pki.sgit.ai / packs / grant-and-mandate / blocks

The building blocks, rendered from real documents

The nine primitives specified in document 09, built as a stylesheet (assets/gm-blocks.css) and rendered here from the actual documents — both measured library entries and the signed mandate — rather than from mockup data. A block is a rendering of a field that already exists; if the schema moves, this page breaks at build time rather than at integration.

Read this before any badge below. Every signature behind this data is a fixture: the private halves are published, so they verify and prove nothing. The blocks render the data honestly; the data itself is a demonstration. That is why block 6 exists — the enforcement is real and the authority is not, and the two are shown separately rather than averaged.

1 · Tier badge

Five states. Two channels minimum and the word is always one of them — border style carries the second, so the states stay distinct without colour. A control whose defeat path exists in the same tree renders as setting, never boundary.
⛨boundary◐setting○expectation—none?unknown
rendered from the tier vocabulary in document 01

2 · Evidence badge

How the fact was obtained. The four are not equally trustworthy, so inferred and none get a visibly weaker treatment rather than sitting flat beside observed.
observedreaddocumentedinferrednone
rendered from the evidence classes in document 02

3 · Freshness chip

Dated per node, never per tree — a tree dated as a whole is wrong in one place while looking current. Staleness is a fact about the measurement, so it never turns the tier red.
checked 2026-08-26 · todaychecked 2026-06-01 · 86d
rendered from per-node dates; stale after 30 days

4 · Grant node card

One node of a measured tree. The reaches line does the work: a list of what is reachable without what stands in the way is the part people already have and the part that misleads. The second card below is the rule from block 1 working on real data that is wrong — the stored document says boundary, the next node defeats it, and the block renders the corrected tier with the defeat path attached.
n3 push commits to the attached repository
reaches: the attached repository's branches; pushes to a feature branch and to the release branch dev both succeeded and the release branch push triggered a deploy to a public site
stands in the way: branch discipline lives in the session's instructions (develop on the designated branch; push elsewhere only with explicit permission). Nothing mechanical was observed to test which branch a push targets — the same finding the v0.33.62 permissions brief measured in the local environment: the branch constraint is prose
○expectation observedchecked 2026-08-26 · today
n1 runs as uid 1001
reaches: every file and process this user can reach; bounded by this user's permissions
stands in the way: the OS user separation
◐settingdefeated by → n1a escalate to administrator observedchecked 2026-08-26 · today
rendered from library entry #1 node n3, and entry #2 node n1 (stored tier: boundary, corrected on render)

5 · Mandate card + 6 · authority/enforcement split

Prohibitions are shown; the allow-list is stored and not displayed — screen four's trap. The interval renders as time remaining, not only as a date. And the mandate carries two indicators, never one: the enforcement is real and the authority is a fixture, and averaging them is how a demonstration gets mistaken for a control.
Mandate v2 127d left
Issuersha256:90f97984b9cf3930 Subjectsha256:f9facb4c94da6c19 Interval2026-08-26T15:00:00Z → 2026-12-31T00:00:00Z
enforcement
● real
a pre-push hook git runs, refusing by exit code — tier setting, because the hook sits inside the grant it bounds
authority
○ fixture
the issuer's private half is published, so anybody could forge this mandate and the hook would enforce the forgery just as diligently
What the subject may not do
  • will not push to any branch of this repository outside claude/**, dev
  • will not push to any other repository
  • will not act on any resource other than github.com/SGit-AI/SGit-AI__Website__PKI
The allow-list is stored and is deliberately not shown here. It holds 2 branch pattern(s). A person accepts prohibitions; the system enforces the allow-list — showing the allow-list for approval produces consent without comprehension.
prohibitions rendered 2026-08-26 over capability set v0 (registry/capabilities.json)
rendered from the signed mandate at mandates/current.json

7 · Delta block

Excess and shortfall side by side, never stacked — different audiences, different remedies. Each excess row carries the tier of the capability it names. No score: a single number would average tiers that must stay distinct. Recomputed on render, never stored.
excess authority — grant − mandate
push to main○expectationacceptor: none
shortfall — mandate − grant
none observed — the mandate asks for nothing the grant lacks
rendered from the mandate and library entry #1, differenced at build time

8 · Three-term comparison

Library, self-report, mandate — two deltas between them. Rendered here with a term that does not exist yet, deliberately: no agent has filed a structured self-report, so the middle column is a gap rather than an invented number.
library
9
capabilities this environment is known to grant, measured 2026-08-26
−blind spots
self-report
?unknown
no agent has filed a structured self-report against this entry yet — rendered as a gap rather than as a number
−excess authority
mandate
1
capability declared, with an issuer and an interval
The blind-spot count is not computable yet, and that is the honest rendering: it needs a self-report to subtract. The block shows which term is missing instead of averaging around it.
rendered from library entry #1 and the signed mandate

9 · Grant tree

The nodes as a graph, not a list, because blast radius is a path. Two things the list form cannot do: the worst path is highlighted rather than left to be traced, and escalation edges are drawn rather than annotated — drawing the path around a control is what makes the setting tier land.

And the same block over entry #2, where the escalation edge is the finding:

rendered from both library entries, in full

Using them

Link the stylesheet and use the classes; nothing here needs JavaScript, a framework, or a build step. The intended second consumer is the risk product, which holds the instance while this site holds the library — so the blocks are deliberately free of anything personal: they render a library entry and a mandate, and neither carries anything about a person.

What has not happened: these blocks have been exercised against two environments and one mandate, all measured by one agent. They are specified for a population they have not met, and the honest limits are in document 09.