# 5 · A placement, not an agent

*Part two — The rating*

---

What, exactly, gets rated? Memo 1's own examples answer before the question is asked, and the answer disposes of the framing every public conversation about agent risk uses:

> the insurance for Claude running on a desktop under a user identity should be higher than the insurance of Claude running on the web

*Stated* — the memo, verbatim. The same model is a different risk in a different place. Rating "Claude" is meaningless; rating *Claude, on this desktop, under this identity, with this credential reach* is a thing an operator can act on. The doctrine turns the examples into the definition:

> A rating attaches to a placement — an agent in an environment under an identity — not to an agent and not to a vendor.

*Stated* — doctrine 01. And the definition lands on ground the estate has already prepared, which is the pattern of this whole pivot: a **library entry is a placement**. The measured twin of the CCR container rates that container — not Claude, not Anthropic, not "AI". The unit insurance needs and the unit the estate measures were the same object before anyone connected them.

## What "micro" is micro about

The memo's recurring word for the product is *micro insurances*, and the definition fixes what the word modifies. Not smaller companies — **smaller units of assessment**: one placement, not one enterprise. That is the scale insurance has historically refused. Cyber cover is bought at the entity; a company buys a policy, a project does not, a service does not, an employee does not. The memo's exceptions prove the rule by their price tags:

> like when you have celebrities or you have somebody who they will insure, you know, you know, the right hand of an individual or a footballer or a golfer or a sportsman

*Stated.* A footballer's leg gets a policy because the asset is singular, identified, and valuable enough to justify a human underwriter working on one unit. The barrier to the micro was never principle. It was **cost per unit** — bespoke underwriting is expensive because assessing each unit required a person.

*Drawn.* Here is the argument of this chapter, assembled from the doctrine's table: for an agent placement, every input a human underwriter would spend days collecting already exists as a machine-readable document. Who is the insured — an identity in a register, its fixture-or-real class read before any signature. What can they reach — a grant, discovered by measurement rather than declared. What are they supposed to do — a signed mandate with an interval. What controls are in place — enforcement tiers computed against the tree rather than claimed. Is the survey current — the twin's age, printed. **The marginal cost of rating one more placement approaches zero**, and that — not any change in what is insurable — is what makes the micro reachable now when it never was. The memo's *"insurance in the past never really scaled, and I think now we are in a position where we can"* is right, for exactly this reason.

## The placement variables, and the judgement flag

Memo 1 names four orderings, and the doctrine is careful to file them as what they are — the project lead's judgements, none measured. They are worth walking because each translates into the estate's existing vocabulary rather than needing new machinery.

**Identity.** Desktop under a *user identity* rates far above a scoped service identity — because the grant becomes the union of everything that user reaches. This is the estate's bootstrap trap arriving as a rating variable: the workaround for agent identity is to hand over a person's, which confers a strictly larger grant than the one being established.

**Asset accretion.** An account with months of accumulated data rates above a clean one — the memo's own contrast — because blast radius scales with reachable assets, and *time in an account is accretion nobody re-measures*. The grant was fixed at assignment; the assets were not.

**Egress.** Network egress present rates above none, because egress is what turns every other exposure from theoretical to realisable, and this estate has watched the difference: its own two twins are a container behind a mandatory proxy and a CI runner whose entry reads NO WALL.

**Surface.** Desktop above hosted web session — and the doctrine notes this follows from the first three rather than standing alone, which matters because it means *desktop is riskier* is a conclusion, not an axiom, and a desktop placement that fixed its identity, accretion and egress could out-rate a sloppy hosted one.

## The measurement the corpus cannot make

*Drawn.* And then the honest sentence that this book considers part two's most important, because it prices everything above: **the estate cannot score its own leading example.** Its two library entries are a CCR container and a GitHub Actions runner. Neither is a desktop; neither is a browser session. The ordering the memo leads with — desktop above web — concerns two placements the estate has never measured. Doctrine 01 draws the conclusion this book endorses: measuring one desktop agent is the cheapest experiment available, and it tests the memo's strongest claim. Until somebody runs `measure.py` on a desktop, the placement variables are a hypothesis with excellent pedigree — and a rating built on them would be a judgement wearing a derivation, which is precisely the object this corpus was built to refuse.

## Aggregation, and the trap with a graph-shaped exit

The memo wants the micro to roll up — *"deal in the micro, which then goes to the macro... graphs of graphs of graphs"* — and the doctrine names the trap in the ambition:

> Micro risks do not add.

*Stated* — doctrine 01. Five hundred placements rated individually and summed will produce an estate rating wrong in the dangerous direction, because the risks are correlated: placements sharing a credential pattern, a base image, a model provider or one misconfigured branch protection fail *together*. This is the oldest problem in insurance — it is why reinsurance exists, and why a flood book is not priced like a fire book.

For this estate it is a graph problem, and that is the good news. Correlation is shared structure, and shared structure is a shared node: two placements whose grant trees converge on the same credential node are not independent, *and the graph already says so*. The doctrine's rule — aggregation reads correlation off shared nodes rather than assuming it away — is a real contribution the graphs-of-graphs framing makes available, and it is stated, not implemented. Nothing in this corpus computes which placements fail together. The rule is where the work would start; chapter 17 keeps it on the list of what nothing proves.
