n8n, AWS SES, WorkMail, Gmail) and its interception points. **Internal-only.** ### 9.6 Documents already carrying their own disclaimers (good precedent to preserve) Many of the best risk documents already model the right posture and their disclaimers should be carried across verbatim to risks.sgit.ai rather than stripped: *"Legal points are factual and not legal advice"*; *"The organisation is invented; every invented element is marked"*; *"Generic to the secure-browser and browser-isolation category. No vendor is named"*; *"The scenario is a product deployment example, shortened and illustrative, not any customer's register"*; *"Offered to be built on and challenged"*; and the CC BY 4.0 release line at the foot of nearly every brief — which is what makes public republication straightforward in the first place. --- ## 3. House style, inherited Full treatment in the graphs pack `06__house-style-and-conventions.md`. Essentials, with the risk-specific emphasis: - **`/llms.txt` is the whole surface**, and here more than anywhere — the commissioned audience is agents. Each entry carries the concept's single most important fact. `/llms-full.txt` is mandatory, not optional - **`/documents/` with raw markdown as source of truth**, rendered pages as presentation - **`/admin/comms.html`** with numbered asks and tasks in explicit states. **Seed with:** N1 the plug correction · N2 RAMM base levels · N3 legal read on the OSMM vendor assessment · N4 the pki.sgit.ai mandate split · N5 verify what "Odysseus" refers to - **`/admin/versions.html`** · **`/about/participant.html`** · a build order published unresolved with open questions and honest tensions - **Voice:** short declarative sentences making checkable claims; publish the argument before the implementation and say which is which; name what you got wrong; **no marketing adjectives** — this is the research site, and the contrast with riskmandate.ai is the product - **Every section serves three readers:** documentation · live demonstration (the four vaults) · **agent guidance**. Here the third is the commission **Vault rules:** publish read keys, never write keys · escrow the write key *before* publishing, or the vault is frozen · audit before publish and adopt the `PUBLIC.md` convention · **no metered capability behind a published read key** — the Risk Graph Explorer's `permissions: {}` is the model. **Licence:** CC BY 4.0 per the 21 August decision. `docs.diniscruz.ai` prior art is **CC0** at source — state the source licence per page. --- ## 4. Two demonstrations to build in 1. **Run the site's own risk register in the open.** The corpus argues that a register is a graph, that unaccepted equals critical, and that the register maintains itself because accountability manufactures demand for evidence. A research site that publishes its own register — its open questions as unaccepted risks, with intervals — demonstrates all three at zero cost. 2. **Ship the definitions endpoint.** 42 concepts as JSON: name, one-line definition, canonical source, maturity, related concepts. It is the single highest-value artefact for the commissioned audience, nothing else in the estate has one, and it is a day's work from `01__concepts-index.md`. --- ## 5. Provenance for moved and republished pages Two classes of source, two rules. **From riskmandate.ai** — the page moved rather than being copied, so record the move: ```yaml moved_from: https://riskmandate.ai/acceptable.html moved_on: 2026-08-22 leave_behind: stub published at source, linking here curation: edited # commercial framing removed ``` **From `docs.diniscruz.ai`** — the full provenance contract from the newsroom pack applies: `first_published` is the **original** date, original URL, original co-authors, honest curation label, `source_licence: CC0-1.0`, and `rel="canonical"` for verbatim republication. **Never redirect the source.** **From the `__Send` repo** — never published, so the version tag is the address: ```yaml source_repo: https://github.com/the-cyber-boardroom/SGraph-AI__App__Send source_repo_path: team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__... source_version: v0.33.36 first_written: 2026-06-28 source_licence: CC BY 4.0 ``` --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/07__gaps-and-open-questions.md — source document, verbatim ============================================================================== # 07 — Gaps, Open Questions and Honest Tensions --- ## 1. Must be written fresh | # | Page | Why | |---|---|---| | **G1** | **The front page** | Nothing in the corpus opens this argument for a cold reader. The pieces exist — underwriting, no-deny, unaccepted-is-critical — but nobody has assembled them into 300 words | | **G2** | **`/agents/` and the definitions endpoint** | The commissioned audience has no surface today. 42 concepts as JSON is the single highest-value artefact this site can ship | | **G3** | **`/shipped/`** | Nothing is implemented. Without this page the site over-claims and breaks the convention the siblings are built on | | **G4** | **`/concepts/` as an addressable index** | The concepts exist across ~185 documents with no index, no anchors and no stable URLs. `01__concepts-index.md` is the raw material | | **G5** | **RAMM base levels** | Levels 1, 2, 4 and 5 are named but only Level 3 has a stated predicate. The Agentic `+` variants are better defined than the base model they extend | | **G6** | **The plug reconciliation** | The corpus records a *"no plug"* correction that `riskmandate.ai/plug.html` does not reflect. One of the two is wrong | --- ## 2. Open questions worth publishing unresolved Following the pki.sgit.ai convention of numbering open questions in public. A model this opinionated earns credibility by naming what it has not settled. | # | Question | Where the corpus gets closest | |---|---|---| | **Q1** | What is the **formula language**? Node Type Formulas are the mechanism the whole ontology rests on, and the notation is undefined | C7's canonical brief names this as its own open question | | **Q2** | Who sets **acceptable**, and what stops it being set to whatever is convenient? | C5 defines it as *"the moment the business is happy to stop funding remediation"* — it does not say who decides or what constrains them | | **Q3** | What happens when the **named acceptor refuses to sign**? | The no-deny mechanic removes denial of the *risk*; it does not address refusal of the *act* | | **Q4** | Does **unaccepted = critical** survive contact with a large estate? | On a register of thousands, everything unaccepted being critical may make critical meaningless. C28's register-density argument circles this without resolving it | | **Q5** | How is the **interval enforced**? Expiry-as-cost is asserted; the mechanism is not specified | C3, C2 | | **Q6** | Is **recoverability** measurable, or only classifiable? | C23 splits reversible from irreversible; nothing grades the middle | | **Q7** | What is the **stopping rule** for the grounding ladder in practice? | C6 states the test — *"the last node where going deeper would neither improve observability nor change a decision"* — but no worked example applies it to a hard case | | **Q8** | How do you stop a register being **gamed** once acceptance carries personal liability? | C31 argues accountability manufactures demand for evidence; the opposite incentive — avoid ever being the named acceptor — is acknowledged but not answered | --- ## 3. Honest tensions Following pki.sgit.ai's `/roadmap/#tensions`. 1. **The model rates the ability to stop but does not provide it.** The corpus states this refusal itself: *"a customer who scores badly will ask us to supply the stop button, which is exactly the enforcement role the corpus refuses."* That boundary is principled — and commercially uncomfortable. 2. **No-deny is the strongest idea and the hardest sell.** Removing the deny button removes the thing most executives use a register for. The corpus is honest that this is a forcing function, not a convenience. 3. **Personal liability is the mechanism and the risk.** Making acceptance a personal act is what generates demand for evidence. It also gives every rational actor a reason to avoid being named. 4. **Nothing is built.** ~496,000 words of design against zero lines of implementing code. That is fine for a research site *if stated*; it is fatal if implied otherwise. 5. **The corpus names real vendors critically.** The OSMM assessment scores two named real vendors [REDACTED · Tier-3 · see PUBLIC.md] at Level 1 and concludes one presents more exposure on the axis it markets hardest. Rigorous, sourced, and a legal exposure. 6. **Two sites, one voice.** riskmandate.ai and risks.sgit.ai share an author and a thesis. If the research site reads like marketing, the split has failed; if the commercial site reads like research, it will not sell. 7. **The EU AI Act thread is neither risk nor graphs.** ~40,000 words across four brief clusters. Risk's genuine claims within it are narrow and sharp — Article 9(5)'s undefined "acceptable", Article 14 as the plug obligation, Article 26(5)/(6) as the worked example. **The rest may deserve its own property.** --- ## 4. Loose ends inside the acceptance thread itself From the corpus's own record, worth carrying onto the site rather than quietly resolving: - **The 4h-for-everyone problem.** In the 2FA example the governance air gap propagates GRC → CIO → CEO → Board with *each accepting at 4h because that is the only option open to them*. Either the ladder needs a per-altitude variant, or that uniformity is a finding about the model. - **Compound pre-approval** is proposed and never worked through. - **Override** is named in the workflow brief without a stated authority model. - **The level ledger** (C27 — accept first, then adjust the level) sits awkwardly with the no-deny mechanic: if you can adjust the level after accepting, denial re-enters through the back door. --- ## 5. Fixes worth doing at source 1. **Reconcile the plug correction** across the corpus and `riskmandate.ai/plug.html`. 2. **Specify RAMM levels 1, 2, 4 and 5** to the standard already set by Level 3 and the Agentic variants. 3. **Legal read on the OSMM vendor assessment** before it goes anywhere public, with a right-of-reply process. 4. **Verify what "Odysseus" refers to** — 42 mentions across three documents, reads as a codename for a real product or engagement. 5. **Decide the EU AI Act thread's home** before it accretes further. 6. **Coordinate the mandate split with pki.sgit.ai**, whose own 19 August site review says *"mandate is the gap, registry is the missing half."* --- This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/08__source-manifest.csv — source document, verbatim ============================================================================== tier,concept,repo_path_or_url,title,words,proposed_page,publishability,why_it_matters 0,C9 register,team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__sg-send-risk-register-graph-of-graphs-facts-only-no-deny-cascade-cia-blast-radius.md,The Risk Register as a Graph of Graphs,3187,/register/,clean,"The founding register document. Facts-only, no-deny, cascade, air gaps, CIA blast radius, told as a five-movement narrative." 0,C6 grounding ladder,team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-grounding-ladder-fact-evidence-measure-vulnerability-risk-definitions.md,The Grounding Ladder,2325,/ladder/,clean,THE most rigorous document in the corpus and what agents most need. Reality-Twin-Measure-Evidence-Fact-Vulnerability-Risk as one formula. 0,C7 node type formulas,team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-node-type-formulas-classification-as-testable-path-pattern-not-judgment.md,Node Type Formulas,1511,/ladder/formulas/,clean,"Classification as a computed path query. Bias relocated from the classifier into the formula, where it is visible and arguable." 0,C8 ontologies of ontologies,team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-ontologies-of-ontologies-three-layers-formulas-bridges-multiple-definitions.md,Ontologies of Ontologies,1275,/ladder/bridges/,clean,"Three layers: shared factual graph, per-party formulas, declared bridges. Merging erases the disagreement." 0,C8 worked bridge,team/humans/dinis_cruz/briefs/06/28/ontology-and-definitions/v0.33.36__arch-brief__sg-send-bridge-vulnerability-formula-system-fault-security-failure-conditions-manion-jacobs.md,Bridging a Security-Centric Vulnerability Formula,1713,/ladder/bridges/,clean - names 3 real researchers favourably,"The first worked external bridge. Their Security Failure is structurally the promotion edge, differing only in terminus." 0,C2 no-deny,team/humans/dinis_cruz/briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__dev-brief__sg-send-risk-acceptance-service-demo-no-deny-time-boxed-acceptance-expiry-as-cost-graph-evidence.md,The Risk Acceptance Service,1831,/acceptance/no-deny/,clean,The no-deny button and the expiry-as-cost table. The most immediately graspable idea in the corpus. 0,C15 underwriting graph,team/humans/dinis_cruz/briefs/06/23/risk-mandate-product-and-workflow/v0.33.33__arch-brief__sg-send-risk-acceptance-workflow-multi-stakeholder-graph-underwriting-propagation-override-pre-approval.md,The Risk Acceptance Workflow,2003,/acceptance/workflow/,clean,"Two dimensions, underwriting graph, altitude, override, compound pre-approval. Override and pre-approval are loose ends." 0,C3 interval ladder,team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__sg-send-acceptance-interval-ladder-hour-to-six-months-default-one-month-interval-implies-response.md,The Acceptance Interval Ladder,2449,/acceptance/the-ladder/,clean,THE SINGLE CLEANEST ARTEFACT IN THE CORPUS. The interval IS the decision. Publish as a table. 0,C10 fractal registers,team/humans/dinis_cruz/briefs/07/17/registers-mandate-and-intervals/v0.33.49__arch-brief__sg-send-fractal-risk-registers-one-per-accepting-role-domain-language-relevance-fade.md,Fractal Risk Registers,2674,/register/,clean,One register per accepting entity; relevance fade as an education mechanism. 0,C5 accepted != acceptable,team/humans/dinis_cruz/briefs/07/28/regulation-graph-and-acceptability/v0.33.53__strategy-brief__sg-send-accepted-is-not-acceptable-orthogonal-axes-appetite-renamed-article-9-mandates-judgement-without-defining-it.md,Accepted Is Not Acceptable,3291,/acceptable/,clean,"Two orthogonal axes, four quadrants, the Article 9(5) definitional gap. Moves off riskmandate.ai." 0,C25 appetite,team/humans/dinis_cruz/briefs/06/30/risk-acceptance-and-appetite/v0.33.38__strategy-brief__sg-send-risk-appetite-band-fractal-two-signals-goldilocks-zone-revealed-dataset.md,Risk Appetite: The Band a Company Reveals,1970,/acceptable/,clean,"Appetite as a fractal, revealed band. Two signals. The Goldilocks zone." 0,C26 psychology,team/humans/dinis_cruz/briefs/06/30/risk-acceptance-and-appetite/v0.33.38__strategy-brief__sg-send-risk-acceptance-psychology-accountability-liability-physical-act-revealed-appetite.md,The Psychology of Risk Acceptance,1666,/practice/,clean,Why the physical act matters. Accountability becomes liability; liability becomes the forcing function. 0,C20-C23 the plug,team/humans/dinis_cruz/briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-who-can-pull-the-plug-ability-to-stop-an-ai-system-fractal-maturity-model-detection-authority-blast-radius-reversibility-intersect-in-time.md,Who Can Pull The Plug,3940,/plug/,clean,"Two symmetric risks, fractal maturity model, four-way time intersection, EU AI Act Art 14. Detection floor 12-18h." 0,RAMM,team/humans/dinis_cruz/briefs/07/02/authorization-and-maturity-model/v0.33.40__arch-brief__sg-send-risk-acceptance-maturity-model-ramm-graph-native-levels-agentic-crosswalk.md,RAMM,2265,/ramm/,clean - FIX BASE LEVELS,Five levels as graph predicates plus Agentic RAMM. Only Level 3 has a stated predicate. 0,worked example,team/humans/dinis_cruz/briefs/08/02/vault-as-substrate/v0.33.55__arch-brief__sg-send-end-to-end-worked-example-article-26-5-creditworthiness-agent-fact-to-board.md,"End To End: One Provision, One Agent, One Graph",4272,/examples/article-26-5/,clean - org invented and marked,"8 facts, 5 risks, 4 stakeholders, 9 questions (5 unanswered). The 30-days-vs-6-months arithmetic finding." 0,C1 underwriting,team/humans/dinis_cruz/briefs/06/18/agentic-permissions/v0.33.40__arch-brief__sg-send-risk-acceptance-underwriting-flows-upward-cross-domain-the-risk-already-exists.md,Risk Acceptance as Underwriting,2265,/acceptance/underwriting/,clean,THE FOUNDING INVERSION. The insurance analogy carries it with no GRC background. 0,worked example,team/humans/dinis_cruz/briefs/07/12/worked-business-case/v0.33.48__briefing__sg-send-browser-isolation-agentic-automation-business-case-facts-vulnerabilities-risks-five-levels-graph.md,Browser Isolation Business Case,4601,/examples/browser-isolation/,clean,"59 nodes 75 edges, drop-in renderable. Includes 3 risks OF THE MITIGATION. 5 altitudes." 0,worked example,team/humans/dinis_cruz/briefs/06/26/semantic-graph-and-query-paths/v0.33.35__data__sg-send-2fa-mappings.json,2FA instance graph (DATA),1253,/examples/2fa/,clean - CC BY 4.0 inline,51 nodes 53 edges. THE ONLY DOWNLOADABLE GRAPH. Declares its own principles inside the file. 0,scenarios,team/humans/dinis_cruz/briefs/07/02/risk-acceptance-and-scenarios/v0.33.40__strategy-brief__sg-send-how-long-would-you-accept-risk-scenario-slides-gamified-survey-vault-capture.md,The Ten Scenarios,1621,/examples/scenarios/,clean,"Hook-reveal-punchline, punchline always 'how long?'. The shipped MVP content." 1,C19 blast radius,team/humans/dinis_cruz/briefs/07/05/aws-configuration-risk-engine/v0.33.44__arch-brief__sg-send-aws-iam-config-risk-ontology-taxonomy-nodes-edges-formulas-bridges.md,AWS IAM Config Risk Ontology,2968,/blast-radius/,clean,"6 layers, ~31 node types, 20 edge types (40 readings), 7 Node Type Formulas. AuthorizationClosure as the agentic union." 1,C39 observability,team/humans/dinis_cruz/briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-the-plug-is-a-sledgehammer-blast-radius-and-side-effects-of-pulling-it.md,The Plug Is A Sledgehammer,1384,/plug/,clean,The blast radius and side effects of pulling it - the symmetric risk. 1,C23 recoverability,team/humans/dinis_cruz/briefs/07/24/who-can-pull-the-plug/v0.33.51__strategy-brief__sg-send-what-money-cannot-buy-back-recoverability-the-hard-limit.md,What Money Cannot Buy Back,1714,/plug/,clean,Recoverability as the hard limit. The dimension that separates catastrophic-but-reversible from smaller-and-permanent. 1,C35 do not internalise,team/humans/dinis_cruz/briefs/07/31/keeping-the-register-healthy/v0.33.54__strategy-brief__sg-send-do-not-internalise-the-risk-accountability-without-authority-relocated-not-augmented-mental-load.md,Do Not Internalise The Risk,3338,/practice/,clean,63-76% of security leaders experiencing or witnessing burnout in a single year. The register is the boundary. 1,C36 evidence economy,team/humans/dinis_cruz/briefs/07/05/evidence-economy/v0.33.44__strategy-brief__sg-send-evidence-economy-force-of-proof-fact-certification-two-prices-evidence-based-revenue-models.md,The Force of Proof,1980,/practice/,clean - DEMAND side only,The risk-acceptor / fact-certifier split. Supply side belongs to newsroom.sgit.ai. 1,C41 twins,team/humans/dinis_cruz/briefs/06/26/digital-twins-and-world-models/v0.33.35__arch-brief__sg-send-digital-twins-twin-of-anything-dimensions-discipline-of-reality-simulation-testing.md,Digital Twins of Anything,1593,/ladder/,CITE graphs.sgit.ai,Twins are where the graph stops modelling and continues into a real system. General form belongs to graphs. 1,origin doc,team/humans/dinis_cruz/briefs/06/04/nhi-2.0/v0.32.3__strategy-brief__sg-send-nhi-2.0-risk-management-acceptance-underwriting-roi.md,"NHI 2.0: Risk Management, Acceptance, Underwriting, ROI",3010,/origins/,CITE nhi.sgit.ai,RISK'S ORIGIN DOCUMENT - first appearance of 'the risk already exists'. Lives on nhi.sgit.ai; cite from here. 1,live vault,https://sgit.ai/demos/vaults/risk-graph-explorer/,Risk Graph Explorer (LIVE),0,/examples/vaults/,published,"7 views, 18 facts / 37 risks / 14 provisions in the Exposed preset. Ghosted edges = unanswered. permissions: {}" 1,live vault,https://sgit.ai/demos/vaults/agentic-browser-isolation/,Agentic Browser Isolation (LIVE),0,/examples/vaults/,published,"17 entry points, 5 altitudes, acceptance-gated escalation with NO DENY BUTTON. C2 and C4 on real data." 1,live vault,https://sgit.ai/demos/vaults/risk-mandate/,Risk Mandate vault (LIVE),0,/examples/vaults/,published,"124 files, 98 commits, 8 app entries. The most-committed published vault - the method applied to its own build." 1,live vault,https://sgit.ai/demos/vaults/regulation-graph/,Regulation Graph (LIVE),0,/examples/vaults/,published,"1,523 nodes / 1,944 edges. Supplies Art 9(5), 14, 26(5)/(6) - the provisions the concepts hang on." 1,prior art,https://docs.diniscruz.ai/2025/07/06/finding-the-good-enough-threshold-optimizing-risk-creativity-and-product-decisions.html,Finding the Good Enough Threshold,4924,/acceptable/,PUBLISHED - CC0 at source,The appetite argument before it had the vocabulary. 15 risk-acceptance mentions - highest density on the site. 1,prior art,https://docs.diniscruz.ai/2025/04/02/maturity-modes-vs-traditional-standards-in-application-security.html,Maturity Models vs Traditional Standards,2701,/ramm/,PUBLISHED - CC0 at source,"The ancestor of RAMM, a year early." 2,EU AI Act thread,team/humans/dinis_cruz/briefs/07/28/regulation-graph-and-acceptability/,Regulation graph cluster (4 docs),13895,/acceptable/ (narrow claims only),needs a home decision,"~40,000 words across 4 clusters. Neither risk nor graphs. Risk's claims are narrow: Art 9(5), 14, 26(5)/(6)." 3,vendor assessment,[REDACTED - Tier-3 - see PUBLIC.md],OSMM Assessment 001,2811,HOLD - LEGAL READ,legal read + right of reply,"Names two real vendors and scores both Level 1. Rigorous and sourced - and a legal exposure. Names and path redacted for publication." 3,competitor map,[REDACTED - Tier-3 - see PUBLIC.md],Competitor comparison,2090,DO-NOT-PUBLISH,INTERNAL ONLY,"Competitor map naming two large vendors. Commercial positioning, not research. Names and path redacted for publication." 3,investor,team/humans/dinis_cruz/briefs/06/02/v0.31.9__strategy-brief__sg-send-investment-strategy-why-now-alchemist-guidance.md,Investment strategy,2821,DO-NOT-PUBLISH,INTERNAL ONLY,"Illustrative revenue, valuation and exit figures. Explicitly scenarios, not projections. Figures redacted for publication - see PUBLIC.md." 3,contract,[REDACTED - Tier-3 - see PUBLIC.md],Partnership contract draft,2452,DO-NOT-PUBLISH,INTERNAL ONLY,An actual contract draft with commercial terms. ============================================================================== == briefs/PUBLIC.md — source document, verbatim ============================================================================== # PUBLIC.md — what was redacted from this brief pack before publication **Applies to:** the eleven source documents published under `/briefs/` on risks.sgit.ai **Redacted:** 23 August 2026, at site v0.1.0 **Convention:** the same one the Regulation Graph vault adopted after an audit — *publish the artefact, and publish what was taken out of it*. A clean document with an unexplained gap is worse than a redacted one with a receipt. --- ## Why anything was redacted at all The brief pack was written as a working document for the agent commissioned to build this site. It names four sources as **Tier-3 — do not publish, quote or paraphrase** — and, being a working document, it names them *by name* so the builder knows what to skip. That is correct for a working document and wrong for a published one: republishing the pack verbatim would publish exactly the four things the pack says not to publish. So the pack is published in full, with the identifying detail of those four rows removed and each removal recorded here. **Nothing else was changed** — no argument was softened, no number adjusted, no finding dropped. Every redaction is marked in place with `[REDACTED · Tier-3 · see PUBLIC.md]` or `[redacted]` inside a file path. The rule is also enforced rather than remembered: `admin/build/validate.js` pattern-matches the distinctive strings of all four Tier-3 rows across **every file in the tree**, with no exemption for `briefs/`, and fails the build if one reappears. A future edit cannot quietly undo this. --- ## The four Tier-3 rows, and what was taken out | Row | What it is | What was redacted | |---|---|---| | **Vendor assessment** (`tier 3`, manifest row 35) | A comparative maturity assessment scoring two named real companies at Level 1, concluding one presents more exposure on the axis it markets hardest. Rigorous, sourced, scrupulous about its own limits — and a legal and relationship exposure | **Both company names**, and the source file path that carries them. The row itself, its word count, its tier and its `HOLD - LEGAL READ` disposition are published unchanged | | **Competitor map** (`tier 3`, manifest row 36) | Competitor maps naming two large risk-management vendors, with dismissive characterisations of their products | **Both company names**, the two disparaging quotes, and the file path that carries one of the names | | **Investment strategy** (`tier 3`, manifest row 37) | Illustrative revenue, valuation and exit figures, explicitly framed at source as scenarios rather than projections | **The figures.** The existence of the document, its word count and its internal-only disposition are published unchanged | | **Partnership contract draft** (`tier 3`, manifest row 38) | An actual contract draft with commercial terms | **The commercial terms**, in the prose and in the file path that spells them out | ## Where each redaction appears | File | Redactions | What | |---|---:|---| | `08__source-manifest.csv` | 4 | The four Tier-3 rows: company names, source paths and commercial figures | | `06__boundaries-and-house-style.md` | 6 | The redaction watch-list itself — company names, two quotes, four entries in the mention-count list, the investor figures, and the contract terms | | `07__gaps-and-open-questions.md` | 1 | Company names in honest tension #5 | | `04__riskmandate-refactor.md` | 1 | Company names and the disparaging quote in "what must not happen" | | `README.md` | 1 | Company names in the Tier-3 warning | | `LICENSE.md` | 1 | Company names in the licence scope note | **Total: 14 redactions across 6 of the 11 documents.** Five documents — `00__BRIEF.md`, `01__concepts-index.md`, `02__risk-acceptance.md`, `03__worked-examples-and-vaults.md` and `05__site-architecture.md` — are published byte-identical to the pack as received. --- ## What is *not* redacted, and why - **The fact that Tier-3 material exists**, its word counts, its tiers and its dispositions. A manifest naming a do-not-publish row is the mechanism working, and hiding the row would hide the mechanism. - **Every other named organisation in the pack.** AWS, MITRE, the EU institutions, and the organisations named in the redaction watch-list's *other* categories are not Tier-3 and are not redacted — the pack's own reasoning for treating them differently is published intact. - **The redaction watch-list's reasoning.** Section 2 of `06__boundaries-and-house-style.md` survives in full apart from the names: the analysis of *why* certain material needs a legal read, framing or a right of reply is the most useful part of that document and is published as written. ## Standing offer If any organisation named in the un-redacted corpus believes a characterisation on this site is unfair, that is [ask N3 on the comms board](https://risks.sgit.ai/admin/comms.html#n3) — a legal read and a right-of-reply process is a precondition of publishing any of that material, and the offer stands whether or not it is ever published. --- This file is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). ============================================================================== == briefs/LICENSE.md — source document, verbatim ============================================================================== # Licence ## This pack Everything in this brief pack — all eight numbered markdown files, `08__source-manifest.csv`, `sources__docs-diniscruz-ai-risk.json`, this file and `README.md` — is released under the **Creative Commons Attribution 4.0 International licence (CC BY 4.0)**. Copyright (c) 2026 Dinis Cruz Licensed under CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/ Attribution: **Dinis Cruz**, with AI co-authorship (Claude, Anthropic). Where a source document names model co-authors, carry those names forward. CC BY is irrevocable. That is deliberate: the point is that these documents remain readable, quotable and re-mixable by the author, by other people, and by agents, permanently and without asking. ## The site this pack commissions **The entire content of `risks.sgit.ai`** — every page, every file under `/documents/`, `/llms.txt`, `/llms-full.txt`, and the admin surfaces — is to be published under **CC BY 4.0**, consistent with the rest of the `*.sgit.ai` network. Put the licence in `/llms.txt`, in the page footer, and as a line at the foot of every raw markdown document: This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0). Use `licence-audit.py` (shipped in the `graphs.sgit.ai` pack, file `licence-audit.py`) in `--check` mode as a CI gate so the stamp cannot silently drift. ## What this licence does *not* cover Three categories carry different regimes. Do not assume CC BY where it does not apply. | Material | Regime | What the site must do | |---|---|---| | **The 8 prior-art articles on `docs.diniscruz.ai`** (Feb–Jul 2025, 59,131 words) | **CC0 1.0** as published on that site | CC0 is *more* permissive than CC BY, so republishing under CC BY is legally fine — but attribute anyway, and keep `rel="canonical"` pointing at the original URL plus the recorded `first_published` date. See `sources__docs-diniscruz-ai-risk.json`. | | **Source PDFs and LinkedIn posts** referenced in that JSON | As originally published | Link, do not mirror silently. Record `source_pdf` and `source_linkedin` in front-matter. | | **Vault contents** at `sgit.ai/demos/vaults/` | Per-vault; read keys are publishable, **write keys never** | Before linking a vault from `risks.sgit.ai`, confirm the write key is escrowed. Publishing a read key for a vault whose write key is lost freezes it permanently. Each vault should carry a `PUBLIC.md`. | | **Tier-3 rows in the manifest** (4 rows) | Internal — commercial terms, competitor naming, investment scenarios | **Do not publish, do not quote, do not paraphrase.** They are listed so you know they exist and know to skip them. | ## Third-party names The corpus names real organisations (two large risk-management vendors [REDACTED · Tier-3 · see PUBLIC.md], AWS, MITRE), real frameworks (EU AI Act Article 26(5), MITRE ATT&CK T1110.004) and real people. Naming a framework or citing a technique is fine. Reproducing a competitor map, or attributing a position to a named company, is not — that material is Tier-3 for exactly this reason. See `06__boundaries-and-house-style.md` § redaction watch-list. --- This file is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).