for agents/llms.txtv0.7.6 · 8 Oct 2026

Edition of 2026-10-0747 articles · 3 desk notes · 3 collections · 1 issuesgit.ai · v0.7.6

SGit Newsroom

One page, one argument, with the figures, the data and the links to check it. Every article is live the moment it is written; the front is the newsroom's choice of where to start.

From the editor Second edition, the same day. The lead moves to the open AI governance framework, because it carries more checkable evidence than anything else published today: a vault with its read key, a database that runs in the browser, and a walk from a control down to a paragraph of the AI Act. The Mandate Stack stays on the front as a highlight, beside the new piece on permission prompts, which reads the same behaviour policy from the person's side. The desk log →

Open framework, built on2026-10-07Graphs & knowledgeAn open AI governance framework, and what its licence let us buildTwenty open AI governance controls under CC BY-SA, why the licence matters, and the same day's conversion into a graph, a database and a walk down to EU law.Why it leads. Twenty open controls, read for what they add, then converted the same day into a published vault, a graph and a browser database joined to the AI Act. The most evidence of anything new on the site.Read it →

Highlights

From the desk all notes →

Collections all collections →

Get the SGit Newsroom newsletter. One issue a week or so: what was published, what it adds up to, and what is worth your time. Subscribe to the SGit Newsroom →

Every article, newest first

2026-10-08Agents & policy7 threadsKnowing when to stop: what experience gives people, and what we have to design into agentsKnowing when to stop is the hard part for people and agents: what experience gives people, and the constraints that give agents the same perspective.
2026-10-08Agents & policy7 threadsAgency is not a yes: a scale for human and agent decisions, from rubber stamp to the reviewer who fixes the sourceA yes or no is not agency: seven dimensions, a seven-level scale for people and agents, and the review as a QA step that fixes the source.
2026-10-08Agents & policy4 threadsHope or enforcement: one customer service agent, three designs, and who keeps each promiseOne customer service agent built three ways, each with an Agent Behaviour Policy: how much of each policy is hope, and what one run can reach.
2026-10-08Agents & policy2 threadsWho are you protecting against? Draw the security line where the attacker is, not above itBefore deciding how secure to be, name the attacker: a six-tier ladder, an air-gapped Mac mini read against it, and eight startups drawing their line.
2026-10-08Agents & policy8 threadsEvery mistake added a rule: complexity, agents, and the way back to shippingWhen every agent mistake adds a rule, complexity wins: map the process, move each piece right as a small shipped component, and keep the rigour for the work.
2026-10-07News & evidence7 threadsLiquid content needs water: liquefy the journalist's notebook, not the finished productA reply to FT Strategies on liquid content: the water is the reporting, so liquefy the journalist's notebook, keep the writing theirs, and pay per use.
2026-10-07News & evidence4 threadsThe bridge, followed to the end: what one local story is worth when it is kept as a graphA bridge closure simulated on a story vault: newsworthy on 5 days, needed on 57, used by three readers, four buyers and an agent, and paid back to its sources.
2026-10-07News & evidence4 threadsStory vault underneath, Reader Skills on top: why local journalism has the most to gainMarkus Franz's Reader Skills on top, the story vault underneath: each skill is a graph query, and local stories can pay back down their chain of sources.
2026-10-07Agents & policy5 threadsZoom into an agent's behaviour policy and you find the business logicBelow the first rules, an agent's behaviour policy is the business: functions, processes, clients, values. Layered, owned, counted, and where vendors plug in.
2026-10-07Agents & policy3 threadsA locked-down desktop for an agent, by the minute, is still hard to rentNine properties a safe agent desktop needs, nine products against them, the macOS day-long lease, and the startup credits that would pay for testing it.
2026-10-07Graphs & knowledge7 threadsAn open AI governance framework, and what its licence let us buildTwenty open AI governance controls under CC BY-SA, why the licence matters, and the same day's conversion into a graph, a database and a walk down to EU law.
2026-10-07Agents & policy12 threadsWhere is the why? A permission prompt asked me to decide, and kept the reasonA prompt asked for a decision and kept the reason. Read through the policy, the law on uninformed consent, and the fixes that worked: put the why in the prompt.
2026-10-06Agents & policy22 threadsThe Mandate Stack: a multi-agent system in production, layer by layerA multi-agent system that runs a business every few hours: eight layers, one written mandate per agent, everything a graph, one human who sends.
2026-10-06Agents & policy8 threadsWhy my agents do not run on my laptop: chat, Cowork and Code in the cloud, a vault as the shared drive, and the two walls an operating system hasAn OS has two hard walls, the kernel and the user; an agent on a laptop runs inside the one marked you, so the agents run in the cloud with a vault as shared drive.
2026-10-06Startups & strategy6 threadsThe deck I could not download: an author-first home for presentations, as a business plan somebody else can buildOne download offered as a subscription, an author paid nothing, and a design for the service the author would have chosen: vaults, keys, seven roles, 85% to the author.
2026-10-06Agents & policy20 threadsThe agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends fromTwelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
2026-10-06Agents & policy13 threadsA personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browserThe 2026 personal agents read through behaviour policy and encryption, and a design on vaults, an attested enclave and the browser where no vendor holds a key.
2026-10-05Agents & policy5 threadsThe investigation GitHub owes its customers: why a global outage of a platform the world deploys through deserves an aviation-style inquiry, and how the evidence could now be gatheredA global GitHub Actions outage read the way aviation reads an incident: independent inquiry, near-miss reporting, second and third stories, vaults for the evidence.
2026-10-05Agents & policy8 threadsSend an agent, not a spreadsheet: the next generation of software due diligence, and why the companies that stopped reading their code are about to be asked about itDue diligence never scaled because it was a form; a buyer can now send an agent into a vendor's environment and read what the code and the practices are.
2026-10-05Graphs & knowledge10 threadsHow much of this did I write? The numbers behind twenty articles in four weeks, and what the input actually wasTwenty articles in four weeks, measured from the session record: 63,000 words in, 85,000 out, no one-line prompts, and the real input is twenty years of writing.
2026-10-05Graphs & knowledge11 threadsIf somebody built a company on code review: how I would do it, and why it is only now possibleA reader's seven questions answered as a company plan: one reader for every layer, review as a science, and the layers as the customer's own.
2026-10-05Agents & policy9 threadsThe identity we wanted to give the agents: a week of design, the line in Google's terms, and why login plus secrets is still too hardA week of designing identities for agents and users met Google's terms; what survived is a passkey-unlocked keyring and a gap nobody sells.
2026-10-04Agents & policy8 threadsThe wall under the reply: end an email with the state of the thread, not the threadEnd an email reply with the state of the thread for this reader, not the quoted wall: decided, open, next, who is on copy, with links to the record.
2026-10-03Graphs & knowledge14 threadsMemory is not a spectator sport: how a web of open sites, graphs and vaults became the memory for sessions like this oneAgentic memory as context management: many published, fractal, provenance-carrying memories rather than one store, shown in the session that wrote the article.
2026-10-03Graphs & knowledge11 threadsCode review as a fractal semantic graph: source code is already one, and the review should read every layer of itSource code is layers within layers, each a graph with its own vocabulary; code review should read a change at every one, and a vault shows it done on real code.
2026-10-02Agents & policy12 threadsReplicating the agentic inbox: a walkthrough from one Claude session to a team of agents that never press sendHow to copy a working agentic email setup in phases: a mailbox and Claude seat of the agent's own, one session with a policy, then roles talking in files.
2026-10-02Startups & strategy3 threadsPrice it, then give it away: the early access programme as the next step after "do they miss it"Define the product, price it, deliver it at a cost that grows a step at a time, then offer it free to people who know you and measure what it costs them.
2026-10-02Agents & policy18 threadsFootprint and blast radius: what the agent actually did, and what it would have costFootprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.
2026-10-01Graphs & knowledge16 threadsCustom UIs are not the exception: the inbox in 2026, where every message has its own universeEvery message has a graph, so it can be shaped for the reader's moment; a custom interface per moment is now how interfaces get made, and each gets a policy.
2026-09-30Agents & policy14 threadsThe ultimate insider: agents, the infrastructure that cannot hold them, and risk management that cannot keep upAgents, the infrastructure meant to contain them, and risk management run on spreadsheets are arriving at once, and together they are one scenario.
2026-09-29News & evidence6 threadsThe reader was always the product: a corrected history of how news got into this messNews has sold the reader to advertisers since 1833; the web took the monopoly, the platforms made the reader measurable, and AI took the traffic.
2026-09-29Agents & policy18 threadsSix agents, one inbox: what a real multi-agent setup taught me about access policiesAn access policy for an agent is only as real as its worst row: every rule in a real six-agent setup, graded by how it is enforced today.
2026-09-28News & evidence6 threadsSixteen thousand fetches, ten clicks, and a token bill nobody is sending: the case for paying publishers to be easy to readAI answer engines pay to read the web as HTML; a publisher who serves markdown, dates, hashes and a typed graph saves them tokens and should get a share.
2026-09-27Vaults & method5 threadsA supply chain of vaults: how GenAI, open data and small custom tools could bring the price of food downThe food chain is a data problem: one encrypted vault per party, joined by append lanes and a typed graph, could cut the waste that keeps prices high.
2026-09-24Agents & policy14 threadsEvery risk is already accepted. The only question is by whom, and for how long.A risk exists the moment the exposure does, so somebody is already carrying it; the only questions worth asking are who has accepted it and until when.
2026-09-24Agents & policy11 threadsBefore you give an agent a connector, give the connector a twinAn agent with a Gmail or Calendar connector can do things the platform cannot undo; a journal of every call, replayed, shows what it did and what can go back.
2026-09-22News & evidence7 threadsThe future of news is the story vault, not the paywallA story is a graph of claims and evidence and the article is one projection of it; keep the graph in a vault and sell what the article was made from.
2026-09-21Startups & strategy4 threadsFor a startup, the most important question is whether they miss itShip something usable, give it away briefly, take it away and see whether anybody misses it; charge at a profit before you talk to investors.
2026-09-21Startups & strategy3 threadsThe SaaS apocalypse will be decided by inertia, not by AIIncumbents and newcomers have the same AI; what separates them is how much past success each has to protect, so inertia decides which SaaS companies survive.
2026-09-20Graphs & knowledge17 threadsFractal Semantic Graphs: everything connects to everything, and nobody has to share a schemaA fractal semantic graph has no privileged level and no single schema: each world keeps its own vocabulary and connects to others through named edges.
2026-09-07Site & engineering1 threadThe proof moved up, the homepage after the rebuild, next to the before picturesThe rebuilt homepage puts four real vaults under one sentence, picks six by the job they do, and computes its numbers at build time from the site's own data.
2026-09-07Site & engineering1 threadThe proof is two clicks behind the claim, what the homepage gets wrong, and the fixThe homepage leads with encryption, which cannot be seen, while twenty-five vaults a stranger can open in one click sit two clicks away in a table.
2026-08-27Site & engineering1 threadA chat box on a site with no server, the plan, and the trade it makessgit.ai has no server, so its directory chat runs a local matcher by default, takes your own key as an opt-in, and leaves the vault bridge unbuilt.
2026-08-26Site & engineering2 threadsTwenty sites in fifteen days, and what that did to the writingOne site became twenty repositories in fifteen days because each argument needed its own version history, and the index now starts from a question.
2026-08-25Vaults & method4 threadsGit for things you cannot put on GitHubsgit is git for files you cannot put on GitHub: encrypted before they leave your machine, versioned like git, stored where the server cannot read a byte.
2026-08-19Vaults & method2 threadsSeven vaults, one methodPublishing seven encrypted vaults in a fortnight produced a method, and every rule in it exists because something went wrong first.
2026-08-17Site & engineering2 threadsGreen does not mean liveTwo releases passed every check and never reached the site because the checks stopped at the git remote; a release now ends by asking the live site its version.

How they connect

Read from the links the articles make to each other. The same thing drawn as a map, and every article as its own graph.

Two rules keep these from going stale. An article never restates a fact it does not own, it links to the page that does, so when the fact changes the article does not start lying. And an article that makes a testable claim links to the test, the same way the comparison pages do.