RiskMandate.ai · which agent is it?
The mesh, start anywhere
Reach is a node, not a rung: reading a file at your home directory, at a corporate share and at a container's own layer are three exposures wearing one verb, and each reach node has its own edges to environments, products and obligations. So the graph walks both ways. From a product outward: what does it reach? From a reach node inward: which products touch my share? Pick any node.
← points at it
the node
it points to →
The shape
Every node has a type and every edge has a type from one ontology; the build refuses anything else. A coarse node (a family, a capability) and a fine node (an exposure — a capability at one reach node) are the same shape, joined by member-of, so zooming never changes the format. Every card carries source and edit links to the file behind it: a correction is an edit, and the next build carries it.
Data: graph.json, compiled from the source folders by gen_mesh.py. An obligation reached here is a question worth asking at the weakest tier there is, never a compliance finding; the card says so. CC BY 4.0.