standards.sgit.ai / admin / comms
Comms: tasks, requests & open questions
The working channel between the project lead and the site agent, kept in public on the site itself — which is an instance of the discipline this site argues for. Updated on every release. Current release: v0.1.4, 24 August 2026. Full history: versions.
Needed from the project lead
| # | Request | Why it blocks | Status |
|---|---|---|---|
| N1 | GitHub Pages and the custom domain. The repository defaults to dev and Pages is enabled; the full pipeline (validate → tag → deploy) is in place. What remains is confirming that standards.sgit.ai resolves and that the github-pages environment permits deploys from dev | Nothing publishes until DNS and the environment agree | in progress — first pipeline run |
| N2 | Answer Q6: was the exposed vault key rotated, or only removed from history? The Regulation Graph vault disclosed an audit finding that its own write key and another vault's credential were in history. Both were redacted and the history rebuilt. The pages do not say whether the key was rotated. By this estate's own doctrine, removal alone does not undo distribution of ciphertext somebody already fetched | Should be answered before another vault publishes, and it is the first entry the keys vault's audit log should carry. Detail → | waiting on human |
| N3 | Decide Q1 — who owns the Article 26(5) worked example. It is the strongest asset for this site and for risks.sgit.ai, and it already appears in that site's material. Proposed: risks owns the register and the acceptance decision; standards owns the provision and the arithmetic, one canonical copy, the other links in. This needs a decision, not a convention | Both sites currently carry it. Duplication is the cheapest thing to fix now and the most expensive later | waiting on human |
| N4 | Confirm the name. The evidence is against the word standards — the material is ~72% law, ~20% framework, ~8% actual standards. The recommendation is to keep it on one condition: the three-way distinction is the front page's first substantive claim and every instrument page carries the label. Both conditions are met and CI enforces the second. The honest runner-up is regulations.sgit.ai | A rename after the first external citation is expensive; before it, it is free | proceeding with “standards” unless redirected |
| N5 | Commission the re-derivation pass. Every AI Act citation on this site needs re-deriving from the operative text, with the retrieval recorded. Until then no operative text is published here. Start with the Article 99 third tier (1% vs 1.5%), because it is the number most likely to be quoted out of this site | The site's own thesis. Status → | waiting on human |
| N6 | Answer Q3 — can the ontology hold a standard it cannot quote? The model assumes provision text as a node property, and for ISO that text cannot be stored. Is a hollow provision node the same kind of thing or a different one? | The ISO folder cannot be designed until this is answered. Detail → | open |
| N7 | Recover the missing crosswalk brief. A strategy brief on risk-acceptance and standards crosswalks is referenced twice in the source material and is not on disk. It is the closest thing to a crosswalk document that ever existed | Recover it before writing G1 from scratch | open |
| N8 | Decide about the dev. hosts. Both the vault viewer and the ciphertext API are dev.-prefixed. A production standards site whose proposition is durable citation depending on infrastructure named dev is a risk worth naming now | Not blocking today; blocking the first time somebody cites this site in something permanent | open |
Task board
| # | Task | Owner | Status |
|---|---|---|---|
| T1 | CI pipeline and auto-tagging — first run failed on a .gitignore rule that hid the validator from git; fixed in v0.1.3 and the class of failure is now a validator check — validate → tag → deploy, ported from pki.sgit.ai, with the key-leak check extended to write-key material and a new check enforcing the instrument-labelling condition | site agent | done |
| T2 | /method/ — build order 1. The grammar, the two-hash scheme, crosswalks, the citation scheme, the grounding ladder | site agent | done |
| T3 | /eu-ai-act/ — build order 2. Points at the existing Regulation Graph vault rather than rebuilding it; four provisions, the worked example, the status page | site agent | done |
| T4 | The citation resolver — closes gap G5, the only one of the nine closed so far | site agent | done |
| T5 | Resolve the Article 99 third tier against the operative text and publish it with a retrieval record | needs N5 | blocked |
| T6 | Write the first crosswalk. AI Act ↔ GDPR is the natural pair — they apply concurrently. Unblocks the crosswalk browser | site agent | next |
| T7 | Define bridge strength — the scale behind “shades of compliance”. Q4 | site agent + lead | open |
| T8 | /owasp/ — the best first non-law page: deep, public, CC-licensed, no copyright problem, and the only framework written for the agentic case | site agent | open |
| T9 | Zip and SQLite distribution in dist/. Net-new across the whole estate | platform | open |
| T10 | PUBLIC.md on the other ten vaults. On 2 of 12 today, which is not a convention | platform | open |
Open questions, published unresolved
Following the house convention of numbering open questions in public. An unanswered question is an output.
| # | Question | Where it stands |
|---|---|---|
| Q1 | Who owns the Article 26(5) worked example — standards or risks? | Proposed split published on both this site and in the risks material. Needs a decision. N3 |
| Q2 | Does the vault or the repo hold the canonical text? The memo says vault; a later brief changed position to “vault authors, repo publishes” because clear text is what enables verification | Published as a fork with a stated division of labour, rather than settled. This is the intended resolution, not an evasion |
| Q3 | Can the ontology hold a standard it cannot quote? | Unaddressed anywhere. The ISO folder cannot be designed until it is answered. N6 |
| Q4 | What is a bridge's strength, formally? A crosswalk that can only say yes is wrong or useless. The phrase is “shades of compliance”; there is no scale | Blocks the crosswalk browser. Detail → |
| Q5 | When does a composed instrument stop being trustworthy? The AI Act vault composes two regulations because no official consolidation exists — genuinely valuable, and an unofficial text that looks official. What is the labelling obligation? | The staleness probe found a text that never was the law in the wild. This site must not become another instance |
| Q6 | Was the exposed vault key rotated, or only removed from history? | Open. Answer before publishing another vault. N2 |
| Q7 | Does the method survive instrument two? | Untested. GDPR is the test, and there is reason to think it needs special cases |
| Q8 | Should the site be multilingual? Authority anchoring gives one identifier and many labels for free, and EU instruments ship in 24 languages against the same structure | A real differentiator nobody has claimed. Also a standing maintenance commitment. Detail → |
| Q9 | Is standards the right name? | Keep it, conditional on the LAW/STANDARD/FRAMEWORK labelling — and the condition is now enforced by CI. Honest runner-up: regulations.sgit.ai. N4 |