pki.sgit.ai / packs / grant-and-mandate / enforcement

07 — The first compiled mandate

PackGrant and Mandate: Reality Before Risk, The Library In The Registry, The Instance In The Risk Product RoleBuilt and tested: a push refused by git, the tier it actually reached, and the control that blocked its own release Date26 August 2026 · draft-1 + change control OriginSite agent, this repo Sourceraw markdown · on GitHub

Summary

Build-order step 1, built. A mandate authored deliberately narrower than the measured grant — permitting pushes to claude/** while the library entry records that the environment can also push to dev, the branch that deploys a public site — compiled into a pre-push hook that git runs and that refuses by exit code. The acceptance test was executed: the push produced error: failed to push some refs, origin/dev was unchanged, and a permitted push in the same minute succeeded, so the refusal came from git rather than from the agent deciding to comply. The tier reached is stated rather than claimed: setting, not boundary, because the hook is inside the grant it bounds and --no-verify still gets past it — exactly the tier-three-to-tier-two move the brief predicted and no further. Two findings the exercise produced that no diagram would have: within the hour the control refused the release that was carrying it, and the correct remedy was the issuer amending the mandate rather than any bypass; and the measurement tool, re-run afterwards, independently caught its own tier change.

Key concepts

Key ideas

Read the document

📄 Pack document · 07__enforcement.md · rendered from the raw markdown (the source of truth)