pki.sgit.ai / documents

The documents

The twenty-one original markdown documents behind this site, captured verbatim under briefs/ and readable here. Each page carries the same apparatus — a summary, the key concepts linked to where they live on the site, the key ideas — and then the full document, rendered in-page from the raw markdown. The raw file stays the source of truth; the page is presentation. That raw-plus-curated split is the provenance discipline this project argues for, applied to itself.

DocumentType · dateIn one line
The screenshot boundary is the instrumentDev brief · 20 Aug 2026Synthetic readers find defects, not preferences; the patience budget comes from outside the model; and the service is one question from the banned tool. Operationalised in the Map Your Case pack.
Levels and variants are two axesDev brief · 20 Aug 2026A grid, not a ladder; everybody starts at level one; and the worked instance is the session itself — mandated, exercised, and held-never-used. Operationalised in the Map Your Case pack.
History is the append-only logArch brief · 20 Aug 2026Growth moves to the commit graph, which dissolves the tension between rules 2 and 3 — and the reference is mutable, so append-only is a policy about one pointer.
The user section is a conformance test for the site’s own claimDev brief · 20 Aug 2026Store the choices, not the answers — and a high threat with no efficacy produces denial rather than change. Built as /assess.
The end-to-end flow, with an agent installation as the twinArch brief · 20 Aug 2026A grant is a tree; a control bounds it only if something outside the grant enforces it; counting acceptances is the metric that inverts.
A secret is defined by expectation, a signature by scarcityArch brief · 20 Aug 2026Publishing a private half leaves a hash wearing a signature’s clothes — and a flag that is true on every row is a column, not evidence.
Observability is the usage graph nobody has to declareArch brief · 20 Aug 2026A verification is not a use; the missing edges are the product; check events belong in the issuer’s own lane.
Every trust edge is a two-way conversationArch brief · 20 Aug 2026Signed-once against checked-every-time as two products; metering and surveillance are one capability.
The register interface: a badge on every edgeDev brief · 20 Aug 2026A policy is a query that must return empty — and a tested negative result on proving where a rented agent runs.
The register was designed in June; published keypairs are fixturesArch brief · 20 Aug 2026The 5 June design located; the fixture class named and bounded; agent cards and workflow signing identified.
Grant is not mandateStrategy brief · 20 Aug 2026Grant is what a credential permits; the gap to the mandate is excess authority — unaccepted by construction, and countable.
Site access reportCross-team brief · 20 Aug 2026Three findings closed, the acceptance test passes, and the composition gap moved up a layer to sit between three sites.
Agent identity, mandate and executionBriefing pack · 19 Aug 2026The leading brief: three layers, four recommendations, and two corrections that would otherwise reach an implementation.
What pki.sgit.ai is missingCross-team brief · 19 Aug 2026The review of this site — the mandate gap, the reframing, and a stated limitation that is itself the finding.
The bootstrap trapStrategy brief · 19 Aug 2026Why agent key registries do not exist: a loop, seven workarounds, and every one hands over a larger identity.
Agent enrolment without borrowed authorityArch brief · 19 Aug 2026Start from a keypair and nothing else; post through an append lane; keep identity separate from mandate.
The append lane is shipped and account-lessArch brief (correction) · 19 Aug 2026Four capability tiers, hashes on the server, and five things earlier briefs got wrong.
The execution brokerArch brief · 19 Aug 2026The agent never holds the credential, which closes the one boundary capability and sequence controls could not reach.
The relay patternArch brief · 16 Aug 2026Encryption says who may read, signing says who acted, ordering comes from data dependencies.
nhi.sgit.ai: two populationsStrategy brief · 16 Aug 2026The identity gap this site is the cryptographic half of.
pki.sgit.ai: the registry has a documented failure to learn fromStrategy brief · 16 Aug 2026The 2019 keyserver failure turned into registry rules; append-only resolved precisely; private before public.
The registry MVP pack has its own section. The five draft briefs published at v0.1.4 as document pages, plus the diagrams, change control and tabletop exercise added at v0.1.5, now live as a dev pack under packs/registry-mvp — sources verbatim under src/, a reader page per document, same treatment as nhi.sgit.ai's packs. A second pack, Map Your Case, owns the assessment at /assess and operationalises the two 20 August programme briefs above.
More documents. The corpus behind this site runs to 729 files mentioning the subject, with dedicated documents going back to February 2026 — an architecture debrief, a messaging implementation, model-integration research, a document identity brief, operating modes, a provenance treatment and a brand strategy. Curating those by question is step 1 of the build order and is queued on comms. The wider corpus is published openly in the SGraph-AI__App__Send repository.