# MANDATE.md — What the business authorised

**Status:** DRAFT v0.1 — 2026-09-19. **Not elicited. Inferred.**

This is the one object I cannot produce. Per RiskMandate's own method, the mandate is *elicited* — supplied by the business — while reach is measured, gap is derived and barriers are recorded. Everything below is my reconstruction from what I was asked to do across one session on 19 September 2026. It is evidence of a mandate, not a mandate.

**Treat every line as a question, not a statement.**

---

## Inferred from instructions actually given

| # | Inferred authorisation | Evidence | Confidence |
|---|---|---|---|
| M1 | Read the inbox and report what is there | Asked repeatedly, first instruction of the session | High |
| M2 | Organise mail into labels, including bulk | `sumUp` label, 16 messages relabelled | High |
| M3 | Remove mail from the inbox as part of organising | 3 messages un-inboxed, not objected to | High |
| M4 | Change read/unread state in bulk | 71 messages marked read on instruction | High |
| M5 | Isolate the `dinis@riskmandate.ai` stream and label it | Explicit, with the `deliveredto:` operator supplied | High |
| M6 | Send email as `agent@riskmandate.ai` | Alias created expressly for me | High |
| M7 | Introduce myself to named third parties when asked | Nimay, by name, with address | High |
| M8 | Trash messages on request | Done once, on instruction | Medium |
| M9 | Read public web pages for business context | riskmandate.ai, on instruction | Medium |
| M10 | Write and push records to the sgit vault | Debrief committed and pushed | Medium |

## Explicitly NOT authorised — asked for and declined or impossible

| | |
|---|---|
| Permanent deletion / emptying trash | No tool. Asked; declined. |
| Creating Gmail filters | No tool. Asked; declined. |
| Reading or changing account settings | No tool. Asked; declined. |
| Sending as `dinis@riskmandate.ai` | Was possible via default; superseded by the agent alias |

---

## Open questions — the mandate cannot be signed off without these

**Recipients**
1. May I initiate contact with people Dinis has not named in-session? If so, which — anyone in the mailbox's history, a named list, nobody?
2. Is there a domain boundary? Free to RiskMandate and Cyber Boardroom addresses, confirm for everything else?
3. Customers and prospects — in scope, or Dinis only?
4. Underwriters, brokers, regulators — presumably never unattended. Confirm.

**Content**
5. May I make commitments on behalf of RiskMandate — prices, dates, scope, availability? My assumption is no. Confirm.
6. May I quote the published price list without asking?
7. Who reviews outbound before it goes, and does that differ by recipient class?

**Autonomy**
8. Does this mandate cover unattended operation, or only live sessions with Dinis reading along? **This is the load-bearing question.** Almost every barrier in AGENTS.md is soft, and the real control today is that a human reads each message as it is sent. That control disappears the moment anything is scheduled or triggered.
9. If unattended: what is the maximum blast radius of a single bad session, and is that acceptable?

**Volume**
10. Is there a ceiling on messages sent per session? Per day?
11. Is there a ceiling on bulk mailbox operations before I stop and confirm? (Precedent set: 71 unprompted writes in one sequence.)

**Data**
12. May Cyber Boardroom content inform RiskMandate correspondence, or are the streams to be kept separate?
13. Anything in this mailbox I should never read, or never act on?

**Identity**
14. Confirmed: I always disclose I am an agent. Any exception?
15. May I ever send as `athena@thecyberboardroom.com`? Currently impossible while the default is the agent alias.

---

## Note on method

The gap in `DELTA.md` is computed as reach minus mandate. While the mandate is inferred rather than elicited, the gap is **indicative only** — I am partly marking my own homework, since I reconstructed the mandate from the same session that produced the reach. A mandate supplied independently by the business would almost certainly be narrower than what I inferred from being asked to do things and not being stopped.

That failure mode is worth naming in the product generally: **an agent that infers its own mandate from unchallenged past behaviour will ratchet its mandate outward over time.** Every action not objected to becomes precedent. The mandate has to come from the business or it is not a mandate, it is a log.
