Insurance for agents
A pivot: the foundation of the risk approach moves from risk acceptance to the insurance policy, because the delta between what an agent can do and what it is authorised to do is where the insurance lives. Eight memos are being recorded on it. This is where they are read into something buildable.
A rating engine that emits levels rather than currency is not a regulated activity, needs no carrier and no loss history, and is therefore buildable today. Money is stage 2. See GM-D38.
A level nobody can recompute is exactly the theatre a premium would have prevented. Every rating ships its derivation. See GM-D39.
Settled: The level scale is 1–5 (GM-D54, the project lead, 31 Aug). Coarse on purpose: currency implies loss data nobody has, 1–100 implies resolution the inputs cannot support, and a band is arguable where a decimal is not.
Two stages, and only one of them is insurance
| Stage 1 — the rating | Stage 2 — the policy | |
|---|---|---|
| Produces | A level, and its derivation | A premium, and a promise to pay |
| Risk transferred | None | To a carrier |
| Regulated activity | No | Yes — authorisation, capital, conduct rules |
| Needs loss history | No — a relative ordering needs no absolute scale | Yes, and none exists for agents anywhere |
| Buildable here | Today | Not by this estate, and not soon |
Everything in this folder is stage 1. Calling it insurance would be the first dishonesty: it transfers no risk and promises no payout. What it does is tell an operator that this placement is several levels worse than that one, and which single change moves it.
The memos
Each is filed verbatim as a brief before it is read, because a transcript outranks any summary of it. The count below is computed from the manifest, never typed.
The policy replaces the acceptance at the foundation; the insurer as the acceptor of last resort filling the register's acceptor:null; the two-insurances split; parametric as the payout shape; the loss event named as the missing primitive.
the brief, rendered → rawMoney decoupled from rating, which dissolves the regulatory blocker; micro-policies as the scale insurance never reached; the placement variables; the questionnaire as a declared-fact collector; the quasi-currency as the adoption path. Also contradicts memo 0 on why the pivot is honest, and the contradiction is answered rather than smoothed.
the brief, rendered → rawThe industry's roles taken without its money, because the roles are what separate the rater from the party that wants to ship; the rating as a gate on go-live rather than a report, which requires a threshold and a decomposition; reinsurance named as the fractal's precedent; and the control-to-premium loop, which the workbench already computes.
the brief, rendered → rawThe accountability question, answered as a taxonomy: the delta divides by who could have closed it — elective (the operator's), structural (the platform's finest grain), defect (a vulnerability, temporary). Platform granularity named as a library artefact and the one public good here. The rating made a function of the world as well as the twin, with independent freshness. And the estate's own measurement found holed: nothing measures commit authorship.
the brief, rendered → rawThe justification, carrying its own counter-example: cyber insurance grew on quantification nobody could check and hurt both sides at once — which is the empirical case for this folder's rule. Insurance's real virtue is that it DEMANDS trustworthy data rather than merely using it. And the enforcement tier is identified as an impact-reduction measure: the quantity security has never been able to articulate.
the brief, rendered → rawThe commercial position and the first SETTLED decision. The level scale is 1–5. The project sits outside the line — schemas, flows, connectors, evidence — never the carrier and never the execution broker, which forecloses it ever being a boundary itself. And openness is load-bearing rather than generous: with no money at stake, an attackable public method is the only honesty mechanism left.
the brief, rendered → rawThe broker market's commercial case is the level reduction it produces — and the broker's own policy is what stops that being apparent authority in the vendor channel. Corrects an earlier framing: a broker changes the grant's TOPOLOGY rather than narrowing it, adding a party with reach of its own, so the net may be positive and deployment topology is a rating variable. Names the case the delta taxonomy could not hold — granularity that exists but is impractical — and fixes it with a cost-to-close dimension rather than a fourth class.
the brief, rendered → rawHow it works with the primitives the estate already has. policy/v0 turns out to be a mandate-shaped statement issued by a rater — one more type, no new register machinery. A policy does not sign; its subject signs and the policy establishes what that is worth. And the handshake relocates enforcement to the RELYING PARTY, who is outside the requesting agent's grant — the first mechanism in this pivot that can reach tier boundary, resolving the limit memo 5 recorded.
the brief, rendered → rawThe last memo, and it SPECIFIES the MVP rather than requesting one — correcting the shape the site agent had proposed for four releases. The first MVP is an explainer, not a calculator: an instrument answers a question somebody already knows how to ask, an explainer creates the person who can ask it. Cost needs assets, and stage 1 needs asset class rather than asset value. Insurer, underwriter and claim join the actor set. And the load-bearing requirement: a world must show its own emptiness, because a polished simulation is the most effective mechanism yet devised for making a demonstration look like a product.
the brief, rendered → rawThe positioning, and the first item in this series that would produce an EXTERNAL fact rather than a position — the pivot has seventy-one decisions and no evidence. Also the mapping that upgrades a rule: the declared-versus-measured gap is the shape of material non-disclosure, so the card-versus-twin gap decides voidability rather than merely worsening a level. And the survey specified as measure.py pointed at a market: dated, re-runnable, evidence-classed, where unknown is never absent.
the brief, rendered → rawTwo memos in one — the interfaces, then time. A warranty is defined precisely as a fact plus a maximum age, failing three ways (false, stale, unknown) with unknown on the same side as false — the opposite of the rating rule, and deliberately so. Cover is continuous, which adds a third clock beside the policy interval and twin freshness. Metering uses is sound where metering checks is not, but a usage-boxed policy needs an in-line counter this project is not. And the reframe: an API is operated, a schema is implemented, so the policy lifecycle ships as documents and appends rather than as an API surface.
the brief, rendered → rawConsumption as a SECOND AXIS beside capability: a resource pool is a grant that DEPLETES, carrying a remaining no existing node has. The first real pooling mechanism in the pivot — variance absorption in a currency that is not money, so no carrier and no authorisation. A budget overage is a loss event that is already recorded by somebody else, which is the first loss data this estate can obtain and lets loss-event/v0 be drafted against a real instance. Resolves GM-D78's collision (the counter exists, run by the supplier for billing) and finds doctrine 07's first mover (the supplier has a reason to refuse: it is paying). Corrected: the memo says the pool defines the grant, and it does not — a pool bounds volume, never reach, and the cheapest catastrophic action is cheap.
the brief, rendered → rawThe money in a policy is a metric for what the claim buys, so pay the claim in the resource itself: a draw on the pool IS the claim, paid in bytes or tokens, settled by the check in milliseconds because trigger, cover and payment are fields of one document. A worked policy with all four excess-of-loss parts for two resources, a pool shared per repository so pooled fate is deliberate, and 'let Claude manage it' read honestly as a SETTING. And the first MVP: insurance/push-policy, whose first finding is that twelve of twelve site releases would have been refused, because the release stamps the version into every page.
the brief, rendered → rawOne policy walked up every place it can be enforced: nothing, a prompt, a skill, a git hook, the destination, out-of-band verification. The levels are the tier test refined, with detection as a tier the test had not named. Assurance per level is measured from the ledger's catch rate on ordinary work, never asserted. A catch above the hook is an incident rather than a volume event: no draw, a different policy, escalation, a candidate for suspension. And level five, replaying git against the ledger, is the control that turns a setting into a detector; built the same day and run over the eleven commits since the hook: no catch.
the brief, rendered → rawThe doctrine
Derived from the memos, naming which memo each part came from. The markdown under
insurance/src/ is the source of truth; these pages render it.
The body of work, its two stages, and the one rule that keeps a rating from becoming theatre.
The ratable unit is a placement, not an agent; inputs carry their evidence channel; measured and declared never merge; unknown is never absent.
The roles are the integrity mechanism; the rating gates go-live rather than reporting; and a gate that overstates its own tier is worse than none. Removing the payout removes one channel of moral hazard and opens another; and a rider read as an endorsement is an append, which the register has done since v0.1.26.
Only the delta an operator could have closed is theirs; platform granularity is a library artefact; and a rating states what changed and which way, never a multiplier. Memo 3 also asked whether a model vendor would carry a policy against its own mistakes — the same argument memo 6 later made about brokers, three memos early.
Cyber insurance is the warning, not the model — and its failure is the empirical case for this folder's rule. The enforcement tier ranks REACHABILITY, which is the neighbouring quantity to the impact reduction the memo asked for, not the same one.
The scale is 1–5, settled. The project supplies schemas rather than standing in the line — which means it can never itself be a boundary.
A broker's claimed reduction is computed by the method, not the broker — and a broker moves exposure as well as removing it, so the net may be positive.
A policy is a mandate-shaped statement; a key signs and the policy says what that is worth; and the relying party is where this pivot can finally reach a boundary.
The first MVP explains rather than calculates — and the world it renders must show its own emptiness, because a polished simulation makes a demonstration look like a product.
The first thing here that could be wrong in a way the world would correct — plus the guard-rail that stops “make them insurable” becoming “make them look insurable”.
A warranty fails three ways and unknown counts as failure; cover runs on three clocks; and the deliverable is documents and appends, not an API.
Consumption is a second axis the corpus never had; a pool bounds volume and never reach; and a budget overage is the first loss event this pivot can actually observe, because somebody else already meters it.
A draw on the pool is a claim paid in the resource and settled by the check itself; the pool is shared per repository; the skill is a setting and says so; and the first MVP's first finding is about this estate.
Six levels of enforcement on the three tiers, with detection as a fourth; assurance per level measured from the ledger; a catch above the hook is an incident; and reconciliation against git as the maintainer's job, built and run the same day.
The MVPs
A budget on pushes per day and bytes per push with a shared daily pool: a policy document, a checker that measures what git would send, an append-only ledger, a hook shipped and not installed, and a skill that makes Claude the enforcement point. First finding: twelve of twelve site releases would have been refused.
The dev pack
The pack the fourth v0.33.62 brief specifies, written 3 September after the nine-item inventory: three vaults, a policy object generic on unit, a ledger that is only ever added to, git hooks as the enforcement point, Claude hooks as instrumentation, and a room of five cards. Step 1 is built: a 400 KB commit refused by git, the eleventh commit of the day recorded as a draw, a push outside the mandate refused. It supersedes nothing here; it generalises the push policy's verdict to any unit at commit and at push, and pins the signed mandate by hash.
What it consumes
Nothing here starts from scratch — the rating's inputs are documents this estate already publishes:
the measured grant (the twin),
the signed mandate,
the delta with its
acceptor: null, the enforcement tier computed in
the workbench, and the fixture-or-real class read from
the register before any signature.
What this does not prove
- That any of this is insurance. Stage 1 emits a rating, transfers no risk, and promises no payout — which is exactly why it needs no carrier and why calling it insurance would be the first dishonesty.
- That the placement orderings are true. Claude-on-a-desktop is rated higher than Claude-on-the-web in the project lead's judgement; nobody has measured a desktop agent, so the estate cannot score its own leading example.
- That a level means the same thing to two organisations. Nothing here is calibrated against loss data, because no agent loss data exists anywhere.
- That aggregation works yet. Correlated risk is named as a graph problem and not solved; summing micro ratings would be wrong in the dangerous direction.
- That an internal underwriter is independent. The separation between the rater and the party that wants to ship is an org-design outcome no schema can enforce — and a rating engine reporting to the deploying business is a setting with a nicer name.
- That the delta classes can be told apart automatically. Distinguishing elective from structural needs a library of platform granularity that does not exist yet — today the classification is a judgement.
- That dynamic re-rating is close. The mapping from a published advisory to the grant nodes it widens exists nowhere, for anybody, and it is the hard part.
- That the estate's own grant measurement is complete. Memo 3 named a node measure.py misses — commit authorship — found by conversation rather than by the tool, and the honest reading is that there are others.
- That five bands are the right resolution. The scale is settled and argued for; nothing validates it against outcomes, because there are no outcomes yet.
- That the not-in-line position is commercially viable. It is a coherent architecture and an unproven business — nobody has paid for a schema here.
- That a broker's netting can be computed today. Rating what a broker adds as well as what it removes needs a grant tree for the broker relationship, and no broker publishes one.
- That the handshake is a boundary anywhere today. It reaches that tier only where the relying party is genuinely independent of the requester, and nothing has been built or installed to test it.
- That a world explains better than a document. It is the memo's hypothesis and the site agent's agreement, and neither is evidence — which is why the 2D-first sequencing exists.
- That the emptiness rule survives contact with a demo. Showing what does not exist is easy to write down and hard to keep when somebody wants to impress a room. It is the first thing that will be argued away.
- That anything here has been checked against the market. The whole log and no external evidence: memo 9's survey is the first item in this series that could be wrong in a way the world would correct, and it has not been run.
- That the readings were right the first time. All eleven were audited against their transcripts at v0.33.82 and six defects were found and fixed — three stale counts, a claim identified with the wrong quantity, an over-claim of immunity to moral hazard, and a dropped question. The method held; the arithmetic and the housekeeping did not.
- That an agent placement can be insured at all today. The categories that exist generally insure firms and entities, not placements — and whether any carrier has since launched one is unresearched, and is deliberately not guessed at.
- That any of the schemas exist. policy/v0 has a shape, loss-event/v0 does not, and the warranty set described in doctrine 10 has never been written down as a schema.
- That blast radius is a good proxy for severity. Doctrine 04 corrects the tier's identification with impact reduction and then leans on the proxy anyway. It is an argument, not a measurement, and it is weakest where a small reach touches something critical.
- That anything here measures severity at all. Nothing in this folder computes how bad a loss is once it occurs. Memo 4 asked for that quantity and the estate does not have it.
- That the push policy is a boundary. It is the first MVP and it is a SETTING: the check runs where the agent runs, against a ledger the agent can edit. The same policy as a required CI check would be a boundary, and that has not been built.
- That agent consumption actually correlates. Doctrine 11 argues it would and names plausible shared causes, but it is a hypothesis, and it is the one the data would settle first.
- That consumption loss data transfers to capability loss data. A pool supplies loss events about SPEND. Nothing here produces a single data point about what a breach costs, which is what a stage-2 premium would need.
- That the policy's numbers fit this repository. The only fit so far, the checker replayed over twelve releases, refused all twelve; doctrine 12 argues the estate's release mechanism is at fault rather than the numbers, and that is an argument, not a calibration from a ledger that has no live entries yet.
- That the vault cost in the case study is measured. It is arithmetic from sgit's design — content-addressed on plaintext, no delta packing across ciphertexts — applied to git's measured numbers; no vault of this site's history exists to weigh.