Where the primitive is load-bearing
Nine applications, across five sites and one commercial product. This site owns the primitive; almost all of the applications live elsewhere. That is the right shape for a reference site, and it is the same shape the grounding ladder already has: each site states the idea in three lines and links to the site that owns it.
| Application | What the twin does | Owner |
|---|---|---|
| The grounding ladder | Measure is grounded on a Twin: the ladder's bottom rung | risks. / standards. |
| The regulation graph | Provision hooks attach to twins; unconnected hooks are a coverage measure | standards. |
| The risk register | Twins as the integration layer, so the system only ever sees a twin | risks. / riskmandate |
| Identity visualisation | The digital twin built from identities, as the first thing you build | nhi. |
| The agent twin | Permissions, capabilities, track record and credibility as twin properties | this site |
| The S3 container | The worked drop-in twin | sg-compute ships it; this site explains it |
| The 2FA capstone | The bottom-up fractal demo: organisation, HR, people, roles | this site designed |
| World models | Twins assembled into a simulated company world | this site designed |
| Hyperscaler abstraction | Twins as what keeps the model portable across cloud consumption | sg-compute adjacency |
Four of the nine are owned by other sites, three are this site's own designed layer, one is shipped elsewhere and explained here, and one is adjacent. One of the nine is built. The built-and-designed table →
The grounding ladder primitive
The ladder runs Fact, Evidence, Measure, Vulnerability, Risk, and its bottom rung is the one this site owns: Measure := an observation of the node it measures, grounded on a Twin. An observation with nothing under it is not a measure, which is what stops a risk register filling with numbers whose provenance nobody can reconstruct.
The ladder as a whole, its stopping test and its use in a risk register belong to risks.sgit.ai and standards.sgit.ai. What belongs here is the rung and what happens at it: the doorway, the air gap, the discipline. The doorway role →
The regulation graph, and coverage shared
Every paragraph of an instrument is a graph; its provisions carry hooks; hooks attach to the things an organisation actually has, which are twins. The consequence is the estate's best twin idea: "a provision whose hooks have no twin attached is a provision that has not yet been connected to anything the organisation actually has, and counting those is a direct, computable statement about how much of the instrument has been genuinely mapped rather than merely imported."
The instrument, the paragraph model and the definitions are standards.sgit.ai's. The twin idea inside it is this site's, and the number has never been computed. The coverage measure →
The risk register, and the integration layer designed
The claim is an integration claim rather than a modelling one: "the system only ever sees a twin, so it works in an enterprise way from the first moment." Instead of building connectors before the product does anything, the product talks to twins from day one, and the twins are progressively connected to real systems or recorded as tracked air gaps.
Which produces the commercial version of the same sentence: "onboarding becomes describing what you have, which builds the digital twin of the organisation." Attractive, and unproven. Owned by risks.sgit.ai and the riskmandate product; this site holds the primitive it rests on.
Identity twins, and visualisation as the entry point designed
The NHI work builds "the digital twin built from identities", with a positioning claim attached: visualisation is "not a feature you add later but where you start, and likely the first revenue stream." The argument is that an identity estate is unintelligible as a list and legible as a graph, and that the legibility is the product.
Owned by nhi.sgit.ai, which links here for the primitive.
The agent twin designed
An agent modelled as a twin, "whose permissions, capabilities, track record, and credibility become properties of the twin." This is the primitive turned on the things now doing the work, and it is the natural counterpart to twins as actors: if a twin performs graph transformations, the agent behind it needs its own twin with its own connectedness.
The brief that proposes it also carries the objection, "the standing question of how connected the twin actually is to reality", which this site publishes as question 1 rather than answering. Identity and mandate for agents are pki.sgit.ai's subject; the twin of the agent is this site's.
The S3 container built
The one that works. sg-compute ships it; this site explains why it is a twin rather than a compatibility shim, which is the distinction the whole primitive turns on. The worked proof →
The 2FA capstone designed
The bottom-up fractal build: organisation, HR system, people and roles as twins stored in IssueFS, assembled from the bottom rather than declared from the top, with the abstraction layers placed at the real seams. It is the designed milestone against which everything downstream labels itself, and it does not exist. Milestone one →
World models designed
Twins assembled into "a Civilization-style world where a company operates", built from mini agents, with every action version controlled in the vault and MITRE ATT&CK layered on top. Entirely unbuilt, published as a roadmap. The simulation layer →
Hyperscaler abstraction designed
Twins as the abstraction that keeps a model portable across cloud consumption, so the graph does not become a description of one provider's console. Adjacent to sg-compute. The source brief carries vendor positioning beyond its twins section, so this site quotes the twins-abstraction part only.