# Not In Line: The Schemas Are The Product, And The Scale Is One To Five

**version** v0.33.76
**date** 31 August 2026
**from** Human (project lead)
**to** Strategy, the RiskMandate team, the registry site

**type** Strategy brief — memo 5 of 8 on the insurance pivot

*Produced from the fifth of eight voice memos, carried verbatim below and then read against the corpus by the site agent. Everything in the transcript is the project lead's; everything under the reading is the site agent's and is labelled as such. **This memo settles a question the estate has been carrying as a blocker:** the level scale is one to five. It is the first decision in this pivot that is settled rather than proposed, and it unblocks the first MVP.*

---

## What This Is

The commercial position, and one settled decision: **the memo places this project outside the line — not the insurer, not the broker, not in the path of the transaction — and inside the connective tissue instead, supplying the schemas, the flows, the mappings and the open-source connectors that let facts and evidence reach an insurable unit wherever it sits; it accepts explicitly that being an insurer is regulated, capital-hungry and infrastructure-heavy and that this project will not do it, which is precisely why the non-financial half matters commercially as well as legally, since an offering not attached to money can execute, add value and run projects today; it settles the level scale at one to five, on the reasoning that a coarse scale is less judgmental than one to a hundred or a currency figure while still supporting the decisions that matter; it names the deliverable as workflows, practices, mappings and graphs of graphs rather than a platform; and it fixes the integration posture as leveraging whatever maturity a company already has rather than replacing it, with everything open source and Creative Commons.** It is the second document of 31 August (cross-ref: v0.33.71–75, the v0.33.61 instrument-before-enforce position, the v0.33.60 service-twin brief, and GM3's library/instance split). New contributions: **the level scale settled, the not-in-line posture stated as a constraint rather than a preference, the schema-and-connector position distinguished from the broker position, and openness identified as load-bearing rather than generous.**

## The Memo, Verbatim

*Transcribed by otter.ai; carried whole, exactly as received. The self-correction in the last third is the memo's most consequential sentence and is discussed in §3.*

> Okay, so now I want to capture the sort of the relationships with risk mandate and the other projects we're doing here, and how everything can kind of fit together in a commercial service that we're providing. So the same way that we were doing with risk mandate, where we don't want to be in line into a lot of these things, right? What I think is very interesting here is the idea that we are an enabler for these things to occur, and we integrate with the multiple service providers, including insurance companies, brokers, you know, etc. And we also basically connect the dots between the facts and the evidence, all the way to the insurable unit, right? Whether that is an insurance company or a provider or something else that actually connects the dots, we we basically are basically in in that loop, right? And and that's that's our bit, right? So everything we do is going to be open source. Everything we do is Creative Commons, and so basically what we're doing is we're trying to basically make the market work, and then be an enabler of that. And you know we have a lot of interesting commercial opportunities here because we can work with companies who are underwriters today, who wants to kind of connect these data, we can work with companies who are insurers, because you know, like we said, like you know, to be an insurer, it's a regulated industry. You need a lot of capital, you need a lot of the infrastructure, and we're not going to do that. Which is also why it's important to have a whole offering that is not dependent on the financial element of insurance, I think that's very important because if we have an element that is not connected to that, then means we can already execute. We can already add value. We can already add projects. We can already integrate these concepts, right? In terms of understanding the risks that somebody's doing, and and this can again we we want in one angle to be allowing the risk-based decisions to occur, which can be done by just mapping insurance, and that's why sometimes even mapping insurance level one to five is good enough, right? Because you you don't have that's less judgmental. Still allows big decisions versus one to 100, or to actually have pound signs, dollar signs connected directly to a particular event, and directly connected to what you insure and what you pay out versus what you don't pay out, and who you do that kind of stuff, right? And that's you know, and in a way, that's just a maturity model. Like we can we can create an insurance. In fact, there was the idea of the insurance maturity model, where it's kind of like you go up levels depending on what you can do with this, right? And and again, who's underwriting, etc. So basically, what we want to do now is to create a set of workflows, a set of practices, a set of mappings and graphs and connections, and basically the whole graphs of graphs is the key element here that will allow us to to already add value and to already have these conversations with the the multiple parties and see where's the best place to tackle the market and where's the best place to actually hit here in terms of the the governance, including the risk acceptance element of this, right? Because ultimately it's about accepting the risk of the you know accepting the risk of the agents that you're buying, and of course that this applies to any technology product, applies to any kind of thing that you can deploy. But I think the what's it called the the thing that is interesting here is the. is the is to start somewhere and then figure out what is the best way to make this work and what is the best way to connect the dots, right? But our our job is to be the broker, right? Not the broker. So our job is to be the one that helps to create the schemas, help to define the flows, help companies to connect the dots, help building open source connectors, and and help companies to integrate. Because again, our logic is to use whatever the company already has, and leverage the maturity of whatever is in place. So it's almost like you know, and this is the beauty again of the Gen AI development world. Like you know, we don't have to reinvent and create bits of the puzzle that a company already has. We can integrate with whatever they have, and then create the JSON schemas and the graphs and the connections that we already mapped out in our other projects, so that's kind of the flow.

## The Reading — the site agent's, from here down

### 1 · The scale is settled: one to five

> mapping insurance **level one to five** is good enough ... because that's **less judgmental**. Still allows big decisions versus one to 100, or to actually have pound signs, dollar signs

**This closes the open question the estate has been carrying since memo 1** ([N17, question 1](../admin/comms.html)), and the reasoning is better than the answer alone.

A five-band scale is **honest about its own resolution.** One to a hundred implies a precision the inputs cannot support — the difference between 61 and 63 would be noise wearing a number, and somebody would argue about it. Currency implies loss data nobody has. **Five bands say only what the evidence can carry**, and coarseness here is a feature rather than a compromise:

| Scale | Implies | Supportable today |
|---|---|---|
| Currency | A loss distribution | **No** — no agent loss data exists anywhere |
| 1–100 | Meaningful distinctions at one-point resolution | **No** — the inputs are counts, tiers and three-valued facts |
| **1–5** | An ordering with defensible boundaries | **Yes** |

*"Less judgmental"* names the social property too, and it is the practical one: a coarse band is arguable in a way a decimal is not. A team told they are at level 3 argues about the band's definition, which is the useful argument. A team told they are at 62.4 argues about the arithmetic, which is not.

**Recorded as GM-D54, settled** — the first decision in this pivot that is not merely proposed.

### 2 · Not in line, and what that forecloses

> the same way that we were doing with risk mandate, where **we don't want to be in line** into a lot of these things

This is a constraint, not a preference, and it has a consequence worth stating plainly because it limits what this project may ever claim.

**A party outside the line cannot enforce.** The estate's own three-tier test: a control bounds a grant only when it is enforced by something the grant does not include. A schema, a connector and a published derivation are none of those. So:

> **This project can never itself be a boundary.** It can ship a check that *becomes* one when installed by somebody who is in line.

That is the precise version and it is not a defeat — it is the corpus's own long-standing position (*instrument before you enforce*, and describing instrumentation as a control is dishonest) applied to the business model. The distinction that matters:

| | Who does it | Tier it can reach |
|---|---|---|
| Compute the rating, publish the derivation | **This project** | Instrumentation — **expectation** |
| Install the gate in a pipeline the deploying team controls | The customer | **Setting** |
| Install it where the deploying team cannot reach | The customer, or a broker | **Boundary** |

**Every tier above the first is somebody else's action**, and the honest sales sentence follows from it: *we can tell you what you are carrying; whether anything stops it is your install.*

### 3 · "Our job is to be the broker. Not the broker."

The memo's self-correction is its most consequential sentence, and it separates two things the corpus has been using one word for.

| | | Us? |
|---|---|---|
| **The execution broker** | Holds the credential, performs the action, returns a receipt. *In line.* Named in [memo 3](v0.33.74__strategy-brief__who-pays-for-the-delta-nobody-chose-and-the-rating-that-moves-overnight.md) as a product with a measurable value | **No** — §2 forecloses it |
| **The insurance broker** | Places risk with carriers, holds a client relationship. *In the money path* | **No** — regulated |
| **The connective tissue** | Schemas, flows, mappings, connectors, evidence. *Beside the line* | **Yes** — this is the correction's landing point |

**And the third position is the one that makes the first two possible.** [Memo 3](v0.33.74__strategy-brief__who-pays-for-the-delta-nobody-chose-and-the-rating-that-moves-overnight.md) established that an execution broker's value is exactly the structural delta it converts to elective. **Somebody has to define how a broker states what it converts**, or every broker's claim is unfalsifiable marketing. That definition is a schema, and shipping it is this project's position exactly.

> **We do not operate the broker. We define what a broker must be able to show.**

Which is a stronger position than it sounds: the party that defines the disclosure format for a market gets to decide what "good" is measurable as, without carrying any of the market's capital or liability.

### 4 · Openness is load-bearing, not generous

> everything we do is going to be open source. Everything we do is Creative Commons ... we're trying to **make the market work**

Three separate reasons this is structural rather than a licensing preference, and the third is new:

**It is the substitute for capital.** [Memo 4](v0.33.75__strategy-brief__why-insurance-and-the-cautionary-tale-is-cyber-insurance-itself.md) observes that insurance's real virtue is that it *creates a party with money at stake in the data being true.* Stage 1 has no such party, so the demand for trustworthy data has to come from the method being attackable — which requires it to be public. **A closed rating engine in a stage with no money has no honesty mechanism at all.**

**It is the monoculture mitigation.** Memo 4 also warns that concentrating cover in one carrier is a risk. A single rating standard is the same risk one altitude up. **A standard anyone can fork, audit and dispute is a monoculture that can be broken on purpose.**

**And it is the only way the connective-tissue position pays.** A schema's value is proportional to adoption; a proprietary interchange format that nobody else implements is not connective tissue, it is a product with an integration problem.

### 5 · Integrate with what exists — and the honest cost of that

> our logic is to **use whatever the company already has**, and leverage the maturity of whatever is in place ... we don't have to reinvent and create bits of the puzzle that a company already has

Right, and it follows from the position: connective tissue that demanded a rebuild would not be connective tissue.

**The cost, stated once:** a rating computed from whatever a company already has inherits **whatever that data's quality is**, and it will vary enormously between organisations. Which returns to [document 01's](../insurance/the-rating.html) two channels: an integration that pulls from an existing CMDB or asset inventory is producing **declared** facts unless something measures them, and the rating must mark them so. **The connector's job includes labelling the evidence class of what it imports** — otherwise "integrate with what exists" quietly becomes "launder what exists".

That is a real design requirement for every connector this project ships, and it is cheap to state now and expensive to retrofit.

### 6 · Where the pivot lands relative to risk acceptance

> including the risk acceptance element of this ... **it's about accepting the risk of the agents that you're buying**

Worth noting because it closes a loop opened by [the pivot briefing](v0.33.71__strategy-brief__insurance-for-agents-the-delta-is-where-the-insurance-lives.md). That brief moved the foundation *from* risk acceptance *to* the policy, and this memo puts acceptance back in the frame — not as a reversal, but as the thing a level makes possible. **A rating does not replace acceptance; it makes acceptance specific.** "We accept the risk of this agent" is a sentence nobody can check. "We accept a level 4 placement, for this quarter, on this service" is a sentence with a date, a subject and a threshold — which is what the register was built to hold.

## Decisions This Implies

| # | Decision | Status |
|---|---|---|
| GM-D54 | **The level scale is 1–5.** Coarse on purpose: currency implies loss data nobody has, 1–100 implies resolution the inputs cannot support, and a band is arguable where a decimal is not | **Settled — the project lead, 31 Aug. Closes N17 q1** |
| GM-D55 | **This project is not in line.** It supplies schemas, flows, connectors and evidence, and never operates the carrier or the execution broker. Consequence: **it can never itself be a boundary** — it ships checks that become one when installed by somebody who is | Proposed |
| GM-D56 | **We define what a broker must be able to show; we do not operate one.** The disclosure format for structural-to-elective conversion is a schema, and shipping it is the position | Proposed |
| GM-D57 | **A connector labels the evidence class of everything it imports.** Integrating with existing systems must not launder declared facts into measured ones | Proposed — the cost of §5, stated before it is paid |

## Open Questions, The Project Lead's

1. **What are the five bands actually called, and what defines a boundary between them?** The scale is settled; the band definitions are not, and they are where the argument will happen — which per §1 is the useful argument.
2. **Which connector first?** §5's requirement is cheap to honour on the first one and expensive to retrofit onto the fifth.
3. **Do we publish the band definitions here** (a standard, like the four rules) **or hold them?** Memo 4's monoculture argument and §4's honesty argument both say publish; the moat argument says otherwise, and it is the same tension as N19 q2.
4. **The first MVP is now unblocked.** With the scale settled and the counterfactual already scale-free, a placement rated 1–5 with its derivation, and a *which control buys the most* view, needs nothing that is not already published. Shall it be built?

---

*CC BY 4.0. Sources: the project lead's voice memo of 31 August 2026, fifth of eight (verbatim above); v0.33.71–75; the Grant & Mandate pack's three-tier control test and GM3. Everything below the transcript is the site agent's reading and says so.*
