# The Grant And Mandate Pack: Reality Before Risk, The Library Belongs To The Registry And The Instance To The Risk Product, And The Comparison Has Three Terms

**version** draft-1 (site-agent first pass — corpus version to be assigned on adoption)
**date** 26 August 2026
**from** The site agent
**to** Project lead, the RiskMandate team, Architecture, Design

**type** Briefing pack, leading brief

*Read this first. This pack is the site agent's first pass at the pack specified in two project-lead briefs of 26 August (v0.33.62), produced at the project lead's request for review — it proposes, it does not decide. Everything in it is constrained by what two sibling sites already publish, and the grant it uses as its worked example was measured inside a running agent environment rather than authored, because the load-bearing rule of the whole pack is that a grant is discovered, not written.*

---

## What This Pack Is For

A buildable set of building blocks — a **grant document**, a **mandate document**, a **delta** computed between them, and a **library** of measured grants — so that a user or an agent can arrive at an agentic environment, discover what it can actually do, declare what it is expected to do, and leave with a **pack that produces risks**. The registry ([pki.sgit.ai](../../index.html)) holds the reusable library; the risk product ([RiskMandate.ai](https://riskmandate.ai)) holds the private instance over it.

The pack exists because the vocabulary now has a shipped register underneath it. As of [site v0.1.26](../../registry/index.html) the grant, the mandate, the tree and the control labels are not diagrams — they are signed statements at public URLs. This pack is the layer above: how those objects are **generated**, **declared** and **compared**, and how the result becomes a shareable artefact that discloses nothing about the person's machine.

## The Three Things A Reader Must Not Re-Derive

The two source briefs settle three points hard enough that relitigating them would rebuild the error the pack was written to fix. They are constraints in this pack, not options.

**1 — Reality before the risk register.** The chain is `reality → twin → facts → finding → risks → decisions`, and it runs in that order. A grant is a *fact*, and a fact is a *measurement*. You cannot author a risk before you have a fact. So the first screen of the MVP is not a risk register and not a risk-appetite questionnaire — it is *which environment, and here is what it can do*. A pack whose first screen is a risk register reproduces exactly the habit it exists to fix.

**2 — The library and the instance split, and the instance stores references.** The registry holds the **library**: a grant per environment, generated by measurement, dated, carrying **no personal data ever**. The risk product holds the **instance**: this user's selections, mandate, deltas and risks — all of the personal data, **never published**. And the instance stores *references* into the library, never copies. Two consequences: the library stays versionable (a corrected building block improves every instance that referenced it, while a copy silently keeps the old answer), and **a finished pack becomes shareable** — a list of library identifiers plus a mandate discloses which products you use and nothing about your machine. That last property is what makes the mandate pack a sendable object at all.

**3 — The comparison has three terms, not two.** An agent asked to report its own grant is both the instrument and the subject: it reports what it can *see*, which is a floor rather than a census, and it cannot report a capability it does not know it has. So a self-report is unfalsifiable alone. The library is the third term that corrects it:

```
   LIBRARY   ---minus--->  SELF-REPORT    = BLIND SPOTS
             what the environment is       what this agent noticed
             known to grant                it has, and did not report

   SELF-REPORT ---minus-->  MANDATE        = EXCESS AUTHORITY
             what this agent noticed        what was asked for
```

The **blind-spot delta is the argument for building the library at all** — without it there is no way to tell a thorough self-assessment from a lazy one — and it is the most persuasive number in the flow: *this agent reported eleven of the nineteen capabilities its environment is known to have.*

## Two Findings This Pack Inherits As Settled

**The grant is discovered, not authored.** A hand-written grant file is a wish — it records what somebody believed the environment could do on the day they typed it, which is the exact thing a grant is not. So the grant document is **generated by measurement, carries provenance per node, and is dated**, and a node with no evidence is marked *unevidenced* rather than omitted. This also makes the drift question mechanical: re-run the measurement and diff it, and the alarming case — a node moving from `setting` to `expectation` — is a control that stopped existing while nothing broke.

**The grant is authority, not authorisation.** The mandate is authorisation: somebody decided it, on a date, for an interval. The grant is authority that *nobody* decided — it arrived bundled with a credential, and under the doctrine of apparent authority the outside world treats it as binding anyway. Calling the grant "implicit authorisation" quietly concedes the point the whole vocabulary exists to make.

## Memory Gives The Grant A Time Axis

With memory off, a grant is a tree — a property of the environment. With memory on, it is that tree **unioned with everything any prior session reached**, for as long as history is retained — a property of the environment *and its past*. Two identical installations then have different grants if their histories differ, which means a library entry can never be the whole answer for a real user: **the library publishes the static term, and the instance carries the accumulated term.** Every grant document carries a `history` field recording whether history is retained and over what window, because it changes the meaning of every other node. This is the clearest case in the whole product, because it needs no security argument — anybody understands that a tool which remembers everything you have shown it can be asked about any of it, and the asking need not come from you.

## What Already Exists, So This Pack Does Not Rebuild It

Both source briefs open with the same instruction: inventory before you design. Done, and it changed the pack.

| Source | Adopt / build | What |
|---|---|---|
| **A mature open policy language (Cedar)** | **Adopt** | Expresses principal, action, resource, context; default-deny; delegation depth limits; **evaluates in a separate process outside the agent's loop** — the exact boundary-vs-setting test this corpus set. It is the compilation target for the mandate's allow-list. It states plainly that it does *not* establish identity, so it composes with the registry rather than competing |
| **graphs.sgit.ai** | **Adopt** | A scoped lexicon, formally defined edge sets with distinct inverses, provenance chains tracking source and authority, multi-scale nodes, and a release gate that fails when frozen content drifts. The grant tree is a graph in that house style rather than a bespoke format, and the drift gate is the library's drift mechanism, already built |
| **pki.sgit.ai** | **Surface** | The register now exists (v0.1.26): identities, mandates, grants, the tree, control labels, at public URLs. This pack's library entries reference registry records; they do not restate them |
| **The mandate document** | **Build** | Nothing found declares a mandate with an issuer and an interval. A permissions file says what is *allowed*; nothing anywhere says what was *expected*, by whom, until when. **That one document is the gap** |

## The First Shipped Artefact Is Small And It Is In This Pack

The v0.33.62 permissions brief measured a running environment and found that its session-end hook enforces committing, signing and pushing — and never checks which branch. The mechanism to make the branch constraint real is *a few lines in a hook that already exists*. That is the whole thesis in one case: here is a mandate, here is the grant it does not cover, here is the delta, and here is the delta closed by an enforcement point that already existed. This pack's [document 03](03__library.md) carries the first measured grant — of the very environment that produced this pack — and its [document 06](06__mvp.md) puts the branch-constraint compilation first in the build order.

## The Naming Checks, Already Run

`card` and `pack` are clean and used. `passport` was tested in this corpus before and found to misfit — set aside. **`wallet` is avoided**: it is taken by the payments work, and it would import the expectation of held verifiable credentials presented by the subject — a model this design deliberately does not use, since grants and mandates are artefacts signed by an issuer, not credentials held by a principal.

## Reading Order

| Order | Document | Covers |
|---|---|---|
| 1 | This document | The three constraints, the inventory, the settled findings |
| 2 | `01 — concepts` | Grant, mandate, delta, excess, shortfall, blind spot, tier, the ordering rule — the lexicon in the sibling site's format |
| 3 | `02 — schemas` | The grant document, the mandate document, the delta computed-not-stored, and the history field |
| 4 | `03 — library` | What a building block is, how it is generated, dated and drift-checked — and the first measured entry |
| 5 | `04 — workflows` | The user path and the agent path, which are different and both specified |
| 6 | `05 — mockups` | The six screens, and why screen four is the trap |
| 7 | `06 — mvp` | Scope, the acceptance test, and what is deliberately excluded |
| 8 | `99 — change control` | Every correction and decision; read it last if reading through, second if building |

## The Agent Is A Primary Consumer

The pack is as much for an agent as for a person, which adds three requirements no design review of screens would catch: the library must be obtainable in **one fetch**; the agent's output is a **document, not a rendering** (if the interface is where the data lives, the agent path does not exist); and the self-report must be **structured before it is compared**, which is what makes the blind-spot delta computable rather than a judgement. The pack's acceptance test is phrased that way, and no page is read by a human anywhere in it.

## What This Pack Is Not

- **Not the risk product.** It builds the library and the two documents; the instance, the risks and the decisions are RiskMandate's.
- **Not a new policy language.** Cedar exists, is default-deny, and evaluates outside the loop.
- **Not a new graph format.** The lexicon, edge sets and provenance conventions are graphs.sgit.ai's.
- **Not a risk-first flow.** Reality, then facts, then the delta, then risks — the ordering is a constraint.
- **Not a claim that a self-report is enough.** It is a floor, and the library is what makes it checkable.

---

*This document is a site-agent first pass. Where it and a later document disagree, the change-control appendix records which is current. All content CC BY 4.0.*
