# Insurance For Agents: The Policy Replaces The Acceptance At The Foundation, And The Delta Is Where The Insurance Lives

**version** v0.33.71
**date** 30 August 2026
**from** Human (project lead)
**to** Strategy, the RiskMandate team, the registry site

**type** Strategy brief — a pivot briefing

*Produced from a voice memo of 30 August 2026, carried verbatim below and then read against the corpus by the site agent. Everything in the transcript is the project lead's; everything under "the reading" is the site agent's and is labelled as such, including one transcription repair proposed rather than applied. The pivot is recorded here as PROPOSED: no published surface has been rebuilt on it, because a foundation should be argued in change control before anything is stood on it.*

---

## What This Is

A pivot in the risk approach, recorded before anything is built on it: **the memo moves the foundation of the RiskMandate pyramid from risk acceptance to the insurance policy, on the argument that the delta between the grant and the mandate — what the agent can do minus what the agent is authorised to do — is where the insurance lives; that this is not a new machine but a new terminal node for the machine already built, since insurance consumes exactly the artefacts this estate already produces (a measured grant, a signed mandate, a computed delta, facts attached to a twin, and an evidence pack at every decision); that the corpus's own hardest sentence — excess authority is unaccepted by construction, because nobody can accept an exposure nobody has written down — acquires a commercial completion, because an underwriter is an acceptor of last resort, accepting for money what no owner accepted, which means the `"acceptor": null` field the register already publishes in its excess-authority view is literally the empty seat a policy fills; that there are two distinct insurances and only one of them is this pivot's subject, since harm done inside the mandate is ordinary liability with a priced history, while harm from the delta is the agent-specific exposure nobody currently carries; that the memo's payout logic — if this happens, then you get this — is parametric insurance described without the word, and parametric is the shape this estate can actually demonstrate, because every trigger it would name is already computable from published documents; and that the memo's proposed agentic insurance maturity model maps with almost no invention onto the estate's existing rating variables: identity class, enforcement tier, twin freshness, and the size of the delta.** It is the first document of 30 August (cross-ref: the v0.33.61 grant-is-not-mandate brief, the v0.33.60 service-twin brief, the v0.33.62 pack-spec, the v0.33.59 two-populations brief, and the 30 August workbench memo). New contributions: **the policy as the terminal node of the chain, the insurer named as the acceptor of last resort, the two-insurances split, the payout connected to parametric triggers, the maturity model connected to the existing tiers, and the loss event identified as the one primitive the estate does not have.**

## The Memo, Verbatim

*Transcribed by otter.ai; carried whole, exactly as received, because the raw transcript outranks any summary of it. One phrase is almost certainly a transcription error and is repaired in the reading below, not here.*

> Okay, so so I want to do a little pivot on the on the risk mandate and the sort of the risk approach, and and we want to on on the idea of creating cyber insurance, basically insurance for AI agents, right? And and the logic is that we want to basically, in a way that is actually quite compatible with what we're doing right now. But the pivot is that instead of at the top of the sort of the pyramid of the logic we have or the foundation, we have risk acceptance. What we have is we have security policies, right? Sort of insurance policies, and and the logic with this is that ultimately, when you sort of measure and when you talk about risk, and when you talk about you know the the side effects, especially when you talk about the the delta between the grant and the mandates, which is what we're talking about here, right? What we then have is a world where the the difference between what the agent can do, right, which is the the grant, and what we want the agent to do, which is the mandate, the delta of that, is where the insurance lives, right? So if you think about it, like in in in the case where the the grant is exactly the same as the mandate, the the the risk is, I guess, is connected to what the the agent can do, but it's it's quite understood, right? So there's a set. In fact, there's actually two risks here, right? Two two type of insurances, but the one of the ones that we are connecting is the the insurance of what you know. What can the agent do in addition to to the mandate that we we give the agent, right? And what the hell? Sorry. So, so that's that's the thing that we we're trying to figure out here, right? So we're trying to figure out here is what what should and what could an insurance flow look like? And what's cool about it is that we already have, I think, a lot of the primitives. We already have a lot of the ways to do this, because ultimately this is a graph, right? It's a graph that has to be connected to the grant and the evidence and the mandates. And if you think about it, all the the components that we have mapped lead this very quickly. So what we kind of need to do is we need to think about what would this look like from an insurance point of view. What would this look like from a sort of a governance and a sort of a structure where we are giving insurance policies to you know to the agents so that whenever you deploy an agent in in your environment, you also need to have what's it called? You also need to have an insurance policy. And to be honest, like this is already a very common world, right? Like you know, employees have employee liability insurance. When I was a contractor, right? You you needed to have you know redempting insurance, right? There's all sorts of insurances that already exist in businesses. What we're now doing is we're saying, well, agents are a bit of a different, you know, you know, entity, and they need to have specific insurance that is specific to the agents. So, for example, one of the things we can do is we can create an agentic insurance maturity model, right, or some kind of modes that we we can do so that it it it works, you know, at that level, right, and so we yeah, so the so let's start mapping this out. Let's start connecting the dots here, right, and seeing what this could look like. Especially because, for example, when you talk about insurance, we need to talk about the the bits that, like, what what you the payout of the insurance, right? So so it's almost about you know reducing the you know like the primitives here because at the end of the day the insurance will be paying out in case something happens or the damage right so we need to kind of again connect those dots so then we can say hey if this happens then you get this payout if that happens, then you get this, and then we can connect that straight away to those capabilities. So yeah, let's let's map this out.

One repair, proposed as a reading: *"redempting insurance"* in the contractor sentence is almost certainly **indemnity insurance** (professional indemnity), which is what a UK contractor is required to carry. The argument does not depend on the repair.

## The Pivot, Stated — the site agent's reading from here down

The chain this estate publishes ends like this: *reality → twin → facts → finding → risks → decisions*, with **risk acceptance** as the terminal act — an owner signs that the organisation chooses to carry an exposure. The memo replaces the terminal node:

| | Acceptance (today) | Policy (the pivot) |
|---|---|---|
| Who carries the exposure | The owner who signs | **A third party, for a premium** |
| What it costs | A signature and accountability | Money, priced against evidence |
| What it demands of the estate | A named acceptor and a dated interval | **Everything acceptance demands, plus a rating basis** — the measurement has to be good enough that a stranger will bet on it |
| What happens when nobody does it | The exposure defaults to critical and escalates itself | The agent is uninsured, and "deploying an uninsured agent" becomes a governance event anyone can check |

The second row is why the pivot is *compatible with what we're doing right now*, as the memo says, rather than a change of direction: **a policy is a stricter consumer of exactly the same artefacts.** An acceptance can, in the worst case, be theatre — a signature over an exposure nobody measured. A premium cannot be theatre; someone loses money if the measurement is wrong. The pivot upgrades the audience for the estate's evidence from *the owner who ought to read it* to *an underwriter who is paid to disbelieve it*.

And it lands on a field that already exists. The register's [excess-authority view](../registry/views/excess-authority.json) publishes, today, for every measured delta:

```json
"excess_authority": { "acceptor": null, "note": "the difference has no acceptor", ... }
```

**That `null` is the pivot.** The corpus's hardest sentence — excess authority is unaccepted by construction, because nobody can accept an exposure nobody has written down — has had no answer except "write it down and find an owner". The memo supplies the second answer, the one the rest of the economy uses: **the insurer is the acceptor of last resort.** An underwriter accepts, for money, what no owner accepted. The empty seat the register has been publishing is the seat a policy sits in.

## The Two Insurances, Separated

The memo catches this itself — *"there's actually two risks here, right? Two two type of insurances"* — and the separation is load-bearing, because the two are priced off different objects and only one is novel:

| | Cover A — mandated operations | Cover B — the delta |
|---|---|---|
| Insures against | Harm done while doing **what was authorised** — the agent pushes to dev, as mandated, and the push takes production down | Harm done through **what was possible but never authorised** — the credential reached forty other repositories and something exercised that reach |
| Insurable interest | The **mandate** | The **delta** (grant − mandate) |
| Human analogue | Employers' liability; professional indemnity | **None that fits.** The nearest is insuring a contractor who was handed the master key to the building to fix one tap — and the building industry's answer is to not hand over that key |
| Priced today? | Approximately — it resembles existing operational/professional cover | **No.** No loss history, no rating basis, no market |
| The memo's focus | Acknowledged | **This one** — *"the one of the ones that we are connecting"* |

Two consequences fall out of the split. **When grant equals mandate, Cover B's premium goes to zero** — the delta is literally the rating variable, so an operator who narrows the grant is buying down premium, which for the first time makes least-privilege *financially* legible rather than just virtuous. And Cover B is exactly the exposure of the [two-populations thesis](v0.33.59__strategy-brief__nhi-site-two-populations-industry-answers-only-agents-you-run.md): for rented agents, where you cannot attest the workload and your only lever is the credential you hand over, control is not available and **transfer is what remains**. *Hand over a credential and hope* gets its commercial completion — the hope becomes a premium.

## The Dots, Connected: insurance vocabulary onto the estate's primitives

The memo's claim — *"we already have a lot of the primitives... it's a graph that has to be connected to the grant and the evidence and the mandates"* — checked against what is actually published. Each row names where the primitive lives today:

| Insurance concept | Estate primitive | Where it lives today | Fit |
|---|---|---|---|
| Proposal form / risk survey | The **measured grant** — the twin | [library entries](../packs/grant-and-mandate/library.html), generated by `measure.py` | Good, with a stated caveat: a grant is a **floor, not a census** — an underwriter must price the survey's own blindness, which the entries already declare |
| Policy schedule (insured, period, cover) | The **mandate** — issuer, subject, scope, interval | [mandates/current.json](../packs/grant-and-mandate/mandates/current.json), signed | Direct — the five fields of a mandate are the schedule's fields |
| Exclusions | **Prohibitions** | The mandate's prohibitions block | Direct |
| Warranties / conditions precedent | **Facts** attached to the twin | The workbench's facts; N12's branch protection | Direct, and the mechanics already exist: a breached warranty voids cover exactly as a flipped fact drops the enforcement tier |
| Insurable interest (Cover B) | The **delta** | [views/excess-authority.json](../registry/views/excess-authority.json), computed never stored | Direct — including the `acceptor: null` seat |
| Underwriting evidence; proof of loss | The **evidence pack** | `evidence-pack/v0` (GM-D33), emitted per decision | Good — checks with sources, twin age, tier, `does_not_prove` inside the artefact; a claims file is an evidence pack with `mode: enforcement` plus receipts |
| Claims record / audit trail | **Receipts** from an execution broker | Designed in the [service-twin brief](v0.33.60__arch-brief__service-twin-agent-never-holds-the-credential-closes-the-authorised-misuse-boundary.md); not built | Designed only — and the brief's own line was that receipts *"create an evidence chain rather than relying on mutable platform audit logs"*, which is precisely what a claims process needs |
| Premium rating variables | **Identity class, enforcement tier, twin freshness, delta size** | The register; GM-D29's computed tiers; the pack's ages | Good — see the maturity model below |
| Renewal | **Re-measurement** | GM-D16, open: *how often is an entry re-measured?* | **The pivot answers an open decision**: policies renew on a date, so the twin must re-measure on a date. Insurance gives re-measurement the forcing function it lacked |
| Loss event; payout trigger | — | **Does not exist** | The one missing primitive. See below |

**The one the estate does not have is the one insurance cannot do without.** Everything above prices the *ex ante* side. A payout needs the *ex post* side: a **loss event** — what happened, attributable to which subject, exercising which capability, with what severity. Nothing in the register, the pack, or the workbench records harm; the closest object is an evidence pack for a refused action, which is the opposite of a loss. `loss-event/v0` is the schema this pivot forces into existence, and the memo's own payout logic says what it must contain: *"if this happens then you get this payout... connect that straight away to those capabilities"* — the trigger must name a capability, the very strings the vocabulary already defines.

## The Payout Is Parametric, And That Is The Estate's Good Luck

The memo's payout sentences describe, without using the word, **parametric insurance**: cover that pays a pre-agreed amount when a defined, measurable event occurs — no loss adjuster, no negotiation, the trigger either fired or it did not. (The indemnity alternative — pay the assessed actual loss — needs adjusters, disputes, and actuarial depth nobody has for agents.)

Parametric is the shape this estate can actually demonstrate, because **every trigger it would plausibly name is already computable from published documents**: *an action outside the mandate was executed* (an evidence pack with delta `excess` and outcome other than refused); *the mandate expired and the agent kept operating* (pack timestamps against the interval); *a warranty fact went false* (the facts snapshot); *the twin went stale beyond the policy's re-measurement clause* (`age_days`). A parametric agent policy is, mechanically, **a Cedar-shaped rule over evidence packs** — which is why the memo is right that the components "lead this very quickly".

The honest limit, stated with the same breath: a computable *trigger* is not a computable *loss*. Parametric pays on the event and accepts basis risk — the payout may not match the harm. That trade is why parametric exists for earthquakes and flight delays, and it is the right first shape here for the same reason: **the event data is strong and the loss data does not exist.**

## The Agentic Insurance Maturity Model, First Cut

The memo asks for one. Read directly off the estate's existing rating variables — proposed, not settled:

| Band | Identity | Mandate | Measurement | Enforcement | Delta | Insurance meaning |
|---|---|---|---|---|---|---|
| **0 — uninsurable** | None, or fixture-class | None, or unaccepted | None | Expectation (prose) | Unknown | Exposure unquantifiable. Declined — and *declined* is useful governance signal on its own |
| **1 — rated, punitively** | Real, registered | Signed, accepted, in interval | Twin exists, may be stale | Expectation | Computed, large | Insurable the way an unlocked warehouse is: at a price that argues for band 2 |
| **2 — standard** | Real | Signed, accepted, renewed | Twin fresh per policy clause | **Setting** (hook), packs at decision points | Computed, bounded | The premium tracks the delta; warranties (facts) discount it |
| **3 — preferred** | Real, with real root (N11) | Signed, accepted, renewed | Re-measured at decision time | **Boundary** (N12; broker with receipts) | ≈ 0 | Cover B nearly free by construction; Cover A is the residual product |

Note what the table is: **the existing tiers, priced.** Nothing in it required a new measurement — which is the memo's compatibility claim, demonstrated. And note what moves an operator up a band: enrol a real identity (N11), turn on branch protection (N12), re-measure on a date (GM-D16). The open items on this estate's comms page are, read through this lens, **premium reductions waiting to be claimed.**

## What Must Be True Before Any Of This Is Insurance

Carried inside the brief, not appended:

- **Insurance is a regulated activity.** Underwriting requires authorisation, capital, and a compliance apparatus. Nothing this estate or RiskMandate ships is a policy until an authorised carrier stands behind it; the honest near-term postures are *rating engine*, *MGA-style evidence layer*, or *standards body for the schemas* — which one is a business decision that is not the site agent's.
- **There is no actuarial base.** Frequency and severity of agent-caused loss are unrecorded anywhere. First products can be parametric precisely to survive this, but pricing will be judgment wearing a formula until loss events accumulate — and whoever's schema records those loss events owns the eventual table. That is the strategic value of `loss-event/v0`.
- **The register's own evidence is fixtures.** Ten of eleven records prove nothing by design; a rating engine demonstrated on fixtures demonstrates the walk, not the trust (the estate's standing position, unchanged by the pivot).
- **A grant is a floor.** The twin under-reports by construction; an underwriter must load for the unmeasured remainder, and the entries' honesty blocks are the only reason that loading is estimable at all.
- **Moral hazard is real here too.** An insured operator has less reason to narrow the delta — which is exactly why premium must track the delta, so the incentive points back toward least privilege.

## Decisions This Implies (proposed into change control)

| # | Decision | Status |
|---|---|---|
| GM-D35 | The `acceptor` seat in the excess-authority view may be filled by a **policy reference** — the insurer as acceptor of last resort. The chain's terminal node reads *…risks → decisions / acceptances / **policies*** | Proposed |
| GM-D36 | `policy/v0` and `loss-event/v0` join the schema family: the registry defines the shapes, the instance (RiskMandate or a carrier) holds the instances — the library/instance split (GM3), unchanged | Proposed — shapes not yet drafted |
| GM-D37 | The first demonstrable product shape is **parametric**: triggers computed over evidence packs, payout table keyed to capability strings | Proposed |

## Open Questions, The Project Lead's

1. **Who is the insured?** The operator, the deploying business, or the agent vendor? The mandate names an issuer and a subject; a policy needs a policyholder, and the answer decides who buys.
2. **What is RiskMandate in this picture** — the rating engine, the MGA, the broker, or the standards body for the schemas? The compliance burden differs by an order of magnitude between those.
3. **Does the maturity model live on this site** (a public rubric, like the four rules) **or inside the product** (a rating secret)? Publishing it makes it a standard; holding it makes it a moat. The estate's habit argues for publishing; the business case is yours to make.
4. **May the workbench demonstrate the flow end-to-end** — a policy document, a simulated excess-authority event, the parametric trigger firing, the payout computed — clearly marked as a demonstration on fixtures? It needs nothing that does not already exist plus the two schemas, and it would be the "insurance flow" the memo asks to see.

---

*CC BY 4.0. Sources: the project lead's voice memo of 30 August 2026 (verbatim above); this repository at v0.1.49; the v0.33.59–v0.33.62 briefs and the excess-authority view, each read rather than recalled. Everything below the transcript is the site agent's reading and says so.*
