# The Behaviour Policy Is A Graph And Every Document Is A Projection: The W3C Has The Vocabulary, And A Prohibition Has Two Lives

**version** v0.33.70
**date** 11 September 2026
**from** Human (project lead)
**to** Whoever models the graph, whoever builds the renderer, and whoever compiles the prohibitions into something that enforces them

**type** Dev brief (specification for the policy graph, its projections and its enforcement targets)

*Second of 11 September. Both the corpus and the outside were searched first. The corpus supplied the projection pattern, published twice on sister sites, and the variant rule that constrains it. The outside search found that the graph the memo describes has a W3C vocabulary with the deontic triad, constraints, a conflict strategy and inheritance already in it, that compiling such a graph to an enforcement engine is practised, that the largest cloud's own agent gateway enforces with a language whose every deny beats every permit, and that all four major model providers state in their own words that a prohibition written into a prompt is not a control. One correction: the memo says the graph scales because it is a graph, and it does not, because the bottleneck is the human who validates each cell. Limitations: no schema is written; no renderer is designed; and the enforcement layer mapping is a specification of what each prohibition must declare, not an integration with anything.*

---

## What This Is

The specification for the behaviour policy as a graph, the documents that are computed from it, and the property every prohibition in it must carry: **the memos state that the behaviour policy is already a graph, that what people call a policy is a projection computed from it programmatically or by an agent, that this is what allows one fact set to be rendered for executives, for every other stakeholder and for the highly technical, that the graph is what lets policy for an agent extend to policy for an agent in an environment with particular permissions in particular situations at particular times without changing structure, that the deliverable is therefore a vault holding the graph and its connections rather than a document, that this introduces the human and the validation and the feedback loop, that the prohibitions are also the input to the tooling and the monitoring, and that the graph is the competitive advantage because the estate has the vault, the tooling and an open method for building it; the first finding is that the projection pattern is already published twice in the estate, as story is a graph and article is projection on one site and as briefs are arguments and infographics are projections on another, so the behaviour policy is the third instance of a commitment already made in public; the second is that the graph has a vocabulary already, being the W3C rights expression language whose model carries permission, prohibition and duty as rules, constraints on time, purpose, count and place, a conflict strategy that says which wins, and inheritance between policies, and which is in production use in the European data space architectures and has already been compiled to an enforcement engine by at least one project, with the honest caveat that it is asset centric rather than agent centric, has no enforcement semantics of its own, and has no published profile for agents; the third is that a prohibition has two lives and the difference is the enforcer test of 20 August, because the four largest model providers each state that a prohibition written into a prompt can be bypassed, so every prohibition node must declare the layer at which it is enforced, from prompt through tool schema, client rule, gateway and sandbox, and only the last three are controls; the fourth is that the graph does not scale because it is a graph, since the representation is uniform but the elicitation is combinatorial and the human who validates each cell is the bottleneck, so every cell carries an asserted default and the human only corrects; and the fifth is that every projection must render the same fact set with an empty diff, which is the variant rule already in force, and the diff does not yet exist.** New contributions: **the vocabulary and the compile target with their limits stated; the enforcement layer as a required attribute of every prohibition; the defaults and correction discipline that makes the combinatorial graph tractable; the lessons on keeping prose and model in step, drawn from rules as code and from the compliance document model that already generates documents from data; and the placement of the enforcement point in the estate's own published architecture.**

## The Pattern Is Already Published, Twice

The memo says:

> This ABP is already a graph, because the policy itself is defined as a graph. What we usually call a policy is a projection of that, that is programmatically calculated from that, or agently created from that.

**Two sister sites already say this about other things.** The newsroom site's thesis is that a story is a graph and an article is a projection. The infographics site's thesis is that briefs are arguments and infographics are projections, and it carries the rule that a fact about the argument an infographic depicts should be checked against its source brief rather than repeated from the summary.

**So the behaviour policy is the third instance of a pattern the estate has committed to in public**, which is a stronger position than inventing it, and it inherits the constraint that came with the pattern: **every projection renders the same fact set and the diff must be empty.** That rule has now blocked something on each of the last three days. **The diff does not exist. Until it does, the multi audience promise may be described and may not be printed.**

## The Graph Has A Vocabulary Already

**The memo's graph is, structurally, the W3C rights expression language.** The information model, a recommendation since 15 February 2018, has:

| Element | What it is | What it is in the behaviour policy |
|---|---|---|
| **Policy** | A set of rules, with subclasses for a generic set, an offer and an agreement | The ABP for one agent in one context |
| **Permission, Prohibition, Duty** | The three rule types | The mandate, the prohibitions, and the obligations such as log before act or ask above a threshold |
| **Action** | What is permitted or prohibited, from an extensible vocabulary | The tool call, the file operation, the network request |
| **Asset** | The thing acted on | The resource, the tool, the data |
| **Party** | Assigner and assignee | The organisation and the agent |
| **Constraint** | Left operand, operator, right operand | Time of day, purpose, count, location, which is exactly the memo's list of situations |
| **Conflict strategy** | Permissions win, prohibitions win, or the policy is void | **Prohibitions win, always** |
| **inheritFrom** | A policy inherits from a parent | Policy for an agent in an environment inherits from policy for the agent |

**It is in production.** The European data space reference architecture uses it as the basis of its usage control language, the dataspace protocol uses its offers and agreements for contract negotiation, a federated cloud initiative published a verifiable credential profile for it on 31 July 2026, and a rights standard for images adopted it as its default usage policy language. **And at least one project compiles it to an enforcement engine already**, translating it into the rule language of a widely deployed policy agent, which is direct evidence that graph as data, compiled to enforcement, is practised rather than proposed.

**Three honest limits, and they decide how it is used.**

**It is asset centric.** Its rules are action on asset by party. The behaviour policy is principal centric: actions by an agent, on a set of resources, under credentials. The mapping works, with the agent as assignee, the tool as asset and the tool operation as a profile defined action, but it is a mapping and not a native fit.

**It has no enforcement semantics.** The 2018 charter excluded them. A formal semantics defining an evaluator exists only as a community group draft. A June 2026 paper proposing deontic runtime governance for agents, enforced outside the model by a triple extractor and a reasoner, criticises it explicitly for specifying no enforcement model and does not use it.

**There is no published profile for agents.** Applications to agents so far run the other way: models writing policies in this vocabulary, not policies governing models.

**So the position is: use it as the interchange vocabulary for the graph, through a profile that adds the agent actions, and compile to something that enforces.** Do not claim the vocabulary enforces anything, because it does not, and do not invent a graph model from nothing when a recommendation with the right triad, the right constraints and the right conflict rule already exists.

## What It Compiles To

**The largest cloud's own agent gateway already enforces with a language whose semantics are the ones this product needs.** Default deny. Two effects, permit and forbid. **Any matching forbid overrides any permit.** A schema based validator, a formal model of the core in a proof assistant, and an analysis tool announced 16 June 2025 that compiles policies to a solver and proves whether a permit is shadowed, a condition is impossible or a denial is complete. The gateway product blocks everything by default, and the provider's own security blog of 20 May 2026 states that model layer controls **such as system prompts and training time alignment can be bypassed by prompt injection or hallucination**.

**A superset announced on 6 August 2026 adds what the sub delegation argument needs.** Temporal operators over an agent's event history: formerly, count within, sum within, and binding. Its published examples are approve before act, running totals, and **no external contact after touching confidential data**, which is the sub delegation prohibition of yesterday's teaching brief expressed as a rule. Every policy in the base language is a valid policy in the superset. **Its reference interpreter is stated not to be for production, and the temporal extensions lose the base language's symbolic analysability.** Use the base language for the product, and watch the superset.

**The alternative compile target is the policy agent used across the container ecosystem**, which evaluates rules against data documents so the ABP can ship as data with a fixed evaluator, whose home page now carries a tool calling example, and which one agent framework integrates at the tool dispatch boundary with allow, deny, requires approval and not applicable verdicts plus a middleware that hides tools before the model ever sees them. **Its deny is a convention rather than an effect**, so deny overrides is a pattern the policy author writes rather than a guarantee the language gives.

**The rule that follows: every prohibition in the graph must be expressible as a forbid in the compile target, and the compiled policy must pass the shadowed permit analysis.** A prohibition that cannot be compiled is a sentence, not a rule.

## A Prohibition Has Two Lives, And Only One Of Them Is A Control

**This is the section that decides whether the product is honest.** The second memo says the prohibition list is a partial defence against prompt injection and the input to guardrails. **Both are true, and only if the prohibition lives in the right place.**

**All four major model providers say the same thing in their own words.**

| Provider | Date | Statement |
|---|---|---|
| The first | 25 May 2026 | Model layer controls shape only what the agent tends to do, not what it is theoretically capable of doing. Protection in the model layer will never be one hundred per cent effective, which is why it cannot stand alone. **The deterministic boundary is what gets hit when everything probabilistic misses** |
| The second | 20 May 2026 | System prompts and training time alignment **can be bypassed by prompt injection or hallucination** |
| The third | 16 July 2026 | Relying on prompts or **the agent will only do X narratives** instead of hard authorisation boundaries invites prompt injection and workflow drift |
| The fourth | 2025 | Reasoning based defences are non deterministic and cannot provide absolute guarantees, and must work in concert with deterministic controls |

**So a prohibition has two lives.** Written into the system prompt, don't delete the database is an instruction inside the trust boundary the attacker is already inside. **It is not a control.** Compiled into a tool call filter, a gateway or a sandbox, the same sentence **is** a control. The standing rule from 20 August says it exactly: a control bounds a grant only if enforced by something the grant does not include.

**Every prohibition node in the graph therefore carries one required attribute, the layer at which it is enforced.**

| Layer | What it is | Is it a control |
|---|---|---|
| **Prompt** | An instruction to the model | **No.** And arguably worse than nothing, because it manufactures assurance without providing it |
| **Tool schema** | The tool is not exposed to the model at all | Yes, for that tool |
| **Client rule** | An allow, ask or deny rule in the agent client | Yes, with a documented gap: text matching rules miss shell and path variants, per the client's own documentation, which points at the sandbox for hard enforcement |
| **Gateway** | Default deny at the point where tool calls leave the agent | **Yes** |
| **Sandbox** | Operating system or network isolation | **Yes**, and the client's own documentation states the sandbox restrictions apply even if a prompt injection bypasses the model's decision making |

**One further datum on the middle row.** The first provider reports that users approved roughly ninety three per cent of permission prompts. **Ask is a weak control.** A prohibition whose enforcement is a human clicking approve is a prohibition enforced by fatigue.

**The product consequence.** The ABP rendered for an executive shows the prohibitions. The ABP rendered for an engineer shows the prohibitions with their layer. **And the ABP rendered for the assessment in tier four shows which prohibitions are enforced only at the prompt layer, because those are the ones that are not enforced at all.** That is the finding the assessment sells, and it falls straight out of one attribute on one node type.

## It Does Not Scale Because It Is A Graph

**One correction to the third memo, made carefully because the memo is right about everything except the word scale.**

> It doesn't matter, right? Like, we scale because it's all a graph.

**The graph makes the representation uniform. It does not make the elicitation cheap.** Policy for an agent, in an environment, with a credential set, in a situation, at a time of day is a product of dimensions, and every added dimension multiplies the number of cells somebody has to confirm. **And the memo itself names the bottleneck**: it introduces the human, the validation and the feedback loop. The human is the constraint. The graph is not.

**Two disciplines make it tractable, and both are already in the estate's method.**

**Assert a default in every cell, and ask the human only to correct.** This is the draft and correction motion of the first brief applied inside the graph. An inherited policy carries its parent's values until somebody overrides them, and the override is the elicitation. **A cell that is empty is a question. A cell with a default is a claim the human can disagree with, and disagreement is cheaper than authorship.** It is also the games mechanic: state the belief, then correct it.

**Ship one dimension at a time.** Agent in environment is two dimensions and is already the tier one product, because the environment decides the grant: the same agent on a desktop, on a desktop with administrator rights, and in a container has three different grants. Credentials are the third dimension and belong to tier three. **Situation and time of day are dimensions the constraint vocabulary supports and no buyer will validate in the first month.** Build them into the model and do not surface them.

## Keeping The Prose And The Graph In Step

**The projection promise fails in a specific way, and the projects that have tried it have written down how.**

**The literate programming approach for law**, in which legal text and code live in one source and the readable document is woven from it, gives one lesson: **the prose is the source, the code is embedded under each clause, and so they cannot drift.** Its limit is one audience rendering.

**The compliance document model** maintained by a national standards body, at version 1.2.3 as of 6 August 2026, exists to generate system security documents from machine readable catalogues and profiles, and a federal authorisation programme is moving to submissions in it. **That is the closest precedent for policy model to documents for reviewers**, and it is in the same domain as this product.

**The rules as code programmes** in several governments reached the same conclusions from the other direction: co draft the natural language and the machine form together, keep the code structure isomorphic to the rule structure, and note that **how versions are governed and how errors in the coded form are found remain unresolved**.

**Condensed into rules for the renderer:**

1. **One source, and the source is the graph.** Prose is derived. Never hand edit a rendered document.
2. **Every rule carries a stable identifier**, so every rendered sentence traces to a node, and the executive's sentence and the engineer's sentence trace to the same one.
3. **Version the graph and re render.** A rendered document states the graph version it came from.
4. **Embed the tests in the source.** Each rule carries an example the compiled policy must satisfy, so drift between the prose, the graph and the enforcement is caught by a test rather than by a reader.
5. **The fact diff runs across renderings before any rendering ships.** Rule 6 of the store pack, and the thing that does not exist.

## The Deliverable Is A Vault, And The Enforcement Point Is Already In The Architecture

**The memo is right that the deliverable is a vault rather than a document, and yesterday's architecture brief already says how.** The graph is data. The projections are computed. The customer clones. **The clone pins a version, and every rendered document states the input versions it was computed against**, which is what makes a later difference explicable rather than alarming.

**And the enforcement point is not new either.** The twins site publishes it: agents present cryptographic identity, **signed mandates** and contextual evidence to an execution broker, which verifies permissions before performing operations, holding credentials while the twin holds reasoning. **The signed mandate is the ABP's mandate half. The execution broker is the gateway row in the table above.** The memo's statement that the policy comes with the twin is not an aspiration, it is a description of an architecture already on a published page.

## What This Does Not Try To Be

- **A schema.** The vocabulary is identified and its mapping is sketched. No profile is written and no node is defined.
- **A renderer.** The rules for one are given. Nothing is built.
- **An integration.** The compile targets are named with their semantics. No policy has been compiled to either.
- **A claim that the vocabulary enforces anything.** It does not, and the brief says so three times.
- **The fact diff.** Named as the blocker for the fourth day running. Not designed here.

## Honest Tensions

| Tension | Note |
|---|---|
| Using the W3C vocabulary | It has the right triad, constraints, conflict rule and inheritance, and it was built for digital assets rather than for agents |
| Compiling to the cloud's language | Its deny semantics are exactly right and formally verified, and it ties the product to one provider's ecosystem |
| The enforcement attribute | It makes the product honest, and it makes most existing agent deployments look bad, because most prohibitions today live in prompts |
| Defaults in every cell | It makes elicitation cheap, and a default nobody corrected is a claim nobody made |
| One dimension at a time | It ships, and it means the situation and time constraints the memo is excited about stay hidden for months |
| Prose derived from the graph | It cannot drift, and executives will want to edit the sentence rather than the node |

## Open Questions

1. **Does a profile of the vocabulary for agent actions need to be published, and under whose name?** The gap is real and filling it is a public act.
2. **Which compile target first?** The cloud's language has the semantics; the policy agent has the ecosystem. Both is a maintenance cost.
3. **What does the enforcement attribute default to when nobody knows?** Prompt is the honest default and it is the one that makes every deployment look unenforced.
4. **Who corrects the defaults, and does their correction carry a signature?** The mandate half is a legal act per the 10 September opinion brief.
5. **Can the fact diff be built as a test over rendered documents rather than as a tool?** The renderer rules suggest it can.
6. **Does the execution broker on the twins site exist as running code?** The page describes it. Nobody has checked.
7. **What is the smallest graph that produces a useful executive rendering?** The answer decides what tier one actually shows.

## Relationship To Previous Briefs

**From the first brief of today**, it takes the four objects and specifies how three of them live in the graph and how the fourth is compiled out of it.

**From the newsroom and infographics sites**, it takes the projection pattern and records this as its third instance.

**From the enforcer test of 20 August**, it takes the rule that decides which prohibitions are controls, and it makes that rule an attribute on a node type.

**From the teaching brief of 10 September**, it takes the sub delegation prohibition and finds it expressible in a policy language announced in August.

**From the vault architecture brief of 10 September**, it takes the pinning and versioning rules for the clone.

**From the twins site**, it takes the signed mandate and the execution broker as the already published enforcement point.

**From the variant rule**, it takes the empty diff requirement, and it is the fourth day that rule has blocked a promise.

## Key Claims

| # | Claim |
|---|-------|
| 1 | The projection pattern is published twice in the estate, and the behaviour policy is its third instance |
| 2 | Every projection renders the same fact set with an empty diff, and the diff does not exist |
| 3 | The graph has a W3C vocabulary already, with permission, prohibition and duty, constraints on time, purpose, count and place, a conflict strategy and inheritance |
| 4 | That vocabulary is in production in the European data space architectures and has been compiled to an enforcement engine by at least one project |
| 5 | It is asset centric, has no enforcement semantics and has no agent profile, so it is the interchange vocabulary and not the enforcer |
| 6 | The largest cloud's agent gateway enforces with a language where any forbid overrides any permit, formally verified and with analysis for shadowed permits |
| 7 | All four major model providers state that a prohibition in a prompt can be bypassed, in their own words and in 2026 |
| 8 | So every prohibition node carries the layer at which it is enforced, and only tool schema, gateway and sandbox are controls |
| 9 | Users approve roughly ninety three per cent of permission prompts, so ask is a weak control |
| 10 | The graph does not scale because it is a graph, because the human validating each cell is the bottleneck, so every cell carries a default and the human only corrects |
| 11 | Prose is derived from the graph, every sentence traces to a node, and a rendered document states its graph version |
| 12 | The enforcement point is already published on the twins site as an execution broker receiving signed mandates |

---

## Sources

All read 11 September 2026.

**Inside the estate.** The newsroom and infographics theses from the network index at https://sgit.ai/network/index.html. The twins site at https://twins.sgit.ai/llms.txt for the signed mandate and the execution broker. The licence to operate demonstration at https://sgit.ai/demos/vaults/licence-to-operate/index.html.

**The vocabulary.** The information model at https://www.w3.org/TR/odrl-model/, recommendation of 15 February 2018. Adoption at https://www.w3.org/blog/2025/w3c-standard-odrl-policy-gaining-industry-adoption, 23 October 2025. The formal semantics draft and the implementation landscape at https://w3c.github.io/odrl/formal-semantics/ and https://w3c.github.io/odrl/landscape/. The verifiable credential profile at https://gaia-x.eu/bridging-policy-trust-and-verifiable-credentials-in-gaia-x-data-spaces/, 31 July 2026. The dataspace protocol at https://eclipse-dataspace-protocol-base.github.io/DataspaceProtocol/2025-1/. The deontic runtime governance paper at https://arxiv.org/html/2606.19464v1, 17 June 2026.

**The compile targets.** The language at https://crates.io/api/v1/crates/cedar-policy, version 4.12.0 of 28 July 2026. The analysis tooling at https://aws.amazon.com/blogs/opensource/introducing-cedar-analysis-open-source-tools-for-verifying-authorization-policies/, 16 June 2025. The gateway's choice of it at https://aws.amazon.com/blogs/security/why-policy-in-amazon-bedrock-agentcore-chose-cedar-for-securing-agentic-workflows/, 20 May 2026. The temporal superset at https://aws.amazon.com/blogs/opensource/introducing-dogwood-runtime-verification-for-ai-agents/, 6 August 2026. The policy agent at https://www.openpolicyagent.org/ with releases at https://github.com/open-policy-agent/opa/releases, and its framework integration at https://ai-sdk.dev/docs/agents/policy-tool-approvals.

**The four providers on prompts as controls.** https://www.anthropic.com/engineering/how-we-contain-claude, 25 May 2026, and the approval rate reported at https://www.infoq.com/news/2026/07/anthropic-claude-containment/, 22 July 2026. https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/, 16 July 2026. The gateway blog above for the second. The approach paper summarised at https://simonwillison.net/2025/Jun/15/ai-agent-security/ for the fourth. Client permission semantics and the sandbox statement at https://code.claude.com/docs/en/permissions.

**Prose and model in step.** The literate programming approach at https://book.catala-lang.org/en/5-1-literate-programming.html. The compliance document model at https://pages.nist.gov/OSCAL/about/news, version 1.2.3 of 6 August 2026. The rules as code findings at https://oecd-opsi.org/publications/cracking-the-code/, 12 October 2020, and the 2026 conference at https://openfisca.org/en/conference/2026/.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
