# Can You Compute Your Plug Profile?

**version** v0.33.51
**date** 24 July 2026
**from** Human (project lead)
**to** Board, Executive, Security, Risk, Public
**type** Strategy brief (series)

*Piece 9 of the Who Can Pull The Plug series. The RAMM close and product landing. Offered to be built on and challenged.*

---

## What This Is

The maturity test the whole series has been building toward: **a mature organisation can state, for every consequential agent it runs, who pulls the plug, how large the blast radius, how fast, with what side effects, and how much can be recovered, and it can show that these answers are true rather than asserted, while an immature one has free text and hope; the difference is not the size of the security team or the length of the policy, it is whether the plug profile can be computed from evidence or only claimed in a questionnaire, which is exactly the maturity RAMM already measures, maturity you compute not claim, so plug-profile completeness becomes a maturity probe expressible as a graph query in the node-type-formula style, where a level is a fact about the graph rather than a narrative, and the single most valuable query in the whole model is show me every accepted risk whose recoverability is zero, because that set is the list of things no plug will save after the event and which must therefore be governed by prevention and by the most senior acceptance; adopting RiskMandate is the mechanism that produces the profile, since a graph-native acceptance workflow generates exactly the owned, evidenced, interval-bound records the query needs, so the introduction and the product close on the same object, and the reader who has followed the five questions arrives here at a page they can actually run against their own estate.** This is piece 9 of the Who Can Pull The Plug series (cross-ref: the series-plan document, the pillar, the v0.33.40 RAMM brief, and the recoverability piece). New contributions: **plug-profile completeness as a computed maturity probe, the zero-recoverability query as the flagship, and the close that unites the introduction with the product.**

## The Test Is Whether You Can Compute It

Every organisation will say it takes the plug question seriously. The test is not the answer but whether the answer can be computed. A mature organisation can produce, for any agent, the five-part profile and the evidence behind each part: the named holder and proof they can actually pull it, the measured blast radius, the tested time-to-pull, the known side effects, and the honest recoverability. An immature one has, at best, a spreadsheet of intentions and a shared belief that someone would handle it. The gap between them is not effort or headcount, it is whether the profile is derived from evidence or asserted in prose, and that is a difference a query can detect.

## This Is Exactly The RAMM Promise

The site already states the principle: maturity you compute, not claim. RAMM treats acceptance as a durable, linked decision node and derives an organisation's maturity from the graph rather than from a self-assessment. The plug profile drops straight into that model. Each dimension is a set of required edges on the acceptance node, and plug-profile completeness is a level predicate: an organisation is mature on this axis when its acceptance nodes carry a named plug-holder, a measured blast radius, a tested speed, recorded side effects, and a recoverability value, and it is not mature before, no matter what it claims. The maturity is a query that returns true or false, which is what makes it honest.

## The Query That Matters Most

Of all the queries the model enables, one deserves to be first-class, and it is the one recoverability demands: show me every accepted risk whose recoverability is zero. That set is the organisation's irreversible exposure, the risks where no plug helps after the event and where only prevention counts. An organisation that can run that query and read a short, deliberate, senior-owned list is in control of its worst exposure. An organisation that cannot run it does not know where its irreversible risks are, which means it is accepting them by default and by silence. The query is both an assurance check and a maturity probe, and a register that cannot answer it is failing at the one thing that matters most.

```
   IMMATURE                            MATURE
   "someone can stop it"                who: named, proven able to pull it
   free text rationale                  blast radius: measured
   a review someday                     speed: tested against time-to-damage
   recoverability unconsidered          recoverability: valued and queryable
   -------------------------            -------------------------
   the profile is CLAIMED               the profile is COMPUTED
   and the key query cannot run         "show every zero-recoverability risk"
```

## Adopting The Product Is The Mechanism

The reason this is the closing piece is that answering the maturity test and using the product are the same act. RiskMandate is the graph-native acceptance workflow, so it produces exactly the owned, evidenced, interval-bound acceptance nodes that the plug-profile query needs to return true. An organisation does not adopt RiskMandate and then separately become mature; the acceptances it creates are the maturity, measured against RAMM. The introduction that began with a question every board understands ends with a page the reader can run against their own estate, and the honest result of that run, complete profile or free text and hope, is the reason to book the demo.

## What This Does Not Try To Be

- **Not a maturity questionnaire.** The whole point is that the level is computed from evidence, not self-rated.
- **Not a claim that adoption equals maturity by fiat.** The acceptances have to be real; the product produces the records, the organisation must do the deciding.
- **Not the end of the profile.** Computing it is the floor; keeping it current as agents and estates change is the ongoing work.

## Honest Tensions

| Tension | Note |
|---------|------|
| Computed maturity versus partial evidence | Real estates yield messy, partial data, and the maturity model must tolerate gaps without either failing everyone or passing everyone |
| The query is only as good as the field | The zero-recoverability query depends on recoverability being scored honestly, which the recoverability piece leaves open |
| Adoption as the mechanism versus doing the work | The product produces the records, but a wall of low-quality acceptances would compute a false maturity |

## Open Questions

| Question | Notes |
|----------|-------|
| What are the plug-profile level predicates? | The exact required edges at each maturity level for the plug profile axis |
| How is completeness scored across an estate? | Whether maturity is per agent, per unit, or portfolio, and how partial coverage is handled |
| How is the zero-recoverability query kept honest? | Preventing the recoverability field from being set high to make the list short |

## Relationship To Previous Briefs

| Date | Document | Relationship |
|---|---|---|
| 24 Jul | `v0.33.51__strategy-brief__sg-send-who-can-pull-the-plug-series-plug-always-exists-blast-radius-speed-side-effects-recoverability-positioning-and-document-plan.md` | The series-plan anchor; this is the maturity close it names |
| 2 Jul | `v0.33.40__arch-brief__sg-send-risk-acceptance-maturity-model-ramm-graph-native-levels-agentic-crosswalk.md` | Maturity you compute not claim; plug-profile completeness is a node-type-formula maturity probe |
| 24 Jul | `v0.33.51__strategy-brief__sg-send-what-money-cannot-buy-back-recoverability-the-hard-limit.md` | Recoverability as a first-class field; the flagship query depends on it |
| 24 Jul | `v0.33.51__strategy-brief__sg-send-who-can-pull-the-plug-pillar-the-plug-always-exists-the-question-is-the-profile.md` | The pillar's question; this is where the reader can run it against their own estate |

---

## Key Claims

| # | Claim |
|---|-------|
| 1 | Maturity is whether the plug profile can be computed from evidence, not claimed in prose |
| 2 | Plug-profile completeness is a maturity probe in the RAMM node-type-formula style |
| 3 | A level is a query that returns true or false, which is what makes it honest |
| 4 | The flagship query is every accepted risk whose recoverability is zero |
| 5 | An organisation that cannot run that query is accepting its irreversible risks by silence |
| 6 | Adopting RiskMandate produces the records the query needs, so introduction and product close on the same object |

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
