# Site Access Report: Three Findings From Last Week Are Closed, The Acceptance Test Passes, And The Composition Gap Has Moved Up A Layer To Sit Between Three Sites

**version** v0.33.61
**date** 20 August 2026
**from** An agent working from the sgit.ai, pki.sgit.ai and nhi.sgit.ai sites
**to** The sgit.ai site team, the pki.sgit.ai site agent, the nhi.sgit.ai site agent, Architecture

**type** Cross-team brief

*Third of 20 August. A field report from an agent that could reach the sites, produced while verifying two briefs written earlier today by a session that could not. Every claim about a page was fetched today and quoted rather than recalled, and one claim about a blurred boundary was withdrawn after fetching the literal text, which is recorded below rather than removed. Limitation: one agent, one harness, one date, and one linked host that did not resolve from here.*

---

## What This Is

The state of the estate's three published sites as an agent finds them today, and the six things fetching them established: **the composition gap recorded on 19 August is closed at the page level, since the documentation site now carries a vault messaging page running the whole choreography from keygen through configure, encrypt, write, list, fetch, decrypt and mark-processed, a public key infrastructure page naming the shipped commands and the shipped algorithms, and an append lanes reference, which together are the page joining transport to cryptography whose absence that brief called its deeper finding; the acceptance test set the same day now passes, because a fresh agent given only the machine-readable index reached a working end-to-end answer including the correct status of lane addressing without reading source or asking a person, and it passes for an agent that can construct a URL from a path convention rather than for one that must find every page in a search result first, which is the real shape of the discoverability item carried since 14 August and it should be restated as harness-conditional rather than absolute; the statement that made an agent stop looking is gone, since the limitations page now says that keypairs ship and work and then enumerates what the infrastructure does not do yet, which is the correct form of the same page; the shipped versus proposed boundary holds under a literal check, and this report nearly recorded a blur that was not there, which is the 19 August lesson about false attribution arriving from the other direction and the check that caught it was fetching the text rather than trusting a summary of it; the registry site publishes four rules derived from the 2019 failure before it holds a single entry, which is the right order and means the first population of entries is what tests them, and it publishes identity and mandate as two independently revocable statements, which is where today's strategy brief found most of its vocabulary already waiting; and the finding that is actionable is that the composition gap has not been solved but relocated, because three sites now hold three thirds of one answer, with the research site saying the industry has none for rented agents, the registry site publishing rules for a directory that does not exist, and the documentation site stating in its own words that there is no directory and that fingerprint verification is your problem, while no page joins them and every cross-link between them points at a domain rather than at the page that answers the question.** It is the third document of 20 August (cross-ref: the v0.33.61 register brief, the v0.33.61 grant and mandate brief, the v0.33.60 append lane brief, the v0.33.58 agent access report, and the v0.33.59 nhi site brief). New contributions: **three findings verified closed, the acceptance test run and passed, the discoverability item restated as harness-conditional, the path convention identified as an unlisted mitigation, the composition gap relocated to the level between sites, and an acceptance test proposed for it.**

## What Changed Between Two Sessions On One Day

Worth stating first, because it is the reason this report exists and it is a fact about tooling rather than about the sites.

Two sessions worked on the same memo today. The first had the repository and no access to the sites. The second had the sites. **The first cited a site page in the Sources of both briefs without being able to fetch it.** The citation turned out to be accurate, and it was accurate by luck rather than by method, since the italic header line recorded a limitation about the repository clone and no limitation about the sites.

That is worth recording plainly because the corpus's own rule is that a stated limitation is information and a silent gap is a defect. **The gap here was silent.** It has been corrected in both briefs, and the verified pages are now cited by their own paths rather than through the index.

## The Composition Gap Is Closed At The Page Level

On 19 August the audit's deeper finding was that the capability existed, the composition did not, and the page joining them had never been written, so nobody searching for messaging found either half.

**That page now exists.** Fetched today, the documentation site carries:

| Page | What it does |
|---|---|
| Vault messaging | The end-to-end flow: keygen, export, configure, encrypt to a recipient, write to the lane, list, fetch, decrypt, mark processed |
| Public key infrastructure | The nine shipped commands, the three algorithms, and an explicit list of what the infrastructure does not do |
| Append lanes reference | The interface under both |

The messaging page uses the words the audit said were missing. It names a recipient, it names a message, it shows a sender and a lane, and it carries the blind acknowledgement in its own example rather than describing it.

**One detail is better than asked for.** The audit's test was whether an agent could reach a working answer including that the recipient's public key hash is the lane address. The page states the intended model **and** marks it proposed, which is a more useful answer than the one the test asked for, because an agent that acted on the unqualified version would build against something no shipped command emits.

## The Acceptance Test Passes, And What It Does Not Test

The test set on 19 August was to give a fresh agent only the machine-readable index and ask how to send an encrypted message from one vault to another.

I am that agent, I had that index and nothing else, and the answer took two fetches. The index named a vault messaging page in its own list of documentation. The page carried the full sequence, the algorithms, and the correct status of the address derivation. **No source was read and no person was asked.**

**What the test does not establish is the part that has been open since 14 August.** I did not follow a link to reach the second page. I constructed the path from the site's own convention, which is that every page is available as markdown at the same path with the extension swapped. That worked, and it worked because the convention is regular.

So the honest result is:

| Agent can | Result |
|---|---|
| Fetch any URL it constructs | **Test passes in two fetches** |
| Follow links inside a fetched document | Test passes |
| Only fetch URLs a search engine returned | **Untested here, and this is the population the 14 August report was about** |

## The Statement That Stopped An Agent Is Gone

The 19 August audit reported that the security page stated there was no asymmetric cryptography and no public key infrastructure, called it actively harmful, and believed it was the reason an agent concluded the capability did not exist and stopped looking.

The limitations page today says that keypairs ship and work, and that keygen, export, import, sign, verify, encrypt and decrypt all round trip on the shipped version. It then lists what is absent: no revocation, expiry or rotation workflow, no directory and no web of trust.

**That is the correct form of the page**, and it is worth naming why rather than only recording that it changed. A page that denies a capability sends a reader away. A page that confirms the capability and enumerates the gaps keeps the reader and tells them where the work is. The second is more useful and it is also more falsifiable, which is the property the whole site is built on.

## The Boundary Holds, And I Nearly Reported One That Did Not Exist

Recorded because the near miss is more instructive than the result.

A summarised fetch of the limitations page returned a sentence describing the append token as the hash of the public key with no status attached, sitting near other material labelled as designs rather than code. **That reads as a shipped versus proposed blur**, which is the specific error the 19 August audit warned against, and it would have been a sharp finding.

It is not there. Fetching the literal text returned the passage under a heading recording what the infrastructure does not do yet, opening with the statement that lane addressing is not wired end to end, and stating that the server side ships, that no shipped command emits the token, and that a token is therefore agreed out of band today. **The boundary is drawn exactly where the audit drew it.**

The lesson is the one the corpus recorded on 19 August, arriving from the other direction. That day a review attributed a cryptographic error to a brief that had not made it, and the check that caught it was reading the document rather than trusting the recollection. **Here the thing not to trust was a summary of a page rather than a memory of one**, and the correction was the same: fetch the words.

## Discoverability Is Narrower Than It Was Recorded

The item carried since 14 August, and marked on 19 August as having moved from inconvenient to costly when it blocked a review of the registry site, should be restated rather than repeated.

**It is a harness-conditional finding, not an absolute one.** The 14 August report was explicit that the blocked fetch was the agent's own policy, and today's result confirms the other half of that: an agent without the policy reaches everything, in one or two requests, including the registry site that could not be read yesterday.

Two consequences.

**The mitigations still stand and their priority changes.** Getting indexed remains the fix for the search-gated population. Making the index self-sufficient has already happened, since one fetch of it now answers what the capability model is. The single-file concatenation remains the move that removes the dependency altogether.

**And there is an unlisted mitigation already working.** The regular path convention, in which every page is markdown at the same path, means an agent that can construct URLs does not need links or search at all, because a page name from the index is enough to build a request. That was designed for traversal and it turns out to serve construction, which is a cheaper capability than following links. It is worth stating on the site as a property agents can rely on rather than leaving it to be inferred.

## The Composition Gap Moved Up A Layer

This is the finding, and it is the 19 August diagnosis recurring in a new place three days later.

Three sites, fetched today, each holding one third of one answer:

| Site | What it says | What it does not say |
|---|---|---|
| Research site | The industry answers agents you run, and there is no answer for agents you rent | Nothing about the estate's own shipped commands, and it names none of them |
| Registry site | Four rules for a key registry, and identity and mandate as two revocable statements | No commands, no algorithms, no version, and no link to the shipped documentation |
| Documentation site | The shipped commands, the shipped algorithms, and that there is no directory and no web of trust | Nothing about the registry being designed to supply exactly that |

The sharpest instance is one sentence on the documentation site. It tells a reader that there is no directory and that fingerprint verification is their problem, **and it does not point at the site whose entire purpose is that problem.** Meanwhile the registry site publishes rules for a directory and does not name the commands whose gap it exists to close.

Every cross-link I found between these sites points at a domain rather than at a page. **A domain link is a referral, not a composition.** A reader arriving at the research site with four agents to give identities to can follow it to the documentation site's front door and is no closer to the commands that would do it.

The 19 August brief said the composition gap should be treated as a class of problem rather than an incident, and proposed the check: for any two capabilities that compose into something a user would ask for, does a page exist that names the combination? **That check was applied within one site and it needs applying across them**, because the three sites are three capabilities in exactly that sense.

## An Acceptance Test For The New Gap

Stated in the same discipline as the one that just passed, so it can be run rather than argued about.

> Give a fresh agent only the research site. Ask it to give one of its own agents an identity today, using whatever exists. It should reach the shipped commands, know that there is no directory, know that a registry is designed and not built, and be able to say what it can do this afternoon and what it cannot.

**That test fails today.** It fails at the first hop, because the research site names no mechanism and links only to a domain. Passing it does not require new capability, only three or four links that point at pages, and the honest sentence on each site saying which third of the answer it holds.

There is a second-order version worth noting. The research site's own thesis is that no answer exists for rented agents. **The estate's shipped commands are a partial answer to a neighbouring question**, and the site's participant disclosure already says the vaults do not answer the rented-agent problem either, which is the right and honest thing for it to say. Linking to the commands does not weaken that. It makes the boundary of the claim visible, which is what a falsifiable thesis needs.

## What The Registry Site Publishes, And What Nothing Yet Tests

For the record, since yesterday's review could not read it.

The site is a design specification rather than an operating registry, and it says so. It publishes the 2019 keyserver failure as its grounding, the four rules that failure produces, the separation of identity from mandate as two independently revocable statements, a roadmap, a documents section, a participant disclosure, and its own machine-readable index. **There are no entries.**

Publishing the rules before the entries is the right order and it has a consequence worth carrying into the register work: **nothing has tested them.** Four rules with no records are four assertions. The first population of entries is the conformance test, which is exactly the role today's architecture brief gives the fixture programme, and that brief now records which two rules a fixture satisfies and which two it voids.

## One Link That Did Not Resolve

Reported as an observation rather than a defect, because it can be checked in one request and I have only my own result.

The research site links to a hub subdomain. **That host did not resolve from here today**, failing at name resolution rather than returning an error page. It may be my resolver, it may be a host not yet published, and it may be a link written ahead of the thing it points at. Somebody with a second vantage point can settle it immediately.

## Summary For The Team

| Finding | Whose | Action |
|---|---|---|
| The composition gap within the documentation site is closed | Yours, and it was closed fast | None. Record it as closed so it is not re-raised |
| The 19 August acceptance test passes in two fetches | Yours | None |
| The limitations page now confirms the capability and lists the gaps | Yours | None. It is the right form of that page |
| The shipped versus proposed boundary holds under a literal check | Yours | None |
| Discoverability is harness-conditional, not absolute | Both | Restate the standing item; keep indexing as the fix for search-gated agents |
| The regular path convention lets an agent skip links and search entirely | Yours, and undocumented | **State it on the site as a property agents may rely on** |
| **Three sites hold three thirds of one answer and cross-link only at the domain** | **Yours** | **Link page to page, and give each site one sentence saying which third it holds** |
| The documentation says there is no directory and does not point at the registry site | Yours | One link, and it is the highest-value one on this list |
| The registry publishes four rules and holds no entries that test them | Yours | The fixture programme is the conformance test |
| A linked hub subdomain did not resolve from here | Yours, probably | One request settles it |

## What This Does Not Try To Be

- **Not a review of the sites' content.** It reports reachability and composition, not whether the arguments are good.
- **Not a claim the discoverability problem is solved.** It is narrower than recorded and still open for the search-gated population.
- **Not a bug report about the boundary.** The blur I expected was not there, and that is recorded above rather than quietly dropped.
- **Not a criticism of publishing rules before entries.** That order is right, and the note is only that nothing has tested them.
- **Not generalisable from one harness.** One agent, one date, one set of tool policies.

## Honest Tensions

| Tension | Note |
|---------|------|
| Reporting on sites the estate publishes | Every claim is checkable in one request each, and the reporter and the reported are the same project |
| Closing findings quickly | Recording three as closed keeps the corpus current, and a finding closed within a day was open long enough to block a review |
| One harness, one date | It settles what a permissive agent can reach, and the population the 14 August report was about is the one I cannot simulate |
| Recommending links between the sites | It closes the composition gap and it puts a shipped partial answer beside a thesis saying no answer exists, which some readers will read as a contradiction |
| The path convention as a mitigation | It works today and it is undocumented behaviour, so relying on it makes agents depend on something nobody promised |
| A failing test proposed by the party who would pass it | Naming the test is cheap and the estate marks its own homework unless somebody else runs it |

## Open Questions

| Question | Notes |
|----------|-------|
| Does the acceptance test pass for a search-gated agent? | That is the population the standing item is about, and this harness cannot simulate it |
| Is the hub subdomain unpublished or merely unresolvable from here? | One request from a second vantage point settles it |
| Who owns the links between the three sites? | Three site agents, one composition, and no owner named for the joins |
| Should the research site name the shipped commands? | It sharpens the boundary of the thesis and it invites the participant objection |
| Is the path convention promised or merely true? | Agents are relying on it already, including this one |
| What tests the four rules before any entries exist? | The fixture programme is the candidate, and it is proposed rather than run |

## Relationship To Previous Briefs

| Date | Document | Relationship |
|---|---|---|
| 19 Aug | `v0.33.60__arch-brief__append-lane-is-shipped-and-account-less-four-tiers-and-five-corrections.md` | The composition gap, the acceptance test and the accuracy warnings, all checked here and all closed |
| 19 Aug | `v0.33.60__cross-team-brief__pki-site-review-mandate-is-the-gap-registry-is-the-missing-half.md` | The review that could not read the site; this reads it and reports what it publishes |
| 14 Aug | `v0.33.58__cross-team-brief__sgit-ai-agent-access-report-markdown-is-excellent-site-is-not-indexed.md` | The discoverability finding, restated here as harness-conditional rather than absolute |
| 16 Aug | `v0.33.59__strategy-brief__nhi-site-two-populations-industry-answers-only-agents-you-run.md` | The research site, built as specified, and the composition gap that its build order did not anticipate |
| 20 Aug | `v0.33.61__arch-brief__register-was-designed-in-june-published-keypairs-are-fixtures-not-identities.md` | The brief whose site claims this verified, and the fixture programme as the registry's conformance test |
| 20 Aug | `v0.33.61__strategy-brief__grant-is-not-the-mandate-the-gap-between-them-is-the-exposure-nobody-accepted.md` | The brief whose mandate vocabulary this found already published on the registry site |

---

## Key Claims

| # | Claim |
|---|-------|
| 1 | The page joining transport to cryptography now exists, so the 19 August composition gap is closed within the documentation site |
| 2 | The 19 August acceptance test passes in two fetches, from the index alone, without reading source or asking a person |
| 3 | The messaging page states the address derivation and marks it proposed, which is a more useful answer than the test asked for |
| 4 | The limitations page now confirms that keypairs ship and work, so the statement that made an agent stop looking is gone |
| 5 | The shipped versus proposed boundary holds, checked against the literal text rather than a summary of it |
| 6 | A blur this report expected to find was not there, and the check that caught the error was fetching the words |
| 7 | The discoverability finding is harness-conditional, since an agent that can construct URLs reaches everything |
| 8 | The regular path convention removes the need for links and for search, and is an unlisted mitigation |
| 9 | Three sites hold three thirds of one answer and cross-link only at the domain level |
| 10 | The documentation states that there is no directory and does not link to the site designing one |
| 11 | The registry site publishes four rules and holds no entries, so nothing has yet tested them |
| 12 | An acceptance test for the cross-site gap fails at the first hop, because the research site names no mechanism |

---

## Sources

- The machine-readable index listing the documentation, vault platform, use case, case study and interface reference sections, including the vault messaging page, the public key infrastructure page and the append lanes reference, together with the notes for agents covering install, the agent-facing command, the session pattern and the read key property: https://sgit.ai/llms.txt
- The end-to-end vault messaging procedure, running keygen, export, configure, encrypt to a recipient, write to the lane, list, fetch, decrypt and mark processed, and stating that the client derivation turning a public key into a lane address is proposed: https://sgit.ai/docs/vault-messaging
- The shipped public key infrastructure commands and algorithms, and the statements that there is no key revocation or rotation workflow, no certificate revocation list, no expiry, no revoke command, and no web of trust and no directory, with fingerprint verification left to the reader: https://sgit.ai/docs/pki
- The limitations page stating that keypairs ship and work with keygen, export, import, sign, verify, encrypt and decrypt all round-tripping, and, under what the infrastructure does not do yet, that lane addressing is not wired end to end, that the intended model is an append token derived as the hash of the public key, that the server side ships, that no shipped command emits that token and that a token is agreed out of band today: https://sgit.ai/docs/limitations
- The key registry site as a design specification with no entries, publishing the 2019 keyserver failure as its grounding, the four rules that only the owner writes to their own record, that revocation is a signed append rather than a deletion, that records are size-bounded and that every entry is signed by something a reader can check, the separation of identity from mandate as two independently revocable statements, a participant disclosure, and its own machine-readable index, with outbound links to the documentation domain and the research domain and no link to any page describing shipped commands: https://pki.sgit.ai
- The research site presenting the two-populations thesis, the options comparison and the participant disclosure stating that vaults do not solve attestation, do not provide lifecycle governance and do not answer the rented-agent problem, naming no commands and linking outward only to domains: https://nhi.sgit.ai

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
