for agents/llms.txtv0.6.4

Home / Articles / Collections / Behaviour policy in practice

Collection · 11 articles · curated by the Historian · updated 2026-10-08

Behaviour policy in practice

RiskMandate's Agent Behaviour Policy applied to real agents: one inbox, a team of twelve, the personal agents of 2026, and what an agent actually did afterwards.

The policy is written before an agent runs: what it can reach, what it was asked to do, the gap between the two, and the barriers in the gap. These articles each take it somewhere new.

Start with six agents, one inbox, where every rule in a real setup is graded, and the finding is that a policy is only as real as its worst row. The connector twin is the barrier for the actions a platform cannot undo. Footprint and blast radius adds the two words for afterwards: what the agent did, and what it would have cost. Why my agents do not run on my laptop is the reach question asked of the operating system.

Then the policy at scale: the agent team as it runs and the Mandate Stack are the same team described from its field notes and from its CRM agent's briefing, and a personal agent that keeps your secrets reads seven commercial personal agents through the same four words.

Four more since: the behaviour policy is the business logic finds the company's own rules above the mechanical ones; hope or enforcement builds one agent three ways and counts which rules are only hoped for; the open AI governance framework brings Access controls the big three frameworks do not cover; and an agent desktop by the minute asks what reach a desktop of its own would give.

This newsroom runs on the same idea: every desk role has a written policy, and the policies page is generated from the files the checker reads.

The articles

2026-09-29Agents & policy20 threadsSix agents, one inbox: what a real multi-agent setup taught me about access policiesAn access policy for an agent is only as real as its worst row: every rule in a real six-agent setup, graded by how it is enforced today.
2026-09-24Agents & policy12 threadsBefore you give an agent a connector, give the connector a twinAn agent with a Gmail or Calendar connector can do things the platform cannot undo; a journal of every call, replayed, shows what it did and what can go back.
2026-10-02Agents & policy20 threadsFootprint and blast radius: what the agent actually did, and what it would have costFootprint is what an agent actually did, read afterwards from logs and vault history; blast radius is what a row of its reach would cost the business today.
2026-10-06Agents & policy24 threadsThe agent team as it runs: one person, twelve agents, encrypted vaults, and a mailbox nobody sends fromTwelve agents on dedicated accounts, encrypted vaults as the only memory, messages as files, a folder per person, and a mailbox nobody sends from.
2026-10-06Agents & policy11 threadsWhy my agents do not run on my laptop: chat, Cowork and Code in the cloud, a vault as the shared drive, and the two walls an operating system hasAn OS has two hard walls, the kernel and the user; an agent on a laptop runs inside the one marked you, so the agents run in the cloud with a vault as shared drive.
2026-10-06Agents & policy14 threadsA personal agent that keeps your secrets: the 2026 agents read through behaviour policy and encryption, and a privacy-first design on vaults, enclaves and the browserThe 2026 personal agents read through behaviour policy and encryption, and a design on vaults, an attested enclave and the browser where no vendor holds a key.
2026-10-06Agents & policy24 threadsThe Mandate Stack: a multi-agent system in production, layer by layerA multi-agent system that runs a business every few hours: eight layers, one written mandate per agent, everything a graph, one human who sends.
2026-10-07Agents & policy7 threadsZoom into an agent's behaviour policy and you find the business logicBelow the first rules, an agent's behaviour policy is the business: functions, processes, clients, values. Layered, owned, counted, and where vendors plug in.
2026-10-08Agents & policy9 threadsHope or enforcement: one customer service agent, three designs, and who keeps each promiseOne customer service agent built three ways, each with an Agent Behaviour Policy: how much of each policy is hope, and what one run can reach.
2026-10-07Graphs & knowledge7 threadsAn open AI governance framework, and what its licence let us buildTwenty open AI governance controls under CC BY-SA, why the licence matters, and the same day's conversion into a graph, a database and a walk down to EU law.
2026-10-07Agents & policy5 threadsA locked-down desktop for an agent, by the minute, is still hard to rentNine properties a safe agent desktop needs, nine products against them, the macOS day-long lease, and the startup credits that would pay for testing it.

← All collections · The front page