# Insurance Without Money First: The Rating Is The Product, And Micro-Policies Scale Where Entity Cover Never Did

**version** v0.33.72
**date** 30 August 2026
**from** Human (project lead)
**to** Strategy, the RiskMandate team, the registry site

**type** Strategy brief — memo 1 of 8 on the insurance pivot

*Produced from the first of eight voice memos recorded on 30 August 2026 about the insurance pivot, carried verbatim below and then read against the corpus by the site agent. Everything in the transcript is the project lead's; everything under the reading is the site agent's and is labelled as such. This memo materially changes the position taken in [v0.33.71](v0.33.71__strategy-brief__insurance-for-agents-the-delta-is-where-the-insurance-lives.md) — it removes the blocker that brief named as fatal to shipping, and creates a tension with that brief's central argument, which is named rather than smoothed over below.*

---

## What This Is

The first of eight memos on the pivot, and the one that makes it buildable: **the memo separates insurance from money and keeps the half that matters, arguing that an insurance policy is first a decision-making mechanism and a way to assign a rating to an environment, and only later a financial instrument — so the estate should build the rating and defer the payout, expressing cover in points, tokens or levels ("insurance level three, insurance level five") inside an internal marketplace before any currency is attached; that this dissolves the blocker [v0.33.71](v0.33.71__strategy-brief__insurance-for-agents-the-delta-is-where-the-insurance-lives.md) named as fatal, because a rating engine emitting levels rather than money is not a regulated activity and needs no carrier, no capital and no authorisation, which moves the whole apparatus from years away to shippable now; that insurance has never scaled below the entity — cyber cover is bought for a company, not a project, not an individual, with the telling exception of a footballer's insured leg, while most firms should hold key-person cover and do not — and that agents are the first population where the micro can actually be reached, because they can be enumerated, measured and connected, micro to macro, as graphs of graphs; that the rating basis is a questionnaire in the wellness-insurance tradition, asking of an environment what an underwriter asks of a smoker — do you have incident response, a security programme, a way to contain the agent — and of the agent's placement what nobody currently asks, since Claude on a desktop under a user identity, Claude on the web with a clean account, Claude on the web with months of accumulated data, and Claude with or without network egress are four materially different risks that no product prices differently today; and that the purpose of the exercise is to let a company know the risks it is buying and to focus its effort, which is an operating goal rather than a financial one.** It is the second document of 30 August (cross-ref: v0.33.71 the pivot briefing, the v0.33.61 grant-is-not-mandate brief, the v0.33.59 two-populations brief, and graphs.sgit.ai's fractal thesis). New contributions: **money decoupled from rating and the regulatory blocker dissolved with it, the micro-policy as the scale insurance never reached, the placement variables named concretely enough to test, the questionnaire identified as the rating instrument, and the quasi-currency as the adoption path.**

## The Memo, Verbatim

*Transcribed by otter.ai; carried whole, exactly as received. Two probable transcription artefacts are noted after it, not repaired here.*

> Okay, so now I want to record a number of memos around specific topics around cyber insurance, which also connect to a lot of the work we've been doing, especially around graphs of graphs and PKI identities, and it's about the same thing that we kind of did with the other projects, where we want to create a body of work that we can then connect with. That we can connect with the overall idea of creating insurance policies for agents that They are operating, and so I think this is actually something that I want I want to have for a while back, and I wish it was more mature when I was a CISO, which is the idea of micro insurances or mini, mini micro small insurance policies, right? And that's kind of what I want to start, because an insurance policy, right? Insurance, if you think about it, it's a really good way to quantify risk, that is based on you know centuries actually of a very mature industry that has dealt with uncertainty and a measurement and data, because you know, the insurance is one of the most data-driven industries that exists. Traditional insurance, and is an insurance that fundamentally it's a model that actually helps to deal with uncertainty. Right? It tells helps helps to deal with what happens when you can't quantify everything, when you have moments of uncertainty, right? And like with risk and risk acceptance, right? I don't feel that risks, that insurance is something that is static. I view it as actually something that should be dynamic and it should change based on events, and it should change based on specific things. Because if you think about the properties of insurance, fundamentally, it's like risk, right? It's it's basically it's a way to de-risk something so that you can keep operating. Because what you're doing is you are basically spreading the risk of or the consequence of something happens throughout multiple situations. It's kind of like you know if you if you take if you have an insurance of you know of of X, you basically, and you have n x happening. You are basically saying, well, if one of them hits, then I'm going to have this problem, and you're kind of de-risking it, right? So, so ultimately, insurance is an enabler for business to continue to operate. It's an enabler to allow you to fundamentally sometimes take quite substantial risks in a way that is is acceptable for the business to operate, and more importantly, it's something that it's very wired in to how business operate. Business understand insurance. Business buy insurance all the time, and it's a very mature market in that level, right? Although it's a market that really needs to innovate, and it's a market that is really going to go into a massive transformation in the next decade. And so, but I think it's very important to view that ultimately insurance is a tool, and when we talk about insurance per agent, we're basically talking about capturing what is the current perceived risk and the consequences of what can go wrong with that agent, and more importantly, what can you sort of get in return when what you predict goes wrong, right? But and this I think goes to the heart of one of the problems I've always saw with insurance is that is it never really took into context the individual components. So when you talk about cyber insurance or other insurance, you tend to deal with, you know, the company, the entity. Like you never really, in most cases, you you wouldn't go down to the project level. You wouldn't go down to individual level. You wouldn't go down to, you know, stuff unless you was, you know, like for example, like when you have celebrities or you have somebody who they will insure, you know, you know, the right hand of an individual or a footballer or a golfer or a sportsman, and you would basically, you know, do that. But you know, for example, most companies should have actually insurance for key individuals, and a lot of them don't, right? Which also why they track it. Sometimes they lose those individuals. So, so I think that insurance in the past never really scaled, and I think now we are in a position where we, where we can scale it, and where we can actually deal with in the micro, which then goes to the macro, who then goes to the overall right, and I think that's what's interesting. Is again, if you look at what we're doing, is the graphs of graphs of graphs, right? So I think it's important. The other thing that I feel is super critical here is to decouple insurance with money, right? Because ultimately, and and even with payout, I think it's important to exclude that initially. It's part of it, and here's what I mean, right? I mean, is that insurance only? It's a decision-making mechanism. It's a way to assign what's it called risk, and it's a way to assign, you know, a rating to a particular environment. So, for example, the insurance for Claude running on a desktop under a user identity should be higher than the insurance of Claude running on the web, and the insurance of Claude running on the web on a clean account, with no other assets, versus one that is running with with years of months of data and then being able to access that data, the Claude agent is massive. And again, same thing like you know with Claude able to connect to the internet versus not able to connect to the internet, so all those are metrics that we should have, and the insurance should be different. And in a way, the insurance then also will promote the idea of the card. Like you know, it's kind of like when you fill a questionnaire to get insurance. You know, like do you smoke? Do you do this? Like wellness insurance, same thing. Like you know, how what is your your habits of what you do that will impact your in your your insurance? Well, the same thing here. You know, like do you have an instance response team? Do you have a cyber security programme? Do you have a way to contain the agent? Do you have you know this or do you have examples of problems breaking into place? Right, and that's super critical, right? Because that's how the insurance premiums should be calculated, but but I think this one of the key points I have here is that when you actually have insurance driven by money, which has financial monetary value, that's not the beginning of the process. That is like it's almost like a maturity model that we should also have that captures the the different practices, but the the process that we should have here should be one that allows the creation of internal marketplaces, the creation of internal insurance distribution premiums that are independent from the financial payout, and this is important because, and I probably I'll do a voice memo just on this, is because the maturity model, the maturity the organisation needs to have initially, even in terms of quantification, is not very high, and sorry, usually is not very high, which is why a lot of risks, you know, sometimes don't have effective quantification numbers, or when they do, it's it's not as scientific as it could be, and but the insurance company will be driving this, right? But one of the key points here is that you should be able to have an insurance model used in an organisation. For example, in this case, for agents, to give agents the insurance that they need, even based on on a quasi currency, it could be points, you can be tokens, it could be levels. You can have you have an insurance level three, insurance level five, insurance level one, because the point here is also to allow companies to know the risks that they're buying and to allow them to focus their efforts, and I think this is sort of a key part of the exercise here is to be able to do things like this, which I will now capture this, and I will start to record specific memos on specific of these topics to to capture it.

Two probable transcription artefacts, noted rather than repaired: *"instance response team"* is **incident response team**, and *"do you have examples of problems breaking into place"* is most likely **do you have exercises for problems, or breakglass in place** — the second is a guess and the argument does not rest on it.

## The Reading — the site agent's, from here down

### 1 · The memo removes the blocker the pivot briefing called fatal

[v0.33.71](v0.33.71__strategy-brief__insurance-for-agents-the-delta-is-where-the-insurance-lives.md) carried this, inside the brief rather than as an appendix:

> **Insurance is a regulated activity.** Underwriting requires authorisation, capital, and a compliance apparatus. Nothing this estate or RiskMandate ships is a policy until an authorised carrier stands behind it.

That constraint made the pivot a multi-year proposition. **The memo dissolves it in one move.** *"Insurance only? It's a decision-making mechanism. It's a way to assign... a rating to a particular environment."* Strip the money and what remains is a rating engine — and a rating engine that emits **levels** rather than currency transfers risk to nobody, promises nobody a payout, and is therefore not insurance in the regulated sense at all. It is closer to a credit score, a safety rating, or a security maturity assessment: unregulated, sellable, and buildable this week.

| | With money (v0.33.71's reading) | Without money (this memo) |
|---|---|---|
| Regulated activity | **Yes** — authorisation, capital, conduct rules | **No** — it is an assessment, not a promise to pay |
| Needs a carrier | Yes | No |
| Needs loss history to price | Yes, and none exists | **No** — a relative ordering needs no absolute scale |
| Buildable by this estate today | No | **Yes** |
| What it produces | A premium | **A level**, and the reasons for it |

The last row is the important one. **A relative ordering is easier than an absolute price and is most of the value.** An operator does not primarily need to know that an agent's exposure is worth £40,000; they need to know that *this* placement is three levels worse than *that* one and which change moves it. That is the memo's *"allow companies to know the risks that they're buying and to allow them to focus their efforts"* — an operating goal, reachable without an actuary.

### 2 · And it contradicts the pivot briefing's central argument — which must be resolved, not smoothed

v0.33.71's case for moving the foundation from acceptance to policy rested on exactly the thing this memo removes:

> An acceptance can, in the worst case, be theatre — a signature over an exposure nobody measured. **A premium cannot be theatre; someone loses money if the measurement is wrong.**

**Take the money out and that discipline goes with it.** A "level 3" issued by the same organisation that operates the agent is precisely as capable of being theatre as an acceptance — arguably more so, because a level *sounds* quantitative. This is a genuine conflict between memo 0 and memo 1, and it is the first thing the doctrine has to answer.

**The proposed resolution, and it is the site agent's:** the discipline must come from somewhere else in stage 1, and this estate already has its substitute for money — **a computation somebody else can re-run.**

> **A level nobody can recompute is exactly the theatre a premium would have prevented.**

So the load-bearing rule for the rating engine: **the level is computed from published evidence, and the computation is published with it.** Not a score handed down, but a derivation an operator, an auditor, or a future underwriter can walk and disagree with — the same reason the register publishes its expected answers as data and reproduces them on every release. Money is one way to make a claim honest; a reproducible derivation is another, and it is the one available now.

### 3 · Micro-policies: the scale insurance never reached, and why agents are different

The memo's diagnosis is accurate and worth stating plainly: **cyber insurance is sold at the entity.** A company buys a policy; a project does not, a service does not, an employee does not. The exceptions prove the shape — a footballer's leg, a pianist's hands: insurable at the micro only where the asset is *singular, identified, and valuable enough to justify bespoke underwriting.* The memo's aside that most firms should hold key-person cover and do not is the same point from the other side: the micro is reachable in principle and too expensive to reach in practice.

**Agents change the economics, and the reason is specific.** Bespoke underwriting was expensive because assessing each unit required a human. An agent's unit of assessment is *already machine-readable*: it has an identity in a register, a grant discovered by measurement, a mandate signed with an interval, and an evidence pack at every decision. **The assessment cost per unit collapses**, and that is the whole reason the micro becomes reachable — not that agents are more insurable in principle, but that the marginal cost of rating one more of them approaches zero.

And the memo's *"graphs of graphs of graphs"* names the composition honestly: micro ratings roll up to a service, a team, an estate. Which raises the first hard problem —

### 4 · The aggregation problem, which the memo does not name and the doctrine must

**Micro risks do not add.** If five hundred agents in an estate are rated individually and the estate's rating is the sum or the average, the number will be **wrong in the dangerous direction**, because the risks are correlated: agents sharing a credential pattern, a base image, a model provider, or a single misconfigured branch protection fail *together*. This is the oldest problem in the industry — it is why reinsurance exists and why a flood book is not priced like a fire book.

For this estate it is a **graph problem, which is convenient**: correlation is shared structure, and shared structure is a shared node. Two agents whose grant trees converge on the same credential node are not independent, and the graph already says so. **The aggregation rule should be that correlation is read off shared nodes rather than assumed away** — which is a real contribution the graphs-of-graphs framing makes available and which no spreadsheet rollup would find.

### 5 · The questionnaire, and the split the estate's own rule forces

The memo reaches for the wellness-insurance questionnaire — *do you smoke* → *do you have an incident response team, a security programme, a way to contain the agent* — and calls it *"how the insurance premiums should be calculated."* The instinct is right and it collides with a rule this estate already holds:

> `library − self-report = blind spots`

**Every question in that questionnaire is self-reported.** "Do you have a way to contain the agent" answered *yes* by the operator is a **declaration**; the pre-push hook found by `measure.py` is a **measurement**. This estate refuses to treat those as the same evidence, and a rating that averaged them would be laundering an assertion into a number.

**So the rating instrument has two channels, and they never merge:**

| Channel | Source | Weight | Failure mode it carries |
|---|---|---|---|
| **Measured** | The twin — `measure.py`, the register, computed tiers | Full | Under-reports: a grant is a floor, not a census |
| **Declared** | The questionnaire, the agent card | **Discounted, and marked as declared** | Over-reports: nobody answers *no* to "do you have incident response" |
| **Unknown** | Neither | **Kept as unknown** — never scored as absent | Assuming absence is the comfortable error |

This is not a new mechanism: it is the estate's five evidence classes (`observed`, `read`, `documented`, `inferred`, `none`) applied to rating inputs. **The questionnaire is a declared-class fact collector**, and saying so keeps it honest. It also gives the memo's *"promote the idea of the card"* a precise meaning: the agent card is where declared facts live, and its declarations become checkable exactly where a measurement exists to check them against — the gap between the card and the twin being, itself, a rating input.

### 6 · The placement variables, named concretely enough to test

The memo's four comparisons are the most immediately useful thing in it, because they are **directional claims about real environments** rather than abstractions:

| Comparison | The memo's ordering | Why, in this estate's vocabulary |
|---|---|---|
| Claude on a **desktop under a user identity** vs **on the web** | Desktop is **higher** risk | The desktop grant is the *user's whole grant* — the union of everything that identity reaches. This is the bootstrap trap as a rating variable |
| Web with a **clean account** vs one with **months of accumulated data** | Accumulated is **"massive"**-ly higher | The grant's blast radius scales with reachable assets; time in an account is asset accretion nobody re-measures |
| **Network egress** vs none | Egress is **higher** | Egress converts a containment boundary into a setting; it is also the exfiltration path that makes every other exposure realisable |

Two honest notes. **These are the project lead's orderings, not measurements** — they are plausible, they match the corpus's own arguments, and none has been tested. And **the estate cannot score them today**: its two library entries are a CCR container and a GitHub Actions runner, neither of which is a desktop or a browser session. **Rating Claude-on-a-desktop requires measuring one, and nobody has.** That is a concrete, cheap next experiment rather than a blocker.

### 7 · The quasi-currency is an adoption strategy, and it is a good one

*"It could be points, it could be tokens, it could be levels... insurance level three, insurance level five."* Read as strategy rather than as economics, this is the strongest practical idea in the memo: **an internal marketplace with a made-up currency lets an organisation run the whole apparatus before it can price anything**, and the memo names the reason precisely — the quantification maturity most organisations have *"is usually not very high, which is why a lot of risks... don't have effective quantification numbers."*

A level-based internal market gets you: a budget an owner must live within, a visible cost to deploying a badly-placed agent, competition for a scarce allocation, and a **loss history accumulating in the right shape** — which is exactly what a future money-priced product needs and cannot buy. Stage 1 generates stage 2's actuarial table as a side effect.

The risk, stated: **a currency with no cost invites gaming more than money does**, because claiming a level is free. Which returns to §2's rule — computed, not declared — as the only thing standing between an internal market and a fiction.

## What This Changes

| Position in v0.33.71 | Status after memo 1 |
|---|---|
| "Nothing here is a policy until a carrier stands behind it" | **Stands, and is no longer a blocker** — the shippable object is a rating, which is not a policy |
| Parametric triggers as the first demonstrable shape (GM-D37) | **Refined**: parametric described a *payout* mechanism; stage 1 has no payout. The triggers survive as **rating events** — the same computations, feeding a level rather than a claim |
| "A premium cannot be theatre" as the argument for the pivot | **Contradicted** — see §2. Replaced by: *a level nobody can recompute is theatre* |
| The four-band maturity model | **Extended** — it was read off enforcement tiers alone; memo 1 adds placement variables and the declared-practice questionnaire as further inputs |
| The loss event as the missing primitive | **Deferred, not solved** — stage 1 needs no payout, so `loss-event/v0` is no longer on the critical path, though the internal market is precisely how its data starts accumulating |

## Decisions This Implies (proposed into change control)

| # | Decision | Status |
|---|---|---|
| GM-D38 | **Stage 1 of the insurance work carries no money.** The deliverable is a rating (levels/points), not a premium — which is not a regulated activity and needs no carrier | Proposed |
| GM-D39 | **A rating must be computed from published evidence and ship its derivation.** A level that cannot be re-run by somebody else is refused, because it is the theatre a premium would have prevented | Proposed — the load-bearing rule |
| GM-D40 | **Rating inputs carry their evidence channel**: measured facts and declared (questionnaire/card) facts are weighted differently and never merged; unknown is never scored as absent | Proposed |
| GM-D41 | **Aggregation reads correlation off shared graph nodes** rather than summing independent micro ratings | Proposed — the aggregation problem, named |

## Open Questions, The Project Lead's

1. **What is the level scale?** Bands 1–5, a continuous score, or letter grades? The memo says *"level three, level five"* without fixing a range, and the choice constrains every surface built on it.
2. **Does the level rate the agent, the placement, or the pair?** The memo's own examples rate *Claude in an environment* — the same model is a different risk on a desktop and in a browser — which suggests the ratable unit is the **placement**, not the agent. Worth settling before anything is built, since it decides what the object is.
3. **Who runs the internal marketplace** — the platform team, security, or the business unit deploying? That decides whether a level is a control or a chargeback.
4. **Do we measure a desktop agent** (§6)? It is the cheapest experiment available, it tests the memo's own strongest ordering, and the estate currently cannot score the example the memo leads with.

---

*CC BY 4.0. Sources: the project lead's voice memo of 30 August 2026, first of eight (verbatim above); [v0.33.71](v0.33.71__strategy-brief__insurance-for-agents-the-delta-is-where-the-insurance-lives.md); this repository at v0.1.50. Everything below the transcript is the site agent's reading and says so, including the contradiction identified in §2 and the resolution proposed for it.*
