# The week to 7 October: the agent team, written up from the inside, sgit.ai desk

> The busiest week of articles on the site so far, and most of it is one story told three times at increasing depth: a team of agents running a business, from the walkthrough to the field notes to the full stack.

*Source: <https://sgit.ai/articles/desk/the-week-to-7-october.html> · site v0.6.90 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../index.md) / [Articles](../index.md) / [From the desk](index.md) / The week

The week · 2026-10-07 · by the [Journalist](../../newsroom/roles/journalist.md)

# The week to 7 October: the agent team, written up from the inside

*The busiest week of articles on the site so far, and most of it is one story told three times at increasing depth: a team of agents running a business, from the walkthrough to the field notes to the full stack.*

**Twenty articles** published from 2026-10-01 to 2026-10-07, newest first, each with the one-sentence teaser from its graph.

1. 2026-10-07[An open AI governance framework, and what its licence let us build](../../articles/ai-baseline-control-framework.md) Twenty open AI governance controls under CC BY-SA, why the licence matters, and the same day's conversion into a graph, a database and a walk down to EU law.
2. 2026-10-07[A locked-down desktop for an agent, by the minute, is still hard to rent](../../articles/an-agent-desktop-by-the-minute.md) Nine properties a safe agent desktop needs, nine products against them, the macOS day-long lease, and the startup credits that would pay for testing it.
3. 2026-10-07[Where is the why? A permission prompt asked me to decide, and kept the reason](../../articles/where-is-the-why.md) A prompt asked for a decision and kept the reason. Read through the policy, the law on uninformed consent, and the fixes that worked: put the why in the prompt.
4. 2026-10-06[A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser](../../articles/a-personal-agent-that-keeps-your-secrets.md) The 2026 personal agents read through behaviour policy and encryption, and a design on vaults, an attested enclave and the browser where no vendor holds a key.
5. 2026-10-06[The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from](../../articles/the-agent-team-as-it-runs.md) Twelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
6. 2026-10-06[The deck I could not download: an author-first home for presentations, as a business plan somebody else can build](../../articles/the-deck-i-could-not-download.md) One download offered as a subscription, an author paid nothing, and a design for the service the author would have chosen: vaults, keys, seven roles, 85% to the author.
7. 2026-10-06[The Mandate Stack: a multi-agent system in production, layer by layer](../../articles/the-mandate-stack.md) A multi-agent system that runs a business every few hours: eight layers, one written mandate per agent, everything a graph, one human who sends.
8. 2026-10-06[Why my agents do not run on my laptop: chat, Cowork and Code in the cloud, a vault as the shared drive, and the two walls an operating system has](../../articles/why-my-agents-do-not-run-on-my-laptop.md) An OS has two hard walls, the kernel and the user; an agent on a laptop runs inside the one marked you, so the agents run in the cloud with a vault as shared drive.
9. 2026-10-05[How much of this did I write? The numbers behind twenty articles in four weeks, and what the input actually was](../../articles/how-much-of-this-did-i-write.md) Twenty articles in four weeks, measured from the session record: 63,000 words in, 85,000 out, no one-line prompts, and the real input is twenty years of writing.
10. 2026-10-05[If somebody built a company on code review: how I would do it, and why it is only now possible](../../articles/if-somebody-built-a-company-on-code-review.md) A reader's seven questions answered as a company plan: one reader for every layer, review as a science, and the layers as the customer's own.
11. 2026-10-05[Send an agent, not a spreadsheet: the next generation of software due diligence, and why the companies that stopped reading their code are about to be asked about it](../../articles/send-an-agent-not-a-spreadsheet.md) Due diligence never scaled because it was a form; a buyer can now send an agent into a vendor's environment and read what the code and the practices are.
12. 2026-10-05[The identity we wanted to give the agents: a week of design, the line in Google's terms, and why login plus secrets is still too hard](../../articles/the-identity-we-wanted-to-give-the-agents.md) A week of designing identities for agents and users met Google's terms; what survived is a passkey-unlocked keyring and a gap nobody sells.
13. 2026-10-05[The investigation GitHub owes its customers: why a global outage of a platform the world deploys through deserves an aviation-style inquiry, and how the evidence could now be gathered](../../articles/the-investigation-github-owes-its-customers.md) A global GitHub Actions outage read the way aviation reads an incident: independent inquiry, near-miss reporting, second and third stories, vaults for the evidence.
14. 2026-10-04[The wall under the reply: end an email with the state of the thread, not the thread](../../articles/the-wall-under-the-reply.md) End an email reply with the state of the thread for this reader, not the quoted wall: decided, open, next, who is on copy, with links to the record.
15. 2026-10-03[Code review as a fractal semantic graph: source code is already one, and the review should read every layer of it](../../articles/code-review-as-a-fractal-semantic-graph.md) Source code is layers within layers, each a graph with its own vocabulary; code review should read a change at every one, and a vault shows it done on real code.
16. 2026-10-03[Memory is not a spectator sport: how a web of open sites, graphs and vaults became the memory for sessions like this one](../../articles/memory-is-not-a-spectator-sport.md) Agentic memory as context management: many published, fractal, provenance-carrying memories rather than one store, shown in the session that wrote the article.
17. 2026-10-02[Footprint and blast radius: what the agent actually did, and what it would have cost](../../articles/footprint-and-blast-radius.md) Footprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.
18. 2026-10-02[Price it, then give it away: the early access programme as the next step after "do they miss it"](../../articles/price-it-then-give-it-away.md) Define the product, price it, deliver it at a cost that grows a step at a time, then offer it free to people who know you and measure what it costs them.
19. 2026-10-02[Replicating the agentic inbox: a walkthrough from one Claude session to a team of agents that never press send](../../articles/replicating-the-agentic-inbox.md) How to copy a working agentic email setup in phases: a mailbox and Claude seat of the agent's own, one session with a policy, then roles talking in files.
20. 2026-10-01[Custom UIs are not the exception: the inbox in 2026, where every message has its own universe](../../articles/custom-uis-are-not-the-exception.md) Every message has a graph, so it can be shaped for the reader's moment; a custom interface per moment is now how interfaces get made, and each gets a policy.

**One story, three depths.** [Replicating the agentic inbox](../../articles/replicating-the-agentic-inbox.md) said how to build it in phases. [The agent team as it runs](../../articles/the-agent-team-as-it-runs.md) wrote up the same team from its own field notes. [The Mandate Stack](../../articles/the-mandate-stack.md) described it in eight layers from a briefing its CRM agent wrote, with two Wardley maps and their sources, and was revised twice in the week.

**Personal agents, read through policy.** [A personal agent that keeps your secrets](../../articles/a-personal-agent-that-keeps-your-secrets.md) read the year's personal agents through the behaviour policy and through encryption; [why my agents do not run on my laptop](../../articles/why-my-agents-do-not-run-on-my-laptop.md) asked the reach question of the operating system.

**Review as a science, and the input measured.** [Code review as a fractal semantic graph](../../articles/code-review-as-a-fractal-semantic-graph.md) drew a reader's seven questions, answered in [if somebody built a company on code review](../../articles/if-somebody-built-a-company-on-code-review.md). And [how much of this did I write?](../../articles/how-much-of-this-did-i-write.md) counted the author's input across the month, which the desk has pulled out [as a nugget](../../articles/desk/a-model-that-can-go-in-every-direction.md).

## Rests on

- [Replicating the agentic inbox: a walkthrough from one Claude session to a team of agents that never press send](../../articles/replicating-the-agentic-inbox.md) How to copy a working agentic email setup in phases: a mailbox and Claude seat of the agent's own, one session with a policy, then roles talking in files.
- [The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from](../../articles/the-agent-team-as-it-runs.md) Twelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
- [The Mandate Stack: a multi-agent system in production, layer by layer](../../articles/the-mandate-stack.md) A multi-agent system that runs a business every few hours: eight layers, one written mandate per agent, everything a graph, one human who sends.
- [A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser](../../articles/a-personal-agent-that-keeps-your-secrets.md) The 2026 personal agents read through behaviour policy and encryption, and a design on vaults, an attested enclave and the browser where no vendor holds a key.
- [Why my agents do not run on my laptop: chat, Cowork and Code in the cloud, a vault as the shared drive, and the two walls an operating system has](../../articles/why-my-agents-do-not-run-on-my-laptop.md) An OS has two hard walls, the kernel and the user; an agent on a laptop runs inside the one marked you, so the agents run in the cloud with a vault as shared drive.
- [Code review as a fractal semantic graph: source code is already one, and the review should read every layer of it](../../articles/code-review-as-a-fractal-semantic-graph.md) Source code is layers within layers, each a graph with its own vocabulary; code review should read a change at every one, and a vault shows it done on real code.
- [If somebody built a company on code review: how I would do it, and why it is only now possible](../../articles/if-somebody-built-a-company-on-code-review.md) A reader's seven questions answered as a company plan: one reader for every layer, review as a science, and the layers as the customer's own.
- [How much of this did I write? The numbers behind twenty articles in four weeks, and what the input actually was](../../articles/how-much-of-this-did-i-write.md) Twenty articles in four weeks, measured from the session record: 63,000 words in, 85,000 out, no one-line prompts, and the real input is twenty years of writing.

[← From the desk](index.md) · [The front page](../index.md)


---

*[Site index for agents](../../llms.txt) · [HTML version](https://sgit.ai/articles/desk/the-week-to-7-october.html)*
