# Behaviour policy in practice, a collection, sgit.ai

> RiskMandate's Agent Behaviour Policy applied to real agents: one inbox, a team of twelve, the personal agents of 2026, and what an agent actually did afterwards.

*Source: <https://sgit.ai/articles/collections/behaviour-policy-in-practice.html> · site v0.6.90 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../index.md) / [Articles](../index.md) / [Collections](index.md) / Behaviour policy in practice

Collection · 7 articles · curated by the [Historian](../../newsroom/roles/historian.md) · updated 2026-10-07

# Behaviour policy in practice

RiskMandate's Agent Behaviour Policy applied to real agents: one inbox, a team of twelve, the personal agents of 2026, and what an agent actually did afterwards.

The policy is written before an agent runs: what it can reach, what it was asked to do, the gap between the two, and the barriers in the gap. These articles each take it somewhere new.

Start with [six agents, one inbox](../../articles/six-agents-one-inbox.md), where every rule in a real setup is graded, and the finding is that a policy is only as real as its worst row. [The connector twin](../../articles/connector-twin-before-you-deploy-an-agent.md) is the barrier for the actions a platform cannot undo. [Footprint and blast radius](../../articles/footprint-and-blast-radius.md) adds the two words for afterwards: what the agent did, and what it would have cost. [Why my agents do not run on my laptop](../../articles/why-my-agents-do-not-run-on-my-laptop.md) is the reach question asked of the operating system.

Then the policy at scale: [the agent team as it runs](../../articles/the-agent-team-as-it-runs.md) and [the Mandate Stack](../../articles/the-mandate-stack.md) are the same team described from its field notes and from its CRM agent's briefing, and [a personal agent that keeps your secrets](../../articles/a-personal-agent-that-keeps-your-secrets.md) reads seven commercial personal agents through the same four words.

This newsroom runs on the same idea: every desk role has a written policy, and [the policies page](../../newsroom/policies.md) is generated from the files the checker reads.

## The articles

[2026-09-29Agents & policy17 threads**Six agents, one inbox: what a real multi-agent setup taught me about access policies**An access policy for an agent is only as real as its worst row: every rule in a real six-agent setup, graded by how it is enforced today.](../../articles/six-agents-one-inbox.md)[2026-09-24Agents & policy11 threads**Before you give an agent a connector, give the connector a twin**An agent with a Gmail or Calendar connector can do things the platform cannot undo; a journal of every call, replayed, shows what it did and what can go back.](../../articles/connector-twin-before-you-deploy-an-agent.md)[2026-10-02Agents & policy17 threads**Footprint and blast radius: what the agent actually did, and what it would have cost**Footprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.](../../articles/footprint-and-blast-radius.md)[2026-10-06Agents & policy16 threads**The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from**Twelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.](../../articles/the-agent-team-as-it-runs.md)[2026-10-06Agents & policy8 threads**Why my agents do not run on my laptop: chat, Cowork and Code in the cloud, a vault as the shared drive, and the two walls an operating system has**An OS has two hard walls, the kernel and the user; an agent on a laptop runs inside the one marked you, so the agents run in the cloud with a vault as shared drive.](../../articles/why-my-agents-do-not-run-on-my-laptop.md)[2026-10-06Agents & policy13 threads**A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser**The 2026 personal agents read through behaviour policy and encryption, and a design on vaults, an attested enclave and the browser where no vendor holds a key.](../../articles/a-personal-agent-that-keeps-your-secrets.md)[2026-10-06Agents & policy22 threads**The Mandate Stack: a multi-agent system in production, layer by layer**A multi-agent system that runs a business every few hours: eight layers, one written mandate per agent, everything a graph, one human who sends.](../../articles/the-mandate-stack.md)

[← All collections](index.md) · [The front page](../index.md)


---

*[Site index for agents](../../llms.txt) · [HTML version](https://sgit.ai/articles/collections/behaviour-policy-in-practice.html)*
