Produced with model assistance. Every page on this site, and every document in the dev packs area, was drafted with a large language model and reviewed by a person before publication. Nothing on this site is a compliance assessment, and no page claims conformity to any standard. What we do not say, and why · how every claim here is evidenced

store.sgit.ai / Which agent do you run?

Which agent do you run?

Pick the application closest to yours. Each one is an Agent Behaviour Policy: everything that agent can do, what you authorised it to do, the gap between them, and what actually stands in the way. The templates are free and public on riskmandate.ai, with published read keys — go and read one. What is priced here is that template with the mandate corrected, a name on the licence and no public key, and at the upper two levels the correction done with you rather than by you.

The catalogue

  • Claude Code on the web — A managed, ephemeral container with one repository attached and an egress proxy above it. The shape this site is maintained from; 13 of 20 rows measured on the thing itself. 15 it can do, 6 wanted, 7 with nothing in the way.
  • Claude Code on your machine — The coding agent on a developer's own machine with confirmation prompts enabled. Read this one beside the confirmations-off shape: one setting moves one barrier and not one number changes. 16 it can do, 5 wanted, 12 with nothing in the way.
  • Claude Code, confirmations off — The same agent, the same machine, the same account, with the confirmation prompt switched off. The prompt was the only thing between an authorised capability and the whole machine, and it was a switch the agent's account could flip. 16 it can do, 5 wanted, 12 with nothing in the way.
  • Claude Desktop — The desktop app with local tools on: files, processes and the network of the machine it sits on. Ten capabilities, three wanted, eight with nothing real in the way. 10 it can do, 3 wanted, 8 with nothing in the way.
  • Claude in the browser, connectors on — Chat with connectors enabled: the tenant's accounts are in reach through whatever was connected. The two excess rows here both sit behind a boundary, which is the exception in this directory. 5 it can do, 3 wanted, 0 with nothing in the way.
  • ChatGPT in the browser — The smallest grant in the set: one capability, one wanted, no excess. The baseline every other shape is measured against, and the proof that a template can be empty and still be right. 1 it can do, 1 wanted, 0 with nothing in the way.
  • A browser extension — Other people's data, and the mandate nobody wrote down. Three capabilities, all three irreversible; the shortest policy in the directory and not the mildest. 3 it can do, 1 wanted, 2 with nothing in the way.
  • GitHub Actions — A hosted runner under a service account: persistence, and reach beyond the turn. Eight of eight rows measured, the only fully measured shape besides the web container. 8 it can do, 5 wanted, 3 with nothing in the way.
  • A scheduled job — A job that outlives the person who made it, running as a service account nobody logs in as. Seven capabilities, four wanted, four with nothing in the way. 7 it can do, 4 wanted, 4 with nothing in the way.
  • Google Workspace MCP servers — Gmail, Drive, Docs, Sheets, Slides, Calendar and Chat, one server each. The page advertises drafting mail and scheduling meetings; the scopes it asks for send mail and cannot touch a calendar. 6 it can do, 2 wanted, 1 with nothing in the way.
  • Gmail, read-only scope — The narrowest scope that reads one message reads every message. Lab 03 asked the model site for this shape first; here it is, read from Google's scope page. 4 it can do, 1 wanted, 2 with nothing in the way.
  • Google Drive, read-only scope — The default corpus is "files owned by or shared to the user": everything anybody ever shared, on day one, without anyone choosing it. 3 it can do, 1 wanted, 1 with nothing in the way.
  • Microsoft 365 connector (Claude) — Delegated permissions, consented once by a Global Administrator. Shared mailboxes are in scope; site-specific narrowing is unsupported because the search is tenant-wide; and the page that says "read-only access" also lists the tools that send mail as the user. 5 it can do, 2 wanted, 1 with nothing in the way.
  • Dropbox MCP server — Eight scopes, two of them write and two of them sharing, and no folder-scoped variant. It reads, creates, moves, deletes and makes shared links; the page says files are not deleted permanently and that recovery depends on your plan. 5 it can do, 1 wanted, 0 with nothing in the way.
  • n8n, owner API key — The first grant here measured on a live instance, by an early beta user's agent: full control of every automation, an outbound node with no restriction on target, every account visible, and credential metadata open through one door and shut through another. 8 it can do, 4 wanted, 4 with nothing in the way.
  • Something not on this list — An agent, a connector or a deployment nobody here has profiled. The grant is measured or read from the vendor's own pages first, and the vault is built from that rather than from a template.

The four levels

Every level is the same document. What changes is the form it arrives in and who does the correcting.

LevelPriceWhat it isWho does it
1The pack, downloaded
You want the material and you do not want to run anything.
£5Every file in the vault, downloaded by you. Yours to use, keep and hand to your agent.automated
2A working vault
You want the thing itself rather than a copy of its contents.
£50The same material as a vault you hold the keys to: clone it, change it, version it, and hand anyone a read key.automated
3Corrected for your situation
Your deployment is not the template, and you would rather not do the correcting.
£500You tell us the industry, the use case and the details. The mandate is corrected against them and the vault comes back yours.agents with review
4Two sessions, and a professional signs it
The answer has to survive somebody else asking about it.
£1,500Half an hour with your team to find out what is actually running, and half an hour to deliver it — reviewed and signed off by a security professional.person

Every level is the same document. What changes is the form it arrives in and who does the correcting — and the line between the third and the fourth is the line between a thing agents do and a thing a person signs.

Something not on the list? An agent, a connector or a deployment nobody has profiled yet starts at the third level, not below it — the first two deliver an existing template and for yours there is not one. The grant gets measured, or read from the vendor's own pages and dated, before anything is built. That one is here.

What the counts on a tile mean

Four numbers, and not one of them is a score.

There is no rating here and there will not be one. The same policy is dangerous in one deployment and harmless in another, and nothing about the document changed: risk depends on the assets, the consequences and the date. A policy cannot be dangerous; a deployment can.

Where the list comes from

riskmandate.ai publishes these shapes and this store promotes them. The catalogue on this page carries the source URL, the time it was retrieved and a hash of the page it was read from, because no page on this site opens a network connection — that is a build check rather than an intention, so the list is taken at build time rather than fetched while you read.

A shape added upstream is on this page at the next build. One that arrives without a code here stops the build rather than rendering a tile whose buttons produce a product code nobody can fill.