# v0.3.2 — who owns what, written down where both sides' agents can read it

Two sites, one purchase, and until today the boundary between them existed only in the heads of the people who drew it. /boundary/ is the rule: this store owns the cart, the order reference, the discount codes, the rails and the page a buyer lands on after paying; riskmandate.ai owns the fifteen shapes, the policies, the vaults, the deeper explanation and the screenshots. Every other question about where something belongs follows from that sentence, including which side a file currently on the wrong one has to move to.

It is on the selling side rather than in the admin console on purpose. A boundary nobody published is a boundary that moves, and a contract between two sites' agents has to be findable by both — so it is indexed, has a markdown twin and is in llms.txt.

THE SECOND HALF IS THE BRIEF, ADDRESSED TO THEM. Four asks in the order that makes each useful on its own: publish a manifest per level so this store can render the download in its own chrome; publish the shape catalogue as data rather than as a page this store parses; do not build a cart; and agree the SHAPE of what we both read rather than just the address, because CORS makes a read possible and does not make it safe to depend on. Plus what is explicitly not being asked for — no callback, no session, no shared state, no account on either side, because both are static sites and the arrangement works precisely because neither needs the other to be up in order to be correct.

Status open, and it will be recorded there when it is answered including if the answer is no. A brief that only appears when it succeeds is a brief nobody should trust.

THE ONE FILE ON THE WRONG SIDE IS MARKED AS DEBT RATHER THAN LEFT TO BE DISCOVERED. data/abp-catalogue.json is promoted from riskmandate.ai at build time with the source URL, the retrieval time and a sha256 of the page it was read from. Promotion at build time is the honest version of the wrong arrangement: it cannot drift silently. It is still the wrong arrangement and the page says so.

AND THE CHECK ADDED YESTERDAY CAUGHT THIS RELEASE'S OWN PREDECESSOR. The v0.3.1 note named the leaked code in its text, and a release note is an indexed page that never declared itself as one of that code's journeys. The rule is right and the note was wrong: it now describes the code without printing it.

- Released: 2026-09-16
- Built from commit: `251a8720ca41a8e4b0ca766112299b8ce5263807`
- Reconstructed: no

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
