---
title: Which agent do you run?
description: "Fifteen Agent Behaviour Policies, one per application, at four levels: the pack by email at £5, a working vault you hold the keys to at £50, corrected against your situation at £500, and two sessions with a security professional signing it at £1,500."
lead: "**Pick the application closest to yours.** Each one is an Agent Behaviour Policy: everything that agent can do, what you authorised it to do, the gap between them, and what actually stands in the way. **The templates are free and public** on riskmandate.ai, with published read keys — go and read one. **What is priced here is that template with the mandate corrected, a name on the licence and no public key**, and at the upper two levels the correction done with you rather than by you."
order: 2
toc: true
wide: true
head_css: /assets/shop.css
---

## The catalogue

{{catalogue}}

## The four levels

Every level is the same document. **What changes is the form it arrives in and who
does the correcting.**

{{levels-table}}

**Something not on the list?** An agent, a connector or a deployment nobody has
profiled yet starts at the third level, not below it — the first two deliver an
existing template and for yours there is not one. The grant gets measured, or read
from the vendor's own pages and dated, before anything is built.
[That one is here](/p/your-own/).

## What the counts on a tile mean

Four numbers, and **not one of them is a score.**

- **It can do** — every capability the credential behind that deployment actually permits. Almost never enumerated anywhere, and reliably larger than whoever deployed it expected.
- **You wanted** — what it is authorised and expected to do. Usually clear, whether or not anybody wrote it down.
- **Not wanted** — the gap. Permitted, and nobody asked for it.
- **Nothing in the way** — how many of those sit behind something that is not a control. **This is the only number a control moves**, and the gap between the last two columns is the business case for putting one in.

**There is no rating here and there will not be one.** The same policy is dangerous
in one deployment and harmless in another, and nothing about the document changed:
risk depends on the assets, the consequences and the date. A policy cannot be
dangerous; a deployment can.

## Where the list comes from

**riskmandate.ai publishes these shapes and this store promotes them.** The
catalogue on this page carries the source URL, the time it was retrieved and a
hash of the page it was read from, because **no page on this site opens a network
connection** — that is a build check rather than an intention, so the list is taken
at build time rather than fetched while you read.

A shape added upstream is on this page at the next build. One that arrives without
a code here **stops the build** rather than rendering a tile whose buttons produce
a product code nobody can fill.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
