# Name The Question Rather Than The Concept, Because Every Coined Noun Tested Either Collides Or Needs Explaining: A Surprise Is An Action Outside The Grant Rather Than A Wrong Action Inside It, Which Makes The Assessment Falsifiable, And The Scan Cannot Run From Outside The Way The Services This Is Modelled On Did

**version** v0.33.64
**date** 4 September 2026
**from** Human (project lead)
**to** Product, Ambassador, Engineering

**type** Strategy brief

*Sixth of 4 September. The memo asks for three things: a name for the gap between grant and mandate, a public site that lets anybody measure their own, and the commercial model that follows. The naming candidates below were tested against the corpus rather than proposed from taste, which ruled out four of them, and the technical term turns out to be settled already. One structural finding changes the product shape and is not in the memo: the services this is modelled on could scan you from outside, and agent exposure cannot be seen from outside, so the site hosts the questions and the interpretation while the measurement happens in the user's own environment. Limitation: domain availability was not checked and the naming recommendation is a recommendation.*

---

## What This Is

A positioning and product brief for the free assessment site and its sub-brand: **the memo asks what to call the gap and rejects the obvious candidates for the right reason, since unauthorised is wrong because the grant is exactly what was authorised, and testing the alternatives against the corpus rules out four more, because latitude and headroom already carry other meanings, blast radius is used three hundred times for the consequence rather than the gap, unaccepted already means an unaccepted risk in the register vocabulary, and excess is the name of a game written last week, which leaves the technical term already settled elsewhere in the estate, excess authority, defined as grant minus mandate and countable, and leaves the public name still open; the recommendation is that a coined noun is the wrong shape entirely, because the audience is standing at the first level of the ladder where they have a different problem rather than a shallower version of ours, a coined noun makes them ask what it means before they can care, and the memo's own constraint is sentence-shaped rather than word-shaped, so the public phrase is what you authorised and never asked for and the site is named for the question a person actually has rather than for the concept we have; the second idea in the memo is sharper than it sounds and deserves to be a definition, that a surprise is an action outside the grant and never a wrong action inside it, which means hallucination within the grant is by design and bounded while an action outside the grant is a measurement failure rather than an agent failure, and that gives the assessment a falsifiable validity test, since an assessment that produced no surprises over a period was calibrated and one that produced any was wrong about the world; the structural finding the memo does not anticipate is that the precedent services worked because the thing they measured was visible from the outside, and agent exposure is not, so this site cannot scan anybody, which is a constraint and also the privacy story, because the measurement runs in the user's environment through the repository specified separately and only a result comes back if the user chooses; the assessment expires by construction because a vendor changing a default moves somebody's exposure without them acting, which is the strongest recurring hook the product has and the one thing a static report cannot offer; and the commercial model maps cleanly onto the ladder already written, with the free site serving the first two levels, the reduction guidance serving the third, and the paid work beginning where somebody wants their own environment modelled rather than the public one.** New contributions: **the naming tests with four candidates ruled out and a recommendation against coining a noun at all, the surprise definition and the falsifiability it buys, the finding that the scan cannot run from outside and what that changes, expiry as the recurring hook, and the commercial model mapped to the existing ladder.**

## The Name

The memo is right to reject unauthorised, and the reason is the whole difficulty: **we authorise the grant. Everything in it is authorised.** The gap is authorised and unasked for, which is an awkward thing to name in one word.

### What the corpus already settled

The technical term exists and should not be re-litigated. The registry pack defines **excess authority** as grant minus mandate, and calls it the countable product. It is precise, it is countable, and it belongs in schemas, packs and policies.

**What is missing is the public name, and that is a different job.**

### The candidates, tested

Tested against the corpus the way this estate has tested five previous names.

| Candidate | Occurrences | Verdict |
|---|---|---|
| **unauthorised** | n/a | **Ruled out by the memo.** It was authorised, and saying otherwise teaches the wrong model on the first word |
| **blast radius** | **315 files** | **Ruled out.** It names the consequence, not the gap, and it is the neighbouring site's whole subject |
| **unaccepted** | 22 files, eleven as "unaccepted risk" | **Ruled out.** It already means a risk nobody signed off, and blurring authority with risk would undo a distinction this corpus has spent months making |
| **latitude** | 6 files, as a product and as coordinates | **Ruled out.** Two existing meanings, and it sounds permissive rather than unowned |
| **headroom** | 7 files, memory and disk | **Ruled out.** Wrong connotation entirely: headroom is capacity you want |
| **excess** | The name of a game written last week | **Ruled out for the public name.** Kept in excess authority, where it is qualified |
| **exposure** | 353 files | Available and vague. It is what the gap produces rather than what it is |
| **uncommissioned** | 0 | Semantically exact and too obscure for a first-time reader |
| **standing authority** | 0 | Clean and accurate: authority that stands whether exercised or not. Dry |

### The recommendation: do not coin a noun

Three reasons, and the third is the one that decides it.

**Every clean candidate is obscure and every familiar candidate collides.** That is what the table above shows, and it is not an accident: the concept is a negation of two other concepts, and negations of pairs do not have short names in English.

**A coined noun asks the reader to learn something before they can care.** The audience is standing at the first level, where the question is what my agents can actually do, and a new word is a tax collected before any value is delivered.

**And the memo's own constraint is sentence-shaped.** The precise statement is *authorised, and never asked for*, and the reason it is precise is that it holds both halves at once. No single word does that without being either wrong or new.

So:

| Layer | Use |
|---|---|
| **Schemas, packs, policies** | **excess authority.** Settled, countable, unchanged |
| **Public copy** | **"what you authorised and never asked for."** A sentence, used consistently, not a coinage |
| **The site name** | **The question**, not the concept |

Naming the site for the question is the same move as the problem deck: a level-one visitor should recognise their own question in the name and need nothing explained. Working candidates in that shape sit around *what can it actually do*, and the choice depends on what is available, which was not checked here.

**The sub-brand relationship the memo asks for is then simple**: it is a RiskMandate service, named for a question, whose result is expressed in the estate's own vocabulary once the visitor is inside.

## The Surprise Definition

The memo says the policy is right if there are no surprises, and that a surprise is an action outside the grant rather than an action the grant permits. That is worth stating as a definition because it does real work.

> **An action inside the grant is never a surprise, however wrong it was. A surprise is an action outside the grant.**

Two failure classes fall out, and people conflate them constantly.

| | What happened | Whose failure | What to do |
|---|---|---|---|
| **Inside the grant, outside the mandate** | The agent did something it was permitted to do and nobody expected | **The grant's.** It was too wide | Reduce the grant, or accept it by name |
| **Outside the grant** | The agent did something the measurement said it could not | **The measurement's**, or containment's | Re-measure. Your model of the world was wrong |

**A hallucination inside the grant is by design and is bounded.** A hallucination that reaches outside the grant is caught, and if it is not caught then the grant was never real.

### What that buys: the assessment is falsifiable

This is the part worth building on. If a surprise means the measurement was wrong, then **the surprise count is the assessment's own validity test**:

```
   zero surprises over a period   ->  the measurement held. The assessment is calibrated
   any surprise                   ->  the assessment was wrong, and by exactly this much
```

Very few security assessments can say what would prove them wrong. This one can, and saying so on the site is worth more than any score, because it is the difference between a report and a claim somebody can check.

It also gives the product its second act. The first service tells you your excess authority. The second, later, tells you whether your measurement of it survived contact with a month of real operation.

## The Scan Cannot Run From Outside

The memo reaches for the right precedent. The free network-exposure services of the early web, of which the best known is ShieldsUP at Gibson Research, worked because somebody typed a URL and the service probed them from the outside and told them what it found. One input, an immediate verdict, no account, and a result worth showing somebody.

**That model does not transfer, and the reason is structural rather than technical.** Those services measured what was visible from the internet. Agent exposure lives inside a laptop, a container, a workspace configuration and a set of connected accounts, and **there is nothing to probe from outside.** A site that claimed to scan it would be lying.

So the shape changes:

| | The precedent | This |
|---|---|---|
| Who measures | The service, from outside | **The user's own environment** |
| What the site does | Probes and reports | **Hosts the questions, the primitives and the interpretation** |
| What crosses the wire | Your address | **A result, only if the user chooses to bring one** |
| Privacy story | Implicit | **Structural.** The site cannot see you even if it wanted to |

That is a weaker hook and a stronger position, and it composes exactly with the repository specified separately: **the repository is the probe, the site is the explanation and the verdict.** The four properties worth preserving from the precedent are the ones that made it spread: free, no account, an immediate and legible verdict, and a result somebody wants to show a colleague.

## What The Site Does, In Order

| Step | Level | What the visitor gets |
|---|---|---|
| 1 | 1 | **The concepts, in four sentences.** What a grant is, what a mandate is, and why the gap is authorised |
| 2 | 1 | **Name your tools.** Pick the products and configurations you use from the public profiles |
| 3 | **1 to 2** | **Your grant appears**, from measurements other people contributed. **Value arrives here, before you have typed anything about yourself** |
| 4 | 2 | **The questions.** What is this agent for, what would surprise you, what must never happen. Answered locally |
| 5 | 2 | **The gap, rendered**, with the irreversible capabilities marked, because those are the ones that decide insurability |
| 6 | 3 | **Reduction guidance**: the specific settings, scripts and configurations that narrow each row, with what each costs you |
| 7 | 3 | **A result you can show somebody**: a policy stating what is covered and what is excluded, at a stated tier |
| 8 | 3 | **Re-check.** The loop closes and the delta moves |

**Step three is the test of the whole thing.** Anybody naming three products should see something they did not know they had granted, and if they do not, the site is not worth visiting.

**Step seven is the memo's scorecard**, and it should be the estate's own object rather than a new one: a policy with conditions met and exclusions with reasons, carrying the tier of its evidence, which here is self-reported. **A self-assessment labelled as one is worth more than a score labelled as a verdict.**

## The Assessment Expires, And That Is The Product

The memo notes this is not static and gives the example that matters: a vendor can change a default and make many people's agents more permissive overnight, without any of those people doing anything.

**So every assessment carries a date and the profile versions it was computed against, and it goes stale when either moves.** Three sources of movement, all of which the site can watch and none of which the user can:

| Movement | Effect |
|---|---|
| A vendor changes a default | Everybody on that profile has a wider grant this morning than last night |
| A product gains a capability | New rows appear in a grant nobody edited |
| An incident is published | A control claimed as enforced is demoted, and any policy relying on it loses a condition |

**That is the recurring value and the strongest reason to come back**, and it is the same mechanism the conformance layer already demonstrates, where a policy moves from one condition met to none with nothing edited by anybody. Here the trigger is somebody else's release note rather than an expiry date, which is worse and more useful.

It is also the honest answer to anybody who asks why a one-off free assessment needs a company behind it: **because the ground moves, and watching it move is work.**

## The Commercial Model

The memo names it and it maps onto the ladder written yesterday without modification.

| Ladder level | What it is | Free or paid |
|---|---|---|
| 1 to 2 | The concepts, the public profiles, your grant, the questions, the gap | **Free, open source, no account** |
| 3 | Reduction guidance and the re-check loop | **Free.** Guidance that costs money is guidance nobody follows |
| 3 | Running it with your own model key, or one bought from us | **Bring your own, or buy.** The first paid thing, and it is a commodity |
| 3 to 4 | **Your environment modelled rather than the public one**: your tools, your assets, your mandate, your risk register | **Paid.** This is the first real offering |
| 4 to 5 | Watching the ground move for a named estate, and reporting upward | **Paid, recurring.** The reason it is a company |

**The free tier has to be genuinely sufficient for an individual**, because the hypothesis is about individuals as much as organisations, and a free tier that cannot answer a person's own question would not test it.

And the boundary should be stated on the site rather than discovered: **everything about the public products is free and open; everything about your particular estate is work somebody does for you.**

## Testing The Hypothesis

The memo's hypothesis is that most people, including technical ones and some security professionals, are carrying a delta far larger than they know. It should be measured rather than asserted, and the site is the instrument.

The honest design: **the site collects nothing by default**, and offers a submission of counts only, by family, with the count of irreversible capabilities outside the mandate, no paths, no hosts, no names, and no obligation. The aggregate is published as it accumulates, including if it disproves the hypothesis.

**If the median delta comes back small, that is worth knowing more than a confirmation would be**, and publishing it would be the single most credible thing the site could do.

## What This Must Not Do

- **Not claim to scan anybody.** The site cannot see a visitor's environment and must say so where somebody would expect otherwise.
- **Not call the gap unauthorised.** It was authorised, and the first word teaches the model.
- **Not present a self-assessment as a verdict.** The tier is on the result.
- **Not coin a noun for the public.** The sentence holds both halves; a word does not.
- **Not collect anything by default**, and not treat a submission of counts as consent to anything else.
- **Not charge for reduction guidance.** Guidance behind a paywall is guidance nobody follows, and the reduction is the point.

## What This Does Not Try To Be

- **Not a scanner.** There is nothing to scan from outside.
- **Not a certification.** It produces a self-assessment with a stated tier and certifies nobody.
- **Not a vendor league table.** Profiles differ by configuration more than by vendor.
- **Not the repository.** That holds the primitives and probes; this explains, interprets and scores.
- **Not a decision on the name.** Four candidates are ruled out with reasons, one recommendation is made, and availability was not checked.

## Honest Tensions

| Tension | Note |
|---------|------|
| A sentence rather than a coined noun | It is accurate and it gives the brand nothing short to own, which marketing will push back on |
| The site cannot measure the visitor | It is the truth and it removes the single mechanic that made the precedent spread |
| A falsifiable assessment | It is the most credible thing here and it guarantees that some assessments will be publicly shown to have been wrong |
| Free through level three | It is the right on-ramp and it defers revenue past the point where most of the value is delivered |
| Expiry as the hook | It is honest and it means the product's recurring value depends on other companies changing things |
| Publishing the aggregate either way | It is the credible move and it may disprove the premise the product is built on |

## Open Questions

| Question | Notes |
|----------|-------|
| What is the site actually called? | The shape is settled and the word is not, and availability decides it |
| Does excess authority survive contact with a non-technical reader? | It is the schema term and it may need never to appear in public copy at all |
| How is a surprise reported? | It is the assessment's validity test and nobody currently has a place to record one |
| Who watches the vendor defaults? | It is the recurring product and it is manual work until somebody automates the diff |
| Is a chat the right interface for step four? | Elicitation is a conversation, and a form is cheaper and worse |
| Should the free tier include the policy output? | It is the shareable artefact and therefore the growth mechanism, which argues for free |

## Relationship To Previous Briefs

| Date | Document | Relationship |
|---|---|---|
| 4 Sep | `v0.33.64__dev-brief__the-grant-mandate-repo-ships-probes-not-tables-grants-are-measured-per-tool-and-contributed-mandates-are-elicited-locally-and-never-leave.md` | The probe half of this pair. The repository measures; this site explains and scores |
| 4 Sep | `v0.33.64__arch-brief__the-shipped-levels-ladder-blends-coverage-with-tier-and-evidence-mode-is-the-axis-that-decides-the-insurance-instrument.md` | The evidence mode an incident demotes, which is one of the three ways an assessment goes stale |
| 3 Sep | `v0.33.63__strategy-brief__the-level-problem-we-built-an-endgame-solution-and-every-audience-is-on-level-one-each-levels-solution-creates-the-next-levels-problem-and-concepts-are-introduced-in-order-of-attrition.md` | The ladder this commercial model maps onto without modification, and the reason to name the question |
| 3 Sep | `v0.33.63__strategy-brief__start-at-the-user-need-not-the-mechanism-one-presentation-per-altitude-a-missing-component-is-a-risk-entry-rather-than-a-blocker-and-the-composability-moat-is-an-architectural-requirement.md` | The dependency map, which is what step six's guidance is drawn from |
| 20 Aug | `v0.33.61__strategy-brief__grant-is-not-the-mandate-the-gap-between-them-is-the-exposure-nobody-accepted.md` | The concept this names, and the phrase the exposure nobody accepted that the public sentence descends from |
| 26 Aug | `v0.33.62__dev-brief__excess-a-tui-game-where-you-never-act-and-only-decide-what-may-happen.md` | Why excess is unavailable as a public name, and the vendor update event this site's expiry mechanic makes real |

---

## Key Claims

| # | Claim |
|---|-------|
| 1 | Unauthorised is the wrong word because the grant is exactly what was authorised, and the first word teaches the model |
| 2 | Four further candidates are ruled out by collisions already in the corpus, including blast radius at 315 files and unaccepted at eleven as unaccepted risk |
| 3 | Excess authority is the settled technical term and should not be re-litigated, and it is not the public name |
| 4 | A coined noun is the wrong shape, because the concept is a negation of two others and the audience is at the first level |
| 5 | The public phrase is what you authorised and never asked for, and the site is named for the question rather than the concept |
| 6 | A surprise is an action outside the grant, never a wrong action inside it |
| 7 | A wrong action inside the grant is the grant's failure; an action outside it is the measurement's |
| 8 | The surprise count is the assessment's validity test, which makes it falsifiable in a way most assessments are not |
| 9 | The precedent services worked because the exposure was visible from outside, and agent exposure is not, so the site cannot scan anybody |
| 10 | The measurement runs in the user's environment and only a result crosses the wire, which makes privacy structural rather than promised |
| 11 | The assessment expires because a vendor changing a default moves somebody's exposure without them acting, and watching that is the recurring product |
| 12 | The commercial boundary is that everything about the public products is free and everything about a particular estate is paid work |

## Sources

- ShieldsUP, the free network exposure service at Gibson Research, confirmed on 4 September 2026 as the precedent the memo describes: a visitor is probed from the outside and given an immediate verdict, with no account. https://www.grc.com/shieldsup and https://en.wikipedia.org/wiki/ShieldsUP
- The RiskMandate corpus, searched on 4 September 2026 for naming collisions across the candidate terms, producing the occurrence counts in the naming table.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
