THE PREVIOUS DESIGN How this page looked until v0.3.15. Kept, not maintained. the same page, as the store looks now ↗
Produced with model assistance. Every page on this site, and every document in the dev packs area, was drafted with a large language model and reviewed by a person before publication. Nothing on this site is a compliance assessment, and no page claims conformity to any standard. What we do not say, and why · how every claim here is evidenced

the previous design / Every agent needs a licence to operate

Every agent needs a licence to operate

You know what you asked for. You do not know what it can do. An Agent Behaviour Policy puts both on one page for one agent in one deployment: what it can do, what you authorised, and the gap between them. Fifteen applications, four levels, £10 to £1,500.

Who are you?

A founderShipping with agents, and somebody is going to ask.An investorBacking a company, and need somebody to look.A C-level execHave to answer for it, to a board.A security professionalDo this for a living, and want the method.Risk and governanceOwn the register, and need the mapping.

Every level is reachable from every one of these. What changes is which one a view opens on and what is said about it — not what is for sale. All six, side by side.

The four things for sale

1

The pack, downloaded

You want the material and you do not want to run anything.

£10Immediately

Every file in the vault, downloaded by you. Yours to use, keep and hand to your agent.

exists and runs

The payment link has not been issued yetWhat arrives, and what does not →

2

A working vault

You want the thing itself rather than a copy of its contents.

£501 to 2 days

The same material as a vault you hold the keys to: clone it, change it, version it, and hand anyone a read key.

exists and runs

The payment link has not been issued yetWhat arrives, and what does not →

3

Corrected for your situation

Your deployment is not the template, and you would rather not do the correcting.

£5001 to 3 days

You tell us the industry, the use case and the details. The mandate is corrected against them and the vault comes back yours.

delivered by a person

The payment link has not been issued yetWhat arrives, and what does not →

4

Two sessions and a custom vault

The answer has to survive somebody else asking about it.

£1,5001 to 5 days

Half an hour with your team to find out what is actually running, and half an hour to deliver it — reviewed and signed off by a security professional.

delivered by a person

The payment link has not been issued yetWhat arrives, and what does not →

Every level is the same document. What changes is the form it arrives in and who does the correcting — and the line between the third and the fourth is the line between a thing agents do and a thing a person signs. What is actually inside one →

The first two arrive automatically. The top two are somebody's work. That is the line that matters when you are choosing: the pack and the vault are produced the moment you pay, and the corrected mandate and the two sessions are done by a named security professional and signed off. The method behind all four has been done many times — six vaults of it are open to read right now, linked below. exists and runs 16 Sep 2026 exists and runs 15 Sep 2026 delivered by a person 15 Sep 2026 delivered by a person 15 Sep 2026

Which agent do you run?

Pick the application closest to yours and the level you want it at. The whole catalogue is here — Claude Code on a machine and in CI, Claude Desktop, ChatGPT in the browser, a browser extension, GitHub Actions, a scheduled job, Gmail and Drive at read-only scope, the Microsoft 365 connector, Dropbox, n8n, and the rest. Something not on the list starts at the third level, because the first two deliver an existing template and for yours there is not one yet.

Six of these, open right now

This work has been done, repeatedly, and it is published. Not a testimonial and not a case study — the vaults themselves, each opened by a read key published on its own page. Go and open one before you buy anything here.

Twenty-eight encrypted vaults are published at sgit.ai, each opened by a read key the site publishes on that vault's own page. The six below are the ones that are this work rather than something else. Each one opens with a read key published on its own page — no account, nothing to install, and nothing asked of you for looking.

Licence to Operateposrhzp3 · 13 MB, 121 files · 4 September 2026

“One agent, its grant of 12 capabilities, its mandate of 4, and the 8-capability delta no policy covers — with a simulated conversation where every reply carries its cost against a live policy”

This is the thing this store sells, built and published. One agent, its grant of twelve capabilities, its mandate of four, and the eight-capability delta no policy covers — which is the exact shape of every document on this site.

RiskMandate · File securitywu365g94 · 2.7 MB, 71 files · 25 August 2026

“An eleven-step risk-acceptance walk, running SQLite in the browser”

A risk register walked from a first finding to an accepted position, over one evolving record. The £500 level is this, done against your situation instead of that one.

Risk Graph Explorer3simlnqe · 428 KB, 33 files · 17 August 2026

“A fact-to-risk graph explorer, built to be public: its app.json requests nothing”

The estate, the role risk map, the risk chains, the register and the acceptance gate — the views a reader of one of these documents actually needs.

AIUC-1 conformance layer2wzct4k7 · 43 MB, 649 files · 5 September 2026

“53 controls, 144 requirements, 1,126 crosswalks — attested_by kept permanently apart from evidenced_by, and 53 conformance rows for a named subject where unevidenced is the default”

Fifty-three controls and a hundred and forty-four requirements turned into something a position can be measured against, with what is attested kept permanently apart from what is evidenced.

Scaling Threat Modeling with Semantic Knowledge Graphs0ict6flm · 4.1 MB, 53 files · 27 August 2026

“ThreatModCon 2025: eleven linked threat models across 51 nodes and 179 threats”

Delivered to a room at a conference in Barcelona, and published afterwards with the models in it. Evidence that the method survives being presented to people who do this for a living.

Regulation Graph73heuprz · 14.9 MB, 207 files · 20 August 2026

“The EU AI Act parsed from Formex into an evidence graph, article by article”

Regulation (EU) 2024/1689 as something you can cite a row of, hash-verified to the official source bytes. What a mapping to a standard looks like when it is done properly.

Quoted from the published catalogue, retrieved 16 September 2026. It is generated at sgit.ai from the same file that site's own table is built from, so the descriptions above are that catalogue's words rather than this store's.

What the templates cost, and what they do not

The templates are free and public, with published read keys, at riskmandate.ai. That is not a generosity and it is not a funnel: a policy nobody can check is a policy asking to be trusted, and the whole point of this document type is that it can be checked. What is priced here is an instance — the same template with the mandate corrected, your name on the licence and no public key on it. The whole argument, at length → exists and runs 15 Sep 2026

Paying, in three lines

You build an order in your own browser and pay on the provider's own page. No account, no cookie, and no form, input or field anywhere on this site — a build check holds that line, so filtering is buttons, quantity is buttons, and your card is somebody else's business. What reaches the payment provider is the amount and an order reference carrying the codes for what you bought. Neither payment link has been created yetyour order says so on the button rather than showing something that looks live. The three steps · Both rails does not exist yet 11 Sep 2026

What this site will not tell you

Nothing here is a compliance assessment, and nothing here is a mark of conformity to a standard. Neither describes this, and that language appears on no deliverable and on no page. The company issues every opinion, with an express non-assumption of personal responsibility on its face, and the person who sells is never the person who signs.

Outputs are model generated and marked as such read, not run 2 Aug 2026. Findings are triaged, never raw: recall-optimised agents run at 0.388 precision, which is about three findings in five wrong, so every finding that reaches you has been reproduced rather than reviewed measured 10 Sep 2026.

And one sentence that a reader might expect on a page like this is not here on purpose: we do not tell you what we can and cannot read, because six questions about what leaks have not been answered yet. The disclosures page says which six. does not exist yet 10 Sep 2026