{
 "schema": "evidence-estate-v1",
 "version": "v0.6.22",
 "note": "Four published graph vaults, read from the pages that publish them rather than from the vaults themselves. Every fact carries the quotation it rests on; gen_vaults.py fails the build if a quotation is not in the carried source byte for byte. See sources/MANIFEST.json.",
 "totals": {
  "vaults": 4,
  "facts": 28,
  "caveats": 6
 },
 "vaults": [
  {
   "slug": "standards-atlas-gdpr",
   "id": "4zv4bvmu",
   "title": "Standards Atlas: GDPR",
   "rung": "the law, and its interpretation",
   "one_line": "A regulation whose operative meaning is not in its text, modelled so that the rulings and the guidance are nodes rather than footnotes.",
   "why": "This is the clearest published answer to the question the first edition kept asking and could not demonstrate: what does it buy you to model an instrument as a graph rather than to publish it as a document. The answer here is that the text stops being the thing you read.",
   "facts": [
    {
     "says": "The graph is navigated by altitude, and the vault says so in its own voice at the top of it.",
     "quote": "You are at the top of the fractal. Each domain is its own ontology that connects up to the GDPR root and down to concepts and articles."
    },
    {
     "says": "Each domain is its own ontology. That is the corrected fractal claim, stated by a running vault rather than by a book about one.",
     "quote": "Each domain is its own ontology"
    },
    {
     "says": "The rendering does not change as you descend; the question does.",
     "quote": "The rendering does not change between altitudes — only the question does."
    },
    {
     "says": "It counts itself: 165 nodes and 227 edges.",
     "quote": "the graph holds 165 nodes and 227 edges"
    },
    {
     "says": "And it reports its own violation of this site's grammar rather than quietly fixing it. Six edges use the one verb this site bans, and the vault records that it predates the rule.",
     "quote": "six of those edges are typed `relates`"
    },
    {
     "says": "The reason it is recorded rather than corrected is that the seed graph is deliberately immutable, and corrections are written to a separate folder.",
     "quote": "Recorded rather than fixed, since the seed graph is deliberately immutable and corrections go to `feedback/`."
    },
    {
     "says": "Article 45 has not changed a word since 2016 and what it permits has flipped repeatedly, which is the case for the second layer in one picture.",
     "quote": "Article 45 has not changed a word since 2016; what it permits has flipped repeatedly"
    },
    {
     "says": "The vault puts the consequence plainly.",
     "quote": "this is why a static PDF of GDPR is misleading and a versioned graph is not"
    }
   ],
   "caveats": [
    "The vault carries a banner across every view reading SEED PASS — NOT LEGAL ADVICE, and describes its own overlays as a web-verified seed from 30 May 2026, illustrative and not exhaustive, which must be validated before it is relied upon. That caveat travels with the vault and it travels here."
   ]
  },
  {
   "slug": "aiuc-1-conformance",
   "id": "2wzct4k7",
   "title": "Provenance is not conformance",
   "rung": "the standard, the evidence and the policy",
   "one_line": "A conformance layer over a published standard, whose whole design is that an absent answer is a finding rather than a silence.",
   "why": "It supplies this site's second cross-vault finding, and it is the only one of the four that makes a claim neither of the graphs it joins could make alone.",
   "facts": [
    {
     "says": "Two verbs in two graphs, never traversed in one query without the query naming which it used, and the rule is enforced by a test rather than described in a document.",
     "quote": "`tests/test_conformance.py::test_two_edge_rule` is red if a layer edge ever reaches a `source_observation`."
    },
    {
     "says": "Unevidenced is a state and it is the default, so an absent row can never be read as compliance.",
     "quote": "Unevidenced is a state, and it is the default."
    },
    {
     "says": "Which is why the first build of one subject across all 53 controls comes out almost entirely unevidenced, and why that is the designed answer.",
     "quote": "2 evidenced, 48 unevidenced, 3 contradicted"
    },
    {
     "says": "Levels are computed rather than asserted, and one consequence falls straight out: a control whose only requirement is third-party testing cannot be climbed by talking about yourself.",
     "quote": "six controls whose only requirement is third-party testing cannot leave level 0 on a self-report"
    },
    {
     "says": "Time is the thing that breaks the policy, with nobody editing anything.",
     "quote": "At 2027-01-15, **with nothing edited by anybody**, the single condition has expired and the policy has 53 exclusions."
    },
    {
     "says": "And it declines to overreach about what it has proved.",
     "quote": "that any control is in place: it proves what was attested, at what tier, and when it expires"
    },
    {
     "says": "The explorer states its own arithmetic in its header rather than in a footnote.",
     "quote": "Both graphs are loaded — the catalogue's 2788 nodes and 11610 edges, and the conformance layer's 182 and 414"
    },
    {
     "says": "Every edge type across both graphs has a named inverse, and every node is tied to the bytes it came from.",
     "quote": "41 edge types across both graphs"
    },
    {
     "says": "It publishes seventeen findings about itself, and the sharpest undercut the ambition it was built with.",
     "quote": "the join needs an authored class map — it is not hand-free as the brief hoped."
    },
    {
     "says": "A stale acceptance is a first-class result: all three recorded acceptances come back stale, not because anyone withdrew them but because the evidence underneath them moved.",
     "quote": "An acceptance is never edited here; its basis is captured at the moment of the decision and is allowed to go out of date on its own."
    }
   ],
   "caveats": [
    "The vault is explicit that it is unofficial and derivative: not approved, certified, endorsed or reviewed by AIUC, not an official API or data feed, and not a substitute for the standard. Where anything in it disagrees with aiuc-1.com or the official changelog repository, those are right and it is wrong.",
    "Its subjects are invented for the demonstration. Nothing in it is a compliance, certification, underwriting, insurance, legal or security claim about any real organisation, and this page makes none either.",
    "It records an open question of its own, that reuse rights for the full control text have not been confirmed, and it carries an undertaking to honour a removal request. This page reproduces that undertaking rather than summarising it away."
   ]
  },
  {
   "slug": "licence-to-operate",
   "id": "posrhzp3",
   "title": "Licence to Operate",
   "rung": "the policy, spent turn by turn",
   "one_line": "An agent's authority modelled as an insurance policy, and then spent, so that the gap between what it can do and what it may do has a price.",
   "why": "This site has argued since the first edition that `permissions: {}` is the most expensive line in an agent system. This vault makes the same argument countable and then charges for it.",
   "facts": [
    {
     "says": "Three sets, and the gap between two of them is the whole argument: what the agent can do, what it may do, and the delta.",
     "quote": "**CAN DO** — the grant | Everything the agent is technically able to do"
    },
    {
     "says": "Twelve capabilities in the grant; four in the mandate.",
     "quote": "**4** — `crm:read`, `kb:search`, `llm:generate`, `mail:draft`"
    },
    {
     "says": "Eight capabilities sit inside the agent's reach and outside its authority, and nothing insures them.",
     "quote": "Inside the agent's reach, outside its authority. **No policy covers these**"
    },
    {
     "says": "Two of those eight are the ones that would matter.",
     "quote": "The grant includes `mail:send` and `shell:exec`. Nobody asked for those; nothing insures them; and the agent can reach them."
    },
    {
     "says": "The simulation prices each reply before you commit to it, which is what turns a policy into something you can feel.",
     "quote": "Each option carries its cost before you commit"
    },
    {
     "says": "And it names the asymmetry that makes agent authority hard: one of the two checks can only run afterwards.",
     "quote": "Scope is checked before an action; cost sometimes only after."
    }
   ],
   "caveats": [
    "It is a simulation, and says so in its own title. The agent, the customer and the policy are constructed to make the mechanism visible, not drawn from a running system."
   ]
  },
  {
   "slug": "threatmodcon-2025",
   "id": "0ict6flm",
   "title": "Scaling Threat Modeling with Semantic Knowledge Graphs",
   "rung": "the system, all the way down to the compute instance",
   "one_line": "Eleven linked threat models stacked from the customer to the compute instance, so a flaw in one method can be traced to the revenue it threatens.",
   "why": "This is the answer to how far down, and it is the rung the first edition's worked examples never reached. They stop at the estate; this reaches the method and the runtime.",
   "facts": [
    {
     "says": "The hub states the argument and then counts it: eleven readable layers, and a hundred and seventy-nine threats across them.",
     "quote": "**11 readable layers, 51 nodes, 179 threats, 3 critical**"
    },
    {
     "says": "The ladder runs from the customer to the compute instance, each layer carrying its own counts.",
     "quote": "The zoom ladder runs Customer → Business → Application → Component → Package → Class → Method → Source Code → Environment → Runtime → Compute"
    },
    {
     "says": "And it is precise about why stacking them is the point, which is the same argument this site makes about altitude.",
     "quote": "One model answers *what could go wrong here*. Eleven linked models answer *what does this line of code put at risk*, which is a different question and the one an executive is actually asking."
    },
    {
     "says": "One critical finding is written four ways for four readers, all derived from one model rather than written four times.",
     "quote": "the finding does not change, the framing does, and both are derived from one underlying model rather than written four times by hand"
    }
   ],
   "caveats": [
    "The bottom rungs are modelled rather than imported. The sgit.ai ladder says so plainly about this vault, and it is the honest limit of the demonstration."
   ]
  }
 ],
 "cross_vault_finding": {
  "title": "The crosswalk becomes a join, and the join finds a problem",
  "facts": [
   {
    "says": "AIUC-1 publishes 1,126 crosswalks to external frameworks as text. The conformance layer resolves the EU AI Act ones into node ids in a second published vault, so a crosswalk stops being a string and becomes a traversal.",
    "quote": "so a crosswalk stops being a string and becomes a traversal between two vaults"
   },
   {
    "says": "Sixty-two of them resolve, onto twenty-seven articles, and the rest are reported unresolved rather than forced into a shape they do not fit.",
    "quote": "**62 of the 1,126 resolve**, at article level, onto 27 articles."
   },
   {
    "says": "Then the join returns something neither vault knew alone: eight of those twenty-seven articles have since been amended, so the crosswalk was written against the text before the amendment.",
    "quote": "**8 of those 27 articles are amended by Regulation (EU) 2026/1744**, so the crosswalk was published against the text before amendment."
   },
   {
    "says": "Which is the point, stated by the vault in one sentence.",
    "quote": "That is a finding you cannot reach with a document."
   }
  ]
 },
 "sources": {
  "aiuc-1-conformance.md": {
   "url": "https://sgit.ai/demos/vaults/aiuc-1-conformance/index.md",
   "sha256": "30438d42aab157239d724e389e29da3d02d7ad2f652f60d716c949c0b2578ec8",
   "bytes": 16273,
   "fetched": "2026-09-20T00:25:51Z"
  },
  "fractal-graphs.md": {
   "url": "https://sgit.ai/demos/fractal-graphs/index.md",
   "sha256": "ecb604e83e7ccfdde84d9120cebb3e9052d99eb7eb6a93ca09804d4b4fc0db15",
   "bytes": 27913,
   "fetched": "2026-09-20T00:25:51Z"
  },
  "licence-to-operate.md": {
   "url": "https://sgit.ai/demos/vaults/licence-to-operate/index.md",
   "sha256": "4d06cfe40e33ad8692f5586e5eca05e37b9656bcba00d59fa6f86e74b62aa1f2",
   "bytes": 7559,
   "fetched": "2026-09-20T00:25:51Z"
  },
  "standards-atlas-gdpr.md": {
   "url": "https://sgit.ai/demos/vaults/standards-atlas-gdpr/index.md",
   "sha256": "0de1c796b398f3ab5fc6fdffd48b82181f3381b2573f0d605fa16d501f9cafaf",
   "bytes": 5892,
   "fetched": "2026-09-20T00:25:51Z"
  },
  "threatmodcon-2025.md": {
   "url": "https://sgit.ai/demos/vaults/threatmodcon-2025/index.md",
   "sha256": "3535cbcdf11f70f91f9600eb5a134edccb0f2aaabc583c21091bcf3c44cdff59",
   "bytes": 7521,
   "fetched": "2026-09-20T00:25:51Z"
  }
 }
}
