What you authorised and never asked for
A grant is what your agent's tools can do. A mandate is what you expected it to do. Everything in the grant is authorised — you, or a default you never looked at, authorised it. The gap between the two is what you authorised and never asked for, and it is where the losses live.
Which of these do you use?
Public profiles, contributed and challengeable. A profile is a configuration of a product listing its tools; two variants of one product are siblings that differ in a few rows. Measured means somebody ran the probes and the file is on the site; a claim means the rows are derived from what the surface is.
Or bring a measurement:
What those tools can do — before you have typed anything about yourself
Name at least one tool above.
What is this agent for?
Questions about work, never about capability: a questionnaire that asks you to enumerate permissions gets a copy of the grant back. Tick what you actually use it for.
What must never happen?
The things you would not accept at any price. These become the exclusions — and where an irreversible row in the grant meets one of these, that is the boundary of insurability, not a bigger draw.
Who would you tell if it did?
The name is the acceptor of everything in the gap that stays. Kept on your machine.
What would surprise you if it did it?
In your own words. Not what would be wrong — what would make you say “I didn't know it could do that”. Kept on your machine; compare it with the gap below.
The self-assessment, as an object
The result carries the tier of its evidence — self-reported, or self-run — and it expires: a vendor changing a default, a product gaining a capability, or an incident demoting a control moves it without you doing anything. A self-assessment labelled as one is worth more than a score labelled as a verdict.
One line you can post:
The tuple this page would submit, and does not
Counts only, by family: no paths, no hosts, no names, no acceptor, no timestamp finer than a day. It is shown so you can see exactly what a submission contains; there is no send. To submit, open a pull request adding it under probes/submissions/, and the aggregate is computed in the open — including if it shows the median gap is small.
What would prove this assessment wrong
| What happened | Whose failure | What to do | |
|---|---|---|---|
| Inside the grant, outside the mandate | The agent did something it was permitted to do and nobody expected | The grant's. It was too wide | Reduce the grant, or accept it by name |
| Outside the grant | The agent did something the measurement said it could not | The measurement's, or containment's | Re-measure. Your model of the world was wrong |
The assessment expires, and that is the product
Every assessment carries a date and the profile versions it was computed against, and it goes stale when either moves. Three sources of movement, none of which you can watch and all of which the site can:
| Movement | Effect |
|---|---|
| A vendor changes a default | Everybody on that profile has a wider grant this morning than last night |
| A product gains a capability | New rows appear in a grant nobody edited |
| An incident is published | A control claimed as enforced is demoted, and any policy relying on it loses a condition |
Free through level three; independence is what costs
| Level | What it is | Free or paid |
|---|---|---|
| 1 – 2 | The concepts, the public profiles, your grant, the questions, the gap — this page | Free, open source, no account |
| 3 | The reduction guidance and the re-check loop — this page | Free. Guidance that costs money is guidance nobody follows |
| 3 | Running the probes where the agent lives — the runner | Free. Self-run, and labelled as such |
| 3 – 4 | Your environment modelled rather than the public one: your tools, your assets, your mandate, your register | Paid. Work somebody does for you |
| 4 – 5 | Somebody running the probes in your environment and vouching for the result; watching the ground move for a named estate | Paid, recurring. Independence is the thing a customer cannot produce for themselves at any price |
The boundary, stated rather than discovered: everything about the public products is free and open; everything about your particular estate is work somebody does for you. Nothing on the paid rungs is a feature an individual cannot have; it is a quantity an individual does not need.
What this does not prove
- Anything about your actual environment. It matched profiles from your answers, or read a findings file you brought; it saw nothing itself. The tier is on the result.
- That the gap is a loss. It is authorised, and most of it is harmless most days; the irreversible rows are the ones that decide.
- That the mandate is right. Twelve purposes and ten exclusions are a coarse questionnaire; the full elicitation is an agent asking you in your own words.
- Calibration. No surprise count exists yet for any assessment made here; the validity test is stated, not passed.
Specified by brief v0.33.64 (name the question, not the concept), shaped by the precedents: one small input, the verdict first as a statement rather than a grade, the evidence beneath, no account, a result worth showing somebody, and the schema before the site. The technical term stays excess authority (grant minus mandate) in the schemas; the public phrase is a sentence, because every coined noun tested either collided or needed explaining. CC BY 4.0.