# 02 — What is built, and where twins are applied

---

## 1. The working twin: the S3-compatible vault container

The estate's one shipped twin, and the best proof of the concept:

> *"the container is **a digital twin of S3**, presenting the same S3-compatible API, so that code using boto3, the AWS CLI, or any S3 SDK **believes it is talking to real S3**, while the files are served from a vault, from local disk, or from memory, chosen as a swappable backend; **the service's own code does not change**."*

Why it is the right exhibit: it demonstrates the twin as a **drop-in interface rather than a simulation**. The consuming code is unmodified; the redirection is an endpoint change; the AWS credential fields are reused to carry the container's auth header. And it demonstrates **stacking** — real S3, or a vault, or memory, behind the same face, selected per environment.

The sg-compute analysis confirms the delivery surface exists (`Routes__Vault__Spec`, the vault specs, the docker packaging). **Lead `/built/` with this.**

## 2. The AWS twins — half-built, honestly labelled

The IAM config risk engine (5 Jul, 2,039 w):

> *"it grounds each AWS object **as a twin** — an IAM policy, an S3 bucket, an EC2 permission — connected to reality the way the grounding ladder requires"*, reusing *"the existing Python codebase and **the digital twins already built**."*

With the principle that makes it a twin application rather than a scanner: **context-not-configuration** — *"the existence of a configuration is never itself a risk… a public S3 bucket is a fact and not a problem until you know what it holds."* The engine produces *"evidenced, typed objects"*; the rating layer rates. Facts from twins, judgement elsewhere — the grounding ladder as a pipeline.

## 3. The application map

Where the twin primitive is load-bearing across the estate, with owners:

| Application | What the twin does | Owner site |
|---|---|---|
| **The grounding ladder** | `Measure` is grounded on a Twin — the ladder's bottom rung | `risks.` / `standards.` |
| **The regulation graph** | Provision hooks attach to twins; unconnected hooks = a **coverage measure** over the instrument | `standards.` |
| **The risk register** | Twins are the integration layer — *"the system only ever sees a twin, so it works in an enterprise way from the first moment"* | `risks.` / riskmandate |
| **NHI visualisation** | *"the digital twin built from identities"* — visualisation as *"not a feature you add later but where you start, and likely the first revenue stream"* | `nhi.` |
| **The agent twin** | *"whose permissions, capabilities, track record, and credibility become properties of the twin"* — with the standing question *"how connected the twin actually is to reality"* | this site |
| **The S3 container** | The worked drop-in twin | `sg-compute.` ships it; this site explains it |
| **The 2FA capstone** | The bottom-up fractal demo — org, HR, people, roles as IssueFS-stored twins | this site (designed) |
| **World models** | Twins assembled into *"a Civilization-style world where a company operates"*, mini agents, vault-versioned actions, MITRE ATT&CK layered on | this site (designed) |
| **Hyperscaler abstraction** | Twins as the abstraction that keeps the model portable across cloud consumption | `sg-compute.` adjacency |

**This site owns the primitive; the applications mostly live elsewhere.** That is the right shape for `twins.sgit.ai` — the reference the other sites point at, exactly as the grounding ladder pattern already works. Each application page here is three paragraphs and a link out.

## 4. The world-model layer — design, clearly labelled

From the 26 June strategy brief: assemble twins into a simulated world — *"an org chart, actions, risks taken, compromises, and clients buying, built from mini agents"* — with the vault as the engine: *"every action is version controlled and every connection is mapped by folders and files without a database… a showcase of serverless databases."* And the honest note that *"LLMs are good at generating worlds and games"*, so the game-design architecture is the explicit analogy.

None of it is built. Publish it as the simulation roadmap, with the 2FA demo as its first concrete milestone — *"develop the core pieces of technology on top of these use cases, which are both a good way to build the technology and a good way to explain how it works."*

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
