{
  "site": "https://sgit.ai",
  "generated": "2026-10-06",
  "site_version": "v0.6.75",
  "schema": "https://sgit.ai/articles/graphs.html",
  "topics": [
    {
      "id": "agents-and-policy",
      "label": "Agents & policy",
      "means": "agents, behaviour policies, permissions, insider risk"
    },
    {
      "id": "vaults-and-method",
      "label": "Vaults & method",
      "means": "sgit, vaults, the publishing method, proofs and audits"
    },
    {
      "id": "news-and-evidence",
      "label": "News & evidence",
      "means": "newsrooms, evidence, claims, the token bill"
    },
    {
      "id": "startups-and-strategy",
      "label": "Startups & strategy",
      "means": "business models, pricing, open source, early access"
    },
    {
      "id": "graphs-and-knowledge",
      "label": "Graphs & knowledge",
      "means": "fractal semantic graphs, altitudes, memory, interfaces"
    },
    {
      "id": "site-and-engineering",
      "label": "Site & engineering",
      "means": "how this site and its network are built"
    }
  ],
  "node_kinds": [
    "artefact",
    "claim",
    "concept",
    "example",
    "method",
    "question"
  ],
  "edge_relations": [
    "answers",
    "compared-with",
    "contrasts",
    "depends-on",
    "example-of",
    "extends",
    "leads-to",
    "produces"
  ],
  "articles": [
    {
      "slug": "how-much-of-this-did-i-write",
      "title": "How much of this did I write? The numbers behind twenty articles in four weeks, and what the input actually was",
      "date": "2026-10-05",
      "updated": "2026-10-05",
      "url": "https://sgit.ai/articles/how-much-of-this-did-i-write.html",
      "markdown": "https://sgit.ai/articles/how-much-of-this-did-i-write.md",
      "card": "https://sgit.ai/articles/cards/how-much-of-this-did-i-write.webp",
      "teaser": "Twenty articles in four weeks, measured from the session record: 63,000 words in, 85,000 out, no one-line prompts, and the real input is twenty years of writing.",
      "topics": [
        "graphs-and-knowledge",
        "site-and-engineering"
      ],
      "tags": [
        "agentic-writing",
        "provenance",
        "evidence",
        "memory",
        "voice-memos",
        "human-in-the-loop",
        "llms",
        "sgit",
        "article"
      ],
      "links_out": [
        "memory-is-not-a-spectator-sport",
        "if-somebody-built-a-company-on-code-review",
        "code-review-as-a-fractal-semantic-graph",
        "introducing-fractal-semantic-graphs",
        "replicating-the-agentic-inbox",
        "the-wall-under-the-reply"
      ],
      "links_in": [],
      "graph": {
        "slug": "how-much-of-this-did-i-write",
        "teaser": "Twenty articles in four weeks, measured from the session record: 63,000 words in, 85,000 out, no one-line prompts, and the real input is twenty years of writing.",
        "topics": [
          "graphs-and-knowledge",
          "site-and-engineering"
        ],
        "core_idea": "Measured from the session transcript and the git history, the twenty articles of the last four weeks took 63,000 words from the author, mostly in thirty-five voice memos, and came out at 85,000 words through 122 releases, with no article from a one-line prompt; the corrections were to direction, framing, voice, vocabulary and scope rather than to hallucinations, and the input that mattered most was twenty years of published writing the agent could find and quote, which is why people with a direction are the input to the loop rather than displaced by it.",
        "nodes": [
          {
            "id": "the-question",
            "label": "How much of this did I write?",
            "kind": "question",
            "summary": "A friend found the volume of text baffling; the answer that I write briefs and review drafts is true and unbelieved, so the session was measured instead."
          },
          {
            "id": "the-record",
            "label": "The session record as evidence",
            "kind": "method",
            "summary": "The Claude Code transcript parsed for who said what and when, joined to the site's git history; limits stated, dataset published beside the article."
          },
          {
            "id": "evidence-vault",
            "label": "The evidence, as a vault",
            "kind": "artefact",
            "summary": "Every number as a file in a published vault with a read key: messages, releases, days, ledgers with message ids, corrections with latency, the dependency map, the article's own fractal, versions with diffs and provenance captures; built by two agents from a brief in an afternoon, and it corrected the article twice."
          },
          {
            "id": "scale",
            "label": "The scale",
            "kind": "example",
            "summary": "281 messages and 62,896 words in, 52,719 of them in thirty-five voice memos; twenty articles and 85,209 words out, 94 figures, 122 releases, 135 searches, 22 research agents."
          },
          {
            "id": "no-one-prompt",
            "label": "No article from a one-line prompt",
            "kind": "claim",
            "summary": "The shortest brief was one memo of 1,943 words; the longest ran to twenty-nine messages; the median article took three releases."
          },
          {
            "id": "seven-articles",
            "label": "Seven articles accounted for by hand",
            "kind": "example",
            "summary": "From 2,395 words in and 2,447 out over five rounds, to 4,522 words in plus a reader's email and 9,289 out over five; the ratio runs from one to four and is the least interesting number."
          },
          {
            "id": "corrections",
            "label": "What the corrections were",
            "kind": "claim",
            "summary": "Direction, framing, voice, vocabulary and scope, with one fact corrected in each direction; briefs getting better, not hallucinations being caught."
          },
          {
            "id": "direction",
            "label": "A model needs someone with a direction",
            "kind": "claim",
            "summary": "A model that can write well in every direction makes educated guesses; the person's job is to say which guess was meant, and each correction narrows the next."
          },
          {
            "id": "the-memo-stands-on",
            "label": "What the memo stands on",
            "kind": "claim",
            "summary": "The last article quotes thirty-three pieces of earlier writing: a 2010 tool, a book, 107 posts, 3,025 team files and twenty-six articles; the agent is fast because the record exists."
          },
          {
            "id": "published-memory",
            "label": "Published record as memory",
            "kind": "concept",
            "summary": "The memory article's mechanism measured: curated, open, machine-readable material the agent is pointed at, rebuilt from twenty-two times when the context was compacted."
          },
          {
            "id": "keep-going",
            "label": "Being able to keep going",
            "kind": "concept",
            "summary": "For twenty years lines of thinking stopped at the edge of what the business needed; now a thought can be followed to the end and published for the next one to stand on."
          },
          {
            "id": "compounding",
            "label": "The compounding",
            "kind": "claim",
            "summary": "Nineteen of twenty-seven articles cite an earlier one; corrections become rules in the build; each article is the distillation the next assumes."
          },
          {
            "id": "experts-are-the-input",
            "label": "The experts are the input",
            "kind": "claim",
            "summary": "Direction, angle, taste and experience are what the loop needs from a person; the architect and the reviewer scale the same way the writing does."
          },
          {
            "id": "what-is-open",
            "label": "What is open",
            "kind": "question",
            "summary": "The articles could be shorter; attribution is hand-checked for seven; the oldest record is quoted not counted; the conversations behind the memos are in no record."
          },
          {
            "id": "better-universe",
            "label": "A better universe to learn from",
            "kind": "claim",
            "summary": "The published trail of an idea, with its graphs, corrections and versions, is a better thing for a model to learn from than everything ever written without context; the vault behind this article is the next brief."
          }
        ],
        "edges": [
          {
            "from": "the-question",
            "to": "the-record",
            "rel": "leads-to"
          },
          {
            "from": "the-record",
            "to": "scale",
            "rel": "produces"
          },
          {
            "from": "the-record",
            "to": "seven-articles",
            "rel": "produces"
          },
          {
            "from": "scale",
            "to": "no-one-prompt",
            "rel": "produces"
          },
          {
            "from": "seven-articles",
            "to": "corrections",
            "rel": "leads-to"
          },
          {
            "from": "corrections",
            "to": "direction",
            "rel": "produces"
          },
          {
            "from": "the-memo-stands-on",
            "to": "published-memory",
            "rel": "example-of"
          },
          {
            "from": "seven-articles",
            "to": "the-memo-stands-on",
            "rel": "leads-to"
          },
          {
            "from": "published-memory",
            "to": "compounding",
            "rel": "leads-to"
          },
          {
            "from": "keep-going",
            "to": "the-memo-stands-on",
            "rel": "extends"
          },
          {
            "from": "direction",
            "to": "experts-are-the-input",
            "rel": "leads-to"
          },
          {
            "from": "compounding",
            "to": "experts-are-the-input",
            "rel": "leads-to"
          },
          {
            "from": "the-record",
            "to": "what-is-open",
            "rel": "contrasts"
          },
          {
            "from": "the-record",
            "to": "evidence-vault",
            "rel": "produces"
          },
          {
            "from": "evidence-vault",
            "to": "corrections",
            "rel": "extends"
          },
          {
            "from": "evidence-vault",
            "to": "better-universe",
            "rel": "leads-to"
          },
          {
            "from": "published-memory",
            "to": "better-universe",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "memory-is-not-a-spectator-sport",
            "if-somebody-built-a-company-on-code-review",
            "code-review-as-a-fractal-semantic-graph",
            "introducing-fractal-semantic-graphs",
            "replicating-the-agentic-inbox",
            "the-wall-under-the-reply"
          ],
          "pages": [
            "/demos/vaults/how-much-evidence/index.html",
            "/articles/data/how-much-of-this-did-i-write.json",
            "/articles/graphs.html",
            "/articles/index.html"
          ],
          "sites": [
            "https://diniscruz.ai/llms.txt",
            "https://github.com/the-cyber-boardroom/SGraph-AI__App__Send",
            "https://leanpub.com/secdevops"
          ]
        },
        "quotes": [
          {
            "text": "I rarely experience hallucinations; I experience briefs that need to be better.",
            "why": "The finding of the corrections list: one fact wrong, the rest a model choosing a reasonable direction and a person saying which one was meant."
          },
          {
            "text": "The agent is fast because the record exists.",
            "why": "The real input is twenty years of published writing, not the memo."
          },
          {
            "text": "The vaults, the graphs and the diffs are the product, not the articles.",
            "why": "Why the evidence behind the article is published as a vault and treated as the next brief."
          }
        ]
      }
    },
    {
      "slug": "if-somebody-built-a-company-on-code-review",
      "title": "If somebody built a company on code review: how I would do it, and why it is only now possible",
      "date": "2026-10-05",
      "updated": "2026-10-06",
      "url": "https://sgit.ai/articles/if-somebody-built-a-company-on-code-review.html",
      "markdown": "https://sgit.ai/articles/if-somebody-built-a-company-on-code-review.md",
      "card": "https://sgit.ai/articles/cards/if-somebody-built-a-company-on-code-review.webp",
      "teaser": "A reader's seven questions answered as a company plan: one reader for every layer, review as a science, and the layers as the customer's own.",
      "topics": [
        "graphs-and-knowledge",
        "startups-and-strategy"
      ],
      "tags": [
        "code-review",
        "fractal-semantic-graphs",
        "graphs",
        "wardley-maps",
        "agent-behaviour-policies",
        "explorer-villager-town-planner",
        "example-mapping",
        "refactoring",
        "blast-radius",
        "five-whys",
        "open-source",
        "startups",
        "ai-generated-code",
        "article"
      ],
      "links_out": [
        "code-review-as-a-fractal-semantic-graph",
        "six-agents-one-inbox",
        "introducing-fractal-semantic-graphs",
        "saas-apocalypse-decided-by-inertia-not-by-ai",
        "footprint-and-blast-radius",
        "connector-twin-before-you-deploy-an-agent",
        "the-question-is-whether-they-miss-it"
      ],
      "links_in": [
        "how-much-of-this-did-i-write",
        "send-an-agent-not-a-spreadsheet",
        "code-review-as-a-fractal-semantic-graph"
      ],
      "graph": {
        "slug": "if-somebody-built-a-company-on-code-review",
        "teaser": "A reader's seven questions answered as a company plan: one reader for every layer, review as a science, and the layers as the customer's own.",
        "topics": [
          "graphs-and-knowledge",
          "startups-and-strategy"
        ],
        "core_idea": "One technology can now read every layer from strategy to bytecode, which makes a graph at every altitude buildable and close to reality, and moves code review from an art of opinion to a science of facts if the models build, prune and maintain the graphs and then leave the line; what is fractal is the grammar and the layers are each company's own, so a code review company projects a graph from stories, derives one from code, reviews the join, holds one layer still to call a change a refactor, reshapes changes by reach, budgets per altitude as the objective good enough, runs its agents under behaviour policies, and gives the grammar away.",
        "nodes": [
          {
            "id": "one-reader-every-layer",
            "label": "One technology can read every layer",
            "kind": "claim",
            "summary": "From a board objective to a syntax tree in one path or through sub-agents of the same kind; what people did by instinct between altitudes becomes buildable, and buildable close to reality, for the first time at scale."
          },
          {
            "id": "art-to-science",
            "label": "From art to science",
            "kind": "claim",
            "summary": "Review was opinion, taste and power because there was no fact base; the map says where the code is and the graph says what a change reaches, and the models get review there only by building and maintaining the graphs and then leaving the line."
          },
          {
            "id": "grammar-vs-layers",
            "label": "The grammar is fractal, the layers are yours",
            "kind": "claim",
            "summary": "Nodes, edges, an ontology, a taxonomy and the move between altitudes are constant; which layers exist, what they are called and where they stop are decided by the company, its culture, languages and stack."
          },
          {
            "id": "projected-graph",
            "label": "The projected graph",
            "kind": "method",
            "summary": "Built top down before the code exists: objectives, stories with rules and examples, features and flows, the commands and surfaces they will touch, components as far as design can honestly see."
          },
          {
            "id": "derived-graph",
            "label": "The derived graph",
            "kind": "method",
            "summary": "Built bottom up from the syntax tree with no model in line: fingerprinted nodes, resolved calls, classes, modules, the commands the code exposes, and proposed stories marked as proposed."
          },
          {
            "id": "the-join",
            "label": "The review is the join",
            "kind": "claim",
            "summary": "Three outcomes: a match, where a derived surface serves a projected story; derived but not projected, a bug or an unwritten story; projected but not derived, the plan or the forgotten thing."
          },
          {
            "id": "rules-and-examples",
            "label": "Stories as rules and examples",
            "kind": "method",
            "summary": "Example Mapping's cards as the top layer: a story node whose children are rules, whose children are examples a test or a run can satisfy; prose stories were the right first layer and the wrong final one."
          },
          {
            "id": "held-layer",
            "label": "A refactor is relative to the held layer",
            "kind": "claim",
            "summary": "A refactor is a change where some layers move and one chosen layer, the one with the tests or the contract, does not; an architecture migration holding only the client interface is a refactor at a higher altitude."
          },
          {
            "id": "deploy-layer",
            "label": "The deploy is a layer",
            "kind": "concept",
            "summary": "Pipelines, environments, running services, configuration and secrets form a graph with its own verbs; a change's reach continues through it, and the non-functional requirements live there."
          },
          {
            "id": "who-reads",
            "label": "Who reads the code depends on the map",
            "kind": "claim",
            "summary": "Explorer code is read for intent, mostly by agents; villager code is read all the way down; town planner code is read by deterministic checks at the boundary, with a person for exceptions. The company sits in the two moves."
          },
          {
            "id": "reshape",
            "label": "Reshape the change before reviewing it",
            "kind": "method",
            "summary": "Split a change by reach: provably no behaviour, merged by a check; reaches tested behaviour, checks plus a glance; reaches a mission-critical path, the right people. Review is sorting, not saying no."
          },
          {
            "id": "reality-first",
            "label": "Replicate reality first",
            "kind": "method",
            "summary": "Derive what a parser can, let a model propose the rest marked proposed, confront the graph with users, experts and tests, version everything so a review can be replayed as the graph was."
          },
          {
            "id": "budgets",
            "label": "A budget per altitude, per change",
            "kind": "method",
            "summary": "Deterministic checks always run; the delta re-derives only what changed; models get small budgets and hard stops; onboarding starts at one point and continues; handed-on work carries its budget and never widens it."
          },
          {
            "id": "behaviour-policies",
            "label": "The reviewing agents run under a policy",
            "kind": "method",
            "summary": "Every agent deriving, proposing or summarising runs under an Agent Behaviour Policy written before its first run: which repositories, which actions, where it writes, what it spends; the control on the reviewers' own blast radius."
          },
          {
            "id": "five-whys",
            "label": "The five whys fix the layer below",
            "kind": "method",
            "summary": "Every finding at one layer is a question about the layer below, and the fix goes there as a rule or a graph query, so the next change like it is caught for the price of a query. Not whack-a-mole."
          },
          {
            "id": "compare-to-intent",
            "label": "Compare the blast radius to the intent",
            "kind": "claim",
            "summary": "Not to the old code: to the projected graph, the commit message, the existing documentation and the stories. Report one line per layer that moved; measure increments as projected nodes gaining a derived match."
          },
          {
            "id": "open-source-only",
            "label": "Open source is the only model that fits",
            "kind": "claim",
            "summary": "The layers are the customer's and the loop runs where the code is; sell the customised deployment, the running of the loop and the accumulated rules; give away the grammar, the parser and the model."
          },
          {
            "id": "corrections",
            "label": "What the first article got wrong",
            "kind": "example",
            "summary": "The refactor sentence was one refactor at one altitude; the seven altitudes were one repository's layers; the text skipped the commands and modules the delta had and the figure showed."
          }
        ],
        "edges": [
          {
            "from": "one-reader-every-layer",
            "to": "art-to-science",
            "rel": "leads-to"
          },
          {
            "from": "one-reader-every-layer",
            "to": "derived-graph",
            "rel": "produces"
          },
          {
            "from": "art-to-science",
            "to": "who-reads",
            "rel": "depends-on"
          },
          {
            "from": "art-to-science",
            "to": "budgets",
            "rel": "leads-to"
          },
          {
            "from": "budgets",
            "to": "behaviour-policies",
            "rel": "depends-on"
          },
          {
            "from": "behaviour-policies",
            "to": "reshape",
            "rel": "extends"
          },
          {
            "from": "grammar-vs-layers",
            "to": "open-source-only",
            "rel": "leads-to"
          },
          {
            "from": "projected-graph",
            "to": "the-join",
            "rel": "produces"
          },
          {
            "from": "derived-graph",
            "to": "the-join",
            "rel": "produces"
          },
          {
            "from": "rules-and-examples",
            "to": "projected-graph",
            "rel": "extends"
          },
          {
            "from": "the-join",
            "to": "compare-to-intent",
            "rel": "produces"
          },
          {
            "from": "held-layer",
            "to": "corrections",
            "rel": "example-of"
          },
          {
            "from": "grammar-vs-layers",
            "to": "corrections",
            "rel": "example-of"
          },
          {
            "from": "deploy-layer",
            "to": "grammar-vs-layers",
            "rel": "example-of"
          },
          {
            "from": "who-reads",
            "to": "reshape",
            "rel": "leads-to"
          },
          {
            "from": "who-reads",
            "to": "budgets",
            "rel": "leads-to"
          },
          {
            "from": "reshape",
            "to": "derived-graph",
            "rel": "depends-on"
          },
          {
            "from": "reality-first",
            "to": "derived-graph",
            "rel": "depends-on"
          },
          {
            "from": "budgets",
            "to": "five-whys",
            "rel": "contrasts"
          },
          {
            "from": "five-whys",
            "to": "who-reads",
            "rel": "extends"
          },
          {
            "from": "reality-first",
            "to": "compare-to-intent",
            "rel": "depends-on"
          },
          {
            "from": "who-reads",
            "to": "open-source-only",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "code-review-as-a-fractal-semantic-graph",
            "introducing-fractal-semantic-graphs",
            "saas-apocalypse-decided-by-inertia-not-by-ai",
            "footprint-and-blast-radius",
            "connector-twin-before-you-deploy-an-agent",
            "the-question-is-whether-they-miss-it",
            "six-agents-one-inbox"
          ],
          "pages": [
            "/demos/vaults/code-review-graphs/index.html",
            "/demos/vaults/synthetic-users/index.html"
          ],
          "sites": [
            "https://nfrs.sgit.ai/",
            "https://coding.sgit.ai/",
            "https://open-source.sgit.ai/",
            "https://wardley-maps.sgit.ai/",
            "https://diniscruz.ai/2025/06/10/explorers-villagers-and-town-planners-understanding-the-generative-ai-divide.md",
            "https://cucumber.io/blog/bdd/example-mapping-introduction/",
            "https://riskmandate.ai/abp.html",
            "https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/03/21/v0.16.26__article__who-should-read-the-code.md",
            "https://github.com/the-cyber-boardroom/SGraph-AI__App__Send/blob/dev/team/humans/dinis_cruz/briefs/07/12/architecture/v0.33.48__arch-brief__sg-send-fractal-semantic-graphs-agentic-operating-layer-deterministic-sovereign-open-source.md"
          ]
        },
        "quotes": [
          {
            "text": "A model in the line on every change is the art again with a different reviewer.",
            "why": "The condition on which the move from art to science depends: the models build and maintain the graphs, then leave the line."
          },
          {
            "text": "The grammar is fractal. The layers are yours.",
            "why": "The distinction the whole answer turns on, and the reason a review product has to learn each company's layers rather than impose its own."
          },
          {
            "text": "Review is not saying no. It is sorting what can go fast from what must go slow, and giving the slow part to people who have the context to decide well.",
            "why": "The job of the product, stated as a job to the change rather than to the reviewer."
          }
        ]
      }
    },
    {
      "slug": "send-an-agent-not-a-spreadsheet",
      "title": "Send an agent, not a spreadsheet: the next generation of software due diligence, and why the companies that stopped reading their code are about to be asked about it",
      "date": "2026-10-05",
      "updated": "",
      "url": "https://sgit.ai/articles/send-an-agent-not-a-spreadsheet.html",
      "markdown": "https://sgit.ai/articles/send-an-agent-not-a-spreadsheet.md",
      "card": "https://sgit.ai/articles/cards/send-an-agent-not-a-spreadsheet.webp",
      "teaser": "Due diligence never scaled because it was a form; a buyer can now send an agent into a vendor's environment and read what the code and the practices are.",
      "topics": [
        "agents-and-policy",
        "startups-and-strategy"
      ],
      "tags": [
        "due-diligence",
        "code-review",
        "agent-behaviour-policies",
        "blast-radius",
        "threat-models",
        "sbom",
        "cyber-resilience-act",
        "product-liability",
        "startups",
        "ai-generated-code",
        "fractal-semantic-graphs",
        "article"
      ],
      "links_out": [
        "if-somebody-built-a-company-on-code-review",
        "footprint-and-blast-radius",
        "six-agents-one-inbox",
        "every-risk-is-already-accepted",
        "code-review-as-a-fractal-semantic-graph",
        "connector-twin-before-you-deploy-an-agent",
        "supply-chain-of-vaults"
      ],
      "links_in": [
        "the-investigation-github-owes-its-customers"
      ],
      "graph": {
        "slug": "send-an-agent-not-a-spreadsheet",
        "teaser": "Due diligence never scaled because it was a form; a buyer can now send an agent into a vendor's environment and read what the code and the practices are.",
        "topics": [
          "agents-and-policy",
          "startups-and-strategy"
        ],
        "core_idea": "Software due diligence was a questionnaire answered by the vendor and disconnected from the code; a buyer can now send a prompt or a small agent under a behaviour policy to run inside the vendor's environment and derive a graph of what reaches production unreviewed, what is documented and threat modelled, what the bugs touched and which agents act under what policy, with the vendor redacting but not rewriting; the test is risk-based, the behaviour policy is the due diligence document for the agents, the companies that stopped reading their code are about to meet the consequence they have not had, a startup should double down on understandability, and the code review company is better sold to buyers than to developers.",
        "nodes": [
          {
            "id": "the-form",
            "label": "Due diligence was a form",
            "kind": "claim",
            "summary": "A spreadsheet of questions answered by the people being asked, measuring whether a document with the right title exists, disconnected from the code and out of date on arrival; built because nothing better was possible."
          },
          {
            "id": "careful-answers",
            "label": "Companies will not lie on a record",
            "kind": "concept",
            "summary": "Questionnaires invite careful, composed, defensible answers with room in them; a false statement on a record comes back with a lawyer, so the room is where the risk lives."
          },
          {
            "id": "the-agent",
            "label": "Send an agent, not a spreadsheet",
            "kind": "method",
            "summary": "A prompt and a small agent under a behaviour policy run inside the vendor's environment, derive graphs of practices and code, write files the vendor reviews before anything leaves, and deliver what is shown in a vault only the buyer opens."
          },
          {
            "id": "derived-not-composed",
            "label": "Derived, not composed",
            "kind": "claim",
            "summary": "The vendor keeps the redaction marker and loses the pen: a map read from the repository can be withheld but not described into shape, and a false map is a false statement on a record."
          },
          {
            "id": "non-answer",
            "label": "Questions where silence is an answer",
            "kind": "method",
            "summary": "Does code reach production unreviewed; is there a threat model and who wrote it; does the documentation match the code; what did the last fifty bugs touch; which agents touch the pipeline; who still understands it."
          },
          {
            "id": "threat-model-read",
            "label": "A threat model is the fastest read of a team",
            "kind": "claim",
            "summary": "Thin means the team does not know what it protects; gaps seen and decided about mean a team that knows where the lines are; the critical unknown vulnerability is almost never in it."
          },
          {
            "id": "bug-signature",
            "label": "Two kinds of bug",
            "kind": "concept",
            "summary": "Bugs in reviewed deterministic parts have reasons; bugs from unreviewed generated code are in places no story asked for, repeat, and reveal something structural each time."
          },
          {
            "id": "risk-based",
            "label": "Risk-based, not pure",
            "kind": "claim",
            "summary": "What counts as enough rises with what the software can do to the buyer; a startup on a prototype passes by saying so; the same sentence from a vendor of mission-critical software is the finding."
          },
          {
            "id": "policy-as-dd",
            "label": "The behaviour policy is the due diligence document",
            "kind": "claim",
            "summary": "A buyer reads off the blast radius, which controls are enforced by the identity and which are wishes, and which risks the vendor has accepted on the buyer's behalf; its absence is a finding before any code is read."
          },
          {
            "id": "the-consequence",
            "label": "The consequence that was missing",
            "kind": "claim",
            "summary": "Companies that stopped reviewing, let engineers go and let anyone prompt features into production accumulated liability that few outside could see; a buyer who can send an agent is the consequence, and investors and acquirers get it too."
          },
          {
            "id": "incumbents-too",
            "label": "Most companies already do not understand their software",
            "kind": "claim",
            "summary": "People moved on, merges were made by people who left, documentation describes an earlier system; the agent asks them the same questions for the first time."
          },
          {
            "id": "startup-advantage",
            "label": "The startup's two advantages",
            "kind": "claim",
            "summary": "It can play the same game as the biggest buyer with the same open source tools, and it has less code to understand; double down on understandability and make it the reason to buy."
          },
          {
            "id": "regulation",
            "label": "Duties arriving before visibility",
            "kind": "example",
            "summary": "Software bills of materials, the Cyber Resilience Act and the revised Product Liability Directive create duties and evidence rights; none tells a buyer whether a vendor understands its software; the agent connects the duties to the facts."
          },
          {
            "id": "the-twist",
            "label": "Sell it to the buyers",
            "kind": "claim",
            "summary": "The code review company is better sold as due diligence to those who buy, invest in and acquire software than as review to developers who have been told they do not need it; the vendor runs it on itself first."
          },
          {
            "id": "what-is-open",
            "label": "What is open",
            "kind": "question",
            "summary": "The agent does not exist; the pieces do; the first vendor it should run against is this site's own repository, with the results published."
          }
        ],
        "edges": [
          {
            "from": "the-form",
            "to": "careful-answers",
            "rel": "produces"
          },
          {
            "from": "the-form",
            "to": "the-agent",
            "rel": "contrasts"
          },
          {
            "from": "the-agent",
            "to": "derived-not-composed",
            "rel": "produces"
          },
          {
            "from": "careful-answers",
            "to": "derived-not-composed",
            "rel": "leads-to"
          },
          {
            "from": "the-agent",
            "to": "non-answer",
            "rel": "depends-on"
          },
          {
            "from": "non-answer",
            "to": "threat-model-read",
            "rel": "example-of"
          },
          {
            "from": "non-answer",
            "to": "bug-signature",
            "rel": "example-of"
          },
          {
            "from": "non-answer",
            "to": "risk-based",
            "rel": "depends-on"
          },
          {
            "from": "non-answer",
            "to": "policy-as-dd",
            "rel": "leads-to"
          },
          {
            "from": "the-agent",
            "to": "the-consequence",
            "rel": "leads-to"
          },
          {
            "from": "the-consequence",
            "to": "incumbents-too",
            "rel": "extends"
          },
          {
            "from": "incumbents-too",
            "to": "startup-advantage",
            "rel": "leads-to"
          },
          {
            "from": "regulation",
            "to": "the-consequence",
            "rel": "compared-with"
          },
          {
            "from": "the-consequence",
            "to": "the-twist",
            "rel": "leads-to"
          },
          {
            "from": "startup-advantage",
            "to": "the-twist",
            "rel": "extends"
          },
          {
            "from": "the-twist",
            "to": "what-is-open",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "if-somebody-built-a-company-on-code-review",
            "code-review-as-a-fractal-semantic-graph",
            "footprint-and-blast-radius",
            "six-agents-one-inbox",
            "every-risk-is-already-accepted",
            "connector-twin-before-you-deploy-an-agent",
            "supply-chain-of-vaults"
          ],
          "pages": [],
          "sites": [
            "https://riskmandate.ai/abp.html"
          ]
        },
        "quotes": [
          {
            "text": "The questionnaire gave the vendor the pen. The agent takes the pen away and leaves the vendor the redaction marker, and that is the whole change.",
            "why": "Why a derived answer differs from a composed one even though the vendor still controls what leaves."
          },
          {
            "text": "A vendor that does not know what reaches production unreviewed does not know what reaches production.",
            "why": "The first question, and why the non-answer is the finding."
          }
        ]
      }
    },
    {
      "slug": "the-identity-we-wanted-to-give-the-agents",
      "title": "The identity we wanted to give the agents: a week of design, the line in Google's terms, and why login plus secrets is still too hard",
      "date": "2026-10-05",
      "updated": "2026-10-05",
      "url": "https://sgit.ai/articles/the-identity-we-wanted-to-give-the-agents.html",
      "markdown": "https://sgit.ai/articles/the-identity-we-wanted-to-give-the-agents.md",
      "card": "https://sgit.ai/articles/cards/the-identity-we-wanted-to-give-the-agents.webp",
      "teaser": "A week of designing identities for agents and users met Google's terms; what survived is a passkey-unlocked keyring and a gap nobody sells.",
      "topics": [
        "agents-and-policy",
        "vaults-and-method"
      ],
      "tags": [
        "identity",
        "agents",
        "secrets",
        "passkeys",
        "webauthn",
        "prf",
        "google-workspace",
        "identity-platform",
        "cognito",
        "zero-knowledge",
        "gdpr",
        "riskmandate",
        "sgit",
        "article"
      ],
      "links_out": [
        "the-wall-under-the-reply",
        "six-agents-one-inbox",
        "replicating-the-agentic-inbox",
        "footprint-and-blast-radius",
        "ultimate-insider-three-collisions"
      ],
      "links_in": [],
      "graph": {
        "slug": "the-identity-we-wanted-to-give-the-agents",
        "teaser": "A week of designing identities for agents and users met Google's terms; what survived is a passkey-unlocked keyring and a gap nobody sells.",
        "topics": [
          "agents-and-policy",
          "vaults-and-method"
        ],
        "core_idea": "A plan to give every agent and user a Workspace identity from one tenant was stopped by Google's resale and function-account clauses; the design moved to a login product plus a bucket of ciphertext plus a browser keyring that only the user's passkey can open, on the rule that no secret can live inside an identity provider, and the week exposed that login, zero-knowledge storage and agent identity are still three separate jobs.",
        "nodes": [
          {
            "id": "the-want",
            "label": "A real identity for every agent and user",
            "kind": "concept",
            "summary": "A Workspace seat per person and per agent from our tenant: mailbox, calendar, drive, login, with sgit encrypting before Google and a passkey as the only decryptor."
          },
          {
            "id": "no-admin-proof-zone",
            "label": "Workspace has no admin-proof zone",
            "kind": "claim",
            "summary": "A super administrator can reach any Drive; client-side encryption is Enterprise Plus and Education only; so encryption happens in sgit, before Google."
          },
          {
            "id": "the-terms",
            "label": "The resale and function-account clauses",
            "kind": "claim",
            "summary": "Current Cloud terms forbid selling, reselling, sublicensing or distributing the Services; the acceptable use policy names reselling End User Accounts in a product and accounts assigned to functions rather than humans."
          },
          {
            "id": "the-correction",
            "label": "A correction to our own pack",
            "kind": "example",
            "summary": "The 'substitute or similar service' clause cited as section 2.6 is in the legacy free-edition agreement the standard-terms URL still serves, not in the current terms."
          },
          {
            "id": "five-options",
            "label": "Five options, one table",
            "kind": "method",
            "summary": "Shared Workspace (needs Google's agreement), Identity Platform plus bucket (chosen), customer's own Workspace, private customer cloud, Cognito plus S3 as the AWS variant."
          },
          {
            "id": "no-secret-in-idp",
            "label": "No secret can live in the login",
            "kind": "claim",
            "summary": "Whoever administers identity can reset a password, mint a token or sign in as anyone; the authority to decrypt must come from the user's authenticator."
          },
          {
            "id": "login-vs-passkey",
            "label": "Login decides paths; the passkey decides meaning",
            "kind": "concept",
            "summary": "The identity provider and the bucket rules decide which paths a user may touch; the passkey decides whether the bytes mean anything; an administrator fakes the first, never the second."
          },
          {
            "id": "code-boundary",
            "label": "The code is the boundary",
            "kind": "claim",
            "summary": "Whoever controls the repository or DNS controls the app; so host away from the cloud project, vendor and hash every dependency, scope the passkey to one subdomain, never the apex."
          },
          {
            "id": "keyring",
            "label": "The keyring",
            "kind": "artefact",
            "summary": "One encrypted file per user holding a key pair and every small secret, unlocked by passkey PRF with a recovery code as second method, shared through per-user public keys, using sgit pki's algorithms."
          },
          {
            "id": "password-manager-first",
            "label": "A password manager first",
            "kind": "method",
            "summary": "Every risky piece in one small product; the acceptance test is to hand a project owner a user id and ask for one plaintext field, then publish the attempt."
          },
          {
            "id": "prf-support",
            "label": "Passkey PRF: most places, not everywhere",
            "kind": "example",
            "summary": "WebAuthn Level 3 became a Recommendation in August 2026; Chrome, Edge, Safari 18 and desktop Firefox ship PRF; Bitwarden and Dashlane unlock vaults with it; the MVP ships a compatibility matrix."
          },
          {
            "id": "agents-not-seats",
            "label": "Agents are not seats",
            "kind": "claim",
            "summary": "An agent gets a service identity, a lane for signed mail and a keyring entry a person releases, scoped and time-limited; our own agents keep their mailboxes because they are our organisation's."
          },
          {
            "id": "industry-agent-identity",
            "label": "Agent identity from the vendors",
            "kind": "example",
            "summary": "Entra Agent ID, Okta for AI Agents, Google Cloud Agent Identity on SPIFFE, Anthropic's managed-agent vaults: workload identity that says which agent, not which person's key."
          },
          {
            "id": "three-jobs",
            "label": "Three jobs, still separate",
            "kind": "claim",
            "summary": "Login is solved; zero-knowledge per-user storage exists in pieces; agent identity exists for machines; nothing on the shelf is all three, and the joins are a startup's first month."
          },
          {
            "id": "gdpr",
            "label": "The regulator describes the property",
            "kind": "example",
            "summary": "Articles 32 and 34(3)(a) and the EDPB's 'if the confidentiality of the key is intact' favour keys the operator cannot break; the market does not sell it."
          },
          {
            "id": "missing-something",
            "label": "Unless we are missing something obvious",
            "kind": "question",
            "summary": "The design pack is published to be corrected; the nearest off-the-shelf answers found were two small password-derived open-source backends."
          }
        ],
        "edges": [
          {
            "from": "the-want",
            "to": "no-admin-proof-zone",
            "rel": "leads-to"
          },
          {
            "from": "the-want",
            "to": "the-terms",
            "rel": "leads-to"
          },
          {
            "from": "the-terms",
            "to": "the-correction",
            "rel": "produces"
          },
          {
            "from": "the-terms",
            "to": "five-options",
            "rel": "leads-to"
          },
          {
            "from": "no-secret-in-idp",
            "to": "login-vs-passkey",
            "rel": "produces"
          },
          {
            "from": "five-options",
            "to": "no-secret-in-idp",
            "rel": "depends-on"
          },
          {
            "from": "login-vs-passkey",
            "to": "keyring",
            "rel": "produces"
          },
          {
            "from": "code-boundary",
            "to": "keyring",
            "rel": "contrasts"
          },
          {
            "from": "keyring",
            "to": "password-manager-first",
            "rel": "leads-to"
          },
          {
            "from": "prf-support",
            "to": "keyring",
            "rel": "depends-on"
          },
          {
            "from": "the-terms",
            "to": "agents-not-seats",
            "rel": "leads-to"
          },
          {
            "from": "industry-agent-identity",
            "to": "agents-not-seats",
            "rel": "compared-with"
          },
          {
            "from": "agents-not-seats",
            "to": "keyring",
            "rel": "depends-on"
          },
          {
            "from": "three-jobs",
            "to": "the-want",
            "rel": "answers"
          },
          {
            "from": "gdpr",
            "to": "three-jobs",
            "rel": "extends"
          },
          {
            "from": "three-jobs",
            "to": "missing-something",
            "rel": "leads-to"
          },
          {
            "from": "the-correction",
            "to": "missing-something",
            "rel": "example-of"
          }
        ],
        "links": {
          "articles": [
            "six-agents-one-inbox",
            "replicating-the-agentic-inbox",
            "footprint-and-blast-radius",
            "ultimate-insider-three-collisions"
          ],
          "pages": [
            "/partnerships/vault-key-management.html",
            "/docs/briefs/secrets-sgit-ai-design-pack.html",
            "/docs/credentials.html",
            "/docs/pki.html",
            "/docs/agent-contact.html",
            "/docs/briefs/riskmandate-partnership-risk-and-sgit-mapping.html"
          ],
          "sites": [
            "https://workspace.google.com/terms/premier_terms/",
            "https://workspace.google.com/terms/use_policy/",
            "https://www.w3.org/TR/webauthn-3/",
            "https://cloud.google.com/identity-platform/pricing",
            "https://userbase.com/"
          ]
        },
        "quotes": [
          {
            "text": "Login decides which paths you may touch. The passkey decides whether the bytes mean anything. An administrator can fake the first and never the second.",
            "why": "The rule the whole design rests on, and why no secret can live inside an identity provider."
          },
          {
            "text": "The law describes the property; the market does not sell it.",
            "why": "The gap the article ends on: login, zero-knowledge storage and agent identity are still three separate jobs."
          }
        ]
      }
    },
    {
      "slug": "the-investigation-github-owes-its-customers",
      "title": "The investigation GitHub owes its customers: why a global outage of a platform the world deploys through deserves an aviation-style inquiry, and how the evidence could now be gathered",
      "date": "2026-10-05",
      "updated": "",
      "url": "https://sgit.ai/articles/the-investigation-github-owes-its-customers.html",
      "markdown": "https://sgit.ai/articles/the-investigation-github-owes-its-customers.md",
      "card": "https://sgit.ai/articles/cards/the-investigation-github-owes-its-customers.webp",
      "teaser": "A global GitHub Actions outage read the way aviation reads an incident: independent inquiry, near-miss reporting, second and third stories, vaults for the evidence.",
      "topics": [
        "agents-and-policy",
        "vaults-and-method"
      ],
      "tags": [
        "incidents",
        "resilience",
        "github",
        "near-misses",
        "second-stories",
        "blast-radius",
        "investigation",
        "aviation",
        "regulation",
        "vaults",
        "sgit",
        "article"
      ],
      "links_out": [
        "send-an-agent-not-a-spreadsheet",
        "footprint-and-blast-radius",
        "green-does-not-mean-live",
        "ultimate-insider-three-collisions",
        "every-risk-is-already-accepted"
      ],
      "links_in": [],
      "graph": {
        "slug": "the-investigation-github-owes-its-customers",
        "teaser": "A global GitHub Actions outage read the way aviation reads an incident: independent inquiry, near-miss reporting, second and third stories, vaults for the evidence.",
        "topics": [
          "agents-and-policy",
          "vaults-and-method"
        ],
        "core_idea": "A fault that reaches every customer of a platform the world deploys through is a near miss for all of them and a statement about how the platform is built, and it deserves what aviation gives its incidents: an independent investigator whose only job is prevention, mandatory and confidential reporting, published evidence, and the second and third story, why the system allowed it and why the fix was not paid for; the old objection that software incident evidence is too confidential and expensive to share has expired, because signed, versioned vaults with one-way read keys and agents that read the graph make the aviation docket affordable for a ninety-minute fault.",
        "nodes": [
          {
            "id": "the-incident",
            "label": "What happened on 5 October",
            "kind": "example",
            "summary": "From 19:11 UTC hosted runners stopped being reliably assigned for every customer; by 20:47 degraded availability; this site's release was cancelled by it and went live two hours late on a retry."
          },
          {
            "id": "two-records",
            "label": "The status page is the whole record",
            "kind": "claim",
            "summary": "Delays, degraded, resolved: true words chosen with care that do not name the component, its reach, the scope or whether the same thing nearly happened before."
          },
          {
            "id": "everybody",
            "label": "Everybody is the point",
            "kind": "claim",
            "summary": "A fault reaching one customer is an incident; a fault reaching all of them at once is a statement about isolation on the one component that gates every deploy, and a near miss for everyone who needed to ship a fix."
          },
          {
            "id": "aviation",
            "label": "What aviation does",
            "kind": "method",
            "summary": "Independent investigators whose sole objective is prevention, mandatory reporting of serious incidents, confidential near-miss reporting in the tens of thousands a year, preliminary reports within weeks, full dockets, tracked recommendations."
          },
          {
            "id": "near-miss",
            "label": "A near miss gets the same investigation",
            "kind": "claim",
            "summary": "Because the systemic causes are the same and the only difference is luck; actual damage is usually a tenth of what was possible; you don't build safety on luck."
          },
          {
            "id": "dice",
            "label": "Count the rolls of the dice",
            "kind": "method",
            "summary": "How many times the same event happened where they got away with it; from a one-off to a predictable statistic; do the people who depend on you consent to that risk."
          },
          {
            "id": "three-stories",
            "label": "First, second and third story",
            "kind": "concept",
            "summary": "What happened; why the system allowed it; why the fix was not paid for. Software write-ups stop at the first; the third is where the money is."
          },
          {
            "id": "whatif",
            "label": "The what-if ladder",
            "kind": "question",
            "summary": "A day, a week, a corruption that cannot be restored, a withdrawal of service by decision: each a dependency question with a blast radius that has not been published, for the platform or for countries."
          },
          {
            "id": "market",
            "label": "Why the market does not fix it",
            "kind": "claim",
            "summary": "Customers cannot see how close to the wind the platform flies; only incidents that reach the status page are known; with the barrier to exit this high, uptime becomes marketing and the business case for hardening cannot be made from inside."
          },
          {
            "id": "objection-expired",
            "label": "The objection has expired",
            "kind": "claim",
            "summary": "Evidence was confidential, enormous and expensive to share; signed, versioned vaults, one-way read keys per party, agents under a behaviour policy and findings as a graph make the aviation docket affordable for a ninety-minute fault."
          },
          {
            "id": "evidence-pipeline",
            "label": "How the evidence would move",
            "kind": "method",
            "summary": "Provider captures and signs; reviews and redacts, never rewrites; investigator reads by need; each customer gets its own derived vault; findings published as a graph linked to evidence hashes with recommendations held open."
          },
          {
            "id": "regulation",
            "label": "What the regulation does and does not do",
            "kind": "example",
            "summary": "Incident reporting duties and critical third-party regimes are arriving; none yet requires an independent published second story for a platform outage."
          },
          {
            "id": "four-asks",
            "label": "Four things to ask for",
            "kind": "method",
            "summary": "A published second story within thirty days for every status-page incident; near misses counted and reported in aggregate; evidence captured into a signed record as a matter of course; an independent reader when an incident reaches everyone."
          },
          {
            "id": "help-inside",
            "label": "Help the people inside",
            "kind": "claim",
            "summary": "Engineers who know where the single points of failure are cannot make the business case against revenue without evidence; a readable record makes it for them."
          }
        ],
        "edges": [
          {
            "from": "the-incident",
            "to": "two-records",
            "rel": "produces"
          },
          {
            "from": "the-incident",
            "to": "everybody",
            "rel": "leads-to"
          },
          {
            "from": "two-records",
            "to": "aviation",
            "rel": "contrasts"
          },
          {
            "from": "everybody",
            "to": "near-miss",
            "rel": "example-of"
          },
          {
            "from": "near-miss",
            "to": "dice",
            "rel": "extends"
          },
          {
            "from": "aviation",
            "to": "three-stories",
            "rel": "depends-on"
          },
          {
            "from": "everybody",
            "to": "whatif",
            "rel": "leads-to"
          },
          {
            "from": "whatif",
            "to": "market",
            "rel": "leads-to"
          },
          {
            "from": "market",
            "to": "objection-expired",
            "rel": "contrasts"
          },
          {
            "from": "objection-expired",
            "to": "evidence-pipeline",
            "rel": "produces"
          },
          {
            "from": "regulation",
            "to": "four-asks",
            "rel": "compared-with"
          },
          {
            "from": "evidence-pipeline",
            "to": "four-asks",
            "rel": "leads-to"
          },
          {
            "from": "three-stories",
            "to": "help-inside",
            "rel": "leads-to"
          },
          {
            "from": "market",
            "to": "help-inside",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "green-does-not-mean-live",
            "footprint-and-blast-radius",
            "ultimate-insider-three-collisions",
            "every-risk-is-already-accepted",
            "send-an-agent-not-a-spreadsheet"
          ],
          "pages": [
            "/docs/pki.html",
            "/docs/append-lane-messaging.html"
          ],
          "sites": [
            "https://www.githubstatus.com/",
            "https://diniscruz.ai/2025/02/10/second-stories__from-three-mile-island-to-cybersecurity.md"
          ]
        },
        "quotes": [
          {
            "text": "A fault that reaches one customer is an incident. A fault that reaches every customer at once is a statement about how the system is built.",
            "why": "Why the scope of tonight's fault, not its duration, is what deserves the inquiry."
          },
          {
            "text": "A system too complicated to understand and too fragile to change is not a reason to leave it alone. It is the single point of failure, named.",
            "why": "The third story, and why it needs an investigator who does not report to the budget it is about."
          }
        ]
      }
    },
    {
      "slug": "the-wall-under-the-reply",
      "title": "The wall under the reply: end an email with the state of the thread, not the thread",
      "date": "2026-10-04",
      "updated": "2026-10-05",
      "url": "https://sgit.ai/articles/the-wall-under-the-reply.html",
      "markdown": "https://sgit.ai/articles/the-wall-under-the-reply.md",
      "card": "https://sgit.ai/articles/cards/the-wall-under-the-reply.webp",
      "teaser": "End an email reply with the state of the thread for this reader, not the quoted wall: decided, open, next, who is on copy, with links to the record.",
      "topics": [
        "agents-and-policy",
        "vaults-and-method"
      ],
      "tags": [
        "email",
        "agents",
        "email-fs",
        "context",
        "reply",
        "summary",
        "netiquette",
        "bluf",
        "drafts",
        "experiment",
        "riskmandate",
        "article"
      ],
      "links_out": [
        "custom-uis-are-not-the-exception",
        "replicating-the-agentic-inbox",
        "memory-is-not-a-spectator-sport",
        "six-agents-one-inbox"
      ],
      "links_in": [
        "how-much-of-this-did-i-write",
        "the-identity-we-wanted-to-give-the-agents"
      ],
      "graph": {
        "slug": "the-wall-under-the-reply",
        "teaser": "End an email reply with the state of the thread for this reader, not the quoted wall: decided, open, next, who is on copy, with links to the record.",
        "topics": [
          "agents-and-policy",
          "vaults-and-method"
        ],
        "core_idea": "The quoted wall under a reply is redundant and occupies the space where a reader asks what they need to know; replace it with a short, reader-specific state of the thread, derived from the record and linking back to it, drafted by the agent team's drafts role from typed blocks and reviewed by a person, and run as an experiment rather than a format.",
        "nodes": [
          {
            "id": "the-wall",
            "label": "The quoted wall is redundant",
            "kind": "claim",
            "summary": "Every reply ships the whole thread to a reader who already has it, and the clients hide it on arrival behind a trimmed-content link."
          },
          {
            "id": "readers-questions",
            "label": "The reader's questions",
            "kind": "concept",
            "summary": "Where are we, what was decided, what is open and whose, what happens next and do I act, who is on this thread now; the wall holds the material and answers none of them."
          },
          {
            "id": "the-tail",
            "label": "End with the state of the thread",
            "kind": "method",
            "summary": "Decided, open, next, on copy, sources: a hundred words written for this reader, with links to the messages condensed, which stay in the thread as the record."
          },
          {
            "id": "for-the-reader",
            "label": "Written for one reader",
            "kind": "claim",
            "summary": "The same thread condenses differently for the counterparty, the newcomer and the colleague who read everything; the question is what this person needs now."
          },
          {
            "id": "cc-is-state",
            "label": "Who is on copy is part of the state",
            "kind": "claim",
            "summary": "Who joined, who left, which participants are agents: facts every newcomer needs that no quoted wall carries."
          },
          {
            "id": "derived-view",
            "label": "Derived, not the record",
            "kind": "concept",
            "summary": "The tail points back at the thread instead of repeating it; if the tail is wrong the record underneath is not, and the reader can check in one tap."
          },
          {
            "id": "precedents",
            "label": "Netiquette, BLUF, Minto, TL;DR, ADRs",
            "kind": "example",
            "summary": "RFC 1855 asked for a summary instead of the full quote in 1995; the Army's bottom line up front; the Pyramid Principle; decision records with a Status line."
          },
          {
            "id": "client-summaries",
            "label": "Reader-side AI summaries",
            "kind": "example",
            "summary": "Superhuman, Shortwave, Copilot in Outlook, Apple Mail and Gmail now compute a summary at the top of a thread for the reader, privately and regenerated each time."
          },
          {
            "id": "sender-vs-reader",
            "label": "Sender's statement versus reader's view",
            "kind": "concept",
            "summary": "The client summary belongs to one reader and nobody stands behind it; the tail is reviewed, shared with everyone on copy, in the record, and can be argued with."
          },
          {
            "id": "drafts-role",
            "label": "The drafts role writes it",
            "kind": "method",
            "summary": "From the typed blocks the inbox role already captures, for a chosen reader, with message ids cited and a hash logged; the person edits and sends; the inbox role records what went out."
          },
          {
            "id": "configurable",
            "label": "Personal, so configurable",
            "kind": "method",
            "summary": "Five rows, one line, or the wall back: the reader's preference is a row in their folder in the CRM; text first, richer forms are variants."
          },
          {
            "id": "experiment",
            "label": "An experiment, not a format",
            "kind": "method",
            "summary": "Four variants rotated by thread for a month on one person's correspondence, with measurements the record can take and the results published either way."
          },
          {
            "id": "falsifiers",
            "label": "What would make this wrong",
            "kind": "question",
            "summary": "Readers scrolling to the quotes anyway, condensations corrected in more than a few replies in ten, clients mangling the rows."
          },
          {
            "id": "missing",
            "label": "What does not exist yet",
            "kind": "question",
            "summary": "The drafts role writing tails automatically, the preference row, the templates, the measurement report, the month of data and the follow-up."
          }
        ],
        "edges": [
          {
            "from": "the-wall",
            "to": "readers-questions",
            "rel": "leads-to"
          },
          {
            "from": "readers-questions",
            "to": "the-tail",
            "rel": "leads-to"
          },
          {
            "from": "for-the-reader",
            "to": "the-tail",
            "rel": "extends"
          },
          {
            "from": "cc-is-state",
            "to": "the-tail",
            "rel": "extends"
          },
          {
            "from": "derived-view",
            "to": "the-tail",
            "rel": "depends-on"
          },
          {
            "from": "precedents",
            "to": "the-tail",
            "rel": "compared-with"
          },
          {
            "from": "client-summaries",
            "to": "sender-vs-reader",
            "rel": "leads-to"
          },
          {
            "from": "sender-vs-reader",
            "to": "the-tail",
            "rel": "extends"
          },
          {
            "from": "client-summaries",
            "to": "the-tail",
            "rel": "contrasts"
          },
          {
            "from": "drafts-role",
            "to": "the-tail",
            "rel": "produces"
          },
          {
            "from": "drafts-role",
            "to": "derived-view",
            "rel": "depends-on"
          },
          {
            "from": "configurable",
            "to": "drafts-role",
            "rel": "extends"
          },
          {
            "from": "configurable",
            "to": "for-the-reader",
            "rel": "depends-on"
          },
          {
            "from": "experiment",
            "to": "the-tail",
            "rel": "answers"
          },
          {
            "from": "experiment",
            "to": "falsifiers",
            "rel": "produces"
          },
          {
            "from": "falsifiers",
            "to": "missing",
            "rel": "leads-to"
          },
          {
            "from": "drafts-role",
            "to": "missing",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "custom-uis-are-not-the-exception",
            "replicating-the-agentic-inbox",
            "memory-is-not-a-spectator-sport",
            "six-agents-one-inbox"
          ],
          "pages": [
            "/docs/agent-contact.html"
          ],
          "sites": [
            "https://www.rfc-editor.org/rfc/rfc1855.txt",
            "https://workspaceupdates.googleblog.com/2025/05/gemini-summary-cards-gmail-app.html",
            "https://support.microsoft.com/en-us/outlook/copilot-pages/summarize-an-email-thread-with-copilot-in-outlook",
            "https://www.microsoft.com/en-us/worklab/work-trend-index/breaking-down-infinite-workday"
          ]
        },
        "quotes": [
          {
            "text": "The wall is shipped with every message and hidden on arrival, which is the clearest possible sign that it is the wrong thing to ship.",
            "why": "The observation the proposal starts from."
          },
          {
            "text": "The client's summary says what the thread looks like from here; the tail says what the sender believes it is.",
            "why": "How the proposal differs from the AI summaries mail clients already compute."
          }
        ]
      }
    },
    {
      "slug": "code-review-as-a-fractal-semantic-graph",
      "title": "Code review as a fractal semantic graph: source code is already one, and the review should read every layer of it",
      "date": "2026-10-03",
      "updated": "",
      "url": "https://sgit.ai/articles/code-review-as-a-fractal-semantic-graph.html",
      "markdown": "https://sgit.ai/articles/code-review-as-a-fractal-semantic-graph.md",
      "card": "https://sgit.ai/articles/cards/code-review-as-a-fractal-semantic-graph.webp",
      "teaser": "Source code is layers within layers, each a graph with its own vocabulary; code review should read a change at every one, and a vault shows it done on real code.",
      "topics": [
        "graphs-and-knowledge",
        "startups-and-strategy"
      ],
      "tags": [
        "code-review",
        "fractal-semantic-graphs",
        "graphs",
        "static-analysis",
        "ast",
        "method-streams",
        "o2-platform",
        "ai-generated-code",
        "vaults",
        "c4",
        "gherkin",
        "threat-modelling",
        "nfrs",
        "article"
      ],
      "links_out": [
        "introducing-fractal-semantic-graphs",
        "footprint-and-blast-radius",
        "custom-uis-are-not-the-exception",
        "every-risk-is-already-accepted",
        "if-somebody-built-a-company-on-code-review"
      ],
      "links_in": [
        "how-much-of-this-did-i-write",
        "if-somebody-built-a-company-on-code-review",
        "send-an-agent-not-a-spreadsheet",
        "memory-is-not-a-spectator-sport"
      ],
      "graph": {
        "slug": "code-review-as-a-fractal-semantic-graph",
        "teaser": "Source code is layers within layers, each a graph with its own vocabulary; code review should read a change at every one, and a vault shows it done on real code.",
        "topics": [
          "graphs-and-knowledge",
          "startups-and-strategy"
        ],
        "core_idea": "Source code is already a fractal semantic graph, stories to syntax tree and below, so a code review should diff every layer: a refactor moves the bottom and leaves the top still, a fix is a story that holds again, and the blast radius is the climb from changed methods to the stories that can reach them.",
        "nodes": [
          {
            "id": "code-is-fractal",
            "label": "Source code is a fractal semantic graph",
            "kind": "claim",
            "summary": "Stories, flows, components, classes, methods and calls, the syntax tree, and down to the machine: each layer a graph with its own node types and verbs, and you change universe between them."
          },
          {
            "id": "fixed-levels",
            "label": "C4 and Gherkin: right instinct, fixed levels",
            "kind": "concept",
            "summary": "C4 named four levels and left the code level optional; Gherkin shaped the top layer and glued it to code with regular expressions. Both saw the shape before anything could fill it cheaply."
          },
          {
            "id": "naming-is-cheap",
            "label": "Naming is now the cheap part",
            "kind": "claim",
            "summary": "A model can say what a function does, which story a command serves and the verb between two nodes, from the syntax tree, once per change, as structured files."
          },
          {
            "id": "ast-first",
            "label": "Start from the syntax tree",
            "kind": "method",
            "summary": "The tree survives reformatting and renaming; derive deterministically what a parser can, and spend the model on what it cannot know."
          },
          {
            "id": "pile-of-files",
            "label": "Every source file produces a pile of files",
            "kind": "method",
            "summary": "Classes, methods and calls, package edges, fingerprints, tests, pattern results, kept as JSON next to the code in git, a vault or both; regenerated only on change."
          },
          {
            "id": "diff-every-layer",
            "label": "Diff every layer",
            "kind": "method",
            "summary": "A refactor moves the bottom layers and leaves the top still; a fix moves the bottom and is visible at the top as a story holding again, with a test; a leak is a forbidden edge."
          },
          {
            "id": "blast-radius",
            "label": "Blast radius as the climb",
            "kind": "concept",
            "summary": "From the methods a change touched, up the call graph with dynamic dispatch, to the commands and stories that can reach them, before anything runs."
          },
          {
            "id": "method-streams",
            "label": "Method streams",
            "kind": "method",
            "summary": "Follow the call tree from one method and write out only that code; a 2012 O2 Platform review technique, now one script over a syntax tree with resolved calls."
          },
          {
            "id": "worked-example",
            "label": "The sgit CLI, read as layers",
            "kind": "example",
            "summary": "427 files, 377 classes, 1,111 methods, 2,592 calls, 72 commands, eleven stories, two streams, ten rules, one commit read upwards; nothing run; published as a vault."
          },
          {
            "id": "fix-shape",
            "label": "One commit, read upwards",
            "kind": "example",
            "summary": "Seven methods changed, no signature or field moved, six tests added; the climb reaches nine commands and six stories. The shape of a fix, and the commit message agrees."
          },
          {
            "id": "reality-loop",
            "label": "Reality corrects the graph",
            "kind": "claim",
            "summary": "You do not have to get the graph right; users confirm the top, experts confirm their layer, tests confirm execution, and every correction is a commit."
          },
          {
            "id": "patterns-are-findings",
            "label": "Patterns are findings",
            "kind": "claim",
            "summary": "Folder shape, type shape, test shape and size shape are queries over the graph; the rules a project states most firmly are the ones that hold."
          },
          {
            "id": "ai-code-burden",
            "label": "The review burden of generated code",
            "kind": "example",
            "summary": "More cloned code and less refactoring, lower delivery stability with adoption, developers reporting almost-right answers and longer debugging: the answer is a different diff, not a faster reviewer."
          },
          {
            "id": "what-is-missing",
            "label": "What does not exist yet",
            "kind": "question",
            "summary": "Proposed stories and edges from a model, node-level tree diffs, a second language, the interface layer, execution paths compared to predicted streams, and the review surface itself."
          },
          {
            "id": "company",
            "label": "A company to build",
            "kind": "concept",
            "summary": "A review that reads every layer, keeps the graph as files the customer owns, runs their rules as queries and improves with every correction; defensible through the record, not the model."
          }
        ],
        "edges": [
          {
            "from": "code-is-fractal",
            "to": "fixed-levels",
            "rel": "compared-with"
          },
          {
            "from": "naming-is-cheap",
            "to": "code-is-fractal",
            "rel": "extends"
          },
          {
            "from": "ast-first",
            "to": "pile-of-files",
            "rel": "leads-to"
          },
          {
            "from": "naming-is-cheap",
            "to": "pile-of-files",
            "rel": "produces"
          },
          {
            "from": "pile-of-files",
            "to": "diff-every-layer",
            "rel": "leads-to"
          },
          {
            "from": "diff-every-layer",
            "to": "blast-radius",
            "rel": "produces"
          },
          {
            "from": "method-streams",
            "to": "diff-every-layer",
            "rel": "extends"
          },
          {
            "from": "ast-first",
            "to": "method-streams",
            "rel": "depends-on"
          },
          {
            "from": "worked-example",
            "to": "code-is-fractal",
            "rel": "example-of"
          },
          {
            "from": "fix-shape",
            "to": "diff-every-layer",
            "rel": "example-of"
          },
          {
            "from": "fix-shape",
            "to": "blast-radius",
            "rel": "example-of"
          },
          {
            "from": "worked-example",
            "to": "fix-shape",
            "rel": "produces"
          },
          {
            "from": "worked-example",
            "to": "method-streams",
            "rel": "example-of"
          },
          {
            "from": "reality-loop",
            "to": "diff-every-layer",
            "rel": "depends-on"
          },
          {
            "from": "patterns-are-findings",
            "to": "reality-loop",
            "rel": "extends"
          },
          {
            "from": "worked-example",
            "to": "patterns-are-findings",
            "rel": "example-of"
          },
          {
            "from": "ai-code-burden",
            "to": "diff-every-layer",
            "rel": "leads-to"
          },
          {
            "from": "worked-example",
            "to": "what-is-missing",
            "rel": "leads-to"
          },
          {
            "from": "what-is-missing",
            "to": "company",
            "rel": "leads-to"
          },
          {
            "from": "reality-loop",
            "to": "company",
            "rel": "depends-on"
          }
        ],
        "links": {
          "articles": [
            "introducing-fractal-semantic-graphs",
            "footprint-and-blast-radius",
            "custom-uis-are-not-the-exception",
            "every-risk-is-already-accepted"
          ],
          "pages": [
            "/demos/vaults/code-review-graphs/index.html",
            "/demos/fractal-graphs/index.html",
            "/demos/vaults/threatmodcon-2025/index.html",
            "/startups/business-plans.html"
          ],
          "sites": [
            "https://coding.sgit.ai/",
            "https://nfrs.sgit.ai/",
            "https://c4model.com/",
            "https://diniscruz.ai/2025/05/29/semantic-knowledge-graphs-for-llm-driven-source-code-analysis.html",
            "https://diniscruz.blogspot.com/2012/06/o2-net-sast-engine-methodstream-and.html"
          ]
        },
        "quotes": [
          {
            "text": "You do not have to get the graph right. You have to get it to where user behaviour, the people who know each layer, and the tests can confirm or correct it.",
            "why": "The condition that makes a model-derived graph of a codebase usable at all."
          },
          {
            "text": "The answer is not a faster reviewer reading the same diff. It is a different diff.",
            "why": "The article's claim about the review burden of generated code."
          }
        ]
      }
    },
    {
      "slug": "memory-is-not-a-spectator-sport",
      "title": "Memory is not a spectator sport: how a web of open sites, graphs and vaults became the memory for sessions like this one",
      "date": "2026-10-03",
      "updated": "",
      "url": "https://sgit.ai/articles/memory-is-not-a-spectator-sport.html",
      "markdown": "https://sgit.ai/articles/memory-is-not-a-spectator-sport.md",
      "card": "https://sgit.ai/articles/cards/memory-is-not-a-spectator-sport.webp",
      "teaser": "Agentic memory as context management: many published, fractal, provenance-carrying memories rather than one store, shown in the session that wrote the article.",
      "topics": [
        "graphs-and-knowledge",
        "agents-and-policy"
      ],
      "tags": [
        "memory",
        "agents",
        "context-engineering",
        "fractal-semantic-graphs",
        "vaults",
        "provenance",
        "open-publishing",
        "email-fs",
        "issues-fs",
        "llms-txt",
        "claude",
        "article"
      ],
      "links_out": [
        "token-bill-nobody-is-sending",
        "introducing-fractal-semantic-graphs",
        "replicating-the-agentic-inbox",
        "custom-uis-are-not-the-exception",
        "six-agents-one-inbox",
        "code-review-as-a-fractal-semantic-graph",
        "price-it-then-give-it-away"
      ],
      "links_in": [
        "how-much-of-this-did-i-write",
        "the-wall-under-the-reply"
      ],
      "graph": {
        "slug": "memory-is-not-a-spectator-sport",
        "teaser": "Agentic memory as context management: many published, fractal, provenance-carrying memories rather than one store, shown in the session that wrote the article.",
        "topics": [
          "graphs-and-knowledge",
          "agents-and-policy"
        ],
        "core_idea": "Memory for agents is context management: many context-specific memories, fractal so an agent loads only the altitude its question needs, published and open so they can be fetched and cited, shared through vaults so sessions and agents hand off through files, with provenance on every item.",
        "nodes": [
          {
            "id": "not-spectator",
            "label": "Memory is not a spectator sport",
            "kind": "claim",
            "summary": "Not one store that accumulates and retrieves by similarity; memory is made, placed, sourced and linked by people and agents."
          },
          {
            "id": "context-management",
            "label": "Memory is context management",
            "kind": "concept",
            "summary": "The question is what this agent needs in its window now, not what we remember; the same question the industry calls context engineering."
          },
          {
            "id": "industry",
            "label": "What the industry built",
            "kind": "example",
            "summary": "Vendor memory features as a single store of conversations; frameworks from MemGPT to Mem0 and Zep; a filesystem beating a graph store on a memory benchmark; builders treating files as the ultimate context."
          },
          {
            "id": "two-modes",
            "label": "Two modes, one memory",
            "kind": "concept",
            "summary": "The agentic session walks the altitudes and is summarised across resets; the one-shot call is handed one bundle; both are served by memory shaped in altitudes."
          },
          {
            "id": "many-memories",
            "label": "Many memories, each its own context",
            "kind": "claim",
            "summary": "Sites, release log, briefs, vaults, Email-FS, the CRM's per-contact worlds: different vocabularies, inconsistent in places on purpose, joined by links and an index rather than a schema."
          },
          {
            "id": "fractal-budget",
            "label": "The fractal is the budget",
            "kind": "method",
            "summary": "Index, graphs, one article's graph, the article, a vault's bundle, the vault: an agent loads the altitude its question lives at, because context has a token cost and degrades as it fills."
          },
          {
            "id": "open-publishing",
            "label": "Findable because it is open",
            "kind": "claim",
            "summary": "Open source and Creative Commons let an agent fetch, quote, link and cite; the more is published, the better the next context."
          },
          {
            "id": "provenance",
            "label": "Provenance built in",
            "kind": "method",
            "summary": "A URL for every quote, a commit for every release, a read key for every vault, a hash for every source file, a byline on every page; claims from memory are not allowed."
          },
          {
            "id": "vault-as-bundle",
            "label": "A vault is a memory bundle",
            "kind": "artefact",
            "summary": "The right information for a moment, encrypted, versioned, hashed, opened with a read key that cannot write; the medium through which agents share memory without a shared session."
          },
          {
            "id": "conventions",
            "label": "Email-FS, Issues-FS, per-contact worlds",
            "kind": "artefact",
            "summary": "Agents talk in files with mailroom, inbox, done and outbox; issues are folders; each contact has its own graph and interface; each agent writes only its own folders."
          },
          {
            "id": "the-session",
            "label": "The session that wrote this",
            "kind": "example",
            "summary": "One Claude Code session across context resets: read the summary of itself, the conventions, the published sites and a review vault; loaded by altitude; checked; wrote back articles with graphs, a vault and six releases."
          },
          {
            "id": "the-loop",
            "label": "Publish, index, load, act, write back",
            "kind": "method",
            "summary": "The loop that makes published material a memory rather than an archive; the next session starts from the files, because the model remembers nothing between sessions."
          },
          {
            "id": "stale-false",
            "label": "Stale pages become false memories",
            "kind": "question",
            "summary": "Four stale facts found while writing: a node count, an index size, generated dates, a feed that stopped; two fixed by measuring at build time, two left standing and named."
          },
          {
            "id": "limits",
            "label": "Opinionated, hard to discover, and one estate",
            "kind": "question",
            "summary": "One person's vocabulary at the top of every ladder; discovery strains the index; the thesis is tested only when a second estate is read alongside."
          },
          {
            "id": "missing",
            "label": "What does not exist yet",
            "kind": "question",
            "summary": "A freshness check in the build, a published shape for the hand-off summary, the one-shot bundle as a vault, a librarian role on this site, a second estate."
          }
        ],
        "edges": [
          {
            "from": "not-spectator",
            "to": "context-management",
            "rel": "leads-to"
          },
          {
            "from": "industry",
            "to": "context-management",
            "rel": "compared-with"
          },
          {
            "from": "industry",
            "to": "not-spectator",
            "rel": "contrasts"
          },
          {
            "from": "context-management",
            "to": "two-modes",
            "rel": "produces"
          },
          {
            "from": "two-modes",
            "to": "fractal-budget",
            "rel": "depends-on"
          },
          {
            "from": "many-memories",
            "to": "not-spectator",
            "rel": "extends"
          },
          {
            "from": "many-memories",
            "to": "conventions",
            "rel": "example-of"
          },
          {
            "from": "fractal-budget",
            "to": "many-memories",
            "rel": "extends"
          },
          {
            "from": "open-publishing",
            "to": "many-memories",
            "rel": "depends-on"
          },
          {
            "from": "provenance",
            "to": "open-publishing",
            "rel": "extends"
          },
          {
            "from": "vault-as-bundle",
            "to": "provenance",
            "rel": "depends-on"
          },
          {
            "from": "vault-as-bundle",
            "to": "conventions",
            "rel": "produces"
          },
          {
            "from": "the-session",
            "to": "context-management",
            "rel": "example-of"
          },
          {
            "from": "the-session",
            "to": "fractal-budget",
            "rel": "example-of"
          },
          {
            "from": "the-session",
            "to": "the-loop",
            "rel": "example-of"
          },
          {
            "from": "the-loop",
            "to": "conventions",
            "rel": "depends-on"
          },
          {
            "from": "stale-false",
            "to": "provenance",
            "rel": "answers"
          },
          {
            "from": "the-session",
            "to": "stale-false",
            "rel": "produces"
          },
          {
            "from": "limits",
            "to": "many-memories",
            "rel": "contrasts"
          },
          {
            "from": "limits",
            "to": "missing",
            "rel": "leads-to"
          },
          {
            "from": "stale-false",
            "to": "missing",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "introducing-fractal-semantic-graphs",
            "token-bill-nobody-is-sending",
            "replicating-the-agentic-inbox",
            "custom-uis-are-not-the-exception",
            "six-agents-one-inbox",
            "code-review-as-a-fractal-semantic-graph",
            "price-it-then-give-it-away"
          ],
          "pages": [
            "/team/index.html",
            "/use-cases/ai-agents.html",
            "/docs/briefs/riskmandate-sandbox-twins-and-tokens.html"
          ],
          "sites": [
            "https://nfrs.sgit.ai/memory/index.html",
            "https://nfrs.sgit.ai/documentation/index.html",
            "https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents",
            "https://www.letta.com/blog/benchmarking-ai-agent-memory/",
            "https://manus.im/blog/Context-Engineering-for-AI-Agents-Lessons-from-Building-Manus"
          ]
        },
        "quotes": [
          {
            "text": "Nothing is remembered by the model between sessions. Everything is remembered by the files.",
            "why": "The design in one line: memory lives in published, shared files, not in the model or a vendor's store."
          },
          {
            "text": "Provenance is what lets memory be shared without being trusted, and it is the part that a vector store cannot give you, because a similarity score is not a source.",
            "why": "Why every item in the memory carries its source."
          }
        ]
      }
    },
    {
      "slug": "footprint-and-blast-radius",
      "title": "Footprint and blast radius: what the agent actually did, and what it would have cost",
      "date": "2026-10-02",
      "updated": "2026-10-02",
      "url": "https://sgit.ai/articles/footprint-and-blast-radius.html",
      "markdown": "https://sgit.ai/articles/footprint-and-blast-radius.md",
      "card": "https://sgit.ai/articles/cards/footprint-and-blast-radius.webp",
      "teaser": "Footprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.",
      "topics": [
        "agents-and-policy",
        "vaults-and-method"
      ],
      "tags": [
        "agents",
        "agent-behaviour-policy",
        "riskmandate",
        "footprint",
        "blast-radius",
        "risk-management",
        "logs",
        "connector-twin",
        "vaults",
        "article"
      ],
      "links_out": [
        "ultimate-insider-three-collisions",
        "connector-twin-before-you-deploy-an-agent",
        "custom-uis-are-not-the-exception",
        "every-risk-is-already-accepted",
        "six-agents-one-inbox"
      ],
      "links_in": [
        "if-somebody-built-a-company-on-code-review",
        "send-an-agent-not-a-spreadsheet",
        "the-identity-we-wanted-to-give-the-agents",
        "the-investigation-github-owes-its-customers",
        "code-review-as-a-fractal-semantic-graph",
        "replicating-the-agentic-inbox",
        "ultimate-insider-three-collisions"
      ],
      "graph": {
        "slug": "footprint-and-blast-radius",
        "teaser": "Footprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.",
        "topics": [
          "agents-and-policy",
          "vaults-and-method"
        ],
        "core_idea": "Add two words to the Agent Behaviour Policy: footprint, what the agent actually did, read afterwards from the record and compared with the mandate, and blast radius, what a row of its reach would cost the business if used in full today, with whether there is a way back.",
        "nodes": [
          {
            "id": "four-words",
            "label": "Reach, mandate, gap and barriers",
            "kind": "concept",
            "summary": "RiskMandate's policy is written before the agent runs: reach is what it can do, mandate what you asked, gap the difference in both directions, barriers what stands in the way."
          },
          {
            "id": "barriers-typed",
            "label": "Only a boundary is a control",
            "kind": "concept",
            "summary": "A barrier is a boundary, a setting, an expectation or nothing, and most of what organisations call controls turn out to be expectations once they are typed."
          },
          {
            "id": "footprint",
            "label": "Footprint",
            "kind": "concept",
            "summary": "The set of things the agent actually did, in a period, read from the record afterwards; the same kind of list as the reach and the mandate, but evidence rather than a decision."
          },
          {
            "id": "footprint-sources",
            "label": "Where the footprint comes from",
            "kind": "artefact",
            "summary": "The connector's audit log, the model provider's tool-call record, a connector twin's replay, a vault's commit history, the append lanes and the agents' own messages."
          },
          {
            "id": "passive-reading",
            "label": "Reading, not intercepting",
            "kind": "claim",
            "summary": "Nothing sits inline, a copy of the logs or a read key is enough so an outside reviewer can do it, and the footprint accumulates so some findings only exist at the twelfth week."
          },
          {
            "id": "footprint-in-the-gap",
            "label": "Footprint in the gap",
            "kind": "concept",
            "summary": "The agent did something within its reach and outside its mandate and nothing stopped it, which is a near miss, and it resolves by adding the row to the mandate or putting a boundary in front of it."
          },
          {
            "id": "dormant-mandate",
            "label": "Dormant mandate",
            "kind": "concept",
            "summary": "A row the owner asked for that the footprint never shows: an over-stated mandate, a check that was relied on and never ran, or a shortfall the reach inventory missed."
          },
          {
            "id": "expected-use-hint",
            "label": "Expected-use hint",
            "kind": "method",
            "summary": "Each mandate row wants a hint of how often the owner expects to see it, always, sometimes, rarely, hopefully never, so a dormant row can be told from a contingency that was never needed."
          },
          {
            "id": "mandate-as-practised",
            "label": "The mandate as practised",
            "kind": "method",
            "summary": "Read the footprint for a month and you have the rows the agent actually uses, with the near misses marked, as the first draft of a policy for an agent that has none."
          },
          {
            "id": "blast-radius",
            "label": "Blast radius",
            "kind": "concept",
            "summary": "What it would cost the business if a row were used in full, today, defined over the reach because whoever takes the agent over inherits its reach and ignores its mandate."
          },
          {
            "id": "reversibility-axis",
            "label": "Whether there is a way back",
            "kind": "concept",
            "summary": "Two rows with the same scope and different reversibility are not the same risk, and the policy should say so."
          },
          {
            "id": "same-footprint-different-blast-radius",
            "label": "Same footprint, different blast radius",
            "kind": "example",
            "summary": "An agent drops a staging table three times over two months; the row is identical each time, and only on day forty-one, when it held six weeks of real records, is it the incident."
          },
          {
            "id": "cloud-comparisons",
            "label": "What the cloud already does",
            "kind": "example",
            "summary": "AWS, Google Cloud and Microsoft Entra already compare permissions granted with permissions used, but a permission set carries no statement of intent, so there is no dormant mandate."
          },
          {
            "id": "vault-as-footprint-recorder",
            "label": "A vault is a footprint recorder by construction",
            "kind": "claim",
            "summary": "Every commit is signed, versioned and append-only, so an agent working in a vault leaves a footprint whether or not anyone intended to collect one, and most of what sgit does shrinks the irreversible part of the blast radius."
          },
          {
            "id": "gap-plus-blast-radius-is-risk",
            "label": "The gap plus blast radius is the risk",
            "kind": "claim",
            "summary": "The gap is exposure, blast radius is impact, and the person who accepts a gap is accepting its blast radius, which until now the policy did not state."
          },
          {
            "id": "reading-our-own-footprint",
            "label": "Reading our own footprint",
            "kind": "question",
            "summary": "Ten agents, six with a written policy, eight days of commit history; the footprint against the six policies is still to be read and published as the second article."
          }
        ],
        "edges": [
          {
            "from": "barriers-typed",
            "to": "four-words",
            "rel": "extends"
          },
          {
            "from": "footprint",
            "to": "four-words",
            "rel": "extends"
          },
          {
            "from": "footprint",
            "to": "footprint-sources",
            "rel": "depends-on"
          },
          {
            "from": "footprint-sources",
            "to": "passive-reading",
            "rel": "leads-to"
          },
          {
            "from": "footprint",
            "to": "footprint-in-the-gap",
            "rel": "produces"
          },
          {
            "from": "footprint",
            "to": "dormant-mandate",
            "rel": "produces"
          },
          {
            "from": "footprint-in-the-gap",
            "to": "dormant-mandate",
            "rel": "contrasts"
          },
          {
            "from": "footprint-in-the-gap",
            "to": "barriers-typed",
            "rel": "depends-on"
          },
          {
            "from": "dormant-mandate",
            "to": "expected-use-hint",
            "rel": "depends-on"
          },
          {
            "from": "footprint",
            "to": "mandate-as-practised",
            "rel": "produces"
          },
          {
            "from": "blast-radius",
            "to": "four-words",
            "rel": "extends"
          },
          {
            "from": "reversibility-axis",
            "to": "blast-radius",
            "rel": "extends"
          },
          {
            "from": "same-footprint-different-blast-radius",
            "to": "blast-radius",
            "rel": "example-of"
          },
          {
            "from": "same-footprint-different-blast-radius",
            "to": "footprint-in-the-gap",
            "rel": "example-of"
          },
          {
            "from": "cloud-comparisons",
            "to": "footprint",
            "rel": "compared-with"
          },
          {
            "from": "cloud-comparisons",
            "to": "dormant-mandate",
            "rel": "contrasts"
          },
          {
            "from": "vault-as-footprint-recorder",
            "to": "footprint-sources",
            "rel": "example-of"
          },
          {
            "from": "vault-as-footprint-recorder",
            "to": "reversibility-axis",
            "rel": "extends"
          },
          {
            "from": "gap-plus-blast-radius-is-risk",
            "to": "blast-radius",
            "rel": "depends-on"
          },
          {
            "from": "gap-plus-blast-radius-is-risk",
            "to": "four-words",
            "rel": "depends-on"
          },
          {
            "from": "reading-our-own-footprint",
            "to": "mandate-as-practised",
            "rel": "depends-on"
          }
        ],
        "links": {
          "articles": [
            "ultimate-insider-three-collisions",
            "connector-twin-before-you-deploy-an-agent",
            "custom-uis-are-not-the-exception",
            "every-risk-is-already-accepted",
            "six-agents-one-inbox"
          ],
          "pages": [
            "/docs/briefs/riskmandate-footprint-and-blast-radius.html",
            "/demos/vaults/kit-bag/index.html",
            "/api/append-lanes.html",
            "/demos/vaults/connector-twin/index.html",
            "/demos/vaults/risk-mandate/index.html",
            "/demos/vaults/risk-acceptance/index.html"
          ],
          "sites": [
            "https://riskmandate.ai/abp.html",
            "https://riskmandate.ai/",
            "https://aws.amazon.com/about-aws/whats-new/2023/11/iam-access-analyzer-inspecting-unused-access",
            "https://aws.amazon.com/about-aws/whats-new/2024/06/aws-iam-access-analyzer-refine-unused-access/",
            "https://cloud.google.com/iam/docs/recommender-overview",
            "https://learn.microsoft.com/en-us/entra/permissions-management/overview",
            "https://techcommunity.microsoft.com/blog/microsoft-entra-blog/2023-state-of-cloud-permissions-risks-report-now-published/1061397"
          ]
        },
        "quotes": [
          {
            "text": "The mandate tells you what you hoped for. The reach tells you what you are exposed to.",
            "why": "Why blast radius is defined over the reach, not the mandate: an attacker inherits the reach."
          },
          {
            "text": "The footprint is how you get near misses for agents without waiting for the luck to run out.",
            "why": "The payoff of reading the footprint against the gap: incidents and near misses are the same events with different luck."
          }
        ]
      }
    },
    {
      "slug": "price-it-then-give-it-away",
      "title": "Price it, then give it away: the early access programme as the next step after \"do they miss it\"",
      "date": "2026-10-02",
      "updated": "",
      "url": "https://sgit.ai/articles/price-it-then-give-it-away.html",
      "markdown": "https://sgit.ai/articles/price-it-then-give-it-away.md",
      "card": "https://sgit.ai/articles/cards/price-it-then-give-it-away.webp",
      "teaser": "Define the product, price it, deliver it at a cost that grows a step at a time, then offer it free to people who know you and measure what it costs them.",
      "topics": [
        "startups-and-strategy",
        "agents-and-policy"
      ],
      "tags": [
        "startups",
        "strategy",
        "pricing",
        "early-access",
        "riskmandate",
        "agent-behaviour-policy",
        "go-to-market",
        "agents",
        "article"
      ],
      "links_out": [
        "the-question-is-whether-they-miss-it"
      ],
      "links_in": [
        "memory-is-not-a-spectator-sport",
        "the-question-is-whether-they-miss-it"
      ],
      "graph": {
        "slug": "price-it-then-give-it-away",
        "teaser": "Define the product, price it, deliver it at a cost that grows a step at a time, then offer it free to people who know you and measure what it costs them.",
        "topics": [
          "startups-and-strategy",
          "agents-and-policy"
        ],
        "core_idea": "A price is a statement of what you think the thing is worth, and giving it away at that price to people who already know you is the cleanest test of whether the statement is true, provided you measure and cut what the free offer costs them.",
        "nodes": [
          {
            "id": "do-they-miss-it",
            "label": "Do they miss it",
            "kind": "concept",
            "summary": "The earlier article's test: hand the thing to people for free, briefly, then take it away, and ask whether they miss it."
          },
          {
            "id": "define-the-product",
            "label": "Define the product",
            "kind": "method",
            "summary": "For RiskMandate the thing somebody receives is an Agent Behaviour Policy for one agent, as an encrypted vault the customer holds the keys to, with the mandate corrected for their deployment."
          },
          {
            "id": "price-as-statement",
            "label": "Price it before you give it away",
            "kind": "claim",
            "summary": "A price is a statement of what you think the thing is worth, and giving it away at that stated price to people who know you is the cleanest test of whether the statement is true."
          },
          {
            "id": "the-ladder",
            "label": "The four-tier ladder",
            "kind": "artefact",
            "summary": "Ten pounds for the pack downloaded, fifty for a working vault, five hundred for the vault corrected for your situation, fifteen hundred for two sessions and a professional's signature."
          },
          {
            "id": "step-cost-delivery",
            "label": "Cost that grows a step at a time",
            "kind": "method",
            "summary": "The agentic workflow means the marginal customer costs a little more, not a lot more, so serving the twentieth customer costs close to serving the second."
          },
          {
            "id": "offer-to-friendlies",
            "label": "Offer it to the people who already know you",
            "kind": "method",
            "summary": "Early adopters, power users and past customers get the first twenty, as a thank-you and as the best possible test group, because their silence means the most."
          },
          {
            "id": "free-is-not-zero",
            "label": "Free is never free for the other side",
            "kind": "claim",
            "summary": "Engaging costs them reading, thinking, deciding and finding a slot, so the first measurement the programme makes is of that attrition and the exercise is to reduce it."
          },
          {
            "id": "do-not-make-them-apply",
            "label": "Do not make them apply",
            "kind": "method",
            "summary": "\"We have twenty of these in the first round. Would you like one? If not, I will give it to someone else\" is honest about scarcity and leaves them nothing to do but say yes or no."
          },
          {
            "id": "early-access-programme",
            "label": "RiskMandate early access programme",
            "kind": "artefact",
            "summary": "Live on 30 September 2026, invite only, it gives the five-hundred-pound tier to people who already run an agent with real access and asks them to say where it is wrong."
          },
          {
            "id": "brutal-outcome",
            "label": "The answer is brutal either way",
            "kind": "claim",
            "summary": "If friendlies take it and ask for more, the question becomes price; if they say it is interesting but have no time, the problem is not the price and you go back to the drawing board."
          },
          {
            "id": "four-kpis",
            "label": "What we count",
            "kind": "method",
            "summary": "Policies created, customised, used, and scenarios run, plus corrections received and the minutes each step cost the person on the other side."
          },
          {
            "id": "agent-brief",
            "label": "For the agents running this",
            "kind": "method",
            "summary": "The list, the short message with no application, the clock on every step, daily counts, every stop recorded as a product change, a stop rule set before the first message, and this article as the record."
          },
          {
            "id": "site-as-memory",
            "label": "The site is becoming the memory",
            "kind": "claim",
            "summary": "An agent picking this up in a year should read, in order, the earlier article, the published offer, this article and the vault holding the counts, so it gets context rather than instructions."
          }
        ],
        "edges": [
          {
            "from": "define-the-product",
            "to": "do-they-miss-it",
            "rel": "extends"
          },
          {
            "from": "price-as-statement",
            "to": "define-the-product",
            "rel": "depends-on"
          },
          {
            "from": "the-ladder",
            "to": "price-as-statement",
            "rel": "example-of"
          },
          {
            "from": "step-cost-delivery",
            "to": "offer-to-friendlies",
            "rel": "leads-to"
          },
          {
            "from": "offer-to-friendlies",
            "to": "price-as-statement",
            "rel": "extends"
          },
          {
            "from": "free-is-not-zero",
            "to": "offer-to-friendlies",
            "rel": "extends"
          },
          {
            "from": "do-not-make-them-apply",
            "to": "free-is-not-zero",
            "rel": "answers"
          },
          {
            "from": "early-access-programme",
            "to": "offer-to-friendlies",
            "rel": "example-of"
          },
          {
            "from": "early-access-programme",
            "to": "the-ladder",
            "rel": "depends-on"
          },
          {
            "from": "early-access-programme",
            "to": "brutal-outcome",
            "rel": "produces"
          },
          {
            "from": "brutal-outcome",
            "to": "free-is-not-zero",
            "rel": "depends-on"
          },
          {
            "from": "brutal-outcome",
            "to": "do-they-miss-it",
            "rel": "compared-with"
          },
          {
            "from": "four-kpis",
            "to": "free-is-not-zero",
            "rel": "depends-on"
          },
          {
            "from": "agent-brief",
            "to": "four-kpis",
            "rel": "depends-on"
          },
          {
            "from": "agent-brief",
            "to": "do-not-make-them-apply",
            "rel": "depends-on"
          },
          {
            "from": "agent-brief",
            "to": "site-as-memory",
            "rel": "leads-to"
          },
          {
            "from": "site-as-memory",
            "to": "do-they-miss-it",
            "rel": "extends"
          }
        ],
        "links": {
          "articles": [
            "the-question-is-whether-they-miss-it"
          ],
          "pages": [
            "/startups/business-plans.html"
          ],
          "sites": [
            "https://riskmandate.ai/early-access.html",
            "https://store.sgit.ai/policies/"
          ]
        },
        "quotes": [
          {
            "text": "A price is a statement of what you think the thing is worth. Giving it away at that stated price, to people who know you, is the cleanest test of whether the statement is true.",
            "why": "The whole method in two sentences: the price is set first and the free offer is the test of it."
          },
          {
            "text": "None of that is zero, and all of it is paid by them.",
            "why": "The part that is easy to leave out: the offer costs the other side attention and schedule, and that cost is what the programme measures."
          }
        ]
      }
    },
    {
      "slug": "replicating-the-agentic-inbox",
      "title": "Replicating the agentic inbox: a walkthrough from one Claude session to a team of agents that never press send",
      "date": "2026-10-02",
      "updated": "2026-10-03",
      "url": "https://sgit.ai/articles/replicating-the-agentic-inbox.html",
      "markdown": "https://sgit.ai/articles/replicating-the-agentic-inbox.md",
      "card": "https://sgit.ai/articles/cards/replicating-the-agentic-inbox.webp",
      "teaser": "How to copy a working agentic email setup in phases: a mailbox and Claude seat of the agent's own, one session with a policy, then roles talking in files.",
      "topics": [
        "agents-and-policy",
        "vaults-and-method"
      ],
      "tags": [
        "agents",
        "email",
        "inbox",
        "agent-behaviour-policy",
        "riskmandate",
        "claude",
        "google-workspace",
        "connectors",
        "vaults",
        "email-fs",
        "walkthrough",
        "article"
      ],
      "links_out": [
        "six-agents-one-inbox",
        "custom-uis-are-not-the-exception",
        "footprint-and-blast-radius",
        "connector-twin-before-you-deploy-an-agent",
        "ultimate-insider-three-collisions"
      ],
      "links_in": [
        "how-much-of-this-did-i-write",
        "the-identity-we-wanted-to-give-the-agents",
        "the-wall-under-the-reply",
        "memory-is-not-a-spectator-sport",
        "six-agents-one-inbox"
      ],
      "graph": {
        "slug": "replicating-the-agentic-inbox",
        "teaser": "How to copy a working agentic email setup in phases: a mailbox and Claude seat of the agent's own, one session with a policy, then roles talking in files.",
        "topics": [
          "agents-and-policy",
          "vaults-and-method"
        ],
        "core_idea": "Claude is used as an agent state machine, one session per role, every message between agents a file in a vault and every outgoing email a draft a person sends; the phases take you from one session to a scheduled team without ever breaking that rule.",
        "nodes": [
          {
            "id": "state-machine",
            "label": "Claude as a state machine",
            "kind": "concept",
            "summary": "Each role is one session that reads its state from a vault, does one kind of work, writes files back and stops; the conductor makes this literal."
          },
          {
            "id": "own-accounts",
            "label": "Accounts of the agent's own",
            "kind": "method",
            "summary": "A Workspace mailbox on a domain you own, a Claude Team seat, a GitHub account on the same identity; never your own inbox."
          },
          {
            "id": "connectors",
            "label": "Connectors enabled, then connected",
            "kind": "artefact",
            "summary": "On a Team plan the owner enables connectors for the organisation; the agent's own account then connects, so the OAuth grants live only there."
          },
          {
            "id": "inbox-agent",
            "label": "The inbox role",
            "kind": "artefact",
            "summary": "The one session that reads the mailbox, labels, moves, summarises and captures what people wrote into the CRM."
          },
          {
            "id": "policy-table",
            "label": "The policy as a table",
            "kind": "method",
            "summary": "Reach, mandate, gap and barriers written before the first run; most barriers in front of a single session are the policy and nothing technical, and the table says so."
          },
          {
            "id": "roles",
            "label": "Roles: @inbox, @drafts, @crm, @briefs, @dev",
            "kind": "concept",
            "summary": "Each role a session with a policy short enough to check; every account has the same reach to the mailbox, two have it in their mandate, one may write."
          },
          {
            "id": "email-fs",
            "label": "Email-FS lite",
            "kind": "artefact",
            "summary": "A message is a file with email headers and typed blocks; mailroom, inbox, done and outbox folders; each role writes only its own folders; one commit per cycle after a leak check."
          },
          {
            "id": "drafts-rule",
            "label": "The agent drafts, a person sends",
            "kind": "claim",
            "summary": "Nothing is sent by an agent; the draft is Cc'd to the person, its hash is logged, and the inbox role records the send from the Sent folder afterwards."
          },
          {
            "id": "security-hold",
            "label": "The security hold",
            "kind": "example",
            "summary": "The one exception: the security role may send one email to one address on a critical finding, and writes a hold file that stops every agent and every run until a person releases it."
          },
          {
            "id": "conductor",
            "label": "The conductor",
            "kind": "artefact",
            "summary": "A scheduled session that runs every role exactly once in a fixed order with a time box, leak-checks and pushes after each step, and writes a report; a security role runs first and last."
          },
          {
            "id": "clone-cost",
            "label": "The clone cost",
            "kind": "claim",
            "summary": "Clone time grows with the number of commits, not file size; fifty commits a day made a seven-minute clone after three days. Commit once per run and compact when a clone passes five minutes."
          },
          {
            "id": "key-rotation",
            "label": "A leaked write key means a new vault",
            "kind": "method",
            "summary": "History keeps what was committed, so a key quoted in a committed file is fixed by a fresh vault seeded from the current files, not by a redaction; scan for other people's secret shapes too."
          },
          {
            "id": "interfaces",
            "label": "Interfaces for the moment",
            "kind": "artefact",
            "summary": "The Now card and the waiting-on board, computed from the vault files when the page opens, nothing stored; each one gets a policy."
          },
          {
            "id": "record",
            "label": "The record",
            "kind": "concept",
            "summary": "Every message a file, every draft in the mailbox, every decision a row: a footprint that can be read afterwards without touching anything."
          },
          {
            "id": "trust",
            "label": "Trust built from the record",
            "kind": "claim",
            "summary": "You do not have to believe what the agent says it did; you can read what it did, and give it more as the drafts you did not change pile up."
          },
          {
            "id": "agents-own-account",
            "label": "The agents' own account",
            "kind": "question",
            "summary": "Each role describes what it reads, writes and refuses, in its own words; the dev role's paragraph and the briefs role's picture of the twelve-agent team are the first two."
          }
        ],
        "edges": [
          {
            "from": "own-accounts",
            "to": "connectors",
            "rel": "leads-to"
          },
          {
            "from": "own-accounts",
            "to": "inbox-agent",
            "rel": "leads-to"
          },
          {
            "from": "policy-table",
            "to": "inbox-agent",
            "rel": "depends-on"
          },
          {
            "from": "inbox-agent",
            "to": "drafts-rule",
            "rel": "depends-on"
          },
          {
            "from": "security-hold",
            "to": "drafts-rule",
            "rel": "example-of"
          },
          {
            "from": "inbox-agent",
            "to": "roles",
            "rel": "leads-to"
          },
          {
            "from": "roles",
            "to": "email-fs",
            "rel": "depends-on"
          },
          {
            "from": "roles",
            "to": "policy-table",
            "rel": "extends"
          },
          {
            "from": "state-machine",
            "to": "roles",
            "rel": "produces"
          },
          {
            "from": "state-machine",
            "to": "conductor",
            "rel": "leads-to"
          },
          {
            "from": "conductor",
            "to": "security-hold",
            "rel": "depends-on"
          },
          {
            "from": "conductor",
            "to": "clone-cost",
            "rel": "produces"
          },
          {
            "from": "clone-cost",
            "to": "key-rotation",
            "rel": "compared-with"
          },
          {
            "from": "email-fs",
            "to": "record",
            "rel": "produces"
          },
          {
            "from": "record",
            "to": "key-rotation",
            "rel": "leads-to"
          },
          {
            "from": "roles",
            "to": "interfaces",
            "rel": "leads-to"
          },
          {
            "from": "interfaces",
            "to": "policy-table",
            "rel": "extends"
          },
          {
            "from": "record",
            "to": "trust",
            "rel": "produces"
          },
          {
            "from": "drafts-rule",
            "to": "trust",
            "rel": "produces"
          },
          {
            "from": "own-accounts",
            "to": "trust",
            "rel": "depends-on"
          },
          {
            "from": "roles",
            "to": "agents-own-account",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "six-agents-one-inbox",
            "custom-uis-are-not-the-exception",
            "footprint-and-blast-radius",
            "connector-twin-before-you-deploy-an-agent",
            "ultimate-insider-three-collisions"
          ],
          "pages": [
            "/docs/append-lane-messaging.html",
            "/docs/agent-contact.html",
            "/docs/briefs/vault-telemetry-append-lanes.html"
          ],
          "sites": [
            "https://riskmandate.ai/abp.html",
            "https://riskmandate.ai/"
          ]
        },
        "quotes": [
          {
            "text": "Nothing is sent by an agent.",
            "why": "The rule that never changes, and the reason the setup gives the person more control rather than less."
          },
          {
            "text": "You do not have to believe what the agent says it did. You can read what it did.",
            "why": "Why the record is the point for someone learning to trust a set of agents."
          },
          {
            "text": "A leaked write key means a new vault, not an edit.",
            "why": "The lesson the record taught on day five: history keeps what was committed."
          }
        ]
      }
    },
    {
      "slug": "custom-uis-are-not-the-exception",
      "title": "Custom UIs are not the exception: the inbox in 2026, where every message has its own universe",
      "date": "2026-10-01",
      "updated": "2026-10-02",
      "url": "https://sgit.ai/articles/custom-uis-are-not-the-exception.html",
      "markdown": "https://sgit.ai/articles/custom-uis-are-not-the-exception.md",
      "card": "https://sgit.ai/articles/cards/custom-uis-are-not-the-exception.webp",
      "teaser": "Every message has a graph, so it can be shaped for the reader's moment; a custom interface per moment is now how interfaces get made, and each gets a policy.",
      "topics": [
        "graphs-and-knowledge",
        "agents-and-policy"
      ],
      "tags": [
        "inbox",
        "email",
        "custom-ui",
        "fractal-semantic-graphs",
        "vault-apps",
        "append-lanes",
        "email-fs",
        "wardley-maps",
        "agents",
        "riskmandate",
        "article"
      ],
      "links_out": [
        "introducing-fractal-semantic-graphs",
        "six-agents-one-inbox",
        "future-of-news-story-vault-not-paywall",
        "connector-twin-before-you-deploy-an-agent",
        "chat-on-a-static-site",
        "seven-vaults-one-method",
        "token-bill-nobody-is-sending",
        "ultimate-insider-three-collisions"
      ],
      "links_in": [
        "the-wall-under-the-reply",
        "code-review-as-a-fractal-semantic-graph",
        "memory-is-not-a-spectator-sport",
        "footprint-and-blast-radius",
        "replicating-the-agentic-inbox"
      ],
      "graph": {
        "slug": "custom-uis-are-not-the-exception",
        "teaser": "Every message has a graph, so it can be shaped for the reader's moment; a custom interface per moment is now how interfaces get made, and each gets a policy.",
        "topics": [
          "graphs-and-knowledge",
          "agents-and-policy"
        ],
        "core_idea": "Every message has a graph with altitudes, so a message is designed for the recipient's moment rather than the sender's thread; a custom interface per moment is how interfaces now get made, each one commoditising the next, and each is an agent surface that gets a policy.",
        "nodes": [
          {
            "id": "follow-up-problem",
            "label": "The follow-up problem",
            "kind": "concept",
            "summary": "Following up is harder than doing the work, because every person has a different context and the thread you share hides its own structure."
          },
          {
            "id": "message-graph",
            "label": "Every message has a graph",
            "kind": "concept",
            "summary": "Extract the actions, questions, statements, decisions and concepts from every message and a thread stops being a thread and becomes a graph."
          },
          {
            "id": "altitudes",
            "label": "Altitudes",
            "kind": "concept",
            "summary": "There is a graph for the block inside a message, the message, the conversation, the company and the contact, each navigable on its own and pointing up and down."
          },
          {
            "id": "email-is-a-medium",
            "label": "Email is a medium",
            "kind": "claim",
            "summary": "The design brief for a message is the recipient's moment when they open it, not the sender's thread, so send what they need in the shape they need it."
          },
          {
            "id": "projection",
            "label": "A message is a projection",
            "kind": "concept",
            "summary": "A message to a person is a projection of the conversation graph, for one reader, at the moment they open it, and a thread is only the raw stream."
          },
          {
            "id": "wardley-strip",
            "label": "Genesis, custom, product, commodity",
            "kind": "concept",
            "summary": "Everything moves from genesis through custom-built to product to commodity, and every new interface built is a thing commoditised for next time."
          },
          {
            "id": "custom-interfaces-not-the-exception",
            "label": "Custom interfaces are not the exception",
            "kind": "claim",
            "summary": "A custom interface per message, per thread, per topic, per question is not an exception; it is how interfaces get made."
          },
          {
            "id": "drop-page",
            "label": "The page that is both the to-do and the place to act",
            "kind": "example",
            "summary": "A page lists the PDFs still owed and gives a place to drop them, through the vault's append lane, with no context switch, no second tool and no email."
          },
          {
            "id": "append-lane",
            "label": "Append lane",
            "kind": "artefact",
            "summary": "A write-only channel anyone with the token can drop a file into, which the vault's owner drains and processes in order."
          },
          {
            "id": "email-fs-blocks",
            "label": "Email-FS blocks",
            "kind": "artefact",
            "summary": "The fenced decision, answer and status blocks that Email-FS-lite uses so agents can read each other's asks without parsing prose, rendered as an interface for a human."
          },
          {
            "id": "eight-days",
            "label": "Eight days, not one afternoon",
            "kind": "example",
            "summary": "From 25 September to 2 October 2026 a small team of agents and one human went from an empty vault to a working way of doing outreach, with sixteen CRM interface releases and around 230 commits."
          },
          {
            "id": "the-loop",
            "label": "Every tap teaches the next interface",
            "kind": "method",
            "summary": "A moment gets a shape, the shape gets a decision, the decision is written to the vault as a record, and the record shapes the next version of the interface."
          },
          {
            "id": "why-it-compounds",
            "label": "Why it compounds",
            "kind": "claim",
            "summary": "Every interface makes the next one better, each one teaches the agent how its user wants to work, and when automation outgrows the inbox the interface becomes the prioritisation."
          },
          {
            "id": "sender-served-structure",
            "label": "The future of email",
            "kind": "claim",
            "summary": "The future of email is sender-served structure, read by the recipient's agent, with the inbox as one view of the graph, and a plain email still works on day one."
          },
          {
            "id": "agent-team",
            "label": "Ten agents and one human",
            "kind": "example",
            "summary": "Ten agents with narrow jobs and one human who decides, talking to each other in files, each writing only its own folders, six with a written Agent Behaviour Policy."
          },
          {
            "id": "interface-is-an-agent-surface",
            "label": "An interface is an agent surface, so it gets a policy",
            "kind": "claim",
            "summary": "A page that drops files into a vault, answers questions or lets a model read a CRM has a grant, a mandate, a delta and barriers, so it gets a policy like any agent."
          }
        ],
        "edges": [
          {
            "from": "follow-up-problem",
            "to": "message-graph",
            "rel": "leads-to"
          },
          {
            "from": "altitudes",
            "to": "message-graph",
            "rel": "extends"
          },
          {
            "from": "message-graph",
            "to": "email-is-a-medium",
            "rel": "leads-to"
          },
          {
            "from": "email-is-a-medium",
            "to": "projection",
            "rel": "produces"
          },
          {
            "from": "projection",
            "to": "altitudes",
            "rel": "depends-on"
          },
          {
            "from": "custom-interfaces-not-the-exception",
            "to": "wardley-strip",
            "rel": "depends-on"
          },
          {
            "from": "projection",
            "to": "custom-interfaces-not-the-exception",
            "rel": "leads-to"
          },
          {
            "from": "drop-page",
            "to": "custom-interfaces-not-the-exception",
            "rel": "example-of"
          },
          {
            "from": "drop-page",
            "to": "append-lane",
            "rel": "depends-on"
          },
          {
            "from": "drop-page",
            "to": "email-fs-blocks",
            "rel": "depends-on"
          },
          {
            "from": "eight-days",
            "to": "drop-page",
            "rel": "extends"
          },
          {
            "from": "agent-team",
            "to": "eight-days",
            "rel": "produces"
          },
          {
            "from": "custom-interfaces-not-the-exception",
            "to": "why-it-compounds",
            "rel": "leads-to"
          },
          {
            "from": "the-loop",
            "to": "why-it-compounds",
            "rel": "leads-to"
          },
          {
            "from": "why-it-compounds",
            "to": "follow-up-problem",
            "rel": "answers"
          },
          {
            "from": "projection",
            "to": "sender-served-structure",
            "rel": "leads-to"
          },
          {
            "from": "sender-served-structure",
            "to": "email-fs-blocks",
            "rel": "depends-on"
          },
          {
            "from": "sender-served-structure",
            "to": "altitudes",
            "rel": "depends-on"
          },
          {
            "from": "agent-team",
            "to": "interface-is-an-agent-surface",
            "rel": "leads-to"
          },
          {
            "from": "interface-is-an-agent-surface",
            "to": "custom-interfaces-not-the-exception",
            "rel": "extends"
          }
        ],
        "links": {
          "articles": [
            "introducing-fractal-semantic-graphs",
            "six-agents-one-inbox",
            "future-of-news-story-vault-not-paywall",
            "connector-twin-before-you-deploy-an-agent",
            "chat-on-a-static-site",
            "seven-vaults-one-method",
            "token-bill-nobody-is-sending",
            "ultimate-insider-three-collisions"
          ],
          "pages": [
            "/demos/vaults/strategy-maps/index.html",
            "/api/append-lanes.html",
            "/docs/append-lane-messaging.html",
            "/demos/vaults/company-xray/index.html",
            "/demos/vaults/evidence-dispatch/index.html",
            "/demos/vaults/board/index.html",
            "/demos/vaults/voice-debrief/index.html",
            "/demos/vaults/vault-app-pocs/index.html",
            "/demos/vaults/deploy-docs/index.html",
            "/demos/vaults/kit-bag/index.html",
            "/demos/vaults/agent-webmaster/index.html",
            "/demos/vaults/risk-mandate/index.html",
            "/docs/agent-contact.html"
          ],
          "sites": [
            "https://riskmandate.ai/abp.html",
            "https://riskmandate.ai/",
            "https://llms.sgit.ai/",
            "https://graphs.sgit.ai/",
            "https://twins.sgit.ai/",
            "https://wardley-maps.sgit.ai/"
          ]
        },
        "quotes": [
          {
            "text": "Every time I ask an agent in chat for something a page could have shown me, that is the next interface.",
            "why": "The measurable version of the title: the trigger that produces each custom interface."
          },
          {
            "text": "The graph is the medium. Email, cards, voice and boards are views of it.",
            "why": "The turn where email stops being the medium and becomes one projection of the graph."
          }
        ]
      }
    },
    {
      "slug": "ultimate-insider-three-collisions",
      "title": "The ultimate insider: agents, the infrastructure that cannot hold them, and risk management that cannot keep up",
      "date": "2026-09-30",
      "updated": "2026-10-02",
      "url": "https://sgit.ai/articles/ultimate-insider-three-collisions.html",
      "markdown": "https://sgit.ai/articles/ultimate-insider-three-collisions.md",
      "card": "https://sgit.ai/articles/cards/ultimate-insider-three-collisions.webp",
      "teaser": "Agents, the infrastructure meant to contain them, and risk management run on spreadsheets are arriving at once, and together they are one scenario.",
      "topics": [
        "agents-and-policy"
      ],
      "tags": [
        "agents",
        "insider-threat",
        "risk-management",
        "infrastructure",
        "riskmandate",
        "agent-behaviour-policy",
        "resilience",
        "security",
        "talk",
        "article"
      ],
      "links_out": [
        "every-risk-is-already-accepted",
        "footprint-and-blast-radius",
        "six-agents-one-inbox",
        "connector-twin-before-you-deploy-an-agent",
        "introducing-fractal-semantic-graphs"
      ],
      "links_in": [
        "the-identity-we-wanted-to-give-the-agents",
        "the-investigation-github-owes-its-customers",
        "footprint-and-blast-radius",
        "replicating-the-agentic-inbox",
        "custom-uis-are-not-the-exception"
      ],
      "graph": {
        "slug": "ultimate-insider-three-collisions",
        "teaser": "Agents, the infrastructure meant to contain them, and risk management run on spreadsheets are arriving at once, and together they are one scenario.",
        "topics": [
          "agents-and-policy"
        ],
        "core_idea": "Agents are the insider threat that never scaled before, the infrastructure was designed for none of it, and risk management runs at the speed of spreadsheets, so the way out is to constrain the agent in order to trust it.",
        "nodes": [
          {
            "id": "threat-definition",
            "label": "A threat is anything that causes business impact",
            "kind": "concept",
            "summary": "A threat does not need to be malicious, and most of the worst damage was a bug, a misconfiguration or a person doing something that was allowed and should not have been."
          },
          {
            "id": "insider-never-scaled",
            "label": "The insider threat never scaled",
            "kind": "claim",
            "summary": "There were two kinds of insider, a human bounded by hours and conscience and static code that did what it was written to do, and both were constrained by something soft but real."
          },
          {
            "id": "agent-as-loop",
            "label": "An agent is a reasoning engine in a loop",
            "kind": "concept",
            "summary": "An agent is a language model in a loop with tools and an objective, and unlike any insider before it has skills: every language, every schema, the ability to write its own connectors and try again."
          },
          {
            "id": "lethal-trifecta",
            "label": "The lethal trifecta",
            "kind": "concept",
            "summary": "Give a model private data, untrusted content and a way to communicate outward, and it can be turned against you by a document it reads."
          },
          {
            "id": "five-incidents",
            "label": "Five incidents",
            "kind": "example",
            "summary": "Replit, Gemini CLI, Amazon Q, EchoLeak and the AI-orchestrated espionage campaign, of which three were not attacks but agents being agents."
          },
          {
            "id": "machine-identities",
            "label": "82 machine identities per human",
            "kind": "example",
            "summary": "Agents are arriving into a population of identities that is already unmanaged, with 42 per cent of machine identities holding privileged access."
          },
          {
            "id": "infrastructure-gaps",
            "label": "The infrastructure that cannot hold them",
            "kind": "claim",
            "summary": "Recovery, identity, permissions and containment were all built for code that stays where you put it, and the stack falls over on its own."
          },
          {
            "id": "grant-vs-mandate",
            "label": "The grant and the mandate",
            "kind": "concept",
            "summary": "Cloud permissions are the union of everything anyone ever needed, so an agent's grant is not what you meant but everything the role accumulated."
          },
          {
            "id": "outages",
            "label": "The two outages",
            "kind": "example",
            "summary": "A DNS race condition took down a large part of AWS US-East-1 for over fourteen hours, and a configuration file that doubled in size broke Cloudflare and much of the web."
          },
          {
            "id": "spreadsheet-risk",
            "label": "Risk management at the speed of spreadsheets",
            "kind": "claim",
            "summary": "48 per cent of organisations track risk in spreadsheets, reviewed quarterly, when the decisions now have to be made in seconds and in advance."
          },
          {
            "id": "chain-to-plug",
            "label": "The chain to pulling the plug",
            "kind": "claim",
            "summary": "Because the register cannot see what the agent can reach it cannot say what the risk is, cannot decide whether it fits the appetite, cannot fund the controls, and the plug comes out."
          },
          {
            "id": "unreported",
            "label": "Nobody has to report",
            "kind": "claim",
            "summary": "Companies are not required to disclose most of what agents do to them, and aviation solved this fifty years ago with confidential reporting that cyber has nothing like."
          },
          {
            "id": "the-collision",
            "label": "The collision",
            "kind": "claim",
            "summary": "An entity inside the company with reach we have not measured, controls we cannot rely on, and a decision process too slow to matter before, during or after the incident."
          },
          {
            "id": "agent-behaviour-policy",
            "label": "Agent Behaviour Policy",
            "kind": "method",
            "summary": "Grant measured, mandate elicited, delta derived, barrier recorded, with each barrier typed honestly as a boundary, a setting, an expectation or nothing."
          },
          {
            "id": "contain-in-layers",
            "label": "Contain in layers",
            "kind": "method",
            "summary": "Identity per agent, twins that journal every call, network segmentation, and append-only records in vaults the host cannot read."
          },
          {
            "id": "the-irony",
            "label": "Brakes are what let a car go fast",
            "kind": "claim",
            "summary": "The more you can constrain an agent, the more you can trust it, and the more autonomy you can afford to give it."
          }
        ],
        "edges": [
          {
            "from": "insider-never-scaled",
            "to": "threat-definition",
            "rel": "depends-on"
          },
          {
            "from": "agent-as-loop",
            "to": "insider-never-scaled",
            "rel": "contrasts"
          },
          {
            "from": "lethal-trifecta",
            "to": "agent-as-loop",
            "rel": "extends"
          },
          {
            "from": "five-incidents",
            "to": "agent-as-loop",
            "rel": "example-of"
          },
          {
            "from": "five-incidents",
            "to": "lethal-trifecta",
            "rel": "example-of"
          },
          {
            "from": "machine-identities",
            "to": "infrastructure-gaps",
            "rel": "example-of"
          },
          {
            "from": "grant-vs-mandate",
            "to": "infrastructure-gaps",
            "rel": "example-of"
          },
          {
            "from": "outages",
            "to": "infrastructure-gaps",
            "rel": "example-of"
          },
          {
            "from": "chain-to-plug",
            "to": "spreadsheet-risk",
            "rel": "depends-on"
          },
          {
            "from": "chain-to-plug",
            "to": "grant-vs-mandate",
            "rel": "depends-on"
          },
          {
            "from": "the-collision",
            "to": "agent-as-loop",
            "rel": "depends-on"
          },
          {
            "from": "the-collision",
            "to": "infrastructure-gaps",
            "rel": "depends-on"
          },
          {
            "from": "the-collision",
            "to": "chain-to-plug",
            "rel": "depends-on"
          },
          {
            "from": "unreported",
            "to": "the-collision",
            "rel": "extends"
          },
          {
            "from": "unreported",
            "to": "five-incidents",
            "rel": "extends"
          },
          {
            "from": "agent-behaviour-policy",
            "to": "grant-vs-mandate",
            "rel": "answers"
          },
          {
            "from": "contain-in-layers",
            "to": "infrastructure-gaps",
            "rel": "answers"
          },
          {
            "from": "the-irony",
            "to": "agent-behaviour-policy",
            "rel": "depends-on"
          },
          {
            "from": "the-irony",
            "to": "contain-in-layers",
            "rel": "depends-on"
          },
          {
            "from": "the-irony",
            "to": "chain-to-plug",
            "rel": "contrasts"
          }
        ],
        "links": {
          "articles": [
            "every-risk-is-already-accepted",
            "footprint-and-blast-radius",
            "six-agents-one-inbox",
            "connector-twin-before-you-deploy-an-agent",
            "introducing-fractal-semantic-graphs"
          ],
          "pages": [
            "/docs/agent-contact.html",
            "/demos/vaults/kit-bag/index.html",
            "/demos/vaults/standards-atlas-gdpr/index.html",
            "/demos/vaults/regulation-graph/index.html",
            "/demos/vaults/pci-dss-graph/index.html",
            "/partnerships/authentitas.html"
          ],
          "sites": [
            "https://riskmandate.ai/abp.html",
            "https://www.anthropic.com/research/building-effective-agents",
            "https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/",
            "https://dev.to/joylo/why-replits-ai-agent-deleted-a-production-database-389p",
            "https://www-cdn.anthropic.com/d7dd50dd1185f59be051b307150d877f2b82bd2c.pdf",
            "https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/",
            "https://techcommunity.microsoft.com/blog/microsoft-entra-blog/2023-state-of-cloud-permissions-risks-report-now-published/1061397",
            "https://en.wikipedia.org/wiki/Aviation_Safety_Reporting_System"
          ]
        },
        "quotes": [
          {
            "text": "Three of those five were not attacks. They were agents being agents.",
            "why": "The distance between benign and malicious agent damage is a prompt, which is why the insider framing fits."
          },
          {
            "text": "The more you can constrain an agent, the more you can trust it, and the more autonomy you can afford to give it.",
            "why": "The irony the talk would end on, and the turn from the problem to the way out."
          }
        ]
      }
    },
    {
      "slug": "how-news-got-here",
      "title": "The reader was always the product: a corrected history of how news got into this mess",
      "date": "2026-09-29",
      "updated": "",
      "url": "https://sgit.ai/articles/how-news-got-here.html",
      "markdown": "https://sgit.ai/articles/how-news-got-here.md",
      "card": "https://sgit.ai/articles/cards/how-news-got-here.webp",
      "teaser": "News has sold the reader to advertisers since 1833; the web took the monopoly, the platforms made the reader measurable, and AI took the traffic.",
      "topics": [
        "news-and-evidence"
      ],
      "tags": [
        "news",
        "publishing",
        "history",
        "advertising",
        "provenance",
        "micropayments",
        "economics",
        "article"
      ],
      "links_out": [
        "future-of-news-story-vault-not-paywall",
        "token-bill-nobody-is-sending",
        "introducing-fractal-semantic-graphs"
      ],
      "links_in": [],
      "graph": {
        "slug": "how-news-got-here",
        "teaser": "News has sold the reader to advertisers since 1833; the web took the monopoly, the platforms made the reader measurable, and AI took the traffic.",
        "topics": [
          "news-and-evidence"
        ],
        "core_idea": "The reader has been the product since 1833 and the money has always flowed to whoever owned the road, so the fix is to stop charging for the road and charge for the cargo: the story as a graph with every claim tied to hashed evidence.",
        "nodes": [
          {
            "id": "reader-as-product",
            "label": "The reader was always the product",
            "kind": "claim",
            "summary": "The reader stopped being the customer in 1833 and became the audience sold to the advertiser, and by 2005 advertising was 82% of American newspaper revenue."
          },
          {
            "id": "penny-press",
            "label": "Penny press",
            "kind": "example",
            "summary": "The New York Sun of September 1833 sold on the street for a cent and was paid for by advertising while other papers relied on high-priced subscriptions."
          },
          {
            "id": "toll-bridge",
            "label": "Unregulated toll bridge",
            "kind": "concept",
            "summary": "A monopoly city newspaper was the only way for a local advertiser to reach local households, and its margins of 20 to 30 per cent paid for the reporting."
          },
          {
            "id": "classifieds-collapse",
            "label": "Classifieds collapse",
            "kind": "example",
            "summary": "Classifieds were about 40% of revenue and fell from $19.6 billion in 2000 to about $6 billion in 2009 once Craigslist let people list a sofa for free."
          },
          {
            "id": "measurable-reader",
            "label": "The measurable reader",
            "kind": "concept",
            "summary": "Cookies in 1996 and AdSense in 2003 let the reader be followed from page to page, and by 2017 Google and Meta took 54.7% of American digital advertising."
          },
          {
            "id": "publisher-as-tenant",
            "label": "Publisher as tenant",
            "kind": "claim",
            "summary": "Publishers depended on traffic from companies that could switch it off, and Facebook referrals to news sites fell 58% in six years."
          },
          {
            "id": "novelty-beats-truth",
            "label": "Novelty beats truth",
            "kind": "claim",
            "summary": "False news on Twitter was 70% more likely to be retweeted than true news, spread by humans not bots, and Facebook weighted an anger reaction at five times a like."
          },
          {
            "id": "provenance-is-labour",
            "label": "Provenance is labour",
            "kind": "claim",
            "summary": "Following a claim to its source is hours of a person's time, and newsrooms that lost 57% of their jobs cut those hours first because they did not move the click."
          },
          {
            "id": "ai-removes-traffic",
            "label": "AI removes the traffic",
            "kind": "claim",
            "summary": "Search traffic to publishers fell a third in the year to November 2025 while the crawlers that replaced it fetch tens of thousands of pages per reader they send back."
          },
          {
            "id": "return-to-rent",
            "label": "Back to selling to readers, by rent",
            "kind": "claim",
            "summary": "Circulation revenue overtook advertising in 2021, but what is sold is the subscription, unlimited access priced for the reader who forgets to cancel."
          },
          {
            "id": "http-402",
            "label": "402 Payment Required",
            "kind": "artefact",
            "summary": "HTTP/1.1 reserved a status code in 1997 for digital cash or micropayment systems, and it is still reserved for future use with no browser having implemented it."
          },
          {
            "id": "mental-transaction-cost",
            "label": "Mental transaction costs",
            "kind": "concept",
            "summary": "Szabo and Shirky argued that deciding whether an article is worth two cents costs more than two cents, an argument that does not apply to an agent with a wallet."
          },
          {
            "id": "advertising-by-default",
            "label": "Advertising as the default",
            "kind": "claim",
            "summary": "The banner ad, the cookie, the pop-up and AdSense were small decisions that together made advertising the default model to support online content."
          },
          {
            "id": "people-pay-when-easy",
            "label": "People pay when paying is easy",
            "kind": "claim",
            "summary": "A million iTunes songs sold in the first week in 2003 and Substack passed five million paid subscriptions in 2025, in an industry that insisted people never would."
          },
          {
            "id": "charge-for-cargo",
            "label": "Charge for the cargo, not the road",
            "kind": "method",
            "summary": "Sell the story as a graph, every claim walked to frozen and hashed evidence, in pence and on demand, with the money walking back to whoever made the fact."
          }
        ],
        "edges": [
          {
            "from": "penny-press",
            "to": "reader-as-product",
            "rel": "example-of"
          },
          {
            "from": "toll-bridge",
            "to": "reader-as-product",
            "rel": "extends"
          },
          {
            "from": "classifieds-collapse",
            "to": "toll-bridge",
            "rel": "example-of"
          },
          {
            "from": "measurable-reader",
            "to": "reader-as-product",
            "rel": "extends"
          },
          {
            "from": "measurable-reader",
            "to": "publisher-as-tenant",
            "rel": "leads-to"
          },
          {
            "from": "measurable-reader",
            "to": "novelty-beats-truth",
            "rel": "leads-to"
          },
          {
            "from": "publisher-as-tenant",
            "to": "provenance-is-labour",
            "rel": "leads-to"
          },
          {
            "from": "ai-removes-traffic",
            "to": "publisher-as-tenant",
            "rel": "extends"
          },
          {
            "from": "ai-removes-traffic",
            "to": "return-to-rent",
            "rel": "leads-to"
          },
          {
            "from": "return-to-rent",
            "to": "charge-for-cargo",
            "rel": "contrasts"
          },
          {
            "from": "mental-transaction-cost",
            "to": "advertising-by-default",
            "rel": "leads-to"
          },
          {
            "from": "http-402",
            "to": "advertising-by-default",
            "rel": "contrasts"
          },
          {
            "from": "people-pay-when-easy",
            "to": "mental-transaction-cost",
            "rel": "contrasts"
          },
          {
            "from": "people-pay-when-easy",
            "to": "charge-for-cargo",
            "rel": "leads-to"
          },
          {
            "from": "http-402",
            "to": "charge-for-cargo",
            "rel": "leads-to"
          },
          {
            "from": "novelty-beats-truth",
            "to": "charge-for-cargo",
            "rel": "leads-to"
          },
          {
            "from": "provenance-is-labour",
            "to": "charge-for-cargo",
            "rel": "leads-to"
          },
          {
            "from": "reader-as-product",
            "to": "charge-for-cargo",
            "rel": "contrasts"
          }
        ],
        "links": {
          "articles": [
            "future-of-news-story-vault-not-paywall",
            "token-bill-nobody-is-sending",
            "introducing-fractal-semantic-graphs"
          ],
          "pages": [],
          "sites": [
            "https://en.wikipedia.org/wiki/Penny_press",
            "https://www.pewresearch.org/journalism/fact-sheet/newspapers/",
            "https://www.poynter.org/reporting-editing/2010/classified-ad-revenue-down-70-percent-in-10-years-with-one-bright-spot/",
            "https://www.axios.com/2022/12/20/google-meta-duopoly-online-advertising",
            "https://news.mit.edu/2018/study-twitter-false-news-travels-faster-true-stories-0308",
            "https://www.pewresearch.org/short-reads/2021/07/13/u-s-newsroom-employment-has-fallen-26-since-2008/",
            "https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/402",
            "https://blog.cloudflare.com/crawlers-click-ai-bots-training/"
          ]
        },
        "quotes": [
          {
            "text": "The reader stopped being the customer in 1833. The reader became the audience that was sold to the customer, and the cover price became a way of proving the audience existed.",
            "why": "The most important of the four corrections: the web did not make the reader the product, the penny press did."
          },
          {
            "text": "The fix is to stop charging for the road and start charging for the cargo.",
            "why": "The four eras end here: the money followed whoever owned distribution, so the proposal is to sell the evidence itself."
          }
        ]
      }
    },
    {
      "slug": "six-agents-one-inbox",
      "title": "Six agents, one inbox: what a real multi-agent setup taught me about access policies",
      "date": "2026-09-29",
      "updated": "2026-10-02",
      "url": "https://sgit.ai/articles/six-agents-one-inbox.html",
      "markdown": "https://sgit.ai/articles/six-agents-one-inbox.md",
      "card": "https://sgit.ai/articles/cards/six-agents-one-inbox.webp",
      "teaser": "An access policy for an agent is only as real as its worst row: every rule in a real six-agent setup, graded by how it is enforced today.",
      "topics": [
        "agents-and-policy"
      ],
      "tags": [
        "agents",
        "connectors",
        "access-policies",
        "non-human-identity",
        "gmail",
        "github",
        "riskmandate",
        "security",
        "article"
      ],
      "links_out": [
        "connector-twin-before-you-deploy-an-agent",
        "replicating-the-agentic-inbox"
      ],
      "links_in": [
        "if-somebody-built-a-company-on-code-review",
        "send-an-agent-not-a-spreadsheet",
        "the-identity-we-wanted-to-give-the-agents",
        "the-wall-under-the-reply",
        "memory-is-not-a-spectator-sport",
        "footprint-and-blast-radius",
        "replicating-the-agentic-inbox",
        "custom-uis-are-not-the-exception",
        "ultimate-insider-three-collisions"
      ],
      "graph": {
        "slug": "six-agents-one-inbox",
        "teaser": "An access policy for an agent is only as real as its worst row: every rule in a real six-agent setup, graded by how it is enforced today.",
        "topics": [
          "agents-and-policy"
        ],
        "core_idea": "Write an agent's access policy as a table with a column for how each rule is enforced, and the policy is exactly as strong as the row that says the agent has been told.",
        "nodes": [
          {
            "id": "worst-row",
            "label": "The worst row",
            "kind": "claim",
            "summary": "If the enforcement column says the agent has been told, that row is a hope, and the policy is exactly as strong as that hope on the day something goes wrong."
          },
          {
            "id": "account-is-blast-radius",
            "label": "The account is the blast radius",
            "kind": "claim",
            "summary": "Every session an agent opens through a connector runs as the account that authorised it, with everything that account can reach."
          },
          {
            "id": "dedicated-accounts",
            "label": "Dedicated accounts per agent",
            "kind": "method",
            "summary": "A dedicated Workspace seat, a dedicated Claude seat and a dedicated GitHub account per agent, so the worst a session can do is bounded by what its account can see."
          },
          {
            "id": "organisational-unit",
            "label": "Organisational unit",
            "kind": "concept",
            "summary": "An account of its own puts each agent in its own organisational unit, and Google Workspace applies its Gmail compliance rules per unit."
          },
          {
            "id": "restrict-delivery",
            "label": "Restrict delivery",
            "kind": "method",
            "summary": "A delivery restriction to my own domain means that even if the reader sends, it can only reach me."
          },
          {
            "id": "attachment-compliance",
            "label": "Attachment compliance",
            "kind": "method",
            "summary": "An outbound rule that strips attachments turns a policy into a property of the mail system."
          },
          {
            "id": "scope-limits",
            "label": "Scope limits on third-party apps",
            "kind": "method",
            "summary": "The sharpest tool in the box cannot express drafts only, because the Gmail API puts drafting and sending in the same grant."
          },
          {
            "id": "six-roles",
            "label": "Six roles",
            "kind": "concept",
            "summary": "The reader, the mailbox, the inbox, the CRM, the dev team and the site editor, each with a policy short enough to check and differing on who may send."
          },
          {
            "id": "exception-before-policy",
            "label": "The exception arrived before the policy",
            "kind": "example",
            "summary": "The reader that must never reply must reply when the message came from me, and never became never, unless on day one."
          },
          {
            "id": "signature-registry",
            "label": "Signature registry",
            "kind": "artefact",
            "summary": "The append-lane machinery of per-session keys and a pinned registry is what would let the reader verify a message came from me, once my key is in it."
          },
          {
            "id": "attachment-finding",
            "label": "The attachment finding",
            "kind": "example",
            "summary": "An agent found that create_draft and update_draft accept an attachments array and proved it with a 17 KB signed PDF that arrived intact."
          },
          {
            "id": "documentation-disagrees",
            "label": "The documentation disagrees with itself",
            "kind": "claim",
            "summary": "One vendor page says the Gmail connector is read-only and another says it can send, reply and forward, so a policy that cites the documentation has cited a moving target."
          },
          {
            "id": "connector-twin",
            "label": "Connector twin",
            "kind": "method",
            "summary": "Before you write down what an agent may do, replay what it can do."
          },
          {
            "id": "enforcement-ladder",
            "label": "Enforcement ladder",
            "kind": "concept",
            "summary": "Identity boundaries and keys enforce themselves, compliance rules enforce at the platform, approval prompts enforce at the human, and everything else is the agent doing as it was told."
          },
          {
            "id": "policy-table",
            "label": "The policy table",
            "kind": "artefact",
            "summary": "One rule per row across six roles, with the column that says whether it is enforced, an admin rule, an approval, or told."
          },
          {
            "id": "cowork-vs-claude-code",
            "label": "Cowork and Claude Code reach",
            "kind": "example",
            "summary": "The Cowork agent has no GitHub connector and cannot open the repository, while the Claude Code agent on the same seat edits the site."
          }
        ],
        "edges": [
          {
            "from": "dedicated-accounts",
            "to": "account-is-blast-radius",
            "rel": "depends-on"
          },
          {
            "from": "organisational-unit",
            "to": "dedicated-accounts",
            "rel": "depends-on"
          },
          {
            "from": "restrict-delivery",
            "to": "organisational-unit",
            "rel": "depends-on"
          },
          {
            "from": "attachment-compliance",
            "to": "organisational-unit",
            "rel": "depends-on"
          },
          {
            "from": "scope-limits",
            "to": "organisational-unit",
            "rel": "depends-on"
          },
          {
            "from": "six-roles",
            "to": "dedicated-accounts",
            "rel": "depends-on"
          },
          {
            "from": "six-roles",
            "to": "exception-before-policy",
            "rel": "leads-to"
          },
          {
            "from": "exception-before-policy",
            "to": "signature-registry",
            "rel": "depends-on"
          },
          {
            "from": "restrict-delivery",
            "to": "exception-before-policy",
            "rel": "answers"
          },
          {
            "from": "attachment-finding",
            "to": "connector-twin",
            "rel": "example-of"
          },
          {
            "from": "attachment-finding",
            "to": "documentation-disagrees",
            "rel": "leads-to"
          },
          {
            "from": "attachment-finding",
            "to": "attachment-compliance",
            "rel": "leads-to"
          },
          {
            "from": "scope-limits",
            "to": "enforcement-ladder",
            "rel": "leads-to"
          },
          {
            "from": "policy-table",
            "to": "enforcement-ladder",
            "rel": "depends-on"
          },
          {
            "from": "policy-table",
            "to": "six-roles",
            "rel": "depends-on"
          },
          {
            "from": "worst-row",
            "to": "policy-table",
            "rel": "depends-on"
          },
          {
            "from": "connector-twin",
            "to": "worst-row",
            "rel": "extends"
          },
          {
            "from": "cowork-vs-claude-code",
            "to": "account-is-blast-radius",
            "rel": "example-of"
          },
          {
            "from": "documentation-disagrees",
            "to": "connector-twin",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "connector-twin-before-you-deploy-an-agent"
          ],
          "pages": [
            "/docs/append-lane-messaging.html",
            "/demos/vaults/licence-to-operate/index.html"
          ],
          "sites": [
            "https://nhi.sgit.ai/research/shared-drives.html",
            "https://knowledge.workspace.google.com/admin/gmail/advanced/restrict-email-messages-to-authorized-addresses-or-domains-only",
            "https://knowledge.workspace.google.com/admin/gmail/advanced/filter-messages-with-attachments",
            "https://workspaceupdates.googleblog.com/2024/12/configure-third-party-apps-by-select-api-scopes-general-availability.html",
            "https://developers.google.com/workspace/gmail/api/auth/scopes",
            "https://claude.com/docs/connectors/google/gmail",
            "https://support.claude.com/en/articles/10166901-use-google-workspace-connectors",
            "https://support.claude.com/en/articles/13930458-set-up-role-based-permissions-on-enterprise-plans"
          ]
        },
        "quotes": [
          {
            "text": "An access policy for an agent is only as real as its worst row.",
            "why": "The claim the whole article is built to test, stated so it can be wrong."
          },
          {
            "text": "The only way to know what a connector can do is to try.",
            "why": "The attachment finding showed a policy written from documentation was wrong."
          }
        ]
      }
    },
    {
      "slug": "token-bill-nobody-is-sending",
      "title": "Sixteen thousand fetches, ten clicks, and a token bill nobody is sending: the case for paying publishers to be easy to read",
      "date": "2026-09-28",
      "updated": "",
      "url": "https://sgit.ai/articles/token-bill-nobody-is-sending.html",
      "markdown": "https://sgit.ai/articles/token-bill-nobody-is-sending.md",
      "card": "https://sgit.ai/articles/cards/token-bill-nobody-is-sending.webp",
      "teaser": "AI answer engines pay to read the web as HTML; a publisher who serves markdown, dates, hashes and a typed graph saves them tokens and should get a share.",
      "topics": [
        "news-and-evidence",
        "graphs-and-knowledge"
      ],
      "tags": [
        "ai",
        "publishing",
        "tokens",
        "llms-txt",
        "markdown",
        "provenance",
        "fractal-semantic-graphs",
        "economics",
        "news",
        "article"
      ],
      "links_out": [
        "future-of-news-story-vault-not-paywall",
        "introducing-fractal-semantic-graphs"
      ],
      "links_in": [
        "memory-is-not-a-spectator-sport",
        "custom-uis-are-not-the-exception",
        "how-news-got-here"
      ],
      "graph": {
        "slug": "token-bill-nobody-is-sending",
        "teaser": "AI answer engines pay to read the web as HTML; a publisher who serves markdown, dates, hashes and a typed graph saves them tokens and should get a share.",
        "topics": [
          "news-and-evidence",
          "graphs-and-knowledge"
        ],
        "core_idea": "The fetches that answer engines make are a token cost to the fetcher as well as a loss to the publisher, and a publisher who serves structure is saving the provider money it already spends, so a share of that saving is owed.",
        "nodes": [
          {
            "id": "baekdal-week",
            "label": "Sixteen thousand fetches, ten clicks",
            "kind": "example",
            "summary": "A week of Cloudflare AI answer retrievals for baekdal.com came to 16,000 requests and the referrals they sent back came to 10."
          },
          {
            "id": "commons-reading",
            "label": "The commons reading",
            "kind": "concept",
            "summary": "The answer engines graze on a shared field and give nothing back, so the field will be fenced and the grazing priced."
          },
          {
            "id": "second-reading",
            "label": "The second reading",
            "kind": "claim",
            "summary": "Those 16,000 fetches are also a cost to the fetcher, because every one is a page of HTML parsed, extracted and turned into tokens."
          },
          {
            "id": "html-vs-markdown",
            "label": "HTML against markdown",
            "kind": "claim",
            "summary": "On this site's 183 pages the markdown twin is 62% fewer tokens than the HTML, and Cloudflare's own example is 81%."
          },
          {
            "id": "re-fetch-waste",
            "label": "The re-fetch waste",
            "kind": "claim",
            "summary": "More than half of legitimate bot crawl traffic re-fetches pages that have not changed, and more than 90% of pages crawlers process are unique, which defeats the cache layer."
          },
          {
            "id": "the-arithmetic",
            "label": "The arithmetic",
            "kind": "example",
            "summary": "Sixteen thousand fetches a week of HTML is about 113 million tokens against 43 million as markdown, tens of dollars a week for one site and a line on a very large invoice across the web."
          },
          {
            "id": "markdown-twin",
            "label": "A markdown twin and a map",
            "kind": "method",
            "summary": "Every page served as clean markdown at a predictable address, with an llms.txt at the root, generated from the same source so the two cannot drift."
          },
          {
            "id": "date-and-hash",
            "label": "A date and a hash",
            "kind": "method",
            "summary": "Tell the fetcher when the page last changed and give it a hash, so a fetch of an unchanged page can be skipped altogether."
          },
          {
            "id": "frozen-sources",
            "label": "Frozen, hashed sources",
            "kind": "method",
            "summary": "Claims that carry the byte range and SHA-256 of the page they came from do the verification round trip once for everyone."
          },
          {
            "id": "typed-graph",
            "label": "A typed graph",
            "kind": "method",
            "summary": "A fractal semantic graph lets an agent load exactly as much as the question needs, so the tokens saved are the page minus the answer."
          },
          {
            "id": "payment-rails-price-content",
            "label": "Every rail prices the content",
            "kind": "claim",
            "summary": "Pay per crawl, RSL, the IAB's protocols, Microsoft's marketplace, Perplexity's pool and Cloudflare's pay per use all price the fetch or the citation, and none pays a site for being cheap to read."
          },
          {
            "id": "the-exchange",
            "label": "The exchange",
            "kind": "claim",
            "summary": "A provider that spends fewer tokens reading a site that serves structure has saved money it was already spending, and should hand part of the saving back as a rebate for the format."
          },
          {
            "id": "tokens-as-currency",
            "label": "Tokens as currency",
            "kind": "concept",
            "summary": "A publisher could be paid in the provider's own credits, which are the budget that builds the site, and News Corp already took part of its deal in credits."
          },
          {
            "id": "broker",
            "label": "The broker",
            "kind": "concept",
            "summary": "A single site cannot send the invoice, so the broker will be whoever sits between the bots and the sites, which today means Cloudflare, TollBit and the marketplaces."
          },
          {
            "id": "audience-not-cheque",
            "label": "Baekdal wants an audience",
            "kind": "question",
            "summary": "Tokens are not an audience, though structure is what makes a citation land on the right paragraph and tokens are the budget that builds the site the reader arrives at."
          },
          {
            "id": "what-would-settle-it",
            "label": "What would settle it",
            "kind": "question",
            "summary": "Three numbers per domain for a week of real retrieval, the tokens spent on HTML, the tokens the twin would have cost and the fetches a change signal would have skipped, live in the providers' logs."
          }
        ],
        "edges": [
          {
            "from": "baekdal-week",
            "to": "commons-reading",
            "rel": "example-of"
          },
          {
            "from": "second-reading",
            "to": "commons-reading",
            "rel": "contrasts"
          },
          {
            "from": "second-reading",
            "to": "html-vs-markdown",
            "rel": "depends-on"
          },
          {
            "from": "second-reading",
            "to": "re-fetch-waste",
            "rel": "depends-on"
          },
          {
            "from": "the-arithmetic",
            "to": "html-vs-markdown",
            "rel": "depends-on"
          },
          {
            "from": "the-arithmetic",
            "to": "baekdal-week",
            "rel": "depends-on"
          },
          {
            "from": "html-vs-markdown",
            "to": "markdown-twin",
            "rel": "depends-on"
          },
          {
            "from": "date-and-hash",
            "to": "re-fetch-waste",
            "rel": "answers"
          },
          {
            "from": "date-and-hash",
            "to": "markdown-twin",
            "rel": "extends"
          },
          {
            "from": "frozen-sources",
            "to": "date-and-hash",
            "rel": "extends"
          },
          {
            "from": "typed-graph",
            "to": "frozen-sources",
            "rel": "extends"
          },
          {
            "from": "payment-rails-price-content",
            "to": "the-exchange",
            "rel": "contrasts"
          },
          {
            "from": "payment-rails-price-content",
            "to": "commons-reading",
            "rel": "example-of"
          },
          {
            "from": "the-exchange",
            "to": "second-reading",
            "rel": "depends-on"
          },
          {
            "from": "the-exchange",
            "to": "the-arithmetic",
            "rel": "depends-on"
          },
          {
            "from": "tokens-as-currency",
            "to": "the-exchange",
            "rel": "extends"
          },
          {
            "from": "the-exchange",
            "to": "broker",
            "rel": "depends-on"
          },
          {
            "from": "audience-not-cheque",
            "to": "the-exchange",
            "rel": "contrasts"
          },
          {
            "from": "the-exchange",
            "to": "what-would-settle-it",
            "rel": "leads-to"
          },
          {
            "from": "what-would-settle-it",
            "to": "second-reading",
            "rel": "answers"
          }
        ],
        "links": {
          "articles": [
            "future-of-news-story-vault-not-paywall",
            "introducing-fractal-semantic-graphs"
          ],
          "pages": [
            "/admin/versions.html",
            "/demos/vaults/evidence-dispatch/index.html",
            "/llms.txt",
            "/demos/vaults/index.html"
          ],
          "sites": [
            "https://blog.cloudflare.com/crawlers-click-ai-bots-training/",
            "https://blog.cloudflare.com/making-ai-search-smarter/",
            "https://developers.cloudflare.com/changelog/post/2026-02-12-markdown-for-agents/",
            "https://www.searchenginejournal.com/cloudflares-new-markdown-for-ai-bots-what-you-need-to-know/567339/",
            "https://ppc.land/cloudflare-and-eth-zurich-say-ai-bots-are-breaking-the-webs-cache-layer/",
            "https://llmstxt.org/",
            "https://platform.claude.com/docs/en/about-claude/pricing",
            "https://variety.com/2024/digital/news/news-corp-openai-licensing-deal-1236013734/"
          ]
        },
        "quotes": [
          {
            "text": "Every step exists today. What does not exist is anyone paying for them.",
            "why": "The gap the proposal is written to fill: the publisher's half of the exchange is already built."
          },
          {
            "text": "It is not new money. It is money being spent today, by the answer engines, on reading the web the hard way.",
            "why": "Why a rebate on waste is the easiest money in the negotiation to agree to."
          }
        ]
      }
    },
    {
      "slug": "supply-chain-of-vaults",
      "title": "A supply chain of vaults: how GenAI, open data and small custom tools could bring the price of food down",
      "date": "2026-09-27",
      "updated": "2026-09-28",
      "url": "https://sgit.ai/articles/supply-chain-of-vaults.html",
      "markdown": "https://sgit.ai/articles/supply-chain-of-vaults.md",
      "card": "https://sgit.ai/articles/cards/supply-chain-of-vaults.webp",
      "teaser": "The food chain is a data problem: one encrypted vault per party, joined by append lanes and a typed graph, could cut the waste that keeps prices high.",
      "topics": [
        "vaults-and-method",
        "startups-and-strategy"
      ],
      "tags": [
        "supply-chain",
        "food",
        "genai",
        "vaults",
        "fractal-semantic-graphs",
        "open-source",
        "creative-commons",
        "deflation",
        "article"
      ],
      "links_out": [
        "introducing-fractal-semantic-graphs",
        "saas-apocalypse-decided-by-inertia-not-by-ai"
      ],
      "links_in": [
        "send-an-agent-not-a-spreadsheet"
      ],
      "graph": {
        "slug": "supply-chain-of-vaults",
        "teaser": "The food chain is a data problem: one encrypted vault per party, joined by append lanes and a typed graph, could cut the waste that keeps prices high.",
        "topics": [
          "vaults-and-method",
          "startups-and-strategy"
        ],
        "core_idea": "The food chain is logistics, logistics is a data problem, and a supply chain of encrypted vaults with small custom tools built once by GenAI could bring the price of food down, if somebody runs the experiment.",
        "nodes": [
          {
            "id": "food-pound",
            "label": "The food pound",
            "kind": "example",
            "summary": "For a kilo of supermarket apples selling at £2.20, the grower's costs were 76p and their profit 3p."
          },
          {
            "id": "spreadsheet-chain",
            "label": "A chain of spreadsheets",
            "kind": "claim",
            "summary": "Each hop keeps its own record of the same consignment, mostly in spreadsheets, and an order, a delivery note, a grade, a price and a payment date are typed in five times."
          },
          {
            "id": "food-loss",
            "label": "Food lost before retail",
            "kind": "example",
            "summary": "The FAO puts the share of food lost between harvest and retail at 13.3% in 2023, and a good deal of it is information."
          },
          {
            "id": "chokepoint",
            "label": "The chokepoint",
            "kind": "concept",
            "summary": "Once a buyer holds a large share of a farm's output it names the price, which is the mechanism Giblin and Doctorow call a chokepoint."
          },
          {
            "id": "regulation-limit",
            "label": "The limit of regulation",
            "kind": "claim",
            "summary": "Codes of practice regulate the conduct of the party with the systems and leave the party without them exactly where it was."
          },
          {
            "id": "logistics-is-data",
            "label": "All of it is logistics",
            "kind": "claim",
            "summary": "Everything between the field and the shelf is a workflow, and logistics is a data problem before it is a transport problem."
          },
          {
            "id": "supply-chain-of-vaults",
            "label": "A supply chain of vaults",
            "kind": "method",
            "summary": "Every party in the chain holds its own encrypted, versioned vault, readable by nobody who does not hold a key, including the host."
          },
          {
            "id": "append-lanes",
            "label": "Append lanes",
            "kind": "artefact",
            "summary": "Write-only channels through which one party can put a file into another's vault without being able to read anything there."
          },
          {
            "id": "typed-graph",
            "label": "One graph across the vaults",
            "kind": "concept",
            "summary": "Each vault keeps its own vocabulary and typed edges join them, which is what makes waste visible."
          },
          {
            "id": "genai-not-to-use-genai",
            "label": "Use GenAI not to use GenAI",
            "kind": "method",
            "summary": "The model is used once, to turn a grower's brief into a working tool, and production runs on plain files with no model in the line."
          },
          {
            "id": "villagers",
            "label": "Villagers and town planners",
            "kind": "concept",
            "summary": "A small company takes the finished tool and runs it for a hundred other growers, paid because it keeps working rather than by the seat."
          },
          {
            "id": "price-hypothesis",
            "label": "The price hypothesis",
            "kind": "question",
            "summary": "The hypothesis is that a supply chain run this way brings the price of food and goods down, and the evidence is partial."
          },
          {
            "id": "deflation-dogma",
            "label": "The deflation dogma",
            "kind": "claim",
            "summary": "The BIS found the link between falling goods prices and lower growth to be weak, and a cheaper loaf because the chain wasted less is not a Japanese lost decade."
          },
          {
            "id": "cost-of-not-sharing",
            "label": "The cost of not sharing",
            "kind": "claim",
            "summary": "About 80% of industrial data is never used, and every grower who learns what a buyer will reject learns it alone."
          },
          {
            "id": "open-weight-models",
            "label": "Open-weight models",
            "kind": "concept",
            "summary": "Companies that build on open weights can run a near-frontier model inside their own environment and innovate on top of it."
          },
          {
            "id": "the-experiment",
            "label": "The experiment",
            "kind": "question",
            "summary": "Nobody has put a grower, a packer and a buyer on vaults and run a season through them, and this article is the brief for that experiment."
          }
        ],
        "edges": [
          {
            "from": "food-pound",
            "to": "chokepoint",
            "rel": "example-of"
          },
          {
            "from": "spreadsheet-chain",
            "to": "food-loss",
            "rel": "leads-to"
          },
          {
            "from": "chokepoint",
            "to": "spreadsheet-chain",
            "rel": "depends-on"
          },
          {
            "from": "regulation-limit",
            "to": "chokepoint",
            "rel": "depends-on"
          },
          {
            "from": "regulation-limit",
            "to": "supply-chain-of-vaults",
            "rel": "compared-with"
          },
          {
            "from": "logistics-is-data",
            "to": "chokepoint",
            "rel": "depends-on"
          },
          {
            "from": "supply-chain-of-vaults",
            "to": "logistics-is-data",
            "rel": "depends-on"
          },
          {
            "from": "supply-chain-of-vaults",
            "to": "append-lanes",
            "rel": "depends-on"
          },
          {
            "from": "supply-chain-of-vaults",
            "to": "typed-graph",
            "rel": "depends-on"
          },
          {
            "from": "typed-graph",
            "to": "food-loss",
            "rel": "answers"
          },
          {
            "from": "genai-not-to-use-genai",
            "to": "supply-chain-of-vaults",
            "rel": "extends"
          },
          {
            "from": "villagers",
            "to": "genai-not-to-use-genai",
            "rel": "depends-on"
          },
          {
            "from": "price-hypothesis",
            "to": "supply-chain-of-vaults",
            "rel": "depends-on"
          },
          {
            "from": "price-hypothesis",
            "to": "deflation-dogma",
            "rel": "contrasts"
          },
          {
            "from": "open-weight-models",
            "to": "cost-of-not-sharing",
            "rel": "extends"
          },
          {
            "from": "open-weight-models",
            "to": "genai-not-to-use-genai",
            "rel": "extends"
          },
          {
            "from": "cost-of-not-sharing",
            "to": "supply-chain-of-vaults",
            "rel": "extends"
          },
          {
            "from": "the-experiment",
            "to": "price-hypothesis",
            "rel": "answers"
          },
          {
            "from": "supply-chain-of-vaults",
            "to": "the-experiment",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "introducing-fractal-semantic-graphs",
            "saas-apocalypse-decided-by-inertia-not-by-ai"
          ],
          "pages": [
            "/api/append-lanes.html",
            "/docs/append-lane-messaging.html",
            "/demos/vaults/company-xray/index.html",
            "/demos/vaults/evidence-dispatch/index.html",
            "/admin/versions.html"
          ],
          "sites": [
            "https://www.bbc.co.uk/programmes/m0031vn4",
            "https://www.sustainweb.org/reports/dec22-unpicking-food-prices/",
            "https://www.fao.org/sustainable-development-goals-data-portal/data/indicators/1231-global-food-losses/en/",
            "https://en.wikipedia.org/wiki/Chokepoint_Capitalism",
            "https://www.supplychaindive.com/news/supply-chain-innovation-survey-BluJay-AdelanteSCM/530263/",
            "https://www.mckinsey.com/industries/metals-and-mining/our-insights/succeeding-in-the-ai-supply-chain-revolution",
            "https://www.bis.org/publ/qtrpdf/r_qt1503e.pdf",
            "https://www.uscc.gov/sites/default/files/2026-03/Two_Loops--How_Chinas_Open_AI_Strategy_Reinforces_Its_Industrial_Dominance.pdf"
          ]
        },
        "quotes": [
          {
            "text": "Everything between the field and the shelf is a workflow, and every workflow is a set of records moving between parties.",
            "why": "The step that turns a food price problem into a data problem the vaults can address."
          },
          {
            "text": "What we never calculate is the economic cost of not sharing.",
            "why": "The second memo's argument, that openness is the other half of the case."
          }
        ]
      }
    },
    {
      "slug": "connector-twin-before-you-deploy-an-agent",
      "title": "Before you give an agent a connector, give the connector a twin",
      "date": "2026-09-24",
      "updated": "",
      "url": "https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.html",
      "markdown": "https://sgit.ai/articles/connector-twin-before-you-deploy-an-agent.md",
      "card": "https://sgit.ai/articles/cards/connector-twin-before-you-deploy-an-agent.webp",
      "teaser": "An agent with a Gmail or Calendar connector can do things the platform cannot undo; a journal of every call, replayed, shows what it did and what can go back.",
      "topics": [
        "agents-and-policy",
        "vaults-and-method"
      ],
      "tags": [
        "agents",
        "connectors",
        "digital-twins",
        "provenance",
        "risk",
        "riskmandate",
        "article"
      ],
      "links_out": [],
      "links_in": [
        "if-somebody-built-a-company-on-code-review",
        "send-an-agent-not-a-spreadsheet",
        "footprint-and-blast-radius",
        "replicating-the-agentic-inbox",
        "custom-uis-are-not-the-exception",
        "ultimate-insider-three-collisions",
        "six-agents-one-inbox"
      ],
      "graph": {
        "slug": "connector-twin-before-you-deploy-an-agent",
        "teaser": "An agent with a Gmail or Calendar connector can do things the platform cannot undo; a journal of every call, replayed, shows what it did and what can go back.",
        "topics": [
          "agents-and-policy",
          "vaults-and-method"
        ],
        "core_idea": "If you cannot say what your agent did, what it saw when it did it, and which of its actions you can undo, you are not ready to give it a connector, and a twin of the connector, a journal plus a replay, answers all three.",
        "nodes": [
          {
            "id": "connector-is-a-grant-of-action",
            "label": "A connector is a grant of action",
            "kind": "claim",
            "summary": "An agent with Gmail and Calendar connectors can send, archive, trash, permanently delete, move events, decline invitations and cancel meetings on somebody's behalf, at machine speed."
          },
          {
            "id": "no-way-back",
            "label": "The platform keeps no way back for some actions",
            "kind": "claim",
            "summary": "The Gmail API documents its delete as permanent, Undo Send is a feature of the interface not the API, and a moved calendar event has no version history a user can open."
          },
          {
            "id": "what-the-platform-keeps",
            "label": "What the platform keeps",
            "kind": "concept",
            "summary": "Trash windows, an administrator's bulk restore and audit logs record that things happened, but none records what the agent saw when it decided to act, or why."
          },
          {
            "id": "connector-twin",
            "label": "Connector twin",
            "kind": "concept",
            "summary": "A journal of every request and response the agent makes, and a replay of that journal into the views the agent saw."
          },
          {
            "id": "twin-not-backup",
            "label": "Twin, not backup, log or replay",
            "kind": "concept",
            "summary": "A backup copies the mailbox, a log is too small, replay is the verb; a twin is an interface to reality, valued for its connection to the real thing."
          },
          {
            "id": "capture",
            "label": "Capture",
            "kind": "method",
            "summary": "For every connector call, copy the tool call the agent made, the request sent to the platform and the response received, and never the Authorization header or any token."
          },
          {
            "id": "append-lane",
            "label": "Append lane",
            "kind": "artefact",
            "summary": "A write-only channel gated by a token the writer holds, whose write response is exactly {\"ok\": true}, so the capture point learns nothing about what else is in the lane."
          },
          {
            "id": "hash-chain",
            "label": "Chain",
            "kind": "method",
            "summary": "Each entry carries the hash of the one before it, so a missing, edited or reordered entry shows to anyone holding the read key."
          },
          {
            "id": "when-to-process",
            "label": "When the journal gets processed",
            "kind": "question",
            "summary": "On a timer, on a threshold of pending entries, on demand or at the end of each session; the right default will come from a few real users rather than from more design."
          },
          {
            "id": "replay-and-revert",
            "label": "Replay and revert",
            "kind": "method",
            "summary": "A vault app rebuilds the inbox and the calendar as the agent saw them at any step, shows before and after for every change, and writes a revert plan a person approves."
          },
          {
            "id": "not-a-copy-of-the-mailbox",
            "label": "The twin is not a copy of the mailbox",
            "kind": "claim",
            "summary": "It holds only what passed through the connector, so it scales with the agent's activity rather than with the size of the mailbox."
          },
          {
            "id": "one-session-replayed",
            "label": "One session, replayed",
            "kind": "example",
            "summary": "An invented scheduling assistant makes seventeen calls in under three minutes and writes a true summary that hides a cancellation sent to a supplier and a permanently deleted payment reminder."
          },
          {
            "id": "undo-is-a-list",
            "label": "Undo is a list, not a promise",
            "kind": "claim",
            "summary": "Every change gets a grade, reversible, partly reversible or not reversible, and the value of the list is that the red rows are named."
          },
          {
            "id": "capture-modes",
            "label": "Broker, gateway or requirement of the agent",
            "kind": "concept",
            "summary": "Three places to capture and three grades of evidence; the mode does not change what is captured, it changes what the evidence is allowed to claim."
          },
          {
            "id": "behaviour-policy",
            "label": "What it does to the agent's behaviour policy",
            "kind": "concept",
            "summary": "With the list of irreversible actions in hand the mandate can say what the agent may do freely, must ask before, and may never do without approval."
          }
        ],
        "edges": [
          {
            "from": "connector-is-a-grant-of-action",
            "to": "no-way-back",
            "rel": "leads-to"
          },
          {
            "from": "no-way-back",
            "to": "what-the-platform-keeps",
            "rel": "extends"
          },
          {
            "from": "what-the-platform-keeps",
            "to": "connector-twin",
            "rel": "leads-to"
          },
          {
            "from": "twin-not-backup",
            "to": "connector-twin",
            "rel": "extends"
          },
          {
            "from": "connector-twin",
            "to": "capture",
            "rel": "depends-on"
          },
          {
            "from": "capture",
            "to": "append-lane",
            "rel": "leads-to"
          },
          {
            "from": "append-lane",
            "to": "hash-chain",
            "rel": "leads-to"
          },
          {
            "from": "hash-chain",
            "to": "when-to-process",
            "rel": "leads-to"
          },
          {
            "from": "when-to-process",
            "to": "replay-and-revert",
            "rel": "leads-to"
          },
          {
            "from": "connector-twin",
            "to": "replay-and-revert",
            "rel": "produces"
          },
          {
            "from": "capture",
            "to": "not-a-copy-of-the-mailbox",
            "rel": "produces"
          },
          {
            "from": "replay-and-revert",
            "to": "undo-is-a-list",
            "rel": "produces"
          },
          {
            "from": "no-way-back",
            "to": "undo-is-a-list",
            "rel": "leads-to"
          },
          {
            "from": "one-session-replayed",
            "to": "replay-and-revert",
            "rel": "example-of"
          },
          {
            "from": "one-session-replayed",
            "to": "undo-is-a-list",
            "rel": "example-of"
          },
          {
            "from": "capture-modes",
            "to": "capture",
            "rel": "extends"
          },
          {
            "from": "undo-is-a-list",
            "to": "behaviour-policy",
            "rel": "leads-to"
          },
          {
            "from": "capture-modes",
            "to": "behaviour-policy",
            "rel": "leads-to"
          },
          {
            "from": "what-the-platform-keeps",
            "to": "replay-and-revert",
            "rel": "contrasts"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/demos/vaults/connector-twin/index.html",
            "/api/append-lanes.html",
            "/demos/vaults/licence-to-operate/index.html",
            "/partnerships/vault-key-management.html",
            "/startups/business-plans.html"
          ],
          "sites": [
            "https://developers.google.com/workspace/gmail/api/reference/rest/v1/users.messages/delete",
            "https://support.google.com/mail/answer/7401",
            "https://support.google.com/mail/answer/2819488",
            "https://support.google.com/calendar/answer/37113",
            "https://knowledge.workspace.google.com/admin/reports/calendar-log-events",
            "https://twins.sgit.ai/",
            "https://twins.sgit.ai/broker/index.html",
            "https://riskmandate.ai/"
          ]
        },
        "quotes": [
          {
            "text": "If you cannot say what your agent did, what it saw when it did it, and which of its actions you can undo, you are not ready to give it a connector.",
            "why": "The claim the whole article is built to defend, stated so it can be wrong."
          },
          {
            "text": "The value of the list is not that most of it is green. It is that the red rows are named.",
            "why": "Why the twin changes governance: irreversible actions become a named list the mandate can be written against."
          }
        ]
      }
    },
    {
      "slug": "every-risk-is-already-accepted",
      "title": "Every risk is already accepted. The only question is by whom, and for how long.",
      "date": "2026-09-24",
      "updated": "",
      "url": "https://sgit.ai/articles/every-risk-is-already-accepted.html",
      "markdown": "https://sgit.ai/articles/every-risk-is-already-accepted.md",
      "card": "https://sgit.ai/articles/cards/every-risk-is-already-accepted.webp",
      "teaser": "A risk exists the moment the exposure does, so somebody is already carrying it; the only questions worth asking are who has accepted it and until when.",
      "topics": [
        "agents-and-policy",
        "graphs-and-knowledge"
      ],
      "tags": [
        "risk",
        "risk-acceptance",
        "governance",
        "grc",
        "fractal-semantic-graphs",
        "eu-ai-act",
        "article"
      ],
      "links_out": [
        "introducing-fractal-semantic-graphs"
      ],
      "links_in": [
        "send-an-agent-not-a-spreadsheet",
        "the-investigation-github-owes-its-customers",
        "code-review-as-a-fractal-semantic-graph",
        "footprint-and-blast-radius",
        "ultimate-insider-three-collisions"
      ],
      "graph": {
        "slug": "every-risk-is-already-accepted",
        "teaser": "A risk exists the moment the exposure does, so somebody is already carrying it; the only questions worth asking are who has accepted it and until when.",
        "topics": [
          "agents-and-policy",
          "graphs-and-knowledge"
        ],
        "core_idea": "Every risk an organisation has is already accepted by somebody, so the only questions are who has accepted it and until when; a register that cannot answer them, on facts, is disconnected from reality.",
        "nodes": [
          {
            "id": "already-accepted",
            "label": "Every risk is already accepted",
            "kind": "claim",
            "summary": "A risk exists the moment the exposure does, so the organisation is carrying it from the start, signed for or not."
          },
          {
            "id": "no-deny-button",
            "label": "There is no deny button",
            "kind": "claim",
            "summary": "You cannot vote a fact out of existence, and a register that lets you reject a risk lets you pretend."
          },
          {
            "id": "three-doors",
            "label": "Three doors",
            "kind": "method",
            "summary": "Accept it personally for a stated interval, fund the work that reduces it, or fix it so the facts that make it true stop holding; silence is not a fourth door."
          },
          {
            "id": "unaccepted-is-critical",
            "label": "Unaccepted is critical",
            "kind": "claim",
            "summary": "A risk nobody has accepted rests on whoever is nearest and rolls upward to their boss, and then to theirs, until somebody signs."
          },
          {
            "id": "interval-ladder",
            "label": "The interval is the decision",
            "kind": "method",
            "summary": "One hour means more data, four hours is a priority-one incident, one month is assemble and fund, and six months is do nothing and review it then, with a name on it."
          },
          {
            "id": "accepted-not-acceptable",
            "label": "Accepted is not acceptable",
            "kind": "concept",
            "summary": "Accepted is an act by a named person on a date for an interval; acceptable is a threshold, and the dangerous state is a risk over the line that nobody has signed for."
          },
          {
            "id": "eu-ai-act-article-9",
            "label": "EU AI Act, Article 9(5)",
            "kind": "example",
            "summary": "Providers of high-risk AI systems must have residual risk judged to be acceptable, and the Act never defines the word."
          },
          {
            "id": "every-risk-has-a-boss",
            "label": "Every risk has a boss",
            "kind": "claim",
            "summary": "Every risk has a holder, every holder has a boss, and every path ends at the board, computed rather than reported, and nobody can accept on anybody else's behalf."
          },
          {
            "id": "risk-graph-explorer",
            "label": "Risk Graph Explorer",
            "kind": "artefact",
            "summary": "A vault that computes what each role is assigned and what arrives through it, so no risk is orphaned and nobody at the top is surprised."
          },
          {
            "id": "fractal-risk-register",
            "label": "From the board to the bytes",
            "kind": "concept",
            "summary": "A board line such as loss of customer funds opens into business, operational and technical risks, each with its own holder and vocabulary, down to the configuration file."
          },
          {
            "id": "established-ended-by-facts",
            "label": "Established by facts, ended by facts",
            "kind": "method",
            "summary": "Every risk names the facts that make it true and the facts that would end it, so it ships with its own falsification condition."
          },
          {
            "id": "one-risk-six-weeks",
            "label": "One risk, six weeks",
            "kind": "example",
            "summary": "An agent's irreversible production writes are accepted for two weeks, expire with the action undone, escalate, are funded, materialise as an incident and cease on day 42 on evidence."
          },
          {
            "id": "vault-per-risk",
            "label": "A vault per risk",
            "kind": "artefact",
            "summary": "Each material risk deserves a vault as its evidence pack, keeping every fact, acceptance, escalation and incident, readable by each audience with its own key."
          },
          {
            "id": "executive-resistance",
            "label": "Why people resist",
            "kind": "concept",
            "summary": "Executives resist giving risk owners an acceptance workflow because they understand it would change their job, which makes this a change programme rather than a feature."
          },
          {
            "id": "fits-alongside-grc",
            "label": "It fits alongside every GRC platform",
            "kind": "claim",
            "summary": "The model reads the register from the platform and writes back what the platform lacks: who accepted, until when, what happens at expiry, and a link to the evidence."
          }
        ],
        "edges": [
          {
            "from": "already-accepted",
            "to": "no-deny-button",
            "rel": "depends-on"
          },
          {
            "from": "no-deny-button",
            "to": "three-doors",
            "rel": "leads-to"
          },
          {
            "from": "three-doors",
            "to": "unaccepted-is-critical",
            "rel": "leads-to"
          },
          {
            "from": "three-doors",
            "to": "interval-ladder",
            "rel": "depends-on"
          },
          {
            "from": "accepted-not-acceptable",
            "to": "already-accepted",
            "rel": "extends"
          },
          {
            "from": "eu-ai-act-article-9",
            "to": "accepted-not-acceptable",
            "rel": "example-of"
          },
          {
            "from": "unaccepted-is-critical",
            "to": "every-risk-has-a-boss",
            "rel": "depends-on"
          },
          {
            "from": "risk-graph-explorer",
            "to": "every-risk-has-a-boss",
            "rel": "example-of"
          },
          {
            "from": "fractal-risk-register",
            "to": "every-risk-has-a-boss",
            "rel": "extends"
          },
          {
            "from": "fractal-risk-register",
            "to": "established-ended-by-facts",
            "rel": "depends-on"
          },
          {
            "from": "risk-graph-explorer",
            "to": "established-ended-by-facts",
            "rel": "example-of"
          },
          {
            "from": "one-risk-six-weeks",
            "to": "three-doors",
            "rel": "example-of"
          },
          {
            "from": "one-risk-six-weeks",
            "to": "interval-ladder",
            "rel": "example-of"
          },
          {
            "from": "one-risk-six-weeks",
            "to": "established-ended-by-facts",
            "rel": "example-of"
          },
          {
            "from": "vault-per-risk",
            "to": "established-ended-by-facts",
            "rel": "depends-on"
          },
          {
            "from": "vault-per-risk",
            "to": "fractal-risk-register",
            "rel": "extends"
          },
          {
            "from": "executive-resistance",
            "to": "no-deny-button",
            "rel": "contrasts"
          },
          {
            "from": "one-risk-six-weeks",
            "to": "fits-alongside-grc",
            "rel": "leads-to"
          },
          {
            "from": "fits-alongside-grc",
            "to": "executive-resistance",
            "rel": "answers"
          }
        ],
        "links": {
          "articles": [
            "introducing-fractal-semantic-graphs"
          ],
          "pages": [
            "/demos/vaults/risk-acceptance/index.html",
            "/demos/vaults/risk-graph-explorer/views/index.html",
            "/demos/vaults/risk-graph-explorer/index.html",
            "/startups/business-plans.html"
          ],
          "sites": [
            "https://risks.sgit.ai/",
            "https://risks.sgit.ai/acceptable/",
            "https://riskmandate.ai/",
            "https://riskmandate.ai/acceptable.html",
            "https://graphs.sgit.ai/v1/docs/fractal-risk-registers.html",
            "https://twins.sgit.ai/actors/index.html",
            "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
            "https://artificialintelligenceact.eu/article/9/"
          ]
        },
        "quotes": [
          {
            "text": "Every acceptance is for an interval, and the interval is not a detail of the decision.",
            "why": "The interval ladder is the model's working part: each length names a different response."
          },
          {
            "text": "Nothing in the row is wrong. It just never learned that the risk was accepted twice, expired once, escalated, funded, materialised as an incident, and ended.",
            "why": "The air gap between a register and reality, shown on one row at one moment."
          }
        ]
      }
    },
    {
      "slug": "future-of-news-story-vault-not-paywall",
      "title": "The future of news is the story vault, not the paywall",
      "date": "2026-09-22",
      "updated": "",
      "url": "https://sgit.ai/articles/future-of-news-story-vault-not-paywall.html",
      "markdown": "https://sgit.ai/articles/future-of-news-story-vault-not-paywall.md",
      "card": "https://sgit.ai/articles/cards/future-of-news-story-vault-not-paywall.webp",
      "teaser": "A story is a graph of claims and evidence and the article is one projection of it; keep the graph in a vault and sell what the article was made from.",
      "topics": [
        "news-and-evidence",
        "graphs-and-knowledge"
      ],
      "tags": [
        "news",
        "publishing",
        "provenance",
        "micropayments",
        "semantic-graphs",
        "article"
      ],
      "links_out": [
        "the-question-is-whether-they-miss-it"
      ],
      "links_in": [
        "custom-uis-are-not-the-exception",
        "how-news-got-here",
        "token-bill-nobody-is-sending"
      ],
      "graph": {
        "slug": "future-of-news-story-vault-not-paywall",
        "teaser": "A story is a graph of claims and evidence and the article is one projection of it; keep the graph in a vault and sell what the article was made from.",
        "topics": [
          "news-and-evidence",
          "graphs-and-knowledge"
        ],
        "core_idea": "The story is a graph and the article is a projection, so a newsroom that keeps the graph in a vault can sell five things from it, in pence and on demand, that reward investigative reporting rather than the click or the renewal.",
        "nodes": [
          {
            "id": "both-models-bad-for-the-reader",
            "label": "Both models are bad for the reader",
            "kind": "claim",
            "summary": "Advertising sells the reader to somebody else, so the content is bait; a subscription charges rent on something most subscribers have stopped using, so the content is the excuse."
          },
          {
            "id": "two-clocks",
            "label": "The two clocks",
            "kind": "example",
            "summary": "Organic Google search traffic to publishers fell 33% in the year to November 2025, and the UK's subscription rules were brought forward to 1 January 2027."
          },
          {
            "id": "objective-loop",
            "label": "The objective is a loop, not a price",
            "kind": "concept",
            "summary": "A commercial model that rewards investigative journalism, so evidenced reporting drives usage, usage drives revenue that depends on neither search nor renewals, and revenue funds more reporting."
          },
          {
            "id": "case-against-micropayments",
            "label": "Why paying per item failed before",
            "kind": "concept",
            "summary": "A $100 subscription lost is 500 micropayments to replace, unbundling breaks the cross-subsidy, and the reader will not stop to decide whether an article is worth twenty pence."
          },
          {
            "id": "three-buyers",
            "label": "Who is standing at the till",
            "kind": "concept",
            "summary": "The reader who wants one thing, the firm that has to forward it with its provenance, and the agent paying per query with a wallet and no anxiety; none of them wants the article."
          },
          {
            "id": "story-is-a-graph",
            "label": "The story is a graph, the article is a projection",
            "kind": "claim",
            "summary": "A story being reported is claims, evidence, sources, raw materials, analysis and drafts, and the article is one walk through that graph for one audience at one moment."
          },
          {
            "id": "fractal-semantic-graph",
            "label": "The graph is fractal, and meaning comes from connectivity",
            "kind": "concept",
            "summary": "A node means nothing on its own, every edge is a verb with a named inverse, and zooming into any node enters a world with its own vocabulary joined by a single named edge."
          },
          {
            "id": "provenance-ladder",
            "label": "Trust through provenance, provenance via evidence",
            "kind": "concept",
            "summary": "Evidence is frozen bytes with a SHA-256 hash, provenance is the path from a claim down named edges to that evidence, and trust is what a market extends to a source whose provenance has held before."
          },
          {
            "id": "story-vault",
            "label": "What a story vault holds",
            "kind": "artefact",
            "summary": "The published text, the evidence it cites, the story graph it belongs to, the source list, the translations and every prompt and decision that produced it, as one addressable unit."
          },
          {
            "id": "anonymous-source-at-the-node",
            "label": "Anonymous sources are marked at the node",
            "kind": "method",
            "summary": "A source the journalist cannot name is a node flagged as anonymous, so every projection built from the graph redacts it automatically."
          },
          {
            "id": "five-projections",
            "label": "Five things to sell from one graph",
            "kind": "concept",
            "summary": "The public article free as the door, the licensed article in pence, the evidence vault, the customised projection and the verification API."
          },
          {
            "id": "evidence-vault",
            "label": "The evidence vault",
            "kind": "concept",
            "summary": "The graph itself, licensed by read key to analysts, lawyers, regulators and other newsrooms, which is the payment that rewards the reporting rather than the click."
          },
          {
            "id": "verification-api",
            "label": "The verification API",
            "kind": "concept",
            "summary": "A company or agent asks whether a claim was reported, is still current and is soundly used, and gets an on-record answer with the chain attached and a warranty."
          },
          {
            "id": "fact-creator-split",
            "label": "Who gets paid",
            "kind": "concept",
            "summary": "60% to the original researcher, 25% to the data organisation, 10% to the journalist and 5% to the outlet, and you cannot pay the fact creator unless the graph names them."
          },
          {
            "id": "payment-rails",
            "label": "The rails",
            "kind": "concept",
            "summary": "The x402 protocol puts a payment inside the HTTP 402 response, settles in about 200 milliseconds and charges no protocol fee, so paying in pence now works."
          },
          {
            "id": "parts-that-run",
            "label": "The parts that already run",
            "kind": "example",
            "summary": "Hash-verified regulation graphs, a Portuguese newsroom with frozen sources and an editor-gated pipeline, a pentest sold as eight projections, and thirty-one vaults on 295 MB, with the billing not built."
          }
        ],
        "edges": [
          {
            "from": "both-models-bad-for-the-reader",
            "to": "objective-loop",
            "rel": "leads-to"
          },
          {
            "from": "two-clocks",
            "to": "both-models-bad-for-the-reader",
            "rel": "extends"
          },
          {
            "from": "three-buyers",
            "to": "case-against-micropayments",
            "rel": "answers"
          },
          {
            "from": "payment-rails",
            "to": "case-against-micropayments",
            "rel": "answers"
          },
          {
            "from": "story-is-a-graph",
            "to": "fractal-semantic-graph",
            "rel": "depends-on"
          },
          {
            "from": "fractal-semantic-graph",
            "to": "provenance-ladder",
            "rel": "produces"
          },
          {
            "from": "story-vault",
            "to": "story-is-a-graph",
            "rel": "depends-on"
          },
          {
            "from": "story-vault",
            "to": "provenance-ladder",
            "rel": "depends-on"
          },
          {
            "from": "anonymous-source-at-the-node",
            "to": "story-vault",
            "rel": "extends"
          },
          {
            "from": "story-vault",
            "to": "five-projections",
            "rel": "produces"
          },
          {
            "from": "three-buyers",
            "to": "five-projections",
            "rel": "leads-to"
          },
          {
            "from": "evidence-vault",
            "to": "five-projections",
            "rel": "example-of"
          },
          {
            "from": "verification-api",
            "to": "five-projections",
            "rel": "example-of"
          },
          {
            "from": "evidence-vault",
            "to": "anonymous-source-at-the-node",
            "rel": "depends-on"
          },
          {
            "from": "verification-api",
            "to": "provenance-ladder",
            "rel": "depends-on"
          },
          {
            "from": "evidence-vault",
            "to": "objective-loop",
            "rel": "answers"
          },
          {
            "from": "fact-creator-split",
            "to": "story-is-a-graph",
            "rel": "depends-on"
          },
          {
            "from": "fact-creator-split",
            "to": "payment-rails",
            "rel": "depends-on"
          },
          {
            "from": "fact-creator-split",
            "to": "objective-loop",
            "rel": "answers"
          },
          {
            "from": "parts-that-run",
            "to": "story-vault",
            "rel": "example-of"
          },
          {
            "from": "story-is-a-graph",
            "to": "both-models-bad-for-the-reader",
            "rel": "contrasts"
          }
        ],
        "links": {
          "articles": [
            "the-question-is-whether-they-miss-it"
          ],
          "pages": [
            "/demos/fractal-graphs/index.html",
            "/demos/fractal-graphs/performance.html",
            "/docs/what-is-sgit.html",
            "/demos/vaults/regulation-graph/index.html",
            "/demos/vaults/dsit-ai-risk-toolkit/index.html",
            "/demos/vaults/voice-debrief/index.html",
            "/demos/vaults/pentest-report/index.html",
            "/demos/vaults/board/index.html",
            "/demos/vaults/catalogue/index.html"
          ],
          "sites": [
            "https://newsroom.sgit.ai/thesis",
            "https://graphs.sgit.ai/",
            "https://newsroom.sgit.ai/economics/paying-the-fact-creator",
            "https://newsroom.sgit.ai/economics/rails",
            "https://pressgazette.co.uk/media-audience-and-business-data/google-traffic-down-2025-trends-report-2026/",
            "https://reutersinstitute.politics.ox.ac.uk/digital-news-report/2026/dnr-executive-summary",
            "https://ppa.co.uk/burnham-government-brings-forward-implementation-of-subscription-rules-to-january-2027",
            "https://www.cjr.org/opinion/micropayments-subscription-pay-by-article.php"
          ]
        },
        "quotes": [
          {
            "text": "The news industry sells the one thing whose price is going to zero, the article, and throws away the one thing nobody else has, the evidence the article was made from.",
            "why": "The claim stated so it can be wrong; everything else is its long form."
          },
          {
            "text": "The story is a graph. The article is a projection. Sell the graph.",
            "why": "The shift the five products follow from, in three sentences."
          }
        ]
      }
    },
    {
      "slug": "saas-apocalypse-decided-by-inertia-not-by-ai",
      "title": "The SaaS apocalypse will be decided by inertia, not by AI",
      "date": "2026-09-21",
      "updated": "",
      "url": "https://sgit.ai/articles/saas-apocalypse-decided-by-inertia-not-by-ai.html",
      "markdown": "https://sgit.ai/articles/saas-apocalypse-decided-by-inertia-not-by-ai.md",
      "card": "https://sgit.ai/articles/cards/saas-apocalypse-decided-by-inertia-not-by-ai.webp",
      "teaser": "Incumbents and newcomers have the same AI; what separates them is how much past success each has to protect, so inertia decides which SaaS companies survive.",
      "topics": [
        "startups-and-strategy"
      ],
      "tags": [
        "saas",
        "strategy",
        "wardley-maps",
        "agents",
        "article"
      ],
      "links_out": [],
      "links_in": [
        "if-somebody-built-a-company-on-code-review",
        "supply-chain-of-vaults"
      ],
      "graph": {
        "slug": "saas-apocalypse-decided-by-inertia-not-by-ai",
        "teaser": "Incumbents and newcomers have the same AI; what separates them is how much past success each has to protect, so inertia decides which SaaS companies survive.",
        "topics": [
          "startups-and-strategy"
        ],
        "core_idea": "AI is available to both sides, so the SaaS apocalypse will be decided by inertia: where each company sits on the evolution axis and how much past success it has to protect.",
        "nodes": [
          {
            "id": "the-claim",
            "label": "The claim, stated so it can be wrong",
            "kind": "claim",
            "summary": "Most medium and large SaaS companies will struggle, spectacularly, in the medium term, as companies and individuals build more of what they actually want instead of renting an approximation of it."
          },
          {
            "id": "ai-on-both-sides",
            "label": "AI is available to both sides",
            "kind": "claim",
            "summary": "The incumbents have the same models the newcomers have, plus more data, more engineers and more money, and if the technology decided this they would already have won."
          },
          {
            "id": "success-breeds-inertia",
            "label": "Success breeds inertia",
            "kind": "concept",
            "summary": "Wardley's climatic pattern: the pre-existing installed base causes inertia to change, and it is almost always new entrants, unencumbered by past success, who initiate it."
          },
          {
            "id": "nokia-twice",
            "label": "Nokia, twice",
            "kind": "example",
            "summary": "Nokia met the mobile phone with nothing to protect and dominated for fifteen years; it met the iPhone with fifteen years of success to protect and was gone from the category within seven."
          },
          {
            "id": "saaspocalypse-feb-2026",
            "label": "The SaaSpocalypse of February 2026",
            "kind": "example",
            "summary": "Roughly $285 billion left the sector in about 48 hours after Anthropic shipped Claude Cowork plug-ins, and by September software stocks had rallied about 40% from the April low."
          },
          {
            "id": "database-is-the-moat",
            "label": "The database is the moat",
            "kind": "claim",
            "summary": "Investors decided the thing underneath was safe and quietly stopped defending the thing on top; that is not a rebuttal of the apocalypse, it is the apocalypse, priced."
          },
          {
            "id": "users-never-happy",
            "label": "Users were never happy",
            "kind": "claim",
            "summary": "91% of employees are frustrated with workplace technology, 80% of features are rarely or never used, and the average organisation wastes $21 million a year on unused licences."
          },
          {
            "id": "excel-persistence",
            "label": "The persistence of Excel",
            "kind": "example",
            "summary": "73% of companies prepare VAT returns in Excel; its persistence is the clearest evidence that SaaS failed users, because it is the one tool where they control the shape of the thing."
          },
          {
            "id": "product-slid-right",
            "label": "The SaaS product slid right",
            "kind": "concept",
            "summary": "On the map, what was a product is commoditising into a substrate, a database, a message bus, a state machine, on which higher-order things get built."
          },
          {
            "id": "vibe-coding-as-briefs",
            "label": "Vibe coding is writing good briefs",
            "kind": "concept",
            "summary": "Product owners were always describing the software they wanted; the loop from I want this to here it is was weeks or months, and is now minutes."
          },
          {
            "id": "incumbents-cannot-build",
            "label": "Why incumbents cannot simply do this",
            "kind": "claim",
            "summary": "SaaS companies never invested in non-functional requirements, engineers spend 42% of their time on maintenance and bad code, and only 19% of teams are elite performers."
          },
          {
            "id": "the-irony",
            "label": "The irony",
            "kind": "claim",
            "summary": "The things SaaS companies refused to build to protect their moats, portability, open schemas, a real API, data you can take out, are precisely the things an agent needs."
          },
          {
            "id": "brief-is-not-a-product",
            "label": "The brief is not a product",
            "kind": "claim",
            "summary": "The reason you bought SaaS was never the features but that the thing is maintained, and the person who vibe coded a replacement does not want to maintain it."
          },
          {
            "id": "villager-companies",
            "label": "Village and town-planner companies",
            "kind": "concept",
            "summary": "Businesses that take the finished brief and run it, maintain, secure, version and deploy it, paid by consumption rather than by the seat, where the handover is a file move plus a version bump."
          },
          {
            "id": "more-engineers",
            "label": "More engineers, not fewer",
            "kind": "claim",
            "summary": "We will need as many developers as now and probably more, because somebody has to read, harden and run the code, and larger human-agent teams become possible once communication can be scaled."
          }
        ],
        "edges": [
          {
            "from": "the-claim",
            "to": "success-breeds-inertia",
            "rel": "depends-on"
          },
          {
            "from": "ai-on-both-sides",
            "to": "success-breeds-inertia",
            "rel": "contrasts"
          },
          {
            "from": "nokia-twice",
            "to": "success-breeds-inertia",
            "rel": "example-of"
          },
          {
            "from": "saaspocalypse-feb-2026",
            "to": "the-claim",
            "rel": "example-of"
          },
          {
            "from": "saaspocalypse-feb-2026",
            "to": "database-is-the-moat",
            "rel": "leads-to"
          },
          {
            "from": "database-is-the-moat",
            "to": "product-slid-right",
            "rel": "extends"
          },
          {
            "from": "users-never-happy",
            "to": "the-claim",
            "rel": "extends"
          },
          {
            "from": "success-breeds-inertia",
            "to": "users-never-happy",
            "rel": "leads-to"
          },
          {
            "from": "excel-persistence",
            "to": "users-never-happy",
            "rel": "example-of"
          },
          {
            "from": "excel-persistence",
            "to": "vibe-coding-as-briefs",
            "rel": "compared-with"
          },
          {
            "from": "vibe-coding-as-briefs",
            "to": "the-claim",
            "rel": "leads-to"
          },
          {
            "from": "incumbents-cannot-build",
            "to": "success-breeds-inertia",
            "rel": "depends-on"
          },
          {
            "from": "incumbents-cannot-build",
            "to": "ai-on-both-sides",
            "rel": "extends"
          },
          {
            "from": "the-irony",
            "to": "success-breeds-inertia",
            "rel": "depends-on"
          },
          {
            "from": "the-irony",
            "to": "the-claim",
            "rel": "leads-to"
          },
          {
            "from": "brief-is-not-a-product",
            "to": "vibe-coding-as-briefs",
            "rel": "contrasts"
          },
          {
            "from": "excel-persistence",
            "to": "brief-is-not-a-product",
            "rel": "leads-to"
          },
          {
            "from": "brief-is-not-a-product",
            "to": "villager-companies",
            "rel": "leads-to"
          },
          {
            "from": "villager-companies",
            "to": "product-slid-right",
            "rel": "depends-on"
          },
          {
            "from": "villager-companies",
            "to": "more-engineers",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/demos/fractal-graphs/index.html"
          ],
          "sites": [
            "https://saassentinel.com/2026/07/03/saaspocalypse-2026-what-happened-to-saas-and-where-the-market-stands-now/",
            "https://www.freshworks.com/press-releases/survey-nine-in-10-employees-are-frustrated-by-their-workplace-technology/",
            "https://www.pendo.io/resources/the-2019-feature-adoption-report/",
            "https://zylo.com/news/2025-saas-management-index",
            "https://blog.gardeviance.org/2016/08/doctrine.html",
            "https://wardley-maps.sgit.ai/",
            "https://stripe.com/files/reports/the-developer-coefficient.pdf",
            "https://dora.dev/research/2024/dora-report/"
          ]
        },
        "quotes": [
          {
            "text": "AI is not the deciding factor, because AI is available to both sides.",
            "why": "The title's argument in one line: the variable both the panic and the recovery stared at was the wrong one."
          },
          {
            "text": "The things SaaS companies refused to build, to protect their moats, are precisely the things an agent needs.",
            "why": "The irony the article calls the whole piece in one paragraph: the moat is now what the customer's agent cannot get past."
          }
        ]
      }
    },
    {
      "slug": "the-question-is-whether-they-miss-it",
      "title": "For a startup, the most important question is whether they miss it",
      "date": "2026-09-21",
      "updated": "2026-10-02",
      "url": "https://sgit.ai/articles/the-question-is-whether-they-miss-it.html",
      "markdown": "https://sgit.ai/articles/the-question-is-whether-they-miss-it.md",
      "card": "https://sgit.ai/articles/cards/the-question-is-whether-they-miss-it.webp",
      "teaser": "Ship something usable, give it away briefly, take it away and see whether anybody misses it; charge at a profit before you talk to investors.",
      "topics": [
        "startups-and-strategy"
      ],
      "tags": [
        "startups",
        "strategy",
        "open-source",
        "investing",
        "article"
      ],
      "links_out": [
        "price-it-then-give-it-away"
      ],
      "links_in": [
        "if-somebody-built-a-company-on-code-review",
        "price-it-then-give-it-away",
        "future-of-news-story-vault-not-paywall"
      ],
      "graph": {
        "slug": "the-question-is-whether-they-miss-it",
        "teaser": "Ship something usable, give it away briefly, take it away and see whether anybody misses it; charge at a profit before you talk to investors.",
        "topics": [
          "startups-and-strategy"
        ],
        "core_idea": "A startup operating model in three pillars: be profitable, make investors come to you, and open source everything, each buying the position needed for the next.",
        "nodes": [
          {
            "id": "three-pillars",
            "label": "Three pillars",
            "kind": "concept",
            "summary": "Be profitable, have investors talking to you, and open source everything, in that order because each one buys you the position you need to do the next."
          },
          {
            "id": "ship",
            "label": "Ship",
            "kind": "method",
            "summary": "Shipping means a thing somebody else can go and use, on their own, and get value from, not a proof of concept or a demo."
          },
          {
            "id": "near-zero-running-cost",
            "label": "Near-zero running cost",
            "kind": "method",
            "summary": "To ship that often the running cost must be near nothing: serverless, as little live state as you can stand, and in our case the file system is the database."
          },
          {
            "id": "give-it-away",
            "label": "Give it away",
            "kind": "method",
            "summary": "Hand it to people for free for a short window, because the feedback starts the moment somebody who is not you has the thing."
          },
          {
            "id": "take-it-away",
            "label": "Take it away",
            "kind": "method",
            "summary": "The trial expired, it is not available right now, nothing else about the product changes, and no apology is needed."
          },
          {
            "id": "do-they-miss-it",
            "label": "Do they miss it?",
            "kind": "question",
            "summary": "If they shrug you have something people will accept when it is free; if they come back and ask for it, you have something."
          },
          {
            "id": "charge-at-profit",
            "label": "Charge, and charge at a profit",
            "kind": "claim",
            "summary": "Two questions, is the price one they are happy to pay and is that price profitable for you, and people routinely answer only the first."
          },
          {
            "id": "no-subscription-by-default",
            "label": "No subscription by default",
            "kind": "claim",
            "summary": "Charging rent for something people are not using is a worse business than being paid when you deliver."
          },
          {
            "id": "raise-from-strength",
            "label": "Raise from strength",
            "kind": "claim",
            "summary": "The worst possible time to raise money is before you are profitable, because you are bargaining from weakness and the worst terms are about control."
          },
          {
            "id": "album-before-the-deal",
            "label": "Do not get signed before you have the album",
            "kind": "example",
            "summary": "Write the songs, record them, get people buying, then take the record deal as somebody who already has an audience."
          },
          {
            "id": "open-source-everything",
            "label": "Open source everything",
            "kind": "method",
            "summary": "It sounds like giving away the asset and is the opposite, for five reasons that each stand alone."
          },
          {
            "id": "technology-is-not-the-moat",
            "label": "The technology is not the moat",
            "kind": "claim",
            "summary": "Treating it as open from the start forces you to find the thing that actually is defensible, usually the data, the relationships, the distribution, or the speed at which you ship."
          },
          {
            "id": "leave-with-your-tools",
            "label": "You leave with your tools",
            "kind": "claim",
            "summary": "Build in the open and the work is still yours when you move on."
          },
          {
            "id": "vault-substrate",
            "label": "The vault as substrate",
            "kind": "artefact",
            "summary": "A vault carries data, app, history and sources as one string, with no database to run and no hosting for the reader, so shipping a small product is cheap, fast and reversible."
          }
        ],
        "edges": [
          {
            "from": "three-pillars",
            "to": "ship",
            "rel": "depends-on"
          },
          {
            "from": "three-pillars",
            "to": "raise-from-strength",
            "rel": "depends-on"
          },
          {
            "from": "three-pillars",
            "to": "open-source-everything",
            "rel": "depends-on"
          },
          {
            "from": "ship",
            "to": "near-zero-running-cost",
            "rel": "depends-on"
          },
          {
            "from": "ship",
            "to": "give-it-away",
            "rel": "leads-to"
          },
          {
            "from": "give-it-away",
            "to": "take-it-away",
            "rel": "leads-to"
          },
          {
            "from": "take-it-away",
            "to": "do-they-miss-it",
            "rel": "leads-to"
          },
          {
            "from": "do-they-miss-it",
            "to": "charge-at-profit",
            "rel": "leads-to"
          },
          {
            "from": "no-subscription-by-default",
            "to": "charge-at-profit",
            "rel": "extends"
          },
          {
            "from": "charge-at-profit",
            "to": "raise-from-strength",
            "rel": "leads-to"
          },
          {
            "from": "album-before-the-deal",
            "to": "raise-from-strength",
            "rel": "example-of"
          },
          {
            "from": "open-source-everything",
            "to": "technology-is-not-the-moat",
            "rel": "depends-on"
          },
          {
            "from": "leave-with-your-tools",
            "to": "open-source-everything",
            "rel": "extends"
          },
          {
            "from": "vault-substrate",
            "to": "near-zero-running-cost",
            "rel": "example-of"
          },
          {
            "from": "vault-substrate",
            "to": "ship",
            "rel": "answers"
          },
          {
            "from": "vault-substrate",
            "to": "open-source-everything",
            "rel": "example-of"
          }
        ],
        "links": {
          "articles": [
            "price-it-then-give-it-away"
          ],
          "pages": [
            "/demos/fractal-graphs/performance.html",
            "/demos/vaults/index.html"
          ],
          "sites": [
            "https://subscriptions.sgit.ai/",
            "https://open-source.sgit.ai/"
          ]
        },
        "quotes": [
          {
            "text": "It means a thing somebody else can go and use, on their own, and get value from.",
            "why": "The definition of shipping that the whole loop depends on."
          },
          {
            "text": "The worst possible time to raise money is before you are profitable, before you have the product, before you understand the fit.",
            "why": "Pillar two stated plainly, and the reason profitability comes first."
          }
        ]
      }
    },
    {
      "slug": "introducing-fractal-semantic-graphs",
      "title": "Fractal Semantic Graphs: everything connects to everything, and nobody has to share a schema",
      "date": "2026-09-20",
      "updated": "",
      "url": "https://sgit.ai/articles/introducing-fractal-semantic-graphs.html",
      "markdown": "https://sgit.ai/articles/introducing-fractal-semantic-graphs.md",
      "card": "https://sgit.ai/articles/cards/introducing-fractal-semantic-graphs.webp",
      "teaser": "A fractal semantic graph has no privileged level and no single schema: each world keeps its own vocabulary and connects to others through named edges.",
      "topics": [
        "graphs-and-knowledge"
      ],
      "tags": [
        "graphs",
        "method",
        "fractal-semantic-graphs",
        "article"
      ],
      "links_out": [],
      "links_in": [
        "how-much-of-this-did-i-write",
        "if-somebody-built-a-company-on-code-review",
        "code-review-as-a-fractal-semantic-graph",
        "memory-is-not-a-spectator-sport",
        "custom-uis-are-not-the-exception",
        "ultimate-insider-three-collisions",
        "how-news-got-here",
        "token-bill-nobody-is-sending",
        "supply-chain-of-vaults",
        "every-risk-is-already-accepted"
      ],
      "graph": {
        "slug": "introducing-fractal-semantic-graphs",
        "teaser": "A fractal semantic graph has no privileged level and no single schema: each world keeps its own vocabulary and connects to others through named edges.",
        "topics": [
          "graphs-and-knowledge"
        ],
        "core_idea": "Every unit of knowledge is already a graph in its owner's vocabulary, and a short shared grammar rather than a shared schema is what lets any node in one world link to any node in another, up or down, without an adapter.",
        "nodes": [
          {
            "id": "fractal-semantic-graph",
            "label": "Fractal Semantic Graph",
            "kind": "concept",
            "summary": "A fractal semantic graph has no privileged level and no single schema; zoom into any node and you enter a new world with its own node types, verbs and taxonomy."
          },
          {
            "id": "semantic-graph",
            "label": "Semantic graph",
            "kind": "concept",
            "summary": "A semantic graph gives the edges meaning: every edge is a verb, and every verb has a named inverse, so a link reads correctly from whichever end you are standing at."
          },
          {
            "id": "ontology",
            "label": "Ontology",
            "kind": "concept",
            "summary": "An ontology is the agreed vocabulary of node types and verbs that a graph is allowed to use, and each altitude gets its own."
          },
          {
            "id": "the-jump",
            "label": "The jump",
            "kind": "method",
            "summary": "On one link in a risk register you can jump into another universe, from an incident to security operations to the DNS estate to a single TCP packet, and nobody built an adapter."
          },
          {
            "id": "everything-is-a-graph",
            "label": "Everything is already a graph",
            "kind": "claim",
            "summary": "A regulation, a PDF, a spreadsheet, a codebase and a JSON document are already graphs; each one only needs its edges named."
          },
          {
            "id": "five-rule-grammar",
            "label": "The five-rule grammar",
            "kind": "method",
            "summary": "Every edge is a verb with an inverse, relates_to is banned, properties carry data never meaning, supersede never delete, and never render the whole graph."
          },
          {
            "id": "banned-verb",
            "label": "relates_to is banned",
            "kind": "claim",
            "summary": "An edge with no verb constrains nothing and cannot narrow a query; the granularity of the verb is the precision of the question you will later be able to ask."
          },
          {
            "id": "provenance-from-the-word",
            "label": "Provenance comes free",
            "kind": "claim",
            "summary": "When the leaf is a word connected to the byte range it came from and the hash of the file that held it, every claim at every altitude above it is traceable to source."
          },
          {
            "id": "the-ladder",
            "label": "The ladder of eleven altitudes",
            "kind": "artefact",
            "summary": "Eleven altitudes, each a live graph in its own vocabulary, from the law down to the compute instance, every altitude joined to the next by a named edge."
          },
          {
            "id": "regulation-graph",
            "label": "Regulation Graph",
            "kind": "artefact",
            "summary": "The EU AI Act parsed from the official XML into 1,523 nodes and 1,944 edges, with the SHA-256 of the retrieved bytes at the end of every provenance chain."
          },
          {
            "id": "crosswalk-finding",
            "label": "The crosswalk finding",
            "kind": "example",
            "summary": "Joining the AIUC-1 standard to the regulation graph showed that 8 of the 27 articles reached have since been amended, a finding that existed in neither graph on its own."
          },
          {
            "id": "gdpr-article-45",
            "label": "GDPR Article 45",
            "kind": "example",
            "summary": "The text has not changed a word since 2016 while what it permits has flipped four times, drawn as a timeline of ruling nodes over one unchanged article node."
          },
          {
            "id": "threat-model-ladder",
            "label": "Threat model zoom ladder",
            "kind": "artefact",
            "summary": "Eleven linked models, 51 nodes and 179 threats, tracing a single SQL injection from the method it lives in to the revenue it puts at risk."
          },
          {
            "id": "named-gaps",
            "label": "What is still modelled rather than imported",
            "kind": "question",
            "summary": "The bottom four altitudes are placed by an author, enterprise architecture is missing, crosswalks resolve at article level only, and the agent altitude is a vocabulary not yet a join."
          },
          {
            "id": "why-now",
            "label": "Why now",
            "kind": "claim",
            "summary": "Naming edges became the cheap part, agents acting on the world make provenance mandatory, and the schema wars are over because nobody won."
          }
        ],
        "edges": [
          {
            "from": "fractal-semantic-graph",
            "to": "semantic-graph",
            "rel": "extends"
          },
          {
            "from": "semantic-graph",
            "to": "ontology",
            "rel": "depends-on"
          },
          {
            "from": "five-rule-grammar",
            "to": "ontology",
            "rel": "contrasts"
          },
          {
            "from": "fractal-semantic-graph",
            "to": "everything-is-a-graph",
            "rel": "depends-on"
          },
          {
            "from": "the-jump",
            "to": "fractal-semantic-graph",
            "rel": "example-of"
          },
          {
            "from": "the-jump",
            "to": "five-rule-grammar",
            "rel": "depends-on"
          },
          {
            "from": "banned-verb",
            "to": "five-rule-grammar",
            "rel": "extends"
          },
          {
            "from": "provenance-from-the-word",
            "to": "everything-is-a-graph",
            "rel": "depends-on"
          },
          {
            "from": "the-ladder",
            "to": "fractal-semantic-graph",
            "rel": "example-of"
          },
          {
            "from": "regulation-graph",
            "to": "the-ladder",
            "rel": "example-of"
          },
          {
            "from": "threat-model-ladder",
            "to": "the-ladder",
            "rel": "example-of"
          },
          {
            "from": "regulation-graph",
            "to": "provenance-from-the-word",
            "rel": "example-of"
          },
          {
            "from": "crosswalk-finding",
            "to": "regulation-graph",
            "rel": "depends-on"
          },
          {
            "from": "crosswalk-finding",
            "to": "the-jump",
            "rel": "example-of"
          },
          {
            "from": "gdpr-article-45",
            "to": "five-rule-grammar",
            "rel": "example-of"
          },
          {
            "from": "named-gaps",
            "to": "the-ladder",
            "rel": "contrasts"
          },
          {
            "from": "why-now",
            "to": "fractal-semantic-graph",
            "rel": "leads-to"
          },
          {
            "from": "why-now",
            "to": "provenance-from-the-word",
            "rel": "extends"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/demos/fractal-graphs/index.html",
            "/demos/vaults/voice-debrief/index.html"
          ],
          "sites": [
            "https://graphs.sgit.ai/",
            "https://standards.sgit.ai/",
            "https://abp.sgit.ai/",
            "https://graphs.sgit.ai/llms.txt"
          ]
        },
        "quotes": [
          {
            "text": "There is no top and no bottom. There is only the altitude you happen to be looking from, and how much definition you choose to load at it.",
            "why": "The definition of fractal in one line: no privileged level, no single schema."
          },
          {
            "text": "Two graphs, built by different people for different purposes in different vocabularies, joined by declared edges, produced a finding that did not exist in either of them.",
            "why": "The evidence that the method does work, not just that it is defined: the amended-articles finding came from the join."
          }
        ]
      }
    },
    {
      "slug": "proof-behind-the-claim",
      "title": "The proof is two clicks behind the claim, what the homepage gets wrong, and the fix",
      "date": "2026-09-07",
      "updated": "",
      "url": "https://sgit.ai/articles/proof-behind-the-claim.html",
      "markdown": "https://sgit.ai/articles/proof-behind-the-claim.md",
      "card": "https://sgit.ai/articles/cards/proof-behind-the-claim.webp",
      "teaser": "The homepage leads with encryption, which cannot be seen, while twenty-five vaults a stranger can open in one click sit two clicks away in a table.",
      "topics": [
        "site-and-engineering",
        "vaults-and-method"
      ],
      "tags": [
        "homepage",
        "positioning",
        "vaults",
        "agents"
      ],
      "links_out": [],
      "links_in": [
        "proof-moved-up"
      ],
      "graph": {
        "slug": "proof-behind-the-claim",
        "teaser": "The homepage leads with encryption, which cannot be seen, while twenty-five vaults a stranger can open in one click sit two clicks away in a table.",
        "topics": [
          "site-and-engineering",
          "vaults-and-method"
        ],
        "core_idea": "Encryption is a property you cannot look at, so the homepage should put the real vaults a visitor can open before the mechanism, and should not carry a claim that no published vault demonstrates.",
        "nodes": [
          {
            "id": "twenty-five-vaults",
            "label": "Twenty-five published vaults",
            "kind": "artefact",
            "summary": "Three weeks ago the site had four published vaults; today it has twenty-five, built by several agents working with one human, including a pentest report with a retest script per finding and a standard rebuilt as a citable graph."
          },
          {
            "id": "encryption-cannot-be-seen",
            "label": "Encryption is a property you cannot look at",
            "kind": "claim",
            "summary": "Zero knowledge cannot be seen either, so the visitor is asked to take the value on faith before being shown anything."
          },
          {
            "id": "terminal-walkthrough",
            "label": "The terminal walkthrough",
            "kind": "example",
            "summary": "The hero's create, commit, history and clone walkthrough demonstrates familiarity, which is a virtue, but not power."
          },
          {
            "id": "abstract-use-cases",
            "label": "Use cases as categories",
            "kind": "example",
            "summary": "Five use-case cards, each a category rather than a thing, while the vault that embodies the category sits one level down."
          },
          {
            "id": "table-two-clicks-away",
            "label": "The proof is a table, two clicks away",
            "kind": "claim",
            "summary": "A table is the right shape for finding a vault and the wrong shape for being convinced by one, and it is under a dropdown two clicks from the hero."
          },
          {
            "id": "open-by-one-string",
            "label": "Opened by one string",
            "kind": "claim",
            "summary": "Both proof vaults are opened by one string, run entirely in the browser, ship with their data, sources and tests, and require the visitor to click rather than to understand encryption."
          },
          {
            "id": "agents-build-for-each-other",
            "label": "Agents build for each other",
            "kind": "example",
            "summary": "A brief published on 6 September was read by another agent who built a vault from it the same day, and the API team's correction is now published above the mistake."
          },
          {
            "id": "briefs-as-log",
            "label": "The briefs page as a log",
            "kind": "example",
            "summary": "The collaboration record is filed under Docs, three levels from the homepage, written as a log, which is the right format for the record and the wrong one for a first-time reader."
          },
          {
            "id": "unproven-merge-claim",
            "label": "The claim with no artefact",
            "kind": "question",
            "summary": "The homepage says a human reviews the merge of agents' branches, and no published vault shows two agents' branches and a human merge in its history."
          },
          {
            "id": "proof-before-mechanism",
            "label": "Reorder so proof comes before mechanism",
            "kind": "method",
            "summary": "The hero shows four real vaults as cards, then six vaults chosen by job, then the team story, then the terminal walkthrough and the zero-knowledge explanation."
          },
          {
            "id": "generated-from-data",
            "label": "Generated from the same data",
            "kind": "method",
            "summary": "The six vaults chosen by job are generated from the same data as the table, so they never go stale."
          },
          {
            "id": "about-page",
            "label": "A page that says who is behind it",
            "kind": "artefact",
            "summary": "A beta tool that asks people to publish their read keys is asking for trust, so there will be a page about who builds sgit, borrowing Interests declared and Reach me, or correct me from a sibling site."
          },
          {
            "id": "site-card",
            "label": "The site card",
            "kind": "artefact",
            "summary": "A card describes a sibling site the way it describes itself, from its entry in the network directory, because a bare link does not say this continues elsewhere, on purpose."
          }
        ],
        "edges": [
          {
            "from": "terminal-walkthrough",
            "to": "encryption-cannot-be-seen",
            "rel": "example-of"
          },
          {
            "from": "abstract-use-cases",
            "to": "twenty-five-vaults",
            "rel": "contrasts"
          },
          {
            "from": "table-two-clicks-away",
            "to": "open-by-one-string",
            "rel": "contrasts"
          },
          {
            "from": "open-by-one-string",
            "to": "twenty-five-vaults",
            "rel": "example-of"
          },
          {
            "from": "open-by-one-string",
            "to": "encryption-cannot-be-seen",
            "rel": "contrasts"
          },
          {
            "from": "agents-build-for-each-other",
            "to": "twenty-five-vaults",
            "rel": "example-of"
          },
          {
            "from": "briefs-as-log",
            "to": "agents-build-for-each-other",
            "rel": "compared-with"
          },
          {
            "from": "unproven-merge-claim",
            "to": "abstract-use-cases",
            "rel": "extends"
          },
          {
            "from": "unproven-merge-claim",
            "to": "open-by-one-string",
            "rel": "contrasts"
          },
          {
            "from": "proof-before-mechanism",
            "to": "encryption-cannot-be-seen",
            "rel": "answers"
          },
          {
            "from": "proof-before-mechanism",
            "to": "table-two-clicks-away",
            "rel": "answers"
          },
          {
            "from": "proof-before-mechanism",
            "to": "briefs-as-log",
            "rel": "answers"
          },
          {
            "from": "generated-from-data",
            "to": "proof-before-mechanism",
            "rel": "extends"
          },
          {
            "from": "about-page",
            "to": "site-card",
            "rel": "depends-on"
          },
          {
            "from": "site-card",
            "to": "generated-from-data",
            "rel": "example-of"
          }
        ],
        "links": {
          "articles": [],
          "pages": [],
          "sites": [
            "https://open-source.sgit.ai/about/index.html"
          ]
        },
        "quotes": [
          {
            "text": "The word \"vault\" appears in the hero three times and the visitor is never shown one.",
            "why": "The diagnosis in one line: the homepage names the thing and never shows it."
          },
          {
            "text": "A claim on a homepage with no artefact behind it is exactly what this site says it does not do.",
            "why": "The gap the article names against itself: the multi-agent merge claim has no published vault behind it."
          }
        ]
      }
    },
    {
      "slug": "proof-moved-up",
      "title": "The proof moved up, the homepage after the rebuild, next to the before pictures",
      "date": "2026-09-07",
      "updated": "",
      "url": "https://sgit.ai/articles/proof-moved-up.html",
      "markdown": "https://sgit.ai/articles/proof-moved-up.md",
      "card": "https://sgit.ai/articles/cards/proof-moved-up.webp",
      "teaser": "The rebuilt homepage puts four real vaults under one sentence, picks six by the job they do, and computes its numbers at build time from the site's own data.",
      "topics": [
        "site-and-engineering",
        "vaults-and-method"
      ],
      "tags": [
        "homepage",
        "positioning",
        "vaults",
        "agents"
      ],
      "links_out": [
        "proof-behind-the-claim"
      ],
      "links_in": [],
      "graph": {
        "slug": "proof-moved-up",
        "teaser": "The rebuilt homepage puts four real vaults under one sentence, picks six by the job they do, and computes its numbers at build time from the site's own data.",
        "topics": [
          "site-and-engineering",
          "vaults-and-method"
        ],
        "core_idea": "The homepage stopped being a page somebody edits and became a view over the site's own data, with real vaults placed before the mechanism and the one unproven claim left unpretended.",
        "nodes": [
          {
            "id": "reframed-sentence",
            "label": "The reframed sentence",
            "kind": "claim",
            "summary": "The hero changed from \"the encrypted git for humans and AI agents\" to \"a vault is a unit of work: data, app, history and sources, shipped as one string\", with encryption as the subordinate clause."
          },
          {
            "id": "four-hero-vaults",
            "label": "Four real vaults in the hero",
            "kind": "artefact",
            "summary": "Four published vaults with their screenshots sit under the sentence, chosen by a hero field in the vault data, so changing the front door is a data edit, not a page edit."
          },
          {
            "id": "six-jobs",
            "label": "What people actually ship",
            "kind": "artefact",
            "summary": "Six vaults chosen by the job they do, hand over a report, publish a standard, give a talk, pitch an investor, ship a game, give an agent a workspace, and none of the six lines is about encryption."
          },
          {
            "id": "vault-as-a-unit",
            "label": "A vault as a unit",
            "kind": "concept",
            "summary": "Retest scripts that travel with the findings and cited papers that never separate from the deck are properties of a vault as a unit, which a newcomer can actually feel."
          },
          {
            "id": "team-band",
            "label": "One human, a team of agents",
            "kind": "artefact",
            "summary": "A band with four numbers computed at build time, releases, vaults, sibling sites, briefs, and the loop told in three beats with the artefacts linked."
          },
          {
            "id": "numbers-not-typed",
            "label": "The numbers are not typed",
            "kind": "method",
            "summary": "Releases come from the version log, vaults from the vault data, sites from the network directory and briefs from the briefs page, so a wrong number means the site is wrong somewhere else too."
          },
          {
            "id": "what-was-cut",
            "label": "What was cut",
            "kind": "example",
            "summary": "The abstract use-case band and the three-doors band were cut, and the terminal walkthrough moved down under the heading Under the hood, it is git."
          },
          {
            "id": "nine-bands-counted",
            "label": "Nine bands before, nine after",
            "kind": "example",
            "summary": "Three bands were cut and three added, corrected in v0.2.61 after counting rather than remembering, and 1,370 words became 1,332 with ten screenshots."
          },
          {
            "id": "unproven-merge-claim",
            "label": "What it cannot show yet",
            "kind": "question",
            "summary": "No published vault demonstrates two agents on one vault, their branches and a human merging them, and the team band is written so that it does not pretend otherwise."
          },
          {
            "id": "vaults-json",
            "label": "admin/content/vaults.json",
            "kind": "artefact",
            "summary": "One file now drives the hero cards, the six jobs, the sortable table and the vault count; adding a vault is adding a row and promoting one is setting a field."
          },
          {
            "id": "homepage-as-view",
            "label": "The homepage as a view over data",
            "kind": "claim",
            "summary": "The homepage stopped being a page somebody edits and became a view over the site's own data, the rule the articles band, network directory and update feed already followed."
          },
          {
            "id": "before-after-comparison",
            "label": "Beside the before pictures",
            "kind": "method",
            "summary": "The rebuild is put next to the previous article's screenshots so the comparison can be made honestly, including what it still cannot show."
          }
        ],
        "edges": [
          {
            "from": "reframed-sentence",
            "to": "vault-as-a-unit",
            "rel": "depends-on"
          },
          {
            "from": "four-hero-vaults",
            "to": "reframed-sentence",
            "rel": "extends"
          },
          {
            "from": "four-hero-vaults",
            "to": "vaults-json",
            "rel": "depends-on"
          },
          {
            "from": "six-jobs",
            "to": "vaults-json",
            "rel": "depends-on"
          },
          {
            "from": "six-jobs",
            "to": "vault-as-a-unit",
            "rel": "example-of"
          },
          {
            "from": "what-was-cut",
            "to": "six-jobs",
            "rel": "contrasts"
          },
          {
            "from": "what-was-cut",
            "to": "nine-bands-counted",
            "rel": "leads-to"
          },
          {
            "from": "team-band",
            "to": "numbers-not-typed",
            "rel": "depends-on"
          },
          {
            "from": "team-band",
            "to": "vaults-json",
            "rel": "depends-on"
          },
          {
            "from": "unproven-merge-claim",
            "to": "team-band",
            "rel": "contrasts"
          },
          {
            "from": "vaults-json",
            "to": "homepage-as-view",
            "rel": "produces"
          },
          {
            "from": "numbers-not-typed",
            "to": "homepage-as-view",
            "rel": "extends"
          },
          {
            "from": "nine-bands-counted",
            "to": "before-after-comparison",
            "rel": "example-of"
          },
          {
            "from": "before-after-comparison",
            "to": "unproven-merge-claim",
            "rel": "leads-to"
          }
        ],
        "links": {
          "articles": [
            "proof-behind-the-claim"
          ],
          "pages": [],
          "sites": []
        },
        "quotes": [
          {
            "text": "If a number on that band is wrong, the site is wrong somewhere else too, and that is the right dependency.",
            "why": "The rule behind the rebuild: nothing on the homepage is typed, everything is computed from the site's own records."
          },
          {
            "text": "That is the trade: pictures of real things instead of paragraphs about them.",
            "why": "What actually changed, stated against the byte and word counts rather than as a slogan."
          }
        ]
      }
    },
    {
      "slug": "chat-on-a-static-site",
      "title": "A chat box on a site with no server, the plan, and the trade it makes",
      "date": "2026-08-27",
      "updated": "",
      "url": "https://sgit.ai/articles/chat-on-a-static-site.html",
      "markdown": "https://sgit.ai/articles/chat-on-a-static-site.md",
      "card": "https://sgit.ai/articles/cards/chat-on-a-static-site.webp",
      "teaser": "sgit.ai has no server, so its directory chat runs a local matcher by default, takes your own key as an opt-in, and leaves the vault bridge unbuilt.",
      "topics": [
        "site-and-engineering"
      ],
      "tags": [
        "chat",
        "llm",
        "byok",
        "plan"
      ],
      "links_out": [],
      "links_in": [
        "custom-uis-are-not-the-exception"
      ],
      "graph": {
        "slug": "chat-on-a-static-site",
        "teaser": "sgit.ai has no server, so its directory chat runs a local matcher by default, takes your own key as an opt-in, and leaves the vault bridge unbuilt.",
        "topics": [
          "site-and-engineering"
        ],
        "core_idea": "With no server to hold a key, a chat box on a static site has three honest tiers: a local matcher, a key in the reader's browser, or a vault app with a bridge, and only one of those is free.",
        "nodes": [
          {
            "id": "static-site-constraint",
            "label": "The constraint nobody can design around",
            "kind": "concept",
            "summary": "sgit.ai is a static site on GitHub Pages with no server, no session and no place to keep a secret, and every sibling on *.sgit.ai is the same."
          },
          {
            "id": "catalogue",
            "label": "The catalogue",
            "kind": "artefact",
            "summary": "Nineteen theses, summaries and categories, emitted at build time from the same data the cards and the table are built from."
          },
          {
            "id": "tier-0-match",
            "label": "Tier 0, match",
            "kind": "method",
            "summary": "A deterministic scorer runs in the browser against the catalogue of all nineteen sites and shows you which words it matched on."
          },
          {
            "id": "no-credential-for-an-index",
            "label": "A reader should never have to hold a credential to use an index",
            "kind": "claim",
            "summary": "The property that made the local matcher the default: it is instant, free, private, works offline and tells you why it chose."
          },
          {
            "id": "tier-1-byok",
            "label": "Tier 1, bring your own key",
            "kind": "method",
            "summary": "Paste an OpenRouter key and the browser calls the model directly, streaming, with the catalogue as the system prompt."
          },
          {
            "id": "key-in-page-origin",
            "label": "The key lives in this page's origin",
            "kind": "concept",
            "summary": "With no host there is no permission floor, so the key goes into localStorage and a fetch to openrouter.ai, and the page cannot protect it the way a vault app can."
          },
          {
            "id": "fallback",
            "label": "Degrade to what works",
            "kind": "method",
            "summary": "When the model call fails the panel falls back to Tier 0 and says so, because degrading to something that works beats an error message."
          },
          {
            "id": "workbench-vault",
            "label": "The SG/Vault workbench vault",
            "kind": "example",
            "summary": "The workbench vault already calls the same OpenRouter endpoint with the versioned sg-llm-request module, so the BYOK client reuses a proven pattern."
          },
          {
            "id": "tier-2-bridge",
            "label": "Tier 2, the bridge",
            "kind": "method",
            "summary": "Serve the directory as a vault app so the key lives in .vault/llm/config.json below the permission floor, the host makes the call and the app never sees the credential."
          },
          {
            "id": "permission-floor",
            "label": "Permission floor",
            "kind": "concept",
            "summary": "The line below which a vault host keeps the key, with an sg.llm API whose grants default to deny and a chat panel every existing vault app gets without being changed."
          },
          {
            "id": "bridge-not-boundary",
            "label": "The bridge protects your key, not all egress",
            "kind": "claim",
            "summary": "The bridge protects the credential you trusted it with; it does not yet stop a malicious app calling a provider with a credential of its own."
          },
          {
            "id": "tool-calling-pane",
            "label": "Ask this site",
            "kind": "artefact",
            "summary": "Ten days later every page carries a pane whose model is given seven tools that run in the page over an index the build emits, and the pane shows every call it made."
          },
          {
            "id": "shared-component",
            "label": "One site's copy, not a versioned module",
            "kind": "question",
            "summary": "The site-wide pane is still one site's copy rather than a versioned module the other eighteen sites can load, and that row decides whether this was worth doing."
          },
          {
            "id": "routing-not-answering",
            "label": "Routing, not teaching",
            "kind": "claim",
            "summary": "The panel points you at a site rather than answering questions about the subjects, because a summary that drifts from the arguments is worse than a link that does not."
          }
        ],
        "edges": [
          {
            "from": "static-site-constraint",
            "to": "tier-0-match",
            "rel": "leads-to"
          },
          {
            "from": "static-site-constraint",
            "to": "key-in-page-origin",
            "rel": "leads-to"
          },
          {
            "from": "tier-0-match",
            "to": "catalogue",
            "rel": "depends-on"
          },
          {
            "from": "tier-1-byok",
            "to": "catalogue",
            "rel": "depends-on"
          },
          {
            "from": "tier-0-match",
            "to": "no-credential-for-an-index",
            "rel": "answers"
          },
          {
            "from": "tier-1-byok",
            "to": "key-in-page-origin",
            "rel": "produces"
          },
          {
            "from": "tier-1-byok",
            "to": "fallback",
            "rel": "leads-to"
          },
          {
            "from": "fallback",
            "to": "tier-0-match",
            "rel": "depends-on"
          },
          {
            "from": "workbench-vault",
            "to": "tier-1-byok",
            "rel": "example-of"
          },
          {
            "from": "tier-1-byok",
            "to": "tier-2-bridge",
            "rel": "compared-with"
          },
          {
            "from": "tier-2-bridge",
            "to": "permission-floor",
            "rel": "depends-on"
          },
          {
            "from": "permission-floor",
            "to": "key-in-page-origin",
            "rel": "contrasts"
          },
          {
            "from": "bridge-not-boundary",
            "to": "permission-floor",
            "rel": "extends"
          },
          {
            "from": "tool-calling-pane",
            "to": "tier-0-match",
            "rel": "extends"
          },
          {
            "from": "tool-calling-pane",
            "to": "catalogue",
            "rel": "depends-on"
          },
          {
            "from": "tool-calling-pane",
            "to": "shared-component",
            "rel": "leads-to"
          },
          {
            "from": "routing-not-answering",
            "to": "catalogue",
            "rel": "depends-on"
          },
          {
            "from": "tool-calling-pane",
            "to": "routing-not-answering",
            "rel": "depends-on"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/network/index.html",
            "/demos/vaults/index.html"
          ],
          "sites": []
        },
        "quotes": [
          {
            "text": "The important property: a reader should never have to hold a credential to use an index.",
            "why": "The rule that makes the free local matcher the default rather than the model."
          },
          {
            "text": "A chat box on one site is a feature. The same panel on all nineteen, reading each site's own catalogue, is the thing that makes a network of nineteen sites navigable, and it is why the catalogue is generated rather than written.",
            "why": "Why the piece is about a network's navigation rather than one widget."
          }
        ]
      }
    },
    {
      "slug": "nineteen-sites",
      "title": "Twenty sites in fifteen days, and what that did to the writing",
      "date": "2026-08-26",
      "updated": "",
      "url": "https://sgit.ai/articles/nineteen-sites.html",
      "markdown": "https://sgit.ai/articles/nineteen-sites.md",
      "card": "https://sgit.ai/articles/cards/nineteen-sites.webp",
      "teaser": "One site became twenty repositories in fifteen days because each argument needed its own version history, and the index now starts from a question.",
      "topics": [
        "site-and-engineering",
        "vaults-and-method"
      ],
      "tags": [
        "network",
        "publishing",
        "method"
      ],
      "links_out": [
        "what-sgit-is"
      ],
      "links_in": [],
      "graph": {
        "slug": "nineteen-sites",
        "teaser": "One site became twenty repositories in fifteen days because each argument needed its own version history, and the index now starts from a question.",
        "topics": [
          "site-and-engineering",
          "vaults-and-method"
        ],
        "core_idea": "A body of work outgrew the site it was published in and split into nineteen siblings so each argument could keep its own version history, and the index into them starts from the reader's question rather than a list of names.",
        "nodes": [
          {
            "id": "twenty-repositories",
            "label": "Twenty repositories in fifteen days",
            "kind": "example",
            "summary": "On 11 August this was one website; by 26 August there were twenty repositories, nineteen of them siblings on *.sgit.ai, fifteen created in the last five days."
          },
          {
            "id": "section-as-promise",
            "label": "A section is a promise",
            "kind": "concept",
            "summary": "A section promises that something is part of the thing it sits inside, and that promise stopped holding when the writing answered questions that were not about sgit."
          },
          {
            "id": "own-version-history",
            "label": "Its own version history",
            "kind": "claim",
            "summary": "Nineteen arguments moving at different speeds through one release log produces a record nobody can read; split, each gets its own record of when it changed its mind."
          },
          {
            "id": "discovery-cost",
            "label": "Discovery got worse",
            "kind": "claim",
            "summary": "Nineteen domains is not a menu; names like nfrs.sgit.ai and issues-fs.sgit.ai mean nothing until you already know what they argue."
          },
          {
            "id": "consistency-by-discipline",
            "label": "Consistency by discipline",
            "kind": "claim",
            "summary": "One site has one stylesheet by construction; nineteen have one stylesheet by discipline, and discipline is the thing that quietly stops happening."
          },
          {
            "id": "cross-link-drift",
            "label": "Cross-link drift",
            "kind": "example",
            "summary": "The audit found graphs.sgit.ai pointing at sentinel.sgit.ai, which does not exist; the site is sg-sentinel.sgit.ai, one character of drift and the link is dead."
          },
          {
            "id": "question-first-directory",
            "label": "Start from the question",
            "kind": "method",
            "summary": "The directory starts from the question the reader arrived with, seventeen lines of it, then five groups by area, then a table of all nineteen."
          },
          {
            "id": "quoted-thesis-rule",
            "label": "Every thesis in the site's own words",
            "kind": "method",
            "summary": "Each thesis on the directory page is quoted from the site's H1 or lede rather than summarised, because a summary drifts and a quotation either matches or is visibly wrong."
          },
          {
            "id": "shared-toolchain",
            "label": "Same generator, same release script",
            "kind": "method",
            "summary": "Same generator, same stylesheet, same release script, same validator, same rule that publishing is adding one file."
          },
          {
            "id": "one-file-per-publish",
            "label": "Publishing is adding one file",
            "kind": "claim",
            "summary": "Adding the twentieth site is writing one markdown file, the same property that lets two agents publish on the same day without conflict."
          },
          {
            "id": "unpublished-sibling",
            "label": "skills.sgit.ai, not published yet",
            "kind": "example",
            "summary": "One of the nineteen has a repository and a DNS record and nothing behind it, listed as not published yet rather than quietly omitted."
          },
          {
            "id": "arguments-not-products",
            "label": "Arguments, not products",
            "kind": "claim",
            "summary": "sg-sentinel says NOT BUILT, risks states zero lines of code implement its model, wardley-maps is PROPOSED: publish the argument before the thing exists and say what it is worth."
          }
        ],
        "edges": [
          {
            "from": "section-as-promise",
            "to": "twenty-repositories",
            "rel": "leads-to"
          },
          {
            "from": "own-version-history",
            "to": "section-as-promise",
            "rel": "extends"
          },
          {
            "from": "own-version-history",
            "to": "twenty-repositories",
            "rel": "leads-to"
          },
          {
            "from": "twenty-repositories",
            "to": "discovery-cost",
            "rel": "leads-to"
          },
          {
            "from": "twenty-repositories",
            "to": "consistency-by-discipline",
            "rel": "leads-to"
          },
          {
            "from": "twenty-repositories",
            "to": "cross-link-drift",
            "rel": "leads-to"
          },
          {
            "from": "question-first-directory",
            "to": "discovery-cost",
            "rel": "answers"
          },
          {
            "from": "quoted-thesis-rule",
            "to": "question-first-directory",
            "rel": "extends"
          },
          {
            "from": "quoted-thesis-rule",
            "to": "cross-link-drift",
            "rel": "compared-with"
          },
          {
            "from": "shared-toolchain",
            "to": "consistency-by-discipline",
            "rel": "answers"
          },
          {
            "from": "one-file-per-publish",
            "to": "shared-toolchain",
            "rel": "depends-on"
          },
          {
            "from": "one-file-per-publish",
            "to": "question-first-directory",
            "rel": "extends"
          },
          {
            "from": "unpublished-sibling",
            "to": "arguments-not-products",
            "rel": "compared-with"
          },
          {
            "from": "arguments-not-products",
            "to": "own-version-history",
            "rel": "depends-on"
          }
        ],
        "links": {
          "articles": [
            "what-sgit-is"
          ],
          "pages": [
            "/network/graphs.html",
            "/updates/",
            "/network/sg-sentinel.html",
            "/network/index.html"
          ],
          "sites": []
        },
        "quotes": [
          {
            "text": "A summary drifts. A quotation either matches or is visibly wrong.",
            "why": "The rule that keeps the directory honest, and the reason the index quotes each site rather than describing it."
          },
          {
            "text": "One character of drift, and the link is dead.",
            "why": "The concrete cost of splitting: a link between sites is a claim about another site that has to be checked."
          }
        ]
      }
    },
    {
      "slug": "what-sgit-is",
      "title": "Git for things you cannot put on GitHub",
      "date": "2026-08-25",
      "updated": "",
      "url": "https://sgit.ai/articles/what-sgit-is.html",
      "markdown": "https://sgit.ai/articles/what-sgit-is.md",
      "card": "https://sgit.ai/articles/cards/what-sgit-is.webp",
      "teaser": "sgit is git for files you cannot put on GitHub: encrypted before they leave your machine, versioned like git, stored where the server cannot read a byte.",
      "topics": [
        "vaults-and-method"
      ],
      "tags": [
        "intro",
        "zero-knowledge",
        "vaults",
        "agents"
      ],
      "links_out": [],
      "links_in": [
        "nineteen-sites"
      ],
      "graph": {
        "slug": "what-sgit-is",
        "teaser": "sgit is git for files you cannot put on GitHub: encrypted before they leave your machine, versioned like git, stored where the server cannot read a byte.",
        "topics": [
          "vaults-and-method"
        ],
        "core_idea": "sgit gives the files people say they cannot put on GitHub the history, branches and shareable links of git, on a server that holds ciphertext and nothing else.",
        "nodes": [
          {
            "id": "files-with-nowhere-to-live",
            "label": "Files with nowhere good to live",
            "kind": "concept",
            "summary": "A risk register with real system names, a regulatory analysis still being argued about, the working memory of an AI agent, client material under NDA."
          },
          {
            "id": "sgit",
            "label": "sgit",
            "kind": "artefact",
            "summary": "sgit is git for those files: encrypted before they leave your machine, versioned exactly like git, stored on a server that cannot read a single byte."
          },
          {
            "id": "zero-knowledge",
            "label": "Zero knowledge, precisely",
            "kind": "claim",
            "summary": "The server holds ciphertext and nothing else, not your filenames, not your directory structure, not your commit messages."
          },
          {
            "id": "no-recovery",
            "label": "No key escrow",
            "kind": "claim",
            "summary": "There is no key escrow, no admin override, no support engineer who can recover it for you, and that last part is a feature with a real cost."
          },
          {
            "id": "vault-key",
            "label": "Vault key",
            "kind": "concept",
            "summary": "A single string that is three things at once, the address of the vault, the authorisation to write to it, and the key that decrypts it."
          },
          {
            "id": "read-key",
            "label": "Read key",
            "kind": "concept",
            "summary": "Derived one way from the vault key, same vault, read-only, safe to publish, and that asymmetry is the whole sharing model."
          },
          {
            "id": "tripwire",
            "label": "Release tripwire",
            "kind": "artefact",
            "summary": "No vault key has ever been published, a rule enforced by a tripwire in the release pipeline that scans every file before either remote is touched."
          },
          {
            "id": "content-addressed-ciphertext",
            "label": "Content-addressed over ciphertext",
            "kind": "concept",
            "summary": "The object's name is a SHA-256 of the encrypted bytes, so the host can deduplicate it, cache it and serve it from a CDN while unable to tell you what it is."
          },
          {
            "id": "real-version-control",
            "label": "A real version control system",
            "kind": "claim",
            "summary": "Multi-parent commits, a tree per directory, deterministic refs derived by HMAC, a genuine merge-base computation and three-way merge, on content the server cannot interpret."
          },
          {
            "id": "nineteen-vaults",
            "label": "Nineteen vaults you can open",
            "kind": "example",
            "summary": "Every vault on sgit.ai is live, and cloning all nineteen from their published keys gave 1,389 files and no failures."
          },
          {
            "id": "capability-without-credential",
            "label": "Capability without credential",
            "kind": "concept",
            "summary": "A vault can contain an application that requests no permissions and still renders the whole risk graph, because the host reads the vault and passes results in."
          },
          {
            "id": "network-of-sites",
            "label": "The network of sites",
            "kind": "artefact",
            "summary": "sgit.ai is one of nineteen sites on *.sgit.ai, each taking one question further than a section could."
          },
          {
            "id": "checkable-not-impressive",
            "label": "Checkable rather than impressive",
            "kind": "claim",
            "summary": "Each site publishes its argument before the thing exists and states plainly what has shipped and what has not."
          }
        ],
        "edges": [
          {
            "from": "sgit",
            "to": "files-with-nowhere-to-live",
            "rel": "answers"
          },
          {
            "from": "sgit",
            "to": "zero-knowledge",
            "rel": "depends-on"
          },
          {
            "from": "zero-knowledge",
            "to": "vault-key",
            "rel": "depends-on"
          },
          {
            "from": "no-recovery",
            "to": "zero-knowledge",
            "rel": "extends"
          },
          {
            "from": "read-key",
            "to": "vault-key",
            "rel": "depends-on"
          },
          {
            "from": "read-key",
            "to": "vault-key",
            "rel": "contrasts"
          },
          {
            "from": "tripwire",
            "to": "vault-key",
            "rel": "depends-on"
          },
          {
            "from": "tripwire",
            "to": "read-key",
            "rel": "extends"
          },
          {
            "from": "content-addressed-ciphertext",
            "to": "zero-knowledge",
            "rel": "extends"
          },
          {
            "from": "real-version-control",
            "to": "sgit",
            "rel": "extends"
          },
          {
            "from": "real-version-control",
            "to": "content-addressed-ciphertext",
            "rel": "depends-on"
          },
          {
            "from": "nineteen-vaults",
            "to": "read-key",
            "rel": "example-of"
          },
          {
            "from": "nineteen-vaults",
            "to": "sgit",
            "rel": "depends-on"
          },
          {
            "from": "capability-without-credential",
            "to": "read-key",
            "rel": "compared-with"
          },
          {
            "from": "capability-without-credential",
            "to": "nineteen-vaults",
            "rel": "extends"
          },
          {
            "from": "network-of-sites",
            "to": "sgit",
            "rel": "extends"
          },
          {
            "from": "network-of-sites",
            "to": "checkable-not-impressive",
            "rel": "example-of"
          },
          {
            "from": "nineteen-vaults",
            "to": "checkable-not-impressive",
            "rel": "example-of"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/network/graphs.html",
            "/network/index.html",
            "/network/sg-sentinel.html",
            "/demos/vaults/index.html",
            "/admin/versions.html"
          ],
          "sites": [
            "https://graphs.sgit.ai/about/participant.html",
            "https://www.linkedin.com/pulse/git-things-you-cannot-put-github-dinis-cruz-qwrte/"
          ]
        },
        "quotes": [
          {
            "text": "Lose it and the data is gone. Leak it and someone can rewrite your history.",
            "why": "The two costs of a vault key being address, authorisation and encryption key at once."
          },
          {
            "text": "We would rather be checkable than impressive.",
            "why": "The house style that the live vaults, the version log and the NOT BUILT pages all follow."
          }
        ]
      }
    },
    {
      "slug": "seven-vaults-one-method",
      "title": "Seven vaults, one method",
      "date": "2026-08-19",
      "updated": "",
      "url": "https://sgit.ai/articles/seven-vaults-one-method.html",
      "markdown": "https://sgit.ai/articles/seven-vaults-one-method.md",
      "card": "https://sgit.ai/articles/cards/seven-vaults-one-method.webp",
      "teaser": "Publishing seven encrypted vaults in a fortnight produced a method, and every rule in it exists because something went wrong first.",
      "topics": [
        "vaults-and-method"
      ],
      "tags": [
        "vaults",
        "publishing",
        "method"
      ],
      "links_out": [],
      "links_in": [
        "custom-uis-are-not-the-exception"
      ],
      "graph": {
        "slug": "seven-vaults-one-method",
        "teaser": "Publishing seven encrypted vaults in a fortnight produced a method, and every rule in it exists because something went wrong first.",
        "topics": [
          "vaults-and-method"
        ],
        "core_idea": "A repeatable method for publishing encrypted vaults, each rule learned by getting something wrong first, starting with classifying the credential before it touches anything.",
        "nodes": [
          {
            "id": "classify-credential",
            "label": "Classify the credential",
            "kind": "method",
            "summary": "Classify the credential before it touches anything, because three of the seven vaults arrived as a vault key described as a read key."
          },
          {
            "id": "vault-key",
            "label": "Vault key",
            "kind": "concept",
            "summary": "A vault key is write access, and because it is also the address and the encryption root there is no revocation, no rotation, and no undo."
          },
          {
            "id": "read-key",
            "label": "Read key",
            "kind": "concept",
            "summary": "A read key is 64 hex characters, derived one-way from a vault key, and safe to publish."
          },
          {
            "id": "check-credential-script",
            "label": "check_credential.py",
            "kind": "artefact",
            "summary": "A script that classifies a credential by shape, exits 0 for publishable and 1 for stop, and never echoes what it was given."
          },
          {
            "id": "release-validator",
            "label": "Release validator tripwire",
            "kind": "artefact",
            "summary": "The release validator scans every tracked file for any key-shaped string and for the actual passphrases, and has caught its own author three times."
          },
          {
            "id": "derive-rather-than-refuse",
            "label": "Derive rather than refuse",
            "kind": "method",
            "summary": "A submission that cannot be published can still become one that can, by deriving the read key and putting the vault key in a gitignored tier."
          },
          {
            "id": "strictly-less-capability",
            "label": "Strictly less capability",
            "kind": "claim",
            "summary": "The whole shape of the project is a capability you can hand over that is strictly less than the one you hold, with the reduction enforced by mathematics rather than by policy."
          },
          {
            "id": "audit-with-published-key",
            "label": "Audit with the key you publish",
            "kind": "method",
            "summary": "Audit every file with exactly the credential a reader will have, not with the vault key."
          },
          {
            "id": "sealed-llm-credential",
            "label": "Sealed LLM credential check",
            "kind": "example",
            "summary": "One vault carried a sealed LLM credential, and attempting to open it with the published read key got InvalidTag from AES-GCM, so no budget was exposed."
          },
          {
            "id": "risk-graph-explorer",
            "label": "Risk Graph Explorer",
            "kind": "artefact",
            "summary": "The sixth vault was public by design, with its own PUBLIC.md whose third rule, no metered capability behind a published read key, was adopted into the guidance."
          },
          {
            "id": "drive-real-product",
            "label": "Capture evidence by driving the real product",
            "kind": "method",
            "summary": "Every screenshot is taken by opening the actual vault in a real browser with the published read key, and the rig grew an appProbe step to ask the app what its elements are called."
          },
          {
            "id": "describe-show-admit",
            "label": "Describe, show, then admit",
            "kind": "method",
            "summary": "Every vault page ends with what the vault does not do, as a section with the same weight as the features."
          },
          {
            "id": "publishing-playbook",
            "label": "Publishing playbook",
            "kind": "artefact",
            "summary": "The method is written down as a playbook aimed at another site's agent rather than at us, which was the real test of whether it was a method or just a habit."
          },
          {
            "id": "honest-ledger",
            "label": "The honest ledger",
            "kind": "claim",
            "summary": "Three vault keys caught, one budget exposure checked and cleared, one upstream rule adopted, and three bugs found by testing rather than assumption."
          }
        ],
        "edges": [
          {
            "from": "classify-credential",
            "to": "check-credential-script",
            "rel": "produces"
          },
          {
            "from": "check-credential-script",
            "to": "vault-key",
            "rel": "depends-on"
          },
          {
            "from": "check-credential-script",
            "to": "read-key",
            "rel": "depends-on"
          },
          {
            "from": "vault-key",
            "to": "read-key",
            "rel": "contrasts"
          },
          {
            "from": "release-validator",
            "to": "check-credential-script",
            "rel": "extends"
          },
          {
            "from": "derive-rather-than-refuse",
            "to": "classify-credential",
            "rel": "extends"
          },
          {
            "from": "derive-rather-than-refuse",
            "to": "read-key",
            "rel": "depends-on"
          },
          {
            "from": "derive-rather-than-refuse",
            "to": "strictly-less-capability",
            "rel": "example-of"
          },
          {
            "from": "audit-with-published-key",
            "to": "read-key",
            "rel": "depends-on"
          },
          {
            "from": "sealed-llm-credential",
            "to": "audit-with-published-key",
            "rel": "example-of"
          },
          {
            "from": "risk-graph-explorer",
            "to": "audit-with-published-key",
            "rel": "leads-to"
          },
          {
            "from": "drive-real-product",
            "to": "honest-ledger",
            "rel": "leads-to"
          },
          {
            "from": "sealed-llm-credential",
            "to": "honest-ledger",
            "rel": "leads-to"
          },
          {
            "from": "classify-credential",
            "to": "honest-ledger",
            "rel": "leads-to"
          },
          {
            "from": "publishing-playbook",
            "to": "classify-credential",
            "rel": "depends-on"
          },
          {
            "from": "publishing-playbook",
            "to": "audit-with-published-key",
            "rel": "depends-on"
          },
          {
            "from": "publishing-playbook",
            "to": "drive-real-product",
            "rel": "depends-on"
          },
          {
            "from": "publishing-playbook",
            "to": "describe-show-admit",
            "rel": "depends-on"
          },
          {
            "from": "describe-show-admit",
            "to": "strictly-less-capability",
            "rel": "extends"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/demos/vaults/algarve-may-2026/index.html",
            "/demos/vaults/field-notes/index.html",
            "/demos/vaults/supplement-stack/index.html",
            "/demos/vaults/risk-mandate/index.html",
            "/demos/vaults/agentic-browser-isolation/index.html",
            "/demos/vaults/risk-graph-explorer/index.html",
            "/catalogue/index.html",
            "/demos/vaults/publishing.html",
            "/docs/limitations.html",
            "/compare/index.html"
          ],
          "sites": []
        },
        "quotes": [
          {
            "text": "Which is the point: a rule that only catches other people is not a rule.",
            "why": "The tripwire catching its own author is what turns a habit into a control."
          },
          {
            "text": "A published vault is an argument that this way of working is sound; an argument that omits its own edges is a brochure.",
            "why": "The reason every vault page ends with what the vault does not do."
          }
        ]
      }
    },
    {
      "slug": "green-does-not-mean-live",
      "title": "Green does not mean live",
      "date": "2026-08-17",
      "updated": "",
      "url": "https://sgit.ai/articles/green-does-not-mean-live.html",
      "markdown": "https://sgit.ai/articles/green-does-not-mean-live.md",
      "card": "https://sgit.ai/articles/cards/green-does-not-mean-live.webp",
      "teaser": "Two releases passed every check and never reached the site because the checks stopped at the git remote; a release now ends by asking the live site its version.",
      "topics": [
        "site-and-engineering"
      ],
      "tags": [
        "ci",
        "deploy",
        "verification"
      ],
      "links_out": [],
      "links_in": [
        "the-investigation-github-owes-its-customers"
      ],
      "graph": {
        "slug": "green-does-not-mean-live",
        "teaser": "Two releases passed every check and never reached the site because the checks stopped at the git remote; a release now ends by asking the live site its version.",
        "topics": [
          "site-and-engineering"
        ],
        "core_idea": "Shipped is a fact about the reader, not about your repository, so a release has to verify the boundary the reader is on and not only the ones the repository can see.",
        "nodes": [
          {
            "id": "two-releases-missed",
            "label": "Two releases that never reached anybody",
            "kind": "example",
            "summary": "Two consecutive releases pushed cleanly, printed both remotes in sync, and the site served a two-release-old page for forty minutes until a human on a phone asked if it was the latest version."
          },
          {
            "id": "version-badge",
            "label": "The version badge",
            "kind": "artefact",
            "summary": "The badge on the home page that a human looked at to notice the miss, and that the release now polls for the new version."
          },
          {
            "id": "wrong-boundary",
            "label": "Checking the wrong boundary",
            "kind": "claim",
            "summary": "The checks were not weak; they were checking the wrong boundary."
          },
          {
            "id": "release-script-steps",
            "label": "What the release actually verified",
            "kind": "method",
            "summary": "Build the site, run the validator, commit and push the encrypted vault and confirm sync, commit and push the git mirror and confirm HEAD equals origin/dev."
          },
          {
            "id": "bytes-arrived-not-readable",
            "label": "The bytes arrived at GitHub",
            "kind": "concept",
            "summary": "HEAD == origin/dev compares hashes, not hopes, but it means the bytes arrived at GitHub, not that anybody can read them."
          },
          {
            "id": "three-boundaries",
            "label": "Three boundaries, two verified",
            "kind": "concept",
            "summary": "Source to git remote, git remote to Pages deploy, Pages deploy to the reader; a GitHub Actions job sits in the unverified gap and reports into a system neither remote knows about."
          },
          {
            "id": "deploy-job-failure",
            "label": "What actually failed",
            "kind": "example",
            "summary": "The deploy job died in Set up job because codeload.github.com rate-limited the download of actions/configure-pages with a 429, while the validate and tag-release jobs passed."
          },
          {
            "id": "shared-infrastructure-breaks",
            "label": "The most likely thing to break is not your code",
            "kind": "claim",
            "summary": "It is a piece of shared infrastructure you do not run, on a day you were not thinking about it."
          },
          {
            "id": "live-version-check",
            "label": "Ask the live site what version it is serving",
            "kind": "method",
            "summary": "A release now polls sgit.ai with a cache-buster for the new version, up to eight minutes, and aborts loudly if it never appears, naming the Actions page."
          },
          {
            "id": "shipped-is-about-the-reader",
            "label": "Shipped is a fact about the reader",
            "kind": "claim",
            "summary": "Shipped is a fact about the reader, not about your repository."
          },
          {
            "id": "three-unpublished-rules",
            "label": "Three rules of the same shape",
            "kind": "method",
            "summary": "A page nothing links to, a page the machine index omits, and a page the deploy never served are all unpublished, and the build or the release fails on each."
          },
          {
            "id": "what-it-does-not-fix",
            "label": "What this does not fix",
            "kind": "question",
            "summary": "It detects a failed deploy but does not repair one, it checks only the home page's badge so a partial deploy would pass, and it adds up to eight minutes to every release."
          }
        ],
        "edges": [
          {
            "from": "two-releases-missed",
            "to": "wrong-boundary",
            "rel": "leads-to"
          },
          {
            "from": "two-releases-missed",
            "to": "version-badge",
            "rel": "depends-on"
          },
          {
            "from": "release-script-steps",
            "to": "bytes-arrived-not-readable",
            "rel": "produces"
          },
          {
            "from": "wrong-boundary",
            "to": "bytes-arrived-not-readable",
            "rel": "depends-on"
          },
          {
            "from": "three-boundaries",
            "to": "wrong-boundary",
            "rel": "extends"
          },
          {
            "from": "deploy-job-failure",
            "to": "three-boundaries",
            "rel": "example-of"
          },
          {
            "from": "deploy-job-failure",
            "to": "shared-infrastructure-breaks",
            "rel": "example-of"
          },
          {
            "from": "wrong-boundary",
            "to": "live-version-check",
            "rel": "leads-to"
          },
          {
            "from": "shared-infrastructure-breaks",
            "to": "live-version-check",
            "rel": "leads-to"
          },
          {
            "from": "live-version-check",
            "to": "release-script-steps",
            "rel": "extends"
          },
          {
            "from": "live-version-check",
            "to": "version-badge",
            "rel": "depends-on"
          },
          {
            "from": "live-version-check",
            "to": "three-unpublished-rules",
            "rel": "example-of"
          },
          {
            "from": "three-unpublished-rules",
            "to": "shipped-is-about-the-reader",
            "rel": "depends-on"
          },
          {
            "from": "shipped-is-about-the-reader",
            "to": "wrong-boundary",
            "rel": "extends"
          },
          {
            "from": "what-it-does-not-fix",
            "to": "live-version-check",
            "rel": "extends"
          }
        ],
        "links": {
          "articles": [],
          "pages": [
            "/admin/versions.html"
          ],
          "sites": [
            "https://github.com/SGit-AI/SGit-AI__CLI"
          ]
        },
        "quotes": [
          {
            "text": "The checks were not weak. They were checking the wrong boundary.",
            "why": "The diagnosis: strong checks on the wrong side of the deploy."
          },
          {
            "text": "All three are the same claim: shipped is a fact about the reader, not about your repository.",
            "why": "The general rule the fix joins, learned from three failures of the same shape."
          }
        ]
      }
    }
  ]
}
