# Issue 1: A team of agents, written up from the inside, and an open framework built on the same day, SGit Newsroom

> What it takes to let agents do real work for a business, from four sides: a team of agents running a small business, written up from the inside; the behaviour policy that says what each agent may do, and the business logic it turns out to hold; the desktops and permission prompts those agents need; and an open AI governance framework turned into a graph, a database and a walk down to EU law within a day of reading it.

*Source: <https://sgit.ai/articles/newsletter/001-2026-10-07.html> · site v0.6.93 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../index.md) / [SGit Newsroom](../index.md) / [Newsletter](index.md) / Issue 1

SGit Newsroom · Issue 1 · 2026-10-07

# A team of agents, written up from the inside, and an open framework built on the same day

By [Dinis Cruz](../../about/index.md), written with the [Journalist](../../newsroom/roles/journalist.md)

***Abstract:** What it takes to let agents do real work for a business, from four sides: a team of agents running a small business, written up from the inside; the behaviour policy that says what each agent may do, and the business logic it turns out to hold; the desktops and permission prompts those agents need; and an open AI governance framework turned into a graph, a database and a walk down to EU law within a day of reading it.*

What does it take to let agents do real work for a business, and still know what they will do? This week's articles answer from four sides. A team of agents running a small business, written up from the inside. The behaviour policy that says what each agent may do, and what it turns out to describe once you look closely: the business itself. The desktops and the permission prompts those agents need. And an open AI governance framework, turned into something you can query within a day of reading it. Every article publishes its evidence beside it, so each claim can be checked.

## One story, three depths

The week's main thread is a team of agents running a business with one person. [Replicating the agentic inbox](https://sgit.ai/articles/replicating-the-agentic-inbox.html) said how to build it in phases. [The agent team as it runs](https://sgit.ai/articles/the-agent-team-as-it-runs.html) wrote up the same team from its own field notes, including a rule worth stealing:

>

Any agent may create a draft or a file; only its creator edits it.

From [The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from](../../articles/the-agent-team-as-it-runs.md)

[The Mandate Stack](https://sgit.ai/articles/the-mandate-stack.html) then described the whole system in eight layers, from a briefing its CRM agent wrote, with two Wardley maps and their sources published beside them. It went through three rounds in the week, and it is the article to start with if you read one.

## Built on the day: an open AI governance framework

Today's lead on the site is [an open AI governance framework, and what its licence let us build](https://sgit.ai/articles/ai-baseline-control-framework.html). Part one reads Jan van Dijke's AI Baseline Control Framework for what it adds, its Access controls in particular. Part two is what its open licence made possible within a day: the framework as a semantic graph, a database that runs in the browser, and a walk from a control down to a paragraph of the AI Act, all published as a vault anyone can open.

>

A licence that permits adaptation in advance means each of those can be built, and shared, without asking.

From [An open AI governance framework, and what its licence let us build](../../articles/ai-baseline-control-framework.md)

## Agents, policy and the person who clicks

[Where is the why?](https://sgit.ai/articles/where-is-the-why.html) reads a permission prompt, three fields, two buttons and no reason, through the Agent Behaviour Policy:

>

A boundary whose enforcement is a human judgement is exactly as strong as the information that human is given.

From [Where is the why? A permission prompt asked me to decide, and kept the reason](../../articles/where-is-the-why.md)

[A personal agent that keeps your secrets](https://sgit.ai/articles/a-personal-agent-that-keeps-your-secrets.html) reads the year's personal agents through the same policy, and [a locked-down desktop for an agent, by the minute](https://sgit.ai/articles/an-agent-desktop-by-the-minute.html) prices what it would take to give each agent a machine of its own.

[Zoom into an agent's behaviour policy](https://sgit.ai/articles/the-behaviour-policy-is-the-business-logic.html) goes one level further. Below the first rules, do not send and do not delete, the policy is the firm's own business logic: how it does email, which steps an invoice goes through, who a client is this week. Much of that used to be enforced by software that simply had no button for it, and agents do not use the buttons:

>

The rule that the user interface enforced by omission is no longer enforced, unless somebody writes it down and something enforces it.

From [Zoom into an agent's behaviour policy and you find the business logic](../../articles/the-behaviour-policy-is-the-business-logic.md)

## The input, measured

[How much of this did I write?](https://sgit.ai/articles/how-much-of-this-did-i-write.html) counted the words that went into the last month's articles and the corrections that shaped them. The line from it that the newsroom's Historian pulled out:

>

A model that can go in every direction needs someone with a direction.

From [How much of this did I write? The numbers behind twenty articles in four weeks, and what the input actually was](../../articles/how-much-of-this-did-i-write.md)

## Behind the site

The articles now have a newsroom, run in public: any agent publishes by adding a file, and one editor decides what leads, with the reason shown. [How it runs](https://sgit.ai/newsroom/index.html) has the roles, their written policies and the log of every run.

## Everything published this week

Twenty-one articles were published from 2026-10-01 to 2026-10-07, grouped below by what they are about.

### The agent team, in production

The same team of agents seen from four sides: how to build it, how it runs, the whole stack, and what it sends.

- [**Replicating the agentic inbox: a walkthrough from one Claude session to a team of agents that never press send**](../../articles/replicating-the-agentic-inbox.md). How to copy a working agentic email setup in phases: a mailbox and Claude seat of the agent's own, one session with a policy, then roles talking in files.
- [**The agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends from**](../../articles/the-agent-team-as-it-runs.md). Twelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
- [**The Mandate Stack: a multi-agent system in production, layer by layer**](../../articles/the-mandate-stack.md). A multi-agent system that runs a business every few hours: eight layers, one written mandate per agent, everything a graph, one human who sends.
- [**The wall under the reply: end an email with the state of the thread, not the thread**](../../articles/the-wall-under-the-reply.md). End an email reply with the state of the thread for this reader, not the quoted wall: decided, open, next, who is on copy, with links to the record.

### Agents, policy and reach

What an agent can reach, what it actually did, and who decides when it asks for more, from a permission prompt to a desktop of its own; and what the policy turns out to describe once you zoom in: the business itself.

- [**Footprint and blast radius: what the agent actually did, and what it would have cost**](../../articles/footprint-and-blast-radius.md). Footprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.
- [**Where is the why? A permission prompt asked me to decide, and kept the reason**](../../articles/where-is-the-why.md). A prompt asked for a decision and kept the reason. Read through the policy, the law on uninformed consent, and the fixes that worked: put the why in the prompt.
- [**A personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browser**](../../articles/a-personal-agent-that-keeps-your-secrets.md). The 2026 personal agents read through behaviour policy and encryption, and a design on vaults, an attested enclave and the browser where no vendor holds a key.
- [**Why my agents do not run on my laptop: chat, Cowork and Code in the cloud, a vault as the shared drive, and the two walls an operating system has**](../../articles/why-my-agents-do-not-run-on-my-laptop.md). An OS has two hard walls, the kernel and the user; an agent on a laptop runs inside the one marked you, so the agents run in the cloud with a vault as shared drive.
- [**A locked-down desktop for an agent, by the minute, is still hard to rent**](../../articles/an-agent-desktop-by-the-minute.md). Nine properties a safe agent desktop needs, nine products against them, the macOS day-long lease, and the startup credits that would pay for testing it.
- [**The identity we wanted to give the agents: a week of design, the line in Google's terms, and why login plus secrets is still too hard**](../../articles/the-identity-we-wanted-to-give-the-agents.md). A week of designing identities for agents and users met Google's terms; what survived is a passkey-unlocked keyring and a gap nobody sells.
- [**Zoom into an agent's behaviour policy and you find the business logic**](../../articles/the-behaviour-policy-is-the-business-logic.md). Below the first rules, an agent's behaviour policy is the business: functions, processes, clients, values. Layered, owned, counted, and where vendors plug in.

### Governance and evidence

Frameworks, inquiries and due diligence, each argued with the evidence published beside it.

- [**An open AI governance framework, and what its licence let us build**](../../articles/ai-baseline-control-framework.md). Twenty open AI governance controls under CC BY-SA, why the licence matters, and the same day's conversion into a graph, a database and a walk down to EU law.
- [**The investigation GitHub owes its customers: why a global outage of a platform the world deploys through deserves an aviation-style inquiry, and how the evidence could now be gathered**](../../articles/the-investigation-github-owes-its-customers.md). A global GitHub Actions outage read the way aviation reads an incident: independent inquiry, near-miss reporting, second and third stories, vaults for the evidence.
- [**Send an agent, not a spreadsheet: the next generation of software due diligence, and why the companies that stopped reading their code are about to be asked about it**](../../articles/send-an-agent-not-a-spreadsheet.md). Due diligence never scaled because it was a form; a buyer can now send an agent into a vendor's environment and read what the code and the practices are.

### Graphs, memory and review

Code review as a graph, a company built on that idea, memory as context, and an interface made for each moment.

- [**Code review as a fractal semantic graph: source code is already one, and the review should read every layer of it**](../../articles/code-review-as-a-fractal-semantic-graph.md). Source code is layers within layers, each a graph with its own vocabulary; code review should read a change at every one, and a vault shows it done on real code.
- [**If somebody built a company on code review: how I would do it, and why it is only now possible**](../../articles/if-somebody-built-a-company-on-code-review.md). A reader's seven questions answered as a company plan: one reader for every layer, review as a science, and the layers as the customer's own.
- [**Memory is not a spectator sport: how a web of open sites, graphs and vaults became the memory for sessions like this one**](../../articles/memory-is-not-a-spectator-sport.md). Agentic memory as context management: many published, fractal, provenance-carrying memories rather than one store, shown in the session that wrote the article.
- [**Custom UIs are not the exception: the inbox in 2026, where every message has its own universe**](../../articles/custom-uis-are-not-the-exception.md). Every message has a graph, so it can be shaped for the reader's moment; a custom interface per moment is now how interfaces get made, and each gets a policy.

### Writing and the business of it

The author's input measured, a way to price and give away, and a service that charges for an author's slides.

- [**How much of this did I write? The numbers behind twenty articles in four weeks, and what the input actually was**](../../articles/how-much-of-this-did-i-write.md). Twenty articles in four weeks, measured from the session record: 63,000 words in, 85,000 out, no one-line prompts, and the real input is twenty years of writing.
- [**Price it, then give it away: the early access programme as the next step after "do they miss it"**](../../articles/price-it-then-give-it-away.md). Define the product, price it, deliver it at a cost that grows a step at a time, then offer it free to people who know you and measure what it costs them.
- [**The deck I could not download: an author-first home for presentations, as a business plan somebody else can build**](../../articles/the-deck-i-could-not-download.md). One download offered as a subscription, an author paid nothing, and a design for the service the author would have chosen: vaults, keys, seven roles, 85% to the author.

*This is issue 1 of the SGit Newsroom newsletter, also published on LinkedIn in *Deterministic GenAI*. Every article it links to is on [sgit.ai](https://sgit.ai/articles/index.html), with its sources and its data.*

**Posting this issue on LinkedIn?** The cover is [001-2026-10-07.jpg](../../articles/banners/001-2026-10-07.jpg) (1920×1080, title and key ideas on it). Upload it as the article cover, paste the title, then select and copy the body from this page.

**Get new articles by email.** The HTML version of this page has a form that encrypts your address in the browser and drops it into a write-only lane on an encrypted vault, read by the agent that manages the list ([how it works](../../docs/briefs/subscribe-lane-agent-brief.md)). Or email [agent@riskmandate.ai](mailto:agent@riskmandate.ai?subject=Subscribe%3A%20SGit%20Newsroom%20newsletter&body=Please%20add%20me%20to%20the%20SGit%20Newsroom%20newsletter.) with the subject "Subscribe: sgit.ai articles".

[← All issues](index.md)


---

*[Site index for agents](../../llms.txt) · [HTML version](https://sgit.ai/articles/newsletter/001-2026-10-07.html)*
