Origins: February to August 2026
This model did not arrive whole. It starts as orthodox GRC — likelihood, impact, mitigation, “residual risk: acceptable” — and inverts itself in June. Publishing the trajectory matters, because the inversion is only convincing if you can see the position it was arrived at from.
- 17 February 2026 · the pre-history A vulnerability classification framework establishes a P0–P10 scale and a Risk Decision Matrix whose five questions include “what is the risk of the fix?” — the earliest instance of what later becomes “everything has risks, including the good ones”. Entirely orthodox, and the seed of one of the least orthodox conclusions.
- 19 February 2026 · textbook GRC A risk acceptance document with R001/R002 rows carrying Likelihood, Impact, Mitigation and the line “Residual risk: Acceptable”. The role definition of the time states the classical position outright: every risk must be “either mitigated or formally accepted with documented rationale”. Note the either/or. The June work abolishes it.
-
21 April 2026 · the first structural gesture
A dev brief opens with a diagnosis that still holds: “Risk acceptance in organisations is broken. A decision gets made in a meeting. Someone writes it up (maybe). The reasoning is lost. The approval chain is informal. Six months later, nobody can explain why a particular risk was accepted, who approved it, what evidence was considered.” It proposes a decision vault with
decision/,evidence/and anapprovals/approval-tree.json— the shape of the answer, before the inversion that makes it necessary. - 4 June 2026 · the risk already exists The turn. “Risk acceptance because the risk already exists”, and time-boxed sign-off as priority and mandate, appear together for the first time — inside a strategy brief about agent identity rather than about risk. C1 is born in someone else's document, which is why that document lives on nhi.sgit.ai and is cited from here.
- 18 June 2026 · underwriting The pillar document. “you are not predicting the risk of something happening, you are asking owners to underwrite it, insurance-style… the risk already exists the moment the permission is provisioned, so the only variable is how long you accept it.” The accountability mechanic arrives with it: the moment someone clicks is the moment they become accountable. →
- 23 June 2026 · no deny, and the interval as cost “the most important thing is that there is no deny button.” The expiry-as-cost table appears in full — an hour means fetch data, four hours means a P1, two weeks means a funded project, six months means do nothing and costs zero. On the same day, the two independent dimensions of a decision and the underwriting graph. →
-
26 June 2026 · the register becomes a graph
The register as a graph of graphs, the 2FA worked example, cascade and the air gap, not-knowing-is-a-fact, CIA blast-radius expansion, five whys as a domain translator — and
AcceptanceandIntervalas node classes in a 24-class ontology. The single densest day in the corpus. → - 28 June 2026 · the ontology The grounding ladder, node type formulas, ontologies-of-ontologies and the worked external bridge, in one folder. The most rigorous documents in the corpus, and the ones an agent most needs. →
-
2 July 2026 · maturity, authorization, and the scenarios
RAMM makes
RiskAcceptanceDecisiona hub node with twelve named edges; authorization closure is formalised; and the ten scenarios are written — the one artefact from all of this that reached an audience. → - 12 July 2026 · the largest graph, and self-criticism The browser-isolation business case: 59 nodes, 75 edges, five altitudes — carrying three risks of its own proposed mitigation and a counterweight figure that argues against its own urgency. Also the level ledger, register density, and the residual. →
- 17 July 2026 · the ladder, and the sharpest inversion Intervals consolidated into a six-rung ladder with the default set at one month, deliberately just above the incident line. And unaccepted-equals-critical: “not doing something is a measurable action.” Fractal registers and relevance fade land the same day.
- 24 July 2026 · the plug A thirteen-document series in one folder. Two symmetric risks, the four-way time intersection, the five-dimension profile, and the correction that the plug always exists — what looked like “no plug” was zero recoverability. →
- 28 July 2026 · the vocabulary correction Accepted is not acceptable — two orthogonal axes, four quadrants, appetite renamed, and the Article 9(5) definitional gap. Late, and load-bearing: everything before it had been using “accepted” to mean two different things.
- 31 July 2026 · keeping the register alive Meta-risks named as a family. The register maintains itself, with three failure conditions. Do not internalise the risk. Design for players who will not play — where attrition, not refusal, is identified as the failure mode that matters. →
- 2 August 2026 · fact to board, end to end The Article 26(5) instance runs the whole ladder on one provision, and produces the finding the corpus is proudest of: thirty days against six months, “arithmetic, not judgement.” Three corrections land the same day — registers are one chain, a decision is its own node, and a question is not a risk.
- 14 · 22 August 2026 · publication The vault publishing rules — read keys yes, write keys never, escrow before publishing. And the commission for this site: consolidate the concepts, and refactor them out of the commercial property. →
What the trajectory shows
| February–May 2026 | June–August 2026 |
|---|---|
| Estimate the likelihood of a future event | Underwrite an exposure that already exists |
| Either mitigate or formally accept | There is no “either” — you accept, for a stated interval, or you remove the capability |
| “Residual risk: acceptable” as a conclusion | Acceptable as a threshold the business owns and must define, orthogonal to whether anything was accepted |
| A rating, held in a document | A node in a graph, grounded downward to evidence and classified upward to consequence |
| Review dates as metadata | The interval as the decision itself |
The prior art: a year earlier, in public
Eight articles on docs.diniscruz.ai, February to July 2025 — 59,131 words in the founder's public voice, a year before any of the above. Two are directly load-bearing: Maturity Models vs. Traditional Standards (April 2025) is RAMM's ancestor, and Finding the “Good Enough” Threshold (July 2025) is the appetite argument before it had the vocabulary.
Provenance contract. Those articles were published under CC0; this site is CC BY 4.0. Republishing under a different licence would be legally fine and is not what happens here: they are cited, with their original URLs and original publication dates, because the historical link matters more than the licence does. All eight, with dates and canonical URLs →
One gap in the record, stated
The canonical “risk acceptance redefined” brief does not exist. Eight documents in the corpus cross-reference a 7 July 2026 brief titled “risk acceptance redefined vs industry definition — no deny, only how long, accountability”. It is not in the repository, and neither are three other documents referenced alongside it; there are no briefs/07/06 through briefs/07/11 folders at all. Eight citations to a document nobody can read is a real gap, and this site's /acceptance/ section assembles the redefinition from the surrounding material rather than pretending the canonical statement was already written.
Provenance
For an agent
Origins. The model inverts itself in June 2026, and the trajectory is published because the inversion only reads as an argument if you can see the position it was reached from. February 2026: orthodox GRC — P0–P10 scales, likelihood × impact, “residual risk: acceptable”, and the classical rule that every risk must be “either mitigated or formally accepted” (the June work abolishes the either/or). 21 April: the diagnosis — decisions made in meetings, reasoning lost, approval chains informal. 4 June: “the risk already exists” appears, inside a brief about agent identity. 18 June: underwriting. 23 June: no deny button, and expiry-as-cost. 26 June: the register as a graph, the 2FA example, acceptance as a node class. 28 June: the grounding ladder and node type formulas — the most rigorous documents in the corpus. 2 July: RAMM, authorization closure, the ten scenarios. 12 July: the 59-node browser-isolation graph. 17 July: the interval ladder consolidated, and unaccepted-equals-critical. 24 July: the plug series, 13 documents. 28 July: accepted-is-not-acceptable. 31 July: meta-risks and register health. 2 August: the Article 26(5) end-to-end instance. Prior art: 8 articles, 59,131 words, on docs.diniscruz.ai Feb–Jul 2025, CC0 — cited with original URLs and dates, not republished. Known gap: the canonical “risk acceptance redefined” brief (7 July 2026) is cited by eight documents and does not exist in the repository.