for agents/llms.txtv0.7.35 · 10 Oct 2026

Home / Articles / The Mandate Stack / Versions / v1.2.0

The Mandate Stack: what changed in v1.2.0

From v1.1.0 (2026-10-06, 692b79842) to v1.2.0 (2026-10-07, bd3c50797), paragraph by paragraph.

9 paragraphs added, 0 removed, 12 changed in place, 107 unchanged. About 853 words added and 0 removed. Insertions are marked like this, deletions like this; unchanged runs are folded to one line; figures appear as their file names.

← v1.1.0 · all versions · v1.2.1 →

1 unchanged paragraph

Summary: RiskMandate runs its business with about fifteen agents and one person, everyfour fewtimes hours,a day on a schedule and whenever the person sits down with them, with the person's name on every message that leaves. The agent that runs its CRM wrote the briefing this article is built from. The system is described in eight layers, from rented compute and channels, through encrypted vaults as shared memory, domain vaults, semantic graphs over people and policies, a scheduled conductor and written behaviour policies, to a human who holds the one step that cannot be undone. The article follows an input from the outside world through the layers to the person who sends,sends; explains why the vault is an app platform rather than storage, and the loop in which a friction becomes a tool in the same session and the tools compound; names the feedback loop that makes the setup hold, the draft as a release candidate with the recipient closing the loop,loop; and draws two Wardley maps with Mermaid, from the outside and from the inside, showing what the team is turning into a commodity and what it is turning into a product. Every layer is linked to the article or document on this site where it was worked out. The published record of agent projects that stall is kept for the end, each reason mapped to the mechanism that answers it. TheEverything namedescribed is ain working one, and nothing planned is included.use.

!shot ms-stack.webp | images/ | The Mandate Stack as it runs on 6 October 2026, read from the bottom: compute and channels rented from vendors, then the team's own files, graphs, schedule and policies, then one person.person above a line of their own. The right column says what each layer gives the team. Infographic from the CRM agent's briefing; nothingeverything plannedshown is included.in use.

> Where this comes from. The agent that runs RiskMandate's CRM wrote a briefing on 6 October 2026, from Dinis Cruz's voice notes and the team's collaboration vault, for anyone, person or agent, who writes about the setup. It describes what runs on that datedate, and includeseverything nothingin planned.it is in use. This article keeps its structure and its counts and links every layer to the place on this site where it was worked out. The agent team as it runs, published the same week, is the roster-level description of the same team; this is the layered one. "The Mandate Stack" is the briefing's working name for the pattern, and a better one may replace it.

1 unchanged paragraph, under In short

• This runs. About fifteen agents and one person run RiskMandate's relationships, research, writing and events, everyfour fewtimes hours,a day on a schedule and whenever Dinis sits down with them, in production, today.

3 unchanged paragraphs

• The vault is an app platform, not storage. A model that writes good HTML and a vault that serves it give one person a loop: hit a friction, build the tool in the same session, deploy it into the vault, use it, repeat. The tools compound, down to an interface for one person. Without that loop, this would be another project that stalled.

37 unchanged paragraphs, under One that runs, From the outside in, Layer 1: compute…

The conductor runs onfour times a schedule.day. It opens a run, takes a lock, gives each agent one step in a fixed order, records evidence in a runs folder, briefs Dinis and stops. The order is security first, then drafts, inbox, briefs, CRM, the event mission, research, dev, and security last. Drafts owed to Dinis are made before anyone else acts; contact folders are brought up to date before the briefs and the CRM use them; security opens so that a hold stops the run before any agent moves, and closes so that what the run changed is reviewed. TheOn briefing gives the cadence as every four hours; The agent team as it runs and the walkthrough give it as four runs a day on weekdays. Both are the agents' descriptionstop of the four scheduled runs, every session Dinis starts with an agent does the same schedule.kind of work sooner, so in practice the team is active far more often than the schedule alone would make it.

12 unchanged paragraphs, under Layer 7: governance, Layer 8: the human

The vault is not storage: the tool loop

[figure ms-tool-loop.webp] Read, eval, print, loop, applied to a business: a friction, a request in the session, a tool as HTML, deployed into the vault, used and corrected. The loop stops when a piece of work no longer calls for a tool. Below: apps already deployed into vaults on this site.

The layers above could be read as a storage architecture with a CRM on top. That is not what makes them work. The vault is an application platform: a folder of files the host cannot read, served as a web app by the vault host, so that anything a model can write as HTML can be deployed by committing it. Building vault apps is the contract, and three surfaces is the choice between a page inside the vault, a vault app and a page on a site.

Put that beside a model that writes good interfaces, and one person gets a loop. Something is hard to see at a glance: who has the ball, what a person's graph looks like, which messages are owed. Ask for a view of it, in the same session, from the same files. The model builds the tool as HTML, sized to the one use case. It is committed and pushed, and the next session, on any account, has it. It is used on real work, and what it gets wrong goes back to the start. Read, eval, print, loop, applied to a business rather than to a line of code.

Three things follow. The tools compound: the team's own interfaces, the team picture drawn from open Email-FS messages, the session card, the hold shown on every page, the onboarding script, came out of the same loop as the CRM's. The interfaces go down to the person: a contact can have a view of their own, and some do, because building it costs a session rather than a project, and because the record it reads from is a graph with its edges written down. And research is the same loop pointed at a question: extract the data, build the graph, map it, analyse it, which is why a research agent exists. A data-science agent would join the same way; there is not one today.

The loop has a natural stop. A piece of work is mature when it no longer calls for a tool. That is the commoditising arrow in the second map below: once a view is boring, it is done, and the next friction is somewhere else. Most of what the stack does was possible before with a bigger team, and much of it has been done before. The loop is what makes it possible for one person, and it is why the setup kept growing instead of stalling.

The pattern is already on this site in other clothes. Custom UIs are not the exception makes the argument for the inbox, where every message gets the interface for its moment. The vaults in the business plans section each carry an app built this way: the Deck Vault, eight web components bundled into one page; the evidence vault behind How much of this did I write?; the connector twin with its replay; the risk graph explorer; Kit Bag, a browser extension shipped in a vault. The code review navigator in the review-folder brief is the same move for repositories. Twenty sites in fifteen days is what the loop did to a network of websites.

11 unchanged paragraphs, under The feedback loop: the draft is pre-production, Two maps: what is being commoditised, and what is being made

!source Map one, the Mermaid wardley-beta source | images/ms-map-user.webp `` wardley-beta title The Mandate Stack from the outside: a person who writes to the team anchor "A person who writes to the team" [0.97, 0.60] component "A reply with Dinis's name on it" [0.89, 0.38] component "The agents' address" [0.87, 0.86] component "The subscribe form" [0.82, 0.66] component "Drafts role" [0.74, 0.38] component "Inbox capture, hashed" [0.68, 0.48] component "The person's folder and graph" [0.60, 0.28] component "Agent Behaviour Policies" [0.52, 0.20] component "Conductor" [0.47, 0.40] component "Email-FS" [0.41, 0.34] component "Append lanes" [0.45, 0.54] component "sgit vaults, shared memory" [0.32, 0.64] component "Claude sessions" [0.27, 0.76] component "Google Workspace" [0.24, 0.90] component "Encrypted storage, S3" [0.12, 0.88] "A person who writes to the team" --> "A reply with Dinis's name on it" "A person who writes to the team" --> "The agents' address" "A person who writes to the team" --> "The subscribe form" "A reply with Dinis's name on it" --> "Drafts role" "The agents' address" --> "Inbox capture, hashed" "The agents' address" --> "Google Workspace" "The subscribe form" --> "Append lanes" "Drafts role" --> "The person's folder and graph" "Inbox capture, hashed" --> "The person's folder and graph" "Drafts role" --> "Agent Behaviour Policies" "Inbox capture, hashed" --> "Agent Behaviour Policies" "Drafts role" --> "Conductor" "Inbox capture, hashed" --> "Conductor" "Conductor" --> "Email-FS" "Conductor" --> "Claude sessions" "Email-FS" --> "sgit vaults, shared memory" "Append lanes" --> "sgit vaults, shared memory" "The person's folder and graph" --> "sgit vaults, shared memory" "sgit vaults, shared memory" --> "Encrypted storage, S3" "Drafts role" --> "Google Workspace" ``

!shot ms-map-team.webp | images/ | Map two, from the inside. The anchor is Dinis. The dashed arrows are the movement the team is making: shared memory and the sgit CLI toward commodity, the behaviour policiespolicies, the graphs and the graphscustom interfaces from genesis toward product. Everything rests on encrypted storage, which is already a commodity. Rendered with Mermaid wardley-beta from the source below.

The second map takes Dinis's point of view and adds movement. What he sees is a CRM that is current without typing, drafts to review andreview, decision drafts in the thread.thread, and the custom interfaces the tool loop produces. The arrows say what the team is doing to its own components. Shared memory runs on sgit, and sgit runs on encrypted object storage, S3. Each of those is being pushed to the right on purpose, so that a vault is a folder, a push is a command, the host sees ciphertext and sizes, and nothing above them has to know how any of it works. The behaviour policies andpolicies, the graphs over people and the custom interfaces move the other way, from genesis toward custom and product, because those are the parts the team is building to sell. The commodity underneath is what makes the custom layer on top affordable.

!source Map two, the Mermaid wardley-beta source | images/ms-map-team.webp `` wardley-beta title The Mandate Stack from the inside: the person running the business, and what is moving anchor "Dinis, running the business" [0.97, 0.50] component "A CRM that is current without typing" [0.90, 0.30] component "Drafts to review and send" [0.87, 0.52] component "Decision drafts in the thread" [0.83, 0.40] component "Custom UIs per use case" [0.79, 0.26] component "Semantic graphs over people" [0.74, 0.24] component "Agent Behaviour Policies" [0.68, 0.20] component "Security role and hold" [0.63, 0.28] component "Conductor" [0.59, 0.42] component "Email-FS" [0.52, 0.34] component "Mission vaults" [0.46, 0.50] component "sgit vaults, shared memory" [0.38, 0.62] component "sgit CLI" [0.26, 0.58] component "Claude sessions" [0.30, 0.76] component "Google Workspace" [0.28, 0.90] component "Encrypted storage, S3" [0.14, 0.88] evolve "Agent Behaviour Policies" 0.50 evolve "Semantic graphs over people" 0.42 evolve "Email-FS" 0.56 evolve "Custom UIs per use case" 0.44 evolve "sgit vaults, shared memory" 0.84 evolve "sgit CLI" 0.80 "Dinis, running the business" --> "A CRM that is current without typing" "Dinis, running the business" --> "Drafts to review and send" "Dinis, running the business" --> "Decision drafts in the thread" "Dinis, running the business" --> "Custom UIs per use case" "Custom UIs per use case" --> "sgit vaults, shared memory" "Custom UIs per use case" --> "Claude sessions" "A CRM that is current without typing" --> "Semantic graphs over people" "Drafts to review and send" --> "Conductor" "Decision drafts in the thread" --> "Conductor" "Semantic graphs over people" --> "sgit vaults, shared memory" "Conductor" --> "Agent Behaviour Policies" "Conductor" --> "Security role and hold" "Conductor" --> "Email-FS" "Conductor" --> "Claude sessions" "Security role and hold" --> "Agent Behaviour Policies" "Email-FS" --> "sgit vaults, shared memory" "Mission vaults" --> "sgit vaults, shared memory" "Semantic graphs over people" --> "Mission vaults" "sgit vaults, shared memory" --> "sgit CLI" "sgit vaults, shared memory" --> "Encrypted storage, S3" "Drafts to review and send" --> "Google Workspace" ``

12 unchanged paragraphs, under Why it holds, A working name, What is not in it

Nothing planned. The briefing's rule, and this article's, is that everyEvery component named above is in use on the date of writing.writing; that was the briefing's rule and it is this article's. What is not in it is the list of things the team knows it lacks. The things The agent team as it runs lists as not working yet still apply: commit authorship is not signed, so an agent's identity inside a shared vault is its branch rather than a signature; a vault key cannot be revoked, only replaced by a new vault; most barriers are policy-only, enforced by the process they constrain, and a separate permission authority that holds the credentials and decides each action does not exist in this setup. The three wishes in Why my agents do not run on my laptop, an identity, a secret store and a key pair per agent, are the platform-side half of the same list.

22 unchanged paragraphs, under The record, for anyone who asks why this is worth writing down, Threads woven here

• Building vault apps, three surfaces and the review-folder brief: the contract the tool loop deploys against, and the same loop applied to repositories. Twenty sites in fifteen days: the loop applied to websites.

3 unchanged paragraphs, under Sources

• TwoThree voice notes by Dinis Cruz, 6 and 7 October 2026: on the complaint that agentic workflows do not reach production and on the name; and on leading with the system, the flow from the outside world, and the maps.maps; and on the vault as an app platform, the tool loop, the schedule of four runs a day, and the source blocks.

4 unchanged paragraphs

*Drafted from a briefing written by the RiskMandate CRM agent (@crm.2, v0.3, 6 October 2026) from Dinis Cruz's voice notes and the team's collaboration vault, and from twothree voice notes by Dinis Cruz, who is the author of the argument and the person with editorial responsibility, by agent@riskmandate.ai (Claude Fable 5.1, claude-fable-5-1) in the sgit.ai site session, on 6 October 2026. The figures are infographics drawn from the briefing with fictional names and sample content, and two Wardley maps rendered with Mermaid from the sources printed above; no contact is named beyond the agents' published address, and no key or token appears in any figure or file. Figures from reports and surveys are quoted with their dates and sample sizes where the source gave them.*

1 unchanged paragraph

← v1.1.0 · all versions · v1.2.1 →