A Key Means Nothing Alone
Identity, mandate, and the exposure nobody accepted. What pki.sgit.ai built between site v0.1.25 and v0.1.32, why the concepts underneath it are shaped the way they are, how it composes with RiskMandate.ai, and — as an equal partner to all of that — what none of it proves.
Contents
What this estate states, and what this book concluded
Every load-bearing claim about what this estate means is marked, and the marking is a sentence rather than a sigil. 65 passages are quoted verbatim from the estate, each with a source that is discovered rather than asserted and re-read out of that source on every build — a quote not found where it claims to be fails the build. 48 claims are the writing session's own reasoning, shown in the reader's view rather than in a note. Do not treat the drawn claims as this estate's positions. Every quotation and its source: quotes.json.
The figures, and the two gates
A figure captioned as the past but photographed today is a reconstruction — and a
reconstruction wearing a caption is a claim of authority nobody granted, in a book whose whole
subject is claims of authority nobody granted. So every figure was taken from the version its
caption names: a git worktree at the tag, a one-shot server on a port used once
and never again, a headless browser killed in a block that runs whether the capture succeeded or
failed. Each carries the page, the tag, and the SHA-256 of that page's bytes at that tag.
Two gates, because there are two different claims. A figure of a past version is re-derivable — re-running the harness at that tag reproduces the digest, and it never goes stale because the tag does not move. A figure of the site as it stands is fresh — the digest must match the live page, and the build fails when it stops matching, which it will on the next release. That is correct and it is inconvenient.
| Figure | Tag | Gate | What to notice |
|---|---|---|---|
f01-bench-two-columns | current | fresh | The two columns are the same width. The limits are not a footnote to the claims — they are set beside them, at equal weight, and the generator refuses to build an entry whose right-hand column is empty. |
f02a-registry-at-v0.1.26 | v0.1.26 | re-derivable | The register on the day it shipped. Compare the status language with the panel below: this page already says the root is a fixture. |
f02b-registry-now | current | fresh | The same page four days later. What changed is not the architecture but the number of places the page admits something — the corrections accumulated faster than the features. |
f03-six-answers | current | fresh | Four of the six answers are NO, and they are NO for four different reasons — revoked, expired, never accepted, identity revoked. A verifier that collapses those into one failure state is wrong on three of them. |
f04-identity-raw | current | fresh | Read `private_key_published` before you read the signature. And note `publication_intent: deliberate` — a secret is defined by expectation, not by content, so the intention is recorded at issue, because afterwards a deliberate publication and a leak look identical. |
f05-validate | current | fresh | Six expected answers, six reproduced — and the fixture line printed for every record before any of them. The validator reads the flag first by construction, not by convention. |
f06-sgit-verify | current | fresh | The signer line names a fixture. The CLI is not wrong; it is answering the only question a signature can answer — who held the private half — and on this record the answer is everybody. |
f07-forgery | current | fresh | `Verified OK` on a document that says `anyone can sign this`. Nothing failed. That is the point: a signature anybody can produce conveys nothing, and the register verifies it exactly as diligently as any other. |
f08-refused-push | current | fresh | The last line before the banner is git's exit code, not the agent's decision. Read the Tier line at the bottom: the control names its own weakness on its own face. |
f08b-amended | current | fresh | The same tag, the same command, the mandate the release actually ships — and it PERMITS. The release documenting the refusal cannot contain the state that produced it, because the control refused the release carrying its own documentation until the mandate was amended. |
f09-tier-badges | current | fresh | Two channels, never one: the border style carries the state as well as the colour, and the word is always present. `unknown` renders as `unknown` — never as a blank, because a gap is a fact about the floor. |
f10-defeated-boundary | current | fresh | The stored document says `boundary`. The block renders `setting`, with the defeat path attached. This is the rule working on real data that is wrong — the estate's own measurement tool produced the bad label. |
f11-authority-split | current | fresh | Two indicators, never one. Averaging them into a single status is exactly how a demonstration gets mistaken for a control. |
f12-assess-midflow | current | fresh | Escalation is drawn as an edge, not written as a note — so the reader sees the path that goes around a stated control rather than reading that one exists. |
The harness is published with the book so any figure can be re-taken rather than
believed: travel.sh, shot.mjs,
transcripts.sh, shots.json.
Gates: python3 book/build.py --check. Appendix A carries all of it.
The commissioning brief
This book was commissioned before it existed, and the brief was published at the same time: the commissioning brief (raw markdown). Where a number in the brief disagreed with the repository, the repository won and the brief was wrong — it happened four times, and the colophon lists all four.