Demo · outcome switchboard
What do you want to see?
Pick an outcome. Each block is a live route or a short framed exhibit — not a minute-by-minute talk track. Pressure-test the function. Build the defender’s skills.
See why now
For leadership and practitioners who feel the gap
Forrester share-of-concern, live. Then the plain-English threat map — every AI threat named with its fitted control and who reskills for it.
What leaders fear most
Base: 1,528 AI decision-makers who have concerns about AI usage. Source: Forrester's State of AI Survey, 2025.
Pressure-test a function
For function heads and CISOs · Track 1
Open the maturity door: live instruments (Quick Mythos + function diagnostic), company samples, and the living standards map. Autonomy must never outrun maturity — the gate says so in plain words.
Build the defender’s skills
For practitioners and people leads · Track 2
Seven personality seats on the skills hub; personal mastery self-place (Aware → Leads) on the same Cloud Security Alliance (CSA) spine. Public, self-assessed, nothing saved.
Board scorecard sample
For CISO / board altitude — not a single-function report
Org-wide AI Security Maturity Model (AISMM) maturity × AI Cyber Maturity Model (AI-CMM) autonomy (illustrative seed). Exposed teams light up. Refresh after a model jump; the same grid tells you who tipped.
Assess-once standards lenses
For compliance · one assess, many regimes
Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.
Fitted guard proof
For builders and security engineers · lab-app receipt
A guard fitted to one real running app catches what the stock filter missed, and the lift is measured before and after, not claimed.
The practice spine
One questionnaire · two equal reads
Pressure-test the function. Build the defender’s skills.
Same underlying answers. One door scores the function. The other names the skills the defender builds next.
The instrument
One questionnaire
Answered once, read twice.
The repo
What we know.
The proof.
Track 1 · Org
Where has AI moved into each function, and did controls keep up?
The gate: Autonomy must not outrun maturity.
Also into Ace: Ace's watch → Field signals on threats and skills. Hermes research, human-reviewed.
Door CTAs on home open the same two reads. Lab-app receipt: StoryBond prove →
Closing the Centre of Excellence loop with field signal
Ace's watch · the homes-agent feed
The practice already has two equal reads of one questionnaire: pressure-test the function, and build the defender’s skills. Ace’s watch is the third motion: what changed in the field, and what a security person should learn because of it. Guided by Ace; human-reviewed before it shapes curriculum.
Situation
A Centre of Excellence (CoE) that only refreshes when someone remembers to read the standards falls behind model and threat velocity. The homes agent (Hermes on the Hostinger VPS) already drafts a human newsletter from open-web research. That newsletter is useful for humans; it is not a curriculum.
The site feed is the differentiator: every published item must name a skill consequence (`skill_delta`), ground against the Cloud Security Alliance (CSA) corpus via `ask_standard`, and cite a real AI Controls Matrix (AICM) control when it claims one. Items that cannot do that are dropped. The home strip and `/ace#watch` stay empty rather than stale.
Approach
Ace's watch on the home page uses the same eyebrow and tagline as the dossier (What changed. And what to learn because of it.). Home shows a short approved teaser; the fuller strip lives at /ace#watch. Copy is cadence-neutral: the cron’s rhythm is Hermes’s business.
A slower living-corpus cron posts persona-scoped findings into `reskill_findings` (“Fresh for you” on guide doors). Canon never mutates at runtime; promotion is an owner step.
Site-feed item kinds (from code)
- From the practice (`loop`)
- From the field (`signal`)
Operating rhythm
There is no Vercel Cron for this loop. Scheduling lives on the Hermes VPS (`/opt/data/config.yaml`).
- 01:15 UTC daily. Pre-flight: secret set, endpoints reachable, feeder present.
- 01:30 UTC daily. Daily Security Briefing → Telegram / Slack newsletter.
- 01:35 UTC daily. Site feed: skill consequences → ground via `ask_standard` → POST `/api/agent/briefing`.
- Daily (separate). Reskill-research fan-out → POST `/api/agent/reskill-findings`.
AGENT_TOOL_SECRET on the VPS only; site writes with service-role that never leaves Vercel.
Unattended research stays on the designed ledger until verified live. Watch strip claims human-reviewed curation, never simulated liveness.
Sources (ops-named)
The RSS roster lives on the Hermes box. Ops handoffs name these after the 2026-07-16 cull. Do not invent the unnamed remainder.
How it connects
Skills
Each skill consequence bridges to Track 2 and fitted SKILL.md work.
Threats
Field signals land on `/threats` and real AICM domains — never a third taxonomy.
Standards
Grounding and control ids must resolve to real AICM objectives. Fake ids 422.
Practice spine
On the SpineDiagram, Ace’s watch is the “Also into Ace” field input — not a fourth front door.
Next moves
- Bind every watch item to a CoE artefact slot. Skill to fit, threats entry to refresh, mastery prompt, or crosswalk note — no orphan headlines.
- Promote living-corpus findings on a standing cadence. Fresh-for-you is candidate layer; owner promotion into canon is how curriculum actually moves.
- Keep catalogs as lenses on one assess. Feed kinds open sample-report and standards lenses with a skill consequence — never a parallel quiz.
Controls reference
For auditors, compliance, and practitioners
Four lenses on the control spine — by domain, framework, instrument, or ownership — not a catalogue dump. Ask Ace when someone challenges “says who.”
Also prove
Finished stories with problem and outcome up front (from the curated roster).
Demo is an outcome switchboard (noindex). Header Demo lands here. Timed oral scripts are retired. Data: web/lib/demo-runsheet.ts · roster: web/lib/demo-cases.ts.