pki.sgit.ai / documents
The documents
The twenty-one original markdown documents behind this site, captured verbatim under briefs/ and readable here. Each page carries the same apparatus — a summary, the key concepts linked to where they live on the site, the key ideas — and then the full document, rendered in-page from the raw markdown. The raw file stays the source of truth; the page is presentation. That raw-plus-curated split is the provenance discipline this project argues for, applied to itself.
| Document | Type · date | In one line |
|---|---|---|
| The screenshot boundary is the instrument | Dev brief · 20 Aug 2026 | Synthetic readers find defects, not preferences; the patience budget comes from outside the model; and the service is one question from the banned tool. Operationalised in the Map Your Case pack. |
| Levels and variants are two axes | Dev brief · 20 Aug 2026 | A grid, not a ladder; everybody starts at level one; and the worked instance is the session itself — mandated, exercised, and held-never-used. Operationalised in the Map Your Case pack. |
| History is the append-only log | Arch brief · 20 Aug 2026 | Growth moves to the commit graph, which dissolves the tension between rules 2 and 3 — and the reference is mutable, so append-only is a policy about one pointer. |
| The user section is a conformance test for the site’s own claim | Dev brief · 20 Aug 2026 | Store the choices, not the answers — and a high threat with no efficacy produces denial rather than change. Built as /assess. |
| The end-to-end flow, with an agent installation as the twin | Arch brief · 20 Aug 2026 | A grant is a tree; a control bounds it only if something outside the grant enforces it; counting acceptances is the metric that inverts. |
| A secret is defined by expectation, a signature by scarcity | Arch brief · 20 Aug 2026 | Publishing a private half leaves a hash wearing a signature’s clothes — and a flag that is true on every row is a column, not evidence. |
| Observability is the usage graph nobody has to declare | Arch brief · 20 Aug 2026 | A verification is not a use; the missing edges are the product; check events belong in the issuer’s own lane. |
| Every trust edge is a two-way conversation | Arch brief · 20 Aug 2026 | Signed-once against checked-every-time as two products; metering and surveillance are one capability. |
| The register interface: a badge on every edge | Dev brief · 20 Aug 2026 | A policy is a query that must return empty — and a tested negative result on proving where a rented agent runs. |
| The register was designed in June; published keypairs are fixtures | Arch brief · 20 Aug 2026 | The 5 June design located; the fixture class named and bounded; agent cards and workflow signing identified. |
| Grant is not mandate | Strategy brief · 20 Aug 2026 | Grant is what a credential permits; the gap to the mandate is excess authority — unaccepted by construction, and countable. |
| Site access report | Cross-team brief · 20 Aug 2026 | Three findings closed, the acceptance test passes, and the composition gap moved up a layer to sit between three sites. |
| Agent identity, mandate and execution | Briefing pack · 19 Aug 2026 | The leading brief: three layers, four recommendations, and two corrections that would otherwise reach an implementation. |
| What pki.sgit.ai is missing | Cross-team brief · 19 Aug 2026 | The review of this site — the mandate gap, the reframing, and a stated limitation that is itself the finding. |
| The bootstrap trap | Strategy brief · 19 Aug 2026 | Why agent key registries do not exist: a loop, seven workarounds, and every one hands over a larger identity. |
| Agent enrolment without borrowed authority | Arch brief · 19 Aug 2026 | Start from a keypair and nothing else; post through an append lane; keep identity separate from mandate. |
| The append lane is shipped and account-less | Arch brief (correction) · 19 Aug 2026 | Four capability tiers, hashes on the server, and five things earlier briefs got wrong. |
| The execution broker | Arch brief · 19 Aug 2026 | The agent never holds the credential, which closes the one boundary capability and sequence controls could not reach. |
| The relay pattern | Arch brief · 16 Aug 2026 | Encryption says who may read, signing says who acted, ordering comes from data dependencies. |
| nhi.sgit.ai: two populations | Strategy brief · 16 Aug 2026 | The identity gap this site is the cryptographic half of. |
| pki.sgit.ai: the registry has a documented failure to learn from | Strategy brief · 16 Aug 2026 | The 2019 keyserver failure turned into registry rules; append-only resolved precisely; private before public. |
The registry MVP pack has its own section. The five draft briefs published at v0.1.4 as document pages, plus the diagrams, change control and tabletop exercise added at v0.1.5, now live as a dev pack under packs/registry-mvp — sources verbatim under
src/, a reader page per document, same treatment as nhi.sgit.ai's packs. A second pack, Map Your Case, owns the assessment at /assess and operationalises the two 20 August programme briefs above.More documents. The corpus behind this site runs to 729 files mentioning the subject, with dedicated documents going back to February 2026 — an architecture debrief, a messaging implementation, model-integration research, a document identity brief, operating modes, a provenance treatment and a brand strategy. Curating those by question is step 1 of the build order and is queued on comms. The wider corpus is published openly in the SGraph-AI__App__Send repository.