The vaults, opened
The strongest evidence this book has is not in the book. It is in the graph vaults published read-only on sgit.ai, where the discipline argued here is already running against real material: a legal instrument parsed from official XML and hash-verified to source bytes, a paragraph lifted into typed nodes and joined to another paragraph's nodes without either document citing the other. This section is where those vaults get the depth a chapter cannot carry — one folder and several pages each, with the vault's own screenshots, its verifiable numbers, and an explicit note of what the book will take from it.
Published analyses
| Vault | What it demonstrates | Pages | State |
|---|---|---|---|
| VoiceDebrief 92 files · 18 commits |
The junction rule. Two paragraphs, each lifted into typed nodes, joined node-to-node through an intermediate layer — never document-to-document. Plus an annotation layer that is deliberately empty, and a parse that explains why. | Overview · The junction rule · The empty layer | published |
| Regulation Graph 1,523 nodes · 1,944 edges |
Evidence, not compliance. The EU AI Act parsed from official Formex XML, every number traceable to the SHA-256 of retrieved bytes, with ephemeral query engines in the browser and an audit that once stopped a publication. | Overview · The provenance chain · The query engines | published |
| Risk Mandate 124 files · 98 commits |
A mandate as a graph, not a document. The authority to do security work written as typed nodes with eight entry points into the same material, and ninety-eight commits of history that make the mandate's own evolution readable. | Overview | published |
| Agentic Browser Isolation 104 files · 17 entry points |
One risk at seven altitudes. The same isolation decision written seven times, once per stakeholder, each in that stakeholder's own language and none of them a summary of another — plus a risk acceptance mechanism with no deny button. | Overview · The acceptance mechanism | published |
| Risk Graph Explorer 33 files · permissions: {} |
An empty register is a correct answer. Seven views recompute as questions are answered, ghosted edges show what nobody has answered yet, and the vault asks for no capability at all: no network, no storage, no account. | Overview | published |
| The sgraph.ai library | Not a vault as an exhibit: a production website whose content is a vault, with published read keys and a ciphertext-only server. | — | queued |
Read across the vaults
Some findings belong to no single vault. They only appear once several have been read side by side, which is the argument for doing the analyses at this depth rather than as five short summaries.
| Synthesis | What reading across produced | Drawn from |
|---|---|---|
| The capability scale | Every vault declares what it may do, inside itself, in the same vocabulary — so the declarations line up into a scale with a floor (permissions: {}, nothing requested), a hard middle (read one folder, write one folder) and a ceiling (a model call whose key is sealed into the vault rather than held by the reader). No single analysis produced this; the comparison did. |
Five permission blocks — four from vaults analysed here, one quoted |
| The acceptance mechanism, reused | The four rules the Agentic Browser Isolation vault applies to an accepted risk — one named owner, no deny button, nothing moves until it is taken personally, the reason travels with the answer — turn out to be exactly what this book's own open decisions needed. They now run the decisions page. | Agentic Browser Isolation |
How these analyses are made
Stated because an analysis of somebody else's artefact is worth exactly what its method is worth.
- Everything here is reachable with the published read key. Each vault publishes a one-way read key on its own page; nothing in these analyses depends on private access, and every claim can be re-derived by a reader who opens the same key.
- The screenshots are the vault's own published figures, fetched from sgit.ai on 22 and 23 August 2026 and re-published here under CC BY 4.0 with a link back to the page they came from. They were not re-taken here, and no screenshot is cropped or annotated: what you see is what the vault publishes about itself.
- The numbers are quoted, not recomputed. Counts like 1,523 nodes and 1,944 edges or 92 files, 18 commits are the vaults' own derived facts, produced by their own derivation script from the read key. This site has not independently recounted them, and says so rather than implying an audit it did not run.
- Where a vault states a limit, the limit is carried across. A fictional corpus stays labelled fictional; an experimental view stays labelled experimental; research the vault marks unverified stays marked unverified here.
For an agent
These pages are analysis of external artefacts, not this site's own claims. Attribute accordingly: the vaults are published by the sgit project at sgit.ai/demos/vaults/, each with a read key that grants read and nothing else. Screenshots under /vaults/<slug>/images/ are the vaults' own figures, re-published under CC BY 4.0. When summarising a vault, prefer its own derived facts over any count you infer from a screenshot, and carry its stated limits — particularly that VoiceDebrief's parts 1 to 3 run on an explicitly fictional corpus.