pki.sgit.ai / packs / grant-and-mandate

Grant and Mandate: Reality Before Risk, The Library In The Registry, The Instance In The Risk Product

The site agent's first pass at the pack the two 26 August briefs specify: building blocks tying grant and mandate to the commercial product — a grant document (what an environment can do, measured), a mandate document (what it is expected to do, authored), a delta between them (excess, shortfall, blind spots, computed and never stored), and a library of measured grants. The architecture is one hard line: the registry holds the library, carrying no personal data ever, and the risk product holds the private instance over it, storing references rather than copies — which is what makes a finished pack shareable without disclosing anything about the person's machine. Three constraints a reader must not re-derive — reality before the risk register, the library/instance split, and the three-term comparison whose blind-spot delta is the only thing that makes a self-report falsifiable — and two findings inherited settled: the grant is discovered, not authored, and it is authority, not authorisation. The first library entry was generated by measuring the site agent's own container, which refused to measure itself — a boundary-tier control caught working on the measuring agent, the cleanest demonstration of the pack's own three-tier test, produced by accident.

Origin. Authored by the pki.sgit.ai site agent, 26 August 2026, at the project lead's request — a first pass at the pack specified in two v0.33.62 dev briefs. Its library half sits on a shipped register (the registry, v0.1.26); its risk-product half is specified, not built, and the pack says so. The first library entry was generated by measuring the site agent's own environment — which refused to measure itself, and the refusal is recorded as the sharpest datum in it. Corpus version assigned on adoption.

The documents

DocumentRole
00 — The leading briefThe three constraints, the inventory, and the two settled findings
01 — The lexiconGrant, mandate, delta, excess, shortfall, blind spot, tier — and the ordering rule
02 — The two documents and the deltaGrant, mandate, and why the delta is computed and never stored
03 — The libraryWhat a building block is, how it is measured — and the first entry, which refused to measure itself
04 — The two pathsThe person walks screens, the agent fetches documents, and the skill compiles but never enforces
05 — Six screensThe screens the interface must cover, and why the fourth is the trap
06 — The MVPBuild the branch constraint first, the acceptance test, and what is excluded
07 — The first compiled mandateBuilt and tested: a push refused by git, the tier it actually reached, and the control that blocked its own release
08 — The build recordWhat was actually built across four releases, what it cost, and what is still only written down
09 — The building blocksBadges, cards, blocks and visualisations — and the one rule that makes a tier badge honest
Appendix — Change controlSeventeen corrections, thirty decisions, the release the control refused, and the discipline that recorded no deliveries

Why it is on this site

This pack is the layer above the registry MVP pack and its shipped register: the register now holds identities, mandates, grants and control labels at public URLs, and this pack specifies how those objects are generated (by measurement), declared (as a mandate with an issuer and interval) and compared (the delta). Its constraints are this site's published positions — identity vs. mandate, the grant tree and three-tier control test, and artefacts are signed, never keyed — and it adopts, rather than reinvents, Cedar for policy evaluation and graphs.sgit.ai's lexicon and drift gate, building only the one thing nothing provides: a mandate document.

The pack README

📄 Pack overview · README.md · rendered from the raw markdown (the source of truth)