pki.sgit.ai / admin / versions

Release history

Every push to dev is a release: CI validates the site, verifies the version bump, tags the commit v{release}.{major}.{minor}, and deploys to GitHub Pages. The version is owned by admin/build/version.txt and must agree with the release commit's subject.

VersionDateWhat shipped
v0.1.74 6 Sep 2026 The badge refetches the version past the cache. assets/version.js is served with a ten-minute cache, so a browser that had it before a release kept showing the old number beside a freshly fetched page: on 6 September the release row said v0.1.73 and the badge said v0.1.72. nav.js now fills the badge from the cached value, refetches the file with cache: 'reload', and refills if it moved. Best-effort: any failure leaves the cached value, which is never blank. One file changed; the release ships what changed.
v0.1.73 6 Sep 2026 Build your own: a prompt pack for an agent. One page that says what to hand to an agent — Claude, ChatGPT, Cursor, any other — and one markdown file that is the hand-off: it points at the pages and the data on this site rather than repeating them, states the twelve rules that are not the agent's to change (a deterministic core, two question classes, a reliability per question, the prediction before the reveal, the gap per capability with its reach and the reduction beside it, three classes never mixed, honest failure, the tier caveat, nothing leaving the browser, every node linked to its source, and the words), and leaves everything else to the agent: genre, look, interface, technology, voice, pacing. Two steps: a plan for review, then the build as a self-contained folder under guess/variants/ with a README, its own self-test output and a screenshot. Variations must differ in genre and technology, not palette. The page renders the markdown beside a copy-the-link button and a one-line starter to paste. The game's sub-navigation gains the page; the site menu is untouched.
v0.1.72 5 Sep 2026 Reach is a node, and the game grows a mesh, an engine that is not fooled by ignorance, and its own pages. Brief v0.33.65 filed and built the same day, with the project lead's memo on the shape. The mesh as files: one file per reach node (six file systems wearing one verb, and the rest — thirty-five), environment, vendor, obligation and question under probes/mesh/, a refine map on every profile saying where each capability lands for it, two profiles nobody calls an agent (a browser extension with broad host permissions, a scheduled job as a service account), and one ontology every edge is typed by; gen_mesh.py compiles the graph with gates. The engine: questions in two classes, identifying and measuring; a reliability per question that tempers the belief update, so a low-reliability answer barely moves the belief and fully counts toward the gap; identify first, then a few measuring questions about the leader; the gap collected per capability throughout, with its reach node and reversibility; the end-of-game prediction kept for the sense of scale. The play screen in two columns: the transcript on the left, the inspector on the right with asserted, inferred and possible in three treatments never mixed, the belief, why this question, disagreements so far, and sources with edit links. Demo mode plays a profile's own modal answers step by step or end to end. The mesh, start anywhere: pick any node, see what points at it and what it points to, and answer which products touch my share. The report: one page with the answer, the clues, the classes, the belief, the specific gap, the scale, the grant as a graph, what it cannot reach, the obligations worth checking with the tier caveat, and the sources. Sources & corrections: every file with view and edit links, and the workflow: a correction is an edit. The self-test caught the first thing the reliability tempering does: the two sibling profiles that differ on one control a person forgets needed an identifying question about the action the person took (did you set it to never ask). Not built, on purpose: the model at its three edges.
v0.1.71 5 Sep 2026 The game is named: Which Agent Is It? The project lead's name and copy, applied with three edits argued on the day: try to identify it stays, because the tree is deterministic and says when it hasn’t met yours yet; operational risk goes, because the game computes no risk — it shows what the agent can reach, what it cannot, and which of it could not be undone; and the prediction step is on the front door, because without it the game is a lookup with a costume on. The kicker reads RiskMandate.ai, the sub-brand relationship the naming brief asked for: a service named for the question, whose result is expressed in the estate's own vocabulary once you are inside. The menu, the bench and llms.txt follow; the folder stays /guess/. The release rewrites every page for the menu label, notified as an exclusion under r4 and accepted.
v0.1.70 5 Sep 2026 The menu, the graph, and the container's rows told from the container's point of view. A Measure group in the nav (the assessment, the game, the probes, the graph, probes/llms.txt) and the same three lines in the bench dropdown and footer — the release that rewrites every page, taken under the notify mode the issuer set on 5 September. The grant as a graph: a profile drawn as its tools, the capability each tool reaches with its reversibility as the fill and the control on the path as the stroke, and what the profile cannot reach; hover for the row, the same rows as a table beneath. Two corrections from the project lead's first play of the game on a phone: the verdict box was grey on black (the site's paragraph ink outranked the box) and is now legible; and the container profile's rows read as if host meant the person's machine. Labels no longer say your or as you; each profile says what host, tenant and world mean for it (reach_names), lists what it cannot reach, and carries the control on every row with its tier as a chip. For this container: host is the vendor's ephemeral container, the keys present are the session's own, commits are signed as the registered agent identity and not as the person, the code-host token is the platform's and scoped. A third tool measured: the harness, self-reported — its code-host API tool writes to the repository by a path the clone's git hooks never see, so a hook is a control on one tool; and its scheduling tool creates something that outlives the container (create.schedule.tenant, a new primitive). The game and the assessment show the reach names, the control chips and the cannot-reach list, and link the graph.
v0.1.69 5 Sep 2026 Probes, not tables — the assessment, and the game. The four 4 September briefs that concern a repository, a site and a game, built the same day as three bench MVPs, each saying what it does not prove. Probes, not tables: twenty-one capability primitives (verb × object × reach + reversible), fourteen probes with the command and how to read it, a runner emitting findings/v1 in OpenSSF Scorecard's probe/finding shape plus reversibility and tier, and seven profiles — two measured (this container's shell and its fetch tool separately, which is the per-tool point stated as data; the CI runner from the 26 August library entry) and five derived and marked as claims. Every evidence file was produced by the environment it describes and says so: independence is what nobody has paid for yet. Grants public, mandates private: probes/yours/ is gitignored. What you authorised and never asked for: name your tools, the grant appears before you have typed anything about yourself, four questions about work, the gap with the irreversible rows first and the reduction on the same screen, a verdict that is a statement rather than a grade, a tier on the result, an expiry. The site cannot scan anybody, says so, and has no button that sends; the counts-only tuple is shown. A surprise is an action outside the grant, which makes the assessment falsifiable. Guess the agent: deterministic decision-tree induction over the profiles, the prediction step before the reveal, and the prediction gap — never a surprise, the collision the brief caught — with the reduction on one screen; the tree is public and self-tested at build (every profile placed from its own modal answers, the count derived, not typed). Two entries for the pack: IE-D24 answers the conformance vault — top-level conditions and exclusions by control belong on policy/v1, in the vault's shape; IE-D25 reads doctrine 13's levels and the architecture brief's evidence-mode rungs as one axis and keeps evidence mode, with the rung-to-instrument mapping adopted as a proposal by analogy. The pack gains its llms.txt. Nav untouched, on purpose: a nav change rewrites every page, and this release ships what changed.
v0.1.68 3 Sep 2026 Memo 13 — the enforcement ladder, and the pack climbs it. Brief v0.33.85 and doctrine 13, recorded before the project lead had read the pack it turns out to describe: one policy walked up every place it can be enforced — nothing, a prompt, a skill, a git hook, the destination, out-of-band verification — and the reading places the six levels on the three tiers and finds a fourth the tier test had not named, detection. Assurance per level is measured from the ledger's catch rate, never asserted (GM-D105); a catch above the hook is an incident, not a volume event (GM-D106); and reconciliation against git is the control the pack lacked (GM-D107). Built the same day: a level on every event, tools/reconcile.py as level five (eleven commits since the hook, no catch), a destination check in report mode, the room's sixth card, and the pack amended by appended sections (IE-D17 to IE-D23, IE-C8). Two things the day taught, both on the ledgers: the push record now precedes the push through a queue, so a push leaves the tree clean (IE-C8); and the estate spent its whole daily pool twice publishing one pack, so the issuer raised the limits for now — by supersession to policy r3 and a revision recorded inside the push policy's own file — the first re-fit from loss data, to be reviewed (IE-D23).
v0.1.67 3 Sep 2026 The acceptance log the ignore file hid — and the first release that ships only what changed. v0.1.66 never deployed: the site validator found two links to packs/insurance-ecosystem/tests/acceptance-2026-09-03.log pointing at a file that .gitignore's *.log rule had kept out of every commit, while the local tree had it, so the local validator passed. The rule now excepts the pack's tests/, the log is committed, and this release is the proof of the badge change: version.txt, version.js, llms.txt, index.md, this row, the ignore file and the log — not two hundred and thirty pages.
v0.1.66 3 Sep 2026 The insurance ecosystem pack — and the release stops touching every page. The pack the fourth v0.33.62 brief specifies, written after the nine-item inventory it demands, under the economics of the third, and under the project lead's instruction that for the pilot one session holding the vault key may run any role in any vault: eleven documents and change control at packs/insurance-ecosystem. Two findings from the inventory changed the design: there is no board application, so the room is a vault app of five cards; and the platform fails open when a hook times out, so the git hooks refuse and the Claude hooks instrument. Question nine settled provisionally (mandate is the narrow thing; August governs). Build-order step 1 is built and run: a 400 KB commit refused by git, the eleventh commit of the day recorded as a draw, a push outside the mandate refused, plus a requested draw decided and drawn via the decision and exhaustion at the fifth reading — with git's own output. Then the pack published itself under its own hook, and the ledger shows what that cost: two commits drawn, two requested and approved under the approver's hat (the relaxation), and two refused as exclusions — the wiring sources at 310,858 B, over the cap by 3,658 B because a one-line change to a large generator costs the whole file, and the badge rewrite. The rewrite is the last one: chrome.py now writes the version into assets/version.js and the badge is filled at load time, so a release ships version.txt, version.js, llms.txt, index.md and what actually changed. The release itself needed one acceptance and one override, both the project lead's, and both are on the ledgers.
v0.1.65 2 Sep 2026 Memo 12 — the claim is the draw, and the first MVP. Brief v0.33.84 and doctrine 12. The reframe first: the money in a policy was always a metric for what the claim buys, so pay the claim in the thing itself — tokens, access grants, bytes — with the amount pre-approved. Then a draw on the pool is the claim, paid in the resource and settled by the check in milliseconds, because trigger, cover and payment are three fields of one document read by one function rather than three parties' documents reconciled by people (GM-D97, GM-D98). The worked policy has all four excess-of-loss parts, twice: pushes per day and bytes per push, each with a normal band, a per-occurrence limit and a daily pool; the pool is shared per repository because the ledger lives there, so pooled fate is deliberate and the per-occurrence limit is what stops one agent spending it alone (GM-D99). Let Claude manage this is read honestly: a skill the agent runs on itself is a setting and says so on its face; the boundary is the same policy read by a party the agent cannot reach (GM-D100). And the first MVP is built: insurance/push-policy — policy.json as a mandate-shaped statement, check.py measuring what git would send and returning normal, drawn or refused, an append-only ledger that is the loss data (GM-D101), a pre-push hook, and a Claude skill. Bytes are counted before the push as uncompressed new objects, a floor and never a bill (GM-D102). Its first finding is about this estate. Replayed over the last twelve releases on dev, the policy refused all twelve, at ten to forty-three times the per-push maximum, because chrome.py stamps the version into every page and a one-line change ships 180 files. The memo describes this exactly — a cost paid continuously by every developer, every push — so the policy is not mis-calibrated; the release is (GM-D103). The hook is shipped and not installed, because installing it would refuse this release too. gen_insurance gains an MVP gate — a README with a does-not-prove section, or no build — and llms.txt's second carry item now says one thing is built and what tier it is.
v0.1.64 1 Sep 2026 The partner deck is rendered, not just transcribed. The design partner deck showed only a machine text extraction, which loses everything a slide carries — the ladder, the weighted dimensions, the two-column comparison all flatten to a list of words. The eleven pages are now rasterised from the PDF at build time and served as plain images: no viewer script, no plugin, no JavaScript, and no PDF-in-an-iframe, which mobile Safari handles badly. Single column on a phone, two columns above 900px, and tapping a slide opens it full-resolution. Rendered at 2× for a retina display and encoded as WebP, the whole deck is 736KB. The artefact is untouched — the images are derived from the same bytes the sha256 gate protects, regenerated on every build, so they cannot drift from the document they depict: if the PDF ever changes the build stops before the renderer runs. The text extraction stays below the slides, where it is useful for searching and quoting, and still says that where the extraction and the PDF differ, the PDF wins. One new gate, self-tested by breaking it: the renderer checks the PDF's real page count against the manifest and refuses a build that disagrees.
v0.1.63 1 Sep 2026 The partner artefacts, captured verbatim — and two of them held. The RiskMandate business partner produced four documents on 31 August, in parallel with the project lead's memo series and after the two met in person. Neither side saw the other's work. /partner/ captures them, and the folder says before it says anything else that none of it is this estate's work. Published: the riskmandate.ai landing page, byte-exact and shown in a sandboxed frame so a third party's marketing is never mistaken for a page of this site, and the Design Partner Deck with a machine text extraction beside the PDF. Held: the two RAMM-I documents, which are internal strategy — they name an existing customer under an active SOW, name acquisition and partnership targets, state a negotiating position on a contract clause, and characterise named competitors for a private audience. This site is public and serves every file in the repository, linked or not, so committing them would publish them and git history would keep them after any deletion. That is the project lead's decision and their partner's; both are staged and go in on one word. The evidence-class discipline is the point of the folder. That the partner asserts these things is observed; the market claims inside them — filings, carriers, approval rates, form numbers, loss figures — are documented, a third party's assertion this estate has verified none of. GM-D57 says a connector labels the evidence class of everything it imports, and these artefacts are a connector. So: the survey has not been run; somebody else's survey has been received, and collapsing the two would be the first dishonesty in the folder. The concordance maps where the two bodies of work meet: four of the partner's five primitives are the same objects as ours under different names; three guard-rails were derived independently and identically, including derive from telemetry, never questionnaires and the not-in-line position; and one real collision — the partner's Index is 0–100 where GM-D54 settled 1–5 and explicitly refused 1–100. Not resolved here, because GM-D54 is the project lead's and the Index is the partner's. And the convergences are marked as weaker evidence than they look, because both bodies of work come from two people who met the day before, in one week, with model assistance. Three new gates, all self-tested by breaking them: a recorded sha256 per artefact that stops the build if one byte moves; a refusal to build if a held artefact appears in src/; and chrome and the validator now skip partner/src/ entirely, because this estate does not inject its nav, its footer or its version stamp into a document it does not own.
v0.1.62 1 Sep 2026 Memo 11 — the second axis, and the first loss data this pivot can have. Brief v0.33.83 and doctrine 11. Every memo before this one rates capability — what an agent can reach. This one rates consumption, which is orthogonal to all of it: two placements with byte-identical grant trees can differ by two orders of magnitude in what they burn, and nothing this estate measures would see it. And it introduces a node the tree never had — a resource pool is a grant that depletes, carrying a remaining that changes with no re-measurement, which makes it a fourth primitive rather than a restatement (GM-D86). The largest thing here is not the buffer. The pivot has argued about insurance for eleven memos with no loss data, no claim shape and no pooling, and this supplies all three at once. A token pool is risk pooling in a currency that is not money — variance absorption across a population, needing no carrier, capital or authorisation, and structurally the thing insurance does rather than the thing underwriting does (GM-D88). The memo's own line is correlated risk named in one sentence — it's okay to have one out of 100 to have a spike, but it's not okay to have 100 having the spike — which is doctrine 01's aggregation problem arriving with a concrete instance, four documents after it was recorded as a rule and not implemented. And a budget overage is a loss event nobody here has to instrument: dated, quantified, attributable, and already recorded on the supplier's invoice — so loss-event/v0, which doctrine 08 called the one primitive the whole pivot lacks, can be drafted against a real instance (GM-D89). Two long-standing blockers fall with it: GM-D78's collision dissolves, because the counter exists and the supplier already runs it for billing, so reading it puts nobody in the line (GM-D90); and doctrine 07's who checks first is answered — the resource supplier has a reason to refuse: it is paying (GM-D91), the first candidate in eleven memos that did not have to be argued into caring. The memo is corrected in one place: it says the pool defines in a way the grant, and it does not. A pool bounds volume, never reach — the cheapest catastrophic action is cheap, so a budget catches the runaway loop and is blind to the single force-push (GM-D87). Also: the structure is excess-of-loss and the memo names three of its four parts, the missing one being the per-occurrence limit that stops one runaway revoking ninety-nine well-behaved licences (GM-D93); remaining > 0 is the only warranty in the pivot that cannot fail the unknown way (GM-D92); and tokens are a currency people actually want, which makes a level is never declared, only derived stop being hygiene (GM-D95). And the series was called complete for the second time and grew for the second time. Filing memo 11 fired the v0.33.82 gate on doctrine 10's own the last of the series — written by me four releases ago about a series I had just watched grow — and on all eight memo N of 10 footers at once. So the gate was rewritten rather than the footers re-edited: checking a hand-typed denominator still leaves a hand-typed denominator, and a document about memo 5 gains nothing from of 10. Don't gate a claim you can simply not make (GM-D96) — the count now lives only where it is derived from the manifest.
v0.1.61 31 Aug 2026 The insurance book: The Delta Is Where the Insurance Lives. The second volume, commissioned in one sentence and by the method of the first: the ten insurance memos and the pivot briefing — filed verbatim as briefs v0.33.71–v0.33.81, read into doctrine at /insurance/, audited at v0.33.82 — made one coherent argument at /insurance-book/: seventeen chapters in five parts (the pivot; the rating; who pays, who rates, who backs the claim; the machinery; the proof and its absence), a PDF that reads start to finish offline, a reference card, and a colophon. The disciplines are inherited, not optional: 76 quotations re-read out of the memo transcripts, doctrine and machine surfaces on every build — the gate refused 19 of the writing session's first attempts, mostly for dropping the sources' own emphasis; 20 computed counts, of which the first build corrected four typed by the writer hours after reading the audit about writers typing numbers; 8 figures taken at the tag their captions name, including the insurance hub at v0.1.51 — preserved believing the series was eight memos — beside today's hub, whose count is computed because believing turned out to be the wrong verb. The memos' contradictions are kept and answered rather than smoothed (memo 1 against memo 0 on where honesty comes from; memo 6 correcting memo 3 on what a broker changes), and the audit's six defects are the closing chapter rather than an appendix. Bench entry with four does-not-proves, the first being that the book inherits all twenty of the corpus's and adds no evidence of its own: nothing described is insurance, nothing described is built, and the survey that could prove any of it wrong has not been run.
v0.1.60 31 Aug 2026 The eleven insurance readings, audited against their transcripts. Brief v0.33.82 — the site agent auditing the site agent, at the project lead's request, and the first brief here with no voice memo above it. Every reading re-read against the memo it came from; all four load-bearing corpus quotations re-verified out of the pre-pivot files they cite, at the dates claimed. The verdict: the method held and the arithmetic did not. What was got right was the expensive stuff — the two-stage split, the three different things one word was covering when memo 5 said not the broker about an insurance broker and memo 6 meant execution brokers, the Fibonacci repair that rescues a settled decision from an instinct that appeared to contradict it, and the 2D-first sequencing labelled honestly as a disagreement with the memo rather than an extension of it. Six defects found and fixed. Three were stale counts — eight memos, memo N of 8, and memo 8 called the last of a series that grew twice — which is the third appearance of that class in this folder, so the fix is a build gate rather than three edits (GM-D81), and the gate caught real text on its first run: the correction note that recorded a false claim by restating it. The note was reworded rather than the gate loosened. One was a category error and it is the most consequential: the enforcement tier was identified with the incident-response team's quantity, but insurance splits a loss into how often and how bad, and the tier is neither — attempts are unchanged, but fewer succeed. The tier ranks reachability, which is blast-radius reduction, not severity reduction (GM-D82, narrowing GM-D52), and blast radius is now named as the proxy it is. One was an over-claim: stage 1 was called structurally immune to moral hazard, which doctrine 09 contradicts without noticing — make your agents look insurable is the same hazard with no carrier in sight, because a level is a badge (GM-D84). One was a dropped question: memo 3 asked whether a model vendor would carry a policy against its own mistakes, three memos before the same argument was made about brokers and presented as new — restored, and generalised (GM-D83). Plus a forward reference that never landed, delivered at last (GM-D85: an endorsement is an append), a transcription artefact that was never flagged when every other memo's was, and a correction only the correcting document knew about. No transcript was touched and no settled decision reopened. Every defect found is internal: the one thing that could establish whether any of this is right about insurance is still the survey, and it still has not been run.
v0.1.59 31 Aug 2026 Memo 10 — the series closes, and insurance/llms.txt ships. Brief v0.33.81 is two memos in one: the interfaces, then time. The best thing in it is the backup example, which yields a definition sharper than anything the pivot had — a warranty is a fact plus a maximum age, and it fails three ways: false, stale, or unknown, with unknown on the same side as false. That is the exact opposite of the rating rule, and deliberately so: for a rating, assuming absence manufactures comfort; for cover, assuming presence manufactures liability (GM-D76). It also completes a climb the pivot had been making without noticing — go-live gate, then running-agent gate, now per-action gate — and adds a third clock beside the policy interval and twin freshness: the warranty's own check interval, without which a policy in force against a fresh twin with a stale warranty looks covered and is not (GM-D77). Two more: metering uses is sound where metering verifications is not — a verification is not a use — but a usage-boxed policy needs an in-line counter this project is not, so we define the counting schema and the relying party or broker holds the counter (GM-D78); and the reframe that answers the memo's own question: an API is operated, a schema is implemented, so the policy lifecycle ships as documents and appends and the answer to "what APIs do we need" is mostly: none that we build (GM-D79). The transcript ends mid-sentence and this brief does not finish it, because guessing the end of a sentence and rendering it as the project lead's position is the same error as guessing a survey's findings. And the machine front door: insurance/llms.txt, generated from the manifest so it cannot drift, carrying every memo, every doctrine document, the settled decision, and — first, before anything else — the four things an agent must carry if it summarises this: nothing here is insurance, nothing here is built, no external evidence has been gathered, and the register it reads is fixtures.
v0.1.58 31 Aug 2026 Memo 9 — the positioning, and the first thing in this pivot that could be wrong. Brief v0.33.80: make your agents insurable as the tagline, and underneath it a research programme. Worth stating before anything else — this pivot has produced seventy-one decisions and no external evidence. Every brief so far is reasoning, checked against the corpus and entirely internal. Can you insure this session? is different in kind: the answer exists outside this estate and nobody here has looked, which makes the survey the first item in the series that could be wrong in a way the world would correct. The tagline gets one guard-rail, mirroring this folder's own rule about levels: it must not become make your agents look insurable, because insurability comes from narrowing the delta or covering it and never from documenting it — and some placements should not be insurable, which is a success of the method rather than a failure of the customer (GM-D72). The memo's inverse question maps onto the estate three ways, and the third upgrades a rule. What breaks cover is exclusions (the mandate's prohibitions), warranties (the facts — a breached warranty voids cover exactly as a flipped fact drops the tier), and material non-disclosure, which turns out to be the gap between the declared channel and the measured one. So the two-channel rule stops being only about rating accuracy: a control declared on the card that the twin cannot find is what voids a policy, not merely what worsens a level — making the card-versus-twin gap the single most consequential quantity an underwriter would want, and this estate can compute it today (GM-D73). The survey itself is specified as measure.py pointed at a market: dated, re-runnable, evidence-classed, unknown never absent, a floor rather than a census, reporting what vendors publish rather than what anyone said in a call (GM-D74). And the brief refuses to predict its own findings, because publishing a prediction as research would be the cardinal sin in the one document whose whole value is that somebody went and looked. Also: the series grew from eight to ten, and the build gate that refuses more processed memos than the manifest expects fired on the ninth — which is what it is for. The count was corrected and the reason recorded on the hub rather than quietly adjusted, because a printed count is a claim.
v0.1.57 31 Aug 2026 Memo 8 of 8 — the series completes, and the last memo specifies the MVP rather than requesting it. Brief v0.33.79 corrects the shape this site had been proposing across four releases. The site agent kept offering an instrument — a placement rated 1–5 with its derivation, plus a which-control-buys-the-most view. The memo asks for an explainer, and says why twice: users is going to be the first important thing, and that's what we can use to explain this. An instrument answers a question somebody already knows how to ask; an explainer creates the person who can ask it — and nobody yet holds a mental model of grant-minus-mandate priced as insurance, so a rating engine has no audience. It also reframes what exists: the simulator, the experiments and the workbench are all instruments, so this estate has instruments and a card game, and no world. Three more: cost needs assets, and the four dimensions named — time, money, recoverability, liability — are correctly the eventual requirement and correctly deferred, because a level is relative, so stage 1 needs asset class (declared, and marked) rather than asset value (GM-D68); the probable Fibonacci turns out not to disturb the settled 1–5 scale at all, because it is a proposal about what the bands represent rather than what they are called, which is the band-definition question already open; and the strongest requirement in the brief is a reservation. A SimCity-like world with data flying between departments implies a working system — when ten of eleven identities here are fixtures, both twins are servers, the claim shape does not exist and the world-state feed exists nowhere for anybody. A polished simulation is the most effective mechanism yet devised for making a demonstration look like a product, which is this corpus's own anxiety about apparent authority arriving in the user interface. So: the world shows its own emptiness — construction sites and empty lots rather than a finished skyline, which explains where the work actually stands better than a skyline would (GM-D69). The hub's MVP block moves from awaiting a decision to specified, awaiting a go-ahead.
v0.1.56 31 Aug 2026 Memo 7 of 8 — the policy becomes a statement, and the boundary finally has a home. Brief v0.33.78 works the pivot through the primitives the estate already has, and the answers are smaller than expected. policy/v0 is a mandate-shaped statement issued by a rater rather than an operator — same five fields, same append-only record, same revocation-by-append, same verification walk — so it needs no new register machinery, just one more statement type beside identity, mandate, acceptance, revocation and grant (GM-D62, answering GM-D36). A precision follows: a policy does not sign. A key signs, proving possession; the policy establishes what that signature is worth — which is exactly the afterwards this corpus named on 19 August when it said a signature proves possession and proves nothing about trustworthiness (GM-D63). And the structural claim resolves a limit recorded two releases ago. v0.33.76 established that a party outside the line can never itself be a boundary. Memo 7 names who can: the handshake puts the check in the relying party, who is by construction outside the requesting agent's grant — making it the first mechanism in this pivot that can reach tier boundary, without this project standing in the line (GM-D64). Three findings from checking it against the corpus: trust is a path is a sentence this estate published on 27 August, arrived at again from the insurance direction four days later; the memo's ten-minute revocation is a ceiling, because the observability brief already computed that revocation propagates only at the rate relying parties check — so an SLA without a required check interval is a hope with a number on it, and the handshake is itself the fix, since verifying on every request gives a latency of one request (GM-D66); and metering verification carries three hazards the observability brief anticipated, the quietest being that pricing a check discourages checking, raising the very latency the handshake exists to lower (GM-D65). Also fixed: a counter that had just become false. The hub said 8 of 8 memos processed because it was counting the pivot briefing as one of the eight. It is not — it precedes the series. The counter now counts only the numbered series, a gate refuses two memos sharing a number, and the hub reads 7 of 8.
v0.1.55 31 Aug 2026 Memo 6 of 8 — the broker market, and a correction to what a broker does. Brief v0.33.77: the commercial case for access and execution brokers is the insurance level they remove, and the memo's key move is that the claim must not rest on the vendor saying so — a broker should carry its own policy underwriting its failures. Read against the corpus that is apparent authority in the vendor channel: a vendor claiming to reduce your exposure is asserting authority nobody granted, and it binds because the buyer acts on it. The policy converts assertion into warranty; the sharper rule is that the claimed reduction is computed by the rating method, never by the broker (GM-D58) — which is the separation rule appearing in a channel it did not anticipate: not the deploying team this time, but the vendor selling to them. And the memo disproves a framing this estate had accepted. v0.33.74 said a broker converts structural delta to elective. That is incomplete: a broker changes the grant's topology — removing reach from one tree and adding a party with reach of its own — so a SaaS broker that narrows platform access while routing every request through a third party has moved exposure rather than removed it, the net may be positive, and deployment topology becomes a first-class rating variable (GM-D59). It also names a case the delta taxonomy could not hold: platforms that do offer the granularity and make it impractical to use. Fixed with a cost-to-close dimension on elective delta rather than a fourth class, because a rating treating all closable delta as equally the operator's fault is nearly as unfair as charging for structural — and it locates the product, since a broker selling into latent delta sells absorbed complexity, which is the larger market (GM-D60). Finally, one loop closes: the broker market exists because dynamic, checkable, PKI-backed authorisation does not — the clearest commercial argument yet for the register, and the thing that makes the broker market transitional by construction.
v0.1.54 31 Aug 2026 Memos 4 and 5 of 8 — the cautionary tale, and the first settled decision. Memo 4 makes the case for insurance by first making the case against it: cyber insurance is the warning, not the model — a market that grew on quantification nobody could check, sold policies worth less than buyers thought, and took payouts that hurt the insurers, with the failure landing on both sides at once. That is the empirical case for this folder's rule: a market can be enthusiastically data-driven and still be pricing fiction, if the data is not checkable — which fixes the priority, since a rating engine's first obligation is not to be accurate, because nobody can be yet, but to be checkable, so being wrong is discoverable rather than accumulating (GM-D51). Two more from it: insurance's real virtue is that it demands trustworthy data rather than merely using it, by creating a party with money at stake in the data being true — a forcing function stage 1 gives up and must replace with a public, attackable method; and the enforcement tier turns out to be an impact-reduction measure, the quantity security has never been able to articulate, since an incident response team does not reduce incidents but shrinks them, and the tier says nothing about how often an agent tries and everything about what a try achieves. This estate has been computing it since v0.1.28 without naming it — and it ranks rather than prices, which must not be overstated (GM-D52). Memo 5 gives the commercial position and the first SETTLED decision in this pivot: the level scale is 1–5 (GM-D54, closing N17 q1). The reasoning beats the answer — currency implies a loss distribution nobody has, 1–100 implies resolution the inputs cannot support, and a coarse band is arguable in a way a decimal is not: level 3 provokes an argument about what the band means, which is useful; 62.4 provokes an argument about arithmetic, which is not. The project places itself outside the line — schemas, flows, connectors and evidence, never the carrier and never the execution broker — and that constraint has a consequence worth stating plainly: a party outside the line cannot enforce, so this project can never itself be a boundary. It ships a check that becomes one when installed by somebody who is in line (GM-D55). The memo's own self-correction — our job is to be the broker, not the broker — separates three things one word was covering, and lands on: we do not operate the broker, we define what a broker must be able to show, without which every broker's claim is unfalsifiable marketing (GM-D56). And openness is load-bearing rather than generous: with no money at stake, an attackable public method is the only honesty mechanism left. The first MVP is now unblocked — the scale is settled and the counterfactual was already scale-free.
v0.1.53 30 Aug 2026 Memo 3 of 8 — who pays for the delta nobody chose, and a defect it found in our own instrument. Brief v0.33.74 works the accountability question through this estate's own GitHub example, which made it checkable. A code host offers read-only or read-write and nothing between, so an operator who needs to push at all must confer push to every branch. The operator did not choose that delta and cannot close it — no budget or diligence makes a platform offer a finer grain. So the answer to who pays is a taxonomy, not a party: the delta divides by who could have closed it — elective (more conferred than needed, or a control skipped: the operator's, and the part effort moves), structural (the platform's finest grain is coarser than the mandate: the platform's, or nobody's, and identical in every customer's estate at once), defect (a vulnerability temporarily widens the grant: the platform's, and temporary). A rating that does not separate these is unfair and useless in one move — unfair because it charges for the unfixable, useless because a level you cannot move is not a decision input (GM-D45). Three more: platform granularity is a library artefact, a fact about the platform measured once and referenced by all, and the only genuinely public-good part of this apparatus (GM-D46); the rating is a function of the world as well as the placement, because a zero-day does not change the twin — it changes what the twin's reach is worth — so both carry independent freshness and both are printed (GM-D47); and the memo's "10x" is declined as false precision, since magnitude needs loss data nobody has while direction and mechanism are computable today (GM-D48). And checking the memo against the published twin found a hole in our own tool: a push credential also confers the ability to author commits as anybody absent signed commits, and neither library entry has a node for it — a defect in the discovery instrument found by conversation rather than by the tool, recorded as GM-D50 rather than quietly patched.
v0.1.52 30 Aug 2026 Memo 2 of 8 — the rating becomes a gate, and the estate's own test turns on it. Brief v0.33.73 asks how an insurer-like ecosystem runs inside a company with no money, and answers by taking the industry's roles rather than its capital: an insurer is a third party for a structural reason — an assessment produced by the party that wants the answer to be yes is not an assessment — so moving it in-house means that separation must be manufactured. That completes the rule from memo 1: a level nobody can recompute is theatre, and a level computed by the party that wants to ship is theatre even when recomputable. Method and separation, both (GM-D43). The memo's consequential move is putting the rating in the path of a deployment — a gate, not a report — which drags in a requirement a report never had: reduce the risk by this quantity is unsayable unless the rating decomposes, so the derivation stops being an audit artefact and becomes the actionable half of the gate (GM-D44). Then the pack's own three-tier test turns on the insurance apparatus, unflatteringly: a gate on a dashboard is an expectation, a CI check the deploying team can edit is a setting — the same failure as the pre-push hook — and only a check evaluated by a party they do not control is a boundary. The roles and the tier are the same question asked twice, so the rating engine declares its own tier on its own face (GM-D42). Three more: reinsurance named as the fractal's three-century precedent, which supplies the rollup's shape and none of its correlation — so GM-D41 narrows rather than closes, because the connection between placements is the graph, not the org chart; the payout is the part that carries the moral hazard, which is a better reason to defer the money than the regulatory one, since a rating that pays nothing cannot be used to stop caring; and the control-to-premium loop is scale-free, which partly retracts last release's claim that the first MVP waits on the level scale — ordering controls by how much they move a rating needs no agreed range, and the workbench already computes it.
v0.1.51 30 Aug 2026 A home for the insurance work, and memo 1 of 8 — the one that makes the pivot buildable. A new base folder for the body of work: the memos, the doctrine derived from them, and the MVPs as they arrive. Memo 1 separates insurance from money and keeps the half that matters — a policy is first a decision-making mechanism and a way to assign a rating to an environment, expressed in points or levels before any currency is attached. That dissolves the blocker v0.33.71 called fatal: a rating engine emitting levels rather than money transfers no risk and promises no payout, so it is not a regulated activity and needs no carrier, no capital and no loss history — which moves the whole apparatus from years away to shippable. It also contradicts that brief's central argument, which said a premium cannot be theatre because someone loses money if the measurement is wrong. Take the money out and that discipline goes with it. The contradiction is named rather than smoothed, and answered with the rule the folder now runs on: a level nobody can recompute is exactly the theatre a premium would have prevented — so every rating ships its derivation (GM-D39). Three more findings from the reading: the ratable unit is a placement, not an agent, because the memo's own examples rate Claude in an environment; the questionnaire is a declared-fact collector and this estate already refuses to average declarations with measurements (library − self-report = blind spots), so measured and declared never merge and unknown is never scored as absent (GM-D40); and the aggregation trap the memo does not name — micro risks do not add, five hundred placements summed will be wrong in the dangerous direction, and correlation is readable off shared graph nodes (GM-D41). Stated honestly on the hub: the estate cannot score the memo's own leading example, because its two twins are a container and a CI runner and nobody has measured a desktop agent. The folder is generated by gen_insurance.py from a manifest, with symmetric gates in both directions plus one that refuses a doctrine document carrying no does not prove section — all four self-tested by breaking each and watching the build fail.
v0.1.50 30 Aug 2026 The insurance pivot, filed and read — brief v0.33.71. A voice memo pivots the risk approach: the foundation of the RiskMandate pyramid moves from risk acceptance to the insurance policy, because the delta between grant and mandate is where the insurance lives. Filed as a strategy brief carrying the memo verbatim above the reading, per the house rule that the transcript outranks any summary of it. The reading connects the dots the memo asks for: the register already publishes "acceptor": null on every measured delta, and the pivot names who sits in the empty seat — the insurer, an acceptor of last resort, accepting for money what no owner accepted. Two insurances separated: harm inside the mandate is ordinary liability with a priced history; harm from the delta is the agent-specific exposure nobody carries, and the memo's subject — with the consequence that when grant equals mandate the premium goes to zero, making least privilege financially legible for the first time. The payout logic is identified as parametric insurance described without the word — the right first shape, because every trigger it would name (excess authority exercised, mandate expired, warranty fact gone false, twin gone stale) is already computable from published evidence packs, while loss data does not exist anywhere for anyone. The memo's agentic insurance maturity model is read directly off the estate's existing rating variables — identity class, enforcement tier, twin freshness, delta size — four bands, in which N11, N12 and GM-D16 become premium reductions waiting to be claimed. Named honestly: the one primitive the estate lacks is the one insurance cannot do without, the loss event; insurance is a regulated activity and nothing here is a policy until a carrier stands behind it; and the pivot is recorded as proposed (GM-D35/36/37) with no surface rebuilt on it — a foundation gets argued in change control before anything is stood on it. Four questions back to the project lead as N16, the first being the one that decides who buys: who is the insured?
v0.1.49 30 Aug 2026 The data viewer — every JSON document, rendered and raw. Asked for by the project lead after the record pages landed: the same treatment the markdown reader gives a brief, for the documents that are JSON. One page takes ?src= and shows the document two ways. The two views are honestly different: rendered is a reading of the parsed document — keys as labels, arrays as numbered cards, long strings and PEM in their own blocks, and keys beginning _ rendered as notes because on this estate they carry the sentence disclaiming the file's authority rather than payload; raw is the file's actual bytes, fetched as text and shown verbatim, because a raw view that pretty-printed a re-serialisation would be showing you something the file does not contain. And it verifies. Where a document carries a sig and names its signer, the page checks that signature in your browser — Web Crypto, ECDSA P-256/SHA-256, over the registry's canonical form, against the signing key in the signer's own record. Confirmed against all twenty-three signed statements in the register before shipping: twenty-three verify, none fails. The check answers three ways and the third is not the second: verified, does-not-verify, and not-checked-here — an unavailable check is not a failed one. When one does verify the page still says what that is worth: the signer is a fixture whose private half is published, so it is integrity, not authority. Wired into the workbench's twin and mandate cards, the register's data files, and every statement on the eleven record pages — each keeping the raw file one click away, and the machine front door now says plainly that agents should keep fetching the .json. Two gates came with it. The link checker now resolves a query string instead of choking on it, and validates the document a viewer link names, so a link to a moved .json breaks the build like any other. And a new check refuses any page that loads the same script twice — which immediately found twenty-two: the book chapters had been fetching and running the markdown reader twice over. Fixed, and the gate self-tested by injecting a duplicate and watching the build fail.
v0.1.48 30 Aug 2026 Every register record now has a page. Reported from a phone by the project lead: the workbench's identity cards linked to registry/records/<fingerprint>/ — a directory, which a static host answers with 404. The narrow fix was to point them at record.json. That was rejected as the wrong fix: raw JSON on a phone is a wall of braces, and the real gap was older and larger — every other document on this site has a rendered page, and identities had none. So gen_records.py now generates one identity card per record: the fixture-or-real class first and loudest, because whether the private half is published decides what every signature below it is worth; then what the register answers about that subject, pulled from the expected-verifications view the validator reproduces on every release; then every signed statement rendered in append order — identity, mandate, acceptance, revocation, grant — each with its own explanation of what that statement type does, its body as a field grid, its signer and its statement hash, and a link to the signed file. A revocation renders as a later card, never as a deletion, which is the append-only rule visible rather than asserted. Key material is linked, never printed: the fixture private halves are published on purpose and a rendered page still has no business carrying one. Eleven pages, 154 in the site. The workbench cards and the register's own verification table now point here, and so does the source link inside every saved evidence pack — which had been recording a dead URL into its own JSON.
v0.1.47 30 Aug 2026 The workbench — a mini-app over the primitives, from the 30 August voice memo. A separate experimental UI, built in parallel with the simulator and the experiments and merged beside them: the key primitives on a left rail — identities, grants (the twin), mandates, facts, actions, a simulator, evidence packs, schemas, and risks (which are deliberately not here) — each a card surface over the real published documents, fetched by reference (GM3: references, never copies). The worked scenario is the memo's: a GitHub push. The real-time check is real: the live mandate's signature is verified in the visitor's browser with Web Crypto against the signing key fetched from the issuer's registry record, over the registry's canonical form — verified byte-identical against jq -cS before shipping, trailing newline and all. Every decision hands back an evidence pack (evidence-pack/v0, decision GM-D33, modelled on the service-twin brief's receipts): every check with its result, evidence and source, the delta, the twin's age, the enforcement tier computed from the facts, and does_not_prove inside the artefact. The twin is operationalised as the corpus defines it — the point where the graph meets reality, to which facts attach and against which obligations are assessed: flip the branch-protection fact and the enforcement tier moves from setting to boundary live, which makes N12 rehearsable before anyone touches repository settings. Default-deny is exercised rather than described: push to main refuses as excess authority, force-push refuses because the vocabulary cannot express it, an unsigned draft refuses everything while still showing the delta it would govern, and superseded v1 still refuses. Authoring lives in localStorage; every fetch is same-origin. And first contact found a real defect: the live mandate names repo.contents.push while the vocabulary declares repo.contents.write — different strings under the registry's own exact-equality rule, recorded as GM19 and deliberately not fixed by silent renaming, because that would invent the containment rule the registry refuses to define. GM-D34 opened; feeds pack decision 6.
v0.1.46 29 Aug 2026 The simulator, and the ladder from REPLAY to LIVE. Two instructions, brief v0.33.70. The next step first: the control room's does-not-prove said REPLAY never becomes LIVE and named what LIVE would need — that prose is now a computed ladder of four doors (the append lane, an unforgeable issuer key, signed facts, an independent measurement), the mode chip is derived from them rather than typed, and the doors page's symmetric gate arrives in its sharpest form: when the last of those doors opens, the build fails, because a board that could claim LIVE and does not is as much a defect as one that claims it and cannot. Proven by flipping all four open in a scratch copy and watching the build refuse. Then the card game: /simulator/, on its own base folder because it is a tool rather than an experiment — the first page here that answers to the visitor instead of replaying this estate's history. Eight cards in three suits, two worlds, a board, and play/step/rewind/reset. The load-bearing rule is that it does not predict, it composes: the browser cannot run mandate.py, so the entire resolution table is precomputed at build — every card, in both worlds, under both mandate states — and shipped as resolutions.json with the tool's own output in each row. Every outcome is a real verdict, a reading of the twin, or UNKNOWN where measurement was refused, and there is no fourth: a simulator that turns a hole into a denial manufactures comfort. The sharpest card is the pre-push hook, which changes no verdict at all and changes who refuses; and the deck asks what history did not — push to main is refused under both mandates, which no page here had ever shown. Five gates. It also retires a stated limit: v0.33.67 declared proposed-action simulation deliberately unbuilt, and the bench entry now records that line as retired rather than dropping it. Screenshot-read caught six defects, including a token painted over a station's label, an egress path sent off the bottom of the board by an absolute coordinate used as a delta, and a hand-typed count on the very panel arguing that counts are computed.
v0.1.45 29 Aug 2026 The control room: one board, both worlds, zero new data. The project lead's instruction — create a new component and UX for that simulation; think about a game UI and SCADA control systems UIs — answered in brief v0.33.69 with the claim that completes v0.33.68's: adding a world is adding a JSON file, and adding a way of seeing is adding a renderer. /experiments/the-control-room/ is a second renderer over the same scenario.json files the deck pages use: mimic diagrams drawn from the grant chains (Unit 1's egress wall solid and its push line broken by a breaker in the setting position; Unit 2's printing NO WALL with a clean line to the asset), annunciator tiles in strict bijection with the twin nodes, and the lamp grammar that makes the memo's contrast pre-verbal: the colour is the tier and nothing else, so a capability with no control on it is the alarm state and refused measurement is a hatched FAULT lamp, never a blank. Faceplates on click; the 26 August incident as a sequence-of-events log with game transport (play, step, reset) where the replay is baked, not computed — every verdict re-run through mandate.py check-branch at build, every quote byte-checked, timestamps derived (mandate v2's issued_at, the v0.1.28 tag's commit time) or an em-dash, and the whole board pinned to REPLAY because a live board needs the write path, monitors and a mandate service that remain stated design. Seven gates, one proven by tampering before shipping; the screenshot-read caught five defects including a JSON null printing as None on a faceplate and a breaker painted over a station at the uniform pitch. Bench entry with four does-not-proves.
v0.1.44 29 Aug 2026 The scenario engine: one engine, two worlds. The project lead's third memo, processed in brief v0.33.68: everything JSON-driven, nothing hardcoded, because the destination is tonnes of scenarios and a game engine that becomes a product. One generator, admin/build/gen_scenario.py, renders any world from a scenario.json that references a measured twin — the engine holds no capabilities of its own, and the deck gate forces cards == twin nodes exactly. Two worlds prove the claim by existing: Push to GitHub — the memo's worked example, this session's own grant chain (user → GitHub App → scoped token → container → Claude Code → Claude → repo) with the soft mandate shown as a place: the constraint keeping this world off the wrong branch is prose in the agent's context, expectation tier, exactly where the memo says mistakes occur, rendered beside the hook it could be and the platform boundary it is not — and The Deploy, the counter-world: the CI runner a permitted push lands in, no agent, no hook, unrestricted egress, and the estate's only boundary-tier grant, the workflow's permissions: block. Every capability card carries a confidence rung computed from its evidence (hypothesis 0 → independent 3, never typed) and a micro-animation of the capability acting — eight kinds, each freezing to its end state under reduced motion, declared depiction and not simulation. Six gates; the site chrome regenerated by its owner (chrome.py), retiring a footer version line frozen at v0.1.35 and moving the experiments into the nav's bench group. Bench entry with five does-not-proves, including that two worlds are not tonnes, and that the platform library (Codex, Lovable, the rest as fact-based scenario.json variations) remains an argument, not an artefact.
v0.1.43 27 Aug 2026 The experiments, the deck, and the table. Three instructions from the project lead's endorsement of the chain room, delivered in brief v0.33.67. A convention: /experiments/, one folder per experiment, one workflow, one visualisation, each with its own generator, gates and bench entry — the hub generated from a manifest whose entries must match the folders in both directions, and the chain room moved in as first occupant, free because nothing is deployed. The deck — the object layer the room lacked, answering the direct question have you added visual representations for grants, mandates, evidence, facts and actions? honestly: it had not. Six suits now — CAN (grant), MAY (mandate), IS (fact), SHOWS (evidence), DOES (action), DECIDES (decision) — each card a rendering of a real artefact with every field read from the source it links, and the resolution order as game mechanics: a DOES resolves against CAN, then MAY, and mints an IS backed by a SHOWS; blast radius is the CAN cards face-up that no MAY card covers. The DOES suit is the genuinely new primitive — actions had no representation anywhere in the estate, which is the book's receipt gap surfacing again, and the card says on its face that it is the slot a receipt would fill. The table, at /experiments/the-table/: four players including the systems (the hook plays reactions; the CI runner holds its own alarming CAN cards), replaying the estate's own 26 August incident from the artefacts it left behind — push permitted, push refused, mandate amended citing the instruction quoted inside the mandate itself, push landing at tag v0.1.28. Forward is the simulation; backward is the audit, and they are the same cards in the same order, which is the register's was it valid last Tuesday? promise as play. Nothing on the table is synthetic, and the gate keeping that true is live: every turn's resolution is re-run through mandate.py check-branch during the build, every reaction byte-checked against the captured transcripts. The twin claim answered from the corpus: a library entry IS a digital twin — measure is taken on a twin, a twin is grounded in its connection to reality — the experiments are twin theatres, and a simulation is running a proposed action against the twin instead of reality. Proposed-action play is specified and deliberately not built; a twin that is not re-measured is a stale delta with a nicer name. One defect found by reading the screenshot: turn one quoted the CI runner's file-reach node where its unrestricted-egress node belongs.
v0.1.42 27 Aug 2026 The chain room — the RiskMandate workflow as a playable simulation. The course-correction of v0.1.41's brief, at the project lead's direction: the doors page answered what has this estate passed, but the assignment was to create the core elements for the RiskMandate.ai workflows — and for that the room and the game-like environment are not decoration, they are the deliverable: the workflows and multiple states / actions are to be simulated first, then supported. Specified in brief v0.33.66 and built at /room/: eight stations, boustrophedon, with the library/instance boundary drawn on the floor — the left zone this site's paper, the right zone the network's terminal dark, so crossing the line reads as changing products. Four verbs, ours (LOOK · ASK · DOOR · NEVER), a dialogue console, and “run the walk”: a work item travels the declared chain with a derived caption and the raw artefact linked at every stop — the measured library entry, the signed mandate, the computed excess row, then across the line into a marked simulation. Game details that are rules rather than decoration: the delta desk has no drawers (a delta is computed, never stored); the counter answers every question with documents (the registry has no opinion); copies bounce at the boundary (references, never copies); and the acceptor's name appears only right of the line — left of it the excess row reads acceptor: none, which is the handover in one image. The right half is a fixture in the shape of RiskMandate's own positioning card — risk band, named acceptor, blast radius, expiry, reviewer, accepted conditions with observed status — and more honest than the card it mirrors: 3 of 4 conditions hold, because the fourth (boundary-tier enforcement) has never held anywhere in this estate. Five gates: the route drawn must equal the declared chain; the fixture stores references, never copies (GM3, enforced on the demo itself, because a demo that violates the architecture it demonstrates teaches the violation); a decision carries a named acceptor and an interval or it is not one; a condition's status is observed, never typed; and the SYNTHETIC marker travels with every quote, per the simulation rules — the marker lives in the filename, the headers and beside every value, because export is where markers die. One defect found by rendering, screenshotting and reading the screenshot: the expiry loop cut a stray diagonal and the route ran through the SYNTHETIC badges. On the bench with its own does_not_prove, and the doors page stands beside it: the room opens none of the nine shut doors — it makes one of them, nobody has ever accepted an exposure, explainable to the person who might.
v0.1.41 27 Aug 2026 The doors — a computed state map where the build breaks when a door opens. Ported from newsroom.sgit.ai's debrief on rendering an agentic team as a point-and-click room — and the room is not what was ported. That debrief says its second surface, the state map, turned out to be the more useful of the two, and this estate agrees for a reason specific to it: the problem here is not that the state is badly presented, it is that almost nothing has passed its own gates, and a room drawn over that would make the estate look more finished, which is the one direction it must not move. The debrief's candidate mapping for this site — a registry counter; issuer, subject, verifier, revoker — was accurate for the site as published and was overtaken by briefs v0.33.63 and v0.33.64, which dismantled exactly that counter; the mapping it offered risks.sgit.ai (the grounding ladder as a staircase, the likely shut door a rung with no instances) now fits this site better. Specified in brief v0.33.65 and built: /registry/doors.html renders this estate's four declared ladders — the bootstrap gradient, the tier ladder, the ordering rule and the confidence ladder — as rungs with computed instance counts, each carrying a door: the condition the next rung will not accept work without. Nine of twelve doors are shut — and the page computes the split rather than asserting it: three could be opened by this project alone (sign the library entries, define a capability name, put a branch protection rule on the remote) and six need somebody who is not this project. The three that are ours are the more uncomfortable half, because nothing is stopping them. The declaration at registry/doors.declared.json holds no counts; every number comes from a named metric function in admin/build/gen_doors.py, so each one has code you can read, and a rung naming a metric that does not exist fails rather than rendering blank. The gate is symmetric by construction: a door declared shut that computes above zero fails as A DOOR OPENED — that is news, and a door declared open that computes zero fails as A DOOR CLOSED — that is a regression. All three failure paths were verified by breaking them, including opening a real door by signing a library entry. Two channels on every state, never colour alone. And one defect was found the way that debrief says defects are found — by rendering it, screenshotting it and reading the screenshot: metric names were breaking mid-word on the phone layout.
v0.1.40 27 Aug 2026 The refactor brief goes to draft-2, on a constraint that was removed. The project lead: nobody is using this pki.sgit.ai website and artefacts/primitives, so we can change everything and don't worry about backwards compatibility. That licence made three of draft-1's proposals visibly worse than they needed to be, and each change is a simplification rather than an addition. Seven statement types collapse to one envelope in two genres — assertion and decision — with the seven primitives carried as predicates rather than types. Draft-1 proposed adding fact and evidence to the register's existing five, which fails the corpus's own scale-invariance rule (one validator, one query engine, one provenance rule — not a family of them per level) and only existed to preserve the five. With nothing to preserve, the recursion test passes: evidence about a fact is an assertion whose subject is a statement, and nothing needs a new file type at any altitude. Acceptance and revocation stop being types — an acceptance is a decision about a mandate — so five collapse to two without losing a distinction. roots.json is deleted rather than renamed, since an anchor is an ordinary assertion; answer is removed rather than deprecated, with no compat shim; the fixture register is regenerated to exercise rungs, independence and staleness rather than migrated to preserve six verdicts it will no longer issue; the numbered statement filenames go, because C7 already made the commit graph the ordering authority and only fetchers kept the prefix; and params.json's signature contradiction — the book's finding A1, where the normative recipe says DER and every signature on disk is raw r||s — is simply corrected in place, because nothing depends on the wrong text. A new §9 states what the freedom buys and the uncomfortable half of it: the reason nothing needs migrating is that nothing has users, which is this estate's own largest open finding rather than a new one, and three of the brief's eight open questions are blocked on somebody outside this project — none of which gets less blocked by a better envelope. The refactor is right and it is not the bottleneck. Scope stated precisely, because two rules look like they conflict and do not: no backwards compatibility applies to artefacts; supersede-never-rewrite still applies to published claims, which is why draft-1 is superseded above rather than edited.
v0.1.39 27 Aug 2026 The registry has no opinion — architecture brief v0.33.64, the refactor that follows v0.33.63's critique. The registry registers, and it does not hold a verdict — structurally rather than modestly, because an opinion needs context and the context lives with the consumer. The corpus supplies the mechanism: the grounding ladder's upward path says each step up is an interpretation somebody is accountable for, and a verdict is an upward step, so the register's answer: YES is a claim of accountability it cannot discharge. What it supplies instead is signed nodes and edges whose worth to a consumer is a function of that consumer's trust in this registry — one of many, in a fractal, on the shape of the root DNS servers with an eventually consistent SLA. The fractal claim is made falsifiable against the register and fails in one place: roots.json is the special case, and once it becomes prunable pointers the test passes. Seven primitives in two layers that must not be blurred — three identities (agent, environment/provider, user) saying WHO; two evidence objects (fact, evidence, both new) saying WHAT IS THE CASE; and two authority objects (grant, mandate) saying what is possible and what was decided. Adding fact and evidence changes the register's genre, from a permission database to an evidence store. The biggest delta is environment identity: a grant becomes a signed fact about a keyed environment by a named measurer, which turns the book's floor, not a census caveat from a confession into a computable independence attribute — and makes the honest number visible, since both library entries state that the instrument IS the subject, so the library today holds zero independent measurements. Rules 1 and 4 stop being constraints and become the mechanism attach, never mutate runs on, which makes abundance a feature and answers 2019 by arithmetic rather than by a size bound. States plainly what PKI is for here: it does not establish trust, it makes edges attributable, and attributable edges are the only thing independence weighting can operate on — while conceding the weakest joint, that cryptography cannot prove two keys are two parties. Six open questions left for the project lead, including whether a second “Grants” in the source memo meant an eighth primitive.
v0.1.38 27 Aug 2026 The registry is not thinking in graphs — strategy brief v0.33.63, from the project lead's memo after reading the book, with its instruction to read graphs.sgit.ai executed. The reframe: the registry has been built as an ORACLE and should have been built as a NODE. Trust is not a verdict handed down by a body of truth; it is a confidence the consumer computes from the independent evidence they can reach, it is a spectrum, and it is specific to the use case, because what you need to accept a message is not what you need to accept a contract. The registry's job is to be one more place that stores evidence and clues. The brief's uncomfortable finding is that this family's corpus already published all of this, and it is older than this site: a public key in isolation does not give you anything; it is the graph it is connected to (4 June 2026 — the sentence this site's book is named after), the confidence ladder making assurance computable from connectivity, weight by independence, not by count, and enrichment, not enforcement — when confidence is low the remedy is more edges, never more validation rules. Four contradictions with the shipped register, three computed from the repository: roots.json is a gate where the corpus specifies an anchor with no authority at all; the verifier returns a verdict where the evidence set should be the product (its basis array is the seed of the right design); rule 2 is contradicted by the earliest graph-native sentence in the corpus, which is itself about PKI — revocation is the absence of trust, not the presence of a revocation entry, and a revocation list can only tell you about the revocations it happens to know about; and graphs.sgit.ai is mentioned zero times on this site's front door, which is the mechanical cause of the drift and is tracked on the sibling estate as ask N2. Proposes anchors.json in place of roots.json, a verifier returning a rung, a typed evidence set and the gaps with the verdict left to the caller, and a views/gaps.json, on the corpus's rule that an absence that is stated can be counted, queried, assigned and closed. Rules 1 and 4 stand untouched; rule 3 stops being the load-bearing defence, because a flood of 150,000 attestations from one origin is one edge under independence weighting. Records what the register would have to say about itself today: independent_paths: 0, since every path terminates in the same published private key.
v0.1.37 27 Aug 2026 The book reads the method sources its brief named, and adopts what they taught. The commissioning brief's §2 names three of the sibling estate's finished books to be read for method rather than material, and is explicit about the order — read the appendix before writing the capture scripts, not after. v0.1.36 did not: it built the harness from the brief's §4 summary and shipped. This release reads the source, at the project lead's prompting and after the book was already published, and acts on it. The harness had independently reached the same core, because §4 carries it faithfully — worktree at a tag, a port never reused, a browser killed in a finally, deviceScaleFactor, pageerror collection, a blank check. Four things it did not have came out of the actual reading. The gen:stat marker system is the one that mattered: the sibling atlas carries every count in its prose as a generated marker rather than a typed number, so a count cannot drift from its build while still reading as a fact. Adopting it immediately corrected three counts in this book that had already gone stale, including a release count this book's own release had falsified — a book arguing that every number should be computed rather than recalled had typed eight of its own by hand. Fifteen markers now, plus a generated STATS block in book/llms.txt; both fail --check on drift, verified by tampering with each. The tags refusal: every release number and every past figure rests on git tags, a shallow clone has none, and this session started against exactly that and had to notice — so a checkout with no tags now refuses rather than computing zeros, verified against a shallow clone, because a silent 0 would have been written into the prose as a fact in a chapter arguing that a gap must never render as an absence. --font-render-hinting=none, without which text rendering follows the host's font config and the same page captured on two machines differs in bytes, failing a digest gate for a reason that has nothing to do with the page. And a settle for anything laid out by script — only /assess/ qualifies here, and raising it from 1.2s to 6s produced a byte-identical capture, recorded as a checked non-issue rather than left as an assumption. Also fixed: a numbering slip in chapter 15, where the first named absence was labelled A9-b and there was no B1. Appendix A now credits the sibling appendix as the source of the technique — a book that marks every borrowed sentence and then presents a borrowed method as its own would be making the mistake it spends seventeen chapters on — and carries the figure table. The colophon records the correction at full size: the brief said to read them, the session decided its summary was enough, and one prompt from outside was worth more than the whole self-review that preceded it, which is also the finding of chapter 15.
v0.1.36 27 Aug 2026 The book, written. A Key Means Nothing Alone is delivered against the commissioning brief published three releases ago: seventeen chapters in five parts plus front matter, a harness appendix, a colophon and a reference card — 35,000 words, with the markdown under book/content/ as the source of truth and every chapter page rendering its own file, so a page cannot describe a chapter it did not render. Fourteen figures, each taken from the release tag its caption names by git worktree on a port used once and never again, with a headless browser killed in a block that runs whether the capture succeeded or failed — and two gates, because there are two claims: a figure of the past must re-derive from its tag, and a figure of the present must still match the live page or the build fails, which it will on the next release. Sixty-five quotations, each re-read out of the source it names on every build, with the locator discovered rather than asserted; a quote not found where it claims to be fails the build, and it caught a conflated attribution during writing. Against those, 48 claims declared as the writing session's own reasoning rather than this estate's, because blending the two is the same error the book is about. Every number computed, and four of them contradicted the brief — most visibly “eight releases in four days”, which the repository says was forty hours across two calendar days; the repository won and the colophon lists all four. Chapter 15 is findings computed rather than recalled: twelve contradictions and seven named absences, both sides of each quoted, and three of them are current artefacts breaking this estate's own load-bearing rules — params.json’s signature recipe fails against every statement in the register it governs; the delta block authors part of a grant from a literal in its generator, naming a branch the measurement never observed, in a pack whose first correction is that grants are discovered and never authored; and the shortfall column is a hardcoded string rendering a gap as a finding of no gap. Two were found by running the estate’s own code rather than reading it. Chapter 12 is written to the RiskMandate team as a contract rather than a description, and names the open question GM-D32 did not settle: who decides when the component contract needs to move. One figure could not be taken as the brief specified, and the reason is a finding — the release that documents the refused push cannot reproduce it, because the control refused the release carrying its own documentation and the mandate had to be amended before that release could exist. Also: the bench entry moves from specified to live with a new does_not_prove, and this site’s own llms.txt is corrected, having said six bench entries while the bench shipped seven — a contradiction the book found and chapter 15 records as fixed here.
v0.1.35 27 Aug 2026 The book brief gets a reader. The commissioning brief was published as raw markdown only — a link that opens as a wall of plain text, while every other document on this site has a rendered page. It now uses the same in-page reader as the documents: metadata block, summary, key concepts and key ideas, then the markdown rendered by assets/mdreader.js with the raw file still the source of truth and a link to it in the header, the label above the render and the page footer. If rendering fails for any reason the page falls back to that link, so the brief is never unreachable. Also linked from the nav and footer under the bench, and in the sitemap.
v0.1.34 27 Aug 2026 The book brief revised the same day it shipped, because the evidence it was modelled on finished arriving. Draft-1 of the commissioning brief was written when one of the sibling estate's three commissioned books had been delivered. All three are now finished, and the two that landed last carry disciplines stronger than what draft-1 specified — so it was tightened rather than left standing. Figures are now time-travelled. Draft-1 said capture the page today and prove it by hash; that proves a figure matches today's page, and cannot prove a figure of v0.1.28 shows v0.1.28. The refused push happened at v0.1.28 and the register shipped at v0.1.26, so several of the twelve figures are inherently of the past — and a reconstruction wearing a caption is a claim of authority nobody granted, which is the exact failure this book is about. Each figure is now taken by checking its tag out into a git worktree, serving it on a port used once and never again, photographing it, and tearing both down in a block that runs whether the capture worked or not. Two gates follow, because there are two claims: a past figure must be re-derivable from its tag, and a present one must still match the live page or the build fails. A provenance rule is added. Every load-bearing claim about what this estate means must declare itself stated — a verbatim quote, with the build re-reading every one out of the source it names — or drawn, the writing session's own reasoning shown in the reader's view. The sibling atlas carries 17 anchored connections against 151 authored ones and tells its reader not to confuse them; this book's likeliest failure is blending the two, which is the same error as apparent authority: nobody decided it, and it binds anyway. And a chapter is added for where this estate contradicts itself and what it does not say — computed rather than recalled, both sides of every contradiction quoted, and the named absences printed. Seventeen chapters now, plus an appendix carrying the harness so any figure or number in the book can be re-derived rather than believed.
v0.1.33 27 Aug 2026 A book commissioned, and its brief published before it exists. A Key Means Nothing Alone — one volume explaining what this site built, why the concepts are shaped as they are, how it composes with RiskMandate.ai, and, as an equal partner, what none of it proves. The commissioning brief is modelled on the sibling estate's book round: a writing round rather than a build round, one book per fresh session, markdown as the source of truth, a PDF that reads start to finish with no link followed, a machine surface carrying hashes, and the honesty positions travelling inside the chapters rather than quarantined in an appendix. Fifteen chapters in five parts; a chapter written as a contract with the RiskMandate team (references never copies, the component contract, and where the chain hands over — the registry's half ends at finding, and risks are theirs); twelve figures each carrying the site version and the SHA-256 of the page, with a gate that breaks the build when a screenshot stops matching what it shows; and an acceptance test that fails the book if a reader finishes believing the register is trustworthy. Published before the book on the same principle as the four rules: a specification that arrives after the thing it describes cannot be used to check it.
v0.1.32 26 Aug 2026 The bench — a place to ship MVPs and experiments, with one mandatory field. A new first-class section collecting what this site has actually built: the register, the mandate hook, grant measurement, the building blocks, the assessment and the synthetic-reader programme — five of six built and running. Modelled on graphs.sgit.ai's working surface, where each experiment lives in its own folder with its own code and is iterated release by release against a brief. The section's rule: every entry must state what it does NOT prove, and the build fails without it — verified by emptying one and watching the generator exit non-zero. That is the whole difference between a bench and a showcase, and it is why the limits render at equal weight beside the claims rather than smaller or greyer. Named the bench rather than labs deliberately: in this industry labs signals unsupported, may vanish, and these are the most rigorously checked artefacts on the site — they are simply not finished products. A bench is where you put something to test it and read the result honestly.
v0.1.31 26 Aug 2026 The building blocks — brief #3 written from the two v0.33.62 briefs, and built. Document 09 specifies nine reusable primitives (tier and evidence badges, freshness chip, grant node card, mandate card, the authority/enforcement split, the delta block, the three-term comparison and the grant tree) as components with rendering rules rather than pictures — because a mockup is thrown away and a block is used. Its load-bearing rule came from the build, not from design: a tier is a property of a node's relationship to the tree, not of the node, so a tier badge must be able to show what defeats it and a defeated control never renders as a boundary. And it adds the one block that exists because building taught the pack something it did not know — the authority/enforcement split, two indicators and never one, because the enforcement is real and the authority is a fixture. Shipped as assets/gm-blocks.css plus a gallery rendering the actual documents — both measured library entries and the signed mandate — so the defeat-path rule is visible working on real data that is wrong. On its first render the gallery caught two schema violations in the pack's own library, and all of them were in the hand-assembled entry while the tool-generated one had none: GM1's a grant is discovered, not authored proving itself on this pack's own data. The generator now fails the build on unrecognised vocabulary, verified by injecting one.
v0.1.30 26 Aug 2026 The deliveries get recorded, and the registry pack stops calling its own subject unbuilt. This estate records every correction meticulously and had recorded no deliveries at all — and the cost was visible: three days after the register shipped, the registry MVP pack still described it as entirely unbuilt in three places, because nothing in the discipline obliged anyone to write down that something was finished. Two fixes. Document 08, the build record: what moved from specified to built across v0.1.26–v0.1.29 — the register, the pack, the enforcement point, two measured library entries — with a fetchable artefact named for every claim, the four findings that cost something to record, what the readiness report's six blocking questions became (three closed by execution, three still open), and a flat list of what is still only written down, because a build record that lists only deliveries is a sales document. And C33/C34 in the registry pack: its own unbuilt status superseded rather than edited, C7's commit-graph model marked implemented rather than queued, the sgit reconciliation recorded as closing document 03's original dependency flag — and the honest limit kept in view, that the registry is built and the trustworthy registry is not, since the root is a fixture and the write path is a reviewed git commit rather than the append lane the pack designs.
v0.1.29 26 Aug 2026 The library's second entry, and the two defects it found. Entry #2 is a GitHub Actions runner, measured by tools/measure.py running inside it rather than written from documentation. It is deliberately the other end of entry #1's node n3: an agent's push ends there, and this is what happens next, so the two join at that edge and together are the blast-radius path. The contrast is the useful part — the hosted agent sits behind a mandatory egress proxy while the runner that deploys its work reached every host unrestricted; the agent retains a session record (its grant is a union over prior turns) while the runner retains nothing (a tree over the present); and the runner's grant is the only one in either entry declared up front, in a permissions: block the job cannot widen. Two defects surfaced by measurement rather than review, both recorded rather than tidied away: the tool labelled the OS user separation a boundary while the next node showed passwordless sudo succeeding — the pack's own setting that reads like a boundary warning, reproduced by an automated measurer, because tiers were being decided in isolation rather than against the tree (corrected, with the mislabelled node kept visible); and the pre-push hook does not travel with a clone, since the file is committed but the core.hooksPath config that activates it is local — the control is one un-run command away from being absent, which strengthens the case for moving the check off-machine.
v0.1.28 26 Aug 2026 A push refused by something that is not the agent — build-order step 1, built and tested. The Grant & Mandate pack gains document 07: a mandate authored deliberately narrower than the measured grant (permitting claude/** while the library entry records the environment can also push to dev, the branch that deploys this site), compiled into a pre-push hook. The acceptance test ran: error: failed to push some refs, origin/dev unchanged, a permitted push succeeding in the same minute — git's refusal, not the agent's compliance. The tier reached is stated rather than claimed: setting, not boundary, because the hook sits inside the grant it bounds and --no-verify still gets past it. Two findings the exercise produced and no diagram would have: within the hour the control refused the release that was carrying it, and the correct remedy was the issuer amending the mandate — v1 was narrower than the authorisation that actually existed — rather than any bypass; and the measurement tool, now runnable anywhere and re-run in the same environment, independently caught its own tier change, which is the drift detector working one commit after the improvement. Recorded with the standing limitation that the mandate's issuer is the fixture root, so the enforcement is real and the authority is not — two halves that come apart, and only the second is waiting on a real enrolment.
v0.1.27 26 Aug 2026 The Grant & Mandate dev pack — the layer above the register. A first pass at the pack two v0.33.62 briefs specify: building blocks tying grant and mandate to the RiskMandate product — a grant document (measured), a mandate document (authored, issuer-signed, interval-bearing), the delta between them (excess, shortfall, blind spots, computed and never stored), and a library of measured grants. The architecture is one hard line the pack states harder than the briefs did: the registry holds the library (no personal data ever), the risk product holds the instance, and the instance stores references, never copies — which is what makes a finished pack shareable without disclosing anyone's estate. Three constraints a reader must not re-derive (reality before the risk register; the library/instance split; the three-term comparison whose blind-spot delta is the only thing that makes a self-report falsifiable), and two findings inherited settled (the grant is discovered, not authored; it is authority, not authorisation). The pack adopts Cedar and graphs.sgit.ai's conventions rather than reinventing them, and builds only the one thing nothing provides: a mandate with an issuer and an interval. Its first library entry was generated by measuring the site agent's own container — which refused to measure itself, blocked by an account-level classifier evaluating outside the agent's loop: a boundary-tier control caught working on the measuring agent, and the cleanest demonstration of the pack's own three-tier test, produced by accident.
v0.1.26 25 Aug 2026 The registry, live — the first MVP ships as files. Eleven records at /registry/: identities, four assumable roles with published keypairs and drop-in sgit keystores, mandates, a grant with the document-12 tree and control labels, acceptances and revocations — every statement a signed file at a constructed URL. sgit-native by execution: bundle, fingerprint and signature formats reconciled against sgit-ai v0.16.0 by round-trip in both directions, so sgit pki import + verify work on the records directly. Ten records are fixtures with private halves published on purpose (change-control C3 as an entire register); one is real (private_key_published: false), keeping the flag evidence rather than a column. Six expected verification answers ship as data and the registry validator reproduces all six; the excess-authority view (41 permitted vs 1 mandated, acceptor none) ships for downstream risk consumers. The record model is C7's commit graph — no seq/prev; the public git history is the chain — making this the first implementation of that correction. The write path today is a git commit reviewed by a maintainer, stated as such; the lane-based phase 2 stays open. Preceded by the readiness report the briefing pack asks a fresh session for: six blocking questions, three answered or dissolved here by execution, three still the project lead's.
v0.1.25 21 Aug 2026 MC11 — the readiness review's finding, recorded where findings live. The pack was read for the first time as an implementation brief — can v3 actually be built from these documents? — and the answer surfaced a gap the register did not hold: document 07's five grant-ordered scenarios land as library examples in phase 1, but scenario 5 (operations — grant: the estate) has no tree to point at — no nodes, no facts, no tiers, no re-run method anywhere in the library, whose surfaces stop at agentbox. Net-new curation of exactly the kind the Wardley maps rate as this tool's genesis component. Recorded as MC11 with open decision MC-D27, blocking the scenario half of phase 1 while the fix-list half stays clear — and recorded at all because the review's other blocking items (who authors level one, the vocabulary tension) turned out to already be on the register as MC-D16 and MC-D23, while this one lived only in a chat message. Capture reads as coverage until an implementer asks it for a tree — which is itself a finding about hindsight packs, and now it is written down.
v0.1.24 21 Aug 2026 The final text of run 001's informed analysis, which its author was still revising when v0.1.23 shipped — so v0.1.23 published an intermediate draft of that one file. Tightened throughout by its own hand; every load-bearing claim re-verified against the code before this release: the truncation (excess.slice(0, 4) over a frightening-first sort), the self-scroll (scrollIntoView({block:'start'}) under a sticky nav with no scroll-margin-top), the flagship example's omitted benign capability, and story V6's test checking availability rather than discoverability. Recorded here rather than quietly overwritten, because the difference between the two texts is exactly the kind of thing this project's own change-control rule exists to make visible.
v0.1.23 21 Aug 2026 Synthetic readers — the instrument that tests the pages, and the first run actually performed. It sits below the Map Your Case pack and deliberately outside it, because it feeds the pack rather than belonging to it, and because its output is simulated material that must never be shelved beside the documents it tested as though it were the same kind of thing. Two agents. One is a browser and nothing else: it navigates, scrolls, clicks where it is told, screenshots, and is configured never to pass page text, structure or purpose on. The other is an archetype in a fresh context that receives pixels and nothing else and points spatially — “click the first box in the row of four”, “scroll up a little” — never naming an element by function unless it can read that word in the image. Three archetypes, published as property lists rather than portraits with their sources recorded nowhere: the shipping founder, the agent-security practitioner, the adoption executive. Four fixed instruments: the elevator pitch told before the first screenshot, the expectation question asked before the page can influence it, the comprehension question at every stop, and the closing question — the first and last of which are the measurement, since neither half is generated by the page. Patience is exogenous: six screens, eight clicks, ten minutes, fixed in advance and spent by mechanical rule, so an abandonment is a measurement rather than a story the model tells about itself. Simulated run 001 was performed against /assess at v0.1.22 and is published in full — six screens, verbatim reactions, the budget ledger, the renderer's notes on how each spatial instruction was resolved. It found four defects. The sharpest: “and 5 more” is inert — a span.dim with cursor:auto sitting at exactly the point the reader wanted the rest of their own delta, and the reader named the cost — “that's the kind of small dead end that makes me stop trusting a page… I'm not going to try a third time.” Also: the entry point speaks the project's vocabulary rather than the reader's (“jargon soup”, in the first ten seconds, from a reader who then liked the tool); the escalation sentence is simultaneously the most interesting and the least understood claim on the page; and loading an example drops the reader into the middle of the snapshot card. And it confirmed two design decisions from the outside, by a reader that could not see the reasoning behind them: the chokepoint sentence — “that is one thing to change, not 9” — was quoted back as the reason it would act, and conceding the value before naming the danger landed with the archetype predicted to be most reactance-prone. The pre-registered prediction for that archetype was wrong, and is published unchanged. Zero confabulations across six screens: every string the reader quoted was verified verbatim against the page's own DOM after the run. Findings flow one way into the pack's change control as MC5–MC9 with six new decisions — including the amendment that makes the arrival condition (cold or pitched) a per-run parameter rather than retiring the brief's rule, and the discipline that the artefact is not edited while a run stands against it: the fixes ship as a version bump and the run is re-run. The schedule of what has not been run is published beside what has.
v0.1.22 21 Aug 2026 A second dev pack: Map Your Case — the pack for the assessment, and written the other way round from its sibling: the registry MVP pack was design first, build later; this one is written after the thing it specifies, because the tool shipped twice (v1 on 20 August, v2 the next day) before its thinking was captured anywhere but commit messages. Thirteen documents plus a change-control appendix that opens with entries rather than waiting for them. Documents 01–04 are capture — thirteen principles each stated with its reason and the check that would catch a violation, because most are implemented as absences and an absence is the easiest thing in a codebase to break politely; the library; the model with its three documented traps; the architecture. Documents 07–09 and 11 are specification, expanded in prose first so v3 is built from documents rather than memory. Two project-lead briefs (v0.33.61, from this morning's voice memos) are processed and operationalised as the pack's programme documents. Levels and variants are two axes: levels vary depth, variants vary rendering, and conflating them makes a poor result undiagnosable — so the design is a grid, not a ladder; everybody starts at level one, because expertise predicts vocabulary and not whether somebody knows their own grant, and the advanced user — largest grant, strongest prior — is the reactance case, not the easy one; five scenarios ordered by grant size rather than job title, dictation to operations; and the three sets — mandated, exercised beyond the mandate, held and never used — with the concession made first (the gap is not only where the danger is; it is also where the value came from) and the third set as the product, because it is the one nobody can defend and it shrinks without anybody losing anything. The screenshot boundary is the instrument: a tabletop of two agents — one rendering (a caller of an existing browser-automation service), one reading pixels and nothing else, never told the page's purpose, clicking spatially; the page under test a fixed artefact authored before the run, because a page generated during the run measures the model agreeing with itself; the patience budget exogenous — screens, minutes, clicks fixed in advance — so abandonment is a measured event rather than a coherent story; and the honest limit stated as the method's credibility: synthetic readers find defects, not preferences — they clear the levels, humans judge the variants. The two 9 August simulation rules travel verbatim, with the marker specified to survive export (filename, headers, beside every quote) and the archetype exception made testable: if the person it came from, or a colleague of theirs, would recognise them in it, it is a portrait. Four Wardley maps agree on one finding — the scarce components are all editorial, none mechanical — which sets the build order: documents before code, tabletop before build. And document 12 is the extra one a hindsight pack owes: v1's six instructive mistakes, the bugs that became principles, and what was verified before each ship. Recorded in the registry pack as C32 with decision 45: document 14 there stays the registry-side view, and shared decisions cross-reference rather than renumber.
v0.1.21 21 Aug 2026 The first document in this pack written by somebody who was not in it. An outside session took the briefing pack cold and answered one question — if this were implemented as specified, what would it look like? — returning twelve screens as real markup and a debrief. It was checked before any of it was adopted, because a document arriving claiming fidelity is one to verify rather than trust: all seven load-bearing strings from document 08's protection table appear verbatim; the C8 citation behind its auditor finding is accurate; and it loads with no framework and no third-party request, so it costs nothing against the conformance claim. Two things needed correcting and both are recorded rather than quietly fixed — its proposed C25–C28 collided with numbers taken while it was writing, so they are adopted as C27–C30; and its third finding says document 08's rule for nobody "specifies the glyph and stops", when 08's own example does carry the trailing clause — what is missing is that the clause is mandatory. The document is published as delivered with those noted at the head, because sources stay verbatim and that applies to another author's as much as to the corpus's. What it found is the interesting part, and five of the six are things the ASCII form could not have surfaced — a 78-column monospace block has no viewport, no colour, no interaction and no wrap point. Colour re-collapses the five result states: red denied and amber unreachable merge for a substantial fraction of readers, grey not checked and grey unknown merge for everybody — so the rule is never fewer than two channels, and the word is always one. The badge's wrap point is a design decision: breaking between state and verifiable-by leaves a bare ✓ beside a claim with "nobody · no method" on the line below, which is the exact misreading the badge exists to prevent, produced by a line break. And a column of five ticks is a page-level tick — which document 08 forbids, and which no individual rule was broken to produce; the build's mitigation is partial and is recorded as partial. Two requirements from documents 12 and 13 turned out to have no owning screen, since both name screens specified before those documents existed — a story with no screen is how a story quietly does not ship. Adopted as C27–C31 with decisions 43–44. On integration: the delivered file inlined a copy of this site's design tokens, and its own note says a drifted copy of a design system is worse than none because it looks current — so the copy is dropped and the real stylesheet linked, its tab switcher is now a <sg-screens> custom element like the rest of the site's JavaScript (with arrow-key navigation added, since a role="tablist" that cannot be driven from the keyboard is an ARIA role making a promise the markup does not keep), and the page carries the site's nav so it inherits the participant disclosure and the versioning — which was one of the document's own open questions. And the exercise established something separate from what it found: the briefing pack works, and Appendix C rates know your users and listen to your ecosystem as not practised — this is the first evidence in the record of what those doctrines are actually worth.
v0.1.20 21 Aug 2026 Appendix C — Doctrine: Wardley's forty doctrines, explained for readers who know the maps and have never met the doctrine, with this project rated against every one and the whole thing built as interactive visualisations. Doctrine is the layer under the map — the maps are context-specific and doctrine always applies, which is why an organisation's ability to handle a hard problem tends to track how well it practises doctrine before any strategy is chosen. The result is not a score, and the shape of it is the finding. Of the 35 doctrines that can be rated at this size, 17 are practised, 12 partly, and 6 are not; five more need an organisation and are marked no basis yet rather than scored, because rating team structure with no team would be theatre. The pattern is uncomfortably clean: this project is strong exactly where a documentation-heavy solo effort can be strong on its own — a common language, transparency, challenging assumptions, knowing the details of what it measured, standards, humility — and weak on every doctrine that requires other people: know your users, listen to your ecosystem, be the owner, distribute power, inspire others, exploit the landscape. Which means the two findings this pack already carried are not two problems. Internal FAQ 11 — nobody outside the project has been asked whether this is a need — and REP-0001's empty Sponsor field are the same doctrinal hole appearing twice. And it changes what happens next: Phase I is nine doctrines, five practised, three partly and one not — know your users, which gates everything after it — so decision 39, ask five operators whether anybody has ever asked them to prove an agent's authority, is a Phase I doctrine fix rather than a nice-to-have, and it needs no registry, no REP and no code. Every rating names the artefact it rests on, so a reader who disagrees has the evidence in front of them; the raw data is published as doctrine.json. Recorded as C26 with decision 42. Appendixes are re-lettered so the letters follow reading order and change control keeps the last: A the PR/FAQ, B REP-0001, C doctrine, D change control. Also in this release, finishing the previous one: the assessment tool gains the picture the memo asked for — a drawing of your machine with the terminal and your assets around it, each one clickable and drawn only if your answers kept it, with a toggle back to the graph — and every capability now opens the evidence pack behind it: each claim on the path, its evidence class, the weakest evidence on that path, and how to go and check it yourself.
v0.1.19 21 Aug 2026 Map your own case rebuilt, after the first walkthrough by a reader who was not its author — and the defects that walkthrough found were more useful than the design that produced them, so they are recorded as C25 rather than fixed quietly. The instructive one was not a UI bug. A "+ add an agent" button added a whole new case on every press, and a reader trying to add a second agent ended up with a dozen. The button was not the problem — the model was: the tool had been built around cases, which is how the design documents think, and a person does not have cases, they have agents. v2 has none; you pick agents, and one assessment covers all of them. A design vocabulary had leaked into an interface and produced something that looked like a coding mistake, which is worth recording in a pack that is fifteen documents of design vocabulary. What v2 does differently. The snapshot comes first, filling in as you go, because the thing worth sending somebody is a summary and nobody reads three screens of preamble to earn one — the privacy material is still there, demoted to a side note where it belongs. You pick named products — Claude Code, ChatGPT, Le Chat and the rest — inside four surface archetypes, instead of translating your own setup into "on my machine" or "hosted by a vendor". The tree is now a graph with an inspector: click any node for what it means, what stands in the way, and where the claim came from. Facts prune it — no credential files, no branch, because a picture of a machine that is not yours is not evidence about you — and "not sure" keeps the branch and marks it, since assuming absence is the comfortable error. Escalation is drawn as an edge: execute programs as you reaches the agent's own config and around the folder restriction, which is what makes the "setting" tier land rather than being asserted. Intent offers only what is actually reachable and now includes benign uses — hold a conversation, draft a document, explain a file — because a tool that lists only frightening capabilities is measuring its own framing. The gap is a picture, and clicking any of it lights up the path. Two removals. Risk acceptance is gone — acceptor, interval, accept and decline belong to the risk product, and this tool's job ends at here is what is possible, and here is the delta. And "what you can do about it" is now controls: tick what is already true and the numbers above move, with each control's effect on your own gap computed rather than asserted. One published claim corrected: a separate user account was described as "an hour". It is not — paths, permissions, editors and agents all assume one account, and desktop apps often cannot do it at all. The reason almost nobody does the most effective thing available is that it is genuinely hard, and implying otherwise blames the reader for a real obstacle. Engineering: the section is its own folder — two pages, five ES modules split by concern, six custom elements, its own stylesheet, and no giant HTML file. The graph is hand-written SVG with no charting library, because a CDN dependency would put a third-party request on a page whose whole argument is that you can open the network panel and watch nothing leave; it still makes only same-origin requests, and that is now checked rather than claimed. New: the library of trees, where every tree is drawn and its raw JSON sits beside it with the selected node highlighted in both.
v0.1.18 20 Aug 2026 Two borrowed formats added to the registry MVP pack as appendixes, and they were borrowed for the sections they force rather than for their style. Both mandate the two disciplines this pack already ran on informally — write down what you rejected, and write down what you do not know — so neither is a foreign template: the pack's honest tensions is an unnamed Rejected Ideas, its open questions is Open Issues, and its decisions register is a Status field nobody had formalised. Appendix A is Amazon's Working Backwards PR/FAQ: a press release dated at a hypothetical launch, an external FAQ, and an internal FAQ written to hurt. It is the only document in the pack that reasons from a customer inward, and it produced three findings fourteen design documents had not. The honest press release is narrower than the pack's own framing — every draft wanted to say know what your agents can do, and the register cannot support that sentence; the published version says what an agent was authorised to do, which is true, less exciting, and correct. The customer-quote slot is published empty, with the reason in it: the format requires a quote from somebody who used the thing, there is none, and inventing one is exactly what this site's participant rules forbid. It is now a dated readiness marker — the day it can be filled honestly, phase 4 has actually happened. And two internal-FAQ answers name work the build order does not contain: the model that monetises best contradicts the positioning, since metered verification requires observing every check, and whether "checkable by a third party" is worth anything to anybody outside the project has never been tested — the cheapest next step in the whole pack, and it needs no registry. Appendix B is REP-0001, the design as a normative specification in Python's PEP form: RFC 2119 keywords, every recorded corrective applied, and the sections PEP 1 makes mandatory — Security Implications, How to Teach This, Rejected Ideas and Open Issues, three of which are where this design has most to say. It is the one place in the pack where the schemas are current rather than superseded-with-a-note. Its Status is Draft and its Sponsor field is empty, because PEP 1 requires a champion and this has none — the pack's standing problem given a form field rather than a caveat. Change control becomes Appendix C and stays last. Recorded as C24 with decisions 37–39, and the downloadable briefing pack is rebuilt to match.
v0.1.17 20 Aug 2026 Three changes to the registry MVP pack, all of them about how it is read rather than what it says. Change control becomes an appendix and moves to the end. It was document 06, sitting in the middle of a numbered sequence while being the one document here that never stops growing — it now runs to twenty-three corrections and thirty-six decisions, which is longer than most of the documents it corrects. Its published URL is unchanged; only its position and its title moved. The reading advice moved with it and is worth keeping: read it second if you are about to build from documents 00–04, so you read them with the errata in hand, and last if you are reading the pack through — never not at all, because draft-1's definition of grant was superseded on the day it shipped. The pack now states its own status honestly, recorded as C23 rather than edited in quietly: it is a design pack with one shipped consumer. Document 10's honest reading — everything at phase 0–1 is designed and nothing is built — is still true of every registry feature and no longer true of the pack, and the distinction that matters is that what shipped is a consumer of the model rather than a piece of the registry. Two findings come with that. The build order gained a phase nobody planned, before phase 0: the first useful thing this pack produced needed none of the infrastructure the pack is about — it needed a library and an interface, not a registry, and a design pack whose first shipped artefact bypasses its own architecture should say so out loud. And one of the pack's own standards was found unmeetable in the field: document 10 requires a named acceptor, and the first interface to try it discovered a name is a fact about the visitor's organisation with nowhere safe to live, so it offers a role. The standard is not wrong; it is unreachable on a page that stores nothing about its visitor, and the two constraints are in genuine conflict. And the pack is now downloadable as a briefing pack (306 KB): the fifteen sources, every supporting brief, the site's machine-readable front door, and the reference implementation — with a briefing for a fresh session that asks it to read the supporting material, then the pack in detail, and then answer one question honestly: do you have what you need, or what has to be answered first? It names six things that will trip a new reader, and it asks for blocking questions rather than a confident plan, because a pack with a third of its decisions still open is one where a confident plan probably means the reader missed them.
v0.1.16 20 Aug 2026 The first thing on this site that is built rather than specified: Map your own case, with document 14 as its specification and a ninth v0.33.61 brief behind it. A visitor picks the agents they run and the surface they run on, ticks what they actually meant the agent to do, and sees what is reachable that they never intended — with a decision per gap carrying an acceptor and an interval, which is what a risk register consumes. It exercises the grant tree, the three-tier control test and the prohibition rendering against a real interface rather than a mockup. Two rules shaped every decision in it, and both cut against the obvious build. The first: a completed assessment describes which agents somebody runs, on which machine, holding which credentials, with which containment — and assembled, dated and ranked, that is a serviceable plan for attacking them, which the site asked them to write down. So the page stores your choices and never your answers: identifiers from a public library, fixed options, and dates derived from them. Implemented as strictly as it can be — there is no free-text input anywhere on the page, which turns "we do not store what you type" into "there is nothing to type". The visible cost is the acceptor: the pack's standard is a named acceptor, a name is a fact about your organisation, so the page offers a role and cannot meet the pack's own standard — recorded rather than hidden. The second rule is measured rather than intuited: a strong threat with a weak answer produces denial, not change. The standing meta-analysis on fear appeals finds defensive response and behaviour change correlate negatively, so a frightening picture of somebody's estate with no credible action performs worse than saying nothing. Every case therefore ends on something the visitor can actually perform, with the number of their own gaps it closes computed rather than asserted — and an action that closes none says so, including one worth doing that does not shrink the tree. The hosted case is the one most likely to backfire, because the containment is the vendor's — uninspectable, unchangeable and, tested rather than assumed, unattestable. That is zero efficacy by construction, so it ends on a request rather than a remedy: ask your vendor for an endpoint that signs an audit record they already hold, for a named relying party. The build added one thing the brief did not — the hosted grant reaches what you put in front of it, and that part is yours. Two more things worth naming: browser storage here is the site's own claim made checkable, not a placeholder — there is no backend, so the no-collection claim is architectural rather than operational, and a "show me everything stored" panel prints the exact bytes; and on a local tree every excess path bottoms out at the same node, so the page says it once at the top — this is one problem rather than eleven. Change control gains C20–C22 and decisions 29–35. The nav gains a sixth group; documents 08, 10 and 12 extend their cross-reference blocks. Tested across the paths that actually fail: a library that moved since your last visit, a browser refusing site data, and a local-folder copy of the site, which gets an opaque origin and is the feature that breaks first in a downloadable bundle.
v0.1.15 20 Aug 2026 Two more v0.33.61 briefs, and the two pack documents they produce. 12 — The grant tree and control labels takes the side the pack had specified least and needed most, once C1 made the gap between grant and mandate the product. A grant is a tree of subgrants, so blast radius is a path through it, not an item in a list — and the load-bearing part is not the tree but the label on each node, above all who enforces the thing standing in the way. The general test needs no vendor-specific claim, which matters because those age in weeks: a control bounds a grant only when it is enforced by something the grant does not include. That gives three tiers — boundary, setting, expectation — and it puts most of what people currently rely on in the middle one, the tier that reads like a boundary and behaves like a setting. A folder restriction enforced by a tool running as you, inside a grant that includes running programs as you, is the same object as a safe in a house you handed the keys to; and a permission prompt disableable by a flag the agent can write is an expectation wearing a setting's clothes. The document also adds the shortfall — mandate minus grant, the region C1 never named, which hurts operations rather than security and is the harder of the two to detect — reconciles prohibitions with C12 by making them a dated generated view over a stored allow-list, and corrects a metric the pack had not stated and would have adopted: counting acceptances is the one measure that inverts under pressure, because it is maximised by making risks easy to accept, so declines, escalations and risks that could not be stated get instrumented first. 13 — Keys and signatures settles which things in this design get keypairs. Two principles adopted: a secret is defined by expectation, not by content — which explains read-keys-yes and write-keys-never in one line, and needs the intention recorded at issue, because a deliberate publication and a leak are indistinguishable six months later — and a signature's value comes entirely from the scarcity of the private half. One proposal declined: per-object keypairs with the private half published. It leaves a hash wearing a signature's clothes, which is worse than a hash because a verifier checks it, succeeds, and concludes something false; it defeats its own stated use, since sealing to a specific object requires exactly the scarcity it removes; and it would make C3's fixture flag true on every row. A flag that is always true is a column, not evidence — so declining the proposal is what preserves C3 rather than conservatism. The rule adopted instead: a key belongs to whatever can keep a secret, and everything else is signed by something that can. Change control gains C16–C19 and decisions 21–28; documents 02, 03, 08, 10 and 11 extend their dated cross-reference blocks, with nothing above those lines rewritten. Both briefs are published as reader pages.
v0.1.14 20 Aug 2026 11 — Observability, from a ninth v0.33.61 brief, and it answers a question this site had raised in four places and answered in none: a mandate says what an agent may be authorised to do, not what it does — so who is using it? The answer refuses the question. What is capturable is verification, not use, and the two come apart in both directions: a party that uses a mandate without bothering to verify it generates nothing, while a resolver walking the chain generates an event with no usage behind it. The error runs in the worst direction, because the party that never verifies is the party whose relying process is weakest — and it is the one this layer cannot see. So the product is the missing edges: which parties hold a mandate I issued and have never once checked it? The issuer holds both halves — who it issued to, and who wrote to its lane — so the join is computable, small, and every row is a relying party accepting a mandate on faith. Where the log lives decides what this is. A central check log at the registry accumulates who is evaluating whom across parties that never consented — the dataset C9 warned about. A check event written by the checker into the issuer's own lane is an owner observing their own asset, which is rule 1 applied to telemetry; so C14 resolves C9 rather than leaving both standing, at the deliberate cost of foreclosing the aggregate — the design that protects the positioning is the design that destroys the dataset. And because nothing is pushed, a relying party's effective revocation latency is the interval between its checks, computable before anything has ever been revoked, which also yields one of the very few mandate clauses that is genuinely decidable. Two things this does not do, stated on the page: the pack's four "records authority; it does not observe behaviour" statements stay exactly as they are, and for a party that never checks the latency is infinite and invisible. Change control gains C13–C15 and decisions 16–20; the build order is amended, not edited — observability ships in phase 3, with mandates, because the justification for building declared mandates is the evidence it produces. The brief is published as a reader page, and one question goes back to the parent project as N10: whether an append lane with no anchors configured accepts any token holder, which decides whether the relying parties you most want to observe can report at all.
v0.1.13 20 Aug 2026 Twelve top-level nav entries become five, using the two-level component sgit.ai already runs — ported with its rules intact rather than reinvented. The flat nav had been growing one entry per section and was wrapping to two rows on a laptop and four on a phone: measured, the bar was 105px at 1400 and 1100, 145px at 760, and 227px at 390. It is now 55px at every desktop width and 92px on a phone, where the whole menu collapses behind one button so the bar stays a single row. Groups: The registry (why they don't exist, the four rules, identity & mandate, build order, prior art), The layers (bootstrap, enrolment, execution, what already ships), Origins, Docs (documents, dev packs, the registry MVP pack) and Site (comms, releases, engineering, the disclosure). Two rules carried over from the parent's implementation and worth keeping: every group label is itself a link to a real page, so nothing on this site is reachable only by opening a menu — the submenu is a shortcut, never the only door; and opening is CSS-only for a mouse (:hover) and for a keyboard (:focus-within), with script needed only for the phone button and for touch, where hover does not exist. If nav.js never loads, the nav still navigates. One addition of our own: Escape closes whatever is open. The "here" state is driven by path prefixes rather than exact matches, because most of this site is pages that are not themselves in the nav — a document, a pack chapter, a redacted review — and without prefixes those would all render with nothing highlighted.
v0.1.12 20 Aug 2026 10 — User stories, features and workflows, and a cross-link pass over the whole pack. The delivery document turns nine documents of design into something a reviewer can sign off: six users — verifier, agent, issuer, processor, policy owner, and auditor as its own seat, because a verifier asks about now and may stop early, while only an auditor reads the log backwards and would notice if history were quietly rewritten; twenty-four stories, each with a test that can fail, because a criterion that cannot come out negative is a description wearing a story's clothes; fourteen features whose status column reads, honestly, that everything at phase 0–1 is designed and nothing is built; six end-to-end workflows; the mandate lifecycle as states; a traceability table; and a flat list of what the pack does not deliver — enforcement, receipts, confidentiality, attestation, a graph browser, a trust score, and estimates, the last because a fabricated number in a delivery document outlives every caveat attached to it. Writing it found two things, both recorded in change control as C12 rather than tidied away: the policy workflow is specified and mapped and has no acceptance test, because the build order's four phases were written before the policy layer existed as a concept; and "log every processor decision publicly" conflicts directly with "the acknowledgement tells the agent nothing" for declined submissions — a public decision log is exactly the oracle the blind ack exists to withhold, and today the blind ack wins by default, which is a decision nobody made. Also: documents 00–05 and 07 each gained a dated added after publication block pointing at the later material that bears on them. Nothing above those lines was rewritten — the pack supersedes rather than edits, which is the rule the change-control page exists to implement.
v0.1.11 20 Aug 2026 The parent link, made obvious. This site is one of three under sgit.ai — which lists all three on its network page — and until now the only way back up was a bare "sgit.ai" entry in the last footer column. A reader landing on a deep page had no visible signal that this is part of a larger project, which matters more here than it would elsewhere: the participant disclosure turns on the relationship, and the whole design is an argument about a CLI that ships from the parent. Now: an accent-outlined ↗ part of sgit.ai badge sits directly beside the brand in the nav on every page, and the footer carries a network line — parent, nhi.sgit.ai, sentinel, and the network page — set between rules above the disclosure rather than buried in a link column. Two layout fixes came with it: the footer grid was declaring four columns for five children, so the last one had been silently wrapping to a second row since the theme was ported, and the badge is hidden in print alongside the other nav chrome.
v0.1.10 20 Aug 2026 Two documents added to the registry MVP pack, both drawing what the earlier ones describe. 08 — UX mockups writes the register interface out as intended output, screen by screen, because the wording is the design: the agent page that must answer six questions without a reader leaving it, one badge expanded into a transcript that also lists what the check did not establish, an index reporting its own unverifiable fraction on the front page, a mandate composer that shows excess authority before the mandate is signed, and a policy page that prints "0 rows" and "detects nothing" on the same screen. Seven strings are marked load-bearing — each the only place a reader learns something the rest of the screen cannot tell them — and three absences are deliberate: no trust score, no page-level tick, no live capability ever rendered. 09 — Wardley maps is the estate's first use of mermaid's wardley-beta diagram type, so the maps are text in the repo and correctable in a pull request rather than hand-drawn beside it. Six maps, each stating its claim and where the site agent's own confidence is thinnest: all the novelty sits in four schema objects; a rented agent's evidence chain terminates in a component that is commodity and worthless; the two absences are not underneath the shipped surface but on top of it, in Genesis; a policy verdict cannot be more solid than a badge two layers down. The working grammar is recorded with the four constraints found by running the parser, so the next author does not have to.
v0.1.9 20 Aug 2026 Four more briefs, and the largest architecture change the MVP pack has taken. History is the append-only log dissolves a tension between two of this site's own published rules: revocation-as-append and size-bounded records only conflict while an entry is a record that accumulates, and the entry should be a file inside a commit graph instead — which also makes rule 1 topology rather than policy, because a third party has nowhere to write into an owner's record. It corrects a comfortable assumption too: objects are immutable, the reference is not, so append-only history is a policy about one pointer — hence a proposed fifth rule, published as a proposal rather than renumbering the four. The notary brief separates signed-once from checked-every-time as two products, and shows that metering and surveillance are one capability. The register interface makes a badge on every edge the primitive, a policy a query that must return empty, and reports a tested negative: inside a running rented session no attestation device is present and nothing is signed. The grant brief is superseded in place by a sharpened version adding the argument that a deny-list mandate widens silently every time a provider ships a feature. Pack change control gains C7–C10 and five decisions. And the open questions are reclassified: four of six now read argued, decision pending with links, two stay genuinely open, and eight new ones opened on 20 August are captured.
v0.1.8 20 Aug 2026 New Origins section, closing the gap a cross-reference review named first: a site arguing for provenance discipline was presenting itself as if it began five days ago. The four-act arc — PKI as messaging, then provenance, then agent identity, then substrate — with the framing number stated plainly (roughly 110 documents against ~3,900 lines of code, all of it written in a six-day burst in February 2026 and not materially changed since), the ideas tried and abandoned, and thirteen primary sources published verbatim: the February self-challenge on whether PKI is the right primitive at all, the supply-chain ≅ agent-chain isomorphism drawn four months before the programme that needed it, the four-key/four-mode taxonomy that admits only Mode 1 exists, the document that retires the shipped registry, and the honest retreat on key custody. Every one re-checked for secrets and identifiers before publication. New prior art page: the registry built in February and superseded in June, which turns rules 1 and 4 from assertions into checked claims — and carries forward the limit the MVP inherits, that a hash chain proves a reader's own view is consistent and cannot alone prove every reader saw the same one. And a redacted public edition of the review itself: the original names a customer and unremediated findings against running code, so it is not published, and the derivative states exactly what was removed and why.
v0.1.7 20 Aug 2026 Three corrections to what already ships, forced by a Librarian cross-reference review of the corpus repo at v0.33.61 (110 PKI documents against ~3,900 lines of PKI code). The first is a correction to this site. v0.1.3 stated that the shipped primitives were RSA-OAEP 4096 and ECDSA P-256 and that "anything naming those curves is describing a system that does not exist" — checked against the sgit pki documentation and then applied to the whole estate, which is wrong: Ed25519 ships (the public SSH keygen tool) and ECDH P-256 ships (SecureChannel, replay-guarded, 43 assertions). X25519 remains correct as a correction, but only for the unbuilt vault-to-vault client crypto. The source was right and the scope was not, and it is recorded rather than quietly edited. Second: the page now says which claims are code-verified and which are taken on trust — sgit pki lives in a separate repository. Third, and the strongest of the three: "no directory" is a retirement, not an absence. A key registry shipped in February 2026 — five endpoints, base-36 lookup codes, duplicate-fingerprint rejection, soft delete, and a genuinely hash-chained transparency log, 29 commits and 183 tests — and was formally superseded in June by the vault-hosted design the MVP pack operationalises. That turns rules 1 and 4 from assertions into checked claims, and carries forward the finding the MVP inherits: a hash chain with no external witness cannot detect equivocation.
v0.1.6 20 Aug 2026 Release-pipeline fix: the v0.1.5 release validated and then failed to publish, with the tag job exiting 141 immediately after printing the version. 141 is SIGPIPE. The cause was REL=$(git log … | grep -m1 … | cut …): grep -m1 exits as soon as it matches, git log is still writing, so it dies of SIGPIPE — and under pipefail that status propagates out of the command substitution and kills the job after the variable has been assigned, which makes it look like the next line failed. It is a race against the pipe buffer, so it passed on a short history and started failing once the log outgrew it — v0.1.5 was the release that crossed the line. The job now reads the history once into a variable and greps it through herestrings, so nothing upstream can be signalled. Verified against the exact commit that failed, 25 consecutive runs with no failure, and all four guard cases still failing correctly (reused version, stale version.txt, merge-commit PR flow, and the happy path). v0.1.5's content — the Packs section, the pack's diagrams, change control and tabletop, and the three v0.33.61 briefs — publishes with this release.
v0.1.5 20 Aug 2026 The registry MVP pack becomes a dev pack, in a new Packs section following the treatment established on nhi.sgit.ai: sources verbatim under packs/registry-mvp/src/, a hub with the file table and pack README, and a reader page per document (gen_packs.py). Three documents added to the pack: 05 — Diagrams (the design as eight checkable pictures, mermaid-rendered — the estate's three thirds, the record hash chain, the write path, the verification walk, the three-session demo, grant/mandate/excess authority, and the fixture flag read before the signature); 06 — Change control (what three same-day project-lead briefs correct in draft-1, recorded rather than silently patched: grant redefined as what a credential permits, the 5 June design precedence, the fixture class, agent cards and workflow signing, and one decision confirmed from two directions — plus the decisions register, four settled and four open); and 07 — Tabletop exercise (five seats, six injects, the four published rules meeting their first population, and the facilitator's rule that makes it a documentation test too). The three v0.33.61 briefs captured with reader pages: the register was designed in June, grant is not mandate, and the site access report — the last acted on directly: this site now states which third of the answer it holds and links page-to-page into the shipped documentation, and llms.txt promises the constructed-path convention agents already rely on. Packs added to the nav.
v0.1.4 20 Aug 2026 First-pass brief pack for the registry MVP, authored by the site agent at the project lead's request and published for review — five draft briefs under briefs/pack-registry-mvp__*, each with a reader page: the leading brief (open data, a single operator, LLM sessions as the first users on both sides; public in data, private in authority — build-order step 4 with the covers off, not step 6 early); the vault architecture (one public vault, records as append-only hash-chained statement logs keyed by signing fingerprint, the processor as sole write-key holder, and the four rules implemented as processor checks plus a public validator — enforcement is verification anybody can re-run); the schemas (identity, mandate, grant, acceptance, revocation; a mandate lives in the issuer's record to keep rule 1 exception-free; the registry never contains a live capability); the first-client workflows (verify, enrol, operate-under-mandate as copy-paste pages a fresh LLM session can follow — the page is the client); and the build order (read path before write path, five phases, every phase's definition of done a fresh-session acceptance test). Marked draft-1 throughout: corpus versions to be assigned on adoption. Roadmap step 4 moves to planned.
v0.1.3 20 Aug 2026 The site acted on its own review. A briefing pack (v0.33.60, 19 Aug) reached a three-layer picture — identity is a registry problem, mandate a delegation problem, and whether a delegation should produce this effect now is a broker problem — and observed that this site answered only the first. Four new pages: the bootstrap trap, why agent key registries do not exist, as a loop rather than a missing feature, with the seven workarounds and the evidence that they are the mechanism behind documented incidents; enrolment, how a key gets in starting from a keypair and nothing else; the execution broker, receipts as the third corner, the concentration risk stated plainly, and the acceptance test; and what already ships, which reframes the registry as the missing half of a feature that exists — the shipped PKI has no revocation and no directory, and those two absences are exactly what a registry supplies. Existing pages extended: the front page leads with the three layers and the reframe, mandate gains the revoked-when column, the authorisation object's fields and two principles stated verbatim, and the rules gain the four-tier capability model reused rather than reinvented. All nine source documents captured under briefs/ with reader pages (gen_documents.py). Two corrections carried: the shipped primitives are RSA-OAEP 4096 and ECDSA P-256, not X25519 or Ed25519; and the lane-address derivation is proposed — do not code against it. The execution layer is named execution broker rather than Service Twin, because a digital twin represents a thing and this acts on one. Nav and footer now come from one definition, admin/build/chrome.py, applied across every page (T3).
v0.1.2 19 Aug 2026 Release-pipeline fix, found by the pipeline's own first run. When dev advances by a merge commit — which is how a pull request lands — HEAD is the merge and the release commit is its parent, so the tag job's "the tag must sit on HEAD" check failed and the release stopped. The job now anchors every check to the newest release commit reachable from HEAD: the version in version.txt must match the newest version in a commit subject, and the tag must sit on that commit rather than on an earlier one. The reused-version and stale-version.txt failures both still fail, which was the point of keeping the second check. Verified against the five cases, including a replay of the commit that failed.
v0.1.1 19 Aug 2026 The site itself, refactored across from the PKI section of nhi.sgit.ai where it was staged, and promoted from three pages to a site. The failure: the 2019 keyserver attack as a dated timeline, the three abused properties mapped one-to-one onto the rules they produce, the append-only resolution, and a side-by-side of the same property safe and fatal. The rules: the four, each captioned with the property it turns around, plus a sequence diagram of revocation-as-signed-append, the attestation trade as an explicit two-way choice, and what vaults do and do not supply. Mandate: promoted from a section to its own page — identity vs. mandate, why it beats a bearer token, and the caution that a mandate constrains authority rather than behaviour. Build order: the six steps with live status, what this is not, the honest tensions, and six open questions published unresolved. Plus the documents section with the scoping brief captured verbatim and readable in-page, and the participant disclosure.
v0.1.0 19 Aug 2026 Site scaffold, pipeline first. The validate → tag → deploy workflow adapted from SGit-AI__Website__NHI, with validation extended to pull requests and a new canonical-host check (every page must declare a canonical on the host named in CNAME — the specific mistake a refactor out of another site invites). The shared sgit.ai stylesheet carried over with this site's additions (the rules ladder, the timeline, the claim block). CNAME, robots.txt, sitemap.xml, llms.txt, the markdown twin of the front page, and this release channel.