pki.sgit.ai / packs / registry-mvp / grant-tree

12 — The grant tree and control labels

PackThe Registry MVP: Open Data, A Single Operator, LLM Sessions First RoleBlast radius is a path through a tree, and the label on each node is the column nobody publishes Date20 August 2026 · draft-1 + change control OriginSite agent, this repo Sourceraw markdown · on GitHub

Summary

The grant side, which the pack had specified least and needed most once C1 made the gap between grant and mandate the product. A grant is a tree of subgrants, so blast radius is a path through it rather than an item in a list — and the load-bearing part is the label on each node, above all who enforces the thing standing in the way. The general test needs no vendor claim: a control bounds a grant only when it is enforced by something the grant does not include, giving boundary, setting and expectation, and placing most of what people currently rely on in the middle tier that reads like a boundary and behaves like a setting. Plus the shortfall, the region C1 never named; the two populations with one hosted tree measured rather than described; prohibitions as a generated presentation layer over a stored allow-list; and the correction that counting acceptances is the one metric that inverts under pressure.

Key concepts

Key ideas

Read the document

📄 Pack document · 12__grant-tree-and-control-labels.md · rendered from the raw markdown (the source of truth)