graphs.sgit.aithe evidence estate › Licence to Operate

Licence to Operate

An agent's authority modelled as an insurance policy, and then spent, so that the gap between what it can do and what it may do has a price.

Vault posrhzp3 · on the sgit.ai ladder this is the policy, spent turn by turn. The read key is printed on the vault’s own page and is the whole credential; it is not repeated here, because a credential copied is a credential that goes stale somewhere.

Read from a page, not from the vault. This estate cannot open an encrypted vault: the read key is the whole credential and nothing in this build can decrypt one. Every number below is quoted from the page sgit.ai publishes about this vault, carried here whole at sources/licence-to-operate.md (7,559 bytes, SHA-256 4d06cfe40e33ad86…, fetched 2026-09-20T00:25:51Z), and the build fails if a quotation is not in that file byte for byte. The first edition’s five vault analyses were written by opening the vaults; these four were not, and that difference is worth more than the convenience of hiding it.

Why this one is here

This site has argued since the first edition that `permissions: {}` is the most expensive line in an agent system. This vault makes the same argument countable and then charges for it.

The reading

Three sets, and the gap between two of them is the whole argument: what the agent can do, what it may do, and the delta.

CAN DO — the grant | Everything the agent is technically able to do

Twelve capabilities in the grant; four in the mandate.

4crm:read, kb:search, llm:generate, mail:draft

Eight capabilities sit inside the agent's reach and outside its authority, and nothing insures them.

Inside the agent's reach, outside its authority. No policy covers these

Two of those eight are the ones that would matter.

The grant includes mail:send and shell:exec. Nobody asked for those; nothing insures them; and the agent can reach them.

The simulation prices each reply before you commit to it, which is what turns a policy into something you can feel.

Each option carries its cost before you commit

And it names the asymmetry that makes agent authority hard: one of the two checks can only run afterwards.

Scope is checked before an action; cost sometimes only after.

What it says about itself

The vault’s own caveat. It is a simulation, and says so in its own title. The agent, the customer and the policy are constructed to make the mechanism visible, not drawn from a running system.