OpenChainGraph · Explainer 5 steps and two gates

The AINumbers Policy Mandate

Every policy and compliance tool in the catalog can hand you one small JSON file: the Policy Mandate. This page walks the v1.0 schema member by member, then follows the document through the two gates that stand between a finished run and a download: the export button's own validation, and the reference validator the repository runs on every build.

Presenter mode shows one step per screen. Arrow keys move, A toggles autoplay, Esc exits.
Every schema member quoted on this page comes from CONTRACT.md §3.1 at commit cd3071e0, the tip of the public main branch on 2026-10-04, and every validation result was run at that commit on that day.
Part one · The artifact

What the mandate contains

One schema covers every policy export in the estate. The first three steps read it from top to bottom.

1
Step 1 · The file itself

One file every policy tool can hand you

A Policy Mandate is AINumbers' own structured format for a compliance or policy result. When a run finishes, the tool's export writes the assessment into this format and offers it as a .policy.json download.

a finished runthe tool computed its result Export Policy Mandateevery policy tool ships it a .policy.json fileone schema for the estate

The contract's export rules make this file mandatory equipment: the Tier 1 export obligation requires a Policy Mandate download from every tool whose output is a policy assessment, alongside its Markdown export. On the repository tree of 2026-10-04, 555 of the 590 tool pages carry the export. Nine catalog tools carry AP2 in their names 102 · 131 · 164 · 259 · 285 · 310 · 320 · 323 · 326. They assess questions in the AP2 problem domain, and the files they emit are AINumbers Policy Mandates describing those assessments.

Give this to an agentread-only
Open any policy tool on ainumbers.co, complete a run, and use its Policy Mandate export. List the top-level members of the downloaded file and keep it for the checks on the rest of this page.
2
Step 2 · The envelope

Who issued the mandate and what kind of rule it carries

The top of the schema identifies the document, the tool that produced it, and the kind of policy it carries. Every member below comes straight from CONTRACT.md §3.1.

the mandate envelope mandate_id issued_at · issued_by tool_id · tool_version jurisdiction · regulatory_frameworks mandate_typeone of fifteen fixed valuespayment_policy · compliance_control · agent_guardrail_mandatethe full fifteen are listed below
MemberWhat it holds in the v1.0 schema
mandate_ida UUIDv4 identifier for this document
issued_atan ISO 8601 timestamp for the issuance
issued_bythe issuing domain; the schema's value is ainumbers.co
tool_idthe id of the tool that produced the assessment
tool_versionthe semver of that tool
mandate_typeone of the fifteen fixed values listed below
jurisdictionan array of ISO 3166-1 alpha-2 country codes
regulatory_frameworksan array of the frameworks the assessment speaks to
The fifteen mandate_type valuesCONTRACT §3.1
payment_policy · aml_rule · kyc_requirement · routing_policy · compliance_control · risk_parameter · credit_assessment · fx_policy · scheme_rule · disclosure_template · fee_schedule_mandate · velocity_rule_mandate · incident_classification_mandate · routing_policy_mandate · agent_guardrail_mandate

The envelope is deliberately mechanical. mandate_id is a UUIDv4 string and tool_version is semver, so both are checkable with one regular expression. jurisdiction carries two-letter country codes and regulatory_frameworks names the frameworks the assessment addresses. mandate_type is the member a downstream consumer reads first, because it says which of the fifteen policy kinds the document belongs to.

Give this to an agentread-only
Read the downloaded .policy.json and report its mandate_id, issued_by, tool_id and mandate_type. Confirm that mandate_type is one of the fifteen values this page lists.
3
Step 3 · The assessment

The assessment carries its own provenance

Below the envelope sits the assessment itself, the inputs that produced it, and an audit block that describes how the run executed.

the assessmentpayload · summary agent_instructions valid_from · valid_until · last_reviewed source_tool_inputs · regulatory_citations audit_metadataexecution_hash: an optional SHA-256 over the runclient_side_executed · zero_pii_verified · deterministic_runthree booleans about how the run executed
MemberWhat it holds in the v1.0 schema
payloadthe assessment itself, as an object of result values
summaryone to three sentences of plain English over the result
agent_instructionsordered action strings a downstream agent can follow
valid_from · valid_untilISO 8601 bounds of the mandate's validity
last_reviewedthe ISO 8601 date the assessment was last reviewed
source_tool_inputsthe inputs the run consumed, as an object
regulatory_citationsan array of citations the assessment stands on
audit_metadata.execution_hashan optional SHA-256 pinning the exact computation the tool ran
audit_metadata booleansclient_side_executed · zero_pii_verified · deterministic_run

The audit block ties a mandate to the estate's wider evidence story. client_side_executed asserts the computation ran in the reader's browser. zero_pii_verified asserts no personal data entered the run. deterministic_run asserts a re-run reproduces the result. Where a tool pins execution_hash, that hash names one exact computation the tool performed.

Give this to an agentread-only
Open the audit_metadata block of the downloaded mandate. Report each boolean and state whether an execution_hash is present.
Part two · Validation before download

Two gates stand between the run and the file

A mandate only helps while it is well formed. The estate checks that twice: once in the browser that would write the file, and once on every build of the repository.

4
Step 4 · The browser gate

The export button validates before it writes a file

The export button is disabled until a run completes. Click it after a run and the tool validates the whole document against the schema first: only a valid document reaches the download step.

a finished runthe analysis completed export enabledthe button unlocks after a run validate the documentthe schema check runs firsta failed check blocks the download valid: the download starts invalid: blocked with a red toast

The interaction contract fixes the states. Before any run the export sits disabled with a tooltip: "Run the analysis above to generate a Policy Mandate". After a run it becomes ready and the tooltip becomes "For API integration · audit trail". Clicking the button validates the whole document, and the browser creates the download's object URL only once that check passes. A failed validation blocks the download and raises a red toast listing the errors. The file is named {tool_id}_{YYYYMMDDHHMMSS}.policy.json, so a folder of exports sorts by tool and by the second each was written.

Try itbrowser
Pick any policy tool on ainumbers.co. Click its Policy Mandate export before running the analysis and record what happens. Then complete a run and export again. Report both behaviours and the file name the second download carries.
5
Step 5 · The repository gate

The same schema is checked on every build

The repository carries a reference validator for the mandate, and the site's preflight suite and CI both run it on every build. A schema change that would break shipped exporters cannot land quietly.

every build of the sitepreflight and CI scripts/validate-policy-mandate.mjsthe reference validator a v1.0 document: valid an empty mandate_type: rejected
The checknode
node --input-type=module -e "import { readFileSync } from 'node:fs'; import validate from './scripts/validate-policy-mandate.mjs'; const doc = JSON.parse(readFileSync(process.argv[1], 'utf8')); console.log(validate(doc));" -- downloaded.policy.json
The validator at commit cd3071e0, run on 2026-10-04Result
a document carrying every member of the v1.0 schemavalid: true · errors: none · warnings: none
the same document with mandate_type emptiedvalid: false
the error the second run reportedmissing required field: mandate_type

The results above are the validator's own output at the commit this page cites. It reports valid, errors and warnings, and it never throws on a malformed document, so a broken file produces a report rather than a crash. The command above runs it by hand against any downloaded mandate from a checkout of the public repository.

Give this to an agentnode
Validate any downloaded mandate with the repository's reference validator. Report the valid flag plus any errors and warnings.
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.