Licence to Operate
An agent's authority modelled as an insurance policy, and then spent, so that the gap between what it can do and what it may do has a price.
Vault posrhzp3 · on the sgit.ai ladder this is the policy, spent turn by turn. The read key is printed on the vault’s own page and is the whole credential; it is not repeated here, because a credential copied is a credential that goes stale somewhere.
4d06cfe40e33ad86…, fetched 2026-09-20T00:25:51Z), and the build fails if a quotation is not in that file byte for byte. The first edition’s five vault analyses were written by opening the vaults; these four were not, and that difference is worth more than the convenience of hiding it.Why this one is here
This site has argued since the first edition that `permissions: {}` is the most expensive line in an agent system. This vault makes the same argument countable and then charges for it.
The reading
Three sets, and the gap between two of them is the whole argument: what the agent can do, what it may do, and the delta.
CAN DO — the grant | Everything the agent is technically able to do
Twelve capabilities in the grant; four in the mandate.
4 —crm:read,kb:search,llm:generate,mail:draft
Eight capabilities sit inside the agent's reach and outside its authority, and nothing insures them.
Inside the agent's reach, outside its authority. No policy covers these
Two of those eight are the ones that would matter.
The grant includesmail:sendandshell:exec. Nobody asked for those; nothing insures them; and the agent can reach them.
The simulation prices each reply before you commit to it, which is what turns a policy into something you can feel.
Each option carries its cost before you commit
And it names the asymmetry that makes agent authority hard: one of the two checks can only run afterwards.
Scope is checked before an action; cost sometimes only after.